mirror of
https://github.com/anthropics/claude-code.git
synced 2026-08-09 15:53:32 +00:00
641 lines
85 KiB
XML
641 lines
85 KiB
XML
<?xml version="1.0" encoding="UTF-8"?>
|
|
<feed xmlns="http://www.w3.org/2005/Atom">
|
|
<id>https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md</id>
|
|
<title>Claude Code Changelog</title>
|
|
<subtitle>Release notes for Claude Code</subtitle>
|
|
<author><name>Anthropic</name></author>
|
|
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/blob/main/CHANGELOG.md"/>
|
|
<link rel="self" type="application/atom+xml" href="https://raw.githubusercontent.com/anthropics/claude-code/main/feed.xml"/>
|
|
<updated>2026-08-08T02:47:59Z</updated>
|
|
<entry>
|
|
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.226</id>
|
|
<title>Claude Code v2.1.226</title>
|
|
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.226"/>
|
|
<updated>2026-08-08T02:47:59Z</updated>
|
|
<content type="html"><p>• Bug fixes and reliability improvements</p></content>
|
|
</entry>
|
|
<entry>
|
|
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.225</id>
|
|
<title>Claude Code v2.1.225</title>
|
|
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.225"/>
|
|
<updated>2026-08-08T01:09:19Z</updated>
|
|
<content type="html"><p>• Added gateway spend-limit support to Claude Code's usage warning; the limit-reached message now names the cap, its reset time, and the operator's message (requires the gateway on 2.1.225)</p>
|
|
<p>• Added a workspace trust prompt to claude agents for untrusted directories, matching the behavior of claude</p>
|
|
<p>• Fixed a transient 401 replacing a long-lived CLAUDE_CODE_OAUTH_TOKEN with a stored login's short-lived token, breaking headless sessions until restart</p>
|
|
<p>• Fixed MCP OAuth servers on macOS intermittently failing with a burst of 401 errors, as if never authenticated, after a keychain read timed out</p>
|
|
<p>• Fixed auto mode counting a safety-filter refusal of its own permission check toward the consecutive-block limit; the action is still denied, but the model is now told to move on rather than retry</p>
|
|
<p>• Fixed cross-session messages staying parked without a notice or expiry in headless sessions and during startup</p>
|
|
<p>• Fixed conversation history breaking on Remote Control session resume after very large conversations were compacted</p>
|
|
<p>• Fixed hovering over a session in another project in the agents list changing the directory the next agent starts in</p>
|
|
<p>• Fixed claude self-hosted-runner registering and then failing every session when --base-dir cannot be created or written; it now exits at startup with a clear error</p>
|
|
<p>• Fixed Claude Code on the web sessions being misreported as stuck, re-sending a growing event backlog on every reconnect</p>
|
|
<p>• Improved Remote Control: photos attached from the Claude app are now shown to Claude directly instead of being read from disk with a separate tool call</p>
|
|
<p>• [VSCode] Fixed Focus view folding away the latest to-do list, a pending question's context, and settled answers; thinking-only folds show "Thought for Ns" and re-collapse when their turn completes</p>
|
|
<p>• SendMessage can now start a conversation with your Remote Control sessions on other machines by name (ListAgents shows them as name [ref]), instead of only replying after they message you first</p>
|
|
<p>• SendMessage: a Remote Control recipient you already confirmed is never swapped for a same-named session on this machine when its own list couldn't be checked</p></content>
|
|
</entry>
|
|
<entry>
|
|
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.224</id>
|
|
<title>Claude Code v2.1.224</title>
|
|
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.224"/>
|
|
<updated>2026-08-07T04:00:51Z</updated>
|
|
<content type="html"><p>• Added self-hosted environments: claude self-hosted-runner turns your own machines or containers into a place Claude Code web, mobile, and desktop sessions can run, on Team and Enterprise plans</p>
|
|
<p>• Added archive plugin source: install plugins from a zip over HTTPS without git or npm, with optional SHA-256 pinning</p>
|
|
<p>• Added a cancel-and-confirm step when removing an unavailable paste changes a command's text</p>
|
|
<p>• Added ANTHROPIC_BEDROCK_REGION_PREFIX env var for Bedrock to prefer a specific cross-region inference profile over the AWS_REGION-derived one</p>
|
|
<p>• Added crossSessionInbound and dialogExpiry settings: cross-session messages sent to a session running with bypassed permissions are held for your approval, and messages to other sessions auto-deliver</p>
|
|
<p>• Added sandbox credential-masking options: extract and onExtractNoMatch for structured env values, decode: "jwt" with maskClaims for JWT-aware masking, and awsPairs/sigv4 for AWS SigV4 re-signing; these need network.tlsTerminate and are honored only from user, managed, or --settings settings</p>
|
|
<p>• Added cross-session SendMessage: Claude Code sessions can now message each other, on any of your machines, with ListAgents to discover them (macOS and Linux)</p>
|
|
<p>• Fixed long (&gt;200 char) project paths resolving to another project's session directory under a shared sanitized prefix; session list, rename, fork, delete and /resume no longer cross projects</p>
|
|
<p>• Fixed SendMessage reporting "Message sent" when the write to a teammate's inbox had actually failed; failed deliveries are now reported as errors</p>
|
|
<p>• Fixed sandbox filesystem deny entries written with a trailing slash (e.g. denyRead: "~/.aws/") being silently bypassable on Linux and macOS</p>
|
|
<p>• Fixed sandbox violation details never appearing in Bash tool results; Claude now sees which file or network access was denied and why</p>
|
|
<p>• Fixed MCP tools that connect mid-turn being deferred for tool search without their names announced to the model</p>
|
|
<p>• Fixed plugin install records being silently corrupted when the same plugin is installed in multiple projects</p>
|
|
<p>• Fixed recalled or restored paste content occasionally attaching wrong data or silently losing text when the paste had aged out or placeholder numbers collided</p>
|
|
<p>• Fixed copy-on-select on Wayland sometimes not reaching the clipboard; the two selection writes no longer race</p>
|
|
<p>• Fixed the feedback survey's transcript share silently failing on long sessions; a failed share now shows an error instead of a success message</p>
|
|
<p>• Fixed Remote Control auto-start intermittently failing with "Remote credentials fetch failed" on a cold start with a stale login token</p>
|
|
<p>• Fixed Remote Control and SDK clients showing a blank "(no content)" message after /clear and other output-less commands</p>
|
|
<p>• Fixed a Remote Control session recreated after its server session expired uploading prior local conversation history into the new session</p>
|
|
<p>• Improved fullscreen mode to keep the full pre-compaction history in scrollback across repeated compactions, instead of only the most recent interval</p>
|
|
<p>• Improved Remote Control: attached web and mobile clients now see compaction progress and the post-compaction boundary instead of a silent pause; /clear resets now propagate to attached clients</p>
|
|
<p>• Improved Remote Control: connection failures now show a persistent failure indicator with details and a reconnect shortcut, instead of only an 8-second toast</p>
|
|
<p>• Removed the 200-subagent-per-session spawn cap; long-running sessions no longer refuse new agents (concurrency and depth limits still apply)</p>
|
|
<p>• Changed managed settings: the approval prompt no longer re-appears after re-login or org switching when the organization's settings are unchanged</p>
|
|
<p>• Changed the feedback-survey transcript share: with your consent it now also uploads the last request's model settings — the system prompt (which includes your CLAUDE.md instructions), tool definitions, and model parameters. Secrets are redacted as before, and these fields are dropped first if the share is too large</p>
|
|
<p>• Changed the Bash tool description to always note that command output is displayed to the model, not reliably to the user</p>
|
|
<p>• Changed recalled paste placeholder numbers to renumber when accepted into the input</p>
|
|
<p>• Changed Remote Control to archive the stale server session instead of leaving a dead one listed when a fresh session is minted after compaction or /resume</p>
|
|
<p>• [VSCode] Fixed the extension showing Remote Control as connected after the connection failed</p>
|
|
<p>• Fixed a session resume silently reconnecting Remote Control after the user turned it off (--resume, SDK hosts, and the VS Code extension)</p>
|
|
<p>• [VSCode] Fixed sessions not honoring remoteControlAtStartup when explicitly enabled</p></content>
|
|
</entry>
|
|
<entry>
|
|
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.223</id>
|
|
<title>Claude Code v2.1.223</title>
|
|
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.223"/>
|
|
<updated>2026-08-06T00:52:31Z</updated>
|
|
<content type="html"><p>• Added owner wildcard entries ("owner/*") to the strictKnownMarketplaces and blockedMarketplaces managed settings for allowing or blocking all marketplace repos under a GitHub org</p>
|
|
<p>• Added a warning when workflow agents, forked skills, slash commands, or resumed background agents' requested subagent model is restricted and the parent model runs instead</p>
|
|
<p>• Added a /teleport hint in cloud sessions showing how to continue locally with claude --teleport &lt;session id&gt;</p>
|
|
<p>• Fixed a Bash permission bypass where a crafted command could hide parts of itself from permission checks</p>
|
|
<p>• Fixed permission prompts so commands padded with tabs or invisible Unicode can no longer hide part of the command from the approval dialog</p>
|
|
<p>• Fixed workflow scripts being able to use dynamic import() to run code outside the workflow sandbox</p>
|
|
<p>• Fixed a permission gap where an agent definition's bypassPermissions mode ignored the org bypass-permissions disable policy</p>
