mirror of
https://github.com/anthropics/claude-code.git
synced 2026-05-09 16:42:43 +00:00
Compare commits
7 Commits
devsec/pin
...
v2.1.138
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
831608a360 | ||
|
|
33a87addb4 | ||
|
|
f7ef09f496 | ||
|
|
2bd8547920 | ||
|
|
6cd790cd21 | ||
|
|
fb063cd5e0 | ||
|
|
60348c9536 |
114
CHANGELOG.md
114
CHANGELOG.md
@@ -1,5 +1,119 @@
|
||||
# Changelog
|
||||
|
||||
## 2.1.138
|
||||
|
||||
- Internal fixes
|
||||
|
||||
## 2.1.137
|
||||
|
||||
- [VSCode] Fixed extension failing to activate on Windows
|
||||
|
||||
## 2.1.136
|
||||
|
||||
- Added `CLAUDE_CODE_ENABLE_FEEDBACK_SURVEY_FOR_OTEL` to re-enable the session quality survey for enterprises capturing responses through OpenTelemetry
|
||||
- Added `settings.autoMode.hard_deny` for auto mode classifier rules that block unconditionally regardless of user intent or allow exceptions
|
||||
- Fixed MCP servers configured in `.mcp.json`, plugins, and claude.ai connectors silently disappearing after `/clear` in the VS Code extension, JetBrains plugin, and Agent SDK
|
||||
- Fixed a rare login loop where a concurrent credential write could overwrite a freshly-rotated OAuth token and force re-login
|
||||
- Fixed MCP OAuth refresh tokens being lost when multiple servers refresh concurrently — users with several remote MCP servers should no longer need daily re-authentication
|
||||
- Fixed an API error (400) when extended thinking emitted a redacted thinking block after a tool call
|
||||
- Fixed `--resume` / `--continue` not finding sessions when the project path contains underscores
|
||||
- Fixed plan mode not blocking file writes when a matching `Edit(...)` allow rule exists
|
||||
- WSL2: image paste from Windows clipboard now works via a PowerShell fallback when xclip/wl-paste cannot read image data
|
||||
- Fixed plugin `Stop`/`UserPromptSubmit` hooks failing when cache cleanup deletes a version still in use by a running session
|
||||
- Improved visual consistency across slash command dialogs: standardized footer hints, dialog spacing, and arrow-key styling, and the dialog frame now appears immediately during loading instead of popping in after
|
||||
- Fixed colors appearing at wrong positions in bash command output and markdown code blocks
|
||||
- Fixed ReasonML diffs rendering corrupted "undefined" text artifacts at word-diff boundaries
|
||||
- Fixed worktree exit dialog warning about uncommitted files in the wrong directory after worktree removal
|
||||
- Fixed `@` file picker not matching files created mid-session in small non-git directories
|
||||
- Fixed `@`-mention file picker not finding files in directories with more than 100 entries
|
||||
- Fixed failed tool calls not being click-to-expand in fullscreen mode when their output was truncated
|
||||
- Fixed Backspace and Ctrl+Backspace getting swapped after using Ctrl+G to open an external editor on terminals with persistent extended-key modes
|
||||
- Fixed `/usage` weekly reset showing time of day instead of the calendar date
|
||||
- Fixed welcome banner ellipsis causing column overflow on CJK terminals
|
||||
- Fixed `/insights` crash when session history contains tool calls with malformed input fields
|
||||
- Fixed a renderer crash when a tool's collapsibility classification changes mid-session
|
||||
- Fixed a `skills` entry in `plugin.json` hiding the plugin's default `skills/` directory, and listing a file path now shows an error instead of failing silently
|
||||
- Fixed IDE shell-integration lock files not respecting `CLAUDE_CONFIG_DIR`
|
||||
- Fixed trailing whitespace in copied terminal output during streaming
|
||||
- Fixed plugin uninstall and enable/disable not matching slugs case-insensitively
|
||||
- Fixed tool error truncation marker showing a negative count for surrogate-pair strings
|
||||
- Fixed env vars from `CLAUDE_ENV_FILE` SessionStart hooks going stale after `/resume` or `/clear`
|
||||
- Fixed `/branch` saving a multi-line session title when given a pasted multi-line name
|
||||
- Fixed a stray leading space on the second line of wrapped text at the column boundary
|
||||
- Fixed Esc not dismissing dialogs in `/install-github-app`, `/desktop`, `/resume`, and `/web-setup`
|
||||
- Fixed `/doctor` MCP schema errors not naming the missing field or showing the source file path
|
||||
- Fixed Bash permission prompts showing an internal parser diagnostic instead of a user-readable explanation
|
||||
- Fixed plugin slash commands with spaces (e.g. `/myplugin review`) not resolving to their namespaced form
|
||||
- Fixed `AskUserQuestion` discarding multi-select answers when supplied as an array
