Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.290 ·

A process Claude Code starts now has npm install scripts turned off differently

Claude Code builds an environment with npm_config_ignore_scripts set to true for a process it starts, now in a changed way

Under the hood Internal Changes
JSON All of v2.1.290
Under the hoodTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PluginsArea: what it touches
Internal ChangesKind: in v2.1.290,
Internal ChangesSection of the release

Unclear Which process is started this way is not known.

What

When Claude Code starts a certain process, it gives it an environment with npm_config_ignore_scripts set to true. That tells npm, the JavaScript package tool, not to run the scripts packages carry for install and other steps. The way this environment is put together has changed: it is built from a base set of variables plus this one, and in some cases it is not merged with the rest of Claude Code's own environment.

Why

Blocking package scripts is a safety step, because install scripts can run arbitrary commands on your machine.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhich process is started this way is not known.

See this entry in the whole of v2.1.290 →

Feedback