|
|
<p>• Fixed resuming a session after a mid-session /cd coming back empty</p>
|
|
<p>• Fixed gateway model discovery hiding Claude models registered under provider-prefixed IDs such as vertex_ai/claude-* or bedrock/anthropic.claude-*</p>
|
|
<p>• Fixed modelOverrides keys that aren't Anthropic model IDs being treated as the session's canonical model ID; unknown keys are now ignored as documented</p>
|
|
<p>• Fixed managed settings: server-delivered settings no longer disable the env block of a machine-local managed-settings.json or MDM profile; admin env now merges per key</p>
|
|
<p>• Fixed sandboxed commands failing to start on Linux when sandbox.filesystem.denyWrite covers the working directory</p>
|
|
<p>• Fixed forked background agents getting stuck "already resuming" for the rest of the session when rebuilding the fork's parent prompt failed during resume</p>
|
|
<p>• Fixed a resumed session failing every turn, or leaving the interactive app on an unresponsive error screen, when its history held a malformed diagnostics attachment</p>
|
|
<p>• Fixed a rare hang when parsing unusual git push output</p>
|
|
<p>• Changed CLAUDE_CODE_DISABLE_1M_CONTEXT to hold every Claude model with a native 1M window to 200K via auto-compaction, not just a fixed list; a startup warning now appears when auto-compaction isn't holding the session to 200K</p>
|
|
<p>• Changed auto-compact to keep sessions on unrecognized model IDs within the assumed context window instead of letting them grow past it; set CLAUDE_CODE_DISABLE_UNKNOWN_MODEL_WINDOW_ENFORCEMENT=1 to restore the previous behavior</p>
|
|
<p>• Changed /review to be an alias of /code-review, which reviews the current diff or a PR (/code-review &lt;level&gt; &lt;pr#&gt;); use /code-review ultra for a deep cloud review</p>
|
|
<p>• Changed /code-review with no effort level to reuse the level you typed last; type a level like /code-review high to change it</p></content>
|
|
</entry>
|
|
<entry>
|
|
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.222</id>
|
|
<title>Claude Code v2.1.222</title>
|
|
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.222"/>
|
|
<updated>2026-08-04T22:39:48Z</updated>
|
|
<content type="html"><p>• Fixed worktree-isolated sessions and their subagents being able to run destructive git commands against the main checkout; isolation now applies to file edits and Bash in every session type</p>
|
|
<p>• Fixed PreToolUse auto-allow hooks bypassing tool restrictions in background agent tasks (summaries, compaction, renames)</p>
|
|
<p>• Fixed /usage-credits on Team and Enterprise showing "you've already sent a usage credit request" for members whose earlier request was dismissed, blocking them from sending a new one</p>
|
|
<p>• Fixed the startup connectivity check hanging and then failing behind an HTTPS proxy; it now uses the same proxy-aware transport as API requests and times out with a clear message</p>
|
|
<p>• Fixed "Connection closed mid-response" errors being reported on responses that had actually completed</p>
|
|
<p>• Fixed /usage overattributing usage to MCP servers: a server's share now reflects only the requests that actually consumed its tool results, instead of every turn after any call to it</p>
|
|
<p>• Fixed sessions not linking to pull requests created after the branch was pushed, including through the GitHub REST API</p>
|
|
<p>• Fixed org-restricted model: opus-style subagent and teammate family aliases dropping to the parent model instead of stepping down to the newest org-allowed model in the family</p>
|
|
<p>• Fixed stream idle timeout firing on custom ANTHROPIC_BASE_URL gateways despite server keep-alive pings arriving on the wire</p>
|
|
<p>• Fixed claude.ai connectors being falsely marked as needing authorization when the session token is invalid — they now show a /login hint instead</p>
|
|
<p>• Fixed tool errors not being displayed for tools no longer available locally, for example after an MCP server is removed</p>
|
|
<p>• Fixed SendMessage rejecting a long summary — it now truncates instead, so sends no longer fail on a character limit</p>
|
|
<p>• Fixed the spinner's effort label in a subagent's transcript view showing the session's effort level instead of the subagent's own effort: setting</p>
|
|
<p>• Fixed rare crashes when a file watcher hit a filesystem error or during file-watcher teardown</p>
|
|
<p>• Fixed screen readers re-reading the whole input line on every backspace in --ax-screen-reader mode — end-of-line deletions now echo just the deleted characters</p>
|
|
<p>• Fixed host model-selection keys not taking precedence over a stale on-disk managed-settings.json when CLAUDE_CODE_PROVIDER_MANAGED_BY_HOST is set</p>
|
|
<p>• Improved auto mode safety: messages sent to other agent sessions via SendMessage are now evaluated by the permission classifier before dispatch</p>
|
|
<p>• Improved the refusal when Claude tries to invoke a skill with disable-model-invocation: Claude is now told to ask you to run the skill instead of replicating its workflow</p>
|
|
<p>• Improved the /diff view, the Remote Control workspace diff, and file-edit diffs in Claude Code on the web sessions to use raw git blob content, ignoring workspace-configured diff drivers and textconv</p>
|
|
<p>• Changed Remote Control auto-start so repo-local settings (.claude/settings.json or .claude/settings.local.json) can no longer turn it on (they can still turn it off); enable it at user scope via /config</p>
|
|
<p>• Removed ultraplan feature</p></content>
|
|
</entry>
|
|
<entry>
|
|
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.221</id>
|
|
<title>Claude Code v2.1.221</title>
|
|
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.221"/>
|
|
<updated>2026-08-04T00:14:17Z</updated>
|
|
<content type="html"><p>• [VSCode] Added Focus view: a chat-menu toggle that hides tool activity behind an expandable per-turn summary with a live running-tool indicator, toggled with Ctrl+Alt+F or the "Claude Code: Toggle Focus view" command</p>
|
|
<p>• Added mode: "mask" for sandbox credential files on Linux and WSL — sandboxed commands read a sentinel copy (the whole file, or just the spans captured by an extract regex) while the sandbox proxy substitutes the real value on egress; on macOS file masking falls back to deny</p>
|
|
<p>• Added warnings to claude plugin validate when a marketplace or plugin name would be rejected by Claude Desktop's managed marketplace sync</p>
|
|
<p>• Added a prompt-audit subcommand to the claude-api skill for auditing prompts and tool descriptions for patterns written for older models</p>
|
|
<p>• Fixed a Bash tool permission-check bypass where zsh could execute hidden commands in [[ ]] regex conditionals; affected commands now prompt for permission</p>
|
|
<p>• Fixed PowerShell permission checks mishandling paths containing quote characters on Windows; such paths now prompt for approval</p>
|
|
<p>• Fixed the thinking toggle having no effect for the rest of a session that started with thinking off; disabling an MCP server mid-connect no longer silently reverts</p>
|
|
<p>• Fixed MCP servers from --mcp-config not being connected before the first turn in print mode (-p), which made the model emit tool calls as literal text</p>
|
|
<p>• Fixed @-mentioned files being silently dropped when pressing Esc to retract a prompt and resubmitting it</p>
|
|
<p>• Fixed a crash when preparing API requests for SDK MCP tools named after built-in object properties such as constructor</p>
|
|
<p>• Fixed WebSearch failing with a 400 error at effort xhigh/max when thinking is disabled</p>
|
|
<p>• Fixed sandboxed large uploads failing with TLS errors through the sandbox proxy</p>
|
|
<p>• Fixed Team and Enterprise spend-limit message incorrectly blaming the org's monthly limit instead of your individual spend limit</p>
|
|
<p>• Fixed Bedrock authentication with AWS SSO named profiles failing in desktop-managed sessions on Windows machines that set a stray HOME environment variable</p>
|
|
<p>• Fixed CLAUDE_CODE_RESUME_INTERRUPTED_TURN=0 not disabling interrupted-turn auto-resume; falsy values are now honored</p>
|
|
<p>• Fixed a rare wake-from-sleep race where two Claude Code processes could both refresh the same MCP connector or WIF OAuth token at once, forcing re-authentication</p>
|
|
<p>• Fixed renaming a session from Claude Code Desktop or claude.ai not updating the CLI's session name; session names from every rename surface are now sanitized</p>
|
|
<p>• Fixed plugin- and org-delivered skills named after terminal-only built-ins (e.g. /help, /feedback) being un-invocable in non-interactive sessions</p>
|
|
<p>• Fixed the "Plugins changed" notification lingering after plugins were reloaded instead of clearing</p>
|
|
<p>• Fixed Vim mode: the yank register now survives dialogs, history search, and the transcript view instead of being silently emptied</p>
|
|
<p>• Fixed Vim mode: undoing back to an empty prompt now arms the "press ← again" confirm before returning to the agent view</p>
|
|
<p>• Improved tool search on Google Vertex AI: re-enabled for Claude 4.5-generation and newer models</p>
|
|
<p>• Improved auto mode: permission checks for parallel tool calls are now cache-efficient, and switching modes while a check is pending reliably prompts instead of applying the stale result</p>
|
|
<p>• Reduced prompt-cache costs for auto-mode permission checks by reusing the cached conversation prefix across decisions</p>
|
|
<p>• Improved Stats panel to count cache tokens in its token totals, with a breakdown by input, output, cache read, and cache write</p>
|
|
<p>• Improved /ultrareview error messages when a repo shares no history with its base: a checkout with no branches is now refused up front with advice to create one, and refusal hints no longer suggest git fetch --unshallow on clones that are already complete</p>
|
|
<p>• Improved Windows startup: process creation times are now read via a native kernel32 call instead of spawning PowerShell, so endpoint security tools that gate powershell.exe no longer prompt</p>
|
|
