Compare commits

...

3 Commits

Author SHA1 Message Date
GitHub Actions
4d07874235 chore: Update CHANGELOG.md and feed.xml 2026-07-20 22:13:53 +00:00
GitHub Actions
015170d3fd chore: Update CHANGELOG.md and feed.xml 2026-07-19 02:55:54 +00:00
GitHub Actions
07dcb0e135 chore: Update CHANGELOG.md and feed.xml 2026-07-18 01:20:23 +00:00
2 changed files with 204 additions and 66 deletions

View File

@@ -1,5 +1,102 @@
# Changelog
## 2.1.216
- Added `sandbox.filesystem.disabled` setting to skip filesystem isolation while keeping network egress control
- Fixed a slowdown in long sessions where message normalization cost grew quadratically with the number of turns, causing multi-second stalls and slow resumes
- Fixed auto mode denying commands with "HTTP 401" classifier errors after the OAuth token expired or rotated mid-session
- Fixed AskUserQuestion telling Claude to continue even when your answer asked it to wait or explain first — free-text answers now get neutral wording
- Fixed Claude Code on the web re-asking the same question and dropping your answer after the session sat idle for a few minutes
- Fixed @-mentions silently attaching nothing after file-modifying hooks, vim dot-repeat of `c`-operators and paste, statusline running twice on resume, and resume-picker hangs on failure
- Fixed resumed background agent sessions reverting to the default agent: the agent's prompt and tool restrictions are now restored
- Fixed worktree-isolated subagents redirecting git into the shared checkout via `git -C`, `--git-dir`, or `GIT_DIR`/`GIT_WORK_TREE`
- Fixed worktree sessions landing in another project's leftover worktree when the working directory did not match the selected project
- Fixed background sessions whose worktree has no git repository being undeletable
- Fixed `claude daemon stop --any` potentially terminating an unrelated process via a stale legacy daemon lockfile
- Fixed Esc-Esc at an idle prompt not opening the rewind picker in long-running sessions with background tasks
- Fixed Bash command permission checking for compound statements with redirects inside `&&` lists or negations
- Fixed pressing Ctrl+X twice in the agent list failing to delete a session, and deleted sessions reappearing when their background worker had died
- Fixed background subagents getting cancelled when a high-priority message arrives during their startup window
- Fixed mouse and focus garbage in the terminal while a GUI editor from `/memory`, `/plan`, `/keybindings`, or Ctrl+G is open; `/memory` no longer waits for the editor to close
- Fixed Claude-in-Chrome 403-looping on reconnect when the session's OAuth token lacks a required scope
- Fixed workflow saves and scheduled-task writes following a symlink at `.claude`, which could redirect writes outside the project
- Fixed MCP re-authenticate revoking working credentials before the new sign-in succeeds, and the reconnect needs-auth message in background sessions pointing at an unusable command
- Fixed read-only commands on Windows accessing network paths without a permission prompt
- Fixed Bash command parsing of non-ASCII characters to match real shell word boundaries
- Fixed PowerShell tool permission validation of commands containing invisible Unicode characters
- Fixed dialogs in fullscreen mode stretching past the right-hand edge of their panel
- Fixed the `/config` settings list in fullscreen mode clipping its keyboard-hint footer
- Fixed the transcript-mode (Ctrl+O) footer hint wrapping on terminals narrower than 104 columns
- Fixed the Prometheus metrics endpoint (`OTEL_METRICS_EXPORTER=prometheus`) emitting invalid `# UNIT` lines
- Fixed skills and commands changed during a session not appearing in the slash menu until restart
- Fixed plugin skills with a `name` frontmatter field losing their plugin prefix in slash-command autocomplete
- Fixed telemetry misreporting permission denials: failed permission-prompt requests no longer count as user rejections, and user interrupts are now reported as user aborts instead of rejections
- Improved the `/fork` confirmation to one line with the new session's name, `claude attach` id, and a note when the copy shares your checkout
- Improved validation of `git` and `gh` command arguments in the PowerShell tool
