{"version":"2.1.295","anchor":"credential-file-path-check-factored-out-and-extended-to-a-rh","canonical_anchor":"credential-file-path-check-factored-out-and-extended-to-a-rh","heading":"Sensitive-file check covers git, GitHub CLI and gcloud credential files","tier":"notice","area":"Permissions","scope":"individual","heads_up":false,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.295\/e\/credential-file-path-check-factored-out-and-extended-to-a-rh","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.295","markdown":"### Sensitive-file check covers git, GitHub CLI and gcloud credential files\n\nClaude Code's check for sensitive file paths now lists stored credential files for git, the GitHub CLI and gcloud\n\n**Unclear.** It is not clear which mode the credential-file check applies in, or whether the list existed before this release.\n\n**What**\n\nClaude Code checks file paths to spot sensitive files. That check now includes a list of files where command-line tools keep saved logins:\n\n- git's stored credentials\n\n- `hosts.yml` for the GitHub CLI (`gh`)\n\n- `credentials.db` and `access_tokens.db` for gcloud\n\nThis list applies only in a particular mode. Path segments that are unusually long are flagged in the same way.\n\n**Why**\n\nThese files hold login details for other services, so the check can make Claude Code stop or ask you before reading them.\n\n- Area: Permissions\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5\n- Scope: individual\n- Heads-up: no"}