<p>• Changed background sessions to commit and push to preserve work, open a draft PR only when the task calls for one, follow your CLAUDE.md git instructions, and always end by reporting where the work lives</p>
|
|
<p>• Changed /plugin install to refresh a stale marketplace catalog and retry before reporting a plugin not found</p>
|
|
<p>• Changed plugins installed from /plugin to activate immediately when safe, instead of always requiring /reload-plugins</p>
|
|
<p>• Changed plugins to accept "." as a skills path, and the root-level SKILL.md validation error now suggests using the plugin root</p>
|
|
<p>• Changed /status to show the session kind: interactive, or a background job that is attached or unattended</p>
|
|
<p>• Changed emoji autocomplete to accept common alternate shortcodes like :thumbsup:, :thumbsdown:, and :love:</p>
|
|
<p>• Changed sessions forked with /fork to create a new worktree of their own instead of working in the original session's checkout</p>
|
|
<p>• Changed Claude in Chrome to close the browser tabs it opens once it no longer needs them</p>
|
|
<p>• Changed fast mode to report on the stream when usage credits run out mid-session, instead of failing silently</p>
|
|
<p>• Changed Monitor: a watch that exits without producing any output now says so instead of reporting "stream ended"</p>
|
|
<p>• Changed the Gateway model field validation: non-string values are rejected with a 400 instead of being forwarded</p>
|
|
<p>• Removed the repeated "Permission mode changed while the auto-mode classifier call was queued" notice from approval prompts</p></content>
|
|
</entry>
|
|
<entry>
|
|
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.220</id>
|
|
<title>Claude Code v2.1.220</title>
|
|
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.220"/>
|
|
<updated>2026-07-25T01:35:47Z</updated>
|
|
<content type="html"><p>• Bug fixes and reliability improvements</p></content>
|
|
</entry>
|
|
<entry>
|
|
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.219</id>
|
|
<title>Claude Code v2.1.219</title>
|
|
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.219"/>
|
|
<updated>2026-07-24T17:14:14Z</updated>
|
|
<content type="html"><p>• Added Claude Opus 5 (claude-opus-5), now the default Opus model — 1M context, fast mode at $10/$50 per Mtok</p>
|
|
<p>• Added sandbox.network.strictAllowlist setting to deny non-allowlisted hosts for sandboxed commands without prompting</p>
|
|
<p>• Added DirectoryAdded hook that fires after /add-dir or the SDK register_repo_root control request registers a new working directory mid-session</p>
|
|
<p>• Added mcp_server_errors to the headless stream-json init event, listing --mcp-config entries skipped by config validation; terminal runs print a startup warning</p>
|
|
<p>• Added the workflowSizeGuideline settings key so the advisory Dynamic workflow size guideline can be set from any settings file; the /config row is hidden while one does</p>
|
|
<p>• Added nested subagent forwarding in stream-json: subagents spawned at depth-2+ now appear when --forward-subagent-text is set, keyed by their spawning Agent tool_use id</p>
|
|
<p>• Fixed claude -p text output dropping the answer already produced when a turn dies on a mid-stream API error</p>
|
|
<p>• Added HTTP status and error text to claude mcp list and /mcp when a server fails to connect, and a warning for MCP config values with hidden leading or trailing whitespace</p>
|
|
<p>• Fixed the Fable model row showing "Requires usage credits" for plans that include it, when a stale cache had baked the label in</p>
|
|
<p>• Fixed the /model picker showing the merged Opus row as plain "Opus" instead of "Opus (1M context)"</p>
|
|
<p>• Fixed copy-on-select inside GNU screen printing base64 into the terminal instead of copying the selection</p>
|
|
<p>• Fixed Remote Control clients keeping a stale fast-mode status after a model switch, reconnect, or failed org check</p>
|
|
<p>• Fixed CLAUDE_CODE_GIT_BASH_PATH on Windows exiting or being used as bash when the path isn't a bash/sh binary; it's now ignored with a warning</p>
|
|
<p>• Fixed Vim mode: pressing ← on an empty prompt now returns to the agent view from NORMAL mode, not just INSERT</p>
|
|
<p>• Fixed screen-reader mode rewriting the entire input line on every keystroke instead of echoing only the typed character</p>
|
|
<p>• Improved the "Remote Control is only available via api.anthropic.com" error to name the specific setting that caused it</p>
|
|
<p>• Improved claude --teleport to show which repo your current checkout points at when it doesn't match the session's repo</p>
|
|
<p>• Changed dynamic workflows to default to a medium size guideline (aim for fewer than 15 agents); pick another size or unrestricted with Dynamic workflow size in /config</p>
|
|
<p>• Changed managed MCP allowlist/denylist ${VAR} entries to resolve from the startup environment and managed-settings env instead of settings-file env</p>
|
|
<p>• Changed the /model picker to highlight only the newest model's name, so the highlight marks the new release rather than an arbitrary subset of the list</p>
|
|
<p>• Added the current default workflow size to the running-workflow status line, with a pointer to /config for changing it</p>
|
|
<p>• Removed Opus 4.7 from fast mode; /fast now applies to Opus 5 and Opus 4.8</p>
|
|
<p>• Updated the claude-api skill to default to Claude Opus 5, with a migration path from Opus 4.8</p>
|
|
<p>• Subagents can now spawn nested subagents up to depth 3 by default (was 1); set CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH=1 to disable nesting</p></content>
|
|
</entry>
|
|
<entry>
|
|
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.218</id>
|
|
<title>Claude Code v2.1.218</title>
|
|
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.218"/>
|
|
<updated>2026-07-22T21:24:49Z</updated>
|
|
<content type="html"><p>• Changed /code-review to run as a background subagent, so review work no longer fills your conversation and keeps stacked slash commands as its review target</p>
|
|
<p>• Added screen-reader announcements of deleted text for word and line deletions (Option+Delete, Ctrl+W, Cmd+Backspace, Ctrl+U, Ctrl+K) in --ax-screen-reader mode</p>
|
|
<p>• Fixed Windows paths with \u-prefixed segments (like C:\Users\unicorn) being corrupted into CJK characters in tool inputs, which made those files inaccessible</p>
|
|
<p>• Fixed the left arrow key discarding the conversation with no undo: presses right after editing now ask to confirm, and Esc in the agent view returns to the conversation it backgrounded</p>
|
|
<p>• Fixed multi-line paste collapsing into one line with j in place of newlines in terminals that encode pasted newlines as Ctrl+J</p>
|
|
<p>• Fixed /context reporting stale pre-compact token usage after compacting from the message picker</p>
|
|
<p>• Fixed /ultrareview failing on descriptive arguments like "review my auth changes" — they now run a review of your current branch with the text applied as a note to the findings</p>
|
|
<p>• Fixed /code-review ultra silently running a local review in non-interactive sessions — it now launches the cloud review</p>
|
|
<p>• Fixed gateway spend metering to price Bedrock application-inference-profile ARNs and other config-mapped upstream model IDs at the configured model's rates</p>
|
|
<p>• Fixed mojibake when a long IDE selection was truncated mid-emoji, and a case where a tool executor error could be silently dropped</p>
|
|
<p>• Fixed an engine teardown race that could start and abandon a phantom turn, and made input pushed after close consistently rejected</p>
|
|
<p>• Fixed spurious "[Request interrupted by user]" messages after interrupted tool calls, and an unpaired tool_use block left in the transcript when a tool aborted mid-response</p>
|
|
<p>• Fixed VoiceOver reading "new line" instead of echoing the typed space at the end of the input in --ax-screen-reader mode</p>
|
|
<p>• Fixed plugin and settings panels not moving the terminal cursor to the focused row, so screen readers and magnifiers can follow arrow-key navigation</p>
|
|
<p>• Fixed crashes (maximum call stack exceeded) when a deeply nested watched directory tree was deleted or moved, and when rendering deeply nested UI trees</p>
|
|
<p>• Fixed pull request events occasionally being lost when a session exited immediately after creating or linking a PR</p>
|
|
<p>• Fixed the Bedrock setup wizard failing profile verification for assume-role profiles in partitioned AWS regions and on proxy-only networks</p>
|
|
<p>• Fixed rare negative or incorrect turn duration measurements after a system clock adjustment by timing turns with a monotonic clock</p>
|
|
<p>• Fixed the "N MCP servers need authentication" startup notice over-counting claude.ai connectors that aren't connected in claude.ai</p>
|
|
<p>• Fixed prompt history entries being dropped or duplicated when history writes raced or failed</p>
|
|
<p>• Fixed a retry loop that re-sent identical doomed requests after a context-overflow error with a large thinking budget; Ctrl+B backgrounding now applies the same background-shell caps as other paths</p>
|
|
<p>• Fixed agent frontmatter hooks running from untrusted folders: hooks now require the agent file's own folder to have accepted workspace trust</p>
|
|
<p>• Fixed fork-session lineage being lost after compaction in headless and SDK sessions</p>
|
|
<p>• Fixed a resumed session failing every turn, or crashing on resume, when its history held a malformed delta attachment</p>
|
|
<p>• Improved /ultrareview error feedback so Claude can correct an invalid argument instead of retrying it unchanged</p>
|
|
<p>• Improved auto mode: the dangerous-rm, background-&amp;, and suspicious-Windows-path checks no longer open permission dialogs; the auto-mode classifier adjudicates them instead</p>
|
|
<p>• Improved sandbox command restrictions for IDE interactions</p>
|
|
<p>• Improved trust dialogs to name the repository root the grant covers</p>
|
|
<p>• Changed /deep-research to start only when invoked manually; Claude no longer launches it on its own</p>
|
|