- Improved the `/ultrareview` diff-too-large error to show configured limits, measured diff size, and largest contributing files
- Improved `/code-review ultra` empty-diff message to name the exact base ref and suggest passing an explicit base
- Improved the spend limit adjustment prompt to show the server's reason when a spend limit change is rejected
- `/context` now shows an explicit warning when the conversation exceeds the context window, and a failed `/compact` displays as an error
- `/rewind` no longer restores or deletes files through symlinks or hard links at tracked paths and reports how many paths it skipped
- Background sessions: `/mcp` and `/install-github-app` now park a "needs input" request in the agent view when no client is attached
- Updated the bundled dataviz skill: reordered the default chart palette and fixed guidance that suggested direct labels for four-series charts
- [VSCode] Fixed right-to-left text (Arabic, Hebrew, Persian) rendering in the wrong order when mixed with English or code
- Fixed cloud sessions dropping the in-flight message when the session's container restarts mid-turn — the interrupted turn now re-runs on resume instead of leaving the session unresponsive
## 2.1.215
- Claude no longer runs the `/verify` and `/code-review` skills on its own; invoke them with `/verify` or `/code-review` when you want them
## 2.1.214
- Fixed single-segment `dir/**` allow rules like `Edit(src/**)` auto-approving writes to nested `dir/` directories anywhere in the tree instead of only `<cwd>/dir`
- Fixed a permission-check bypass affecting commands run in Windows PowerShell 5.1 sessions
- Fixed Bash permission checks to fail closed on file-descriptor redirect forms that bash parses differently than the permission analyzer
- Fixed Bash permission checks misjudging very long commands — commands over 10,000 characters now always prompt instead of running automatically
- Fixed Bash permission checks treating zsh variable subscripts and modifiers in `[[ ]]` comparisons as inert text — these commands now prompt for approval
- Fixed Bash permission checks to no longer auto-approve certain `help` and `man` commands that could run unsafe options, command substitutions, or backslash paths
- Fixed permission prompts on remote sessions that could proceed before the local confirmation dialog
- Added the EndConversation tool: Claude can end sessions with highly abusive users or jailbreak attempts, as on claude.ai since 2025 — see https://www.anthropic.com/research/end-subset-conversations
- Added a periodic progress heartbeat for long-running tool calls that previously went silent
- Added an ISO `modified` timestamp to memory file frontmatter
- Added `message.uuid`, `client_request_id`, and `tool_source` attributes to OpenTelemetry log events for message-level correlation and tool provenance
- Added `CLAUDE_CODE_OTEL_CONTENT_MAX_LENGTH` to configure the 60 KB truncation limit on OpenTelemetry content attributes
- Added reasoning effort to the `subagentStatusLine` payload, so custom agent rows can render model and effort
- Added permission prompts for `docker` commands (including the Podman `docker` shim) carrying daemon-redirect flags (`--url`, `--connection`, `--identity`, and Podman's remote mode) that previously ran without one
- Fixed a crash when a GrowthBook feature evaluates to null, and a bug where a malformed flag payload could wipe the cached feature flags
- Fixed Bash tool killing the Claude session when a `pkill -f` pattern accidentally matched the CLI's own process (Linux)
- Fixed unbounded memory growth when `--settings` points at a device file or multi-GB file; oversized (>2 MiB) settings files now fail at startup with a clear error
- Fixed streaming turns failing with "Socket is closed" behind corporate proxies on Windows
- Fixed stream-json output truncation at exit for slow-reading SDK/pipeline consumers; the exit drain now scales with queued bytes instead of a flat 2s cap
- Fixed scheduled tasks refusing their own configured prompt as untrusted input — the fired prompt is now delivered as the session's assigned task
- Fixed PowerShell tool commands hanging until timeout when a child process waited on standard input (Windows)
