You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
Secret RedactionArea: what it touches
ImprovementsKind: in v2.1.287,
ImprovementsSection of the release
What
Claude Code keeps a list of patterns it uses to spot secrets, such as passwords and keys, and hide them. The list has a new rule, sensitive-assign-escaped. It catches secrets assigned inside text whose quote marks are escaped with a backslash, like \". This happens with JSON stored inside another string.
The rule only hides the matching text and does not do anything else with it. It is marked as low confidence.
Why
Secrets inside escaped JSON used to get past the secret-hiding list. Now they get hidden.
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear where this secret-hiding list is applied, for example usage data, transcripts or both.