<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/" xml:lang="en-US">
  <id>tag:github.com,2008:https://github.com/anthropics/claude-code/releases</id>
  <link type="text/html" rel="alternate" href="https://github.com/anthropics/claude-code/releases"/>
  <link type="application/atom+xml" rel="self" href="https://github.com/anthropics/claude-code/releases.atom"/>
  <title>Release notes from claude-code</title>
  <updated>2026-10-08T05:03:36Z</updated>
  <entry>
    <id>tag:github.com,2008:Repository/937253475/v2.1.294</id>
    <updated>2026-10-08T05:03:54Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.294"/>
    <title>v2.1.294</title>
    <content type="html">&lt;h2&gt;What&#39;s changed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Fixed &lt;code&gt;prompt&lt;/code&gt; and &lt;code&gt;agent&lt;/code&gt; hooks written as instructions (such as &quot;Block commands that...&quot;) allowing what they should block&lt;/li&gt;
&lt;li&gt;Improved how &lt;code&gt;prompt&lt;/code&gt; hooks on Stop and SubagentStop written as instructions (such as &quot;Carry on if the build is broken&quot;) are judged, so Claude is less likely to stop early&lt;/li&gt;
&lt;/ul&gt;</content>
    <author>
      <name>ashwin-ant</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/178951676?s=60&amp;v=4"/>
  </entry>
  <entry>
    <id>tag:github.com,2008:Repository/937253475/v2.1.293</id>
    <updated>2026-10-07T18:10:20Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.293"/>
    <title>v2.1.293</title>
    <content type="html">&lt;h2&gt;What&#39;s changed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Added Claude Haiku 5.5 (&lt;code&gt;claude-haiku-5-5&lt;/code&gt;), now the default Haiku model on the Anthropic API — 1M context, $0.10/$0.50 per Mtok ($0.50/$2.50 for prompts over 100K)&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;agentType&lt;/code&gt; to the &lt;code&gt;subagentStatusLine&lt;/code&gt; payload, so scripts can tell custom subagent types apart&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;isDeferred&lt;/code&gt; to &lt;code&gt;$.tool.register&lt;/code&gt; for mods: &lt;code&gt;false&lt;/code&gt; lists the tool&#39;s schema in the prompt from the start instead of behind tool search&lt;/li&gt;
&lt;li&gt;Fixed Claude sometimes treating its own last actions before a context compaction as done after it, and retracting or redoing finished work&lt;/li&gt;
&lt;li&gt;Fixed a memory leak where an HTTP MCP connection kept every request it had sent until it closed&lt;/li&gt;
&lt;li&gt;Fixed a message sent while Claude was working being lost when &lt;code&gt;←&lt;/code&gt; moved the session to the background; if a queued message can&#39;t move, &lt;code&gt;←&lt;/code&gt; now stays put and says so&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/model&lt;/code&gt; effort ←/→ wrapping past the highest or lowest level, which could accidentally save Low as a model&#39;s default effort&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/tui&lt;/code&gt; disconnecting Claude in Chrome in a session started with &lt;code&gt;--chrome&lt;/code&gt;, and ignoring &lt;code&gt;--no-chrome&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fixed Claude being told to continue or message subagents with &lt;code&gt;SendMessage&lt;/code&gt; in sessions, including resumed ones, where a host, a permission rule or a &lt;code&gt;--tools&lt;/code&gt; list removed that tool&lt;/li&gt;
&lt;li&gt;Fixed subagents and &lt;code&gt;--agent&lt;/code&gt; sessions being told a built-in tool was disabled for the whole session when only their own tool list left it out&lt;/li&gt;
&lt;li&gt;Fixed a claude.ai-synced skill&#39;s edited description sometimes not reaching the model until a new conversation or &lt;code&gt;/clear&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude logs&lt;/code&gt;, &lt;code&gt;stop&lt;/code&gt;, &lt;code&gt;kill&lt;/code&gt;, &lt;code&gt;rm&lt;/code&gt; and &lt;code&gt;claude daemon status&lt;/code&gt;, &lt;code&gt;stop&lt;/code&gt;, &lt;code&gt;uninstall&lt;/code&gt; sometimes signing you out when your login had expired or was about to&lt;/li&gt;
&lt;li&gt;Fixed the footer&#39;s agents count disappearing after a momentary failure to read the sessions folder (for example, too many open files)&lt;/li&gt;
&lt;li&gt;Fixed a custom agent named &lt;code&gt;worker&lt;/code&gt; being shown as &quot;Agent&quot; when it starts, and the agent detail dialog&#39;s title losing the agent type once the agent finishes&lt;/li&gt;
&lt;li&gt;Fixed the Artifact tool&#39;s transcript row briefly reading &lt;code&gt;Artifact(&quot;(unprintable path)&quot;)&lt;/code&gt; while a publish call was still streaming in&lt;/li&gt;
&lt;li&gt;Fixed the &lt;code&gt;/ultrareview&lt;/code&gt; upload on Linux wrongly refusing some repositories, such as one inside another checkout, over a settings file that &quot;could not be parsed&quot; while a sandboxed command was running&lt;/li&gt;
&lt;li&gt;Fixed the &lt;code&gt;/ultrareview&lt;/code&gt; upload&#39;s refusal over split-index files advising a git command that could leave git unable to read its index&lt;/li&gt;
&lt;li&gt;Fixed replies in very long Remote Control and cloud sessions that could still appear a block at a time instead of streaming in&lt;/li&gt;
&lt;li&gt;Fixed Remote Control uploading a session&#39;s starting history again after every credential recovery&lt;/li&gt;
&lt;li&gt;Fixed PushNotification reporting &quot;Remote Control inactive&quot; in sessions started with &lt;code&gt;claude remote-control&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fixed a mod&#39;s hooks on &lt;code&gt;classic.*&lt;/code&gt; events being skipped while the plugin hooks worker restarts, which left settings hooks to answer without them&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude plugin test&lt;/code&gt; failing for mods that call &lt;code&gt;$.session.append&lt;/code&gt;; tests can read the appended rows back with the new &lt;code&gt;mock.session&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude plugin eval&lt;/code&gt; refusing every Bash-granting run on Macs with Docker Desktop (links under &lt;code&gt;~/.docker/bin&lt;/code&gt;); the refusal now names which part of a credential store held the link&lt;/li&gt;
&lt;li&gt;Fixed the Claude apps gateway refusing to start when a &lt;code&gt;desktop&lt;/code&gt; policy sets Claude Desktop&#39;s built-in browser keys, such as &lt;code&gt;builtinBrowserEnabled&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude agents&lt;/code&gt; offering bypass permissions that background sessions then ignored when consent was saved only in &lt;code&gt;.claude/settings.local.json&lt;/code&gt; or a &lt;code&gt;--settings&lt;/code&gt; file; it now asks for consent first, and a session that ignores bypass shows a short notice that stays&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;←&lt;/code&gt; backgrounding a session after 10 seconds while the prompt held unsent text (it now cancels the move) or a question was waiting for your answer&lt;/li&gt;
&lt;li&gt;Fixed Esc, or No without feedback, on a permission prompt not stopping the turn when &lt;code&gt;←&lt;/code&gt; had just been pressed to move the session to the background&lt;/li&gt;
&lt;li&gt;Fixed the agents view briefly replacing the session list with placeholder rows when the sessions folder could not be read (for example, too many open files)&lt;/li&gt;
&lt;li&gt;Fixed path-scoped rules and nested CLAUDE.md files not loading when Claude views a file with a single-file cat, head, tail, sed -n or grep command in the Bash tool instead of the Read tool&lt;/li&gt;
&lt;li&gt;Fixed pasted text that begins and ends with the same words sometimes being sent to Claude as if it had been typed&lt;/li&gt;
&lt;li&gt;Fixed a skill name in pasted text being treated as typed when an accent typed or pasted right after the paste merged into its last letter&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/feedback&lt;/code&gt; returning to the drafts list after Ctrl+O or Ctrl+Z while a report was sending, leaving the send impossible to cancel&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude purge&lt;/code&gt; stopping silently (exit 0, or a hang in a terminal) when a file or folder could not be deleted; it now deletes the rest, lists what it could not delete, and exits 1&lt;/li&gt;
&lt;li&gt;Fixed keybindings.json checks: a lone &quot; &quot; (space key) is no longer reported as an error, and keys like &quot;ctrl+ k&quot; now get a warning&lt;/li&gt;
&lt;li&gt;Fixed vim mode &lt;code&gt;&amp;gt;&amp;gt;&lt;/code&gt; and &lt;code&gt;&amp;lt;&amp;lt;&lt;/code&gt; on a line of only spaces leaving the cursor past the end of the line, where a following &lt;code&gt;x&lt;/code&gt; deleted nothing&lt;/li&gt;
&lt;li&gt;Fixed vim mode: after deleting whole lines in Visual mode (&lt;code&gt;V&lt;/code&gt; then &lt;code&gt;d&lt;/code&gt;) the cursor lands on the first non-blank, and &lt;code&gt;.&lt;/code&gt; after it acts on the cursor&#39;s line&lt;/li&gt;
&lt;li&gt;Windows: Fixed stopping a status line, hook, or shell command sometimes terminating an unrelated process that had been given the same process ID&lt;/li&gt;
&lt;li&gt;Reverted the auto mode denial message change from 2.1.281 that told Claude a denial covers the outcome, not only the exact command&lt;/li&gt;
&lt;li&gt;Reverted the 2.1.290 fix for cloud sessions staying asleep after a container restart lost a pending &lt;code&gt;/loop&lt;/code&gt; wakeup or scheduled task; Claude is no longer told, and the session stays asleep&lt;/li&gt;
&lt;li&gt;Improved startup for Team and Enterprise organizations: policy and managed settings are fetched earlier, and a stalled request is retried after 3 seconds&lt;/li&gt;
&lt;li&gt;Improved Claude in Chrome: fewer page actions are refused when the browser is slow to report its tabs&lt;/li&gt;
&lt;li&gt;Improved the Claude in Chrome message in cloud sessions when the browser can&#39;t be reached: if you belong to more than one organization, it now says the extension must be signed in to the same one, and how to change that&lt;/li&gt;
&lt;li&gt;Improved the Bash edit diff note to say the listed files changed while the command ran, which can include writes by other processes&lt;/li&gt;
&lt;li&gt;Improved artifacts: Claude pins libraries to exact versions two weeks old or older&lt;/li&gt;
&lt;li&gt;Changed claude.ai skill syncing to check for changes about every 40 minutes, instead of every 10, while no session is in use&lt;/li&gt;
&lt;li&gt;Changed the order of agent lists and of MCP servers announced to the model: names with non-ASCII characters now sort after ASCII names&lt;/li&gt;
&lt;li&gt;Changed OpenTelemetry &lt;code&gt;claude_code.at_mention&lt;/code&gt; logging to emit at most 100 agent and 100 MCP-resource events each time a prompt is read&lt;/li&gt;
&lt;li&gt;Self-hosted runner: Changed the orchestrator to sleep 4 to 6 seconds between polls instead of a constant 5, so several replicas for one environment stop polling at the same moment&lt;/li&gt;
&lt;li&gt;[Claude Tag] Fixed Claude in Slack saying a workspace isn&#39;t set up in Enterprise Grid channels shared across workspaces when Slack labels a message with a workspace that isn&#39;t connected&lt;/li&gt;
&lt;li&gt;[Claude Tag] Fixed Claude in Slack stopping mid-task in a channel when an admin changed the channel&#39;s connectors, plugins, skills or rules; the change now applies once Claude finishes&lt;/li&gt;
&lt;li&gt;[Claude Tag] Fixed asking Claude in Slack to run a thread&#39;s routine now with extra notes starting a separate run that couldn&#39;t post back; the run now continues in that thread&lt;/li&gt;
&lt;li&gt;[Claude Tag] Fixed an access bundle&#39;s Add a connector dialog in Claude Tag admin settings showing every Google connector as connected after one Google sign-in&lt;/li&gt;
&lt;li&gt;[Claude Tag] Improved Claude Tag admin settings to list an Enterprise Grid that isn&#39;t connected yet, with a Connect button&lt;/li&gt;
&lt;li&gt;[Claude Tag] Changed Claude in Slack to join announcement channels, where only admins can post, without posting its intro&lt;/li&gt;
&lt;li&gt;[Claude Tag] Changed the limit on channel rules in Claude Tag admin settings from 20 to 50 for each workspace and for the organization-wide Slack page&lt;/li&gt;
&lt;li&gt;[Code Review] Improved Code Review&#39;s Add a repository dialog to list each repository that couldn&#39;t be added and why, such as missing GitHub write access&lt;/li&gt;
&lt;/ul&gt;</content>
    <author>
      <name>ashwin-ant</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/178951676?s=60&amp;v=4"/>
  </entry>
  <entry>
    <id>tag:github.com,2008:Repository/937253475/v2.1.292</id>
    <updated>2026-10-06T18:59:30Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.292"/>
    <title>v2.1.292</title>
    <content type="html">&lt;h2&gt;What&#39;s changed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Added &lt;code&gt;--marketplace &amp;lt;source&amp;gt;&lt;/code&gt; to &lt;code&gt;claude plugin install&lt;/code&gt;: adds the marketplace if needed, under the same policy checks as &lt;code&gt;claude plugin marketplace add&lt;/code&gt;, then installs the plugin from it&lt;/li&gt;
&lt;li&gt;Added an &lt;code&gt;effort&lt;/code&gt; parameter to the Agent tool, so Claude runs a sub-agent at the effort level you ask for&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MS&lt;/code&gt; environment variable to set a longer base delay for the backoff when retrying an overloaded (529) request&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;prompt.autocomplete&lt;/code&gt;, an event a mod hooks to add its own rows to the prompt box&#39;s autocomplete list&lt;/li&gt;
&lt;li&gt;Added prompt caching to &lt;code&gt;$.model.complete&lt;/code&gt; for mods: &lt;code&gt;prompt&lt;/code&gt; and &lt;code&gt;system&lt;/code&gt; take blocks of text, and &lt;code&gt;cache: true&lt;/code&gt; on a block caches the request up to it&lt;/li&gt;
&lt;li&gt;Added workflow agents to the &lt;code&gt;agent.spawn&lt;/code&gt; mod hook, with their run and index, so a mod can refuse them&lt;/li&gt;
&lt;li&gt;Fixed subagent definitions with &lt;code&gt;permissionMode: auto&lt;/code&gt; entering auto mode when auto mode is unavailable (disabled by settings, circuit breaker, or a model that doesn&#39;t support it)&lt;/li&gt;
&lt;li&gt;Fixed sandboxed commands being able to read the staged file copies of &lt;code&gt;/ultrareview&lt;/code&gt; uploads under &lt;code&gt;~/.claude/seed-admin&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fixed a managed sandbox read-deny path (and user ones beside it) that appears or re-points mid-session not dropping project grants inside it or ending credential injection from files it covers&lt;/li&gt;
&lt;li&gt;Fixed a notebook or PDF read on macOS and Windows being able to return a file outside what was approved, through a link swapped in mid-read&lt;/li&gt;
&lt;li&gt;Fixed a tampered on-disk cache of server-managed settings being able to switch off or unseat the built-in policy plugin while the settings fetch failed&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;rm -rf&lt;/code&gt; on the 8.3 short name or another alternate Windows spelling of the home folder or a drive not being treated as removing it&lt;/li&gt;
&lt;li&gt;Security: Fixed PreToolUse hook approvals and auto mode bypassing the permission prompt for file reads from network (UNC) paths&lt;/li&gt;
&lt;li&gt;Fixed a skill&#39;s or slash command&#39;s &lt;code&gt;allowed-tools&lt;/code&gt; rule coming back in a later turn when you leave auto mode or plan mode partway through that turn&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;NO_PROXY&lt;/code&gt; being ignored for Claude Code&#39;s own API requests (sign-in, policy, feedback, artifacts) when &lt;code&gt;HTTPS_PROXY&lt;/code&gt; is set&lt;/li&gt;
&lt;li&gt;Fixed an MCP tool with a name longer than 128 characters making every request fail; that tool is now left out and an MCP error names it&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude plugin&lt;/code&gt; commands such as &lt;code&gt;marketplace add&lt;/code&gt; and &lt;code&gt;install&lt;/code&gt; running before an organization&#39;s managed settings had loaded on a first run&lt;/li&gt;
&lt;li&gt;Fixed one-shot &lt;code&gt;claude -p&lt;/code&gt; and Agent SDK runs stopping a background command 5 seconds after the final result, and one-shot &lt;code&gt;claude -p&lt;/code&gt; runs dropping a scheduled wakeup; both are now waited for&lt;/li&gt;
&lt;li&gt;Fixed plan mode not being restored when resuming a session from the &lt;code&gt;claude --resume&lt;/code&gt; session picker or with &lt;code&gt;/resume&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fixed saved scheduled tasks created after &lt;code&gt;/resume&lt;/code&gt;, &lt;code&gt;/branch&lt;/code&gt; or &lt;code&gt;/clear&lt;/code&gt; never firing, and saved tasks ignoring later creates and deletes after two writes to the tasks file milliseconds apart&lt;/li&gt;
&lt;li&gt;Fixed a background session&#39;s &lt;code&gt;/loop&lt;/code&gt; silently stopping when the session&#39;s process restarted (for example after a crash), because its pending wakeup was lost&lt;/li&gt;
&lt;li&gt;Fixed Grep and Glob reporting no matches when the file or folder they were given could not be read; Claude now retries once or tells you&lt;/li&gt;
&lt;li&gt;Fixed the Read tool returning only the first entry, with no error, when a PDF&#39;s &lt;code&gt;pages&lt;/code&gt; was a list such as &quot;6,9,15&quot;; it now returns an error saying to read each page or range separately&lt;/li&gt;
&lt;li&gt;Fixed @-mentioned text files over 256KB being left out silently: Claude is now told the file&#39;s size and to read it in portions&lt;/li&gt;
&lt;li&gt;Fixed the usage limit alert repeating once per background agent when agents failed on a limit that had already stopped the main conversation&lt;/li&gt;
&lt;li&gt;Fixed Remote Control viewers seeing an empty subagent pane for background subagents in sessions hosted by the desktop app or an IDE&lt;/li&gt;
&lt;li&gt;Fixed cross-session delivery notices showing two sessions with similar names as one recipient, and the expiry notice blaming the desktop app when a terminal session let the message lapse&lt;/li&gt;
&lt;li&gt;Fixed Send now in the desktop app ending the subagent a turn was waiting on when another message was already queued&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/bug&lt;/code&gt;, &lt;code&gt;/share&lt;/code&gt; and &lt;code&gt;/feedback &amp;lt;text&amp;gt;&lt;/code&gt; starting over after Ctrl+O or Ctrl+Z while a report was being sent, and closing as cancelled after it had been sent&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/remote-env&lt;/code&gt; replacing your saved default environment when you pressed Enter right away: the list now opens on your default, and no row has a check mark when no default is in effect&lt;/li&gt;
&lt;li&gt;Fixed some pasted text reaching Claude as typed text when several pastes overlapped in one prompt&lt;/li&gt;
&lt;li&gt;Fixed vim mode leaving the cursor past the end of a line, j/k losing their column on shorter lines, and &lt;code&gt;f&lt;/code&gt;/&lt;code&gt;t&lt;/code&gt;/&lt;code&gt;F&lt;/code&gt;/&lt;code&gt;T&lt;/code&gt;/&lt;code&gt;;&lt;/code&gt;/&lt;code&gt;,&lt;/code&gt; jumping to, or deleting up to, a match on another line of the prompt&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/add-dir&lt;/code&gt; path box letting Shift+Enter or a paste add a line break, and treating fast-typed &quot;tab&quot;, &quot;up&quot; or &quot;down&quot; as those keys&lt;/li&gt;