<p>• Changed plan mode with auto to no longer prompt for Bash commands the static analyzer can't prove read-only; the auto-mode classifier judges them instead</p>
|
|
<p>• Added an announcement when fast mode changes as a result of switching models via /config model=&lt;x&gt; or Remote Control</p>
|
|
<p>• Changed server-managed settings so benign feature and cost toggles no longer trigger the settings-approval prompt</p>
|
|
<p>• Changed agent markdown files to reject agent names containing :, which is reserved for plugin namespacing</p>
|
|
<p>• Changed skills with context: fork to run in the background by default; opt out per skill with background: false</p>
|
|
<p>• Added yes/no/on/off/1/0 (case-insensitive) as accepted values for skill and plugin frontmatter booleans, alongside true/false</p>
|
|
<p>• Fixed remote sessions continuing to send heartbeats after their worker was replaced, which left long-lived desktop and IDE processes retrying a rejected request every few seconds forever</p></content>
|
|
</entry>
|
|
<entry>
|
|
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.217</id>
|
|
<title>Claude Code v2.1.217</title>
|
|
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.217"/>
|
|
<updated>2026-07-21T21:35:04Z</updated>
|
|
<content type="html"><p>• Added emoji shortcode autocomplete in the prompt input: type :heart: to insert ❤️, or :hea for suggestions — disable with the emojiCompletionEnabled setting</p>
|
|
<p>• Added warnings when transcript writes are failing (e.g. disk full) or when session saving is off due to an inherited environment variable, instead of losing transcripts silently</p>
|
|
<p>• Fixed a memory leak where truncated MCP tool outputs kept the full untruncated result in memory for the rest of the session</p>
|
|
<p>• Fixed Windows auto-update failures that could leave claude.exe missing; failed updates now restore the preserved executable automatically</p>
|
|
<p>• Fixed background session isolation not canonicalizing symlinked working directories, which could let sessions escape their workspace folder</p>
|
|
<p>• Fixed auto-compact never triggering for Claude Opus 4.8 on Bedrock and /compact failing once over the limit</p>
|
|
<p>• Fixed corporate mTLS, TLS-verify, OAuth scope, and proxy settings being ignored in Claude Desktop sessions</p>
|
|
<p>• Fixed screen reader mode's startup announcement being cut off by the first prompt render, and the thinking status row re-rendering every few seconds to update elapsed time and token counts</p>
|
|
<p>• Fixed managed settings that set OTEL_EXPORTER_OTLP_ENDPOINT not governing all signals — lower-scope signal-specific overrides no longer redirect telemetry away from the managed endpoint</p>
|
|
<p>• Fixed --resume/--continue and /resume failing with a TypeError when a transcript has a malformed attachment entry</p>
|
|
<p>• Fixed Remote Control sessions not showing a pending permission prompt or dialog to viewers that connected after it appeared</p>
|
|
<p>• Fixed background shells sometimes becoming impossible to stop after a session is sent to the background (/background or ←) or when the session exits on a heavily loaded machine, most visible on Windows</p>
|
|
<p>• Fixed a CLAUDE.md or SKILL.md paths frontmatter value with many brace groups OOM-killing or stalling the CLI at startup — brace expansion is now budget-bounded</p>
|
|
<p>• Fixed the transcript preview sitting flush against the input area when attaching to a starting background session; it now leaves the same one-line gap as the live layout, so the transcript no longer shifts when the session takes over</p>
|
|
<p>• Improved footer PR badge links to be clickable hyperlinks even when terminal support can't be detected (e.g. over ssh/tmux); set FORCE_HYPERLINK=0 to opt out</p>
|
|
<p>• Changed the login-expiry warning to appear 3 days before expiry instead of 5</p>
|
|
<p>• Capped the frontend-design plugin suggestion tip at 3 lifetime impressions instead of repeating indefinitely</p>
|
|
<p>• Added a cap on concurrently-running subagents (default 20, override with CLAUDE_CODE_MAX_CONCURRENT_SUBAGENTS) so one message can't fan out unbounded background agents</p>
|
|
<p>• Changed subagents to no longer spawn nested subagents by default; set CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH to allow deeper nesting</p>
|
|
<p>• Fixed --max-budget-usd not stopping background subagents: once the cap is reached, new spawns are denied and running background agents are halted</p></content>
|
|
</entry>
|
|
<entry>
|
|
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.216</id>
|
|
<title>Claude Code v2.1.216</title>
|
|
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.216"/>
|
|
<updated>2026-07-20T22:13:53Z</updated>
|
|
<content type="html"><p>• Added sandbox.filesystem.disabled setting to skip filesystem isolation while keeping network egress control</p>
|
|
<p>• Fixed a slowdown in long sessions where message normalization cost grew quadratically with the number of turns, causing multi-second stalls and slow resumes</p>
|
|
<p>• Fixed auto mode denying commands with "HTTP 401" classifier errors after the OAuth token expired or rotated mid-session</p>
|
|
<p>• Fixed AskUserQuestion telling Claude to continue even when your answer asked it to wait or explain first — free-text answers now get neutral wording</p>
|
|
<p>• Fixed Claude Code on the web re-asking the same question and dropping your answer after the session sat idle for a few minutes</p>
|
|
<p>• Fixed @-mentions silently attaching nothing after file-modifying hooks, vim dot-repeat of c-operators and paste, statusline running twice on resume, and resume-picker hangs on failure</p>
|
|
<p>• Fixed resumed background agent sessions reverting to the default agent: the agent's prompt and tool restrictions are now restored</p>
|
|
<p>• Fixed worktree-isolated subagents redirecting git into the shared checkout via git -C, --git-dir, or GIT_DIR/GIT_WORK_TREE</p>
|
|
<p>• Fixed worktree sessions landing in another project's leftover worktree when the working directory did not match the selected project</p>
|
|
<p>• Fixed background sessions whose worktree has no git repository being undeletable</p>
|
|
<p>• Fixed claude daemon stop --any potentially terminating an unrelated process via a stale legacy daemon lockfile</p>
|
|
<p>• Fixed Esc-Esc at an idle prompt not opening the rewind picker in long-running sessions with background tasks</p>
|
|
<p>• Fixed Bash command permission checking for compound statements with redirects inside &amp;&amp; lists or negations</p>
|
|
<p>• Fixed pressing Ctrl+X twice in the agent list failing to delete a session, and deleted sessions reappearing when their background worker had died</p>
|
|
<p>• Fixed background subagents getting cancelled when a high-priority message arrives during their startup window</p>
|
|
<p>• Fixed mouse and focus garbage in the terminal while a GUI editor from /memory, /plan, /keybindings, or Ctrl+G is open; /memory no longer waits for the editor to close</p>
|
|
<p>• Fixed Claude-in-Chrome 403-looping on reconnect when the session's OAuth token lacks a required scope</p>
|
|
<p>• Fixed workflow saves and scheduled-task writes following a symlink at .claude, which could redirect writes outside the project</p>
|
|
<p>• Fixed MCP re-authenticate revoking working credentials before the new sign-in succeeds, and the reconnect needs-auth message in background sessions pointing at an unusable command</p>
|
|
<p>• Fixed read-only commands on Windows accessing network paths without a permission prompt</p>
|
|
<p>• Fixed Bash command parsing of non-ASCII characters to match real shell word boundaries</p>
|
|
<p>• Fixed PowerShell tool permission validation of commands containing invisible Unicode characters</p>
|
|
<p>• Fixed dialogs in fullscreen mode stretching past the right-hand edge of their panel</p>
|
|
<p>• Fixed the /config settings list in fullscreen mode clipping its keyboard-hint footer</p>
|
|
<p>• Fixed the transcript-mode (Ctrl+O) footer hint wrapping on terminals narrower than 104 columns</p>
|
|
<p>• Fixed the Prometheus metrics endpoint (OTEL_METRICS_EXPORTER=prometheus) emitting invalid # UNIT lines</p>
|
|
<p>• Fixed skills and commands changed during a session not appearing in the slash menu until restart</p>
|
|
<p>• Fixed plugin skills with a name frontmatter field losing their plugin prefix in slash-command autocomplete</p>
|
|
<p>• Fixed telemetry misreporting permission denials: failed permission-prompt requests no longer count as user rejections, and user interrupts are now reported as user aborts instead of rejections</p>
|
|
<p>• Improved the /fork confirmation to one line with the new session's name, claude attach id, and a note when the copy shares your checkout</p>
|
|
<p>• Improved validation of git and gh command arguments in the PowerShell tool</p>
|
|
<p>• Improved the /ultrareview diff-too-large error to show configured limits, measured diff size, and largest contributing files</p>
|
|
<p>• Improved /code-review ultra empty-diff message to name the exact base ref and suggest passing an explicit base</p>
|
|
<p>• Improved the spend limit adjustment prompt to show the server's reason when a spend limit change is rejected</p>
|
|
<p>• /context now shows an explicit warning when the conversation exceeds the context window, and a failed /compact displays as an error</p>
|
|
<p>• /rewind no longer restores or deletes files through symlinks or hard links at tracked paths and reports how many paths it skipped</p>
|
|
<p>• Background sessions: /mcp and /install-github-app now park a "needs input" request in the agent view when no client is attached</p>
|
|
<p>• Updated the bundled dataviz skill: reordered the default chart palette and fixed guidance that suggested direct labels for four-series charts</p>
|
|
<p>• [VSCode] Fixed right-to-left text (Arabic, Hebrew, Persian) rendering in the wrong order when mixed with English or code</p>
|
|
<p>• Fixed cloud sessions dropping the in-flight message when the session's container restarts mid-turn — the interrupted turn now re-runs on resume instead of leaving the session unresponsive</p></content>
