Follow Discord
Sweep 08 Oct 2026 · 18:53Z Build v2.1.295 516 read Stable v2.1.286 Latest v2.1.295 Next v2.1.295 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.292 ·

More credential files are recognised as sensitive

Claude Code's sensitive-file check now also matches files such as deploy_key, .vault-token, .dockercfg, .tfstate, .kdbx and *.ovpn

You'll notice Improvements
JSON All of v2.1.292
You'll noticeTier: how much it should matter to you
1Useful: my rating, 1 to 5
1Signal: worth watching, 1 to 5
PermissionsArea: what it touches
ImprovementsKind: in v2.1.292,
ImprovementsSection of the release

Unclear It is not clear whether matching files are blocked from reading, blocked from writing, or only flagged.

What

Claude Code checks file names to spot files that hold secrets, such as passwords or keys. That check now matches more of them, including:

  • deploy_key
  • .vault-token
  • .dockercfg
  • *.tfstate
  • *.kdbx
  • *.ovpn
  • service account key files, such as application_default_credentials.json
  • ssh_host_*_key

The check on whether a path is safe now uses a shared helper.

Why

More of the files that commonly hold credentials are now treated as sensitive, which likely gives them extra protection.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtIt is not clear whether matching files are blocked from reading, blocked from writing, or only flagged.

See this entry in the whole of v2.1.292 →

Feedback