&lt;li&gt;Fixed fast typing, input-method text and decomposed accents being dropped while a prompt footer row was selected, and &lt;code&gt;!&lt;/code&gt; leaving the row selected&lt;/li&gt;
&lt;li&gt;Fixed fullscreen mode sending a full-screen clear on every window resize and Ctrl+L when iTerm2 is detected, which may be what filled iTerm2&#39;s scrollback with stale pages&lt;/li&gt;
&lt;li&gt;Fixed a spurious &quot;could not be examined&quot; note for @-words that name no file when a Read deny rule is set and the working directory is under a symlink&lt;/li&gt;
&lt;li&gt;Fixed &quot;instruction file not loaded&quot; lines going stale or missing after &lt;code&gt;/cd&lt;/code&gt; or a permission change, and added a transcript line when a nested one isn&#39;t loaded&lt;/li&gt;
&lt;li&gt;Fixed a compaction summary that repeated &lt;code&gt;/name&lt;/code&gt; letting Claude invoke a skill that is reserved for the user&lt;/li&gt;
&lt;li&gt;Fixed Write, Edit, NotebookEdit and LSP rows, and single Read, Grep and Glob rows, hiding why a mod denied the call: the row now shows the reason&lt;/li&gt;
&lt;li&gt;Fixed a cloud session showing a turn that never ended when its worker was stopped just as the turn finished&lt;/li&gt;
&lt;li&gt;Fixed cloud sessions with a large transcript sometimes asking for a permission again after it was approved&lt;/li&gt;
&lt;li&gt;Fixed scheduled tasks and other queued notifications being lost in cloud sessions when a message was retried or edited while Claude was reading them&lt;/li&gt;
&lt;li&gt;Fixed cloud sessions forgetting the thinking setting chosen in the client when the session&#39;s container restarted&lt;/li&gt;
&lt;li&gt;Fixed Cowork cloud sessions saying a proxy blocked artifacts when Anthropic couldn&#39;t confirm the organization&#39;s settings&lt;/li&gt;
&lt;li&gt;Fixed plugins whose hooks module makes many &lt;code&gt;$.state&lt;/code&gt; calls through one const taking minutes to load or validate&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude plugin validate&lt;/code&gt; listing a matcher or state value for a hooks module that the engine reads from elsewhere&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude plugin validate&lt;/code&gt; listing a &lt;code&gt;$.state&lt;/code&gt; value read through a top-level &lt;code&gt;var&lt;/code&gt; that was declared again or reassigned; such a module is now refused&lt;/li&gt;
&lt;li&gt;Fixed a plugin&#39;s served &lt;code&gt;$&lt;/code&gt; method restarting the hook origin, which could run a guard hook with a &lt;code&gt;.catch&lt;/code&gt; above it again without end&lt;/li&gt;
&lt;li&gt;Fixed plugin interface calls made while the plugin hooks worker restarts running without the hooks other plugins put on them&lt;/li&gt;
&lt;li&gt;Fixed a mod&#39;s &lt;code&gt;config.set&lt;/code&gt;, &lt;code&gt;state.set&lt;/code&gt;, &lt;code&gt;env.set&lt;/code&gt; or &lt;code&gt;agent.spawn&lt;/code&gt; hook that denies after calling &lt;code&gt;next(e)&lt;/code&gt; being answered as a refusal: the hook is now reported as failed, by name&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/theme&lt;/code&gt;, the &lt;code&gt;/config&lt;/code&gt; Theme menu and the first-run theme step saving a theme before a plugin&#39;s &lt;code&gt;config.set&lt;/code&gt; hook was asked&lt;/li&gt;
&lt;li&gt;Fixed a plugin&#39;s &lt;code&gt;tool.check&lt;/code&gt; hook answering allow running a tool that requires your answer (a question, a plan approval) without showing its dialog&lt;/li&gt;
&lt;li&gt;Fixed a mod&#39;s start-up prompt, command or subagent being queued a second time when the hooks worker was replaced&lt;/li&gt;
&lt;li&gt;Fixed a mod&#39;s hook that called &lt;code&gt;next(e)&lt;/code&gt; and then failed while the turn was interrupted letting the call through; the call is now rejected&lt;/li&gt;
&lt;li&gt;Fixed a plugin&#39;s prompt drop or setting deny being ignored when its reason was longer than 4,096 characters&lt;/li&gt;
&lt;li&gt;Fixed an organization&#39;s plugin being unloaded on its own reload, or after another plugin crashed, when it returned a &lt;code&gt;$&lt;/code&gt; name that a user-installed mod had added; the mod is now unloaded instead&lt;/li&gt;
&lt;li&gt;Fixed tool calls made while the plugin hooks worker restarts being answered without the plugins&#39; permission hooks&lt;/li&gt;
&lt;li&gt;Fixed plugin &lt;code&gt;tool.call&lt;/code&gt; hooks seeing some tool calls before misnamed parameters were repaired; a hook now sees the arguments the tool will run with&lt;/li&gt;
&lt;li&gt;Fixed a mod&#39;s guard hook with a &lt;code&gt;.catch&lt;/code&gt; being skipped silently for calls another mod&#39;s hook makes beneath the guard&#39;s own &lt;code&gt;$&lt;/code&gt; call; its &lt;code&gt;.catch&lt;/code&gt; is now asked&lt;/li&gt;
&lt;li&gt;Improved startup of &lt;code&gt;claude -p&lt;/code&gt; and SDK sessions: the first turn no longer waits for HTTP and SSE MCP servers to answer &lt;code&gt;resources/list&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Improved rendering speed of long bulleted or numbered replies: they stream, resize and re-open in the transcript (ctrl+o) much faster&lt;/li&gt;
&lt;li&gt;Improved Ctrl+C draft recovery: a cleared prompt now stays reachable with Up after a slash command or a sent message&lt;/li&gt;
&lt;li&gt;Improved hook output handling: &lt;code&gt;&amp;lt;system-reminder&amp;gt;&lt;/code&gt; tags written in a hook&#39;s output are escaped before they reach Claude&lt;/li&gt;
&lt;li&gt;Improved tool input handling: Grep accepts &lt;code&gt;file_path&lt;/code&gt; for &lt;code&gt;path&lt;/code&gt;, and Write, WebFetch and Read ignore a few stray parameters instead of failing the call&lt;/li&gt;
&lt;li&gt;Improved the steps shown when a marketplace declared in a settings file has a name that looks like an official Anthropic marketplace&lt;/li&gt;
&lt;li&gt;Improved sandbox auto-allow: with strict sandbox mode set in user, managed or --settings settings, an interpreter command with an env var prefix like &lt;code&gt;FOO=bar python3 app.py&lt;/code&gt; runs unprompted&lt;/li&gt;
&lt;li&gt;Improved the Artifact tool&#39;s listing: Claude now sees how many published artifacts you have and can list up to 200 at once instead of 50&lt;/li&gt;
&lt;li&gt;Improved cloud sessions after a restart: Claude is now told which stopped background agents it can resume by id&lt;/li&gt;
&lt;li&gt;Improved the Claude in Chrome message in claude.ai cloud sessions when the browser can&#39;t be reached: Claude is now told it may continue with alternatives if the user prefers&lt;/li&gt;
&lt;li&gt;Improved the /focus tip: it now invites you to try focus view mid-turn and shows how to switch back&lt;/li&gt;
&lt;li&gt;Improved startup with local (stdio) MCP servers that ignore the newer protocol check: after one slow connect they are remembered for 7 days and connected the older way without the wait&lt;/li&gt;
&lt;li&gt;Changed local (stdio) MCP server connections to negotiate protocol version 2026-07-28 by default on every install, including Bedrock, Vertex and Foundry; &lt;code&gt;MCP_PROTOCOL_NEGOTIATION=legacy&lt;/code&gt; opts out&lt;/li&gt;
&lt;li&gt;Changed &lt;code&gt;claude plugin test&lt;/code&gt;: a failed &lt;code&gt;expect&lt;/code&gt; inside a hook the test registered, or a stub answer the engine refuses, now fails the test instead of passing silently&lt;/li&gt;
&lt;li&gt;Changed usage limit messages to write claude.ai settings links with https:// so terminals and apps can make them clickable&lt;/li&gt;
&lt;li&gt;Changed scheduled and Run now routine runs to publish a new artifact only you can see without asking for approval; artifacts that request connectors or other access still ask&lt;/li&gt;
&lt;li&gt;Changed agent names to allow at most 256 characters: a longer one is rejected, and a skill&#39;s or a plugin file&#39;s &lt;code&gt;name&lt;/code&gt; longer than that is ignored&lt;/li&gt;
&lt;li&gt;[Cloud sessions] Fixed routine runs occasionally staying listed as running for hours after they had finished&lt;/li&gt;
&lt;li&gt;[Cloud sessions] Fixed editing or duplicating a routine turning off its push notifications when the routine had no saved notification setting&lt;/li&gt;
&lt;li&gt;[Cloud sessions] Fixed SVG, HEIC, TIFF and other less common image files failing to attach; they now attach as regular files&lt;/li&gt;
&lt;li&gt;[Cloud sessions] Fixed approval prompts offering &quot;Always allow&quot; for connector tools that an organization set to require approval; the choice had no effect&lt;/li&gt;
&lt;li&gt;[Remote Control] Fixed the first message of a new Remote Control session started from claude.ai/code accepting only images; it now accepts PDFs and other files like later messages&lt;/li&gt;
&lt;li&gt;[Claude Tag] Added an Edit button to the Allowed domains card on a channel&#39;s Configure page, so Enterprise admins can open the access bundle that sets the channel&#39;s domains&lt;/li&gt;
&lt;li&gt;[Claude Tag] Fixed replies sent in a Slack thread while Claude was still on its first request there being held until that request finished, or missed when sent seconds apart&lt;/li&gt;
&lt;li&gt;[Claude Tag] Fixed Slack threads woken only by GitHub pull request activity or a routine staying on their original model after an admin changed the channel or workspace default model&lt;/li&gt;
&lt;li&gt;[Claude Tag] Fixed Claude sometimes posting a spend limit notice in Slack when the real cause was that your organization had run out of usage credits&lt;/li&gt;
&lt;li&gt;[Claude Tag] Fixed a session hanging until interrupted when a permission prompt that can&#39;t be answered from Slack was denied automatically&lt;/li&gt;
&lt;li&gt;[Claude Tag] Improved &lt;code&gt;@Claude !status&lt;/code&gt; in a channel to say when Claude has stopped reading its untagged messages, why, and that an @-mention starts it reading again&lt;/li&gt;
&lt;li&gt;[Claude Tag] Changed the first message of a Slack thread continued with &lt;code&gt;!fork&lt;/code&gt; to a card showing where it came from, the request, and who asked, with a link to the original thread&lt;/li&gt;
&lt;li&gt;[Claude Tag] Changed the organization-wide and default spend limit boxes on Claude Tag&#39;s spend limits page in admin settings to save only when you press Save or Enter, not when you click away&lt;/li&gt;
&lt;li&gt;[Code Review] Added the period&#39;s total with its change from the previous period, and a breakdown by repository, to the PRs reviewed chart in Code Review analytics&lt;/li&gt;
&lt;li&gt;[Code Review] Fixed a queued review failing when the pull request moved to a new base branch and the old one was deleted; the commit is now re-queued for review&lt;/li&gt;
&lt;li&gt;[Code Review] Fixed reviews ignoring a CLAUDE.md&#39;s rules when the pull request edits that file; reviews now use its version from the base branch&lt;/li&gt;
&lt;/ul&gt;</content>
    <author>
      <name>ashwin-ant</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/178951676?s=60&amp;v=4"/>
  </entry>
  <entry>
    <id>tag:github.com,2008:Repository/937253475/v2.1.291</id>
    <updated>2026-10-06T03:55:19Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.291"/>
    <title>v2.1.291</title>
    <content type="html">&lt;h2&gt;What&#39;s changed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a regression in 2.1.290 where cloud sessions could drop answers to permission prompts&lt;/li&gt;
&lt;li&gt;Fixed a regression in 2.1.288 where the last messages of a session could be lost when quitting&lt;/li&gt;
&lt;/ul&gt;</content>
    <author>
      <name>ashwin-ant</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/178951676?s=60&amp;v=4"/>
  </entry>
  <entry>
    <id>tag:github.com,2008:Repository/937253475/v2.1.290</id>
    <updated>2026-10-05T23:33:17Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.290"/>
    <title>v2.1.290</title>
    <content type="html">&lt;h2&gt;What&#39;s changed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Added &lt;code&gt;serverToolUses&lt;/code&gt; to the result of a mod&#39;s &lt;code&gt;turn.step&lt;/code&gt; hook: the tool calls the API ran itself (the advisor), each with its id, name, input, start and end&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;agentId&lt;/code&gt; to the &lt;code&gt;tool.check&lt;/code&gt; event of plugin hooks, so a hook can tell a subagent&#39;s permission check from the main session&#39;s&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;ceiling&lt;/code&gt; to the question and verdict a mod&#39;s &lt;code&gt;tool.check&lt;/code&gt; hook reads, naming the approval an organization requires for a tool&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;ThemeKey&lt;/code&gt; and &lt;code&gt;Color&lt;/code&gt; types to the plugin hooks typings, so an editor lists the theme colors a mod&#39;s drawing can name&lt;/li&gt;
&lt;li&gt;Added to &lt;code&gt;claude plugin validate&lt;/code&gt;: each hook a mod registers at a gating site is listed with whether it has a &lt;code&gt;.catch&lt;/code&gt; (&lt;code&gt;gatingHooks&lt;/code&gt; under &lt;code&gt;--json&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;Added a Deny button to the Claude apps gateway&#39;s sign-in approval page: it ends the pending sign-in, so the waiting terminal stops within seconds&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;claude attach &amp;lt;name&amp;gt;&lt;/code&gt; and &lt;code&gt;claude logs &amp;lt;name&amp;gt;&lt;/code&gt;: part of a session name works in place of the id&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;/claude-api managed-agents-onboard &amp;lt;url&amp;gt;&lt;/code&gt; to set up the Managed Agents pattern a page describes as &lt;code&gt;ant apply&lt;/code&gt; files&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;/claude-api managed-agents-onboard &amp;lt;quickstart-name&amp;gt;&lt;/code&gt; to build a Console quickstart template, such as &lt;code&gt;deep-researcher&lt;/code&gt;, with the &lt;code&gt;ant&lt;/code&gt; CLI&lt;/li&gt;
&lt;li&gt;Added a warning when a managed settings file is a link to a file outside the managed settings folder&lt;/li&gt;
&lt;li&gt;Added a /status and doctor warning when managed settings ignore user-configured sandbox allowRead paths or allowed domains&lt;/li&gt;
&lt;li&gt;Fixed requests failing behind proxies and gateways that reject one of Claude Code&#39;s beta headers with a status other than 400, or together with a second beta&lt;/li&gt;
&lt;li&gt;Fixed long sessions with hundreds of images getting stuck on &quot;Request rejected as unprocessable by the model&quot; errors&lt;/li&gt;
&lt;li&gt;Fixed a turn ending at once when the API&#39;s output content filter stopped a reply while Claude was still thinking; the request is now retried once before the error is shown&lt;/li&gt;
&lt;li&gt;Fixed resumed subagents and teammates losing their earlier thinking and prompt cache after receiving a message mid-run&lt;/li&gt;
&lt;li&gt;Fixed WebFetch silently dropping page text past 100,000 characters; it now says how much was unread and takes an &lt;code&gt;offset&lt;/code&gt; to read on&lt;/li&gt;
&lt;li&gt;Fixed a crash (&quot;Maximum call stack size exceeded&quot;) when a response nested lists or quotes thousands of levels deep&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/rewind&lt;/code&gt; not listing a prompt sent while Claude was still working&lt;/li&gt;
&lt;li&gt;Fixed scheduled tasks (&lt;code&gt;/loop&lt;/code&gt; with an interval, reminders) silently not coming back on resume once the conversation was compacted; covers compactions made from this version on&lt;/li&gt;
&lt;li&gt;Fixed scheduled tasks set in the foreground never firing after a ← or &lt;code&gt;/background&lt;/code&gt; hand-off, and recurring ones firing an extra run on every resume, respawn or fork&lt;/li&gt;
&lt;li&gt;Fixed headless &lt;code&gt;--json-schema&lt;/code&gt; runs exiting non-zero with &lt;code&gt;is_error: true&lt;/code&gt; on a &lt;code&gt;success&lt;/code&gt; result when the connection dropped after the structured output was already delivered&lt;/li&gt;
&lt;li&gt;Fixed plan mode letting the auto mode classifier approve non-read-only connector tools that carry a server-pushed ask policy&lt;/li&gt;
&lt;li&gt;Fixed a project &lt;code&gt;CLAUDE.md&lt;/code&gt;, rule or &lt;code&gt;AGENTS.md&lt;/code&gt; symlinked outside the working directories loading under &lt;code&gt;permissions.blockReadsOutsideWorkingDirectories&lt;/code&gt; or a &lt;code&gt;Read&lt;/code&gt; deny rule&lt;/li&gt;
&lt;li&gt;Fixed URL allow and deny patterns with a wildcard inside an &lt;code&gt;xn--&lt;/code&gt; host label matching differently from one process to the next&lt;/li&gt;
&lt;li&gt;Fixed an MCP server provided by your organization being relisted as your own after signing in or reconnecting, including from a late result in headless and SDK sessions&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/ultrareview&lt;/code&gt; dropping uncommitted changes without a warning on Windows when &lt;code&gt;git stash create&lt;/code&gt; failed, and refusing them after a &lt;code&gt;git add -N&lt;/code&gt; file was deleted or moved&lt;/li&gt;
&lt;li&gt;Fixed the &lt;code&gt;plansDirectory&lt;/code&gt; setting&#39;s project-root check for paths that contain a backslash on macOS and Linux&lt;/li&gt;
&lt;li&gt;Fixed replies in very long Remote Control and cloud sessions that could appear a block at a time instead of streaming in&lt;/li&gt;
&lt;li&gt;Fixed the background daemon&#39;s log passing terminal control characters to the screen under &lt;code&gt;claude daemon run&lt;/code&gt; and &lt;code&gt;claude daemon logs&lt;/code&gt;; they now show as &lt;code&gt;\uXXXX&lt;/code&gt; escapes&lt;/li&gt;
&lt;li&gt;Self-hosted runner: Fixed a crafted, very long line of a session&#39;s error output freezing the runner for several seconds&lt;/li&gt;
&lt;li&gt;Fixed a plugin hook with a &lt;code&gt;.catch&lt;/code&gt; being unloaded, and its &lt;code&gt;.catch&lt;/code&gt; skipped, when the hook kept the hooks worker busy on a prompt or tool call&lt;/li&gt;
&lt;li&gt;Fixed a mod&#39;s &lt;code&gt;turn.step&lt;/code&gt; result listing a tool call that a mid-response model fallback had discarded&lt;/li&gt;
&lt;li&gt;Fixed a Cowork cloud session&#39;s reply sometimes never finishing when its container restarted just after Claude sent a message or a file&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude plugin validate&lt;/code&gt; and plugin loading refusing a hooks module that destructures an option named like one of its top-level functions&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/ultrareview&lt;/code&gt; failing to upload uncommitted changes when &lt;code&gt;core.safecrlf=true&lt;/code&gt; is set in git&#39;s configuration&lt;/li&gt;
&lt;li&gt;Fixed the effort level changing when a flagged message is retried on a fallback model that has a different level saved in settings&lt;/li&gt;
&lt;li&gt;Windows: Fixed multi-line &lt;code&gt;!&lt;/code&gt; shell blocks in skills and commands failing when the file is saved with CRLF line endings&lt;/li&gt;
&lt;li&gt;Fixed Claude Code hanging until killed when a &lt;code&gt;/permissions&lt;/code&gt; tab was clicked while searching in fullscreen mode&lt;/li&gt;
&lt;li&gt;Fixed conversation compaction sometimes failing with a &quot;null is not an object&quot; error&lt;/li&gt;
&lt;li&gt;Fixed plugin hooks reading an empty &lt;code&gt;answer&lt;/code&gt; on &lt;code&gt;turn.complete&lt;/code&gt; for a subagent that hands its report back in auto mode&lt;/li&gt;
&lt;li&gt;Fixed a mod being unloaded without a message when a refresh followed its failed reload; its failure line now says the version loaded before is unloaded&lt;/li&gt;
