Compare commits

...

7 Commits

Author SHA1 Message Date
GitHub Actions
3b272769d0 chore: Update CHANGELOG.md and feed.xml 2026-08-04 22:39:48 +00:00
GitHub Actions
dd79613923 chore: Update CHANGELOG.md and feed.xml 2026-08-04 00:14:17 +00:00
GitHub Actions
7ef6eec9d9 chore: Update CHANGELOG.md and feed.xml 2026-07-25 01:35:47 +00:00
GitHub Actions
0c188278cd chore: Update CHANGELOG.md and feed.xml 2026-07-24 17:14:14 +00:00
GitHub Actions
2982f95155 chore: Update CHANGELOG.md and feed.xml 2026-07-22 21:24:49 +00:00
GitHub Actions
ac062f33ab chore: Update CHANGELOG.md and feed.xml 2026-07-21 21:35:04 +00:00
Roy Arsan
c4dbd740a7 Merge pull request #79898 from anthropics/royarsan/gateway-aws-example
Add Claude apps gateway on AWS example deployment assets
2026-07-21 20:39:13 +01:00
2 changed files with 337 additions and 141 deletions

View File

@@ -1,5 +1,164 @@
# Changelog
## 2.1.222
- Fixed worktree-isolated sessions and their subagents being able to run destructive git commands against the main checkout; isolation now applies to file edits and Bash in every session type
- Fixed PreToolUse auto-allow hooks bypassing tool restrictions in background agent tasks (summaries, compaction, renames)
- Fixed `/usage-credits` on Team and Enterprise showing "you've already sent a usage credit request" for members whose earlier request was dismissed, blocking them from sending a new one
- Fixed the startup connectivity check hanging and then failing behind an HTTPS proxy; it now uses the same proxy-aware transport as API requests and times out with a clear message
- Fixed "Connection closed mid-response" errors being reported on responses that had actually completed
- Fixed `/usage` overattributing usage to MCP servers: a server's share now reflects only the requests that actually consumed its tool results, instead of every turn after any call to it
- Fixed sessions not linking to pull requests created after the branch was pushed, including through the GitHub REST API
- Fixed org-restricted `model: opus`-style subagent and teammate family aliases dropping to the parent model instead of stepping down to the newest org-allowed model in the family
- Fixed stream idle timeout firing on custom `ANTHROPIC_BASE_URL` gateways despite server keep-alive pings arriving on the wire
- Fixed claude.ai connectors being falsely marked as needing authorization when the session token is invalid — they now show a `/login` hint instead
- Fixed tool errors not being displayed for tools no longer available locally, for example after an MCP server is removed
- Fixed `SendMessage` rejecting a long summary — it now truncates instead, so sends no longer fail on a character limit
- Fixed the spinner's effort label in a subagent's transcript view showing the session's effort level instead of the subagent's own `effort:` setting
- Fixed rare crashes when a file watcher hit a filesystem error or during file-watcher teardown
- Fixed screen readers re-reading the whole input line on every backspace in `--ax-screen-reader` mode — end-of-line deletions now echo just the deleted characters
- Fixed host model-selection keys not taking precedence over a stale on-disk `managed-settings.json` when `CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST` is set
- Improved auto mode safety: messages sent to other agent sessions via `SendMessage` are now evaluated by the permission classifier before dispatch
- Improved the refusal when Claude tries to invoke a skill with `disable-model-invocation`: Claude is now told to ask you to run the skill instead of replicating its workflow
- Improved the `/diff` view, the Remote Control workspace diff, and file-edit diffs in Claude Code on the web sessions to use raw git blob content, ignoring workspace-configured diff drivers and textconv
- Changed Remote Control auto-start so repo-local settings (`.claude/settings.json` or `.claude/settings.local.json`) can no longer turn it on (they can still turn it off); enable it at user scope via `/config`
- Removed ultraplan feature
## 2.1.221
- [VSCode] Added Focus view: a chat-menu toggle that hides tool activity behind an expandable per-turn summary with a live running-tool indicator, toggled with `Ctrl+Alt+F` or the "Claude Code: Toggle Focus view" command
- Added `mode: "mask"` for sandbox credential files on Linux and WSL — sandboxed commands read a sentinel copy (the whole file, or just the spans captured by an `extract` regex) while the sandbox proxy substitutes the real value on egress; on macOS file masking falls back to `deny`
- Added warnings to `claude plugin validate` when a marketplace or plugin name would be rejected by Claude Desktop's managed marketplace sync
- Added a `prompt-audit` subcommand to the `claude-api` skill for auditing prompts and tool descriptions for patterns written for older models
- Fixed a Bash tool permission-check bypass where zsh could execute hidden commands in `[[ ]]` regex conditionals; affected commands now prompt for permission
- Fixed PowerShell permission checks mishandling paths containing quote characters on Windows; such paths now prompt for approval
- Fixed the thinking toggle having no effect for the rest of a session that started with thinking off; disabling an MCP server mid-connect no longer silently reverts
- Fixed MCP servers from `--mcp-config` not being connected before the first turn in print mode (`-p`), which made the model emit tool calls as literal text
- Fixed @-mentioned files being silently dropped when pressing Esc to retract a prompt and resubmitting it
- Fixed a crash when preparing API requests for SDK MCP tools named after built-in object properties such as `constructor`
- Fixed WebSearch failing with a 400 error at effort `xhigh`/`max` when thinking is disabled
- Fixed sandboxed large uploads failing with TLS errors through the sandbox proxy
- Fixed Team and Enterprise spend-limit message incorrectly blaming the org's monthly limit instead of your individual spend limit
- Fixed Bedrock authentication with AWS SSO named profiles failing in desktop-managed sessions on Windows machines that set a stray `HOME` environment variable
- Fixed `CLAUDE_CODE_RESUME_INTERRUPTED_TURN=0` not disabling interrupted-turn auto-resume; falsy values are now honored
- Fixed a rare wake-from-sleep race where two Claude Code processes could both refresh the same MCP connector or WIF OAuth token at once, forcing re-authentication
- Fixed renaming a session from Claude Code Desktop or claude.ai not updating the CLI's session name; session names from every rename surface are now sanitized
- Fixed plugin- and org-delivered skills named after terminal-only built-ins (e.g. `/help`, `/feedback`) being un-invocable in non-interactive sessions
- Fixed the "Plugins changed" notification lingering after plugins were reloaded instead of clearing
- Fixed Vim mode: the yank register now survives dialogs, history search, and the transcript view instead of being silently emptied
- Fixed Vim mode: undoing back to an empty prompt now arms the "press ← again" confirm before returning to the agent view
- Improved tool search on Google Vertex AI: re-enabled for Claude 4.5-generation and newer models
- Improved auto mode: permission checks for parallel tool calls are now cache-efficient, and switching modes while a check is pending reliably prompts instead of applying the stale result
- Reduced prompt-cache costs for auto-mode permission checks by reusing the cached conversation prefix across decisions
- Improved Stats panel to count cache tokens in its token totals, with a breakdown by input, output, cache read, and cache write
- Improved `/ultrareview` error messages when a repo shares no history with its base: a checkout with no branches is now refused up front with advice to create one, and refusal hints no longer suggest `git fetch --unshallow` on clones that are already complete
