Follow Discord
Sweep 29 Sep 2026 · 18:10Z Build v2.1.285 506 read Stable v2.1.280 Latest v2.1.285 Next v2.1.285 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.285 ·

Secret redaction catches more passwords written inside URLs

Secret scrubbing now catches more forms of usernames and passwords written into URLs, including quoted and encoded ones

Group of 2 You'll notice Improvements
JSON All of v2.1.285
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
RedactionArea: what it touches
ImprovementsKind: in v2.1.285,
ImprovementsSection of the release

What

Claude Code scrubs secrets from text such as logs before they are stored or shown. A URL can carry a username and password before an @ sign, like https://user:pass@host. This part is called userinfo.

  • The url-userinfo pattern now handles quoted userinfo and delimiter characters. Before, it was a simple match on everything between :// and @.
  • New patterns are added: url-userinfo-tail, url-userinfo-later-at, url-userinfo-encoded and masked-value-rest.
  • Patterns for sensitive assignments, such as password=..., now accept other kinds of whitespace.

Why

Credentials written into URLs are removed in more of the forms they appear in, so fewer slip through into logs or output.

See this entry in the whole of v2.1.285 →

Feedback