Follow Discord
Sweep 03 Oct 2026 · 20:28Z Build v2.1.289 510 read Stable v2.1.285 Latest v2.1.289 Next v2.1.289 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.289 ·

find -rm is no longer auto-approved as a read-only command

Claude Code now treats find ... -rm like find ... -delete: it is not auto-allowed as read-only and is flagged as destructive

Group of 4 You'll notice Improvements
JSON All of v2.1.289
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.289,
ImprovementsSection of the release

What

Claude Code automatically allows some shell commands without asking you first, because they only read files. A find command (which searches for files) was on that list unless it used an action such as -delete or -exec. The -rm action has now been added to the blocked actions.

  • Read-only check: the auto-allow pattern for find and the set of blocked find actions both now include -rm. The pattern now reads -delete\b|-rm\b|-exec\b|-execdir\b|-ok\b|-okdir\b|-fprint0?\b|-fls\b|-fprintf\b|-files0-from\b, so a find using -rm is no longer treated as safe.
  • Spacing: the pattern now accepts only spaces and tabs between arguments ([ \t]+ instead of \s), so a line break can no longer separate find arguments.
  • Destructive-command list: the pattern that marks commands as destructive used to match only find ... -delete. It now matches find ... -rm too, so those commands get the same handling as -delete.
  • Remote switch: the -rm check sits behind a small helper, called from the bash read-only check and from one other place. It treats -rm as blocked unless the remote flag tengu_warm_sunrise has been explicitly set to false by a server. Nothing has been read about the state of this flag.

Why

Before, a find ... -rm command could match the read-only pattern and run without a permission prompt. It now goes through the normal permission check, and a server-side flag exists that could undo this.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhether the change to argument separators also depends on the remote flag is not clear.

See this entry in the whole of v2.1.289 →

Feedback