&lt;li&gt;Fixed a mod&#39;s &lt;code&gt;prompt.submit&lt;/code&gt; hook that drops a prompt after calling &lt;code&gt;next(e)&lt;/code&gt; being ignored silently: the hook is now reported as failed, by name&lt;/li&gt;
&lt;li&gt;Fixed a mod&#39;s pane or band being redrawn without end when it followed its end over a tree that changed height at every drawing&lt;/li&gt;
&lt;li&gt;Fixed an image read on macOS and Windows being able to return a file outside what was approved, through a link swapped in mid-read&lt;/li&gt;
&lt;li&gt;Fixed a case where a user-installed mod could get an organization&#39;s plugin unloaded; the mod is now the one unloaded&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;disableClaudeAiConnectors&lt;/code&gt; and &lt;code&gt;allowedMcpServers&lt;/code&gt; URL rules not being applied to some MCP entries declared in &lt;code&gt;.mcp.json&lt;/code&gt;, plugins or agents&lt;/li&gt;
&lt;li&gt;Fixed a mod&#39;s inline pane being redrawn without end when its tree changed height at every drawing&lt;/li&gt;
&lt;li&gt;Fixed an &lt;code&gt;@&lt;/code&gt;-mention under the read block or &lt;code&gt;--restricted&lt;/code&gt; being able to read a file outside the working directories through a link changed mid-read&lt;/li&gt;
&lt;li&gt;Fixed Esc in the agents view confirming &quot;Press enter again to restart this session — it isn&#39;t responding&quot;; Esc now just reopens the session&lt;/li&gt;
&lt;li&gt;Fixed agent view losing a background session&#39;s &lt;code&gt;/loop&lt;/code&gt; run count, countdown and live status line after the session enters a worktree that it creates&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude agents&lt;/code&gt; sessions in manual permission mode asking for approval to read an image pasted into a reply or a new agent&#39;s prompt&lt;/li&gt;
&lt;li&gt;Fixed a deny or ask rule missing a command or path whose name came from a variable set as a prefix on &lt;code&gt;declare&lt;/code&gt;, &lt;code&gt;typeset&lt;/code&gt;, &lt;code&gt;export&lt;/code&gt; or &lt;code&gt;readonly&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fixed Read deny rules not applying to image paths pasted or dragged into the prompt, or to file names listed for an @-mentioned folder&lt;/li&gt;
&lt;li&gt;Fixed a case where a user-installed mod could make an organization&#39;s guard skip its check; such a mod is now unloaded&lt;/li&gt;
&lt;li&gt;Fixed plugin hooks stalling each redraw when a mod draws a long multi-line text holding non-Latin characters&lt;/li&gt;
&lt;li&gt;Fixed repeated Ctrl+X in the agents view deleting the whole next section after the bottom session of a section was deleted&lt;/li&gt;
&lt;li&gt;Fixed You should know writing its notes in English regardless of the &lt;code&gt;language&lt;/code&gt; setting&lt;/li&gt;
&lt;li&gt;Fixed a freeze after sending some very long messages&lt;/li&gt;
&lt;li&gt;Fixed a slowdown when expanding the transcript (ctrl+o) or resizing over large tool output that contains non-ASCII characters such as arrows, dashes or box-drawing&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude respawn&lt;/code&gt; re-sending an earlier message to a backgrounded session that has no saved transcript instead of starting it with an empty conversation&lt;/li&gt;
&lt;li&gt;Fixed Esc after an &lt;code&gt;n:&lt;/code&gt; or Ctrl+F search in the agents view moving focus to a section header, where Ctrl+X twice would delete every session in the section&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude agents&lt;/code&gt; saving a slash command it could not deliver to a stopped session and then running it by itself the next time that session restarted&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/ultrareview&lt;/code&gt; uploading uncommitted changes unfiltered for files under a git filter driver named &lt;code&gt;unset&lt;/code&gt; or &lt;code&gt;unspecified&lt;/code&gt;; the upload now stops and asks you to rename the driver&lt;/li&gt;
&lt;li&gt;Fixed auto mode denials suggesting a permission rule that would skip the classifier for a whole tool or that Claude Code would ignore&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude --teleport&lt;/code&gt; and &lt;code&gt;/teleport&lt;/code&gt; deleting the files in a folder that had replaced a tracked file of the same name when you chose to stash: the stash is now refused, and says why&lt;/li&gt;
&lt;li&gt;Fixed Esc confirming agent view&#39;s &quot;Press enter again to restart this session fresh&quot; prompt&lt;/li&gt;
&lt;li&gt;Fixed agent view&#39;s &lt;code&gt;/loop&lt;/code&gt; run count freezing and its countdown disappearing after &lt;code&gt;/clear&lt;/code&gt;; the count now restarts with the new conversation&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;--channels&lt;/code&gt; permission relay: a reply ID that repeats within a session is now ignored instead of approving a different prompt&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/chrome&lt;/code&gt; &quot;Reconnect extension&quot; not restoring browser tools after a failed Chrome connection, and added an explanation when it can&#39;t (&lt;a class=&quot;issue-link js-issue-link&quot; data-error-text=&quot;Failed to load title&quot; data-id=&quot;5629882228&quot; data-permission-text=&quot;Title is private&quot; data-url=&quot;https://github.com/anthropics/claude-code/issues/98135&quot; data-hovercard-type=&quot;issue&quot; data-hovercard-url=&quot;/anthropics/claude-code/issues/98135/hovercard&quot; href=&quot;https://github.com/anthropics/claude-code/issues/98135&quot;&gt;#98135&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Fixed mods staying off for people who reach Claude through a gateway (&lt;code&gt;ANTHROPIC_BASE_URL&lt;/code&gt; with &lt;code&gt;ANTHROPIC_AUTH_TOKEN&lt;/code&gt;) and have no Anthropic account&lt;/li&gt;
&lt;li&gt;Fixed replies sent from &lt;code&gt;claude agents&lt;/code&gt; just after a background session crashed being refused after 2 seconds: they are now retried for up to 12 seconds while the session restarts&lt;/li&gt;
&lt;li&gt;Fixed slash commands and answers to a multiple-choice question that &lt;code&gt;claude agents&lt;/code&gt; could not deliver to a running session being saved and sent by themselves the next time it was restarted&lt;/li&gt;
&lt;li&gt;Fixed sandboxed commands that pipe a heredoc into another command (&lt;code&gt;cat &amp;lt;&amp;lt;EOF | python3&lt;/code&gt;) asking for approval on every run&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude agents&lt;/code&gt; failing with &quot;Couldn&#39;t restart the background service&quot; and background sessions stopping after a Homebrew upgrade (takes effect from the upgrade after this one)&lt;/li&gt;
&lt;li&gt;Fixed agent view&#39;s &quot;restart this session fresh&quot; re-sending an earlier message from the session instead of starting with an empty conversation&lt;/li&gt;
&lt;li&gt;Fixed Bash permission checks auto-approving some read-only commands (such as &lt;code&gt;rg&lt;/code&gt; or &lt;code&gt;git grep&lt;/code&gt;) whose arguments the shell would still expand as wildcards; these now prompt for approval&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude plugin test&lt;/code&gt; refusing to run after an upgrade because of an out-of-date saved setting&lt;/li&gt;
&lt;li&gt;Fixed Bash permission checks auto-approving certain commands whose variable names zsh reads differently from bash; these now prompt for approval&lt;/li&gt;
&lt;li&gt;Fixed a short form of a &lt;code&gt;git clone&lt;/code&gt; option keeping the sandbox exemption from a git pattern such as &lt;code&gt;git *&lt;/code&gt; in &lt;code&gt;sandbox.excludedCommands&lt;/code&gt;; it is now treated like the long form&lt;/li&gt;
&lt;li&gt;Fixed the first feature-flag request of a session ignoring a proxy or API endpoint set in a project&#39;s settings&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/ultrareview&lt;/code&gt; of a local branch silently leaving uncommitted work out of the upload in a repository that keeps its branches outside &lt;code&gt;.git&lt;/code&gt; (git 2.54+); it now refuses with an explanation&lt;/li&gt;
&lt;li&gt;Fixed cloud sessions staying asleep after a container restart lost a pending &lt;code&gt;/loop&lt;/code&gt; wakeup or scheduled task; Claude is now told and can schedule it again&lt;/li&gt;
&lt;li&gt;Fixed the Claude apps gateway&#39;s retention sweep deleting a returning developer&#39;s identity row refreshed at the same moment, on PostgreSQL versions without the November 2025 fixes&lt;/li&gt;
&lt;li&gt;Fixed sandboxed Monitor tool commands skipping the permission prompt under sandbox auto-allow; they now follow your permission rules&lt;/li&gt;
&lt;li&gt;Fixed the Claude apps gateway failing to start when the certificate it presents to the identity provider has an empty subject&lt;/li&gt;
&lt;li&gt;Fixed the Claude apps gateway exiting with a bare &quot;Invalid URL&quot; when &lt;code&gt;store.postgres_url&lt;/code&gt; can&#39;t be parsed; the error now names the setting and says what the URL may hold&lt;/li&gt;
&lt;li&gt;Fixed background agents failing with &quot;Agent stalled&quot; and Workflow tool subagents restarting from their prompt when a Mac woke from sleep&lt;/li&gt;
&lt;li&gt;Fixed slow or failed startup since 2.1.285 under SDK hosts such as the VS Code extension when managed settings deny reads of many paths on a slow filesystem (notably Windows drives under WSL)&lt;/li&gt;
&lt;li&gt;Fixed a response interrupted by computer sleep being treated as a stalled stream on Bedrock, Vertex, Foundry, and custom gateways&lt;/li&gt;
&lt;li&gt;Fixed a freeze before the first request and in the &lt;code&gt;/sandbox&lt;/code&gt; Config tab on Linux and WSL when a sandbox read rule such as &lt;code&gt;~/**/.env&lt;/code&gt; covers a large folder&lt;/li&gt;
&lt;li&gt;Fixed skills not being found when asked for by the name in SKILL.md when their folder has a different name (for example a non-English name): the skill listing now shows both names&lt;/li&gt;
&lt;li&gt;Fixed a plan written in plan mode being lost when a cloud session&#39;s container restarted before the plan was presented&lt;/li&gt;
&lt;li&gt;Fixed the Bash tool occasionally losing shell aliases, functions and plugin PATH entries for a whole session when its first command ran seconds after startup on a new config directory&lt;/li&gt;
&lt;li&gt;Fixed unbounded memory use when an HTTP MCP server sends a very large response&lt;/li&gt;
&lt;li&gt;Fixed artifact operations failing in a Claude Code run started from inside a cloud session (for example &lt;code&gt;claude -p&lt;/code&gt; run from the Bash tool)&lt;/li&gt;
&lt;li&gt;Fixed files sent from remote sessions sometimes being refused as &quot;not the one approved&quot; when four or more were sent at once&lt;/li&gt;
&lt;li&gt;Fixed plan mode not being restored when resuming a session with &lt;code&gt;--continue&lt;/code&gt; or &lt;code&gt;--resume &amp;lt;session-id&amp;gt;&lt;/code&gt; in the terminal&lt;/li&gt;
&lt;li&gt;Fixed a marketplace named after another GitHub marketplace&#39;s download folder stopping that marketplace from downloading&lt;/li&gt;
&lt;li&gt;Fixed automatic compaction giving up with &quot;Prompt is too long&quot; when a Mac went to sleep while it was running&lt;/li&gt;
&lt;li&gt;Fixed the rewind menu (Esc Esc / &lt;code&gt;/rewind&lt;/code&gt;) freezing for hundreds of milliseconds per keypress when the conversation contains a very large pasted stack trace or source file&lt;/li&gt;
&lt;li&gt;Fixed a subdirectory&#39;s AGENTS.md not being attached when a file under it is @-mentioned&lt;/li&gt;
&lt;li&gt;Fixed self-hosted runner sessions resumed after a stopped runner failing with &quot;missing but already registered worktree&quot; when the sessions folder is a relative symlink&lt;/li&gt;
&lt;li&gt;Fixed a freeze when the secret scan or a permission prompt met long token-like text&lt;/li&gt;
&lt;li&gt;Fixed Bash permission checks not applying Read deny rules or the outside-directory read block to a wildcard in some option values of read-only commands&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;CLAUDE_CODE_USER_DIALOG_TIMEOUT_MS=5m&lt;/code&gt; being read as 5 ms and cancelling remote dialogs at once; values with a unit suffix now fall back to &lt;code&gt;dialogExpiry&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fixed a stall when an MCP server&#39;s tool listing contains very long runs of combining characters&lt;/li&gt;
&lt;li&gt;Fixed two pastes that overlap in one prompt being sent to the model partly as typed text instead of as one pasted block&lt;/li&gt;
&lt;li&gt;Fixed Claude in Chrome&#39;s browser picker showing a message meant for Claude when the chosen browser is no longer connected, and the VS Code dialog&#39;s list going stale after a switch&lt;/li&gt;
&lt;li&gt;Fixed background subagents losing write and Bash access in their worktree after the main session enters or exits a different worktree&lt;/li&gt;
&lt;li&gt;Fixed background commands, the agents view and daemon workers sending telemetry and a feature-flag request to Anthropic behind a Claude apps gateway when no managed settings on the machine force gateway login&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;--restricted&lt;/code&gt; (and &lt;code&gt;CLAUDE_CODE_RESTRICTED=1&lt;/code&gt;) sessions opening the cross-session messaging socket&lt;/li&gt;
&lt;li&gt;Fixed sessions moved to the background while idle reopening as &quot;no saved transcript&quot; after a restart or idle cleanup; they now resume their conversation&lt;/li&gt;
&lt;li&gt;Fixed background workers honoring &lt;code&gt;--allow-dangerously-skip-permissions&lt;/code&gt; on respawn without the bypass-permissions disclaimer having been accepted&lt;/li&gt;
&lt;li&gt;Fixed Claude replying in an endless loop when a plugin&#39;s async Stop hook passes an unquoted script path under a folder with a space, such as Application Support&lt;/li&gt;
&lt;li&gt;Fixed a freeze of several seconds when secret masking met very long unbroken text&lt;/li&gt;
&lt;li&gt;Fixed some permission rules and safety checks not being applied to a tool call after a PreToolUse hook rewrote its input&lt;/li&gt;
&lt;li&gt;Fixed first launch asking to pick a login method again after &lt;code&gt;claude auth login&lt;/code&gt; or with a credentials file already in the config directory&lt;/li&gt;
&lt;li&gt;Fixed file names containing line breaks being displayed incorrectly in file tool errors and permission prompts&lt;/li&gt;
&lt;li&gt;Fixed a large paste expanded in place being sent to the model as typed text after the next keystroke when it held accents stored as separate characters, as macOS file names do&lt;/li&gt;
&lt;li&gt;Fixed macOS &lt;code&gt;/login&lt;/code&gt; reporting success when the keychain refused the new login and kept an old one it could not remove&lt;/li&gt;
&lt;li&gt;Fixed SDK hosts using &lt;code&gt;--include-partial-messages&lt;/code&gt; seeing a reply stay open after the turn ended when its stream was cut, interrupted or fell back to non-streaming&lt;/li&gt;
&lt;li&gt;Fixed sandboxed Bash commands on Linux running &lt;code&gt;ConfigChange&lt;/code&gt; hooks and reloading settings mid-command when &lt;code&gt;.claude/settings.json&lt;/code&gt; or &lt;code&gt;.claude/settings.local.json&lt;/code&gt; does not exist&lt;/li&gt;
&lt;li&gt;Fixed errors reading &quot;Premature close&quot; instead of naming the missing program when a tool Claude Code runs, such as git or gh, is not installed (macOS, Linux)&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/loop&lt;/code&gt; and other recurring session-only scheduled tasks running an extra time after a sandboxed Bash command on Linux or after &lt;code&gt;.claude/scheduled_tasks.json&lt;/code&gt; was deleted&lt;/li&gt;
&lt;li&gt;Fixed edits to the file a symlinked settings file points at running without the settings-file permission question&lt;/li&gt;
&lt;li&gt;Improved MCP startup behind a network proxy: a server the proxy blocks (HTTP 403) is no longer retried three times&lt;/li&gt;
&lt;li&gt;Improved permission prompts from background agents to show the Ctrl+X Ctrl+K shortcut that stops all background agents&lt;/li&gt;
&lt;li&gt;Improved the built-in &lt;code&gt;plugin-authoring&lt;/code&gt; skill: Claude now gives the one command another person runs to install a mod you made, and writes it in a README&#39;s install section&lt;/li&gt;
&lt;li&gt;Improved the reply to &lt;code&gt;/plugin&lt;/code&gt; in the desktop app&#39;s Code tab: it now says where to install and manage plugins there&lt;/li&gt;
&lt;li&gt;Improved the Bash changed-files view: when a chained command includes git merge, pull or checkout, it lists the files without full diffs&lt;/li&gt;
&lt;li&gt;Improved the Claude apps gateway&#39;s log when an upstream&#39;s cloud credentials or connection fail: the warning now ends with the underlying cause&lt;/li&gt;
&lt;li&gt;Improved the error shown when a cloud session is started without a claude.ai sign-in: it now names &lt;code&gt;claude auth login&lt;/code&gt; and /login and no longer blames API-key authentication&lt;/li&gt;
&lt;li&gt;Improved the Read tool&#39;s message for binary files: it now points Claude to a skill or a shell command that can read the format&lt;/li&gt;
&lt;li&gt;Improved the error shown when a git config file stops the &lt;code&gt;/ultrareview&lt;/code&gt; upload: it is about half as long and says what kind of file is the problem&lt;/li&gt;
&lt;li&gt;Improved the errors shown when the &lt;code&gt;/ultrareview&lt;/code&gt; upload refuses a checkout: each known cause now has its own message, with a way to fix it&lt;/li&gt;
&lt;li&gt;Improved the Claude apps gateway to log a warning during the last 30 days before the certificate it presents to the identity provider expires&lt;/li&gt;
&lt;li&gt;Improved Claude in Chrome: a &lt;code&gt;browser_batch&lt;/code&gt; call now gets 90 seconds, up from 60, before it is reported as timed out&lt;/li&gt;
&lt;li&gt;Improved the Claude apps gateway&#39;s browser sign-in pages: brand fonts, centered layout, and dark mode&lt;/li&gt;
&lt;li&gt;Improved responsiveness while resuming large sessions: timers, input and rendering keep running while the transcript loads&lt;/li&gt;
&lt;li&gt;Improved the / and @ suggestion lists: the selected row now starts with a ❯ pointer, so you can see it without color&lt;/li&gt;
&lt;li&gt;Changed &lt;code&gt;CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC&lt;/code&gt; to also skip the startup connection warm-up&lt;/li&gt;
&lt;li&gt;Changed Claude in Chrome so that a project&#39;s settings files can no longer turn it on; use &lt;code&gt;--chrome&lt;/code&gt;, &lt;code&gt;/chrome&lt;/code&gt; or your user settings&lt;/li&gt;
&lt;li&gt;Changed the Bash tool to ask for permission before running &lt;code&gt;pyright&lt;/code&gt;, which is no longer treated as a read-only command&lt;/li&gt;
&lt;li&gt;Changed what a mod&#39;s &lt;code&gt;$.process.spawn&lt;/code&gt; rejects with when another mod denies it after the child ran: it now says the call ran and a plugin withheld its result&lt;/li&gt;
&lt;li&gt;Changed the background daemon&#39;s log to write a multi-line message as one JSON-quoted line&lt;/li&gt;
&lt;li&gt;Changed skills and custom commands to refuse a &lt;code&gt;!&lt;/code&gt; shell command that contains raw control characters other than tab and newline, with a message that shows where they are&lt;/li&gt;
&lt;li&gt;Changed &lt;code&gt;/artifacts&lt;/code&gt;: opening an artifact in your browser now closes the list&lt;/li&gt;
