What
The sandbox is the protection that limits which files and network addresses Claude Code's commands can reach. The built-in descriptions of its settings were expanded:
sandbox.enablednow reads "Run Bash commands inside the sandbox. Default: false."ignoreViolationsandenableWeakerNestedSandboxgain descriptions, including a Linux-only option to run without the fresh /proc mount.allowUnsandboxedCommands: afalseset in managed settings, a--settingsfile or user settings holds, and in some cases a project-level value is ignored.overrides_lockedis now described as true also whenallowUnsandboxedCommands: falsecomes from a--settingsfile or user settings, not only from an admin policy.- Project settings cannot re-open paths that another layer denies for reading, and a project-level
network.strictAllowlistvalue is ignored in some cases.
Why
These are descriptions, not new behaviour. They make it clearer that a project's own settings file cannot loosen sandbox limits set by your administrator, a --settings file or your own user settings.
Names in the bundle--settings
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubt
It is not clear whether this is only descriptive text or whether this release also enforces these rules.