- Fixed Python scripts under the PowerShell tool crashing with UnicodeDecodeError when reading non-UTF-8 data from standard input (Windows)
- Fixed Python scripts run via the PowerShell tool crashing with UnicodeEncodeError on non-ASCII output, and PowerShell 7 error messages containing raw ANSI escape sequences (Windows)
- Fixed the PowerShell tool reporting `where.exe`, `fc.exe`, and `diff.exe` as errors when they return a valid negative answer (Windows)
- Fixed `>` and `>>` under the PowerShell tool on Windows PowerShell 5.1 writing UTF-16LE files that other tools couldn't read as UTF-8
- Fixed a displaced background daemon deleting its successor's control socket on shutdown, which made the next client kill the healthy replacement daemon
- Fixed background sessions parked with `←` or `/background` and left idle keeping the background daemon and a worker process alive indefinitely
- Fixed completed background sessions being impossible to remove via `claude rm` or the agent view once the background service had gone idle
- Fixed background sessions dispatched from a non-git folder being impossible to delete from the agents view
- Fixed reopening a stopped background session failing to restore its saved conversation when an unreadable folder exists in the session store
- Fixed the Remote Control "session ready" push notification firing for sessions where Remote Control was not explicitly enabled
- Fixed `/install-github-app` and the `/mcp` settings menu being blocked in agent-view sessions — they're now refused only in background sessions with no terminal attached
- Fixed plugins enabled via the `--settings` CLI flag not loading (regression since v2.1.181)
- Fixed feature flags going stale in long-running sessions after the OAuth token rotates
- Fixed `/ultrareview` refusing to run in repos with no merge base — it now offers to review all tracked files
- Fixed `claude update` and `claude doctor` hanging silently, and the `/status` System diagnostics section going blank, when a shell-config path is a directory
- Fixed memory frontmatter values being silently truncated at an inline `#` when memory files are saved
- Fixed session cost and token telemetry double-counting on streams that emit multiple cumulative `message_delta` frames
- Fixed a spurious "check your network" warning that appeared while the advisor was thinking
- Fixed hooks with exit code 2 not blocking as documented when the hook's stdout JSON fails schema validation
- Fixed OTel log events emitted outside the turn's async context missing the interaction span's trace context
- Fixed MCP transient errors during prompts/resources refresh clearing the server's slash commands and resources
- Improved the `claude rc` workspace-trust error in the home directory to say trust there is never saved and to suggest running from a project directory
- Changed single-segment `dir/**` hook `if:` conditions to match only `<cwd>/dir`; write `**/dir/**` for any-depth matching. `deny`/`ask` permission rules keep their any-depth match.
- Changed `file` commands using `-m`/`--magic-file` or `-f`/`--files-from` to require permission instead of being auto-allowed as read-only
- Changed keep-alive connection pooling to disable after a stale-connection error, so retries open a fresh socket
- Changed SessionStart hooks to report source `"fork"` when a session begins as a fork instead of `"resume"`
## 2.1.212
- `/fork` now copies your conversation into a new background session (its own row in `claude agents`) while you keep working; the in-session subagent it used to launch is now `/subtask`

173
feed.xml
View File

@@ -6,7 +6,113 @@
<author><name>Anthropic</name></author>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md"/>
<link rel="self" type="application/atom+xml" href="https://raw.githubusercontent.com/anthropics/claude-code/main/feed.xml"/>
<updated>2026-07-17T00:26:21Z</updated>
<updated>2026-07-20T22:13:53Z</updated>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.216</id>
<title>Claude Code v2.1.216</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.216"/>
<updated>2026-07-20T22:13:53Z</updated>
<content type="html">&lt;p&gt;• Added sandbox.filesystem.disabled setting to skip filesystem isolation while keeping network egress control&lt;/p&gt;
