{"version":"2.1.290","anchor":"git-worktree-guard-handles-runtime-expanded-words","canonical_anchor":"git-worktree-guard-handles-runtime-expanded-words","heading":"Git commands with shell-filled words are blocked in worktree sessions","tier":"notice","area":"Worktrees","scope":"individual","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/git-worktree-guard-handles-runtime-expanded-words","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### Git commands with shell-filled words are blocked in worktree sessions\n\nIn worktree sessions, git commands are now refused if a word the shell fills in at run time comes before git's subcommand\n\n**What**\n\nA git worktree is a separate working copy of a repository. Claude Code has a guard that stops git commands in a worktree session from acting on the main shared checkout. That guard now also refuses a git command when a word at or before the git subcommand (such as `commit` or `checkout`) is something the shell only fills in when the command runs, such as a variable.\n\n**Why**\n\nA word like that could hide what the command really does until it runs. Git is now blocked more strictly in worktree sessions, so a command you expect to work may be refused if it is written this way.\n\n- Area: Worktrees\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5\n- Scope: individual\n- Heads-up: yes"}