New /restart command keeps your session and refuses remote or non-typed use#
A /restart command (alias /update) restarts Claude Code, keeps the session and offers a newer version, but only when typed by you at the prompt
You can now hold project settings changes made from a cloud session until you approve them, by running claude apply-project-settings in that folder. This applies when your computer serves the cloud session. Admins can force unattended serving off through managed settings with unattended_serving_off. Resumed sessions no longer keep the prompt cache warm unless the new resumeTouches setting is on. Claude Code's own stand-in for gh, added last release, can now reach any GitHub Enterprise host when ghesHosts is set to "any". Host apps can block file writes in chosen folders, except inside one declared worktree.
A /restart command that keeps your session is in this build but not switched on yet. It also answers to /update and offers newer versions. A shortcut that answers some artifact edit requests with direct file edits is also off for now. Cloud sessions can hand finished file writes to the next turn's worker, but only once that is switched on remotely. A setup guide feature is wired into the prompt box but does nothing yet.
An oversized reply from an MCP server over HTTP now fails only that request and keeps the connection open. Language server requests now time out instead of waiting forever. Reads and rewrites of a session transcript now wait for each other, so compaction and resume cannot clash. Resumed teammates no longer bring back an agent type that a rule or plugin now blocks. The Read tool instructions no longer include the guidance on PDF page ranges.
Written by our agent from the shipped bundle, not by Anthropic.
claude mcp serve lists agent types and blocks background agents in restricted modeclaude mcp serve now offers custom subagent types, and new switches can block background-agent launch and remote isolation, used in its http mode
When your computer serves a cloud session, changed project settings are held back until claude apply-project-settings, and user settings can only tighten
Two new environment variables let an embedding app block file writes inside chosen paths, except inside one declared worktree
ElsewherePlugins get a new ui.selection operation, and http.fetch and URL audio playback now use a plugin storage id, with $.audio.play refusing URLs without one
ExtensionsCLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTS turns off structured outputsSetting CLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTS stops Claude Code from asking the model for replies in a fixed format
Want the reasoning? Read walks the 31 entries that probably matter to you, each one opening to what changed and why.
Read this release → Every row →Anything you can use today, anything that visibly changes, and anything worth poking at. One line each, open for detail.
A /restart command (alias /update) restarts Claude Code, keeps the session and offers a newer version, but only when typed by you at the prompt
claude mcp serve lists agent types and blocks background agents in restricted mode#claude mcp serve now offers custom subagent types, and new switches can block background-agent launch and remote isolation, used in its http mode
Unclear It is not clear what sets backgroundAgentLaunchDisabled or whether a user can set it.
When your computer serves a cloud session, changed project settings are held back until claude apply-project-settings, and user settings can only tighten
Unclear Where the claude apply-project-settings command itself is defined could not be confirmed, only the messages that point to it.
A turn handoff can now carry answered Write calls to a cloud worker, which writes those files into the home folder before the turn continues
Unclear It is not clear how the new worker learns about and receives the carried writes from end to end.
Before reusing a summary prepared in advance, auto-compact now checks it still covers the conversation and fits, and refuses it with a named reason if not
Unclear It is not clear whether preparing summaries in advance runs for anyone, since its setting is only shown when a server-side switch allows it.
Two new environment variables let an embedding app block file writes inside chosen paths, except inside one declared worktree
Unclear Which host application sets these variables is not shown.
Plugins get a new ui.selection operation, and http.fetch and URL audio playback now use a plugin storage id, with $.audio.play refusing URLs without one
Unclear It is not clear what ui.selection returns, or whether the extra check on signed-in requests is always on.
Claude Code has a new remotely controlled switch, off unless turned on, with a check for an "arbiter" permission mode beside it
Unclear It is not clear what the switch controls, where the arbiter check is used, or what "arbiter" mode is.
Built but off unless enabled remotely: a shortcut that answers some artifact edit requests with direct file edits instead of a model reply
Unclear It is not clear where in Claude Code this shortcut is wired in.
CLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTS turns off structured outputs#Setting CLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTS stops Claude Code from asking the model for replies in a fixed format
Unclear It is not clear which models the new support check excludes.