|
||||
- Fixed `/clear <name>` not labeling the cleared session for `/resume`
|
||||
- Fixed `CronList` output missing qualifiers and the scheduled prompt
|
||||
- Fixed "Jump to bottom" overlay leaving color artifacts on CJK characters in fullscreen mode
|
||||
- Fixed wide markdown tables leaving a stale bordered render in terminal scrollback while streaming
|
||||
- Fixed pasted text being silently dropped when a long prompt with a pasted-text placeholder was auto-truncated
|
||||
- Fixed `/release-notes` getting stuck on an old version after a failed changelog refresh
|
||||
- Fixed `/mcp` server list not scrolling when there are more servers than fit in the terminal
|
||||
- Fixed mid-input slash command autocomplete not working after an initial slash command
|
||||
- Fixed scrolling to bottom re-engaging auto-follow with `autoScrollEnabled: false`
|
||||
- Fixed prompt suggestions being auto-submitted by Enter on an empty input instead of requiring Tab or arrow to accept
|
||||
- Fixed keyboard shortcut hints not reflecting rebound keys from `keybindings.json`
|
||||
- Fixed `/settings` language change being reverted on Escape after confirming
|
||||
- Fixed `/terminal-setup` only appearing in autocomplete on exact name match instead of partial prefixes
|
||||
- Fixed "Chat about this" on an `AskUserQuestion` dialog erasing the question text
|
||||
- Fixed MCP tool results being invisible when the server returns content blocks
|
||||
- Improved error message when `--worktree` collides with an existing or stale worktree
|
||||
- Changed plugin marketplace removal key to `d` (matching delete elsewhere) instead of `r` which collided with retry
|
||||
|
||||
## 2.1.133
|
||||
|
||||
- Added `worktree.baseRef` setting (`fresh` | `head`) to choose whether `--worktree`, `EnterWorktree`, and agent-isolation worktrees branch from `origin/<default>` or local `HEAD`. **Note:** the default `fresh` changes `EnterWorktree`'s base back to `origin/<default>` (it has been local `HEAD` since 2.1.128) — set `worktree.baseRef: "head"` to keep unpushed commits in new worktrees
|
||||
- Added `sandbox.bwrapPath` and `sandbox.socatPath` managed settings (Linux/WSL) to specify custom bubblewrap and socat binary locations
|
||||
- Added `parentSettingsBehavior` admin-tier key (`'first-wins' | 'merge'`) to let admins opt SDK `managedSettings` (parent tier) into the policy merge
|
||||
- Hooks now receive the active effort level via the `effort.level` JSON input field and the `$CLAUDE_EFFORT` environment variable, and Bash tool commands can read `$CLAUDE_EFFORT`
|
||||
- Improved focus mode behavior
|
||||
- Improved memory usage by releasing warm-spare background workers under memory pressure
|
||||
- Fixed parallel sessions all dead-ending at 401 after a refresh-token race wiped shared credentials
|
||||
- Fixed `Edit`/`Write` allow rules scoped to a drive root (`C:\`) or POSIX `/` matching incorrectly and always prompting
|
||||
- Fixed an unhandled rejection (`ECOMPROMISED`) when a history or session-log file lock is compromised by clock skew or slow disk
|
||||
- Fixed pressing Esc during conversation compaction showing a spurious "Error compacting conversation" notification
|
||||
- Fixed `HTTP(S)_PROXY` / `NO_PROXY` / mTLS not being respected for the full MCP OAuth flow including discovery, dynamic client registration, token exchange, and token refresh
|
||||
- Fixed Read/Write/Edit being denied on mapped network drives passed via `--add-dir` / SDK `additionalDirectories`
|
||||
- Fixed Remote Control stop/interrupt from claude.ai not fully canceling the CLI session the same way local Esc does, causing queued messages to never advance after interrupting a stuck tool or prompt
|
||||
- Fixed `/effort` in one session unexpectedly changing the effort level of other concurrent sessions, and a related issue where an IDE effort change could be silently dropped
|
||||
- Fixed subagents not discovering project, user, or plugin skills via the Skill tool
|
||||
- `claude --help` now lists `--remote-control` alongside `--remote-control-session-name-prefix`
|
||||
- [VSCode] Fixed `claudeCode.claudeProcessWrapper` failing with "Unsupported platform" when the extension build doesn't bundle a Claude binary
|
||||
|
||||
## 2.1.132
|
||||
|
||||
- Added `CLAUDE_CODE_SESSION_ID` environment variable to the Bash tool subprocess environment, matching the `session_id` passed to hooks
|
||||
- Added `CLAUDE_CODE_DISABLE_ALTERNATE_SCREEN=1` env var to opt out of the fullscreen alternate-screen renderer and keep the conversation in the terminal's native scrollback
|
||||