&lt;p&gt;• Fixed a slowdown in long sessions where message normalization cost grew quadratically with the number of turns, causing multi-second stalls and slow resumes&lt;/p&gt;
&lt;p&gt;• Fixed auto mode denying commands with "HTTP 401" classifier errors after the OAuth token expired or rotated mid-session&lt;/p&gt;
&lt;p&gt;• Fixed AskUserQuestion telling Claude to continue even when your answer asked it to wait or explain first — free-text answers now get neutral wording&lt;/p&gt;
&lt;p&gt;• Fixed Claude Code on the web re-asking the same question and dropping your answer after the session sat idle for a few minutes&lt;/p&gt;
&lt;p&gt;• Fixed @-mentions silently attaching nothing after file-modifying hooks, vim dot-repeat of c-operators and paste, statusline running twice on resume, and resume-picker hangs on failure&lt;/p&gt;
&lt;p&gt;• Fixed resumed background agent sessions reverting to the default agent: the agent's prompt and tool restrictions are now restored&lt;/p&gt;
&lt;p&gt;• Fixed worktree-isolated subagents redirecting git into the shared checkout via git -C, --git-dir, or GIT_DIR/GIT_WORK_TREE&lt;/p&gt;
&lt;p&gt;• Fixed worktree sessions landing in another project's leftover worktree when the working directory did not match the selected project&lt;/p&gt;
&lt;p&gt;• Fixed background sessions whose worktree has no git repository being undeletable&lt;/p&gt;
&lt;p&gt;• Fixed claude daemon stop --any potentially terminating an unrelated process via a stale legacy daemon lockfile&lt;/p&gt;
&lt;p&gt;• Fixed Esc-Esc at an idle prompt not opening the rewind picker in long-running sessions with background tasks&lt;/p&gt;
&lt;p&gt;• Fixed Bash command permission checking for compound statements with redirects inside &amp;amp;&amp;amp; lists or negations&lt;/p&gt;
&lt;p&gt;• Fixed pressing Ctrl+X twice in the agent list failing to delete a session, and deleted sessions reappearing when their background worker had died&lt;/p&gt;
&lt;p&gt;• Fixed background subagents getting cancelled when a high-priority message arrives during their startup window&lt;/p&gt;
&lt;p&gt;• Fixed mouse and focus garbage in the terminal while a GUI editor from /memory, /plan, /keybindings, or Ctrl+G is open; /memory no longer waits for the editor to close&lt;/p&gt;
&lt;p&gt;• Fixed Claude-in-Chrome 403-looping on reconnect when the session's OAuth token lacks a required scope&lt;/p&gt;
&lt;p&gt;• Fixed workflow saves and scheduled-task writes following a symlink at .claude, which could redirect writes outside the project&lt;/p&gt;
&lt;p&gt;• Fixed MCP re-authenticate revoking working credentials before the new sign-in succeeds, and the reconnect needs-auth message in background sessions pointing at an unusable command&lt;/p&gt;
&lt;p&gt;• Fixed read-only commands on Windows accessing network paths without a permission prompt&lt;/p&gt;
&lt;p&gt;• Fixed Bash command parsing of non-ASCII characters to match real shell word boundaries&lt;/p&gt;
&lt;p&gt;• Fixed PowerShell tool permission validation of commands containing invisible Unicode characters&lt;/p&gt;
&lt;p&gt;• Fixed dialogs in fullscreen mode stretching past the right-hand edge of their panel&lt;/p&gt;
&lt;p&gt;• Fixed the /config settings list in fullscreen mode clipping its keyboard-hint footer&lt;/p&gt;
&lt;p&gt;• Fixed the transcript-mode (Ctrl+O) footer hint wrapping on terminals narrower than 104 columns&lt;/p&gt;
&lt;p&gt;• Fixed the Prometheus metrics endpoint (OTEL_METRICS_EXPORTER=prometheus) emitting invalid # UNIT lines&lt;/p&gt;
&lt;p&gt;• Fixed skills and commands changed during a session not appearing in the slash menu until restart&lt;/p&gt;
&lt;p&gt;• Fixed plugin skills with a name frontmatter field losing their plugin prefix in slash-command autocomplete&lt;/p&gt;
&lt;p&gt;• Fixed telemetry misreporting permission denials: failed permission-prompt requests no longer count as user rejections, and user interrupts are now reported as user aborts instead of rejections&lt;/p&gt;
&lt;p&gt;• Improved the /fork confirmation to one line with the new session's name, claude attach id, and a note when the copy shares your checkout&lt;/p&gt;
