Fetching from the wire…
Tools2026-09-04 · source-backed
Edit/Write/Read rules whose path contains parentheses were dropped as invalid and ignored by the Bash sandbox, so folders intended as read-only were writable. A single rule with an uncompilable pattern, such as an unclosed bracket, made every file edit fail with "Invalid regular expression." Bash permission checks auto-approved zsh commands hiding a command substitution inside a REPORTTIME, REPORTMEMORY or DIRSTACKSIZE assignment. It also reverts the 2.1.259 change applying Read() deny rules to Bash arguments, which had been denying npm run build under a Read(./**/build/**) rule in every mode. Re-read your deny rules for parentheses and brackets. Claude Code changelog
Each link below shares sources, entities, or timing with this story.
Go rotate a key. I'll wait. Claude Code 2.1.246, released August 25, lists this in its changelog: a fix for "telemetry and metrics requests to Anthropic carrying the API key configured for a third-party gateway (ANTHROPIC_BASE_URL); a credential is now only sent to its own hos...
The changelog through 2.1.235 (code.claude.com) confirms the todo-tool removal from Opus 4.8, Sonnet 5, Fable 5, and Mythos 5+ that ran here on 2026-08-15 is restorable with that flag. Everything else in this window has already been covered: the Bash memory cgroups and the tod...
Your Edit(src/**) allow rule doesn't mean what you think it means. Until today, it matched any directory named src at any depth in the repo. Not <cwd>/src. Any src/. Including one an agent just created three levels down, or one that arrived in a dependency checkout. The v2.1.2...
The same man whose framework a model regression destroyed also published the most aggressive prediction of the week, and the tension between those two facts is the whole argument. "The Shape of Things to Come, Part 1: The Continuous Thunderdome" argues traditional CI/CD collap...
One Claude Code release fixed two independent permission-check bypasses on the same day. That's the story. Version 2.1.221, shipped August 4, patches a Bash tool bypass where zsh could execute hidden commands embedded inside [[ ]] regex conditionals. The approval prompt never...
If you use plan mode as a read-only sandbox before you approve anything, stop and upgrade first. v2.1.212 patched a real safety hole: in plan mode, file-modifying Bash commands could execute without the permission gate you'd expect. Anything below 2.1.212 could mutate files mi...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.