&lt;li&gt;Changed Bash permission checks so that more forms of the &lt;code&gt;ps&lt;/code&gt; command ask for approval instead of running without asking&lt;/li&gt;
&lt;li&gt;Changed plugin hooks so long text is clipped and logged instead of being refused or dropped silently&lt;/li&gt;
&lt;li&gt;Changed background sessions whose scheduled task is gone: they now move to Completed about 20 seconds later and can be updated or shut down when idle&lt;/li&gt;
&lt;li&gt;Changed the &quot;Press ← again&quot; confirm on a just-cleared prompt: a second ← no longer has to wait a second before it switches, and holding ← down now switches too&lt;/li&gt;
&lt;li&gt;Changed the errors shown when the &lt;code&gt;/ultrareview&lt;/code&gt; upload fails at a git step: they name the step and what to try, and no longer repeat git&#39;s own error text&lt;/li&gt;
&lt;li&gt;Changed &lt;code&gt;/code-review&lt;/code&gt; at medium effort to also report cleanup and CLAUDE.md conventions findings on models without tuned review settings, including Opus 5.5 and Sonnet 5.5&lt;/li&gt;
&lt;li&gt;Changed an in-process teammate&#39;s &lt;code&gt;agent_id&lt;/code&gt; in Agent results to its agent ID (its &lt;code&gt;name@team&lt;/code&gt; address stays in &lt;code&gt;teammate_id&lt;/code&gt;); TeammateIdle hooks no longer fire from its subagents or forks&lt;/li&gt;
&lt;li&gt;Changed background sessions waiting on a scheduled wakeup (&lt;code&gt;/loop&lt;/code&gt;): they are now left running through updates and low memory, where being restarted or shut down could silently lose the wakeup&lt;/li&gt;
&lt;li&gt;Changed &lt;code&gt;/model&lt;/code&gt;, &lt;code&gt;/effort&lt;/code&gt; and &lt;code&gt;/rename&lt;/code&gt; sent from &lt;code&gt;claude agents&lt;/code&gt; to a busy background session to apply right away, without a confirmation, instead of when the turn ends&lt;/li&gt;
&lt;li&gt;Changed the Claude apps gateway&#39;s minimum supported PostgreSQL version from 14 to 11&lt;/li&gt;
&lt;li&gt;Changed the interactive session&#39;s WebSearch budget to refill over time (100 calls/hour; &lt;code&gt;CLAUDE_CODE_WEB_SEARCH_REFILLS_PER_HOUR&lt;/code&gt; sets the rate, 0 turns it off) instead of ending after 200 calls&lt;/li&gt;
&lt;li&gt;Changed &lt;code&gt;CLAUDE_CODE_DISABLE_ATTACHMENTS&lt;/code&gt; so a repository&#39;s &lt;code&gt;.claude/settings.json&lt;/code&gt; or &lt;code&gt;.claude/settings.local.json&lt;/code&gt; can no longer set it; shell, user and managed settings still can&lt;/li&gt;
&lt;li&gt;Changed &lt;code&gt;claude plugin update&lt;/code&gt; on a plugin loaded from a directory to print just its reason, without the &quot;Failed to update plugin&quot; prefix, as for built-in plugins&lt;/li&gt;
&lt;li&gt;Changed the built-in &lt;code&gt;gh api&lt;/code&gt; in cloud sessions: a host other than github.com set in &lt;code&gt;GH_HOST&lt;/code&gt; or &lt;code&gt;GH_REPO&lt;/code&gt; is now refused (use &lt;code&gt;--hostname&lt;/code&gt; or a full URL), and stderr notes requests to other hosts&lt;/li&gt;
&lt;li&gt;Changed the &lt;code&gt;claude-api&lt;/code&gt; skill&#39;s Managed Agents examples to turn off the web tools unless the agent needs them and to use the &lt;code&gt;auto&lt;/code&gt; permission policy&lt;/li&gt;
&lt;li&gt;Self-hosted runners: Changed &lt;code&gt;claude --environment &amp;lt;id&amp;gt;&lt;/code&gt; to create its session through the current Sessions API; printed and JSON session ids keep their session_… form&lt;/li&gt;
&lt;li&gt;[VSCode] Added a screen reader announcement, &quot;Message queued.&quot;, when you send a message while Claude is working&lt;/li&gt;
&lt;li&gt;[VSCode] Added a way to review and run a plugin marketplace&#39;s install or update command from the Manage plugins dialog&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed a blank chat you never typed into keeping a background Claude process running after you open a saved conversation in its place&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed settings dialogs blaming a timeout when Claude Code stopped unexpectedly during a save&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed the branch switch dialog offering to switch when it could not check for uncommitted changes&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed a permission prompt that arrived behind an open dialog taking keyboard focus, so a key pressed in the dialog could answer it&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed sign-in and new sessions giving no clear reason when Claude Code cannot find or start its program&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed the agent map showing a nested sub-agent with &quot;Tool calls (0)&quot; and placing the agents it starts under the main agent&lt;/li&gt;
&lt;li&gt;[VSCode] Improved Continue After Reload: tabs reopened after VS Code restarts its extensions now also finish a step the restart interrupted&lt;/li&gt;
&lt;li&gt;[VSCode] Improved file pills in messages: hovering one now shows the file&#39;s path from the project folder, so same-named files can be told apart&lt;/li&gt;
&lt;li&gt;[VSCode] Changed message timestamps to show by default (turn them off with the Claude Code: Show Message Timestamps setting)&lt;/li&gt;
&lt;li&gt;[Cloud sessions] Fixed turning off prompt suggestions through a cloud environment&#39;s environment variables having no effect in new cloud sessions&lt;/li&gt;
&lt;li&gt;[Cloud sessions] Fixed the working indicator in a cloud session spinning on for several seconds after Claude&#39;s reply had finished; it now stops with the reply&lt;/li&gt;
&lt;li&gt;[Cloud sessions] Fixed History on a never-run routine&#39;s page still saying &quot;No runs yet&quot; after you pressed Run now; it now shows the new run&lt;/li&gt;
&lt;li&gt;[Cloud sessions] Fixed an unarchived cloud session looking as if Claude were still working until you sent another message&lt;/li&gt;
&lt;li&gt;[Remote Control] Fixed a computer that just started Remote Control taking up to a minute to appear in the Remote Control menu of a new session; it now appears within seconds&lt;/li&gt;
&lt;li&gt;[Claude Tag] Added fast mode in Slack: mention Claude with &lt;code&gt;!fast&lt;/code&gt; to switch a thread to fast mode, moving it to Opus if needed, and &lt;code&gt;!fast off&lt;/code&gt; to switch back; replies show (fast) while it&#39;s on&lt;/li&gt;
&lt;li&gt;[Claude Tag] Added the optional Path prefixes field when creating a custom connection in an access bundle, so its allow rule can cover only those paths instead of the whole host&lt;/li&gt;
&lt;li&gt;[Claude Tag] Fixed members with the Claude Tag Admin permission getting &quot;Couldn&#39;t load memory files&quot; on the Activity page&#39;s Memory tab; they can now read workspace and channel memory&lt;/li&gt;
&lt;li&gt;[Claude Tag] Fixed a workspace guest&#39;s Confirm on a Claude settings card in Slack removing its buttons for everyone; only the guest sees the refusal, and members can still confirm or cancel&lt;/li&gt;
&lt;li&gt;[Claude Tag] Fixed scheduled routines in Slack channels running on a model other than the channel&#39;s default; each run that starts a new session now uses the current default model&lt;/li&gt;
&lt;li&gt;[Claude Tag] Fixed GitHub repositories in an access bundle attached by a channel-name rule being refused in the channels the rule covers; Claude can now add, list and clone them there&lt;/li&gt;
&lt;li&gt;[Claude Tag] Improved Claude&#39;s notice in your direct messages when your own Claude plan&#39;s usage limit is reached: it shows within seconds and says when the limit resets&lt;/li&gt;
&lt;li&gt;[Claude Tag] Improved the earlier Claude in Slack app&#39;s reply when it can&#39;t start a session: it now says what failed and who can fix it, in full only once per thread&lt;/li&gt;
&lt;li&gt;[Claude Tag] Changed the channel instructions limit to 8,192 characters instead of bytes, so non-English text gets the same room, and added a character count beside Save on the Configure page&lt;/li&gt;
&lt;li&gt;[Code Review] Fixed blocking review comments sometimes opening with a &quot;nit&quot; label that contradicted their severity&lt;/li&gt;
&lt;li&gt;[Code Review] Fixed tips to comment &quot;&lt;a class=&quot;user-mention notranslate&quot; data-hovercard-type=&quot;user&quot; data-hovercard-url=&quot;/users/claude/hovercard&quot; data-octo-click=&quot;hovercard-link-click&quot; data-octo-dimensions=&quot;link_type:self&quot; href=&quot;https://github.com/claude&quot;&gt;@claude&lt;/a&gt; review&quot; being posted on fork and Manual-mode pull requests in organizations that have turned Code Review off&lt;/li&gt;
&lt;/ul&gt;</content>
    <author>
      <name>ashwin-ant</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/178951676?s=60&amp;v=4"/>
  </entry>
  <entry>
    <id>tag:github.com,2008:Repository/937253475/v2.1.289</id>
    <updated>2026-10-03T23:07:17Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.289"/>
    <title>v2.1.289</title>
    <content type="html">&lt;h2&gt;What&#39;s changed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a deny or ask rule on a nested part of a compound shell command not holding over a user-installed mod&#39;s approval on managed machines&lt;/li&gt;
&lt;li&gt;Fixed the terminal freezing on short code blocks with many unclosed &lt;code&gt;&amp;lt;script&amp;gt;&lt;/code&gt; tags or deeply nested &lt;code&gt;${&lt;/code&gt; substitutions&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;Read&lt;/code&gt; deny rules not applying to files @-mentioned, changed, or selected in the IDE through a symlink&lt;/li&gt;
&lt;li&gt;[VSCode] Reverted a 2.1.288 change to &lt;code&gt;claude auth status&lt;/code&gt; that may have made sign-outs more frequent&lt;/li&gt;
&lt;li&gt;Improved how quickly large files open in a plugin code pane by laying the highlighted view out once at its final width&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;plugin list&lt;/code&gt;, &lt;code&gt;plugin eval&lt;/code&gt; and &lt;code&gt;plugin update&lt;/code&gt; showing a stale copy of a plugin installed from a local folder marketplace, and hot reload for a symlinked &lt;code&gt;--plugin-dir&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fixed installed mods not loading in the first session after an upgrade&lt;/li&gt;
&lt;li&gt;Fixed a plugin&#39;s rows above the prompt showing a stale row while the Background tasks dialog was open in fullscreen&lt;/li&gt;
&lt;li&gt;Fixed plugin panes drawing nothing when a link used a localhost address, an &lt;code&gt;@&lt;/code&gt; in its path, an uppercase host or a &lt;code&gt;file:&lt;/code&gt; path&lt;/li&gt;
&lt;li&gt;Fixed a user-installed plugin being able to rewrite the descriptions of an organization-managed MCP server&#39;s sign-in tools&lt;/li&gt;
&lt;li&gt;Fixed a freeze or forced quit at launch when a plugin drew a Box with a border style the terminal does not know&lt;/li&gt;
&lt;li&gt;Fixed supervised and background sessions ending when a plugin&#39;s on-screen handler threw asynchronously&lt;/li&gt;
&lt;li&gt;Fixed sessions ending with an interface error when a plugin region with no height kept growing&lt;/li&gt;
&lt;li&gt;Fixed Bash deny and ask rules missing a command behind an environment variable prefix with an expanded value (e.g. &lt;code&gt;TZ=&quot;$HOME&quot; rm -rf build&lt;/code&gt;) when the sandbox auto-allows commands&lt;/li&gt;
&lt;li&gt;Fixed a Bash deny or ask rule being skipped under sandbox auto-allow when a bare variable assignment came before the command&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude plugin validate&lt;/code&gt; skipping the plugin when the folder also holds a marketplace manifest&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;agent.spawn&lt;/code&gt; for teammates, one agent id across plugin hook events, and idle and waiting states in &lt;code&gt;$.agent.list()&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fixed sessions ending with &quot;unrecoverable interface error&quot; when a value a mod&#39;s &lt;code&gt;ui.render&lt;/code&gt; hook wrote made a row throw while drawn; the engine now draws its own row instead&lt;/li&gt;
&lt;li&gt;Fixed text with a tab, a stray escape and a C1 control, or a short text with a tab and CRLF line endings, drawing over the rows below it&lt;/li&gt;
&lt;li&gt;Fixed right-aligned content in a mod&#39;s pane or band drawing under the close mark or &lt;code&gt;[-]&lt;/code&gt;, which now also keep one column in from the terminal&#39;s edge&lt;/li&gt;
&lt;li&gt;Fixed a mod&#39;s &lt;code&gt;Client&lt;/code&gt; that fails while drawn taking down everything the mod drew around it; it now fails alone and raises &lt;code&gt;ui.fault&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude plugin validate&lt;/code&gt; failing an Anthropic marketplace&#39;s own plugin and listing a clean &lt;code&gt;plugin.json&lt;/code&gt; in &lt;code&gt;--json&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fixed a mod&#39;s band that fails to draw briefly telling the cards under it to step aside&lt;/li&gt;
&lt;li&gt;Fixed a failed plugin component showing &lt;code&gt;Error&lt;/code&gt; or nothing as its reason when the failure carried no message&lt;/li&gt;
&lt;li&gt;Improved the line a mod&#39;s author sees when its band or pane fails to draw: it names the mod and says nothing was drawn&lt;/li&gt;
&lt;li&gt;Fixed published artifact pages freezing or crashing the reader&#39;s browser tab on short code blocks with many unclosed &lt;code&gt;&amp;lt;script&amp;gt;&lt;/code&gt; tags&lt;/li&gt;
&lt;li&gt;Fixed a mod&#39;s Client region staying failed for the whole session after the terminal threw while drawing it&lt;/li&gt;
&lt;/ul&gt;</content>
    <author>
      <name>ashwin-ant</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/178951676?s=60&amp;v=4"/>
  </entry>
  <entry>
    <id>tag:github.com,2008:Repository/937253475/v2.1.288</id>
    <updated>2026-10-02T20:19:57Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.288"/>
    <title>v2.1.288</title>
    <content type="html">&lt;h2&gt;What&#39;s changed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Added &lt;code&gt;$.ui.selection()&lt;/code&gt; for mods: returns the text you last selected in fullscreen mode and, when the selection lies within one transcript row, that row&lt;/li&gt;
&lt;li&gt;Added a built-in &lt;code&gt;gh api&lt;/code&gt; to cloud sessions whose image has no GitHub CLI, and fixed the built-in sending control characters from file names, jq filters or GitHub errors to the terminal&lt;/li&gt;
&lt;li&gt;Added recovery for a prompt cleared with Ctrl+C: pressing Up on the empty prompt brings the draft back, including pasted text and images&lt;/li&gt;
&lt;li&gt;Added a re-authenticate prompt when an MCP server asks for more OAuth scope during a tool call&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;--max-findings &amp;lt;n&amp;gt;|all&lt;/code&gt; to /code-review to report more or fewer findings than the usual limit; the choice is reused until you pass &lt;code&gt;--max-findings default&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Added Ctrl+F to find a session by name and Alt+↑/↓ to jump between groups in the agents view; both, and rename, can be rebound in keybindings.json&lt;/li&gt;
&lt;li&gt;Added a screen reader mode announcement of the new permission mode when you approve a plan, including with Shift+Tab&lt;/li&gt;
&lt;li&gt;Fixed mid-response API timeouts failing the turn: non-interactive sessions and subagents now continue from the partial response, and thinking-only responses are retried&lt;/li&gt;
&lt;li&gt;Fixed long conversations failing with &quot;Prompt is too long&quot; instead of auto-compacting when the last reply reported zero token usage&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;--resume&lt;/code&gt; sometimes dropping files and other context that a compaction had just restored&lt;/li&gt;
&lt;li&gt;Fixed a resumed session sometimes not saving the last response of a turn, so that the next &lt;code&gt;--resume&lt;/code&gt; showed the prompt unanswered&lt;/li&gt;
&lt;li&gt;Fixed resume occasionally loading a transcript cut short when the same session rewrote the file during the load&lt;/li&gt;
&lt;li&gt;Fixed resuming a conversation started on 2.1.286 or earlier dropping the model&#39;s earlier thinking&lt;/li&gt;
&lt;li&gt;Fixed session titles, memory recall and prompt hooks failing on Mantle or behind gateways that reject structured outputs; added &lt;code&gt;CLAUDE_CODE_DISABLE_STRUCTURED_OUTPUTS&lt;/code&gt; to turn structured outputs off&lt;/li&gt;
&lt;li&gt;Fixed auto mode denials pointing Claude at a Bash permission rule when the blocked tool was not Bash&lt;/li&gt;
&lt;li&gt;Fixed auto mode on Bedrock and Mantle switching to the local classifier for the rest of the session after a request to an older model, such as a WebFetch summary or a &lt;code&gt;sonnet&lt;/code&gt; subagent&lt;/li&gt;
&lt;li&gt;Fixed cloud sessions that restarted on a newly picked model replying with that model after the server refused it&lt;/li&gt;
&lt;li&gt;Fixed Cowork cloud sessions staying marked as waiting for input after a WebFetch permission prompt for an unapproved URL went unanswered for five minutes&lt;/li&gt;
&lt;li&gt;Fixed prompt suggestions not appearing on a phone that joins a Cowork cloud session started on another device&lt;/li&gt;
&lt;li&gt;Fixed a mod&#39;s button sometimes running a different button&#39;s action when pressed on a view drawn before Claude Code restarted&lt;/li&gt;
&lt;li&gt;Fixed a plugin&#39;s pane showing nothing when one &lt;code&gt;Code&lt;/code&gt; element held a diff that does not parse; it now draws as plain code&lt;/li&gt;
&lt;li&gt;Fixed plugin LSP servers receiving literal &lt;code&gt;${user_config.*}&lt;/code&gt; and &lt;code&gt;${CLAUDE_PLUGIN_ROOT}&lt;/code&gt; placeholders in &lt;code&gt;initializationOptions&lt;/code&gt; and &lt;code&gt;settings&lt;/code&gt; instead of substituted values or manifest defaults&lt;/li&gt;
&lt;li&gt;Fixed a plugin&#39;s &lt;code&gt;tool.call&lt;/code&gt; hook making Bash fail and file searches read the wrong folder in subagents that run in a worktree&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;git-subdir&lt;/code&gt; plugin installs failing, or caching an incomplete plugin, on older git (before 2.39, e.g. Ubuntu 22.04&#39;s 2.34)&lt;/li&gt;
&lt;li&gt;Fixed plugins loaded with &lt;code&gt;--plugin-dir&lt;/code&gt; not showing &quot;Configure options&quot; in &lt;code&gt;/plugin&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fixed background sessions ending when a plugin was reloaded or disabled while one of its timers or reads was still running&lt;/li&gt;
&lt;li&gt;Fixed sandboxed heredocs with an unquoted delimiter (&lt;code&gt;python3 &amp;lt;&amp;lt;EOF&lt;/code&gt;) asking for approval on every run under sandbox auto-allow when the body holds only plain text and simple &lt;code&gt;$VAR&lt;/code&gt; references&lt;/li&gt;
&lt;li&gt;Fixed Bash tool permission check to prompt before a &lt;code&gt;BASHPID&lt;/code&gt; assignment whose value the shell would evaluate as arithmetic, instead of allowing it silently&lt;/li&gt;
&lt;li&gt;Fixed fullscreen sessions exiting with &quot;unrecoverable interface error&quot; when opening the background tasks dialog while a plugin or mod showed rows above the prompt&lt;/li&gt;
&lt;li&gt;Fixed Claude reporting a message to another session as delivered when that session held it: the notice now says it wasn&#39;t delivered and names the session, and in SDK sessions Claude can now learn of it mid-turn&lt;/li&gt;