- Improved Windows startup: process creation times are now read via a native kernel32 call instead of spawning PowerShell, so endpoint security tools that gate `powershell.exe` no longer prompt
- Changed background sessions to commit and push to preserve work, open a draft PR only when the task calls for one, follow your CLAUDE.md git instructions, and always end by reporting where the work lives
- Changed `/plugin install` to refresh a stale marketplace catalog and retry before reporting a plugin not found
- Changed plugins installed from `/plugin` to activate immediately when safe, instead of always requiring `/reload-plugins`
- Changed plugins to accept `"."` as a `skills` path, and the root-level `SKILL.md` validation error now suggests using the plugin root
- Changed `/status` to show the session kind: `interactive`, or a background job that is `attached` or `unattended`
- Changed emoji autocomplete to accept common alternate shortcodes like `:thumbsup:`, `:thumbsdown:`, and `:love:`
- Changed sessions forked with `/fork` to create a new worktree of their own instead of working in the original session's checkout
- Changed Claude in Chrome to close the browser tabs it opens once it no longer needs them
- Changed fast mode to report on the stream when usage credits run out mid-session, instead of failing silently
- Changed Monitor: a watch that exits without producing any output now says so instead of reporting "stream ended"
- Changed the Gateway `model` field validation: non-string values are rejected with a 400 instead of being forwarded
- Removed the repeated "Permission mode changed while the auto-mode classifier call was queued" notice from approval prompts
## 2.1.220
- Bug fixes and reliability improvements
## 2.1.219
- Added Claude Opus 5 (`claude-opus-5`), now the default Opus model — 1M context, fast mode at $10/$50 per Mtok
- Added `sandbox.network.strictAllowlist` setting to deny non-allowlisted hosts for sandboxed commands without prompting
- Added `DirectoryAdded` hook that fires after `/add-dir` or the SDK `register_repo_root` control request registers a new working directory mid-session
- Added `mcp_server_errors` to the headless stream-json init event, listing `--mcp-config` entries skipped by config validation; terminal runs print a startup warning
- Added the `workflowSizeGuideline` settings key so the advisory Dynamic workflow size guideline can be set from any settings file; the `/config` row is hidden while one does
- Added nested subagent forwarding in stream-json: subagents spawned at depth-2+ now appear when `--forward-subagent-text` is set, keyed by their spawning Agent `tool_use` id
- Fixed `claude -p` text output dropping the answer already produced when a turn dies on a mid-stream API error
- Added HTTP status and error text to `claude mcp list` and `/mcp` when a server fails to connect, and a warning for MCP config values with hidden leading or trailing whitespace
- Fixed the Fable model row showing "Requires usage credits" for plans that include it, when a stale cache had baked the label in
- Fixed the `/model` picker showing the merged Opus row as plain "Opus" instead of "Opus (1M context)"
- Fixed copy-on-select inside GNU screen printing base64 into the terminal instead of copying the selection
- Fixed Remote Control clients keeping a stale fast-mode status after a model switch, reconnect, or failed org check
- Fixed `CLAUDE_CODE_GIT_BASH_PATH` on Windows exiting or being used as bash when the path isn't a bash/sh binary; it's now ignored with a warning
- Fixed Vim mode: pressing ← on an empty prompt now returns to the agent view from NORMAL mode, not just INSERT
- Fixed screen-reader mode rewriting the entire input line on every keystroke instead of echoing only the typed character
- Improved the "Remote Control is only available via api.anthropic.com" error to name the specific setting that caused it
- Improved `claude --teleport` to show which repo your current checkout points at when it doesn't match the session's repo
- Changed dynamic workflows to default to a medium size guideline (aim for fewer than 15 agents); pick another size or unrestricted with Dynamic workflow size in `/config`
- Changed managed MCP allowlist/denylist `${VAR}` entries to resolve from the startup environment and managed-settings env instead of settings-file env
- Changed the `/model` picker to highlight only the newest model's name, so the highlight marks the new release rather than an arbitrary subset of the list
- Added the current default workflow size to the running-workflow status line, with a pointer to `/config` for changing it
- Removed Opus 4.7 from fast mode; `/fast` now applies to Opus 5 and Opus 4.8
- Updated the claude-api skill to default to Claude Opus 5, with a migration path from Opus 4.8
- Subagents can now spawn nested subagents up to depth 3 by default (was 1); set CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH=1 to disable nesting
## 2.1.218
- Changed `/code-review` to run as a background subagent, so review work no longer fills your conversation and keeps stacked slash commands as its review target
- Added screen-reader announcements of deleted text for word and line deletions (`Option+Delete`, `Ctrl+W`, `Cmd+Backspace`, `Ctrl+U`, `Ctrl+K`) in `--ax-screen-reader` mode
- Fixed Windows paths with `\u`-prefixed segments (like `C:\Users\unicorn`) being corrupted into CJK characters in tool inputs, which made those files inaccessible
- Fixed the left arrow key discarding the conversation with no undo: presses right after editing now ask to confirm, and Esc in the agent view returns to the conversation it backgrounded
- Fixed multi-line paste collapsing into one line with `j` in place of newlines in terminals that encode pasted newlines as Ctrl+J
- Fixed `/context` reporting stale pre-compact token usage after compacting from the message picker
- Fixed `/ultrareview` failing on descriptive arguments like "review my auth changes" — they now run a review of your current branch with the text applied as a note to the findings
- Fixed `/code-review ultra` silently running a local review in non-interactive sessions — it now launches the cloud review
- Fixed gateway spend metering to price Bedrock application-inference-profile ARNs and other config-mapped upstream model IDs at the configured model's rates
- Fixed mojibake when a long IDE selection was truncated mid-emoji, and a case where a tool executor error could be silently dropped
- Fixed an engine teardown race that could start and abandon a phantom turn, and made input pushed after close consistently rejected
- Fixed spurious "[Request interrupted by user]" messages after interrupted tool calls, and an unpaired `tool_use` block left in the transcript when a tool aborted mid-response
- Fixed VoiceOver reading "new line" instead of echoing the typed space at the end of the input in `--ax-screen-reader` mode
- Fixed plugin and settings panels not moving the terminal cursor to the focused row, so screen readers and magnifiers can follow arrow-key navigation
- Fixed crashes (maximum call stack exceeded) when a deeply nested watched directory tree was deleted or moved, and when rendering deeply nested UI trees
- Fixed pull request events occasionally being lost when a session exited immediately after creating or linking a PR
- Fixed the Bedrock setup wizard failing profile verification for assume-role profiles in partitioned AWS regions and on proxy-only networks
- Fixed rare negative or incorrect turn duration measurements after a system clock adjustment by timing turns with a monotonic clock
- Fixed the "N MCP servers need authentication" startup notice over-counting claude.ai connectors that aren't connected in claude.ai
- Fixed prompt history entries being dropped or duplicated when history writes raced or failed
- Fixed a retry loop that re-sent identical doomed requests after a context-overflow error with a large thinking budget; `Ctrl+B` backgrounding now applies the same background-shell caps as other paths