|
|
</entry>
|
|
<entry>
|
|
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.215</id>
|
|
<title>Claude Code v2.1.215</title>
|
|
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.215"/>
|
|
<updated>2026-07-19T02:55:54Z</updated>
|
|
<content type="html"><p>• Claude no longer runs the /verify and /code-review skills on its own; invoke them with /verify or /code-review when you want them</p></content>
|
|
</entry>
|
|
<entry>
|
|
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.214</id>
|
|
<title>Claude Code v2.1.214</title>
|
|
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.214"/>
|
|
<updated>2026-07-18T01:20:23Z</updated>
|
|
<content type="html"><p>• Fixed single-segment dir/ allow rules like Edit(src/) auto-approving writes to nested dir/ directories anywhere in the tree instead of only &lt;cwd&gt;/dir</p>
|
|
<p>• Fixed a permission-check bypass affecting commands run in Windows PowerShell 5.1 sessions</p>
|
|
<p>• Fixed Bash permission checks to fail closed on file-descriptor redirect forms that bash parses differently than the permission analyzer</p>
|
|
<p>• Fixed Bash permission checks misjudging very long commands — commands over 10,000 characters now always prompt instead of running automatically</p>
|
|
<p>• Fixed Bash permission checks treating zsh variable subscripts and modifiers in [[ ]] comparisons as inert text — these commands now prompt for approval</p>
|
|
<p>• Fixed Bash permission checks to no longer auto-approve certain help and man commands that could run unsafe options, command substitutions, or backslash paths</p>
|
|
<p>• Fixed permission prompts on remote sessions that could proceed before the local confirmation dialog</p>
|
|
<p>• Added the EndConversation tool: Claude can end sessions with highly abusive users or jailbreak attempts, as on claude.ai since 2025 — see https://www.anthropic.com/research/end-subset-conversations</p>
|
|
<p>• Added a periodic progress heartbeat for long-running tool calls that previously went silent</p>
|
|
<p>• Added an ISO modified timestamp to memory file frontmatter</p>
|
|
<p>• Added message.uuid, client_request_id, and tool_source attributes to OpenTelemetry log events for message-level correlation and tool provenance</p>
|
|
<p>• Added CLAUDE_CODE_OTEL_CONTENT_MAX_LENGTH to configure the 60 KB truncation limit on OpenTelemetry content attributes</p>
|
|
<p>• Added reasoning effort to the subagentStatusLine payload, so custom agent rows can render model and effort</p>
|
|
<p>• Added permission prompts for docker commands (including the Podman docker shim) carrying daemon-redirect flags (--url, --connection, --identity, and Podman's remote mode) that previously ran without one</p>
|
|
<p>• Fixed a crash when a GrowthBook feature evaluates to null, and a bug where a malformed flag payload could wipe the cached feature flags</p>
|
|
<p>• Fixed Bash tool killing the Claude session when a pkill -f pattern accidentally matched the CLI's own process (Linux)</p>
|
|
<p>• Fixed unbounded memory growth when --settings points at a device file or multi-GB file; oversized (&gt;2 MiB) settings files now fail at startup with a clear error</p>
|
|
<p>• Fixed streaming turns failing with "Socket is closed" behind corporate proxies on Windows</p>
|
|
<p>• Fixed stream-json output truncation at exit for slow-reading SDK/pipeline consumers; the exit drain now scales with queued bytes instead of a flat 2s cap</p>
|
|
<p>• Fixed scheduled tasks refusing their own configured prompt as untrusted input — the fired prompt is now delivered as the session's assigned task</p>
|
|
<p>• Fixed PowerShell tool commands hanging until timeout when a child process waited on standard input (Windows)</p>
|
|
<p>• Fixed Python scripts under the PowerShell tool crashing with UnicodeDecodeError when reading non-UTF-8 data from standard input (Windows)</p>
|
|
<p>• Fixed Python scripts run via the PowerShell tool crashing with UnicodeEncodeError on non-ASCII output, and PowerShell 7 error messages containing raw ANSI escape sequences (Windows)</p>
|
|
<p>• Fixed the PowerShell tool reporting where.exe, fc.exe, and diff.exe as errors when they return a valid negative answer (Windows)</p>
|
|
<p>• Fixed &gt; and &gt;&gt; under the PowerShell tool on Windows PowerShell 5.1 writing UTF-16LE files that other tools couldn't read as UTF-8</p>
|
|
<p>• Fixed a displaced background daemon deleting its successor's control socket on shutdown, which made the next client kill the healthy replacement daemon</p>
|
|
<p>• Fixed background sessions parked with ← or /background and left idle keeping the background daemon and a worker process alive indefinitely</p>
|
|
<p>• Fixed completed background sessions being impossible to remove via claude rm or the agent view once the background service had gone idle</p>
|
|
<p>• Fixed background sessions dispatched from a non-git folder being impossible to delete from the agents view</p>
|
|
<p>• Fixed reopening a stopped background session failing to restore its saved conversation when an unreadable folder exists in the session store</p>
|
|
<p>• Fixed the Remote Control "session ready" push notification firing for sessions where Remote Control was not explicitly enabled</p>
|
|
<p>• Fixed /install-github-app and the /mcp settings menu being blocked in agent-view sessions — they're now refused only in background sessions with no terminal attached</p>
|
|
<p>• Fixed plugins enabled via the --settings CLI flag not loading (regression since v2.1.181)</p>
|
|
<p>• Fixed feature flags going stale in long-running sessions after the OAuth token rotates</p>
|
|
<p>• Fixed /ultrareview refusing to run in repos with no merge base — it now offers to review all tracked files</p>
|
|
<p>• Fixed claude update and claude doctor hanging silently, and the /status System diagnostics section going blank, when a shell-config path is a directory</p>
|
|
<p>• Fixed memory frontmatter values being silently truncated at an inline # when memory files are saved</p>
|
|
<p>• Fixed session cost and token telemetry double-counting on streams that emit multiple cumulative message_delta frames</p>
|
|
<p>• Fixed a spurious "check your network" warning that appeared while the advisor was thinking</p>
|
|
<p>• Fixed hooks with exit code 2 not blocking as documented when the hook's stdout JSON fails schema validation</p>
|
|
<p>• Fixed OTel log events emitted outside the turn's async context missing the interaction span's trace context</p>
|
|
<p>• Fixed MCP transient errors during prompts/resources refresh clearing the server's slash commands and resources</p>
|
|
<p>• Improved the claude rc workspace-trust error in the home directory to say trust there is never saved and to suggest running from a project directory</p>
|
|
<p>• Changed single-segment dir/ hook if: conditions to match only &lt;cwd&gt;/dir; write /dir/** for any-depth matching. deny/ask permission rules keep their any-depth match.</p>
|
|
<p>• Changed file commands using -m/--magic-file or -f/--files-from to require permission instead of being auto-allowed as read-only</p>
|
|
<p>• Changed keep-alive connection pooling to disable after a stale-connection error, so retries open a fresh socket</p>
|
|
<p>• Changed SessionStart hooks to report source "fork" when a session begins as a fork instead of "resume"</p></content>
|
|
</entry>
|
|
<entry>
|
|
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.212</id>
|
|
<title>Claude Code v2.1.212</title>
|
|
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.212"/>
|
|
<updated>2026-07-17T00:26:21Z</updated>
|
|
<content type="html"><p>• /fork now copies your conversation into a new background session (its own row in claude agents) while you keep working; the in-session subagent it used to launch is now /subtask</p>
|
|
<p>• Added claude auto-mode reset to restore the default auto-mode configuration, with a confirmation prompt (pass --yes to skip)</p>
|
|
<p>• Added a session-wide limit on WebSearch tool calls (default 200, tunable via CLAUDE_CODE_MAX_WEB_SEARCHES_PER_SESSION) to stop runaway search loops</p>
|
|
<p>• Added a per-session cap on subagent spawns (default 200, override with CLAUDE_CODE_MAX_SUBAGENTS_PER_SESSION) to stop runaway delegation loops; /clear resets the budget</p>
|
|
<p>• MCP tool calls running longer than 2 minutes now move to the background automatically so the session stays usable; configure the threshold or disable with CLAUDE_CODE_MCP_AUTO_BACKGROUND_MS</p>
|
|
<p>• Typing /resume in the agent view now opens a picker of past sessions — including sessions deleted from the list — and resumes your pick as a background session</p>
|
|
<p>• Fixed plan mode auto-running file-modifying Bash commands (e.g. touch, rm) without a permission prompt or SDK canUseTool callback</p>
|
|
<p>• Fixed worktree creation following a repository-committed symlink at .claude/worktrees, which could create files outside the repository</p>
|
|
<p>• Fixed a continue:false hook's halt being dropped when the tool fails or completes mid-stream, and hook infrastructure errors being misreported as user rejections</p>
|
|
<p>• Fixed SIGTERM during a running Bash tool orphaning the command's process tree in print/SDK mode; the CLI now aborts the turn, kills the tree, and exits 143</p>
|
|
<p>• Fixed /background and claude --bg failing with "EUNKNOWN: unknown error, uv_spawn" on Windows when Group Policy blocks PowerShell 5.1; the daemon now prefers PowerShell 7</p>
|
|
<p>• Fixed shell mode (!) not executing commands containing file paths while the path autocomplete popup was open</p>
|
|
<p>• Fixed auto-mode denial notifications rendering broken characters when a long denial reason was truncated mid-emoji</p>
|
|
<p>• Fixed Ctrl+J not inserting a newline in the agent view dispatch input on terminals with extended key reporting, and surfaced the newline shortcut in the ? help overlay</p>
|
|
<p>• Fixed /ultrareview rejecting PR references like #123, PR 123, and pasted PR URLs; error hints now name the command you actually typed</p>