The agents fleet view adds find and jump-between-groups actions, and its keys, including rename and set group, can now be rebound
Unclear The default key for agents:setGroup is not listed, so it may no longer be ctrl+e.
autoCompactWindow can now hold a different value for each model, and /autocompact and /config show and save it for the current model
Unclear It is not shown whether the top-level setting was already read in the same way before.
An rm hidden in a bash -c script with a run-time target now needs explicit approval, with CLAUDE_CODE_DISABLE_INLINE_SHELL_RM_PROMPT to turn it off
Unclear What this variable controls, and whether any rm prompt for inline shell commands is on by default, is not established.
Setting CLAUDE_CODE_GROWTHBOOK_KICK_ON_WARM_CACHE makes non-interactive runs refresh feature flags early even with a saved copy
Unclear It is not clear exactly what the early refresh changes later in the run.
The activity keep-alive settings now include a resumeTouches option, which is off unless set otherwise
Unclear It is not clear what turning this option on does or where it is set.
The description Claude reads about what artifacts can do now mentions the viewer's camera, microphone, location, screen and device motion
Unclear It is not clear whether artifacts are actually given access to these features.
The code review command accepts --max-findings <n>, all or default, and remembers your choice for later reviews
Unclear It does not say which review command, by name, gains this option.
Two environment variables control holding screen-reader announcements, for up to 10 seconds, and rewriting held ones, which is off by default
Unclear Where these announcements are held, and whether another setting must also be on, is not shown.
A new remote switch, off by default, can stop extended usage requests for workflows set to wait out a usage limit
Unclear What counts as extra usage being turned off for a real reason is not stated.
Tools whose names start with mcp__claude-device__chrome_ are now treated as Claude in Chrome tools
Unclear Which Claude Code behaviours depend on this list of Chrome prefixes is not established.
A session can now take on a starting permission mode it was handed even when it is not a remote session, if an option asks for it
Unclear It is not clear what sets this option or whether a reader can set it.
Two new keyboard shortcut actions, chat:increaseEffort and chat:decreaseEffort, step the effort level up or down
Unclear It is not clear whether these actions have keys assigned by default or are held back behind a switch.
On Linux, setting CLAUDE_CODE_CONFIG_WATCH_EVENTS makes Claude Code spot config file changes through system change events
requestTimeout#Requests to LSP language servers now give up after 60000 ms by default, which an LSP server's requestTimeout setting can change
Unclear Whether requests already waited 60000 milliseconds before this change, so that the default is unchanged, is not established.
Log batches sent to Datadog can now be gzip-compressed, falling back to uncompressed if Datadog refuses one
Unclear Whether compression is on by default when the environment variable is not set is not established.
Plugins gain a way to fetch a URL, and Claude Code refuses to restart itself unless you type /restart
Unclear Whether either change is switched on or limited by a setting is not clear.
claude project purge is now claude purge#The purge command moved from claude project purge to claude purge; the old name still works but prints a deprecation notice
A new light purple theme colour for an auto-accept shimmer effect sits next to the existing auto-accept colour
Unclear It is not clear where the new colour is shown.
Variables in a plugin language server's initializationOptions and settings are now filled in, and an empty command gets a clear error
What would fix it?
Smaller changes and internals, grouped as the pipeline found them. Nothing is dropped, it is only further down.
15 more of these are in What probably matters to you, above.
Claude Code now has a confirmation dialog for writing account memory everywhere, alongside its existing account memory permission prompt
Unclear It is not clear when this dialog appears or whether it is switched off unless enabled remotely.
8 more of these are in What probably matters to you, above.
Login now warns when your credentials could not be saved instead of claiming success, names the storage used, and can let you continue without logging in
Unclear It is not clear where this message appears.
New cloud sessions now get their permission mode from --permission-mode, may start in auto mode by default, and weigh your carried mode when deciding
Unclear It is not clear how the carried mode and typed level change the choice, or what the second notice says.
The built-in gh used in proxied and cloud sessions now handles any GitHub Enterprise host, suggests gh api equivalents and gives clearer errors and help
Idle background subagents now wake for more queued items, can wake only to deliver results, and are dropped after repeated failed resumes
Unclear Part of the new wake-up path may not run yet, and it is not clear what decides the extra cases that trigger a check.