- Added a "Pasting…" footer hint while a Ctrl+V image paste is being read from the clipboard
|
||||
- Fixed external SIGINT (e.g. IDE stop button, `kill -INT`) not running graceful shutdown — terminal modes are now restored and the `--resume` hint is printed instead of an abrupt exit
|
||||
- Fixed an uncaught exception when the terminal is closed or SSH disconnects mid-session under the native build
|
||||
- Fixed `--resume` failing with `no low surrogate in string` when a tool error truncation split an emoji; pre-corrupted sessions are sanitized on load
|
||||
- Fixed `--permission-mode` flag being ignored when resuming a plan-mode session with `-p --continue`/`--resume`, and plan mode not being re-applied after `ExitPlanMode` within the same session
|
||||
- Fixed fullscreen mode showing a blank screen after laptop sleep/wake or Ctrl+Z/`fg` until the next keystroke or stream output
|
||||
- Fixed cursor landing mid-grapheme on Ctrl+E/A/K/U/arrow keys when an Indic conjunct or ZWJ emoji wraps across lines
|
||||
- Fixed vim operators corrupting text containing decomposed (NFD) accented characters
|
||||
- Fixed pasting text starting with `/` silently swallowing the input or triggering an unknown-command reply
|
||||
- Fixed pasting dumping stray escape sequences into the prompt when focus events or mouse-tracking reports interleave with the bracketed paste
|
||||
- Fixed mouse wheel scrolling being too fast in Cursor and VS Code 1.92–1.104 due to an upstream xterm.js bug
|
||||
- Fixed scroll-wheel handling in JetBrains IDE 2025.2 terminals (spurious arrow keys, wrong-direction events, runaway acceleration)
|
||||
- Fixed `/usage` Ctrl+S hanging when copying the stats screenshot to the clipboard on Linux/X11
|
||||
- Fixed `/terminal-setup` showing a contradictory error in Windows Terminal — Shift+Enter is natively supported there
|
||||
- Fixed `/effort` picker not reflecting the `CLAUDE_CODE_EFFORT_LEVEL` env var override
|
||||
- Fixed `/status` showing the wrong default model for some users
|
||||
- Fixed slash command autocomplete popup being capped at ~3–5 visible commands instead of scaling with terminal height
|
||||
- Fixed statusline `context_window` token counts reflecting cumulative session totals instead of current context usage
|
||||
- Fixed Alt+T (thinking toggle) not working on macOS terminals without "Option as Meta" enabled (iTerm2, Terminal.app defaults)
|
||||
- Fixed dead keyboard input on Windows after re-opening a background session from `claude agents`
|
||||
- Fixed unbounded memory growth (10GB+ RSS) when a stdio MCP server writes non-protocol data to stdout
|
||||
- Fixed MCP servers that connect but fail `tools/list` silently showing 0 tools — they now retry once and show "connected · tools fetch failed" in `/mcp`
|
||||
- Fixed unauthorized claude.ai MCP connectors showing as "failed" instead of "needs auth", and headless `-p` mode retrying non-transient 4xx connection failures
|
||||
- Improved visual consistency in slash command dialogs and `/login`, `/upgrade`, `/extra-usage` dialog spacing
|
||||
- Updated the `/tui fullscreen` startup banner to describe additional renderer benefits (lower memory usage, mouse support, auto-copy on select)
|
||||
- Fixed Bedrock and Vertex 400 errors when `ENABLE_PROMPT_CACHING_1H` is set
|
||||
|
||||
## 2.1.131
|
||||
|
||||
- Fixed VS Code extension failing to activate on Windows due to a hardcoded build path in the bundled SDK (`createRequire` polyfill bug)
|
||||
|
||||
@@ -5,8 +5,8 @@ Thank you for helping us keep Claude Code secure!
|
||||
|
||||
The security of our systems and user data is Anthropic's top priority. We appreciate the work of security researchers acting in good faith in identifying and reporting potential vulnerabilities.
|
||||
|
||||
Our security program is managed on HackerOne and we ask that any validated vulnerability in this functionality be reported through their [submission form](https://hackerone.com/anthropic-vdp/reports/new?type=team&report_type=vulnerability).
|
||||
Our security program is managed on HackerOne and we ask that any validated vulnerability in this functionality be reported through their [submission form](https://hackerone.com/4f1f16ba-10d3-4d09-9ecc-c721aad90f24/embedded_submissions/new).
|
||||
|
||||
## Vulnerability Disclosure Program
|
||||
## Anthropic Bug Bounty
|
||||
|
||||
Our Vulnerability Program Guidelines are defined on our [HackerOne program page](https://hackerone.com/anthropic-vdp).
|
||||
Our Bug Bounty Program Guidelines are defined on our [HackerOne program page](https://hackerone.com/anthropic).
|
||||
|
||||
Reference in New Issue
Block a user