Follow Discord
Sweep 02 Oct 2026 · 18:55Z Build v2.1.288 509 read Stable v2.1.285 Latest v2.1.287 Next v2.1.288 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.287 ·

Remotely served project hooks pick a private temp folder more strictly

Project hooks served remotely now use a temp folder only if it lies outside what the session can write, and log a specific error if none does

You'll notice Improvements
JSON All of v2.1.287
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
HooksArea: what it touches
ImprovementsKind: in v2.1.287,
ImprovementsSection of the release
What

Hooks are commands that run automatically at set points in a session. When project hooks are served remotely, they run in a sandbox, a restricted environment that limits what they can touch, and need a private temporary folder. Claude Code now looks for one in this order:

  • the folder named by TMPDIR
  • the system temp folder
  • on Linux, a fixed path

The chosen folder must lie outside anything the session can write to. Previously it used TMPDIR if that was out of reach, and otherwise fell back to a default temp folder. When no suitable folder is found, or the hook is not wrapped in the sandbox, Claude Code now logs an error with the specific reason, such as no temp directory lying outside what the session can write.

Why

This tightens the sandbox around hooks that come from a remote source, so they cannot share a temp folder the session itself can write into. It applies only to remotely served hooks.

See this entry in the whole of v2.1.287 →

Feedback