Follow Discord
Sweep 02 Oct 2026 · 18:55Z Build v2.1.288 509 read Stable v2.1.285 Latest v2.1.287 Next v2.1.288 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.287 ·

Sandboxed project hooks are checked more strictly before they run

A sandboxed project hook now runs only if Claude Code confirms it is a deny-by-default sandbox launch; otherwise it is skipped and an error is logged

You'll notice Improvements
JSON All of v2.1.287
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
HooksArea: what it touches
ImprovementsKind: in v2.1.287,
ImprovementsSection of the release
What

A hook is a command that Claude Code runs automatically at set points, for example before or after it uses a tool. A project hook is one defined in a project's own settings. When Claude Code wraps a project hook in a sandbox (a restricted environment that limits what the command can reach), it now checks that the result really is a deny-by-default sandbox launch. Deny-by-default means everything is blocked unless it is explicitly allowed.

If the check fails, the hook is not run, and the failure is logged at error level. The earlier check looked only at whether the wrapped command began with a fixed profile prefix. That check has been replaced by the new one.

Why

This is a security hardening step. A project hook that is meant to run inside a strict sandbox will not run at all unless that sandbox is confirmed to be in place.

See this entry in the whole of v2.1.287 →

Feedback