- Fixed agent frontmatter hooks running from untrusted folders: hooks now require the agent file's own folder to have accepted workspace trust
- Fixed fork-session lineage being lost after compaction in headless and SDK sessions
- Fixed a resumed session failing every turn, or crashing on resume, when its history held a malformed delta attachment
- Improved `/ultrareview` error feedback so Claude can correct an invalid argument instead of retrying it unchanged
- Improved auto mode: the dangerous-rm, background-`&`, and suspicious-Windows-path checks no longer open permission dialogs; the auto-mode classifier adjudicates them instead
- Improved sandbox command restrictions for IDE interactions
- Improved trust dialogs to name the repository root the grant covers
- Changed `/deep-research` to start only when invoked manually; Claude no longer launches it on its own
- Changed plan mode with auto to no longer prompt for Bash commands the static analyzer can't prove read-only; the auto-mode classifier judges them instead
- Added an announcement when fast mode changes as a result of switching models via `/config model=<x>` or Remote Control
- Changed server-managed settings so benign feature and cost toggles no longer trigger the settings-approval prompt
- Changed agent markdown files to reject agent names containing `:`, which is reserved for plugin namespacing
- Changed skills with `context: fork` to run in the background by default; opt out per skill with `background: false`
- Added `yes`/`no`/`on`/`off`/`1`/`0` (case-insensitive) as accepted values for skill and plugin frontmatter booleans, alongside `true`/`false`
- Fixed remote sessions continuing to send heartbeats after their worker was replaced, which left long-lived desktop and IDE processes retrying a rejected request every few seconds forever
## 2.1.217
- Added emoji shortcode autocomplete in the prompt input: type `:heart:` to insert ❤️, or `:hea` for suggestions — disable with the `emojiCompletionEnabled` setting
- Added warnings when transcript writes are failing (e.g. disk full) or when session saving is off due to an inherited environment variable, instead of losing transcripts silently
- Fixed a memory leak where truncated MCP tool outputs kept the full untruncated result in memory for the rest of the session
- Fixed Windows auto-update failures that could leave `claude.exe` missing; failed updates now restore the preserved executable automatically
- Fixed background session isolation not canonicalizing symlinked working directories, which could let sessions escape their workspace folder
- Fixed auto-compact never triggering for Claude Opus 4.8 on Bedrock and `/compact` failing once over the limit
- Fixed corporate mTLS, TLS-verify, OAuth scope, and proxy settings being ignored in Claude Desktop sessions
- Fixed screen reader mode's startup announcement being cut off by the first prompt render, and the thinking status row re-rendering every few seconds to update elapsed time and token counts
- Fixed managed settings that set `OTEL_EXPORTER_OTLP_ENDPOINT` not governing all signals — lower-scope signal-specific overrides no longer redirect telemetry away from the managed endpoint
- Fixed `--resume`/`--continue` and `/resume` failing with a TypeError when a transcript has a malformed attachment entry
- Fixed Remote Control sessions not showing a pending permission prompt or dialog to viewers that connected after it appeared
- Fixed background shells sometimes becoming impossible to stop after a session is sent to the background (`/background` or `←`) or when the session exits on a heavily loaded machine, most visible on Windows
- Fixed a `CLAUDE.md` or `SKILL.md` paths frontmatter value with many brace groups OOM-killing or stalling the CLI at startup — brace expansion is now budget-bounded
- Fixed the transcript preview sitting flush against the input area when attaching to a starting background session; it now leaves the same one-line gap as the live layout, so the transcript no longer shifts when the session takes over
- Improved footer PR badge links to be clickable hyperlinks even when terminal support can't be detected (e.g. over ssh/tmux); set `FORCE_HYPERLINK=0` to opt out
- Changed the login-expiry warning to appear 3 days before expiry instead of 5
- Capped the frontend-design plugin suggestion tip at 3 lifetime impressions instead of repeating indefinitely
- Added a cap on concurrently-running subagents (default 20, override with `CLAUDE_CODE_MAX_CONCURRENT_SUBAGENTS`) so one message can't fan out unbounded background agents
- Changed subagents to no longer spawn nested subagents by default; set `CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH` to allow deeper nesting
- Fixed `--max-budget-usd` not stopping background subagents: once the cap is reached, new spawns are denied and running background agents are halted
## 2.1.216
- Added `sandbox.filesystem.disabled` setting to skip filesystem isolation while keeping network egress control
@@ -861,7 +1020,6 @@
## 2.1.169
- Self-hosted runner: added a `post-session` lifecycle hook that runs after the session ends and before the workspace is deleted, so you can snapshot uncommitted work or export logs; also made the child-process SIGTERM→SIGKILL window configurable (default unchanged at 5s)
- Added `--safe-mode` flag (and `CLAUDE_CODE_SAFE_MODE`) to start Claude Code with all customizations (CLAUDE.md, plugins, skills, hooks, MCP servers) disabled for troubleshooting
- Added `/cd` command to move a session to a new working directory without breaking the prompt cache mid-session
- Added a `disableBundledSkills` setting and `CLAUDE_CODE_DISABLE_BUNDLED_SKILLS` environment variable to hide bundled skills, workflows, and built-in slash commands from the model

318
feed.xml
View File

@@ -6,7 +6,184 @@
<author><name>Anthropic</name></author>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md"/>
<link rel="self" type="application/atom+xml" href="https://raw.githubusercontent.com/anthropics/claude-code/main/feed.xml"/>
<updated>2026-07-20T22:13:53Z</updated>
<updated>2026-08-04T22:39:48Z</updated>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.222</id>
<title>Claude Code v2.1.222</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.222"/>
<updated>2026-08-04T22:39:48Z</updated>
<content type="html">&lt;p&gt;• Fixed worktree-isolated sessions and their subagents being able to run destructive git commands against the main checkout; isolation now applies to file edits and Bash in every session type&lt;/p&gt;
&lt;p&gt;• Fixed PreToolUse auto-allow hooks bypassing tool restrictions in background agent tasks (summaries, compaction, renames)&lt;/p&gt;
&lt;p&gt;• Fixed /usage-credits on Team and Enterprise showing "you've already sent a usage credit request" for members whose earlier request was dismissed, blocking them from sending a new one&lt;/p&gt;
&lt;p&gt;• Fixed the startup connectivity check hanging and then failing behind an HTTPS proxy; it now uses the same proxy-aware transport as API requests and times out with a clear message&lt;/p&gt;
&lt;p&gt;• Fixed "Connection closed mid-response" errors being reported on responses that had actually completed&lt;/p&gt;
&lt;p&gt;• Fixed /usage overattributing usage to MCP servers: a server's share now reflects only the requests that actually consumed its tool results, instead of every turn after any call to it&lt;/p&gt;
&lt;p&gt;• Fixed sessions not linking to pull requests created after the branch was pushed, including through the GitHub REST API&lt;/p&gt;
&lt;p&gt;• Fixed org-restricted model: opus-style subagent and teammate family aliases dropping to the parent model instead of stepping down to the newest org-allowed model in the family&lt;/p&gt;
&lt;p&gt;• Fixed stream idle timeout firing on custom ANTHROPIC_BASE_URL gateways despite server keep-alive pings arriving on the wire&lt;/p&gt;