The hosted model catalog can now name a minimum Claude Code version that older builds skip, and failed first cloud messages now give a clearer reason
Unclear Whether any model list currently sets a minimum version is not established.
Auto mode can now decide Claude in Chrome actions from grant rules without its safety check, and allows read-only calls the server skipped
Unclear It is not clear what turns on the option that skips the classifier for Claude in Chrome.
Plugin installs and marketplace clones now retry over the other git transport, HTTPS or SSH, when the first fails, and report both errors
Unclear It is not clear what the gitHubHttpsFallback option does when installing a plugin.
ScheduleWakeup is loaded up front and steered toward self-paced /loop#The ScheduleWakeup tool is no longer deferred, so Claude has it from the start, and it gains guidance for /loop runs with no interval
Unclear The tool may be switched on or off elsewhere, so it is not settled that every session has it.
The tool that publishes HTML pages to claude.ai now tells Claude to publish when a page beats text or work is for others, even unasked
Unclear It is not clear whether the publishing tool is available to everyone or switched on only for some accounts.
Resumed sessions can keep the 1-hour prompt cache warm on a timer, but only when server config sets resumeTouches
Unclear It is not clear where resumeTouches is set or whether you can change it yourself.
When the API refuses an image or PDF, Claude Code now drops it from later requests and reports a media_removed error that explains why
Claude Code can now edit an HTML artifact you own in one quick request, and hands the job back when the page is shared, too large or would prompt
Unclear It is not clear what starts this quick edit or whether it is switched on for everyone.
Claude Code can warn you when the combined size of your CLAUDE.md instruction files goes over the limit, showing the size and the limit
Unclear What the further environment check looks at is not known.
Unless a launch-folder policy allows them, settings such as enabledPlugins and modelOverrides from the launch folder are now removed
Unclear It is not clear what sets the policy that decides whether these settings are kept or removed.
The auto-update notice can now show restart wording such as "/restart to apply" or "Restart to update", fetched from a remote configuration
Unclear It is not clear whether /restart exists as a command you can run, or what condition chooses between the two wordings.
A pasted team setup guide now appears as a short placeholder, the same way long pasted text does
Unclear Whether the team setup guide feature is available yet, and what triggers it, is not clear.
In a diskless session, Claude Code now refuses to attach or upload local files and reports an error instead
Unclear It is not clear which sessions count as diskless.
Results from the database write tool now report warnings and embedded data after the usage figures, for single and batch writes
Unclear It is not clear what the embedded part contains, or whether the change is available to everyone.
Claude's artifact instructions now allow device features such as motion sensors only when you have that capability and the page declares it
Served sessions gain a mode where a project hook that changed since attaching is set aside or run as recorded, not always held
Unclear What switches this mode on is not known.
Activity passed in from a linked conversation is now labelled as not a new message from a person and never approval for a prompt
Unclear It is not clear which feature links conversations in this way.
Skills from MCP servers and memory stores, and plugin agents, now have their frontmatter read with limits and are skipped or refused if it can't be read
Unclear It is not clear what reading a header as untrusted changes beyond skipping skills whose header fails.
Claude's environment details gain a githubCli entry, the model is told when built-in gh goes away, and the gh stand-in can reach any GitHub host
Unclear It is not clear what sets ghesHosts to "any".
Side queries now retry without the structured-output format when the API rejects output_config.format, and new helpers recognise PDF and format errors
Unclear It is not clear what check now decides whether the format is requested at first.
Headless sessions can skip waiting for MCP servers the conversation doesn't need, and no longer defer servers added after the first request
Unclear It is not clear which mode or setting turns this skipping on.
When this computer serves a cloud session with no one at the terminal, the launch folder's local settings and hooks are skipped and you are told why
Unclear What puts Claude Code into this served-session mode is not shown.
When an MCP server asks you to finish something in a browser, the dialog now offers Open in browser, I'm done, continue and Decline
Unclear It is not clear which MCP requests use the new layout and which still use the old two-button one.
The Remote Control bridge now records when its environment secret expires and can re-register early to renew it; stop messages are reworked
Unclear What starts an early re-registration, and what sets the separate check-in interval, is not established.