&lt;p&gt;• Improved validation of git and gh command arguments in the PowerShell tool&lt;/p&gt;
&lt;p&gt;• Improved the /ultrareview diff-too-large error to show configured limits, measured diff size, and largest contributing files&lt;/p&gt;
&lt;p&gt;• Improved /code-review ultra empty-diff message to name the exact base ref and suggest passing an explicit base&lt;/p&gt;
&lt;p&gt;• Improved the spend limit adjustment prompt to show the server's reason when a spend limit change is rejected&lt;/p&gt;
&lt;p&gt;• /context now shows an explicit warning when the conversation exceeds the context window, and a failed /compact displays as an error&lt;/p&gt;
&lt;p&gt;• /rewind no longer restores or deletes files through symlinks or hard links at tracked paths and reports how many paths it skipped&lt;/p&gt;
&lt;p&gt;• Background sessions: /mcp and /install-github-app now park a "needs input" request in the agent view when no client is attached&lt;/p&gt;
&lt;p&gt;• Updated the bundled dataviz skill: reordered the default chart palette and fixed guidance that suggested direct labels for four-series charts&lt;/p&gt;
&lt;p&gt;• [VSCode] Fixed right-to-left text (Arabic, Hebrew, Persian) rendering in the wrong order when mixed with English or code&lt;/p&gt;
&lt;p&gt;• Fixed cloud sessions dropping the in-flight message when the session's container restarts mid-turn — the interrupted turn now re-runs on resume instead of leaving the session unresponsive&lt;/p&gt;</content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.215</id>
<title>Claude Code v2.1.215</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.215"/>
<updated>2026-07-19T02:55:54Z</updated>
<content type="html">&lt;p&gt;• Claude no longer runs the /verify and /code-review skills on its own; invoke them with /verify or /code-review when you want them&lt;/p&gt;</content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.214</id>
<title>Claude Code v2.1.214</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.214"/>
<updated>2026-07-18T01:20:23Z</updated>
<content type="html">&lt;p&gt;• Fixed single-segment dir/ allow rules like Edit(src/) auto-approving writes to nested dir/ directories anywhere in the tree instead of only &amp;lt;cwd&amp;gt;/dir&lt;/p&gt;
&lt;p&gt;• Fixed a permission-check bypass affecting commands run in Windows PowerShell 5.1 sessions&lt;/p&gt;
&lt;p&gt;• Fixed Bash permission checks to fail closed on file-descriptor redirect forms that bash parses differently than the permission analyzer&lt;/p&gt;
&lt;p&gt;• Fixed Bash permission checks misjudging very long commands — commands over 10,000 characters now always prompt instead of running automatically&lt;/p&gt;
&lt;p&gt;• Fixed Bash permission checks treating zsh variable subscripts and modifiers in [[ ]] comparisons as inert text — these commands now prompt for approval&lt;/p&gt;
&lt;p&gt;• Fixed Bash permission checks to no longer auto-approve certain help and man commands that could run unsafe options, command substitutions, or backslash paths&lt;/p&gt;
&lt;p&gt;• Fixed permission prompts on remote sessions that could proceed before the local confirmation dialog&lt;/p&gt;
&lt;p&gt;• Added the EndConversation tool: Claude can end sessions with highly abusive users or jailbreak attempts, as on claude.ai since 2025 — see https://www.anthropic.com/research/end-subset-conversations&lt;/p&gt;
&lt;p&gt;• Added a periodic progress heartbeat for long-running tool calls that previously went silent&lt;/p&gt;
&lt;p&gt;• Added an ISO modified timestamp to memory file frontmatter&lt;/p&gt;
&lt;p&gt;• Added message.uuid, client_request_id, and tool_source attributes to OpenTelemetry log events for message-level correlation and tool provenance&lt;/p&gt;
&lt;p&gt;• Added CLAUDE_CODE_OTEL_CONTENT_MAX_LENGTH to configure the 60 KB truncation limit on OpenTelemetry content attributes&lt;/p&gt;
&lt;p&gt;• Added reasoning effort to the subagentStatusLine payload, so custom agent rows can render model and effort&lt;/p&gt;
&lt;p&gt;• Added permission prompts for docker commands (including the Podman docker shim) carrying daemon-redirect flags (--url, --connection, --identity, and Podman's remote mode) that previously ran without one&lt;/p&gt;