|
|
<p>• Fixed /ultrareview &lt;branch&gt; not fetching the branch from origin when it exists remotely; it now suggests the closest branch name on typos</p>
|
|
<p>• Fixed /ultrareview skipping the billing confirmation in a new conversation after /clear</p>
|
|
<p>• Fixed /ultrareview's "not a git repository" error on Claude Desktop now suggesting the project's repository folder instead of terminal commands</p>
|
|
<p>• Fixed hosted (host-managed) sessions failing at startup when repository settings configured mTLS certs, extra CA bundles, or OAuth scopes; these transport settings are now ignored with a warning</p>
|
|
<p>• Fixed a spurious "File has not been read yet" error when editing a file that had been read with offset/limit before resuming a session</p>
|
|
<p>• Fixed ExitWorktree failing with "no active EnterWorktree session" after resuming a session with --continue/--resume in print/SDK mode</p>
|
|
<p>• Fixed the workflow agent grid staying empty for Remote Control clients that join a session mid-run</p>
|
|
<p>• Fixed streaming-mode control requests being marked complete before their handler finished, which could lose the request on session restart</p>
|
|
<p>• Fixed background sessions created with /fork losing their live-parent protection after a state write failure</p>
|
|
<p>• Fixed reopening a stopped background session from the agent view failing silently — it now resumes the session, or shows why it can't and lets you force a restart</p>
|
|
<p>• Fixed agent teams: a stopping teammate could send the leader duplicate idle notifications when team initialization re-ran within a session</p>
|
|
<p>• Fixed the plan-approval dialog footer splitting "ctrl+g to edit in &lt;editor&gt;" apart when the file path is long</p>
|
|
<p>• Fixed the welcome banner keeping its old panel widths after a combined width+height terminal resize in fullscreen mode</p>
|
|
<p>• Fixed diff previews losing their line numbers and +/- markers in narrow layouts</p>
|
|
<p>• Fixed @-mentions attaching nothing after a partial file read, plugin uninstall targeting the wrong marketplace, and false "Command timed out" on exit code 143</p>
|
|
<p>• Fixed OpenTelemetry HTTP exports being rejected with 411/400 by Azure Monitor and other endpoints that don't accept chunked transfer encoding</p>
|
|
<p>• Fixed OTLP event log records missing trace_id/span_id when TRACEPARENT is set in SDK/headless mode</p>
|
|
<p>• Fixed conversations with many images incorrectly failing with "Request too large" errors, and improved the error message to explain the actual cause</p>
|
|
<p>• Fixed web search and web fetch returning "API Error" text as search results or page content when the API was overloaded</p>
|
|
<p>• Improved web search and web fetch reliability by retrying 529 errors and rate-limited requests with bounded backoff</p>
|
|
<p>• Improved prompt caching: the mid-conversation system block now works behind LLM gateways and custom base URLs (Bedrock, Vertex, 1P)</p>
|
|
<p>• Improved background agent attach: cold-attaching now instantly shows the formatted transcript while the session boots, instead of a blank wait</p>
|
|
<p>• Reduced token usage in inter-agent messaging: SendMessage bodies are no longer duplicated into replayed history and tool results</p>
|
|
<p>• Changed /fork to name the copy after your prompt when the session has no title, so the row is recognizable in the agent view</p>
|
|
<p>• Changed bare /btw to reopen the side-question panel on your most recent exchange so you can browse earlier answers</p>
|
|
<p>• Changed the ← footer hint to pulse N done for a moment when a background agent finishes while nothing needs your input</p>
|
|
<p>• Deprecated the Task tool's mode parameter (now ignored); subagents inherit the parent session's permission mode by default</p>
|
|
<p>• Changed Enterprise forceLoginMethod to be enforced for VS Code extension, SDK, setup-token, and install-github-app logins, not just the terminal</p>
|
|
<p>• Changed session transcripts to record the reasoning effort level on each assistant message</p>
|
|
<p>• Changed headless/SDK sessions to apply a set_model control request mid-turn; the next model round-trip uses the new model instead of waiting for the next turn</p>
|
|
<p>• Changed agent view / claude agents --json: sessions waiting on a sandbox, MCP-input, or managed-settings prompt now show as "Needs input" instead of "Working"</p>
|
|
<p>• Updated the auth status panel title from "Cloud authentication" to "Authentication"</p>
|
|
<p>• Corrected an earlier release note (2.1.200): tmux through the 3.6 series lacks synchronized output; newer tmux with support is detected automatically</p></content>
|
|
</entry>
|
|
<entry>
|
|
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.211</id>
|
|
<title>Claude Code v2.1.211</title>
|
|
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.211"/>
|
|
<updated>2026-07-15T23:02:29Z</updated>
|
|
<content type="html"><p>• Added --forward-subagent-text flag and CLAUDE_CODE_FORWARD_SUBAGENT_TEXT environment variable to include subagent text and thinking in stream-json output</p>
|
|
<p>• Fixed permission previews relayed to chat channels not neutralizing bidirectional-override, zero-width, and look-alike quote characters, so tool inputs cannot visually alter the approval message</p>
|
|
<p>• Fixed auto mode overriding a PreToolUse hook's ask decision for unsandboxed Bash — a hook ask now floors the decision at a prompt</p>
|
|
<p>• Fixed parallel Claude Code sessions all logging out simultaneously after wake-from-sleep when many sessions share one credential store</p>
|
|
<p>• Fixed plugin MCP servers not reconnecting after an idle web session woke, leaving MCP calls failing until the next message</p>
|
|
<p>• Fixed Claude Code on Vertex and Bedrock attempting the default Opus model at startup and printing a spurious fallback notice when a model is explicitly configured</p>
|
|
<p>• Fixed subagents spawned with an explicit model override reverting to the parent's model when resumed or sent a follow-up message</p>
|
|
<p>• Fixed nested .claude/rules/*.md files loading even when setting sources exclude project settings</p>
|
|
<p>• Fixed file upload validation: filenames ending in a DOS device suffix (.prn) or trailing dot are now accepted, and files with multiple hard links are refused</p>
|
|
<p>• Fixed file uploads to Claude in Chrome from remote and CLI sessions</p>
|
|
<p>• Fixed edits that leave the input as "?" being silently swallowed and toggling the shortcuts panel</p>
|
|
<p>• Fixed a startup hang when the Claude in Chrome extension is enabled but Chrome is not running</p>
|
|
<p>• Fixed a 300ms delay revealing async content (Settings tabs, Stats, diff views, and other loading states)</p>
|
|
<p>• Fixed reopening a just-stopped background session from the agents view starting a blank conversation under the same session id</p>
|
|
<p>• Fixed /loop hiding the session from /resume after a single use</p>
|
|
<p>• Fixed screen reader users losing the audible terminal bell after /terminal-setup or onboarding terminal setup</p>
|
|
<p>• Fixed background jobs on LLM gateway auth (ANTHROPIC_AUTH_TOKEN + ANTHROPIC_BASE_URL) coming back "Not logged in" after the daemon respawns them</p>
|
|
<p>• Fixed claude agents jobs becoming permanently undeletable when git no longer recognizes their worktree — the row now shows why the delete was refused instead of silently reappearing</p>
|
|
<p>• Fixed /clear not resetting the session cost counter — the statusline's cost now starts at $0 after /clear</p>
|
|
<p>• Fixed Claude in Chrome setup pages failing to open in the browser on Windows</p>
|
|
<p>• Fixed headless print-mode sessions on Windows crashing or silently exiting when stdin is unreadable</p>
|
|
<p>• Fixed background session titles in the agents view showing the naming model's refusal text when the prompt contains a link</p>
|
|
<p>• Fixed background agents killed by the user auto-respawning, and revived agents re-running stale prompts from old sessions</p>
|
|
<p>• Fixed routines with no schedule reporting a next run time in the year 1</p>
|
|
<p>• Hardened synced skill/plugin directory naming on Windows and kept CCR web fetch/search proxies working after /clear</p>
|
|
<p>• Improved terminal layout and rendering performance</p>
|
|
<p>• Improved background agent result reporting — Claude now reports the status of still-running agents and waits for the real completion instead of fabricating results</p>
|
|
<p>• Improved the memory index over-limit warning to measure only loaded content, excluding frontmatter and HTML comments</p>
|
|
<p>• Updated integer environment variables (timeouts, token budgets, retry counts) to accept scientific notation and digit-separator spellings like 1e6 and 64_000</p>
|
|
<p>• Updated documentation links to the current docs sites</p>
|
|
<p>• Changed "always allow" permission rules to save at the repository root, so approvals granted in a git worktree persist across sessions and worktrees</p>
|
|
<p>• Changed /usage-credits to ask for confirmation before sending a request to organization admins</p>
|
|
<p>• Changed Vim mode s and S (substitute char/line) to work in NORMAL mode, matching vim behavior</p>
|
|
<p>• [VSCode] Updated the Remote Control banner to describe what it does</p>
|
|
<p>• Claude in Chrome: hardened file-upload path validation</p>
|
|
<p>• Claude in Chrome: save_to_disk on screenshot actions now writes the image to disk and returns the path; previously it did nothing</p>
|
|
<p>• Fixed a prompt-caching regression on Bedrock, Vertex, Mantle, and Foundry that billed the trailing system context block as fresh input tokens on every request.</p></content>
|
|
</entry>
|
|
<entry>
|
|
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.210</id>
|
|
<title>Claude Code v2.1.210</title>
|
|
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.210"/>
|
|
<updated>2026-07-14T23:45:19Z</updated>
|
|
<content type="html"><p>• Added a live elapsed-time counter to the collapsed tool summary line so long-running tool calls visibly tick instead of looking stuck</p>