Chrome tool permission prompts now carry the client platform, the granting rule and classifier status, and settings rows can show a short notice
Unclear Whether these details are shown to you anywhere is not established.
Stopping or rewinding a remote session turn now properly ends the turn and clears a message that was being held back, instead of leaving it stuck
Unclear What sets a session up to retire parked requests on stop is not established.
Files on network paths are no longer auto-approved, and served sessions refuse edits to settings files, with clearer reasons in the prompt
Unclear It is not clear when a session counts as served or exactly what you see when an edit is refused.
When a conversation is too long for auto mode's safety check, Claude Code can now compact it and tell Claude to retry the action afterwards
Unclear What decides whether Claude Code asks for compaction, rather than only blocking, is not settled.
The Code tab in Claude Desktop now gets a warning when your CLAUDE.md and rules files together exceed the recommended size
Unclear The recommended size limit itself is not stated.
The code review prompt can now keep every finding with no limit, or have results reported through a tool call
Unclear It is not clear what decides which version or which limit a review uses.
The dialog for MCP servers that ask you to sign in again with extra permissions now falls back to on when the server sends no setting
Unclear It is not clear what the second remote switch, now read where the old one was, controls.
The updater now checks the installed claude runs, fails with native_binary_missing if it is only a stub, and shows clearer failure hints
Unclear Where this failure category is shown to the person installing is not stated.
Clearing the prompt box with Ctrl+C now keeps the text, and pressing Up while the box is empty restores it
Unclear The exact situations in which Ctrl+C keeps the text, and how long it is kept, are not known.
rewind_conversation now waits for a stopping turn to settle and refuses when the messages it would cut are no longer on disk
Unclear What the Send-now interruption mark changes for a user is not known.
The dialog an MCP server uses to ask you for input can now be told you will confirm when you are done, and can check whether an answer would be taken
Unclear It is not established whether this dialog is linked to the step-up sign-in setting for MCP servers whose default changed.
Claude Code now checks each MCP server sign-in response for a missing-permission answer and returns the server's real response
Unclear It is not shown where the step-up dialog switch is read, so the link between this change and that dialog is unconfirmed.
Remote sessions can now say a permission request was withdrawn because nobody answered it in time, and a --any-host flag appears
Unclear It is not clear which commands accept --any-host or --gh-standin, or what they do.
If the current model cannot accept a whole PDF, Claude Code now attaches the PDF as a reference instead of sending the entire file
Claude Code now defers a second set of tools, keeping their details out until tool search finds them
Unclear It is not clear which tools are on the new list.
In remote sessions, a project hook that changed after you approved it is now held until you give permission again
Unclear The exact wording you see when asked again, and whether this is switched on for everyone, is not clear.
Tool calls served to a remote session are cancelled when that session is no longer served, and broken project hooks are tracked
Unclear It is not clear what switches this behaviour on or what its defaults are.
When a hold is on, tools and instructions from an MCP server that is reconnecting are not announced as gone, and are re-announced if they return
Unclear What turns the hold on is not known.
Plugins are now refused network access when CLAUDE_CODE_EVAL_CONFINED is set, and a message says the session's credential is withheld
Unclear Which sessions count as being in the mode that gets the credential-withheld message is not known.
ANTHROPIC_DEFAULT_SONNET_MODEL#If ANTHROPIC_DEFAULT_SONNET_MODEL names an excluded model, auto mode's classifier uses the Sonnet 5 default and logs the reason once
Unclear Which models are on the exclusion list is not stated.
Claude Code can decide to reuse an earlier compaction summary, and refuses when, for example, the result would not fit
Unclear What triggers this reuse, and whether it is switched on, is not stated.
When a permission check fails with an error and a certain option is set, Claude Code asks for your approval instead of passing the action on
Unclear What sets this option is not stated, so it is unclear when it applies.
When pulling shared team memory partly fails, Claude Code now logs how many files failed and keeps them queued for the next sync
When a conversation grows too long for auto mode's checks, Claude is told which actions did not run and to issue them again
Unclear What triggers this reminder and whether anything controls it is not established.
