# Claude Code v2.1.288

> Claude Code v2.1.288, released 2 Oct 2026 (2026-10-02). 350 entries read out of the shipped bundle. Unofficial, and not affiliated with Anthropic.

[Web version](https://changelogs.core-directive.com/v/2.1.288)

You can now hold project settings changes made from a cloud session until you approve them, by running claude apply-project-settings in that folder. This applies when your computer serves the cloud session. Admins can force unattended serving off through managed settings with unattended_serving_off. Resumed sessions no longer keep the prompt cache warm unless the new resumeTouches setting is on. Claude Code's own stand-in for gh, added last release, can now reach any GitHub Enterprise host when ghesHosts is set to "any". Host apps can block file writes in chosen folders, except inside one declared worktree.

A /restart command that keeps your session is in this build but not switched on yet. It also answers to /update and offers newer versions. A shortcut that answers some artifact edit requests with direct file edits is also off for now. Cloud sessions can hand finished file writes to the next turn's worker, but only once that is switched on remotely. A setup guide feature is wired into the prompt box but does nothing yet.

An oversized reply from an MCP server over HTTP now fails only that request and keeps the connection open. Language server requests now time out instead of waiting forever. Reads and rewrites of a session transcript now wait for each other, so compaction and resume cannot clash. Resumed teammates no longer bring back an agent type that a rule or plugin now blocks. The Read tool instructions no longer include the guidance on PDF page ranges.

## Sections

Each section is its own markdown document of whole entries, in pages of about 40 KB. The whole release in one document is [full.md](https://changelogs.core-directive.com/v/2.1.288/full.md).

- [What probably matters to you](https://changelogs.core-directive.com/v/2.1.288/what-probably-matters-to-you.md): 53 entries, 2 pages
- [Improvements](https://changelogs.core-directive.com/v/2.1.288/improvements.md): 152 entries, 4 pages
- [Bug Fixes](https://changelogs.core-directive.com/v/2.1.288/bug-fixes.md): 27 entries
- [In Development](https://changelogs.core-directive.com/v/2.1.288/in-development.md): 16 entries
- [Internal Changes](https://changelogs.core-directive.com/v/2.1.288/internal-changes.md): 100 entries, 3 pages
- [Removed](https://changelogs.core-directive.com/v/2.1.288/removed.md): 2 entries

## What probably matters to you

The first 10 of 53, one line each. The section's own pages have every one in full.

- [New /restart command keeps your session and refuses remote or non-typed use](https://changelogs.core-directive.com/v/2.1.288/e/restart-command-with-tengu-fancy-wand.json): A /restart command (alias /update) restarts Claude Code, keeps the session and offers a newer version, but only when typed by you at the prompt
- [New hidden switch tied to an "arbiter" permission mode](https://changelogs.core-directive.com/v/2.1.288/e/new-gate-tengu-sorrel-trellis-gusset-defaults-off-with-an.json): Claude Code has a new remotely controlled switch, off unless turned on, with a check for an "arbiter" permission mode beside it
- [Shortcut for artifact edit requests that skips the model call, built but switched off](https://changelogs.core-directive.com/v/2.1.288/e/artifact-patch-turn-fast-path-gated-by-tengu-cobalt-plint.json): Built but off unless enabled remotely: a shortcut that answers some artifact edit requests with direct file edits instead of a model reply
- [Turn handoffs to cloud workers can now carry over pending file writes](https://changelogs.core-directive.com/v/2.1.288/e/carried-writes-turn-handoff-gated-on-tengu-fizzy-petal.json): A turn handoff can now carry answered Write calls to a cloud worker, which writes those files into the home folder before the turn continues
- [Bash permission check now catches risky rm inside sh -c scripts](https://changelogs.core-directive.com/v/2.1.288/e/new-env-var-claude-code-disable-inline-shell-rm-prompt.json): An `rm` hidden in a `bash -c` script with a run-time target now needs explicit approval, with `CLAUDE_CODE_DISABLE_INLINE_SHELL_RM_PROMPT` to turn it off
- [Cloud sessions served by your computer take settings more cautiously](https://changelogs.core-directive.com/v/2.1.288/e/cloud-session-served-settings-new-warnings-and-claude-appl.json): When your computer serves a cloud session, changed project settings are held back until `claude apply-project-settings`, and user settings can only tighten
- [Setup-guide paste feature wired in but switched off](https://changelogs.core-directive.com/v/2.1.288/e/setup-guide-pastelink-helpers-are-wired-in-but-stubbed-out.json): Hooks for a setup-guide paste and link feature are in place, including a wider pasted-text chip match, but they do nothing in this build
- [Host apps can fence off folders so file tools write only to a worktree](https://changelogs.core-directive.com/v/2.1.288/e/host-set-worktree-fence-env-vars-now-enforced-on-file-writes.json): Two new environment variables let an embedding app block file writes inside chosen paths, except inside one declared worktree
- [`claude mcp serve` lists agent types and blocks background agents in restricted mode](https://changelogs.core-directive.com/v/2.1.288/e/per-agent-type-listing-and-subagent-definitions-in-claude-m.json): `claude mcp serve` now offers custom subagent types, and new switches can block background-agent launch and remote isolation, used in its http mode
- [Plugin runtime adds ui.selection and ties network and audio access to a plugin id](https://changelogs.core-directive.com/v/2.1.288/e/plugin-runtime-uiselection-op-httpfetch-refactor-plugin.json): Plugins get a new ui.selection operation, and http.fetch and URL audio playback now use a plugin storage id, with $.audio.play refusing URLs without one