&lt;p&gt;• Fixed claude.ai connectors being falsely marked as needing authorization when the session token is invalid — they now show a /login hint instead&lt;/p&gt;
&lt;p&gt;• Fixed tool errors not being displayed for tools no longer available locally, for example after an MCP server is removed&lt;/p&gt;
&lt;p&gt;• Fixed SendMessage rejecting a long summary — it now truncates instead, so sends no longer fail on a character limit&lt;/p&gt;
&lt;p&gt;• Fixed the spinner's effort label in a subagent's transcript view showing the session's effort level instead of the subagent's own effort: setting&lt;/p&gt;
&lt;p&gt;• Fixed rare crashes when a file watcher hit a filesystem error or during file-watcher teardown&lt;/p&gt;
&lt;p&gt;• Fixed screen readers re-reading the whole input line on every backspace in --ax-screen-reader mode — end-of-line deletions now echo just the deleted characters&lt;/p&gt;
&lt;p&gt;• Fixed host model-selection keys not taking precedence over a stale on-disk managed-settings.json when CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST is set&lt;/p&gt;
&lt;p&gt;• Improved auto mode safety: messages sent to other agent sessions via SendMessage are now evaluated by the permission classifier before dispatch&lt;/p&gt;
&lt;p&gt;• Improved the refusal when Claude tries to invoke a skill with disable-model-invocation: Claude is now told to ask you to run the skill instead of replicating its workflow&lt;/p&gt;
&lt;p&gt;• Improved the /diff view, the Remote Control workspace diff, and file-edit diffs in Claude Code on the web sessions to use raw git blob content, ignoring workspace-configured diff drivers and textconv&lt;/p&gt;
&lt;p&gt;• Changed Remote Control auto-start so repo-local settings (.claude/settings.json or .claude/settings.local.json) can no longer turn it on (they can still turn it off); enable it at user scope via /config&lt;/p&gt;
&lt;p&gt;• Removed ultraplan feature&lt;/p&gt;</content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.221</id>
<title>Claude Code v2.1.221</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.221"/>
<updated>2026-08-04T00:14:17Z</updated>
<content type="html">&lt;p&gt;• [VSCode] Added Focus view: a chat-menu toggle that hides tool activity behind an expandable per-turn summary with a live running-tool indicator, toggled with Ctrl+Alt+F or the "Claude Code: Toggle Focus view" command&lt;/p&gt;
&lt;p&gt;• Added mode: "mask" for sandbox credential files on Linux and WSL — sandboxed commands read a sentinel copy (the whole file, or just the spans captured by an extract regex) while the sandbox proxy substitutes the real value on egress; on macOS file masking falls back to deny&lt;/p&gt;
&lt;p&gt;• Added warnings to claude plugin validate when a marketplace or plugin name would be rejected by Claude Desktop's managed marketplace sync&lt;/p&gt;
&lt;p&gt;• Added a prompt-audit subcommand to the claude-api skill for auditing prompts and tool descriptions for patterns written for older models&lt;/p&gt;
&lt;p&gt;• Fixed a Bash tool permission-check bypass where zsh could execute hidden commands in [[ ]] regex conditionals; affected commands now prompt for permission&lt;/p&gt;
&lt;p&gt;• Fixed PowerShell permission checks mishandling paths containing quote characters on Windows; such paths now prompt for approval&lt;/p&gt;
&lt;p&gt;• Fixed the thinking toggle having no effect for the rest of a session that started with thinking off; disabling an MCP server mid-connect no longer silently reverts&lt;/p&gt;
&lt;p&gt;• Fixed MCP servers from --mcp-config not being connected before the first turn in print mode (-p), which made the model emit tool calls as literal text&lt;/p&gt;
&lt;p&gt;• Fixed @-mentioned files being silently dropped when pressing Esc to retract a prompt and resubmitting it&lt;/p&gt;
&lt;p&gt;• Fixed a crash when preparing API requests for SDK MCP tools named after built-in object properties such as constructor&lt;/p&gt;
&lt;p&gt;• Fixed WebSearch failing with a 400 error at effort xhigh/max when thinking is disabled&lt;/p&gt;
&lt;p&gt;• Fixed sandboxed large uploads failing with TLS errors through the sandbox proxy&lt;/p&gt;
&lt;p&gt;• Fixed Team and Enterprise spend-limit message incorrectly blaming the org's monthly limit instead of your individual spend limit&lt;/p&gt;
&lt;p&gt;• Fixed Bedrock authentication with AWS SSO named profiles failing in desktop-managed sessions on Windows machines that set a stray HOME environment variable&lt;/p&gt;
&lt;p&gt;• Fixed CLAUDE_CODE_RESUME_INTERRUPTED_TURN=0 not disabling interrupted-turn auto-resume; falsy values are now honored&lt;/p&gt;
&lt;p&gt;• Fixed a rare wake-from-sleep race where two Claude Code processes could both refresh the same MCP connector or WIF OAuth token at once, forcing re-authentication&lt;/p&gt;
&lt;p&gt;• Fixed renaming a session from Claude Code Desktop or claude.ai not updating the CLI's session name; session names from every rename surface are now sanitized&lt;/p&gt;
&lt;p&gt;• Fixed plugin- and org-delivered skills named after terminal-only built-ins (e.g. /help, /feedback) being un-invocable in non-interactive sessions&lt;/p&gt;
&lt;p&gt;• Fixed the "Plugins changed" notification lingering after plugins were reloaded instead of clearing&lt;/p&gt;
&lt;p&gt;• Fixed Vim mode: the yank register now survives dialogs, history search, and the transcript view instead of being silently emptied&lt;/p&gt;
&lt;p&gt;• Fixed Vim mode: undoing back to an empty prompt now arms the "press ← again" confirm before returning to the agent view&lt;/p&gt;
&lt;p&gt;• Improved tool search on Google Vertex AI: re-enabled for Claude 4.5-generation and newer models&lt;/p&gt;
&lt;p&gt;• Improved auto mode: permission checks for parallel tool calls are now cache-efficient, and switching modes while a check is pending reliably prompts instead of applying the stale result&lt;/p&gt;
&lt;p&gt;• Reduced prompt-cache costs for auto-mode permission checks by reusing the cached conversation prefix across decisions&lt;/p&gt;
&lt;p&gt;• Improved Stats panel to count cache tokens in its token totals, with a breakdown by input, output, cache read, and cache write&lt;/p&gt;
&lt;p&gt;• Improved /ultrareview error messages when a repo shares no history with its base: a checkout with no branches is now refused up front with advice to create one, and refusal hints no longer suggest git fetch --unshallow on clones that are already complete&lt;/p&gt;
&lt;p&gt;• Improved Windows startup: process creation times are now read via a native kernel32 call instead of spawning PowerShell, so endpoint security tools that gate powershell.exe no longer prompt&lt;/p&gt;
&lt;p&gt;• Changed background sessions to commit and push to preserve work, open a draft PR only when the task calls for one, follow your CLAUDE.md git instructions, and always end by reporting where the work lives&lt;/p&gt;
&lt;p&gt;• Changed /plugin install to refresh a stale marketplace catalog and retry before reporting a plugin not found&lt;/p&gt;
&lt;p&gt;• Changed plugins installed from /plugin to activate immediately when safe, instead of always requiring /reload-plugins&lt;/p&gt;
&lt;p&gt;• Changed plugins to accept "." as a skills path, and the root-level SKILL.md validation error now suggests using the plugin root&lt;/p&gt;
&lt;p&gt;• Changed /status to show the session kind: interactive, or a background job that is attached or unattended&lt;/p&gt;
&lt;p&gt;• Changed emoji autocomplete to accept common alternate shortcodes like :thumbsup:, :thumbsdown:, and :love:&lt;/p&gt;
&lt;p&gt;• Changed sessions forked with /fork to create a new worktree of their own instead of working in the original session's checkout&lt;/p&gt;
&lt;p&gt;• Changed Claude in Chrome to close the browser tabs it opens once it no longer needs them&lt;/p&gt;