Notices about held or expired messages between sessions now say plainly they were not delivered and explain why
Resuming a session now checks the saved model before using it, and a saved "default" resolves to the current default model
Unclear It is unclear where the logic for restoring a model after a refused launch model is used, so its effect is unknown.
When subagents are nested as deep as allowed, the Agent tool is taken away from the next one, even if its definition asks for it
Unclear The depth limit is not stated, and it is not clear where the record that the tool was withheld shows up.
Auto mode's classifier floor can now take effect even when the automatic checker cannot run, which it could not before
Unclear It is not clear what the classifier floor does to a tool call when the classifier cannot run.
An artifact's database now refuses writes with a specific error when its total stored size hits the limit, including when a document grows
When two machines try to host the same Remote Control session, one can now follow the newer one or step down
Unclear It is unclear what decides which of these paths runs, or whether this tracking is active.
The menu for a single plugin now lists Update now and a red Uninstall option, so you can manage the plugin from there
Unclear Some kinds of plugin may not show these options.
Remote Control now renews this computer's credential before it expires, instead of only after a connection is rejected
Unclear Renewal depends on an expiry time from the server, and what sets it is not known.
The hooks panel now lists this machine's hooks, says whether each runs in the cloud session, and shows your consent status
Unclear It is not clear what setting or condition makes this panel appear.
Approving Claude's plan to leave plan mode now switches the session to default permission mode, and the mode indicator shows an "on" hint
Unclear It is not clear what the busy state for slash commands changes for you in practice.
API timeout errors are now classified as timedOut instead of serverError, and are retried or sent to a fallback model rather than failing
Unclear It is not clear what this handling actually does, for example whether it retries the request or skips a fallback.
Cleanup of unused Remote Control placeholder sessions now keeps connected sessions and checks title, use and server state before archiving
Unclear It is unclear what records that a placeholder session was used.
For remote background commands, Claude is now told a command is over when its output file ends with an exit or stop line
Unclear It is not confirmed that the remote host actually writes these closing lines.
When Claude Code can't find a task you ask it to stop, the error may now name the host tool that owns it
Unclear It is not clear when the host-tool lookup is on or what the "needs" part of the message names.
The Claude in Chrome permission dialog can now show a dimmed notice naming the site, above the answer options
Unclear It is not clear in which situations the notice is shown or exactly what it says.
Read, Edit, Write and NotebookEdit now refuse a file path that ends in white space once . and .. are worked out
A keypress now clears held screen-reader announcements and redraws the screen, and right-click copy first removes the current selection
Failed MCP tool calls now say if the response passed the size limit or the connection closed, and warn the tool may already have run
Published verbatim by Anthropic for v2.1.288. Text is unmodified from the upstream changelog. Everything else on this page came out of the bundle instead, which is why the two lists don't match.
Of these 89 bullets, 18 name something an entry on this page also names, 29 name something no entry here does, and 42 name nothing specific enough to line up either way. The pairings are made on names both sides wrote down, a flag or a setting or a slash command, so read one as probably the same thing rather than as a fact, and read the middle number as candidates rather than as a miss count.
