Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.290 ·

--safe-mode is now checked the same way as --restricted

The --safe-mode flag now goes through the same check as --restricted and --strict-mcp-config, run when it is needed

You'll notice Improvements
JSON All of v2.1.290
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
3Signal: worth watching, 1 to 5
StartupArea: what it touches
ImprovementsKind: in v2.1.290,
ImprovementsSection of the release

Unclear What difference the new check makes in practice is not known.

What

A flag is an option you add when starting claude. Claude Code now checks the --safe-mode flag with the same routine it already uses for --restricted and --strict-mcp-config. The check now runs when it is needed rather than once up front.

Why

This could change how --safe-mode is handled in some situations.

Read from
Since it was published

The entry above is what we published on the day. These lines were added later, as Anthropic's own pages caught up, and they sit beside the original rather than replacing it.

Confirmed since Anthropic's documentation has since written up --safe-mode, on Debug your configuration. Start with [`claude --safe-mode`](/docs/en/cli-reference#cli-flags), which launches a session with your customizations disabled, including: debug-your-config see the edit
Confirmed since Anthropic's documentation has since written up --restricted, on Claude Code changelog. * Fixed `--tools` and `--restricted` not applying to built-in tools that register after launch, and deprecated tool names reaching tools outside the caller's tool set changelog see the edit
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhat difference the new check makes in practice is not known.
Anthropic's documentation agreesAnthropic's documentation has since written up --restricted, on Claude Code changelog.
Anthropic's release notes agreeFixed an @-mention under the read block or --restricted being able to read a file outside the working directories through a link changed…

See this entry in the whole of v2.1.290 →

Feedback