# Claude Code v2.1.286

> Claude Code v2.1.286, released 30 Sep 2026 (2026-09-30). 290 entries read out of the shipped bundle. Unofficial, and not affiliated with Anthropic.

[Web version](https://changelogs.core-directive.com/v/2.1.286)

You can now rely on a built-in security plugin to keep your deny rules in force when other plugins try to lift them. It can also refuse plugins that did not come from your organization. Plugins can now build the system prompt themselves through a new `prompt.compose` hook, and Claude Code falls back to its own prompt if that fails. Setting `CLAUDE_CODE_AUTO_MODE_TIER` to any value, even "full", puts auto mode on its strict tier. With `CLAUDE_CODE_ARTIFACT_SHARE` set, Claude can share an artifact with your organisation or named colleagues after you confirm. A new notice offers a key, ctrl+y by default, to make a newer model your default.

This release has 16 entries in the build that are not switched on yet. On Linux, project hooks can run in a locked-down sandbox called bubblewrap, with no network and a hidden home folder. That sandbox waits on a server switch. Keepalive pings that hold a one-hour prompt cache open during idle pauses are also off unless switched on remotely. A background task for importing local memory notes is taking shape, with a "memory import" entry in the task list. Remote tool permission checks gain retries for timed-out safety checks, behind three switches.

Prompts rewritten by a hook on submit now reach Claude as rewritten. Resumed sessions restart interrupted turns by mistake less often. Resuming in `--print` mode with an SDK connection now always runs its cleanup step, even after a failure. The ultrareview details dialog no longer offers to open the review in a browser. Starting a remote session no longer sends file sync, folder seeding or sync consent options. The `/plugin-types` command is now hidden from command listings but still works.

## Sections

Each section is its own markdown document of whole entries, in pages of about 40 KB. The whole release in one document is [full.md](https://changelogs.core-directive.com/v/2.1.286/full.md).

- [What probably matters to you](https://changelogs.core-directive.com/v/2.1.286/what-probably-matters-to-you.md): 44 entries, 2 pages
- [Improvements](https://changelogs.core-directive.com/v/2.1.286/improvements.md): 124 entries, 4 pages
- [Bug Fixes](https://changelogs.core-directive.com/v/2.1.286/bug-fixes.md): 25 entries
- [In Development](https://changelogs.core-directive.com/v/2.1.286/in-development.md): 10 entries
- [Internal Changes](https://changelogs.core-directive.com/v/2.1.286/internal-changes.md): 79 entries, 2 pages
- [Removed](https://changelogs.core-directive.com/v/2.1.286/removed.md): 8 entries

## What probably matters to you

The first 10 of 44, one line each. The section's own pages have every one in full.

- [Prompt cache keepalive added, with a policy that switches it off for HIPAA organizations](https://changelogs.core-directive.com/v/2.1.286/e/cache-keepalive-sender-for-prompt-cache-tengu-sequential-cl.json): Claude Code can ping the API to keep a one-hour prompt cache alive during pauses, unless the allow_cache_keepalive policy denies it
- [Cloud sessions running commands on your computer get a hook sandbox, auto-mode notices and hook-rewrite rules](https://changelogs.core-directive.com/v/2.1.286/e/bubblewrap-sandbox-for-project-hooks-on-linux-gated-by-teng.json): Remote tools gains a bubblewrap sandbox for project hooks, reasons for auto mode being off, and finer handling of hook input rewrites
- [Auto-mode classifier learns about relayed messages in shared projects](https://changelogs.core-directive.com/v/2.1.286/e/hearth-member-relay-rows-env-override-plus-flag-defaulting.json): The auto-mode classifier gains rules for messages relayed from a project's coordinator or another thread, with a new env var, flag and killswitch
- [New CLAUDE_CODE_AUTO_MODE_TIER variable selects the strict auto mode tier](https://changelogs.core-directive.com/v/2.1.286/e/claude-code-auto-mode-tier-env-var-any-set-value-selects-s.json): Setting `CLAUDE_CODE_AUTO_MODE_TIER` to any value selects the "strict" auto mode tier, and it is passed on to processes Claude Code starts
- [Built-in claude-test plugin gets clearer start-up errors and no longer requires a terminal session](https://changelogs.core-directive.com/v/2.1.286/e/claude-test-plugin-module-with-guided-start-up-errors-and-us.json): The claude-test plugin now explains why it failed to start, gives new advice on duplicate copies, and drops its terminal-only message
- [New built-in "You should know" plugin suggests learning topics, off by default](https://changelogs.core-directive.com/v/2.1.286/e/you-should-know-builtin-plugin-side-agent-suggests-things.json): New built-in plugin cc-plugin-you-should-know can suggest a learning topic above the prompt while Claude works; you have to turn it on
- [Artifact tool gains a share action, behind CLAUDE_CODE_ARTIFACT_SHARE](https://changelogs.core-directive.com/v/2.1.286/e/artifact-tool-gains-a-share-action-gated-by-claude-code-a.json): Claude can offer to share an artifact with your organisation or named colleagues, with you confirming each share on a card
- [Local memory import shows up as a background task; footer memories pill removed](https://changelogs.core-directive.com/v/2.1.286/e/local-memory-import-background-task-local-memory-import.json): A new resumable 'memory import' background task for local memory notes is wired into the task list, and the footer's memories pill is gone
- [Early plugin sync at startup for remote sessions, behind an environment variable](https://changelogs.core-directive.com/v/2.1.286/e/early-plugin-sync-for-remote-ccr-sessions-behind-an-env-v.json): A new early plugin sync step at startup runs only when CLAUDE_CODE_CCR_EARLY_PLUGINS_SYNC is set, and not in interactive sessions or with a proxy auth helper
- [A new own_record option for unattended permission handling](https://changelogs.core-directive.com/v/2.1.286/e/unattended-permission-mode-own-record-stopped-sentinel-wi.json): A permission setting now accepts `own_record` for unattended sessions, and one more outcome now counts as stopped
