{"version":"2.1.292","anchor":"project-write-local-path-now-refuses-credential-files-hard","canonical_anchor":"project-write-local-path-now-refuses-credential-files-hard","heading":"Uploading a local file to a project now refuses secrets and risky files","tier":"notice","area":"Projects","scope":"individual","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.292\/e\/project-write-local-path-now-refuses-credential-files-hard","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.292","markdown":"### Uploading a local file to a project now refuses secrets and risky files\n\nProject uploads from a local path now refuse credential files, devices, Claude Code's own config, hard-linked files and files you are not allowed to read\n\n**What**\n\nThe project write tool can upload a file from your computer into a project when it is given a local path. Before, it only checked that the file sat inside the working directory and was not a symbolic link, which is a shortcut pointing at another file. It now also refuses:\n\n- Credential files.\n\n- Devices, meaning special system files that stand for hardware rather than ordinary files.\n\n- Files inside Claude Code's own config and token folders.\n\n- Files that your read permission rules do not allow.\n\n- Files with a hard link, meaning the same file also exists under a second name. Claude is told to pass the file's text directly instead.\n\n- Paths that are too long.\n\nThe check against open-file entries under `\/proc` now compares exactly against the real resolved path.\n\n**Why**\n\nThese checks make it much harder for a project upload to carry passwords, tokens or other private files off your machine, whether by accident or because a file's name hides what it really is.\n\n- Area: Projects\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 2\/5\n- Scope: individual\n- Heads-up: yes"}