&lt;li&gt;Fixed OpenTelemetry &lt;code&gt;claude_code.tool.blocked_on_user&lt;/code&gt; spans reporting &lt;code&gt;unknown&lt;/code&gt; source or decision in &lt;code&gt;-p&lt;/code&gt; and SDK sessions and for PreToolUse hook approvals&lt;/li&gt;
&lt;li&gt;Fixed permission asks that ended unanswered, in &lt;code&gt;-p&lt;/code&gt; or on an interrupted turn, emitting no &lt;code&gt;tool_decision&lt;/code&gt; event&lt;/li&gt;
&lt;li&gt;Fixed Edit and Retry in Cowork cloud sessions refusing a message sent before &lt;code&gt;/compact&lt;/code&gt; even though its history was still saved&lt;/li&gt;
&lt;li&gt;Fixed unattended sessions (&lt;code&gt;CLAUDE_CODE_RETRY_WATCHDOG&lt;/code&gt;) retrying for hours after a very long response stream failed; Claude Code now streams again, and gives up after three timeouts&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/login&lt;/code&gt; reporting &quot;Login successful&quot; when credentials could not be saved to secure storage; it now shows the failure, and offers a retry when the new login didn&#39;t take effect (&lt;a class=&quot;issue-link js-issue-link&quot; data-error-text=&quot;Failed to load title&quot; data-id=&quot;4803944904&quot; data-permission-text=&quot;Title is private&quot; data-url=&quot;https://github.com/anthropics/claude-code/issues/73861&quot; data-hovercard-type=&quot;issue&quot; data-hovercard-url=&quot;/anthropics/claude-code/issues/73861/hovercard&quot; href=&quot;https://github.com/anthropics/claude-code/issues/73861&quot;&gt;#73861&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Fixed a Stop during Bedrock credential lookup sometimes moving the session to a fallback model instead of ending the request&lt;/li&gt;
&lt;li&gt;Fixed a second &lt;code&gt;gcpAuthRefresh&lt;/code&gt;/&lt;code&gt;awsAuthRefresh&lt;/code&gt; browser sign-in opening when a laptop wakes from sleep while another Claude Code process is signing in&lt;/li&gt;
&lt;li&gt;Fixed agent teams: a plugin-defined agent spawned by name now runs with its own prompt, tools, disallowedTools and effort instead of the defaults&lt;/li&gt;
&lt;li&gt;Fixed headless (&lt;code&gt;-p&lt;/code&gt; / SDK) sessions occasionally ignoring SIGTERM when a supervisor such as &lt;code&gt;timeout&lt;/code&gt; or systemd sends SIGCONT alongside it&lt;/li&gt;
&lt;li&gt;Fixed restarted cloud sessions restoring a model that the organization&#39;s enforced model list refuses&lt;/li&gt;
&lt;li&gt;Fixed MCP tool calls sometimes running twice when a remote server&#39;s result was over 16 MB or could not be parsed&lt;/li&gt;
&lt;li&gt;Fixed subagents in Claude Desktop&#39;s Code tab getting none of the tools of a user-configured MCP server named &lt;code&gt;memory&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fixed Claude in Chrome asking before every screenshot and page read on a site you allowed when auto mode is unavailable (such as with &lt;code&gt;disableAutoMode&lt;/code&gt; or an older model); typing, navigation and JavaScript still ask&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude plugin install&lt;/code&gt; failing for GitHub-source plugins on macOS and Linux machines with no GitHub SSH key: the clone now falls back to HTTPS and prints a notice&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;sandbox.credentials.files&lt;/code&gt; entries on git config files not taking effect while &lt;code&gt;permissions.blockReadsOutsideWorkingDirectories&lt;/code&gt; is on&lt;/li&gt;
&lt;li&gt;Fixed Claude leaving out your organization&#39;s design systems when starting slides or a design with the Artifact tool on Team and Enterprise plans or machines with managed settings&lt;/li&gt;
&lt;li&gt;Fixed the keyboard not working on Windows after Claude Code restarts itself (first sign-in to a Claude apps gateway, provider setup, &lt;code&gt;/tui&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;Fixed a stall when launching an agent whose &lt;code&gt;tools:&lt;/code&gt; lists very many &lt;code&gt;Agent(...)&lt;/code&gt; entries&lt;/li&gt;
&lt;li&gt;Fixed sessions on Claude 3 Opus and Claude 3 Sonnet failing on every turn after a whole PDF entered the conversation&lt;/li&gt;
&lt;li&gt;Fixed the npm auto-updater reporting success when the platform-native binary failed to download and only the placeholder &lt;code&gt;claude&lt;/code&gt; stub was installed&lt;/li&gt;
&lt;li&gt;Fixed Remote Control cleanup archiving a session that is still connected or was just re-attached by another Claude Code process&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;owner/repo&lt;/code&gt; plugin marketplaces showing only the second attempt&#39;s error when both the SSH and HTTPS fetch fail; both errors are now shown, with the transport tried first on top&lt;/li&gt;
&lt;li&gt;Fixed path-scoped &lt;code&gt;.claude/rules&lt;/code&gt; and nested CLAUDE.md files not loading when Write or Edit creates or changes a file in their scope (previously only Read loaded them)&lt;/li&gt;
&lt;li&gt;Fixed a dangerous &lt;code&gt;rm&lt;/code&gt; (such as one on &lt;code&gt;/&lt;/code&gt; or the home directory) inside a &lt;code&gt;bash -c&lt;/code&gt; or &lt;code&gt;sh -c&lt;/code&gt; script running without a prompt in bypassPermissions mode or under a shell allow rule (&lt;a class=&quot;issue-link js-issue-link&quot; data-error-text=&quot;Failed to load title&quot; data-id=&quot;5551594056&quot; data-permission-text=&quot;Title is private&quot; data-url=&quot;https://github.com/anthropics/claude-code/issues/96300&quot; data-hovercard-type=&quot;issue&quot; data-hovercard-url=&quot;/anthropics/claude-code/issues/96300/hovercard&quot; href=&quot;https://github.com/anthropics/claude-code/issues/96300&quot;&gt;#96300&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Fixed LSP tool calls hanging indefinitely when a language server uses dynamic capability registration or stops responding; requests now time out after 60s (per-server &lt;code&gt;requestTimeout&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;idle_prompt&lt;/code&gt; notification hooks firing while background agents are still running (&lt;a class=&quot;issue-link js-issue-link&quot; data-error-text=&quot;Failed to load title&quot; data-id=&quot;5426721023&quot; data-permission-text=&quot;Title is private&quot; data-url=&quot;https://github.com/anthropics/claude-code/issues/93672&quot; data-hovercard-type=&quot;issue&quot; data-hovercard-url=&quot;/anthropics/claude-code/issues/93672/hovercard&quot; href=&quot;https://github.com/anthropics/claude-code/issues/93672&quot;&gt;#93672&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Fixed PreToolUse and PermissionRequest hooks being skipped when matching them failed or the tool&#39;s input could not be serialized to JSON; the call is now blocked&lt;/li&gt;
&lt;li&gt;Fixed the first request in a fresh environment or after a model switch using the built-in output limit and auto-compact window, not the server&#39;s; that request may now wait up to 1.5 seconds&lt;/li&gt;
&lt;li&gt;Fixed the &quot;What should Claude do instead?&quot; hint showing on the Interrupted row after sending queued messages with ctrl+enter&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/login&lt;/code&gt; in a &lt;code&gt;--bare&lt;/code&gt; session running a sign-in the session never reads, which could replace your saved login; it now says which credentials work&lt;/li&gt;
&lt;li&gt;Fixed the InstructionsLoaded hook omitting agent_id and agent_type when a subagent&#39;s file access loads a rule or nested CLAUDE.md; rules and nested CLAUDE.md files loaded on file access now also report effort&lt;/li&gt;
&lt;li&gt;Fixed the Agent tool in &lt;code&gt;claude mcp serve&lt;/code&gt; always reporting no available agents and rejecting every subagent_type&lt;/li&gt;
&lt;li&gt;Fixed the terminal cursor not following the typed text in the fullscreen transcript viewer&#39;s search and in &lt;code&gt;/theme&lt;/code&gt;&#39;s custom color search&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/permissions&lt;/code&gt; in screen reader mode: typing a rule&#39;s number now picks it instead of opening the search box&lt;/li&gt;
&lt;li&gt;Improved auto mode: when a conversation grows too long for the client-side safety classifier to review, it is now compacted instead of prompting for, or failing, every tool call&lt;/li&gt;
&lt;li&gt;Improved screen reader mode: short announcements, such as a deleted word, now stay on screen until your next key press or until something above them on screen changes&lt;/li&gt;
&lt;li&gt;Improved screen reader mode: answered questions in question dialogs now say &quot;answered&quot; beside their box&lt;/li&gt;
&lt;li&gt;Improved the &lt;code&gt;/usage-credits&lt;/code&gt; message shown to Team and Enterprise members whose organization has turned off usage credit requests&lt;/li&gt;
&lt;li&gt;Improved cloud sessions: a new conversation&#39;s first turn no longer waits for a stdio MCP server whose config sets &lt;code&gt;alwaysLoad: false&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Improved &quot;You should know&quot; notes to say &quot;we&quot;, &quot;the main agent&quot; or &quot;you&quot; depending on who was responsible for a decision&lt;/li&gt;
&lt;li&gt;Improved the error for an artifact database write refused at the database&#39;s size limit: it now states the limit and what frees space&lt;/li&gt;
&lt;li&gt;Improved Bash permission prompts to give a shorter reason when part of a command can&#39;t be checked before it runs&lt;/li&gt;
&lt;li&gt;Self-hosted runner: Improved the built-in &lt;code&gt;gh api&lt;/code&gt;: a refused gh command now prints its &lt;code&gt;gh api&lt;/code&gt; equivalent, &lt;code&gt;--paginate&lt;/code&gt; follows every page of a repository&#39;s lists, and a nested &lt;code&gt;claude&lt;/code&gt; no longer removes it&lt;/li&gt;
&lt;li&gt;Improved Remote Control&#39;s recovery from an expired server credential: sessions stay connected during renewal and are kept if it gives up after a server outage&lt;/li&gt;
&lt;li&gt;Changed the background command time limit to apply only in unattended sessions (&lt;code&gt;-p&lt;/code&gt;, Agent SDK, CI, cloud); terminal, desktop app and VS Code sessions have no limit&lt;/li&gt;
&lt;li&gt;Changed the client-side auto mode classifier to ignore an &lt;code&gt;ANTHROPIC_DEFAULT_SONNET_MODEL&lt;/code&gt; pin that names Claude Sonnet 5.5 or Opus 5.5 and use Claude Sonnet 5 instead&lt;/li&gt;
&lt;li&gt;Changed &lt;code&gt;claude project purge&lt;/code&gt; to &lt;code&gt;claude purge&lt;/code&gt;; the old name still works and prints a notice&lt;/li&gt;
&lt;li&gt;Changed the agents view &lt;code&gt;n:&lt;/code&gt; filter (and Ctrl+F search) so Enter opens the session whose name matches best instead of the top row&lt;/li&gt;
&lt;li&gt;Changed &lt;code&gt;/autocompact&lt;/code&gt; to save the auto-compact window per model, so each model keeps its own setting when you switch&lt;/li&gt;
&lt;li&gt;Changed MCP URL prompts from servers that can&#39;t report when you&#39;re done to wait for &quot;I&#39;m done, continue&quot; before the tool call continues, so you can finish in the browser first&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed a claude.ai connector staying on &quot;Needs authentication&quot; after you authorize it: the MCP servers dialog now offers Check connection&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed the opt-in New Conversation shortcut (Cmd/Ctrl+N) starting a conversation in every visible Claude view instead of only the one you are in&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed the chat view resuming the next saved session after you archive the one it shows; it now starts a new conversation instead&lt;/li&gt;
&lt;li&gt;[Cloud sessions] Fixed the Cloud sessions switch in Claude Code admin settings staying locked off while an unrelated security setting was loading or had failed to load&lt;/li&gt;
&lt;li&gt;[Cloud sessions] Fixed pressing Stop while a self-hosted runner was still starting not cancelling the queued message, which could then run once the runner was up&lt;/li&gt;
&lt;li&gt;[Claude Tag] Fixed Claude Tag admin settings offering a &quot;Remove this scope&quot; option, which always failed, on channels whose settings were created automatically&lt;/li&gt;
&lt;li&gt;[Claude Tag] Improved Claude to also follow a related Slack thread in another channel that it only read, so updates there reach the conversation that depends on them&lt;/li&gt;
&lt;li&gt;[Claude Tag] Improved save errors on a channel&#39;s Configure page: too-long channel instructions now say to shorten them, and a save refused for lost access no longer says to try again&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude plugin test&lt;/code&gt; reporting mods as turned off remotely when it had only read an out-of-date saved setting&lt;/li&gt;
&lt;/ul&gt;</content>
    <author>
      <name>ashwin-ant</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/178951676?s=60&amp;v=4"/>
  </entry>
  <entry>
    <id>tag:github.com,2008:Repository/937253475/v2.1.287</id>
    <updated>2026-10-01T18:43:19Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.287"/>
    <title>v2.1.287</title>
    <content type="html">&lt;h2&gt;What&#39;s changed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Added Claude Mods: plugins may now modify deeper behavior&lt;/li&gt;
&lt;li&gt;Added You should know, a built-in mod where a side agent watches your back and flags things you or Claude might miss. Turn it on with &lt;code&gt;/plugin enable cc-plugin-you-should-know@builtin&lt;/code&gt; (for first-party sessions with telemetry on)&lt;/li&gt;
&lt;li&gt;Added an &lt;code&gt;n:&amp;lt;text&amp;gt;&lt;/code&gt; filter to the agents view that matches session names and tasks; a filter now shows matches in collapsed sections and Enter opens the first match&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;prompt_text&lt;/code&gt; to the OpenTelemetry &lt;code&gt;user_prompt&lt;/code&gt; event, a copy of &lt;code&gt;prompt&lt;/code&gt; for backends that nest dotted keys; drop or mask it wherever you drop or mask &lt;code&gt;prompt&lt;/code&gt; (&lt;a class=&quot;issue-link js-issue-link&quot; data-error-text=&quot;Failed to load title&quot; data-id=&quot;4741613374&quot; data-permission-text=&quot;Title is private&quot; data-url=&quot;https://github.com/anthropics/claude-code/issues/70763&quot; data-hovercard-type=&quot;issue&quot; data-hovercard-url=&quot;/anthropics/claude-code/issues/70763/hovercard&quot; href=&quot;https://github.com/anthropics/claude-code/issues/70763&quot;&gt;#70763&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Added URL prompts from MCP servers on the 2025-11-25 protocol, for example to sign in. If a server no longer connects after this update, add &quot;bareElicitationCapability&quot;: true to its MCP config entry&lt;/li&gt;
&lt;li&gt;Windows: Added a startup warning when denying the Bash tool also turns off the PowerShell tool, so Claude has no shell tool&lt;/li&gt;
&lt;li&gt;Self-hosted runner: Added a built-in &lt;code&gt;gh api&lt;/code&gt; (REST only) for sessions that use Anthropic-managed git on macOS and Linux machines where the GitHub CLI is not installed&lt;/li&gt;
&lt;li&gt;Fixed fast mode staying off in remote sessions owned by an agent with no user account, even when the organization allows it&lt;/li&gt;
&lt;li&gt;Fixed Remote Control not receiving messages for minutes at a time when a reconnect request got no response; it now gives up after 30 seconds and retries&lt;/li&gt;
&lt;li&gt;Fixed hooks configured with &lt;code&gt;asyncRewake&lt;/code&gt; waking Claude over and over with &quot;found issues&quot; notifications when the hook&#39;s script file is missing; the broken hook is now reported once&lt;/li&gt;
&lt;li&gt;Fixed tool heartbeats not reaching SDK hosts while the model&#39;s response stream was stalled with no data arriving&lt;/li&gt;
&lt;li&gt;Fixed Bedrock and Vertex startup model checks ignoring an enforced &lt;code&gt;availableModels&lt;/code&gt; list, which could collapse &lt;code&gt;/model&lt;/code&gt; to one Opus row&lt;/li&gt;
&lt;li&gt;Fixed the Claude in Chrome browser picker showing a JSON parse error when Chrome could not be reached&lt;/li&gt;
&lt;li&gt;Fixed picking Fable in &lt;code&gt;/model&lt;/code&gt; on a claude.ai login saving the current version&#39;s id, so your saved default now follows the newest Fable like Opus and Sonnet do&lt;/li&gt;
&lt;li&gt;Fixed switching between Opus 5.5 and Sonnet 5.5 (&lt;code&gt;/model&lt;/code&gt;, &lt;code&gt;opusplan&lt;/code&gt;) rewriting earlier MCP tool announcements, which could drop earlier extended thinking&lt;/li&gt;
&lt;li&gt;Fixed Amazon Bedrock Guardrails blocks that arrive mid-response ending the turn with an API error instead of the guardrail&#39;s message when the reply began with thinking&lt;/li&gt;
&lt;li&gt;Fixed a dangerous &lt;code&gt;rm&lt;/code&gt; (such as one on &lt;code&gt;/&lt;/code&gt; or the home directory) losing its always-ask safeguard when the same command also redirected output to a &lt;code&gt;~&lt;/code&gt; or wildcard path&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude -p&lt;/code&gt; and SDK sessions repeating a model fallback on every later message after the model was switched while a reply was running&lt;/li&gt;
&lt;li&gt;Fixed a folder&#39;s CLAUDE.md being attached a second time after resuming a session or after a compaction&lt;/li&gt;
&lt;li&gt;Fixed background sessions that could not be reopened from &lt;code&gt;claude agents&lt;/code&gt; after the agent exited and removed the worktree the session was started in&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/advisor&lt;/code&gt; pairing checks: Sonnet 5.5 can now advise Opus 4.7 and 4.8, and advisors the API would refuse are flagged up front instead of being silently dropped&lt;/li&gt;
&lt;li&gt;Fixed Bash permission prompts showing internal parser names such as &quot;Contains simple_expansion&quot; instead of a plain explanation&lt;/li&gt;
&lt;li&gt;Fixed a cause of fullscreen sessions on slow or busy machines exiting with &quot;Claude Code exited after an unrecoverable interface error&quot; while a scroll key was held in a long conversation&lt;/li&gt;
&lt;li&gt;Fixed organization per-tool permission ceilings being silently dropped for an MCP tool named &lt;code&gt;__proto__&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fixed Claude being told to page large MCP results saved as JSON with Read&#39;s offset and limit, which cannot split one long line&lt;/li&gt;
&lt;li&gt;Fixed the commit attribution reminder being delivered inside a tool result after a compaction&lt;/li&gt;
&lt;li&gt;Fixed screen reader mode leaving the cursor away from the typed text in search boxes (such as /resume and /permissions) and sign-in code fields&lt;/li&gt;
&lt;li&gt;Fixed screen reader mode refusing Enter with nothing typed on /rewind&#39;s summarize options, whose added context is optional&lt;/li&gt;
&lt;li&gt;Fixed screen reader mode showing a &quot;Tab to amend&quot; hint on approval prompts, where Tab does nothing&lt;/li&gt;
&lt;li&gt;Fixed screen reader mode listing arrow keys that do nothing in /permissions and /mcp, and saying &quot;Select with numbers&quot; in empty menus or while a search box has the keys&lt;/li&gt;
&lt;li&gt;Fixed screen reader mode leaving out the changed lines in file edit approval prompts and other diffs&lt;/li&gt;
&lt;li&gt;Fixed screen reader mode sending the &lt;code&gt;claude --teleport&lt;/code&gt; progress screen, and an MCP form field while it is being checked, to the screen reader again on every spinner frame&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;CLAUDE_CODE_DISABLE_EXPERIMENTAL_BETAS&lt;/code&gt; not removing the structured-output format from session-title and prompt-hook requests, which Bedrock-backed gateways reject&lt;/li&gt;
