DEVELOPER-TOOL

Claude Code

developer-tooltopic-noteanthropic

Overview

Claude Code is Anthropic’s official CLI coding agent built on the Claude Agent SDK. It enables multi-agent code review, ecosystem integration through MCP (Model Context Protocol), and advanced features for interactive development workflows. The tool serves as a comprehensive platform for AI-assisted software development with enterprise-grade capabilities.

Timeline

  • 2026-05-03-AI-Digest — v2.1.126 (May 1) ships model picker via /v1/models endpoint when ANTHROPIC_BASE_URL is set (relevant for Bedrock/Vertex routing), new claude project purge [path] command, OAuth /mcp menu fix, custom-headers MCP authentication fix.

  • 2026-05-02-AI-Digest — No new release this weekend; v2.1.123 from April 29 remains latest. Simon Willison publishes end-to-end iNaturalist sightings tool built entirely on a phone via Claude Code for web, demonstrating the agentic-coding curve at the developer-tooling level.

  • 2026-03-10-AI-Digest - v2.1.72 released

  • 2026-03-11-AI-Digest - Multi-agent code review capabilities introduced

  • 2026-03-12-AI-Digest - MCP ecosystem reaches 97M monthly downloads

  • 2026-03-15-AI-Digest - Interactive elicitation feature released

  • 2026-03-25-AI-Digest - Managed-settings.d enterprise policy framework added

  • 2026-03-27-AI-Digest - OAuth RFC 9728 compliance implemented

  • 2026-03-30-AI-Digest - Source leak via npm reveals KAIROS daemon architecture

  • 2026-03-31-AI-Digest - /buddy companion feature launched; source leak continues

  • 2026-04-01-AI-Digest - /buddy companion expanded with additional capabilities

  • 2026-04-02-AI-Digest - /powerup lessons framework introduced

  • 2026-04-03-AI-Digest - MCP result persistence override capability released

  • 2026-04-04-AI-Digest - v2.1.92 adds forceRemoteSettingsRefresh policy, interactive Bedrock setup wizard with AWS auth, per-model cost breakdown for /cost, 60% faster Write tool diffs; /tag and /vim commands removed.

  • 2026-04-05-AI-Digest — Week-in-review: three releases in three days (v2.1.90-92); v2.1.92 highlighted with Bedrock wizard, 60% faster Write diffs, forceRemoteSettingsRefresh policy.

  • 2026-04-06-AI-Digest — v2.1.92 remains latest release; no new weekend release.

  • 2026-04-07-AI-Digest — No new release; v2.1.92 remains current with Bedrock wizard, policy controls, and faster Write diffs

  • 2026-04-07-AI-Digest — No new release; v2.1.92 remains latest. OpenAI’s Responses API shell tool positions as direct competitor to Claude Code’s agentic environment.

  • 2026-04-08-AI-Digest — Three releases in two days: v2.1.94 (Apr 7) ships Amazon Bedrock powered by Mantle support behind CLAUDE_CODE_USE_MANTLE=1, raises default effort from medium to high for API/Bedrock/Vertex/Foundry/Team/Enterprise users, adds compact Slack message headers, fixes 429 rate-limit stalls and macOS keychain login failures; v2.1.96 (Apr 8) hotfixes a Bedrock 403 “Authorization header is missing” regression in v2.1.94.

  • 2026-04-09-AI-Digest — v2.1.97 ships substantive new features and hardening: Ctrl+O focus view toggle in NO_FLICKER mode, refreshInterval status line setting, workspace.git_worktree exposed in status line JSON, Cedar policy file syntax highlighting (.cedar/.cedarpolicy), Bash tool permission hardening and validation, and a critical fix for an MCP HTTP/SSE memory leak draining ~50 MB/hr from long-running sessions. Also fixes —resume picker issues, file-edit diffs disappearing, and Korean/Japanese text corruption on Windows. Fourth Claude Code release in five days, signaling sustained fire-fighting after the v2.1.94 platform changes.

  • 2026-04-10-AI-Digest — No new release; v2.1.97 remains current. The v2.1.94 → v2.1.97 fire-fighting cadence appears to be stabilizing. Claude Managed Agents launches alongside as a separate Anthropic product for hosted agent deployment at $0.08/session-hour.