&lt;p&gt;• Changed fast mode to report on the stream when usage credits run out mid-session, instead of failing silently&lt;/p&gt;
&lt;p&gt;• Changed Monitor: a watch that exits without producing any output now says so instead of reporting "stream ended"&lt;/p&gt;
&lt;p&gt;• Changed the Gateway model field validation: non-string values are rejected with a 400 instead of being forwarded&lt;/p&gt;
&lt;p&gt;• Removed the repeated "Permission mode changed while the auto-mode classifier call was queued" notice from approval prompts&lt;/p&gt;</content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.220</id>
<title>Claude Code v2.1.220</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.220"/>
<updated>2026-07-25T01:35:47Z</updated>
<content type="html">&lt;p&gt;• Bug fixes and reliability improvements&lt;/p&gt;</content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.219</id>
<title>Claude Code v2.1.219</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.219"/>
<updated>2026-07-24T17:14:14Z</updated>
<content type="html">&lt;p&gt;• Added Claude Opus 5 (claude-opus-5), now the default Opus model — 1M context, fast mode at $10/$50 per Mtok&lt;/p&gt;
&lt;p&gt;• Added sandbox.network.strictAllowlist setting to deny non-allowlisted hosts for sandboxed commands without prompting&lt;/p&gt;
&lt;p&gt;• Added DirectoryAdded hook that fires after /add-dir or the SDK register_repo_root control request registers a new working directory mid-session&lt;/p&gt;
&lt;p&gt;• Added mcp_server_errors to the headless stream-json init event, listing --mcp-config entries skipped by config validation; terminal runs print a startup warning&lt;/p&gt;
&lt;p&gt;• Added the workflowSizeGuideline settings key so the advisory Dynamic workflow size guideline can be set from any settings file; the /config row is hidden while one does&lt;/p&gt;
&lt;p&gt;• Added nested subagent forwarding in stream-json: subagents spawned at depth-2+ now appear when --forward-subagent-text is set, keyed by their spawning Agent tool_use id&lt;/p&gt;
&lt;p&gt;• Fixed claude -p text output dropping the answer already produced when a turn dies on a mid-stream API error&lt;/p&gt;
&lt;p&gt;• Added HTTP status and error text to claude mcp list and /mcp when a server fails to connect, and a warning for MCP config values with hidden leading or trailing whitespace&lt;/p&gt;
&lt;p&gt;• Fixed the Fable model row showing "Requires usage credits" for plans that include it, when a stale cache had baked the label in&lt;/p&gt;
&lt;p&gt;• Fixed the /model picker showing the merged Opus row as plain "Opus" instead of "Opus (1M context)"&lt;/p&gt;
&lt;p&gt;• Fixed copy-on-select inside GNU screen printing base64 into the terminal instead of copying the selection&lt;/p&gt;
&lt;p&gt;• Fixed Remote Control clients keeping a stale fast-mode status after a model switch, reconnect, or failed org check&lt;/p&gt;
&lt;p&gt;• Fixed CLAUDE_CODE_GIT_BASH_PATH on Windows exiting or being used as bash when the path isn't a bash/sh binary; it's now ignored with a warning&lt;/p&gt;
&lt;p&gt;• Fixed Vim mode: pressing ← on an empty prompt now returns to the agent view from NORMAL mode, not just INSERT&lt;/p&gt;
&lt;p&gt;• Fixed screen-reader mode rewriting the entire input line on every keystroke instead of echoing only the typed character&lt;/p&gt;
&lt;p&gt;• Improved the "Remote Control is only available via api.anthropic.com" error to name the specific setting that caused it&lt;/p&gt;
&lt;p&gt;• Improved claude --teleport to show which repo your current checkout points at when it doesn't match the session's repo&lt;/p&gt;
&lt;p&gt;• Changed dynamic workflows to default to a medium size guideline (aim for fewer than 15 agents); pick another size or unrestricted with Dynamic workflow size in /config&lt;/p&gt;
&lt;p&gt;• Changed managed MCP allowlist/denylist ${VAR} entries to resolve from the startup environment and managed-settings env instead of settings-file env&lt;/p&gt;
&lt;p&gt;• Changed the /model picker to highlight only the newest model's name, so the highlight marks the new release rather than an arbitrary subset of the list&lt;/p&gt;
&lt;p&gt;• Added the current default workflow size to the running-workflow status line, with a pointer to /config for changing it&lt;/p&gt;
&lt;p&gt;• Removed Opus 4.7 from fast mode; /fast now applies to Opus 5 and Opus 4.8&lt;/p&gt;
&lt;p&gt;• Updated the claude-api skill to default to Claude Opus 5, with a migration path from Opus 4.8&lt;/p&gt;
&lt;p&gt;• Subagents can now spawn nested subagents up to depth 3 by default (was 1); set CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH=1 to disable nesting&lt;/p&gt;</content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.218</id>
<title>Claude Code v2.1.218</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.218"/>
<updated>2026-07-22T21:24:49Z</updated>
<content type="html">&lt;p&gt;• Changed /code-review to run as a background subagent, so review work no longer fills your conversation and keeps stacked slash commands as its review target&lt;/p&gt;
&lt;p&gt;• Added screen-reader announcements of deleted text for word and line deletions (Option+Delete, Ctrl+W, Cmd+Backspace, Ctrl+U, Ctrl+K) in --ax-screen-reader mode&lt;/p&gt;
&lt;p&gt;• Fixed Windows paths with \u-prefixed segments (like C:\Users\unicorn) being corrupted into CJK characters in tool inputs, which made those files inaccessible&lt;/p&gt;
&lt;p&gt;• Fixed the left arrow key discarding the conversation with no undo: presses right after editing now ask to confirm, and Esc in the agent view returns to the conversation it backgrounded&lt;/p&gt;
&lt;p&gt;• Fixed multi-line paste collapsing into one line with j in place of newlines in terminals that encode pasted newlines as Ctrl+J&lt;/p&gt;
&lt;p&gt;• Fixed /context reporting stale pre-compact token usage after compacting from the message picker&lt;/p&gt;
&lt;p&gt;• Fixed /ultrareview failing on descriptive arguments like "review my auth changes" — they now run a review of your current branch with the text applied as a note to the findings&lt;/p&gt;
&lt;p&gt;• Fixed /code-review ultra silently running a local review in non-interactive sessions — it now launches the cloud review&lt;/p&gt;
&lt;p&gt;• Fixed gateway spend metering to price Bedrock application-inference-profile ARNs and other config-mapped upstream model IDs at the configured model's rates&lt;/p&gt;
&lt;p&gt;• Fixed mojibake when a long IDE selection was truncated mid-emoji, and a case where a tool executor error could be silently dropped&lt;/p&gt;
&lt;p&gt;• Fixed an engine teardown race that could start and abandon a phantom turn, and made input pushed after close consistently rejected&lt;/p&gt;
&lt;p&gt;• Fixed spurious "[Request interrupted by user]" messages after interrupted tool calls, and an unpaired tool_use block left in the transcript when a tool aborted mid-response&lt;/p&gt;
&lt;p&gt;• Fixed VoiceOver reading "new line" instead of echoing the typed space at the end of the input in --ax-screen-reader mode&lt;/p&gt;
&lt;p&gt;• Fixed plugin and settings panels not moving the terminal cursor to the focused row, so screen readers and magnifiers can follow arrow-key navigation&lt;/p&gt;
&lt;p&gt;• Fixed crashes (maximum call stack exceeded) when a deeply nested watched directory tree was deleted or moved, and when rendering deeply nested UI trees&lt;/p&gt;
&lt;p&gt;• Fixed pull request events occasionally being lost when a session exited immediately after creating or linking a PR&lt;/p&gt;
&lt;p&gt;• Fixed the Bedrock setup wizard failing profile verification for assume-role profiles in partitioned AWS regions and on proxy-only networks&lt;/p&gt;
&lt;p&gt;• Fixed rare negative or incorrect turn duration measurements after a system clock adjustment by timing turns with a monotonic clock&lt;/p&gt;
&lt;p&gt;• Fixed the "N MCP servers need authentication" startup notice over-counting claude.ai connectors that aren't connected in claude.ai&lt;/p&gt;
