Follow Discord
Sweep 02 Oct 2026 · 18:55Z Build v2.1.288 509 read Stable v2.1.285 Latest v2.1.288 Next v2.1.288 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.288 ·

Sensitive settings from the launch folder can now be dropped before they apply

Unless a launch-folder policy allows them, settings such as enabledPlugins and modelOverrides from the launch folder are now removed

You'll notice Improvements
JSON All of v2.1.288
You'll noticeTier: how much it should matter to you
3Useful: my rating, 1 to 5
3Signal: worth watching, 1 to 5
SettingsArea: what it touches
ImprovementsKind: in v2.1.288,
ImprovementsSection of the release
What

The launch folder is the folder Claude Code was started in, and it can hold its own settings. Claude Code now removes a list of sensitive settings from that folder's settings before combining them with the rest, unless a policy says they should be read as written. The list includes:

Why

These settings can turn on plugins, approve MCP servers (outside tools Claude can call), move where memory is stored or redirect which model is used. Dropping them from a folder's own settings stops an untrusted folder from quietly changing them when you start Claude Code there.

Read from
What the documentation says
Documented inclaude-code/mcp
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear what sets the policy that decides whether these settings are kept or removed.

See this entry in the whole of v2.1.288 →

Feedback