Preflight Checklist
What's Wrong?
Claude Code Desktop App's built-in Sparkle auto-updater silently upgraded from 1.10628.0 → 1.11187.4 overnight on 2026-06-09 at ~00:49 AM local time, without any authorization, warning, or consent.
The update's initialization logic wiped the entire ~/.claude/projects/ directory, destroying ALL .jsonl session files — approximately 1 month of accumulated conversations (2026-05-09 through 2026-06-08). No warning. No backup. No rollback. Nothing.
Critical design flaws:
autoUpdates: false in ~/.claude/settings.json does NOT apply to the Desktop App — only the CLI. Undocumented.
-
- No default backup of
~/.claude/projects/
-
- No pre-update snapshot or rollback mechanism
-
- Update ran silently at 00:49 AM with no user consent
Log evidence (~/Library/Logs/Claude/main.log):
[updater] Version changed since last launch: 1.10628.0 → 1.11187.4
Recovery path for affected users (undocumented!):
Session data also exists in:
~/Library/Application Support/Claude/local-agent-mode-sessions/<org>/<session>/local_<id>/audit.jsonl
This directory survived the update. Users can recover conversations from audit.jsonl files. Anthropic should communicate this immediately to all affected users.
What Should Happen?
autoUpdates: false MUST disable Desktop App auto-updates (or be clearly documented that it doesn't)
-
- Add a UI toggle to disable Desktop App auto-updates
-
- Enable local auto-backup of
~/.claude/projects/ by default (daily snapshots, 30-day retention)
-
- Mandatory pre-update snapshot of
~/.claude/projects/ before ANY update
-
- Implement rollback mechanism if update causes data loss
-
- Require explicit user consent before updating — prohibit silent overnight updates
-
- Publicly document the
local-agent-mode-sessions/audit.jsonl recovery path
-
- Proactively notify all users w[updater] Version changed since last launch: 1.10628.0 → 1.11187.4
- From: ~/Library/Logs/Claude/main.log
- Timestamp: 2026-06-09 14:11 UTC
- ~/.claude/projects/ directory rebuild timestamp: 2026-06-09 00:49 AM local time
- All .jsonl files from prior month: DELETED
- Affected versions: Desktop App 1.10628.0 → 1.11187.4, CLI 2.1.165
- Platform: macOS Apple Silicon
- User UUID: 251a9628-3209-4a87-bc2b-cd045f19e334ho may have been affected by this update
Error Messages/Logs
[updater] Version changed since last launch: 1.10628.0 -> 1.11187.4
File: ~/Library/Logs/Claude/main.log
Timestamp: 2026-06-09 14:11 UTC
~/.claude/projects/ rebuilt: 2026-06-09 00:49 AM local
All .jsonl session files: PERMANENTLY DELETED
Steps to Reproduce
- Install Claude Code Desktop App and use it for several weeks
-
- Accumulate session files in ~/.claude/projects/
-
- Set autoUpdates: false in ~/.claude/settings.json (thinking this disables all updates)
-
- Leave the app closed overnight
-
- Wake up the next morning and open Claude Code Desktop
Expected: All previous sessions intact
Actual: ~/.claude/projects/ recreated empty; all .jsonl session files gone
Note: The autoUpdates: false flag only controls CLI updates. The Desktop App's Sparkle updater ignores it completely and runs independently. There is no documented way to disable it.
Claude Model
None
Is this a regression?
Yes, this worked in a previous version
Last Working Version
1.10628.0
Claude Code Version
2.1.165 (Desktop App 1.11187.4)
Platform
Anthropic API
Operating System
macOS
Terminal/Shell
Terminal.app (macOS)
Additional Information
Full incident report filed to: [email protected] + [email protected]
Account: [email protected]
IMPORTANT for all affected users: Session data survives in audit.jsonl files at:
~/Library/Application Support/Claude/local-agent-mode-sessions///local_/audit.jsonl
This recovery path is completely undocumented. Anthropic must communicate this to all users affected by recent Desktop App auto-updates.
Preflight Checklist
What's Wrong?
Claude Code Desktop App's built-in Sparkle auto-updater silently upgraded from
1.10628.0→1.11187.4overnight on 2026-06-09 at ~00:49 AM local time, without any authorization, warning, or consent.The update's initialization logic wiped the entire
~/.claude/projects/directory, destroying ALL.jsonlsession files — approximately 1 month of accumulated conversations (2026-05-09 through 2026-06-08). No warning. No backup. No rollback. Nothing.Critical design flaws:
autoUpdates: falsein~/.claude/settings.jsondoes NOT apply to the Desktop App — only the CLI. Undocumented.~/.claude/projects/Log evidence (
~/Library/Logs/Claude/main.log):Recovery path for affected users (undocumented!):
Session data also exists in:
This directory survived the update. Users can recover conversations from
audit.jsonlfiles. Anthropic should communicate this immediately to all affected users.What Should Happen?
autoUpdates: falseMUST disable Desktop App auto-updates (or be clearly documented that it doesn't)~/.claude/projects/by default (daily snapshots, 30-day retention)~/.claude/projects/before ANY updatelocal-agent-mode-sessions/audit.jsonlrecovery pathError Messages/Logs
Steps to Reproduce
Expected: All previous sessions intact
Actual: ~/.claude/projects/ recreated empty; all .jsonl session files gone
Note: The autoUpdates: false flag only controls CLI updates. The Desktop App's Sparkle updater ignores it completely and runs independently. There is no documented way to disable it.
Claude Model
None
Is this a regression?
Yes, this worked in a previous version
Last Working Version
1.10628.0
Claude Code Version
2.1.165 (Desktop App 1.11187.4)
Platform
Anthropic API
Operating System
macOS
Terminal/Shell
Terminal.app (macOS)
Additional Information
Full incident report filed to: [email protected] + [email protected]
Account: [email protected]
IMPORTANT for all affected users: Session data survives in audit.jsonl files at:
~/Library/Application Support/Claude/local-agent-mode-sessions///local_/audit.jsonl
This recovery path is completely undocumented. Anthropic must communicate this to all users affected by recent Desktop App auto-updates.