You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
SandboxArea: what it touches
ImprovementsKind: in v2.1.290,
ImprovementsSection of the release
Unclear The full effect of the new path resolution steps is not clear.
What
The sandbox limits which files and folders commands may touch. You can list paths that commands may not read. Those paths can now start with ~ (your home folder) or be relative (written from the current folder), and Claude Code converts them into full paths before applying them.
The note shown when a credential-hiding rule is dropped, because a read block already covers the same file, now says the block may cover it through a symlink or a relative spelling. Before, it only mentioned symlinks.
Why
A block written as ~/something or as a relative path could otherwise fail to protect the file you meant.
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtThe full effect of the new path resolution steps is not clear.