|
|
<p>• Added a startup warning for Write(path), NotebookEdit(path), and Glob(path) permission rules — use Edit(path) or Read(path) instead</p>
|
|
<p>• Fixed isolation: 'worktree' subagents being able to run git-mutating commands against the main repo checkout instead of their own isolated worktree</p>
|
|
<p>• Fixed the ultracode keyword opt-in firing on non-human-originated input such as webhook payloads and relayed PR comments</p>
|
|
<p>• Fixed a rendered text fragment leaking into crash telemetry when a UI component returned content outside a styled text element</p>
|
|
<p>• Fixed paste markers leaking into external editors opened from Claude Code, which could appear as stray È/É characters around pasted text</p>
|
|
<p>• Fixed claude attach sometimes failing with "job not found" or "agent is still starting" errors during session transitions — attach now waits for the daemon to settle, and terminal resizes during a slow attach are applied once it completes</p>
|
|
<p>• Fixed a session crash when a tool's result renderer returned a numeric bigint value or plain text instead of a UI element</p>
|
|
<p>• Fixed a hook callback timeout being misreported to the model as a user rejection, which made unattended sessions stop and wait</p>
|
|
<p>• Fixed Claude assuming a cd took effect after its command was moved to the background; the tool result now states the working directory is unchanged</p>
|
|
<p>• Fixed plugin-provided MCP servers being torn down when MCP servers are re-synced mid-session</p>
|
|
<p>• Fixed plan approvals without edits being labeled "(edited by user)" and overwriting the plan file with a stale snapshot</p>
|
|
<p>• Fixed /doctor skipping its auto-mode-default proposal on Bedrock, Vertex, and Foundry, where auto mode no longer needs an opt-in</p>
|
|
<p>• Fixed Grep content mode claiming "No matches found" when paginating past the end of results</p>
|
|
<p>• Fixed unmatched $1/$2 positional placeholders in skills and commands being silently stripped; they are now preserved verbatim</p>
|
|
<p>• Fixed plugin cache writes leaving temp files behind on failure and failing on locked-file renames on Windows and network filesystems</p>
|
|
<p>• Fixed background workers crash-looping when a client resets its connection to the background service</p>
|
|
<p>• Fixed claude agents --effort ultracode not reaching dispatched sessions; the value was silently dropped</p>
|
|
<p>• Fixed pressing ← to open the agents view dropping the task tracker when returning to the session</p>
|
|
<p>• Fixed the agents dashboard retaining pasted images from abandoned reply drafts after their session was deleted</p>
|
|
<p>• Fixed killed background sessions leaving a permanent git worktree lock behind; the periodic sweep now releases locks whose owning process is gone</p>
|
|
<p>• Fixed SDK MCP servers registered via an initialize control request waiting until the next turn to start connecting</p>
|
|
<p>• Fixed returning to the agents view from a session leaving overlapping ghost frames with CLAUDE_CODE_DISABLE_ALTERNATE_SCREEN=1</p>
|
|
<p>• Fixed late-appearing .claude/* symlinks not being reconciled into the sandbox deny-write list</p>
|
|
<p>• Hardened the Agent tool against indirect prompt injection via content a subagent read</p>
|
|
<p>• Improved the Bash/PowerShell tool message when a command hits its timeout and is auto-backgrounded, so the model can distinguish a hang from an explicit background request</p>
|
|
<p>• Improved auto mode: the permission classifier now defaults to Sonnet 5 for external sessions, validated on the session's first request and pinned for the session</p>
|
|
<p>• Improved the bundled dataviz skill's chart color validation with perceptual OKLab color difference and recalibrated color-blindness thresholds</p>
|
|
<p>• Memory writes that leave a MEMORY.md index over its read limit now produce an explicit error instead of silent truncation</p>
|
|
<p>• Screen reader mode now announces permission mode changes aloud when cycling modes with Shift+Tab</p>
|
|
<p>• The agents footer hint now shows how many background agents are waiting on your input, with a brief color emphasis when the count changes</p>
|
|
<p>• Agent view: the session you pressed ← from stays visibly marked even after mouse hover or arrow keys move the selection</p>
|
|
<p>• Fable temporarily shows as unavailable in the advisor picker while a server-side issue causing Fable advisor failures is fixed</p></content>
|
|
</entry>
|
|
<entry>
|
|
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.209</id>
|
|
<title>Claude Code v2.1.209</title>
|
|
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.209"/>
|
|
<updated>2026-07-14T06:36:21Z</updated>
|
|
<content type="html"><p>• Fixed /model and other dialogs being blocked in claude agents background sessions (reverts an overly broad guard)</p></content>
|
|
</entry>
|
|
<entry>
|
|
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.208</id>
|
|
<title>Claude Code v2.1.208</title>
|
|
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.208"/>
|
|
<updated>2026-07-14T01:10:34Z</updated>
|
|
<content type="html"><p>• Added screen reader mode: opt-in plain-text rendering for screen reader users. Run claude --ax-screen-reader, set CLAUDE_AX_SCREEN_READER=1, or add "axScreenReader": true to settings.</p>
|
|
<p>• Added vimInsertModeRemaps setting: map two-key insert-mode sequences like jj to Escape in vim mode</p>
|
|
<p>• Added CLAUDE_CODE_PROCESS_WRAPPER: agent view and the background service now honor a corporate launcher by running every Claude Code self-spawn through a required wrapper executable</p>
|
|
<p>• Added mouse-click support for multi-select menus and "Other" input rows in fullscreen mode</p>
|
|
<p>• Changed the Fable 5 usage-credits consent prompt to start with the decline option focused</p>
|
|
<p>• Fixed fast mode staying off after switching back to a model that supports it — it now restores automatically when enabled in settings</p>
|
|
<p>• Fixed replies typed to a background agent being lost when delivery fails — the text is now saved and delivered when the session restarts</p>
|
|
<p>• Fixed background-session attach failing permanently ("Couldn't start the background daemon") after an update replaced the binary a running claude agents process was launched from</p>
|
|
<p>• Fixed the context window (and auto-compact indicator) briefly resetting to 200k after the CLI auto-updates, causing a false "100% context used" when resuming long-context sessions</p>
|
|
<p>• Fixed supervised and background sessions crashing when a server closed an HTTP/2 connection with a GOAWAY while requests were in flight</p>
|
|
<p>• Fixed truncated stream-json/JSON output and missing result message when piping large responses from claude -p</p>
|
|
<p>• Fixed CLAUDE_CODE_MAX_OUTPUT_TOKENS and similar env vars silently using the mantissa of scientific-notation values (1e6 became 1)</p>
|
|
<p>• Fixed very large markdown tables stalling rendering or using excessive memory; tables over 200 rows show the first 200 with a "… N more rows" notice</p>
|
|
<p>• Fixed the Edit tool failing on files modified after reading when the target text still matches uniquely</p>
|
|
<p>• Fixed Read reporting empty files as "shorter than offset", Grep silently returning "No files found" for invalid regex patterns, Grep count mode under-reporting totals when paginated, and Glob crashing with an unclear error when the pattern, path, or working directory contained a null byte</p>
|
|
<p>• Fixed apiKeyHelper script failures being hidden behind a generic 401 after ~10 silent retries; the script's own error is now shown within 3 attempts</p>
|
|
<p>• Fixed Bedrock streaming requests failing with a misleading "Truncated event message received" when a gateway transforms the response — the error now names the content-type and points at the proxy</p>
|
|
<p>• Fixed /upgrade showing a login flow instead of the upgrade URL when the browser fails to open</p>
|
|
<p>• Fixed stream-json input killing the session on blank CRLF or whitespace-only lines from Windows-style SDK hosts</p>
|
|
<p>• Fixed headless stream-json sessions hanging permanently when a control_request carried a non-string set_model payload; the CLI now answers with an error response</p>
|
|
<p>• Fixed repeated "No completion record was found" notices on session resume — orphaned background tasks now collapse into a single summary</p>
|
|
<p>• Fixed Remote Control clients attaching to a terminal-hosted session not seeing background agents and workflow progress until a task started or stopped</p>
|
|
<p>• Fixed the Agent tool launching with no tools when a subagent's tools list resolves to nothing — it now returns a clear error naming the unrecognized entries</p>
|
|
<p>• Fixed /usage showing stale cached bars over fresher data, and /mcp not reclassifying placeholder servers after config edits</p>
|
|
<p>• Fixed "Change directory" in SDK hosts (e.g. Claude Desktop) failing with "A turn is in progress" on idle sessions that have a running background task</p>
|
|
<p>• Fixed the workflow save dialog showing ~/.claude/workflows/ instead of the CLAUDE_CONFIG_DIR location for user-scope saves</p>
|
|
<p>• Fixed /release-notes adding the viewed notes to the model's context — "Show all" previously injected the entire changelog into every subsequent request</p>
|
|
<p>• Fixed a memory leak in the agent view where pasted images were retained for the screen's lifetime after sending peek replies</p>
|
|
<p>• Fixed SDK sessions losing agents defined via the initialize request when a plugin refresh ran before the client attached</p>
|
|
<p>• Fixed several memory leaks in long sessions: MCP stdio server stderr accumulating up to 64 MB per server, LSP documents staying open indefinitely (now LRU with 50-doc cap), async hook output retained after backgrounding, and unbounded growth in headless/SDK sessions from large tool-result payloads</p>
|
|
<p>• Fixed a memory blowup when reading files with extremely long single lines using offset/limit — the read now returns a clean error instead of loading the whole line</p>
