Source Intelligence

DisclaimerUnofficial, and not affiliated with Anthropic. Nearly all of this is read straight out of what ships: npm bundles, captured prompts, published docs. Anthropic's own notes go in verbatim, marked as theirs. The rest is my reading, and every entry carries the strings behind it. If one looks wrong, vote it down and say why.

All of v2.1.40 Home All releases olderv2.1.39 v2.1.41newer
Claude Code v2.1.40

macOS Sandbox: TLS Certificate Verification

What

New setting to allow Go programs to verify TLS certificates via trustd agent.

Usage

Configure in sandbox settings:

{
  "enableWeakerNetworkIsolation": true
}
Details
  • Required for Go programs (gh, gcloud, terraform, kubectl) using MITM proxies with custom CAs
  • Enables access to com.apple.trustd.agent mach service
  • Security trade-off: Opens potential data exfiltration vector through trustd
Evidence

Trustd agent setting (search for "Enable weaker network isolation", "com.apple.trustd.agent")

Strings lifted out of the shipped bundle, so the claim above can be checked against them.

Related

Other releases about the same thing. Found by shared names or similar wording; neither means one caused the other.

See this entry in the whole of v2.1.40 →