{"version":"2.1.290","anchor":"sandbox-git-dir-write-protection-distinguishes-remoteuntrus","canonical_anchor":"sandbox-git-dir-write-protection-distinguishes-remoteuntrus","heading":"The sandbox can withhold git folder access for remote working folders","tier":"notice","area":"Sandbox","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290\/e\/sandbox-git-dir-write-protection-distinguishes-remoteuntrus","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.290","markdown":"### The sandbox can withhold git folder access for remote working folders\n\nSandbox setup now works out the git folder for your working folder and can withhold write access to it when that folder is remote\n\n**Unclear.** The exact condition under which the git folder access is withheld is not clear.\n\n**What**\n\nThe sandbox limits which files commands run by Claude Code may change. Its setup now:\n\n- works out the git folder for the current working folder\n\n- notes which cleanup paths for bare git repositories were vouched for on your own machine\n\n- can withhold write access to the git folder when the working folder is remote, and records when that happens\n\n- postpones one Linux-only step in some cases\n\nBefore, the sandbox always granted write access to the working folder's git folder and treated all cleanup paths the same way.\n\n**Why**\n\nThis tightens what a sandboxed command may write in remote sessions.\n\n- Area: Sandbox\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 2\/5\n- Scope: individual\n- Heads-up: no"}