&lt;p&gt;• Fixed a crash when a GrowthBook feature evaluates to null, and a bug where a malformed flag payload could wipe the cached feature flags&lt;/p&gt;
&lt;p&gt;• Fixed Bash tool killing the Claude session when a pkill -f pattern accidentally matched the CLI's own process (Linux)&lt;/p&gt;
&lt;p&gt;• Fixed unbounded memory growth when --settings points at a device file or multi-GB file; oversized (&amp;gt;2 MiB) settings files now fail at startup with a clear error&lt;/p&gt;
&lt;p&gt;• Fixed streaming turns failing with "Socket is closed" behind corporate proxies on Windows&lt;/p&gt;
&lt;p&gt;• Fixed stream-json output truncation at exit for slow-reading SDK/pipeline consumers; the exit drain now scales with queued bytes instead of a flat 2s cap&lt;/p&gt;
&lt;p&gt;• Fixed scheduled tasks refusing their own configured prompt as untrusted input — the fired prompt is now delivered as the session's assigned task&lt;/p&gt;
&lt;p&gt;• Fixed PowerShell tool commands hanging until timeout when a child process waited on standard input (Windows)&lt;/p&gt;
&lt;p&gt;• Fixed Python scripts under the PowerShell tool crashing with UnicodeDecodeError when reading non-UTF-8 data from standard input (Windows)&lt;/p&gt;
&lt;p&gt;• Fixed Python scripts run via the PowerShell tool crashing with UnicodeEncodeError on non-ASCII output, and PowerShell 7 error messages containing raw ANSI escape sequences (Windows)&lt;/p&gt;
&lt;p&gt;• Fixed the PowerShell tool reporting where.exe, fc.exe, and diff.exe as errors when they return a valid negative answer (Windows)&lt;/p&gt;
&lt;p&gt;• Fixed &amp;gt; and &amp;gt;&amp;gt; under the PowerShell tool on Windows PowerShell 5.1 writing UTF-16LE files that other tools couldn't read as UTF-8&lt;/p&gt;
&lt;p&gt;• Fixed a displaced background daemon deleting its successor's control socket on shutdown, which made the next client kill the healthy replacement daemon&lt;/p&gt;
&lt;p&gt;• Fixed background sessions parked with ← or /background and left idle keeping the background daemon and a worker process alive indefinitely&lt;/p&gt;
&lt;p&gt;• Fixed completed background sessions being impossible to remove via claude rm or the agent view once the background service had gone idle&lt;/p&gt;
&lt;p&gt;• Fixed background sessions dispatched from a non-git folder being impossible to delete from the agents view&lt;/p&gt;
&lt;p&gt;• Fixed reopening a stopped background session failing to restore its saved conversation when an unreadable folder exists in the session store&lt;/p&gt;
&lt;p&gt;• Fixed the Remote Control "session ready" push notification firing for sessions where Remote Control was not explicitly enabled&lt;/p&gt;
&lt;p&gt;• Fixed /install-github-app and the /mcp settings menu being blocked in agent-view sessions — they're now refused only in background sessions with no terminal attached&lt;/p&gt;
&lt;p&gt;• Fixed plugins enabled via the --settings CLI flag not loading (regression since v2.1.181)&lt;/p&gt;
&lt;p&gt;• Fixed feature flags going stale in long-running sessions after the OAuth token rotates&lt;/p&gt;
&lt;p&gt;• Fixed /ultrareview refusing to run in repos with no merge base — it now offers to review all tracked files&lt;/p&gt;
&lt;p&gt;• Fixed claude update and claude doctor hanging silently, and the /status System diagnostics section going blank, when a shell-config path is a directory&lt;/p&gt;
&lt;p&gt;• Fixed memory frontmatter values being silently truncated at an inline # when memory files are saved&lt;/p&gt;
&lt;p&gt;• Fixed session cost and token telemetry double-counting on streams that emit multiple cumulative message_delta frames&lt;/p&gt;
&lt;p&gt;• Fixed a spurious "check your network" warning that appeared while the advisor was thinking&lt;/p&gt;
&lt;p&gt;• Fixed hooks with exit code 2 not blocking as documented when the hook's stdout JSON fails schema validation&lt;/p&gt;
&lt;p&gt;• Fixed OTel log events emitted outside the turn's async context missing the interaction span's trace context&lt;/p&gt;
&lt;p&gt;• Fixed MCP transient errors during prompts/resources refresh clearing the server's slash commands and resources&lt;/p&gt;
&lt;p&gt;• Improved the claude rc workspace-trust error in the home directory to say trust there is never saved and to suggest running from a project directory&lt;/p&gt;
