{"version":"2.1.292","anchor":"sensitive-file-detection-extended-to-more-credential-filenam","canonical_anchor":"sensitive-file-detection-extended-to-more-credential-filenam","heading":"More credential files are recognised as sensitive","tier":"notice","area":"Permissions","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.292\/e\/sensitive-file-detection-extended-to-more-credential-filenam","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.292","markdown":"### More credential files are recognised as sensitive\n\nClaude Code's sensitive-file check now also matches files such as `deploy_key`, `.vault-token`, `.dockercfg`, `*.tfstate`, `*.kdbx` and `*.ovpn`\n\n**Unclear.** It is not clear whether matching files are blocked from reading, blocked from writing, or only flagged.\n\n**What**\n\nClaude Code checks file names to spot files that hold secrets, such as passwords or keys. That check now matches more of them, including:\n\n- `deploy_key`\n\n- `.vault-token`\n\n- `.dockercfg`\n\n- `*.tfstate`\n\n- `*.kdbx`\n\n- `*.ovpn`\n\n- service account key files, such as `application_default_credentials.json`\n\n- `ssh_host_*_key`\n\nThe check on whether a path is safe now uses a shared helper.\n\n**Why**\n\nMore of the files that commonly hold credentials are now treated as sensitive, which likely gives them extra protection.\n\n- Area: Permissions\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5\n- Scope: individual\n- Heads-up: no"}