  • 2026-04-11-AI-Digestv2.1.98 ships with interactive Bedrock setup wizard (guided AWS auth, region config, credential verification, and model pinning from the login screen), per-model and cache-hit cost breakdown for /cost, Monitor tool for streaming background script events, and 60% faster Write tool diff computation on large files. Linux sandbox ships apply-seccomp helper in both npm and native builds. Eight releases in nine days through April.

  • 2026-04-12-AI-Digestv2.1.101 ships with /team-onboarding command (generates teammate ramp-up guides from local usage), OS CA certificate store trust by default (enterprise TLS proxies work out-of-the-box), /ultraplan auto-creates cloud environments, improved brief mode and focus mode, better tool-not-available errors, and fixed idle-return token hint and fullscreen scroll duplication. Ninth release in eleven April days; the skip from v2.1.98 to v2.1.101 suggests internal builds that didn’t ship publicly.

  • 2026-04-13-AI-Digest — No new release; v2.1.101 remains current. Claude Code prominently featured at HumanX 2026 as the tool driving “Claude mania” — now generating over $2.5B in annualized revenue and cited as the single AI tool most attendees would keep.

  • 2026-04-14-AI-Digestv2.1.105 ships (Apr 13): path parameter for EnterWorktree (multi-worktree switching as first-class), PreCompact hook support (hooks can block compaction via exit code 2 or {"decision":"block"}), background monitor support for plugins via top-level monitors manifest key, /proactive aliased to /loop, stalled stream handling (abort after 5 min, retry non-streaming), and improved network error messages. Tenth public release in twelve April days.

  • 2026-04-15-AI-DigestClaude Code Routines launches in research preview: saved prompt + repos + connectors configurations that run on Anthropic’s cloud via schedule, API trigger, or GitHub event, removing the “my Mac was asleep” failure mode for long-running automations. Per-plan daily quotas (Pro 5, Max 15, Team/Enterprise 25). Shipped with a redesigned Claude Code UX (integrated terminal, in-app file editor, HTML/PDF preview, faster diff viewer, drag-and-drop layout). v2.1.108 (Apr 14) adds /recap session-context command, ENABLE_PROMPT_CACHING_1H / FORCE_PROMPT_CACHING_5M cache TTL env vars, model-invokable built-in slash commands via the Skill tool, /undo as alias for /rewind, /model mid-conversation warnings, /resume defaulting to current directory, separated rate-limit vs plan-quota errors, 5xx/529 linking to status.claude.com, lower memory for file reads. v2.1.109 adds a rotating progress hint to the extended-thinking indicator. Eleventh public release in fourteen April days.

  • 2026-04-16-AI-Digestv2.1.110 (Apr 15, 22:07) ships alongside v2.1.109 earlier the same day. Headline additions: /tui command and tui setting (flicker-free fullscreen rendering), Focus view decoupled from verbose transcript (Ctrl+O now toggles only the transcript, /focus toggles the focus panel separately — splitting the overloaded v2.1.97 binding), push notification tool (Claude can fire mobile push notifications when Remote Control is enabled), autoScrollEnabled config, /plugin Installed tab reordering by favorites and items-needing-attention, /doctor warns on duplicate MCP server scopes, scheduled tasks resurrect on --resume / --continue, Remote Control parity for /autocompact//context//exit//reload-plugins, IDE-diff feedback loop (Write tool informs model when the user edits proposed content before accepting). Fixes for MCP tool calls hanging on server disconnect, non-streaming fallback multi-minute hangs, focus-mode recap/status-line regressions, plugin dependency resolution from plugin.json, and dropped keystrokes after CLI relaunches. Twelfth public April release in fifteen days; combined with the prior day’s Routines launch, the clearest signal yet that Anthropic treats Claude Code as an always-on ambient agent substrate rather than a session-bound CLI.