&lt;li&gt;Fixed screen reader mode leaving out the top lines of a second approval prompt, a changed /config row or the rejected-plan line when the previous screen was taller than the terminal window&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;--include-partial-messages&lt;/code&gt; sending a cut-short reply&#39;s &lt;code&gt;message_stop&lt;/code&gt; late or never, so apps could show the reply as still in progress&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude agents&lt;/code&gt; sometimes not showing the permission prompt a background session is waiting on&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/ultrareview&lt;/code&gt; giving advice about &lt;code&gt;.git/info/attributes&lt;/code&gt; when the upload stops on a committed &lt;code&gt;.gitattributes&lt;/code&gt; it cannot read, such as one saved as UTF-16&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude remote-control&lt;/code&gt; failing to register behind an HTTP proxy with a misleading &quot;Check your organization permissions&quot; error (&lt;a class=&quot;issue-link js-issue-link&quot; data-error-text=&quot;Failed to load title&quot; data-id=&quot;5591297531&quot; data-permission-text=&quot;Title is private&quot; data-url=&quot;https://github.com/anthropics/claude-code/issues/97352&quot; data-hovercard-type=&quot;issue&quot; data-hovercard-url=&quot;/anthropics/claude-code/issues/97352/hovercard&quot; href=&quot;https://github.com/anthropics/claude-code/issues/97352&quot;&gt;#97352&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Fixed sandboxed Bash commands on Linux inheriting an open handle on the Claude Code executable&lt;/li&gt;
&lt;li&gt;Fixed the running-tool dot and three spinners still moving with the &quot;Reduce motion&quot; setting on, and /rewind&#39;s confirm screen updating its &quot;ago&quot; time while you type a note&lt;/li&gt;
&lt;li&gt;Fixed times in &lt;code&gt;claude agents&lt;/code&gt; changing every second in screen reader mode; they now change at most every 10 seconds&lt;/li&gt;
&lt;li&gt;Fixed a revoked claude.ai login showing a generic &lt;code&gt;API Error: 401&lt;/code&gt; instead of &quot;OAuth token revoked&quot;; in &lt;code&gt;-p&lt;/code&gt; mode the error now starts with &quot;Failed to authenticate&quot;&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/ultrareview&lt;/code&gt; upload refusals advising you to copy a variable named by a repository&#39;s settings file into your own user settings&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;--output-format stream-json&lt;/code&gt; and the SDK not streaming the turns of a &lt;code&gt;context: fork&lt;/code&gt; skill run by typing &lt;code&gt;/&amp;lt;skill&amp;gt;&lt;/code&gt; as the prompt, as they do for the Skill tool&#39;s fork&lt;/li&gt;
&lt;li&gt;Fixed /feedback and /bug: the pre-filled GitHub issue no longer includes your recent error messages, and the confirmation screen now lists them as part of the report&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude plugin marketplace add --sparse&lt;/code&gt; and &lt;code&gt;git-subdir&lt;/code&gt; plugin installs failing with &quot;transport &#39;http&#39; not allowed&quot; when the repository is served over plain http&lt;/li&gt;
&lt;li&gt;Fixed cloud sessions sometimes losing the earlier conversation when the session restarted while it was being compacted&lt;/li&gt;
&lt;li&gt;Fixed a plugin reload that overlapped the startup &lt;code&gt;--plugin-url&lt;/code&gt; download corrupting the session&#39;s cached copy of the plugin archive&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/desktop&lt;/code&gt; quoting partial output when opening Claude Desktop timed out or printed too much output; the error now names the cause&lt;/li&gt;
&lt;li&gt;Fixed an MCP connector tool call occasionally running twice, or the connector&#39;s calls failing until restart, when its server changed which MCP protocol version it supports&lt;/li&gt;
&lt;li&gt;Fixed SessionStart hooks from synced plugins not running in new cloud sessions&lt;/li&gt;
&lt;li&gt;Fixed the transcript&#39;s &quot;N hooks ran&quot; summary and the verbose debug log&#39;s matched-hooks count including Claude Code&#39;s internal callbacks, so one configured hook no longer shows as two&lt;/li&gt;
&lt;li&gt;Fixed files Claude sends from cloud and Remote Control sessions failing when the upload finished just after the 30-second timeout; it now waits 35 seconds&lt;/li&gt;
&lt;li&gt;Fixed repositories added mid-session in cloud and SDK sessions not loading their skills and plugins, and loading CLAUDE.md late, after Claude changed directory&lt;/li&gt;
&lt;li&gt;Fixed PNG, JPEG and WebP images over 8,000 pixels on a side failing to send from a remote session; Claude now sends a scaled-down copy&lt;/li&gt;
&lt;li&gt;Fixed messages sent from the Claude apps with 17 to 20 attached files delivering only the first 16&lt;/li&gt;
&lt;li&gt;Fixed headless sessions reporting an MCP server as needing authentication after one refused call, even though later calls succeed&lt;/li&gt;
&lt;li&gt;macOS: Fixed Remote Control sessions started with &lt;code&gt;claude remote-control&lt;/code&gt; stopping mid-turn when the Mac went to idle sleep&lt;/li&gt;
&lt;li&gt;Windows: Fixed interactive &lt;code&gt;claude&lt;/code&gt; hanging or crashing with &quot;Raw mode is not supported&quot; when its input is piped or redirected; it now says why and exits (use &lt;code&gt;-p&lt;/code&gt; for piped input)&lt;/li&gt;
&lt;li&gt;Bedrock, Vertex, Mantle: Fixed model availability checks under &lt;code&gt;CLAUDE_CODE_SKIP_*_AUTH&lt;/code&gt; sending a different &lt;code&gt;Authorization&lt;/code&gt; header than real requests when &lt;code&gt;ANTHROPIC_CUSTOM_HEADERS&lt;/code&gt; repeats it&lt;/li&gt;
&lt;li&gt;Improved &lt;code&gt;/config&lt;/code&gt;: settings that cycle show ‹ › and step both ways with ←/→, narrow terminals stack each value under its label, and PgUp/PgDn page the list&lt;/li&gt;
&lt;li&gt;Improved plugin marketplace errors to say in plain words why a marketplace was ignored or refused, and what to do&lt;/li&gt;
&lt;li&gt;Improved plugin listings to note when a plugin&#39;s dependencies were not installed, and updating a plugin now retries an install that did not finish&lt;/li&gt;
&lt;li&gt;Improved the Claude apps gateway&#39;s error when Amazon Bedrock rejects a model ID: developers now see which model is unavailable, and the gateway log names the ID that was sent&lt;/li&gt;
&lt;li&gt;Improved SDK sessions so a message sent with priority &quot;now&quot; no longer cancels a running web fetch or web search; it keeps loading in the background&lt;/li&gt;
&lt;li&gt;Improved &lt;code&gt;/memory&lt;/code&gt;: the left and right arrow keys now flip its on/off settings, such as Auto-memory&lt;/li&gt;
&lt;li&gt;Improved &lt;code&gt;/skill&lt;/code&gt; names typed mid-message: Claude is now told they are skills, including &lt;code&gt;disable-model-invocation&lt;/code&gt; ones&lt;/li&gt;
&lt;li&gt;Improved the contrast of the prompt input border in light themes and of the ❯ before your earlier messages&lt;/li&gt;
&lt;li&gt;Improved delivery of files Claude sends from cloud sessions and Remote Control: an upload that fails on a timeout, a network error or a 502, 503 or 504 is now retried once&lt;/li&gt;
&lt;li&gt;Improved what Claude says when a file cannot be sent for a reason that may be temporary: it now mentions that you can ask for the file again in a few minutes&lt;/li&gt;
&lt;li&gt;Improved the prompt for a held message from another session to show the message between dashed lines, matching other permission prompts&lt;/li&gt;
&lt;li&gt;Improved MCP and other tool permission prompts to show the tool call between dashed lines, matching file edit prompts&lt;/li&gt;
&lt;li&gt;Improved MCP startup in headless mode: a remote server whose first connect fails transiently is now retried without waiting for the slowest server to finish connecting&lt;/li&gt;
&lt;li&gt;Improved files Claude sends from a remote session: large files now stream from disk instead of being read into memory, and a file over the size limit is refused with the server&#39;s limit named&lt;/li&gt;
&lt;li&gt;Improved the explanation Claude gives when the server refuses a file it sends from a Remote Control or cloud session, such as an oversized image&lt;/li&gt;
&lt;li&gt;Improved handling of large MCP tool results: less memory, smaller session files, and no extra upload to count tokens for results far over the limit&lt;/li&gt;
&lt;li&gt;Windows: Improved Bash tool speed by removing a subshell that ran before every command&lt;/li&gt;
&lt;li&gt;Changed a shell write through a repo-committed symlink onto a sensitive file or out of the working tree to name where it lands and wait for a person, on lines with a &lt;code&gt;~&lt;/code&gt; target too&lt;/li&gt;
&lt;li&gt;Changed Opus 4.7+ and Fable to use a 1M context window by default on Bedrock, Vertex, Foundry and the Claude apps gateway, with no &lt;code&gt;[1m]&lt;/code&gt; suffix (&lt;code&gt;CLAUDE_CODE_DISABLE_1M_CONTEXT=1&lt;/code&gt; keeps 200K)&lt;/li&gt;
&lt;li&gt;Changed replies from &lt;code&gt;claude agents&lt;/code&gt; to arrive as queued messages; slash commands other than &lt;code&gt;/stop&lt;/code&gt; sent while a turn is running now run when it ends&lt;/li&gt;
&lt;li&gt;Changed whole-tool &lt;code&gt;Bash&lt;/code&gt; allow rules and allowing hooks to prompt for, not run, shell writes to files Claude Code&#39;s file tools refuse outright (the Anthropic profile store, the host credentials file)&lt;/li&gt;
&lt;li&gt;Changed right-click paste on Windows and Linux, and middle-click paste on Linux, to happen when the button is released; moving the pointer away before releasing cancels it&lt;/li&gt;
&lt;li&gt;Changed MCP server &lt;code&gt;alwaysLoad: false&lt;/code&gt; to defer all of that server&#39;s tools behind tool search&lt;/li&gt;
&lt;li&gt;Changed screen reader mode to write new or changed lines without first pausing with the cursor at the start of the line; set &lt;code&gt;CLAUDE_AX_PREPARK_MS=50&lt;/code&gt; to restore the pause&lt;/li&gt;
&lt;li&gt;Changed automatic model switches after a flagged message to keep your current effort level instead of the new model&#39;s default&lt;/li&gt;
&lt;li&gt;Changed waiting permission prompts to show oldest first, so a new prompt no longer covers the one you&#39;re reading (prompts with a countdown still open on top)&lt;/li&gt;
&lt;li&gt;[VSCode] Added &quot;Run in background&quot; to a running command or sub-agent, to move it to the background and keep working&lt;/li&gt;
&lt;li&gt;[VSCode] Added the output of background shells and Monitors to their cards in the agent map&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed settings dialogs blaming a timeout when Claude Code&#39;s reply was too large to confirm a save&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed reopening a cloud session that the side bar already brought to this machine opening it again in a new tab; the side bar is shown instead&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed the side bar&#39;s Web tab not listing cloud sessions started after the window loaded; a failed load now says &quot;Remote server is not connected&quot; instead of &quot;No web sessions yet&quot;&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed a tab restored after a reload starting a second Claude process on a conversation the side bar already has open; it now shows the &quot;still open somewhere else&quot; notice&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed tool-row file links, session-list links and two hints showing in plain text&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed a background agent&#39;s still-running command showing as failed once the main turn ended&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed a user&#39;s own &lt;code&gt;/usage&lt;/code&gt; or &lt;code&gt;/context&lt;/code&gt; command opening the extension&#39;s dialog instead of running when picked from the command menu&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed file links in the plan preview tab doing nothing when clicked; they now open the file like links in chat replies&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed opening a tool&#39;s input or output in an editor tab failing with &quot;Timeout waiting after 1000ms&quot; on remote hosts such as WSL when the tab is slow to appear&lt;/li&gt;
&lt;li&gt;[VSCode] Improved the Manage plugins dialog: a failed marketplace add, remove or refresh now says what went wrong&lt;/li&gt;
&lt;li&gt;[VSCode] Changed the Claude in Chrome &quot;Enabled by default&quot; switch to also connect the editor&#39;s own sessions, which still ask before browser actions&lt;/li&gt;
&lt;li&gt;[Cloud sessions] Fixed occasional failures to fetch from or push to GitHub when GitHub briefly refused a newly issued access token&lt;/li&gt;
&lt;li&gt;[Claude Tag] Fixed Claude posting a failure warning, such as a spend limit notice, in a Slack thread when a background event like GitHub activity woke it and nobody was waiting on a reply&lt;/li&gt;
&lt;li&gt;[Claude Tag] Fixed Claude Tag&#39;s spend limits page in admin settings leaving out recently created and private channels in organizations with many channels&lt;/li&gt;
&lt;li&gt;[Claude Tag] Improved Claude&#39;s task list in long Slack threads: background work no longer reposts it as a new message on its own, so people following the thread aren&#39;t notified&lt;/li&gt;
&lt;li&gt;[Code Review] Fixed finding comments and their &quot;Why this was flagged&quot; text stopping mid-sentence; they now end on a complete sentence&lt;/li&gt;
&lt;li&gt;[Code Review] Fixed Code Review skipping a pull request after a new push when its review had failed twice on the previous commit; it now reviews the latest commit&lt;/li&gt;
&lt;li&gt;[Code Review] Improved the failed-review card on a pull request whose conversation is locked: it now says the lock blocked the review and that nothing was posted or charged&lt;/li&gt;
&lt;/ul&gt;</content>
    <author>
      <name>ashwin-ant</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/178951676?s=60&amp;v=4"/>
  </entry>
  <entry>
    <id>tag:github.com,2008:Repository/937253475/v2.1.286</id>
    <updated>2026-09-30T19:10:13Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.286"/>
    <title>v2.1.286</title>
    <content type="html">&lt;h2&gt;What&#39;s changed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Added a count such as &quot;2 of 5&quot; to the permission prompt when several permission requests stack up&lt;/li&gt;
&lt;li&gt;Added mouse support for the &quot;N more&quot; rows of lists in fullscreen mode: click one to jump to that end of the list, with hover and pressed states&lt;/li&gt;
&lt;li&gt;Fixed several Claude Code processes and IDE extensions each opening a login browser when gcpAuthRefresh or awsAuthRefresh credentials expire&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude --resume&lt;/code&gt; and &lt;code&gt;--continue&lt;/code&gt; sometimes losing every turn after a batch of parallel tool calls when the earlier session crashed or was killed&lt;/li&gt;
&lt;li&gt;Fixed API 400 errors after a tool or hook returned an object, number or boolean instead of text, including in resumed sessions&lt;/li&gt;
&lt;li&gt;Fixed cloud sessions with very large histories never waking up because the container was stopped while the transcript was still loading&lt;/li&gt;
&lt;li&gt;Fixed the Claude apps gateway&#39;s spend meter pricing 1-hour prompt cache writes at the cheaper 5-minute rate, and counting only the first model call&#39;s input tokens on streamed turns that run a server-side tool such as web search&lt;/li&gt;
&lt;li&gt;Fixed macOS sessions still showing &quot;Not logged in&quot; or &quot;Login expired&quot; after &lt;code&gt;/login&lt;/code&gt; succeeds in another Claude Code window when a leftover &lt;code&gt;~/.claude/.credentials.json&lt;/code&gt; exists&lt;/li&gt;
&lt;li&gt;Fixed every turn failing when the Anthropic API refuses the model your default or a model alias resolves to: Claude Code now retries once on the previous model of the same tier&lt;/li&gt;
&lt;li&gt;Fixed Remote Control sessions (including &lt;code&gt;claude remote-control&lt;/code&gt;) staying connected after your organization&#39;s policy turns Remote Control off; they now disconnect with a notice&lt;/li&gt;
&lt;li&gt;Fixed refusal and &lt;code&gt;--fallback-model&lt;/code&gt; retries failing when the fallback model can&#39;t run fast; they now run at standard speed, with a one-time notice in interactive sessions&lt;/li&gt;
&lt;li&gt;Fixed headless sessions repeating the &quot;MCP servers require authentication&quot; reminder after a successful re-authentication when the MCP discovery cache is enabled&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude auth status&lt;/code&gt; reporting a Console sign-in&#39;s stored API key as &lt;code&gt;claude.ai&lt;/code&gt;; it now reports &lt;code&gt;api_key&lt;/code&gt;, and the VS Code extension treats that session as an API key session&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/status&lt;/code&gt; listing an Anthropic profile beside an API key as if both were in effect; the profile is now marked as not in use&lt;/li&gt;
&lt;li&gt;Fixed Claude not being told when a file attached to a message sent over Remote Control did not arrive, and a file sometimes getting only 10 seconds for its last download try&lt;/li&gt;
&lt;li&gt;Fixed a Remote Control message that arrived while Claude Code was exiting being marked delivered and then never answered; it now stays queued for the session&#39;s next run&lt;/li&gt;
&lt;li&gt;Fixed MCP error messages showing a credential&#39;s value when &quot;Bearer&quot; or &quot;Basic&quot; came before its key name&lt;/li&gt;
&lt;li&gt;Fixed percent-encoded Bearer tokens being only partly masked in error messages&lt;/li&gt;
&lt;li&gt;Fixed redacted logs and transcripts showing a secret whose key name has an invisible character inside, such as a zero-width space&lt;/li&gt;
&lt;li&gt;Fixed logs and transcripts showing part of a URL password that contains punctuation such as &lt;code&gt;)&lt;/code&gt;, quotes, &lt;code&gt;]&lt;/code&gt;, &lt;code&gt;&amp;amp;&lt;/code&gt; or a second &lt;code&gt;@&lt;/code&gt;, or that runs past a &lt;code&gt;/&lt;/code&gt; to a bracketed host such as &lt;code&gt;[::1]&lt;/code&gt; in an ssh URL&lt;/li&gt;
&lt;li&gt;Fixed the session transcript in the zip that &lt;code&gt;/feedback&lt;/code&gt; saves to disk containing invalid JSON lines after secret redaction&lt;/li&gt;
&lt;li&gt;Fixed MCP connectors listing no tools for up to a day after their server dropped the older MCP handshake&lt;/li&gt;
&lt;li&gt;Fixed a repeat MCP sign-in request from Claude replacing the pending sign-in link, which could stop that link from working&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/usage&lt;/code&gt; not crediting an MCP server for a tool call made while that server was still connecting or had only just connected, such as right after a restart&lt;/li&gt;
&lt;li&gt;Fixed plugins enabled on claude.ai occasionally going missing from Claude Code for a session after a transient server error&lt;/li&gt;
&lt;li&gt;Fixed a message typed into a running subagent showing twice in its transcript after the subagent read it&lt;/li&gt;
&lt;li&gt;Fixed subagent hand-back messages showing a raw task id instead of the agent&#39;s name when the subagent had no registered name&lt;/li&gt;
