Follow Discord
Sweep 02 Oct 2026 · 18:55Z Build v2.1.288 509 read Stable v2.1.285 Latest v2.1.288 Next v2.1.288 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.288 ·

Sandbox file-read rules gather more sources

The sandbox's file-read rules now include user settings passed in directly, allowRead re-opens and credential files resolved across all settings levels

Group of 2 Under the hood Internal Changes
JSON All of v2.1.288
Under the hoodTier: how much it should matter to you
2Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
ElsewhereArea: what it touches
Internal ChangesKind: in v2.1.288,
Internal ChangesSection of the release

What

The sandbox limits which files commands run by Claude Code can touch. Part of its setup is a list of files it may not read, plus exceptions that open some of them again. This release changes how that list is put together.

  • The function that collects read rules now accepts an optional settings object. It merges deny and ask rules from user settings, plus sandbox re-opens, from that object and removes duplicates. Before, rules came only from settings already loaded from their usual places.
  • Sandbox allowRead entries, called re-opens because they open up paths that were otherwise blocked, are now collected as well.
  • Sandbox credential files (credentials?.files) are now worked out once across every settings level up front, instead of inside the loop over each level. Their deny forms feed the check that decides whether an allowRead entry re-opens a path.

Why

User-settings edits that have not been saved yet are now taken into account when deciding which files the sandbox blocks. Credential files are checked against allowRead re-opens, which affects whether an exception can open them up.

Read from
Names in the bundleallowRead
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhat part of Claude Code passes these settings in is not known.

See this entry in the whole of v2.1.288 →

Feedback