Follow Discord
Sweep 02 Oct 2026 · 18:55Z Build v2.1.288 509 read Stable v2.1.285 Latest v2.1.287 Next v2.1.288 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.287 ·

Secrets inside escaped quoted text are now hidden

Claude Code's secret-hiding rules can now catch a secret assigned inside text with backslash-escaped quotes, such as JSON nested in a string

You'll notice Improvements
JSON All of v2.1.287
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
Secret RedactionArea: what it touches
ImprovementsKind: in v2.1.287,
ImprovementsSection of the release
What

Claude Code keeps a list of patterns it uses to spot secrets, such as passwords and keys, and hide them. The list has a new rule, sensitive-assign-escaped. It catches secrets assigned inside text whose quote marks are escaped with a backslash, like \". This happens with JSON stored inside another string.

The rule only hides the matching text and does not do anything else with it. It is marked as low confidence.

Why

Secrets inside escaped JSON used to get past the secret-hiding list. Now they get hidden.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear where this secret-hiding list is applied, for example usage data, transcripts or both.

See this entry in the whole of v2.1.287 →

Feedback