&lt;li&gt;Fixed foreground subagents sometimes missing the task-tracking tools (TaskCreate/Get/Update/List, TodoWrite) in sessions that have them enabled&lt;/li&gt;
&lt;li&gt;Fixed subagents spawned with worktree isolation loading the project CLAUDE.md and its imports a second time from the worktree copy on their first file read&lt;/li&gt;
&lt;li&gt;Fixed Workflow tool subagents being restarted from their original prompt when a connection stalled for a few minutes mid-response&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/compact&lt;/code&gt;, &lt;code&gt;/clear&lt;/code&gt;, and &lt;code&gt;/rewind&lt;/code&gt; typed while viewing a background agent&#39;s or teammate&#39;s transcript silently acting on the main conversation: a dialog now names the target and asks first&lt;/li&gt;
&lt;li&gt;Fixed background jobs showing done while waiting for your approval&lt;/li&gt;
&lt;li&gt;Fixed the commit attribution reminder being re-sent inside tool output when a model fallback lasts only one turn&lt;/li&gt;
&lt;li&gt;Fixed a click on the space between words of a collapsed row (such as &quot;Thought for 4s&quot;) highlighting the row without expanding it in fullscreen mode&lt;/li&gt;
&lt;li&gt;Fixed a row with no details, such as an action row with a long name, pushing every other row&#39;s details to the right in list screens&lt;/li&gt;
&lt;li&gt;Fixed files with very long names not reaching a cloud session when attached to it&lt;/li&gt;
&lt;li&gt;Fixed plugin errors for a marketplace Claude Code refuses to load: they now say why and how to fix it instead of &quot;not found&quot;&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/plugin&lt;/code&gt;&#39;s Discover tab showing a marketplace name unquoted in its &quot;Checking … for new plugins&quot; line when its rows already show that name in quotes&lt;/li&gt;
&lt;li&gt;Improved commit guidance: when your project or user skills include one named &lt;code&gt;verify&lt;/code&gt;, Claude is now told to run it right before committing, except for docs-only and tests-only commits&lt;/li&gt;
&lt;li&gt;Improved send now (ctrl+enter) in a subagent&#39;s view: it now moves the subagent&#39;s running command to the background so your message is read right away&lt;/li&gt;
&lt;li&gt;Improved replies from background agents to your messages so they no longer open with a separate recap of what you said&lt;/li&gt;
&lt;li&gt;Improved claude.ai artifact link reads: WebFetch now asks the same questions as the Artifact tool&#39;s read (no artifact prompt while the session&#39;s network access is on, one per artifact while it is off), and an auto-mode yes no longer counts where only you can answer&lt;/li&gt;
&lt;li&gt;Improved fetch, skill, file read, sandbox network, Claude in Chrome, workflow script and notebook edit permission prompts to match the look of file edit prompts&lt;/li&gt;
&lt;li&gt;Improved Bash, PowerShell and Monitor permission prompts to show the command between dashed lines, matching file edit prompts&lt;/li&gt;
&lt;li&gt;Improved list scrollbars in fullscreen mode: in most lists the bar no longer shifts as the &quot;N more&quot; rows come and go, and it now has ↑/↓ arrows you can click or hold to scroll&lt;/li&gt;
&lt;li&gt;Improved the external editor (Ctrl+G): editors that take a line number now open on the line your cursor is on in the prompt&lt;/li&gt;
&lt;li&gt;Improved slash command suggestion responsiveness while typing when many skills or plugin commands are installed; command descriptions now match by word prefix&lt;/li&gt;
&lt;li&gt;Improved the output style picker: it now opens on your current style instead of Default, with each style&#39;s description on the line under its name; number keys no longer pick a style&lt;/li&gt;
&lt;li&gt;Improved &lt;code&gt;/hooks&lt;/code&gt;: the closing line of a hook&#39;s detail screen now says &quot;this hook&quot; instead of &quot;it&quot;&lt;/li&gt;
&lt;li&gt;Improved the model fallback notice and the autocompact-thrashing error to say when a fallback dropped the context window from 1M to 200K tokens&lt;/li&gt;
&lt;li&gt;Improved responsiveness of SDK and &lt;code&gt;-p&lt;/code&gt; sessions when a host re-sends an MCP server enable for a server that is already connected&lt;/li&gt;
&lt;li&gt;Improved the protocol page a Claude apps gateway serves at &lt;code&gt;/protocol&lt;/code&gt;: it now says not to reject unknown input and matches what Claude Code sends today&lt;/li&gt;
&lt;li&gt;Changed prompts sent while nothing is running or queued to show in the normal text color right away instead of gray&lt;/li&gt;
&lt;li&gt;Changed how failed API requests are retried: one limit now covers a whole model call, so with the default retry settings a failing call sends at most 14 requests&lt;/li&gt;
&lt;li&gt;Changed &lt;code&gt;--bare&lt;/code&gt; to connect only the MCP servers named on the command line, send the model no system reminders, and start no background tasks; under &lt;code&gt;--bare&lt;/code&gt;, a shell command that reaches its timeout now stops instead of moving to the background&lt;/li&gt;
&lt;li&gt;Changed the send-now key (ctrl+enter) to move a skill&#39;s own shell command to the background instead of ending it&lt;/li&gt;
&lt;li&gt;Changed the WebFetch error for a rate-limited domain safety check to tell Claude not to retry it in a loop&lt;/li&gt;
&lt;li&gt;Changed plugin installs to refuse npm sources that are git repositories or folders, and to install plugin dependencies only from registry packages&lt;/li&gt;
&lt;li&gt;Changed list screens (&lt;code&gt;/artifacts&lt;/code&gt;, &lt;code&gt;/mcp&lt;/code&gt;, &lt;code&gt;/skills&lt;/code&gt;, &lt;code&gt;/hooks&lt;/code&gt; and others) to always line up each row&#39;s details in one column after the names&lt;/li&gt;
&lt;li&gt;Changed the overflow rows of lists to read &quot;↑ N more&quot; / &quot;↓ N more&quot; instead of &quot;N more above&quot; / &quot;N more below&quot;&lt;/li&gt;
&lt;li&gt;Changed &lt;code&gt;/hooks&lt;/code&gt; to open on one list of your configured hooks grouped by event, so viewing a hook takes one Enter instead of three&lt;/li&gt;
&lt;li&gt;Changed the theme picker to a scrolling list that fits your terminal instead of pushing the preview off screen; number keys no longer pick a theme&lt;/li&gt;
&lt;li&gt;Changed &lt;code&gt;/exit&lt;/code&gt;&#39;s Remove worktree to run after Claude Code stops the servers and shells it started there, which on Windows could keep the folder from being deleted&lt;/li&gt;
&lt;li&gt;Changed the &lt;code&gt;claude-api&lt;/code&gt; skill&#39;s Managed Agents examples to create environments with limited networking&lt;/li&gt;
&lt;li&gt;Removed the browser link from &lt;code&gt;/ultrareview&lt;/code&gt; and &lt;code&gt;claude ultrareview&lt;/code&gt; output&lt;/li&gt;
&lt;li&gt;Windows: Fixed &lt;code&gt;claude --bg&lt;/code&gt; and the agents view refusing a folder that &lt;code&gt;claude&lt;/code&gt; already trusts when its trust record was saved with different letter case&lt;/li&gt;
&lt;li&gt;[VSCode] Added bookmarks: save Claude&#39;s responses and keep them in view in a Bookmarks side panel&lt;/li&gt;
&lt;li&gt;[VSCode] Added the questions Claude asks and your answers to the conversation: after you answer a question card, a Questions row shows each question with your picks&lt;/li&gt;
&lt;li&gt;[VSCode] Added option previews to question cards in the chat panel: the highlighted choice&#39;s mockup or snippet shows beside or under the options&lt;/li&gt;
&lt;li&gt;[VSCode] Added rows under a message that open to the terminal output, browser tab, browser instructions and selected code sent with it&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed a second copy of a conversation opening in a tab when it was already open in the side bar; the side bar now switches to it&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed settings dialogs reporting a failed save, without re-checking, when Claude Code printed more than 1 MB of output&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed an endless &quot;Teleporting session…&quot; spinner when the extension stops responding&lt;/li&gt;
&lt;li&gt;[VSCode] Improved the Manage plugins dialog: it says when a turned-off plugin is still on because of other settings, and explains a plugin folder clash&lt;/li&gt;
&lt;li&gt;[VSCode] Changed Stop and Escape to end only the current turn; background agents keep running and can be stopped one by one from the agent map&lt;/li&gt;
&lt;li&gt;[VSCode] Changed the &quot;✻ Claude Code&quot; status bar item to show in every window, so you can open Claude when no file is open&lt;/li&gt;
&lt;li&gt;[Cloud sessions] Fixed an answered question card or approved tool call getting no reply when the session had gone idle after Claude sent a message&lt;/li&gt;
&lt;li&gt;[Cloud sessions] Fixed clearing an organization environment&#39;s setup script in admin settings leaving new cloud sessions still running the old script&lt;/li&gt;
&lt;li&gt;[Cloud sessions] Fixed the Runner actions menu on the self-hosted environments admin page closing on its own a few seconds after it opened&lt;/li&gt;
&lt;li&gt;[Cloud sessions] Fixed routine runs whose cloud session never started showing as Succeeded in the Runs pane, the routine&#39;s page and the sidebar; they now show as Failed&lt;/li&gt;
&lt;li&gt;[Cloud sessions] Fixed clicking an audio or video file in a cloud session&#39;s Outputs card opening an empty file search instead of playing the file&lt;/li&gt;
&lt;li&gt;[Cloud sessions] Changed a routine&#39;s page to read &quot;Due&quot; with the scheduled time, instead of a next run time in the past, when a scheduled run is late and hasn&#39;t started&lt;/li&gt;
&lt;li&gt;[Claude Tag] Added an Add channel button to Claude Tag&#39;s spend limits page in admin settings, so a limit can be set on any channel, including a private one, from its channel ID or Slack link&lt;/li&gt;
&lt;li&gt;[Claude Tag] Fixed memory recall finding nothing in organizations that cannot use the default Sonnet model&lt;/li&gt;
&lt;li&gt;[Claude Tag] Fixed a Slack channel losing its Claude settings when an Enterprise Grid admin moves it to another workspace and the first post afterward doesn&#39;t mention Claude&lt;/li&gt;
&lt;li&gt;[Claude Tag] Fixed Claude in a Slack thread occasionally starting over on a fresh machine, losing work it hadn&#39;t pushed, when your reply answered a question it had just asked&lt;/li&gt;
&lt;li&gt;[Claude Tag] Fixed public channel names on Claude Tag&#39;s spend limits page in admin settings showing as raw Slack IDs in larger organizations&lt;/li&gt;
&lt;li&gt;[Claude Tag] Improved the titles of sessions started from Slack as shown on claude.ai: they now read as the words you typed, without Slack user IDs or escape codes&lt;/li&gt;
&lt;/ul&gt;</content>
    <author>
      <name>ashwin-ant</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/178951676?s=60&amp;v=4"/>
  </entry>
  <entry>
    <id>tag:github.com,2008:Repository/937253475/v2.1.285</id>
    <updated>2026-09-29T19:27:30Z</updated>
    <link rel="alternate" type="text/html" href="https://github.com/anthropics/claude-code/releases/tag/v2.1.285"/>
    <title>v2.1.285</title>
    <content type="html">&lt;h2&gt;What&#39;s changed&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Added &lt;code&gt;CLAUDE_CODE_DISABLE_WEB_FETCH&lt;/code&gt; environment variable to turn off the WebFetch tool&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;claude --desktop&lt;/code&gt; to open the Claude desktop app on the current directory, or on a session with &lt;code&gt;--continue&lt;/code&gt; / &lt;code&gt;--resume &amp;lt;id&amp;gt;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;claude plugin configure &amp;lt;plugin&amp;gt;&lt;/code&gt; to show a plugin&#39;s options and which are unset, or save new values read from stdin with &lt;code&gt;--values-stdin&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;&amp;lt;server&amp;gt;.&amp;lt;key&amp;gt;=&amp;lt;value&amp;gt;&lt;/code&gt; to &lt;code&gt;claude plugin install --config&lt;/code&gt;, so a bundled &lt;code&gt;.mcpb&lt;/code&gt; MCP server&#39;s own settings can be set at install time and it starts without visiting &lt;code&gt;/plugin&lt;/code&gt; → Configure&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;allowedProviders&lt;/code&gt; managed setting to limit which API providers a machine may use (Anthropic API, a custom endpoint, Bedrock, Mantle, Vertex AI, Foundry, Claude Platform on AWS, or a Cloud gateway)&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;CLAUDE_CODE_NONSTREAMING_TIMEOUT_RETRIES&lt;/code&gt; environment variable to cap re-sends of a non-streaming fallback request that timed out&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude -p&lt;/code&gt; with &lt;code&gt;CLAUDE_CODE_FORK_SUBAGENT=1&lt;/code&gt;: a subagent&#39;s own Agent call now runs in the foreground, so the subagent gets the child&#39;s result&lt;/li&gt;
&lt;li&gt;Fixed plugin and marketplace installs and updates over SSH ignoring the ssh program set in &lt;code&gt;GIT_SSH&lt;/code&gt; or in your git config&#39;s &lt;code&gt;core.sshCommand&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fixed Claude Code refusing to start when the OS denies reading the managed settings file; it now warns and starts without that file&#39;s policies. Other read errors and unparseable files stop every session&lt;/li&gt;
&lt;li&gt;Fixed cloud sessions that restarted after their conversation was compacted refusing the next update to an artifact the session had already read or published&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude plugin disable&lt;/code&gt; and &lt;code&gt;enable&lt;/code&gt; with a full &lt;code&gt;name@marketplace&lt;/code&gt; id changing a settings entry in another letter case instead of the installed plugin&#39;s own&lt;/li&gt;
&lt;li&gt;Fixed files attached to a message sent over Remote Control being left out after a single failed download; a network error, timeout or server error is now retried up to twice&lt;/li&gt;
&lt;li&gt;Fixed switching models mid-session with a &lt;code&gt;set_model&lt;/code&gt; request (such as the Agent SDK&#39;s &lt;code&gt;setModel&lt;/code&gt;) leaving the new model on the built-in output-token limit and auto-compact window until restart&lt;/li&gt;
&lt;li&gt;Fixed redacted logs and transcripts showing part of a URL password that contains &lt;code&gt;@&lt;/code&gt;, or all of it when the URL writes its &lt;code&gt;@&lt;/code&gt; as &lt;code&gt;%40&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fixed SSH passphrase and new-host prompts from worktree and &lt;code&gt;/teleport&lt;/code&gt; fetches taking over the terminal; these fetches now fail fast instead of asking&lt;/li&gt;
&lt;li&gt;Fixed switching off an MCP server added mid-session in SDK and &lt;code&gt;-p&lt;/code&gt; sessions leaving its tools available&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude -p --permission-prompt-tool&lt;/code&gt;: a background subagent&#39;s permission request now goes to the prompt tool instead of being auto-denied&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude mcp list&lt;/code&gt; and &lt;code&gt;claude mcp get&lt;/code&gt;, and the not-found error of &lt;code&gt;claude mcp remove&lt;/code&gt;, &lt;code&gt;login&lt;/code&gt; and &lt;code&gt;logout&lt;/code&gt;, printing line breaks and terminal escape sequences from MCP server names and values&lt;/li&gt;
&lt;li&gt;Fixed sandbox auto-allow asking for approval on every run of many inline scripts (&lt;code&gt;python3 -c&lt;/code&gt;, &lt;code&gt;node -e&lt;/code&gt;) just because they contain &lt;code&gt;=&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fixed fork subagents not keeping the session&#39;s plan mode or &lt;code&gt;dontAsk&lt;/code&gt; mode: a fork now runs under its parent&#39;s permission mode and cannot exit plan mode&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude remote-control --help&lt;/code&gt; saying &lt;code&gt;--[no-]chrome&lt;/code&gt; defaults to the machine&#39;s &lt;code&gt;/chrome&lt;/code&gt; setting; spawned sessions keep Claude in Chrome off unless &lt;code&gt;--chrome&lt;/code&gt; is passed&lt;/li&gt;
&lt;li&gt;Fixed background subagents in auto mode prompting a second, redundant reply after each report&lt;/li&gt;
&lt;li&gt;Fixed cloud session creation and &lt;code&gt;/remote-env&lt;/code&gt; reading only the newest 20 of an account&#39;s environments&lt;/li&gt;
&lt;li&gt;Fixed Remote Control marking a message as read as soon as it arrived instead of when Claude started on it, and losing a message still queued when the terminal quit (it now arrives on the next resume)&lt;/li&gt;
&lt;li&gt;Fixed installing a plugin with &lt;code&gt;claude plugin install&lt;/code&gt; or &lt;code&gt;/plugin&lt;/code&gt; putting it into an installed plugin&#39;s cache or data folder when their ids differ only in &lt;code&gt;.&lt;/code&gt;, &lt;code&gt;-&lt;/code&gt;, &lt;code&gt;@&lt;/code&gt; or (macOS, Windows) capitals; the install is now refused&lt;/li&gt;
&lt;li&gt;Fixed hooks and SDK permission callbacks seeing a missing or outdated plan on ExitPlanMode when the plan was written in the same response&lt;/li&gt;
&lt;li&gt;Fixed the first reply in cloud sessions arriving tens of milliseconds late, a regression in 2.1.283&lt;/li&gt;
&lt;li&gt;Fixed sessions that authenticate with &lt;code&gt;ANTHROPIC_AUTH_TOKEN&lt;/code&gt; against the Anthropic API never loading the organization&#39;s policy&lt;/li&gt;
&lt;li&gt;Fixed a failed &lt;code&gt;agent()&lt;/code&gt;, &lt;code&gt;parallel()&lt;/code&gt; or &lt;code&gt;pipeline()&lt;/code&gt; call that a workflow script awaits later, or not at all, being treated as an unhandled promise rejection, which could end a background session&lt;/li&gt;
&lt;li&gt;Fixed synchronous hooks hanging Claude Code while a background process the hook started (for example &lt;code&gt;some-daemon &amp;amp;&lt;/code&gt;) kept its output open; the hook now finishes shortly after its own process exits&lt;/li&gt;
&lt;li&gt;Fixed WebFetch reporting a rate-limited domain safety check as a network or enterprise policy block&lt;/li&gt;
&lt;li&gt;Fixed the fullscreen ctrl+o transcript freezing briefly when opened on turns with hundreds of file reads or searches; tool calls still running when the transcript opens now show their results when they finish&lt;/li&gt;
&lt;li&gt;Fixed Amazon Bedrock mid-stream &lt;code&gt;modelTimeoutException&lt;/code&gt; and &lt;code&gt;serviceUnavailableException&lt;/code&gt; errors showing a raw JSON body instead of the error message&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/autofix-pr&lt;/code&gt; and &lt;code&gt;/schedule&lt;/code&gt; saying the Claude GitHub App is not installed on a repository whose install status had not been checked yet&lt;/li&gt;
&lt;li&gt;Fixed dismissing a row (x) in &lt;code&gt;/artifacts&lt;/code&gt; unlinking its file from the artifact, so publishing the same file again created a new artifact instead of updating it&lt;/li&gt;
&lt;li&gt;Fixed Artifact tool publishes after a conversation rewind (Esc Esc) overwriting a file&#39;s newer content that Claude had read only in the rewound turns; the publish is now refused until Claude re-reads the file&lt;/li&gt;
&lt;li&gt;Fixed an &lt;code&gt;Artifact&lt;/code&gt; allow rule (&quot;don&#39;t ask again&quot;) letting the Artifact tool publish a file outside the working directories without asking; add the file&#39;s folder with &lt;code&gt;--add-dir&lt;/code&gt; for the rule to cover it&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/cost&lt;/code&gt; and SDK &lt;code&gt;modelUsage&lt;/code&gt; reporting a turn under the wrong model when the server answered a refusal with a different fallback model than the client expected&lt;/li&gt;