&lt;p&gt;• Changed single-segment dir/ hook if: conditions to match only &amp;lt;cwd&amp;gt;/dir; write /dir/** for any-depth matching. deny/ask permission rules keep their any-depth match.&lt;/p&gt;
&lt;p&gt;• Changed file commands using -m/--magic-file or -f/--files-from to require permission instead of being auto-allowed as read-only&lt;/p&gt;
&lt;p&gt;• Changed keep-alive connection pooling to disable after a stale-connection error, so retries open a fresh socket&lt;/p&gt;
&lt;p&gt;• Changed SessionStart hooks to report source "fork" when a session begins as a fork instead of "resume"&lt;/p&gt;</content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.212</id>
<title>Claude Code v2.1.212</title>
@@ -506,69 +612,4 @@
&lt;p&gt;• Remote Control is now disabled when ANTHROPIC_BASE_URL points at a non-Anthropic host, matching the existing behavior under CLAUDE_CODE_USE_BEDROCK/_VERTEX/_FOUNDRY&lt;/p&gt;
&lt;p&gt;• Changed opening the agents view from a foreground session to require a single ← press instead of two, matching the behavior in background sessions&lt;/p&gt;</content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.195</id>
<title>Claude Code v2.1.195</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.195"/>
<updated>2026-06-26T21:29:36Z</updated>
<content type="html">&lt;p&gt;• Added CLAUDE_CODE_DISABLE_MOUSE_CLICKS to disable mouse click/drag/hover in fullscreen mode while keeping wheel scroll&lt;/p&gt;
&lt;p&gt;• Fixed hook matchers with hyphenated identifiers (e.g. code-reviewer, mcp__brave-search) accidentally substring-matching — they now exact-match. Use mcp__brave-search__.* to match all tools from a hyphenated MCP server.&lt;/p&gt;
&lt;p&gt;• Fixed voice dictation on macOS capturing silence in long-running sessions after the default input device changes&lt;/p&gt;
&lt;p&gt;• Fixed voice dictation auto-submit never firing for languages written without spaces (Japanese, Chinese, Thai)&lt;/p&gt;
&lt;p&gt;• Fixed external plugins enabled only by project .claude/settings.json not requiring explicit install consent on every loader path&lt;/p&gt;
&lt;p&gt;• Fixed /plugin Enable/Disable not working when a plugin's plugin.json name differs from its marketplace entry name&lt;/p&gt;
&lt;p&gt;• Fixed background jobs disappearing from claude agents or losing data when written by a newer Claude Code version&lt;/p&gt;
&lt;p&gt;• Fixed reopening a crashed background task showing a blank screen for up to 5 seconds instead of its restart&lt;/p&gt;
&lt;p&gt;• Fixed background agent daemons running unreachable when the control socket fails to start, blocking restarts&lt;/p&gt;
&lt;p&gt;• Improved voice mode on Linux: now distinguishes "no microphone" from "SoX not installed" when SoX is present but no audio capture device exists&lt;/p&gt;
&lt;p&gt;• Improved claude agents completed list to fill available vertical space; on short terminals the header compacts so live sessions stay visible&lt;/p&gt;
&lt;p&gt;• Improved Remote session startup with a provisioning checklist while the container starts&lt;/p&gt;</content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.193</id>
<title>Claude Code v2.1.193</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.193"/>
<updated>2026-06-25T21:45:51Z</updated>
<content type="html">&lt;p&gt;• Added autoMode.classifyAllShell setting to route all Bash/PowerShell commands through the auto-mode classifier instead of only arbitrary-code-execution patterns&lt;/p&gt;
&lt;p&gt;• Added auto-mode denial reasons to the transcript, the denial toast, and /permissions recent denials&lt;/p&gt;
&lt;p&gt;• Added claude_code.assistant_response OpenTelemetry log event containing the model's response text. Redacted unless OTEL_LOG_ASSISTANT_RESPONSES=1; when that var is unset it follows OTEL_LOG_USER_PROMPTS, so deployments that already log prompt content will start receiving response content on upgrade — set OTEL_LOG_ASSISTANT_RESPONSES=0 to keep prompts-only.&lt;/p&gt;
&lt;p&gt;• Added live file path autocomplete to bash mode (!)&lt;/p&gt;
&lt;p&gt;• Added a startup notice when MCP servers need authentication, pointing at /mcp&lt;/p&gt;