  • 2026-04-17-AI-Digestv2.1.111 (Apr 16, 15:18 UTC) ships to time with Claude Opus 4.7 general availability. Headline features: Claude Opus 4.7 “xhigh” effort level with new /effort command for depth-vs-latency tuning (xhigh becomes Opus 4.7 Claude Code default); /ultrareview cloud multi-agent code review command (no-args reviews current branch, /ultrareview <PR#> fetches and reviews a specific GitHub PR via parallel agent dispatch on the Routines substrate); /less-permission-prompts skill that scans transcripts to propose security allowlists; Windows PowerShell tool progressively rolling out (opt-in/out via CLAUDE_CODE_USE_POWERSHELL_TOOL); Auto mode for Max subscribers on Opus 4.7; Auto (match terminal) theme option; Ctrl+U clears entire input buffer; /skills supports sorting by token count; plan files auto-named after prompts; read-only bash globs no longer trigger permission prompts; further /setup-vertex and /setup-bedrock wizard polish. v2.1.112 (Apr 16, 19:55 UTC) is a narrow hotfix for “claude-opus-4-7 is temporarily unavailable” errors in Auto mode — five-hour turnaround from bug to fix. Fourteen April releases in sixteen days; /ultrareview is the first Claude Code feature to reach back into the Routines cloud substrate for something other than cron jobs — earliest proof point that Routines is a remote parallel-agent execution substrate slash commands can dispatch into ad hoc.

  • 2026-04-18-AI-Digestv2.1.113 (Apr 17) ships the native binary as the default distribution channel, replacing the bundled JavaScript runtime — a structural shift from an npm-installed Node.js CLI to a compiled standalone executable with faster cold starts, smaller install footprint, and no Node runtime dependency. Security hardening headlines: sandbox.network.deniedDomains configuration key for blocking specific egress hosts without disabling network access entirely (partial-allowlist sandboxing for agent runs), and Bash hardening that wraps env, sudo, watch, ionice, setsid, /private paths, and find -exec/-delete in additional validation layers. UX polish: subagent 10-minute stall detection (long-running subagents now emit a warning and offer to abort instead of hanging silently), /ultrareview launch-dialog refinement (clearer branch-vs-PR mode selection), Shift+↑/↓ fullscreen scroll (paginated scrollback in /tui mode), readline-style Ctrl+A / Ctrl+E (start/end of input line), Remote Control parity for /extra-usage and @-autocomplete (mobile Claude Code can now introspect usage and reference files by name), and assorted bug fixes. Fifteenth public April release in seventeen days; the native binary is the biggest distribution-layer change since v2.0 — an explicit bet that Claude Code’s install surface should look like a compiled system tool, not a JavaScript app.

  • 2026-04-19-AI-Digestv2.1.114 (Apr 18, 01:34 UTC) is a single-fix weekend hotfix that resolves a crash in the permission-dialog path when an Agent Teams teammate requests tool permission. Sixteenth April release in nineteen days, landing hours after the v2.1.113 native-binary rebase — the operational fingerprint of a team compounding against Cursor’s Composer 2 release velocity rather than an internal monthly cadence.

  • 2026-04-22-AI-Digestv2.1.117 (Apr 22, 00:04 UTC) is the first April release to widen the agent programming model rather than polish existing surfaces. Headline: forked subagents as an external-build opt-in via CLAUDE_CODE_FORK_SUBAGENT=1, moving the forked-subagent architecture from internal-only to any custom Claude Code binary. Agent frontmatter mcpServers now loaded for main-thread agent sessions via --agent, closing the long-running gap where custom agents had reduced tool access compared to inline work. /resume now proactively offers to summarize stale, large sessions (natural follow-on to v2.1.116’s 40MB+ resume-performance work). MCP startup moves to concurrent connection handling. Enterprise posture: managed-settings enforcement for blockedMarketplaces / strictKnownMarketplaces — the plugin/marketplace-governance equivalent of v2.1.113’s sandbox.network.deniedDomains posture. Native builds on macOS and Linux now replace the Glob and Grep tools with embedded bfs and ugrep — the same “walk the bundled-JS-dependency tree” posture as the April-17 jq→native migration. OpenTelemetry adds three new event attributes (command_name, command_source, effort) and a fix for Opus 4.7 context-window calculations (was reporting 200K, actually 1M). Plain-CLI OAuth refresh fix restores token refresh on expired non-terminal sessions. What v2.1.117 still does not ship: any response to the OX Security MCP disclosure — no STDIO input sanitization change, no protocol-level hardening, no sandbox.mcp.* settings. Seventeenth public April release in twenty-two days.

