Follow Discord
Sweep 02 Oct 2026 · 18:55Z Build v2.1.288 509 read Stable v2.1.285 Latest v2.1.288 Next v2.1.288 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.288 ·

Network paths always need approval, and served sessions refuse to edit settings files

Files on network paths are no longer auto-approved, and served sessions refuse edits to settings files, with clearer reasons in the prompt

Group of 2 You'll notice Improvements
JSON All of v2.1.288
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.288,
ImprovementsSection of the release

What

Claude Code's permission checks decide what Claude may do on its own and what needs your approval. They get stricter in two places:

  • Network paths: a file on a network location (UNC paths such as \\server\share, automounted folders, or paths outside trusted network directories) is now flagged as a network path. It is never approved automatically, and the prompt gives the new reason network_path.
  • Served sessions: when a session runs tools on this computer for a remote session, any tool that would edit or write a settings file is refused.
  • Ask prompts in served sessions now open with ask.outside_sandbox and ask.settings_person_only text, and your own settings now take part in those permission checks.
  • New messages explain why a person must approve, for example "This can delete files or discard changes for good, so a person needs to approve it." These are chosen by the gate tengu_reactive_zephyr, which has not been read, so whether they appear for any given account is unknown.

Why

Network paths and settings files are places where an automatic action could reach further than expected or change how Claude Code itself behaves. These changes put a person back in the loop for them.

Read from
Feature flag
tengu_reactive_zephyr Off in both readings

The flag server returned off for the account this site reads and for the anonymous baseline. A reading of off cannot rule out a rollout these two readings sit outside of.

This account: off · anonymous baseline: off · compiled default in v2.1.288: not a boolean we can read

These values were read against a different version of Claude Code, so treat them as the nearest reading available instead of one taken on this release.

Read once, for one account on one subscription tier, against v2.1.288. It isn't a statement about your account. What a flag value here can and cannot tell you

What has happened since
Flag reading moved The flag server now returns on for tengu_reactive_zephyr, read as this account. A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.
Flag reading moved The flag server now returns off for tengu_reactive_zephyr, read as this account. A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.
Flag reading moved The flag server now returns on for tengu_reactive_zephyr, read as this account. A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.
Flag reading moved The flag server now returns off for tengu_reactive_zephyr, read as this account. A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.
Flag reading moved The flag server now returns nothing at all, having stopped carrying it for tengu_reactive_zephyr, read as this account. A reading is one sample. Claude Code evaluates its flags remotely, so no client sees the targeting rule behind a value and this says nothing about your account.

See this across every release →

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhere the new approval-message wording is shown, and when the remote setting enables it, was not established.

See this entry in the whole of v2.1.288 →

Feedback