{"version":"2.1.296","anchor":"sandbox-option-settings-merge","canonical_anchor":"sandbox-option-settings-merge","heading":"The sandbox option now merges with your settings instead of replacing them","tier":"notice","area":"Sandbox","scope":"individual","heads_up":true,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.296\/e\/sandbox-option-settings-merge","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.296","markdown":"### The sandbox option now merges with your settings instead of replacing them\n\nSandbox options passed in now merge with your sandbox settings, deny lists add up, and failIfUnavailable defaults to true\n\n**What**\n\nThe sandbox is the restricted space Claude Code runs commands in. When a sandbox option is passed to Claude Code, it is now merged into the sandbox settings rather than handled separately:\n\n- `filesystem.denyRead`, `filesystem.denyWrite`, `network.deniedDomains`, `credentials.files` and `credentials.envVars` are added together instead of one list replacing the other.\n\n- Setting `filesystem` or `network` explicitly clears an inherited `filesystem.disabled` or inherited proxy ports.\n\n- When sandboxing is turned on, `failIfUnavailable` now defaults to true.\n\n- Passing both a settings file path and the sandbox option stops with the error \"Cannot use both a settings file path and the sandbox option.\"\n\n**Why**\n\nAnyone passing the sandbox option, for example from a program built on Claude Code, now gets fail-closed behaviour by default: if the sandbox is not available, Claude Code does not carry on without it. Deny rules from different places also no longer silently cancel each other out.\n\n- Area: Sandbox\n- Tier: You'll notice\n- Useful: 2\/5\n- Signal: 1\/5\n- Scope: individual\n- Heads-up: yes"}