&lt;p&gt;• Added automatic memory-pressure reaping for idle background shell commands (disable with CLAUDE_CODE_DISABLE_BG_SHELL_PRESSURE_REAP=1)&lt;/p&gt;
&lt;p&gt;• Fixed /model and other client-data-gated UI showing stale/empty state immediately after /login&lt;/p&gt;
&lt;p&gt;• Fixed backgrounding (←←) spuriously cancelling with "N background tasks would be abandoned" when all running tasks carry over to the new session&lt;/p&gt;
&lt;p&gt;• Fixed pinned background agents being re-prompted to "Continue from where you left off" after every auto-update&lt;/p&gt;
&lt;p&gt;• Fixed backgrounding the main turn spawning a phantom "general-purpose (resumed)" subagent that re-ran the main conversation&lt;/p&gt;
&lt;p&gt;• Fixed agent panel hiding sibling agents when viewing a subagent&lt;/p&gt;
&lt;p&gt;• Improved background agents: the launch result no longer instructs Claude to "end your response" — it keeps working on other tasks while the agent runs&lt;/p&gt;
&lt;p&gt;• Improved MCP headersHelper auth: the helper now re-runs and reconnects automatically when a tool call returns 401/403&lt;/p&gt;
&lt;p&gt;• Improved plugin auto-rename: marketplace renames maps are now followed automatically, updating your settings to the new name&lt;/p&gt;
&lt;p&gt;• Improved /add-dir message when the directory is already a working directory&lt;/p&gt;</content>
</entry>
<entry>
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.191</id>
<title>Claude Code v2.1.191</title>
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.191"/>
<updated>2026-06-24T21:58:06Z</updated>
<content type="html">&lt;p&gt;• Added /rewind support for resuming a conversation from before /clear was run&lt;/p&gt;
&lt;p&gt;• Fixed scroll position jumping to the bottom while reading earlier output during a streaming response&lt;/p&gt;
&lt;p&gt;• Fixed background agents resurrecting after being stopped — stopping an agent from the tasks panel is now permanent&lt;/p&gt;
&lt;p&gt;• Fixed /voice showing a generic "not available" message when disabled by an organization's policy — it now explains the restriction&lt;/p&gt;
&lt;p&gt;• Fixed /login URL opening truncated in Windows Terminal when it wraps across lines&lt;/p&gt;
&lt;p&gt;• Fixed Cmd+click on links in fullscreen mode for Ghostty over ssh/tmux&lt;/p&gt;
&lt;p&gt;• Fixed claude agents sending builtin slash commands like /usage to background sessions as prompt text instead of showing a hint&lt;/p&gt;
&lt;p&gt;• Fixed claude agents job rows showing full filesystem paths for pasted images instead of the [Image #N] placeholder&lt;/p&gt;
&lt;p&gt;• Fixed hooks with comma-separated matchers (e.g. "Bash,PowerShell") silently never firing&lt;/p&gt;
&lt;p&gt;• Fixed /permissions Recently-denied tab: approving a denial now persists on close instead of being silently discarded&lt;/p&gt;
&lt;p&gt;• Fixed the agent panel jumping by one row when scrolling the roster past the overflow cap&lt;/p&gt;
&lt;p&gt;• Fixed the welcome splash art overflowing the default 80×24 macOS Terminal window&lt;/p&gt;
&lt;p&gt;• Fixed managed settings: forceRemoteSettingsRefresh now takes effect when set via MDM or file policy, and the fetch sends Cache-Control: no-cache to prevent proxies from serving stale responses&lt;/p&gt;
&lt;p&gt;• Improved sandbox network permission dialog: hosts you allow with "Yes" are now remembered for the rest of the session instead of re-prompting on every connection&lt;/p&gt;
&lt;p&gt;• Improved MCP server reliability: capability discovery (tools/list, prompts/list, resources/list) now retries transient network errors with short backoff&lt;/p&gt;
&lt;p&gt;• Improved MCP OAuth: discovery and token requests now retry once after transient network errors, and headless environments skip the browser popup and go straight to the paste-the-URL prompt&lt;/p&gt;
&lt;p&gt;• Improved MCP error messages: HTTP 404 errors now show the URL and point to your MCP config&lt;/p&gt;
&lt;p&gt;• Improved vim mode prompt-history search (NORMAL /) to hint how to reach slash commands&lt;/p&gt;
&lt;p&gt;• Reduced CPU usage during streaming responses by ~37% by coalescing text updates to 100ms&lt;/p&gt;
&lt;p&gt;• Reduced long-session memory growth from terminal output cache&lt;/p&gt;</content>
</entry>
</feed>