{"version":"2.1.285","anchor":"schema-merge-ignores-proto-keys","canonical_anchor":"schema-merge-ignores-proto-keys","heading":"Merging configuration data now ignores keys named __proto__","tier":"notice","area":"Settings","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285\/e\/schema-merge-ignores-proto-keys","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285","markdown":"### Merging configuration data now ignores keys named __proto__\n\nWhen Claude Code merges structured data, it now drops any key named __proto__\n\n**What**\n\nClaude Code sometimes combines pieces of structured data, such as settings described by a schema (a description of what the data should look like). When it does, it now deletes any entry named `__proto__` and skips it while combining.\n\n**Why**\n\nIn JavaScript, the language Claude Code is written in, `__proto__` is a special name. Data that contains it can alter how every object behaves, a kind of attack known as prototype pollution. Skipping it closes off that attack.\n\n- Area: Settings\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}