Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.292 ·

Uploading a local file to a project now refuses secrets and risky files

Project uploads from a local path now refuse credential files, devices, Claude Code's own config, hard-linked files and files you are not allowed to read

You'll notice Improvements
JSON All of v2.1.292
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
ProjectsArea: what it touches
ImprovementsKind: in v2.1.292,
ImprovementsSection of the release
What

The project write tool can upload a file from your computer into a project when it is given a local path. Before, it only checked that the file sat inside the working directory and was not a symbolic link, which is a shortcut pointing at another file. It now also refuses:

  • Credential files.
  • Devices, meaning special system files that stand for hardware rather than ordinary files.
  • Files inside Claude Code's own config and token folders.
  • Files that your read permission rules do not allow.
  • Files with a hard link, meaning the same file also exists under a second name. Claude is told to pass the file's text directly instead.
  • Paths that are too long.

The check against open-file entries under /proc now compares exactly against the real resolved path.

Why

These checks make it much harder for a project upload to carry passwords, tokens or other private files off your machine, whether by accident or because a file's name hides what it really is.

See this entry in the whole of v2.1.292 →

Feedback