&lt;p&gt;• Fixed prompt history entries being dropped or duplicated when history writes raced or failed&lt;/p&gt;
&lt;p&gt;• Fixed a retry loop that re-sent identical doomed requests after a context-overflow error with a large thinking budget; Ctrl+B backgrounding now applies the same background-shell caps as other paths&lt;/p&gt;
&lt;p&gt;• Fixed agent frontmatter hooks running from untrusted folders: hooks now require the agent file's own folder to have accepted workspace trust&lt;/p&gt;
&lt;p&gt;• Fixed fork-session lineage being lost after compaction in headless and SDK sessions&lt;/p&gt;
&lt;p&gt;• Fixed a resumed session failing every turn, or crashing on resume, when its history held a malformed delta attachment&lt;/p&gt;
&lt;p&gt;• Improved /ultrareview error feedback so Claude can correct an invalid argument instead of retrying it unchanged&lt;/p&gt;
&lt;p&gt;• Improved auto mode: the dangerous-rm, background-&amp;amp;, and suspicious-Windows-path checks no longer open permission dialogs; the auto-mode classifier adjudicates them instead&lt;/p&gt;
&lt;p&gt;• Improved sandbox command restrictions for IDE interactions&lt;/p&gt;
&lt;p&gt;• Improved trust dialogs to name the repository root the grant covers&lt;/p&gt;
&lt;p&gt;• Changed /deep-research to start only when invoked manually; Claude no longer launches it on its own&lt;/p&gt;
&lt;p&gt;• Changed plan mode with auto to no longer prompt for Bash commands the static analyzer can't prove read-only; the auto-mode classifier judges them instead&lt;/p&gt;
&lt;p&gt;• Added an announcement when fast mode changes as a result of switching models via /config model=&amp;lt;x&amp;gt; or Remote Control&lt;/p&gt;
&lt;p&gt;• Changed server-managed settings so benign feature and cost toggles no longer trigger the settings-approval prompt&lt;/p&gt;
&lt;p&gt;• Changed agent markdown files to reject agent names containing :, which is reserved for plugin namespacing&lt;/p&gt;
&lt;p&gt;• Changed skills with context: fork to run in the background by default; opt out per skill with background: false&lt;/p&gt;
&lt;p&gt;• Added yes/no/on/off/1/0 (case-insensitive) as accepted values for skill and plugin frontmatter booleans, alongside true/false&lt;/p&gt;
&lt;p&gt;• Fixed remote sessions continuing to send heartbeats after their worker was replaced, which left long-lived desktop and IDE processes retrying a rejected request every few seconds forever&lt;/p&gt;</content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.217</id>
<title>Claude Code v2.1.217</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.217"/>
<updated>2026-07-21T21:35:04Z</updated>
<content type="html">&lt;p&gt;• Added emoji shortcode autocomplete in the prompt input: type :heart: to insert ❤️, or :hea for suggestions — disable with the emojiCompletionEnabled setting&lt;/p&gt;
&lt;p&gt;• Added warnings when transcript writes are failing (e.g. disk full) or when session saving is off due to an inherited environment variable, instead of losing transcripts silently&lt;/p&gt;
&lt;p&gt;• Fixed a memory leak where truncated MCP tool outputs kept the full untruncated result in memory for the rest of the session&lt;/p&gt;
&lt;p&gt;• Fixed Windows auto-update failures that could leave claude.exe missing; failed updates now restore the preserved executable automatically&lt;/p&gt;
&lt;p&gt;• Fixed background session isolation not canonicalizing symlinked working directories, which could let sessions escape their workspace folder&lt;/p&gt;
&lt;p&gt;• Fixed auto-compact never triggering for Claude Opus 4.8 on Bedrock and /compact failing once over the limit&lt;/p&gt;
&lt;p&gt;• Fixed corporate mTLS, TLS-verify, OAuth scope, and proxy settings being ignored in Claude Desktop sessions&lt;/p&gt;
&lt;p&gt;• Fixed screen reader mode's startup announcement being cut off by the first prompt render, and the thinking status row re-rendering every few seconds to update elapsed time and token counts&lt;/p&gt;
&lt;p&gt;• Fixed managed settings that set OTEL_EXPORTER_OTLP_ENDPOINT not governing all signals — lower-scope signal-specific overrides no longer redirect telemetry away from the managed endpoint&lt;/p&gt;
&lt;p&gt;• Fixed --resume/--continue and /resume failing with a TypeError when a transcript has a malformed attachment entry&lt;/p&gt;
&lt;p&gt;• Fixed Remote Control sessions not showing a pending permission prompt or dialog to viewers that connected after it appeared&lt;/p&gt;
&lt;p&gt;• Fixed background shells sometimes becoming impossible to stop after a session is sent to the background (/background or ←) or when the session exits on a heavily loaded machine, most visible on Windows&lt;/p&gt;
&lt;p&gt;• Fixed a CLAUDE.md or SKILL.md paths frontmatter value with many brace groups OOM-killing or stalling the CLI at startup — brace expansion is now budget-bounded&lt;/p&gt;
&lt;p&gt;• Fixed the transcript preview sitting flush against the input area when attaching to a starting background session; it now leaves the same one-line gap as the live layout, so the transcript no longer shifts when the session takes over&lt;/p&gt;
&lt;p&gt;• Improved footer PR badge links to be clickable hyperlinks even when terminal support can't be detected (e.g. over ssh/tmux); set FORCE_HYPERLINK=0 to opt out&lt;/p&gt;
&lt;p&gt;• Changed the login-expiry warning to appear 3 days before expiry instead of 5&lt;/p&gt;
&lt;p&gt;• Capped the frontend-design plugin suggestion tip at 3 lifetime impressions instead of repeating indefinitely&lt;/p&gt;
&lt;p&gt;• Added a cap on concurrently-running subagents (default 20, override with CLAUDE_CODE_MAX_CONCURRENT_SUBAGENTS) so one message can't fan out unbounded background agents&lt;/p&gt;
&lt;p&gt;• Changed subagents to no longer spawn nested subagents by default; set CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH to allow deeper nesting&lt;/p&gt;
&lt;p&gt;• Fixed --max-budget-usd not stopping background subagents: once the cap is reached, new spawns are denied and running background agents are halted&lt;/p&gt;</content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.216</id>
<title>Claude Code v2.1.216</title>
@@ -474,143 +651,4 @@
&lt;p&gt;• Improved MCP error messages: clearer error when a server config has url but no type, suggesting "type": "http" instead of the misleading "command: expected string"&lt;/p&gt;
&lt;p&gt;• Changed /review &amp;lt;pr&amp;gt; back to a fast single-pass review; use /code-review &amp;lt;level&amp;gt; &amp;lt;pr#&amp;gt; for the multi-agent review at a chosen effort level&lt;/p&gt;</content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.201</id>
<title>Claude Code v2.1.201</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.201"/>
<updated>2026-07-03T23:50:29Z</updated>
<content type="html">&lt;p&gt;• Claude Sonnet 5 sessions no longer use the mid-conversation system role for harness reminders&lt;/p&gt;</content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.200</id>
<title>Claude Code v2.1.200</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.200"/>
<updated>2026-07-03T16:52:26Z</updated>
<content type="html">&lt;p&gt;• Changed AskUserQuestion dialogs to no longer auto-continue by default; opt into an idle timeout via /config&lt;/p&gt;
&lt;p&gt;• Changed the "default" permission mode to "Manual" across the CLI, --help, VS Code, and JetBrains; --permission-mode manual and "defaultMode": "manual" are accepted alongside default&lt;/p&gt;
&lt;p&gt;• Fixed a crash at startup when disabledMcpServers or enabledMcpServers in .claude.json is set to a non-array value&lt;/p&gt;
&lt;p&gt;• Fixed background sessions silently stopping mid-turn after sleep/wake or when reopening a stalled session&lt;/p&gt;
&lt;p&gt;• Fixed background sessions re-running a turn cancelled with Esc after a stall respawn&lt;/p&gt;
&lt;p&gt;• Fixed background agents never starting again after a crash left a stale daemon.lock whose PID the OS reused&lt;/p&gt;