$.ui.selection() for mods: returns the text you last selected in fullscreen mode and, when the selection lies within one transcript row, that row
No entry names this gh api to cloud sessions whose image has no GitHub CLI, and fixed the built-in sending control characters from file names, jq filters or GitHub errors to the terminal
Probably built-in-gh-agent-proxy-now-supports-any-github-enterprise, gh-shim-refusal-message-is-now-more-explicit, built-in-gh-api-client-prompt-text-added-with-no-in-bundle --max-findings <n>|all to /code-review to report more or fewer findings than the usual limit; the choice is reused until you pass --max-findings default
Probably review-arg-parser-adds-max-findings --resume sometimes dropping files and other context that a compaction had just restored
No entry names this --resume showed the prompt unanswered
No entry names this CLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTS to turn structured outputs off
Probably new-env-var-claude-code-disable-structured-outputs-turns-off sonnet subagent
Nothing to match on Code element held a diff that does not parse; it now draws as plain code
Probably signed-cache-cert-check-reports-hours-left-instead-of-days, updater-status-text-and-failure-hints ${user_config.*} and ${CLAUDE_PLUGIN_ROOT} placeholders in initializationOptions and settings instead of substituted values or manifest defaults
Probably plugin-user-config-substitution-can-leave-unset-keys-li, plugin-lsp-config-expands-variables-inside-initializationopt #95801[BUG] Plugin userConfig template ${user_config.X} not substituted in lspServers initializationOptions Open
tool.call hook making Bash fail and file searches read the wrong folder in subagents that run in a worktree
No entry names this #92533Any function-hook tool.call on Bash breaks Agent isolation: "worktree" — every Bash call refused with "isolation context for this agent was lost" Open
git-subdir plugin installs failing, or caching an incomplete plugin, on older git (before 2.39, e.g. Ubuntu 22.04's 2.34)
No entry names this #98629[BUG] Plugin install fails for git-subdir sources since 2.1.274: "git checkout after sparse-checkout failed … index.lock: File exists" Open
--plugin-dir not showing "Configure options" in /plugin
Probably plugin-user-config-substitution-can-leave-unset-keys-li, cloud-hooks-dialog-gets-plugin-hook-note-and-consent-summary python3 <<EOF) asking for approval on every run under sandbox auto-allow when the body holds only plain text and simple $VAR references
Probably new-guard-prompts-on-rm-hidden-inside-sh-c-scripts-wit BASHPID assignment whose value the shell would evaluate as arithmetic, instead of allowing it silently
No entry names this claude_code.tool.blocked_on_user spans reporting unknown source or decision in -p and SDK sessions and for PreToolUse hook approvals
No entry names this -p or on an interrupted turn, emitting no tool_decision event
No entry names this /compact even though its history was still saved
No entry names this CLAUDE_CODE_RETRY_WATCHDOG) retrying for hours after a very long response stream failed; Claude Code now streams again, and gives up after three timeouts
No entry names this /login reporting "Login successful" when credentials could not be saved to secure storage; it now shows the failure, and offers a retry when the new login didn't take effect (anthropics/claude-code#73861)
Probably bare-mode-login-now-refuses-with-explanation, login-shows-a-dedicated-screen-when-credentials-cannot-be-sa #95425/login reports "Login successful" but token is never saved: ENOTDIR rmdir on stale .storage-write.lock file (2.1.277) Open
#89801TUI /login reports success but never persists credentials — Keychain timeout classified as transient skips the file fallback Open
#86616macOS login keychain corrupted twice in 3 days (CSSMERR_CSP_INVALID_DATA); corruption timing matches Claude Code credential writes under ~20 concurrent instances Open
#95386[BUG] macOS: "Keychain is not writable" reported while security add-generic-password succeeds; login never persists (v2.1.276) Open
gcpAuthRefresh/awsAuthRefresh browser sign-in opening when a laptop wakes from sleep while another Claude Code process is signing in
No entry names this -p / SDK) sessions occasionally ignoring SIGTERM when a supervisor such as timeout or systemd sends SIGCONT alongside it
Nothing to match on memory
Nothing to match on #98546Desktop-hosted sessions: subagents receive none of the tools of a user MCP server named `memory` (misclassified as account memory server, since 2.1.284) Open
disableAutoMode or an older model); typing, navigation and JavaScript still ask
Probably auto-mode-off-explanation-text-for-permission-prompts claude plugin install failing for GitHub-source plugins on macOS and Linux machines with no GitHub SSH key: the clone now falls back to HTTPS and prints a notice
No entry names this sandbox.credentials.files entries on git config files not taking effect while permissions.blockReadsOutsideWorkingDirectories is on
No entry names this /tui)
No entry names this tools: lists very many Agent(...) entries
No entry names this claude stub was installed
