Claude Code v2.1.292 ·
More credential files are recognised as sensitive
Claude Code's sensitive-file check now also matches files such as deploy_key, .vault-token, .dockercfg, .tfstate, .kdbx and *.ovpn
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.292,
ImprovementsSection of the release
Unclear It is not clear whether matching files are blocked from reading, blocked from writing, or only flagged.
What
Claude Code checks file names to spot files that hold secrets, such as passwords or keys. That check now matches more of them, including:
deploy_key
.vault-token
.dockercfg
*.tfstate
*.kdbx
*.ovpn
- service account key files, such as
application_default_credentials.json
ssh_host_*_key
The check on whether a path is safe now uses a shared helper.
Why
More of the files that commonly hold credentials are now treated as sensitive, which likely gives them extra protection.
How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear whether matching files are blocked from reading, blocked from writing, or only flagged.
See this entry in the whole of v2.1.292 →