&lt;p&gt;• Fixed background-agent daemon handover so a reinstalled older build can no longer take over the daemon; build recency is now judged by the version's embedded build timestamp&lt;/p&gt;
&lt;p&gt;• Fixed background-agent roster issues: transient corruption permanently disabling orphan cleanup, older binaries not preserving fields written by newer versions, and socket auth tokens being stripped during daemon restarts&lt;/p&gt;
&lt;p&gt;• Fixed subagents cut off by a rate limit before producing any text output returning an empty result instead of failing cleanly&lt;/p&gt;
&lt;p&gt;• Fixed control bytes from background-agent output reaching the terminal in the agent view&lt;/p&gt;
&lt;p&gt;• Fixed claude agents --plugin-dir &amp;lt;dir&amp;gt; not showing the plugin's agents and skills in the agent view when the flag is placed after agents&lt;/p&gt;
&lt;p&gt;• Fixed project-scoped plugins not loading correctly from git worktrees of the same repository&lt;/p&gt;
&lt;p&gt;• Fixed /mcp server list not tracking focus for screen readers and magnifiers&lt;/p&gt;
&lt;p&gt;• Fixed voice dictation showing a misleading "Voice connection failed" message when a recording captures no audio&lt;/p&gt;
&lt;p&gt;• Fixed rendering flicker under tmux 3.4+ by enabling synchronized terminal output&lt;/p&gt;
&lt;p&gt;• Improved screen-reader output: decorative glyphs are now hidden, transcript symbols read as short labels, and nested tables read as Header: value. lines&lt;/p&gt;
&lt;p&gt;• Improved the install script to explain when installation is killed by the system running out of memory&lt;/p&gt;</content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.199</id>
<title>Claude Code v2.1.199</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.199"/>
<updated>2026-07-02T23:35:12Z</updated>
<content type="html">&lt;p&gt;• Stacked slash-skill invocations like /skill-a /skill-b do XYZ now load all leading skills (up to 5), not just the first&lt;/p&gt;
&lt;p&gt;• Fixed SSL certificate errors (TLS-inspecting proxies, missing NODE_EXTRA_CA_CERTS, expired certs) burning retries before showing actionable guidance — they now fail immediately with the fix hint&lt;/p&gt;
&lt;p&gt;• Fixed streaming responses being discarded when the API emits a mid-stream overloaded/server error after partial output — the partial is now kept with an incomplete-response notice&lt;/p&gt;
&lt;p&gt;• Fixed subagents cut off by a rate limit or server error silently failing instead of returning their partial work to the parent&lt;/p&gt;
&lt;p&gt;• Fixed subagents reporting API errors (e.g. usage limit reached) as successful results — the error is now reported to the parent agent&lt;/p&gt;
&lt;p&gt;• Fixed the background-agent daemon on Linux killing itself and every running agent every ~50 seconds after an unclean shutdown left a corrupted worker record&lt;/p&gt;
&lt;p&gt;• Fixed background agents failing to cold-start over SSH on macOS with "Could not switch to audit session" (regression in 2.1.196)&lt;/p&gt;
&lt;p&gt;• Fixed claude stop being silently undone when it raced a background-agent respawn — the respawn now honors the stop&lt;/p&gt;
&lt;p&gt;• Fixed background job progress indicators stalling for minutes while the job ran long commands&lt;/p&gt;
&lt;p&gt;• Fixed background sessions on memory-starved machines showing a generic error — they now indicate low memory and suggest freeing resources&lt;/p&gt;
&lt;p&gt;• Fixed remote sessions briefly flapping between Working and Idle in the agent view when a background agent completes&lt;/p&gt;
&lt;p&gt;• Fixed idle subagents vanishing from the agent panel while other subagents were still working; surplus idle agents now collapse into an expandable summary row&lt;/p&gt;
&lt;p&gt;• Fixed typing /model or /fast while viewing a subagent silently opening the lead's model picker — a notice now explains the command applies to the lead&lt;/p&gt;
&lt;p&gt;• Fixed SessionStart, Setup, and SubagentStart hooks silently hiding stderr when exiting with code 2 — the error is now shown in the transcript&lt;/p&gt;
&lt;p&gt;• Fixed claude --dangerously-skip-permissions daemon &amp;lt;subcommand&amp;gt; being treated as a chat prompt instead of running the subcommand&lt;/p&gt;
&lt;p&gt;• Fixed SendMessage silently misrouting when a re-spawned agent reuses a previous agent's name — the tool now detects the mismatch and asks the caller to retarget&lt;/p&gt;
&lt;p&gt;• Fixed opening or resuming a session with no new messages needlessly growing the transcript file&lt;/p&gt;
&lt;p&gt;• Fixed backgrounding a session with ← or /background dropping its /color from the agent view row&lt;/p&gt;
&lt;p&gt;• Fixed resetting a corrupted config file from the startup recovery dialog destroying it unrecoverably — it now backs up the file first&lt;/p&gt;
&lt;p&gt;• Fixed Claude in Chrome repeatedly opening the reconnect page when sessions run from different builds or config directories&lt;/p&gt;
&lt;p&gt;• Fixed plan mode not prompting for state-changing browser tool calls; read-only browser_batch calls are now correctly auto-allowed&lt;/p&gt;
&lt;p&gt;• Transient server rate-limit errors (429s unrelated to your usage limit) are now retried automatically with backoff for subscribers instead of failing the turn&lt;/p&gt;
&lt;p&gt;• CLAUDE_CODE_RETRY_WATCHDOG now raises the default retry count for non-capacity transient errors to 300 and lifts the cap of 15 on CLAUDE_CODE_MAX_RETRIES&lt;/p&gt;
&lt;p&gt;• claude agents session rows now show pull-request links as bare #N without the redundant "PR" label&lt;/p&gt;</content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.198</id>
<title>Claude Code v2.1.198</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.198"/>
<updated>2026-07-01T20:45:29Z</updated>
<content type="html">&lt;p&gt;• Subagents now run in the background by default, so Claude keeps working while they run and is notified when they finish (previously a gradual rollout)&lt;/p&gt;
&lt;p&gt;• Claude in Chrome is now generally available&lt;/p&gt;
&lt;p&gt;• Added background agent notifications in claude agents — sessions that need input or finish now fire the Notification hook (agent_needs_input / agent_completed)&lt;/p&gt;
&lt;p&gt;• Added /dataviz skill for chart and dashboard design guidance with a runnable color-palette validator&lt;/p&gt;
&lt;p&gt;• Gateway: added Claude Platform on AWS (anthropicAws) as an upstream provider; model-not-found responses now advance the failover chain&lt;/p&gt;
&lt;p&gt;• Background agents launched from claude agents now commit, push, and open a draft PR when they finish code work in a worktree, instead of stopping to ask&lt;/p&gt;
&lt;p&gt;• The built-in Explore agent now inherits the main session's model (capped at opus) instead of running on haiku&lt;/p&gt;
&lt;p&gt;• Subagents and context compaction now inherit the session's extended thinking configuration, improving output quality on delegated tasks&lt;/p&gt;
&lt;p&gt;• Fixed brief network drops mid-response aborting the turn — transient errors like ECONNRESET now retry with backoff instead of failing&lt;/p&gt;
&lt;p&gt;• Fixed excessive background classifier requests when sandboxed processes repeatedly accessed the same network host&lt;/p&gt;
&lt;p&gt;• Fixed background tasks in web, desktop, and VS Code task panels getting stuck on "Running" after they finish or after resuming a session&lt;/p&gt;
&lt;p&gt;• Fixed agent teams: a teammate that dies on an API error now reports "failed" to the lead, and messaging a stuck teammate wakes it to retry immediately&lt;/p&gt;
&lt;p&gt;• Fixed the /diff panel not refreshing when you switch branches or commit outside the session&lt;/p&gt;
&lt;p&gt;• Fixed markdown tables overflowing and wrapping their right border when rendered in fullscreen mode&lt;/p&gt;
