You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
HooksArea: what it touches
ImprovementsKind: in v2.1.287,
ImprovementsSection of the release
What
Hooks are commands that run automatically at set points in a session. When project hooks are served remotely, they run in a sandbox, a restricted environment that limits what they can touch, and need a private temporary folder. Claude Code now looks for one in this order:
The chosen folder must lie outside anything the session can write to. Previously it used TMPDIR if that was out of reach, and otherwise fell back to a default temp folder. When no suitable folder is found, or the hook is not wrapped in the sandbox, Claude Code now logs an error with the specific reason, such as no temp directory lying outside what the session can write.
Why
This tightens the sandbox around hooks that come from a remote source, so they cannot share a temp folder the session itself can write into. It applies only to remotely served hooks.