&lt;li&gt;Fixed the Artifact tool so that publishing a page no longer lets Claude overwrite its source file without re-reading it when Claude&#39;s earlier read was cut short or the file had changed since&lt;/li&gt;
&lt;li&gt;Fixed auto mode skipping its classifier for Artifact tool asset uploads and reads of someone else&#39;s artifact when you had approved that artifact earlier in another permission mode&lt;/li&gt;
&lt;li&gt;Fixed a misleading &quot;core.worktree is set&quot; error from &lt;code&gt;/ultrareview&lt;/code&gt; when the project folder briefly could not be read&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/ultrareview&lt;/code&gt; on macOS and Linux failing to upload the working tree from a git worktree whose per-worktree config sets &lt;code&gt;core.longpaths&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fixed the Artifact tool sometimes reporting a publish as a conflict with another session after retrying a temporary server error, when the first attempt had actually succeeded&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/ultrareview&lt;/code&gt; uploads including uncommitted changes to credential files whose name has a colon before the extension, such as &lt;code&gt;server:8443.key&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fixed a rare auth failure when two sessions recover a login refresh lock left by a crashed process at the same time&lt;/li&gt;
&lt;li&gt;Fixed the PowerShell tool&#39;s permission check skipping deny and ask rules, and caching that failure for later checks, when its command parser failed to start (for example when the machine was out of memory)&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;/ultrareview&lt;/code&gt; uploads on macOS and Linux running slowly on some unusual file names, and their credential-file check missing file or folder names with many backup or editor marks&lt;/li&gt;
&lt;li&gt;Fixed a cancelled shell command or hook still starting, and running to its end, when the cancel arrived while it was being set up&lt;/li&gt;
&lt;li&gt;Fixed vim mode: after editing in the external editor (Ctrl+G), &lt;code&gt;x&lt;/code&gt; or &lt;code&gt;r&lt;/code&gt; in NORMAL mode no longer breaks a pasted-text placeholder at the end of the prompt&lt;/li&gt;
&lt;li&gt;Fixed responses blocked by the API&#39;s output content filter being re-sent and retried, sometimes for minutes, instead of showing the filter&#39;s error right away&lt;/li&gt;
&lt;li&gt;Fixed plugins silently skipping a bundled &lt;code&gt;.mcpb&lt;/code&gt; MCP server that still needs configuration: &lt;code&gt;/plugin&lt;/code&gt;, the install message and &lt;code&gt;claude plugin install&lt;/code&gt; now say so and point to Configure&lt;/li&gt;
&lt;li&gt;Fixed compacting or resuming a session failing, opening without its history, or crashing when its saved transcript holds a compaction marker or loop wakeup entry with missing or malformed fields&lt;/li&gt;
&lt;li&gt;WSL: Fixed &lt;code&gt;/ultrareview&lt;/code&gt; refusing to upload a checkout on a Linux volume when a changed file&#39;s name has a colon or ends in a dot or space&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;CLAUDE_CODE_RESUME_INTERRUPTED_TURN&lt;/code&gt; re-running a turn that had ended at &lt;code&gt;--max-turns&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fixed sign-in that could wait forever after the browser showed success&lt;/li&gt;
&lt;li&gt;Windows: Fixed &lt;code&gt;/ultrareview&lt;/code&gt; uploading a linked worktree of a repository rooted at your home folder in some cases&lt;/li&gt;
&lt;li&gt;Fixed cloud sessions reporting the uploads folder as missing before any file had been uploaded&lt;/li&gt;
&lt;li&gt;Fixed a reply sent from &lt;code&gt;claude agents&lt;/code&gt; to a background session waiting on a permission prompt sometimes approving the pending command&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude attach&lt;/code&gt;, &lt;code&gt;logs&lt;/code&gt;, &lt;code&gt;stop&lt;/code&gt;, &lt;code&gt;respawn&lt;/code&gt; and &lt;code&gt;rm&lt;/code&gt; starting a new session with the command name as its prompt when options came before it, such as from a shell alias&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude mcp list&lt;/code&gt; leaving out WebSocket (&lt;code&gt;ws&lt;/code&gt;) MCP servers; each is now listed with its URL and health status&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;claude mcp get&lt;/code&gt; showing no Type, Command, Args, or Environment for stdio servers whose config entry omits the &lt;code&gt;type&lt;/code&gt; field&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;.claude/settings.local.json&lt;/code&gt; allow rules being held back outside a git repository when git&#39;s trace2 output is configured&lt;/li&gt;
&lt;li&gt;Fixed the &lt;code&gt;/claude-api&lt;/code&gt; eval runner scaffold and report builder writing through a symlink or hard link planted at an output file&lt;/li&gt;
&lt;li&gt;Fixed the &lt;code&gt;/claude-api&lt;/code&gt; eval runner scaffold counting responses cut off at &lt;code&gt;max_tokens&lt;/code&gt; in the score averages; they are now marked truncated and counted separately&lt;/li&gt;
&lt;li&gt;Fixed &lt;code&gt;&amp;amp;nbsp;&lt;/code&gt; showing as literal text in the terminal when a reply uses it to indent text, such as row labels in a markdown table&lt;/li&gt;
&lt;li&gt;Fixed a brief freeze (up to a second) partway through long sessions outside fullscreen mode, which came back after &lt;code&gt;/clear&lt;/code&gt; or &lt;code&gt;/compact&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Fixed an approved Edit never going through when its target is a device, such as a file symlinked to /dev/null, and the approval came from the IDE diff view or changed the edit&lt;/li&gt;
&lt;li&gt;Fixed a failing API request being retried up to 21 times when streaming kept failing; the non-streaming fallback now shares the request&#39;s retry budget instead of getting a fresh set of retries&lt;/li&gt;
&lt;li&gt;Improved Claude in Chrome: the native host now reports your computer&#39;s name, so connected browsers can be labeled by computer instead of &quot;Browser 1&quot; / &quot;Browser 2&quot;&lt;/li&gt;
&lt;li&gt;Improved Bedrock and Vertex AI sessions to switch to an older available model of the same tier, instead of failing, when an admin removes access to the default model; session titles and summaries now fall back with it&lt;/li&gt;
&lt;li&gt;Improved plugin marketplace errors to name why a git address is refused instead of citing enterprise policy&lt;/li&gt;
&lt;li&gt;Improved validation of git URLs for plugins, marketplaces and the current repository&#39;s remote&lt;/li&gt;
&lt;li&gt;Improved Artifact tool results: they now suggest publishing in the same step as writing or editing the page, which can save a round trip&lt;/li&gt;
&lt;li&gt;Improved Remote Control: a &lt;code&gt;/btw&lt;/code&gt; side question asked of a session hosted by an app such as Claude Desktop now sees the turn in progress, not only the last finished one&lt;/li&gt;
&lt;li&gt;Improved pictures Claude sends as BMP, HEIC, HEIF, AVIF or TIFF files: the Claude apps now show a preview where Claude Code can convert them&lt;/li&gt;
&lt;li&gt;Improved subagents in auto mode: a subagent&#39;s run now ends as soon as it hands its report back to its caller, instead of taking extra turns that reach no one&lt;/li&gt;
&lt;li&gt;Improved Bedrock and Vertex start-up model checks: models your account cannot use are now remembered for up to a day instead of being re-checked on every launch&lt;/li&gt;
&lt;li&gt;Improved Artifact tool publish results to use fewer tokens: the note on updating an artifact is shorter, and where to find your artifacts is no longer repeated after every publish&lt;/li&gt;
&lt;li&gt;Improved SDK liveness during a non-streaming fallback request: with partial messages on, a &lt;code&gt;ping&lt;/code&gt; stream event is now sent every 30 seconds on the Anthropic API, Claude Platform on AWS and gateways&lt;/li&gt;
&lt;li&gt;Improved &lt;code&gt;/resume&lt;/code&gt; and &lt;code&gt;claude --resume&lt;/code&gt; on a session that is running in the background: they now open that session instead of refusing, and a prompt given with &lt;code&gt;claude --resume &amp;lt;id&amp;gt; &quot;prompt&quot;&lt;/code&gt; is sent to it as its next turn&lt;/li&gt;
&lt;li&gt;Improved per-turn performance when many permission deny rules and MCP tools are configured&lt;/li&gt;
&lt;li&gt;Improved responsiveness when leaving the ctrl+o transcript view in long sessions when fullscreen rendering is off&lt;/li&gt;
&lt;li&gt;Improved Bedrock, Vertex and Mantle start-up model checks to send the same User-Agent, x-app and session ID headers as regular requests&lt;/li&gt;
&lt;li&gt;Changed MCP tools so a tool that sets its own &lt;code&gt;_meta[&#39;anthropic/alwaysLoad&#39;]&lt;/code&gt; to false stays deferred when its &lt;code&gt;--mcp-config&lt;/code&gt;, Agent SDK or plugin server is set to &lt;code&gt;alwaysLoad&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Changed background Bash and PowerShell commands to stop after a time limit (their &lt;code&gt;timeout&lt;/code&gt; with &lt;code&gt;run_in_background&lt;/code&gt;, default 30 min, max 2 h); Claude is notified when one is stopped&lt;/li&gt;
&lt;li&gt;Changed Code Review&#39;s pull request reviews and &lt;code&gt;/ultrareview&lt;/code&gt; to run when &lt;code&gt;disableWorkflows&lt;/code&gt; is on, unless the machine running the review has it set by its own administrator (MDM or the managed-settings file)&lt;/li&gt;
&lt;li&gt;Changed sessions behind a custom &lt;code&gt;ANTHROPIC_BASE_URL&lt;/code&gt; to use the 1M context window of models that have one (Opus 4.7+, Sonnet 5+, Fable); run &lt;code&gt;/autocompact 200k&lt;/code&gt; if your gateway stops at 200K&lt;/li&gt;
&lt;li&gt;Changed Team and Enterprise sessions, and sessions whose sign-in plan Claude Code can&#39;t determine, to withhold WebFetch until the organization policy loads if it couldn&#39;t be loaded at startup&lt;/li&gt;
&lt;li&gt;Changed /memory so that Auto-memory can no longer be turned on from a background session or from a session one of Claude Code&#39;s own tools started; turning it off there still works&lt;/li&gt;
&lt;li&gt;Changed the one-time offer to make auto mode your default permission mode to also show on third-party providers and with telemetry off, when your user settings default to another mode&lt;/li&gt;
&lt;li&gt;Changed &lt;code&gt;claude -p&lt;/code&gt; and Python Agent SDK sessions on third-party providers or with telemetry off to start in auto mode when no permission mode is configured, like interactive sessions; &lt;code&gt;--permission-mode&lt;/code&gt; still overrides it&lt;/li&gt;
&lt;li&gt;Changed Bedrock, Mantle and Claude Platform on AWS requests to a base URL with a non-default port to include the port in the SigV4-signed Host header&lt;/li&gt;
&lt;li&gt;Changed the MCP server name &lt;code&gt;widgets&lt;/code&gt; to be reserved in cloud sessions and on self-hosted runners: your own server under it, or a close spelling such as &lt;code&gt;widgets_&lt;/code&gt;, no longer loads, so rename it&lt;/li&gt;
&lt;li&gt;Changed &lt;code&gt;/ultrareview&lt;/code&gt; on macOS and Linux to leave symbolic refs out when uploading a local checkout; a checkout whose current branch is a symbolic ref is now refused with an explanation&lt;/li&gt;
&lt;li&gt;Windows: Changed project and local settings &lt;code&gt;env&lt;/code&gt; to no longer set &lt;code&gt;ALLUSERSPROFILE&lt;/code&gt;, &lt;code&gt;SystemDrive&lt;/code&gt;, or the &lt;code&gt;CommonProgramFiles&lt;/code&gt; variables; set them in user or managed settings instead&lt;/li&gt;
&lt;li&gt;Changed &lt;code&gt;/tasks&lt;/code&gt; to fold background work Claude Code runs for itself under one &quot;System tasks&quot; row; press Enter on it to show those tasks&lt;/li&gt;
&lt;li&gt;Changed &lt;code&gt;/ultrareview&lt;/code&gt; on macOS and Linux to require git 2.31 or newer to upload a local repository; checkouts made with &lt;code&gt;--separate-git-dir&lt;/code&gt; are now refused instead of being uploaded with an older method&lt;/li&gt;
&lt;li&gt;Changed &lt;code&gt;/ultrareview&lt;/code&gt; uploads on macOS and Linux to send a partial clone as a working-tree snapshot on git 2.31 or newer, instead of falling back or refusing when git&#39;s version looked too old&lt;/li&gt;
&lt;li&gt;Changed &lt;code&gt;/ultrareview&lt;/code&gt; uploads on macOS and Linux to refuse, instead of fetching, a partial clone missing some of its working tree&#39;s files on older git versions; a clone made without &lt;code&gt;--filter&lt;/code&gt; uploads&lt;/li&gt;
&lt;li&gt;Changed Bedrock, Vertex and Mantle start-up model checks to identify themselves as Claude Code, like other Claude Code requests&lt;/li&gt;
&lt;li&gt;Changed &lt;code&gt;claude mcp get&lt;/code&gt; to hide the command, arguments, and environment values of stdio MCP servers provided by plugins; variable names are still shown&lt;/li&gt;
&lt;li&gt;Changed &lt;code&gt;/claude-api&lt;/code&gt; so it can no longer be run from Remote Control clients&lt;/li&gt;
&lt;li&gt;Changed &lt;code&gt;/config chrome=true&lt;/code&gt; to direct you to the /config panel instead of enabling Claude in Chrome by default; &lt;code&gt;/config chrome=false&lt;/code&gt; still turns it off when it was on&lt;/li&gt;
&lt;li&gt;Changed sandbox settings so project settings cannot widen or turn off an admin-required sandbox, replace the proxy behind a managed deny list, extend a strict allowlist, or reopen managed read-denies&lt;/li&gt;
&lt;li&gt;[VSCode] Added a note under a restored tab&#39;s last message when a window reload interrupted it and no reply will follow&lt;/li&gt;
&lt;li&gt;[VSCode] Added a plugin options form to Manage plugins: installing a plugin that has options asks for the unset ones, and a gear on its row changes them later&lt;/li&gt;
&lt;li&gt;[VSCode] Added an on-demand diagnostics tool so Claude in the panel can read the Problems panel&#39;s current errors and warnings at any time, not only right after it edits a file&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed pressing Enter after typing a slash command running an unrelated menu item picked by fuzzy match, or doing nothing&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed an open agent transcript losing the agent&#39;s newer messages during a long session&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed a message that quotes a Claude Code or IDE tag losing the rest of its text in the chat&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed a message sent while Claude was working disappearing from the conversation after the session was reopened&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed the session list&#39;s Web tab showing the previous account&#39;s sessions after an account switch&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed restored tabs re-running an interrupted turn when VS Code was started with &lt;code&gt;CLAUDE_CODE_RESUME_INTERRUPTED_TURN&lt;/code&gt; set, even with Continue After Reload off&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed Escape stopping the running turn instead of closing the command menu after clicking one of its rows&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed opening Past conversations replacing a live conversation with its saved copy&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed a Claude tab reloaded after an extension restart staying blank instead of saying how to recover&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed opening a conversation that is already open in another window or app starting a second copy of it without warning; it now asks first&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed a hook&#39;s reason for blocking or stopping a prompt disappearing after a window reload&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed tabs stuck on a conversation that can&#39;t be resumed: the error now says so and offers to start a new conversation&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed every file Read, Write and Edit stalling for ten minutes and then being skipped when the editor stops responding to the extension&#39;s automatic save before the tool runs&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed the agent map labeling a sub-agent with the session&#39;s model instead of the model it actually ran on (e.g. under &lt;code&gt;CLAUDE_CODE_SUBAGENT_MODEL_FORCE&lt;/code&gt; or an agent&#39;s own &lt;code&gt;model&lt;/code&gt;)&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed uninstalling a plugin from the Manage plugins dialog, which removed the wrong installation or failed for a plugin installed for the project&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed sign-in staying on the authorization-code step after going back and choosing the same sign-in method again&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed the chat panel stalling when a long session trims its oldest rows&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed the conversation disappearing from a session when many agents run&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed the editor tab keeping an old name after a session was renamed with /rename, by a SessionStart hook, or on claude.ai&lt;/li&gt;
&lt;li&gt;[VSCode] Fixed the agent map&#39;s transcript view leaving out messages sent to a running agent&lt;/li&gt;
&lt;li&gt;[VSCode] Improved the Manage plugins dialog: a failed plugin action now opens a popup that explains it and, where there is one, offers the fix&lt;/li&gt;
&lt;li&gt;[VSCode] Changed the Manage plugins dialog to ask before removing a marketplace or turning off a plugin that your project&#39;s shared &lt;code&gt;.claude/settings.json&lt;/code&gt; turns on&lt;/li&gt;
&lt;li&gt;[Cloud sessions] Fixed Run now on a routine showing internal error text when the run is refused before it starts; it now shows the same explanation as the routine&#39;s failure notification&lt;/li&gt;
&lt;li&gt;[Cloud sessions] Changed &lt;code&gt;MCP_DISCOVERY_CACHE=1&lt;/code&gt;, when set in your cloud environment&#39;s variables rather than a settings file, to reuse your connectors&#39; tool lists after a session restart; other MCP servers are no longer cached and connect at startup&lt;/li&gt;
&lt;li&gt;[Claude Tag] Added direct messages with Claude for members on an Enterprise plan Standard or Usage-Based Chat seat who also have Cowork; a seat that includes Claude Code is no longer required&lt;/li&gt;
&lt;li&gt;[Claude Tag] Fixed the Default model setting in admin settings and a channel&#39;s Configure page offering models your organization can&#39;t use, which made saves or new sessions fail&lt;/li&gt;
&lt;li&gt;[Claude Tag] Fixed the note under Claude&#39;s Slack messages saying it answered on a fallback model, and why, disappearing when Claude later edited that message&lt;/li&gt;
&lt;li&gt;[Code Review] Fixed the organization menu in Code Review&#39;s &quot;Add a repository&quot; dialog showing only a few of your GitHub organizations; it now loads more as you scroll&lt;/li&gt;
&lt;li&gt;[Code Review] Improved the Code Review check run to say when your repository&#39;s REVIEW.md wasn&#39;t applied, for example on a very large pull request or when REVIEW.md is a symbolic link&lt;/li&gt;
&lt;/ul&gt;</content>
    <author>
      <name>ashwin-ant</name>
    </author>
    <media:thumbnail height="30" width="30" url="https://avatars.githubusercontent.com/u/178951676?s=60&amp;v=4"/>
  </entry>
</feed>