&lt;p&gt;• Fixed Claude Platform on AWS and Mantle sessions dead-ending with "Please run /login" when the STS token expires — awsAuthRefresh now runs automatically&lt;/p&gt;
&lt;p&gt;• Fixed "no route to host" for local-network hosts in macOS background agent sessions by declaring Local Network entitlements&lt;/p&gt;
&lt;p&gt;• Fixed /desktop failing with "Cannot determine working directory" after entering and exiting a worktree&lt;/p&gt;
&lt;p&gt;• Fixed background agents repeatedly showing "Reconnecting…" every ~52 seconds on macOS while the agents view was open&lt;/p&gt;
&lt;p&gt;• Fixed pressing ← inside claude attach &amp;lt;id&amp;gt; exiting to the shell instead of opening the agent view&lt;/p&gt;
&lt;p&gt;• Fixed claude --bg silently creating an unattachable session when combined with --print/-p; the conflicting flags are now rejected up front&lt;/p&gt;
&lt;p&gt;• Fixed the workflow progress view dropping the earliest agents from the list while the phase counter stayed correct in SDK and desktop-app sessions&lt;/p&gt;
&lt;p&gt;• Fixed .claude/rules/ conditional rules not loading when the target file is reached via a symlinked path&lt;/p&gt;
&lt;p&gt;• Fixed Cmd+click not opening URLs in fullscreen mode in Warp on macOS&lt;/p&gt;
&lt;p&gt;• Fixed double-click word selection in fullscreen mode to select the entire URL including the scheme&lt;/p&gt;
&lt;p&gt;• Fixed plan mode not auto-allowing read-only tool calls when a session starts in plan mode&lt;/p&gt;
&lt;p&gt;• Fixed /branch deriving its default fork name from the compaction summary instead of the first real prompt&lt;/p&gt;
&lt;p&gt;• Improved focus mode: subagents launched in a turn now appear in its activity summary, and completed background notifications fold into a single count&lt;/p&gt;
&lt;p&gt;• Improved syntax highlighting accuracy in code blocks, diffs, and file previews by upgrading to highlight.js 11&lt;/p&gt;
&lt;p&gt;• Keyboard shortcut hints now show opt/cmd instead of alt/super when connected from a Mac over SSH&lt;/p&gt;
&lt;p&gt;• Improved API retry UX: the error reason is now shown after the second attempt, and a status page link replaces the spinner tip when the API is overloaded&lt;/p&gt;
&lt;p&gt;• /login now opens the sign-in dialog from the claude agents view instead of saying it isn't available&lt;/p&gt;
&lt;p&gt;• Subagents now treat messages from the agent that launched them as normal task direction; an agent's message is still never treated as the user's approval&lt;/p&gt;
&lt;p&gt;• Removed the /agents wizard; ask Claude to create or manage subagents, or edit .claude/agents/ directly&lt;/p&gt;</content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.197</id>
<title>Claude Code v2.1.197</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.197"/>
<updated>2026-06-30T17:56:29Z</updated>
<content type="html">&lt;p&gt;• Introducing Claude Sonnet 5: now the default model in Claude Code, with a native 1M-token context window and promotional pricing of $2/$10 per Mtok through August 31. Update to version 2.1.197 for access. https://www.anthropic.com/news/claude-sonnet-5&lt;/p&gt;</content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.196</id>
<title>Claude Code v2.1.196</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.196"/>
<updated>2026-06-29T23:27:24Z</updated>
<content type="html">&lt;p&gt;• Added support for organization default models — admins set it in the org console; it shows as "Org default" (or "Role default") in /model when you haven't picked one yourself&lt;/p&gt;
&lt;p&gt;• Added readable default names for sessions at start, making them easier to identify and message&lt;/p&gt;
&lt;p&gt;• Added clickable file attachments in chat — Cmd/Ctrl-click reveals the file in Finder/Explorer&lt;/p&gt;
&lt;p&gt;• Security: claude mcp list/get no longer spawn .mcp.json servers that a repo self-approved via a committed .claude/settings.json; untrusted workspaces show ⏸ Pending approval&lt;/p&gt;
&lt;p&gt;• Fixed waking a background job permanently deleting its conversation and re-running the original prompt when the transcript probe misread a real transcript; the file is now set aside, never deleted&lt;/p&gt;
&lt;p&gt;• Fixed the rate-limit warning flickering off and rate-limit telemetry being over-counted when multiple parallel requests were in flight at the moment a usage limit was hit&lt;/p&gt;
&lt;p&gt;• Fixed duplicate recap lines after a background session's turn: a schema-rejected StructuredOutput attempt no longer renders alongside its retry&lt;/p&gt;
&lt;p&gt;• Fixed PowerShell git diff/git grep, egrep/fgrep, and quoted search patterns containing | being reported as failures when they exit 1, matching Bash behavior&lt;/p&gt;
&lt;p&gt;• Fixed multiple claude agents side panel issues: keyboard focus getting stuck when opening an agent, background jobs losing their subagent types on every open, and sessions showing incorrect status while actively running&lt;/p&gt;
&lt;p&gt;• Fixed claude agents --dangerously-skip-permissions silently falling back to auto mode instead of showing the bypass disclaimer and applying bypass mode to spawned agents&lt;/p&gt;
&lt;p&gt;• Fixed mid-turn crash recovery for Remote sessions — sessions interrupted by a server restart now auto-resume on the next worker&lt;/p&gt;
&lt;p&gt;• Fixed sessions moved with /cd reappearing in the old directory's resume list after a non-graceful exit when the old path contained special characters&lt;/p&gt;
&lt;p&gt;• Fixed claude plugin validate skipping local plugins whose source is "." and stopping after the first error class&lt;/p&gt;
&lt;p&gt;• Fixed Esc Esc at an idle prompt not opening the rewind menu (regression); use Ctrl+C or Ctrl+X Ctrl+K to stop background agents&lt;/p&gt;
&lt;p&gt;• Fixed MCP OAuth requesting the authorization server's full scopes_supported catalog when no scope is specified, causing invalid_scope failures on GitLab self-hosted and other enterprise IdPs&lt;/p&gt;
&lt;p&gt;• Fixed /context showing 0 tokens for all tool groups on Bedrock&lt;/p&gt;
&lt;p&gt;• Fixed /deep-research misreporting verifier failures as "all claims refuted" instead of unverified&lt;/p&gt;
&lt;p&gt;• Fixed plugin dependency version pins not being honored when the marketplace was added as a local folder path backed by a git repo&lt;/p&gt;
&lt;p&gt;• Fixed claude agents session status: completed rows no longer flip between "Done" and "Needs your input", stalled agents are now labeled "Needs attention", and results that mention a PR show a clickable link&lt;/p&gt;
&lt;p&gt;• Fixed voice dictation swallowing spaces and spuriously starting a recording during very fast typing when voice mode is enabled&lt;/p&gt;
&lt;p&gt;• Improved background session reliability: long-running commands and workflows now survive the session's process being stopped, restarted, or updated — including on Windows, where background shells are handed off instead of being killed&lt;/p&gt;
&lt;p&gt;• Improved background agents: workers killed by a daemon restart are now automatically resumed from where they left off the next time the agents view opens&lt;/p&gt;
&lt;p&gt;• Improved /code-review workflow: merged five cleanup finders into one, cutting token usage by roughly 25%&lt;/p&gt;
&lt;p&gt;• Reduced per-frame rendering work in the terminal UI by skipping no-op subtree walks during streaming&lt;/p&gt;
&lt;p&gt;• The streaming idle watchdog is now on by default for all providers — it aborts and retries when a response stream produces no events for 5 minutes. Set CLAUDE_ENABLE_STREAM_WATCHDOG=0 to disable.&lt;/p&gt;
&lt;p&gt;• Remote Control is now disabled when ANTHROPIC_BASE_URL points at a non-Anthropic host, matching the existing behavior under CLAUDE_CODE_USE_BEDROCK/_VERTEX/_FOUNDRY&lt;/p&gt;
&lt;p&gt;• Changed opening the agents view from a foreground session to require a single ← press instead of two, matching the behavior in background sessions&lt;/p&gt;</content>
</entry>
</feed>