Nothing to match on #95297[BUG] `claude upgrade` reports success but leaves `bin/claude.exe` as the fallback stub — native binary not linked Open
#88105[BUG] Auto-update to 2.1.237 leaves broken stub on Windows: [email protected] missing from npm registry (incomplete release) Open
#96265[Windows] claude update (npm global) reports success but leaves 500-byte placeholder claude.exe: 'not a valid application for this OS platform' Open
#85974[Bug] Auto-update reports success with non-functional stub binary after postinstall link failure Duplicate
#85975[Bug] Auto-update reports success with non-functional stub binary after postinstall link failure Duplicate
owner/repo plugin marketplaces showing only the second attempt's error when both the SSH and HTTPS fetch fail; both errors are now shown, with the transport tried first on top
No entry names this #96811Plugin marketplace update/refresh forces HTTPS and fails even when the existing clone works fine over SSH Closed
.claude/rules and nested CLAUDE.md files not loading when Write or Edit creates or changes a file in their scope (previously only Read loaded them)
No entry names this #96361[BUG] Path-scoped rules and nested CLAUDE.md never load when Write creates a new file Open
#93248[FEATURE] `paths:` frontmatter on rules and skills triggers on reads only, so neither loads when Claude creates a file Open
rm (such as one on / or the home directory) inside a bash -c or sh -c script running without a prompt in bypassPermissions mode or under a shell allow rule (anthropics/claude-code#96300)
Probably inline-sh-cbash-c-rm-commands-now-get-a-dangerous-rem, new-guard-prompts-on-rm-hidden-inside-sh-c-scripts-wit #96300Dangerous-rm check does not look inside `sh -c` / `bash -c` Closed
requestTimeout)
Probably lsp-requests-get-a-timeout-and-telemetry-workspace-file-wat, lsp-servers-get-a-configurable-per-request-timeout-default #96044LSP client answers client/registerCapability with -32601, wedging servers that use dynamic registration (and no per-request timeout) Closed
idle_prompt notification hooks firing while background agents are still running (anthropics/claude-code#93672)
No entry names this #98373[BUG] idle_prompt "Claude is waiting for your input" fires while background agents/tasks are still running Open
#93672[BUG] Notification idle_prompt fires while background subagents are still running Closed
/login in a --bare session running a sign-in the session never reads, which could replace your saved login; it now says which credentials work
Probably bare-mode-login-now-refuses-with-explanation, login-shows-a-dedicated-screen-when-credentials-cannot-be-sa claude mcp serve always reporting no available agents and rejecting every subagent_type
Probably mcp-serve-honours-strict-mcp-config, per-agent-type-listing-and-subagent-definitions-in-claude-m /theme's custom color search
No entry names this /permissions in screen reader mode: typing a rule's number now picks it instead of opening the search box
No entry names this /usage-credits message shown to Team and Enterprise members whose organization has turned off usage credit requests
No entry names this alwaysLoad: false
No entry names this gh api: a refused gh command now prints its gh api equivalent, --paginate follows every page of a repository's lists, and a nested claude no longer removes it
Probably built-in-gh-agent-proxy-now-supports-any-github-enterprise, gh-shim-refusal-message-is-now-more-explicit, built-in-gh-api-client-prompt-text-added-with-no-in-bundle -p, Agent SDK, CI, cloud); terminal, desktop app and VS Code sessions have no limit
Nothing to match on ANTHROPIC_DEFAULT_SONNET_MODEL pin that names Claude Sonnet 5.5 or Opus 5.5 and use Claude Sonnet 5 instead
Probably auto-mode-classifier-ignores-anthropic-default-sonnet-model claude project purge to claude purge; the old name still works and prints a notice
Probably claude-project-purge-moved-to-top-level-claude-purge-ol n: filter (and Ctrl+F search) so Enter opens the session whose name matches best instead of the top row
Nothing to match on /autocompact to save the auto-compact window per model, so each model keeps its own setting when you switch
Probably per-model-autocompactwindow-setting claude plugin test reporting mods as turned off remotely when it had only read an out-of-date saved setting
No entry names this A model matched these bullets to the GitHub issues they fix, so a link can be wrong.
2 of 27 tool descriptions changed. 1 of 25 tool schemas changed. The appended system-reminder blocks moved: 1 line added, 1 line removed.
Claude Code, interactive mode
2 prompt changes in this release could not be quoted from the build, so no entry on this page describes them.
712 documentation changes were recorded within 24 hours either side of this release, nearest first. The closest 12 are below. They're here because they happened near this release in time. That's not a claim that this release caused the edit, or that the page documents anything in it.
The 63 literal strings found in the bundle, with the number of entries that name each one. Picking one searches for it. A name is here because this build's code mentions it, which is not the same as it working or being finished.
What's wrong with this entry?