|
|
<p>• Fixed multi-second per-turn slowdowns in sessions with many permission deny/ask rules — rule matchers are now compiled once and cached</p>
|
|
<p>• Improved input responsiveness while agent task lists update — task updates no longer re-render the entire UI</p>
|
|
<p>• Reduced per-tool-call CPU overhead in print/SDK sessions with many MCP tools by caching tool-pool assembly (up to 7x faster tool rounds at high tool counts)</p>
|
|
<p>• Reduced memory usage by bounding the file edit read cache to 16 MB instead of pinning up to 1,000 full files</p>
|
|
<p>• Reduced session transcript size (up to 79x in edit-heavy sessions) and bounded checkpoint disk usage by pruning superseded file-history backups</p>
|
|
<p>• Reduced memory usage when resuming sessions with background agents or forks spawned from large conversations</p>
|
|
<p>• Completed background agents now stay listed in /tasks until cleanup instead of vanishing the moment they finish</p>
|
|
<p>• Attaching to a stopped background agent now shows its transcript immediately while the session warms up, instead of a blank "Session is starting" screen</p>
|
|
<p>• Background sessions: an older daemon no longer silently restarts workers spawned by a newer version onto the older binary</p>
|
|
<p>• Agent view: Ctrl+X now deletes renamed-branch worktrees, never destroys unpushed commits, keeps the session row when a worktree is kept, and reused worktree names reset to the current base</p>
|
|
<p>• Catastrophic removals (e.g. rm -rf ~) in commands containing $(…)/backticks/&lt;(…) now prompt in --dangerously-skip-permissions and auto mode, matching the plain form</p>
|
|
<p>• /install-github-app and the /mcp settings menu no longer open in background sessions</p>
|
|
<p>• MCP servers configured with an empty URL now show as "not configured" in /mcp instead of a config error</p>
|
|
<p>• /usage now shows your last-known usage bars with an "as of" note when the usage endpoint is rate-limited, instead of an error screen</p>
|
|
<p>• Fixed Bedrock auth failing with "Session token not found or invalid" for AWS SSO profiles whose sso_region differs from the Bedrock region (2.1.207 regression)</p></content>
|
|
</entry>
|
|
<entry>
|
|
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.207</id>
|
|
<title>Claude Code v2.1.207</title>
|
|
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.207"/>
|
|
<updated>2026-07-11T00:52:04Z</updated>
|
|
<content type="html"><p>• Auto mode is now available without CLAUDE_CODE_ENABLE_AUTO_MODE opt-in on Bedrock, Vertex AI, and Foundry; disable via disableAutoMode in settings</p>
|
|
<p>• Fixed the terminal freezing and keystrokes lagging while streaming responses containing very long lists, tables, paragraphs, or code blocks</p>
|
|
<p>• Fixed remote managed settings from a non-interactive run (claude -p, the SDK) being permanently recorded as consented without ever showing the security consent dialog</p>
|
|
<p>• Fixed spurious prompt-injection warnings triggered by benign system-generated conversation updates</p>
|
|
<p>• Fixed the auto-updater overwriting a custom launcher script or symlink at ~/.local/bin/claude on every release; /doctor now reports an externally managed launcher</p>
|
|
<p>• Fixed compound commands with cd prompting for permission when the only output redirect was to /dev/null</p>
|
|
<p>• Fixed the transcript jumping above the start of the answer when a response finishes streaming</p>
|
|
<p>• Fixed extensions.worktreeConfig being left in the repo's .git/config (breaking go-git tools like tea) after the last worktree.sparsePaths worktree was removed</p>
|
|
<p>• Fixed malformed bracket patterns in rules globs, skill paths, .ignore, and .worktreeinclude breaking file reads, file suggestions, and worktree creation</p>
|
|
<p>• Fixed a crash loop in agent teams where a malformed teammate mailbox message caused repeated errors every second until the mailbox file was manually deleted</p>
|
|
<p>• Fixed background sessions auto-named by accepting a plan not showing that name on their agent-view row</p>
|
|
<p>• Fixed background sessions that entered a git worktree resuming blank after a cold reopen from the agent list</p>
|
|
<p>• Fixed Remote Control task status updates being lost when the connection recovered from a network interruption or credential refresh</p>
|
|
<p>• Fixed Remote Control sessions hosted by the desktop app not showing background agent and workflow progress on mobile and web</p>
|
|
<p>• Fixed Deep research runs labeling every Fetch-phase agent "unknown" — chips now show the source hostname</p>
|
|
<p>• Fixed Bedrock repeatedly requesting fresh AWS SSO credentials from IAM Identity Center on every API request</p>
|
|
<p>• Improved agent view: pasting the same text again now expands the collapsed [Pasted text #N] placeholder instead of adding a second one</p>
|
|
<p>• Improved agent view: blocked session peeks now lead with the question and show a worded staleness clock (waiting 3m) instead of the same timestamp twice</p>
|
|
<p>• Changed Bedrock, Vertex, and Claude Platform on AWS to default to Claude Opus 4.8</p>
|
|
<p>• Changed auto mode to no longer read autoMode from .claude/settings.local.json (repo-resident); use ~/.claude/settings.json instead</p>
|
|
<p>• Fixed an indefinite hang on Windows when AWS credential resolution stalls (e.g. a stuck credential_process): the 60-second stall guard now fires instead of waiting forever.</p>
|
|
<p>• Plugin hooks/monitors/MCP headersHelper: ${user_config.*} in shell-form commands is now rejected (shell-injection fix). Hooks: use exec form (args array) or $CLAUDE_PLUGIN_OPTION_&lt;KEY&gt;; monitors and headersHelper: read the value inside the script (config file or the server's env block).</p>
|
|
<p>• Plugin option values (pluginConfigs) are no longer read from project-level .claude/settings.json; only user, --settings, and managed settings are honored</p>
|
|
<p>• Fixed /usage-credits amount inputs silently stripping malformed values (e.g. a pasted timestamp) to digits; malformed amounts are now rejected with an error, and amounts over $1,000 require a typed confirmation</p></content>
|
|
</entry>
|
|
<entry>
|
|
<id>https://github.com/anthropics/claude-code/releases/tag/v2.1.206</id>
|
|
<title>Claude Code v2.1.206</title>
|
|
<link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.206"/>
|
|
<updated>2026-07-09T23:34:23Z</updated>
|
|
<content type="html"><p>• Added directory path suggestions to /cd, matching /add-dir behavior</p>
|
|
<p>• Added a /doctor check that proposes trimming checked-in CLAUDE.md files by cutting content Claude could derive from the codebase</p>
|
|
<p>• /commit-push-pr now auto-allows git push to the repo's configured push remote (remote.pushDefault, or the sole remote when only one is configured) in addition to origin</p>
|
|
<p>• Gateway: /login now supports Anthropic-operated public gateway endpoints</p>
|
|
<p>• EnterWorktree now asks for confirmation before entering a git worktree outside the project's .claude/worktrees/ directory</p>
|
|
<p>• Background agents now upgrade to a new version in the background right after a Claude Code update, instead of paying a slow stale-session upgrade when you attach</p>
|
|
<p>• Fixed an expired login failing every model with a misleading "There's an issue with the selected model" error instead of prompting to run /login</p>
|
|
<p>• Fixed claude --resume and --continue not responding to keyboard input on startup</p>
|
|
<p>• Fixed MCP servers configured via --mcp-config or .mcp.json ignoring a per-server request_timeout_ms, which caused long-running MCP tool calls to time out at the 60s default in fresh sessions</p>
|
|
<p>• Fixed CLAUDE_CODE_EXTRA_BODY being silently ignored by claude agents / --bg background workers; the shell-exported override now follows the dispatching session</p>
|
|
<p>• Fixed OAuth MCP servers requiring manual re-authentication after a single failed token refresh</p>
|
|
<p>• Fixed --permission-prompt-tool pointing at an MCP server crashing with "MCP tool not found" on cold start before the server finishes connecting</p>
|
|
<p>• Fixed /model picker rows printing a price for a different model than the row named, and stopped quoting first-party list prices on providers that don't bill them</p>
|
|
<p>• Fixed server-provided model rows being misplaced in the /model picker when an entitlement or allowlist restriction drops the row they were positioned against</p>
|
|
<p>• Fixed desktop sessions getting stuck showing "running" after a slash command was sent mid-turn</p>
|
|
<p>• Fixed keyboard input being ignored in the agents view when a setup prompt appeared before a bare claude --resume on Windows</p>
|
|
<p>• Fixed claude rm leaving the removed job in the daemon roster, causing the row to reappear in claude agents</p>
|
|
<p>• Fixed /remote-control showing "Unknown command" when logged out — it now explains how to sign in</p>
|
|
<p>• Fixed left arrow not stepping back out of a phase or agent in the workflow detail view</p>
|
|
<p>• Fixed /status listing the same broken-install warning twice</p>
|
|
<p>• Fixed false "disused plugin" tips and skewed disuse telemetry for LSP plugins</p>
|
|
<p>• Fixed /doctor's update check to compare Homebrew installs against their cask's channel instead of the settings channel</p>
|
|
<p>• Fixed the fullscreen jump-to-bottom pill suggesting Ctrl+End on macOS, not showing rebound chords, and wrapping over the transcript</p>
|
|
<p>• Bedrock: fixed a multi-minute startup hang when using an awsCredentialExport helper on networks with restricted egress</p>
|
|
<p>• Improved /code-review findings quality on claude-opus-4-8 across all effort levels</p>
|
|
<p>• Improved agents view: status column now uses full terminal width instead of truncating at 64 characters</p>
|
|
<p>• Changed agents view: Ctrl+X now permanently removes a completed session, and sessions no longer render twice; deleted background jobs stay deleted</p></content>
|
|
</entry>
|
|
</feed>
|