  • 2026-04-23-AI-Digestv2.1.118 (Apr 23, 00:42 UTC) is the TUI-ergonomics companion to v2.1.117’s agent-architecture widening. Headline: vim visual modesv (visual) and V (visual-line) with operators, selection, and visual feedback — finally closing the largest remaining gap in the Claude Code vim-mode surface and bringing prompt editing within parity of external editors like Neovim. Custom named themes via /theme, plus hand-edited JSON files in ~/.claude/themes/, move theme configurability from bundled-set to checkable-into-dotfiles. /cost and /stats consolidate into /usage (old names remain as aliases). MCP tool hooks via type: "mcp_tool" let hook authors invoke MCP tools directly from the pre/post/PreCompact hook pipeline — unlocking agentic workflows that previously required custom shell plumbing. Enterprise-governance: DISABLE_UPDATES is now a stricter env var than DISABLE_AUTOUPDATER (blocks all update paths for regulated deployments); wslInheritsWindowsSettings lets WSL inherit Windows-side managed settings, closing a long-standing dual-policy-tree gap. Auto mode defaults gain "$defaults" composition (add custom rules alongside built-ins rather than replace them). claude plugin tag creates release git tags with version validation — a small but telling signal that Anthropic treats plugins as versioned release artifacts. Eighteenth public April release in twenty-three days. Still not shipped: any response to the OX Security MCP disclosure — no STDIO sanitization change, no sandbox.mcp.* settings, no protocol-level MCP hardening. The MCP-Safe community track holds into week three.

  • 2026-04-28-AI-Digest — v2.1.121 ships substantive release with alwaysLoad MCP server option, claude plugin prune command, type-to-filter on /skills, and PostToolUse hooks generalized to all tools; memory-leak fixes for image processing, /usage command, and dangling Bash CWD issue.

  • 2026-04-29-AI-Digest — v2.1.122 (April 28 evening) ships ANTHROPIC_BEDROCK_SERVICE_TIER env var for service-tier routing, /resume PR-URL session lookup, /mcp shadowed-connector visibility, OpenTelemetry numeric-attribute fix, /branch rewound-timeline crash fix; followed by v2.1.123 (April 29) one-line OAuth 401 retry-loop hot-fix.

  • 2026-04-30-AI-Digest — No new release today; v2.1.123 (April 29) remains latest as Claude Code enters a quiet patch in release cadence.

  • 2026-05-04-AI-Digest — No new release this week. The most recent cut (v2.1.126, May 1) added model picker via /v1/models for Anthropic-compatible gateway routing (relevant for Bedrock/Vertex), claude project purge [path] teardown command, and HTTP/SSE MCP server reauth fixes. Release cadence shift from daily (April) to multi-day (May) reflects post-Opus 4.7-GA operational normalization.

  • 2026-05-08-AI-Digest — Five releases in four days — v2.1.128, .129, .131, .132, and v2.1.133 (last landing late on 2026-05-07) — decisively refute the “three quiet weeks” framing from 2026-05-07-AI-Digest. Headline change in v2.1.133 is the new worktree.baseRef setting (fresh | head, default fresh) which restores origin/<default> as the worktree base, explicitly reverting v2.1.128’s branch-from-local-HEAD default. Hooks now receive effort.level (JSON) and $CLAUDE_EFFORT (env, also exposed in Bash-tool subprocesses); parentSettingsBehavior lands for managedSettings policy merge. v2.1.132 adds CLAUDE_CODE_SESSION_ID to Bash subprocess env and CLAUDE_CODE_DISABLE_ALTERNATE_SCREEN. Material runtime fix: a 10GB+ MCP memory leak on stdio servers, plus a silent tools/list failure that previously surfaced as “tools fetch failed” with no upstream signal.

  • 2026-05-09-AI-Digest — Three more releases — v2.1.136 on May 8, then v2.1.137 and v2.1.138 in quick succession on May 9. The substantive one is v2.1.136: it adds CLAUDE_CODE_ENABLE_FEEDBACK_SURVEY_FOR_OTEL (re-enables the session-quality survey for OTel-capturing enterprises) and settings.autoMode.hard_deny for unconditional auto-mode classifier blocks, alongside ~40 fixes. Two reliability fixes worth naming: MCP servers from .mcp.json, plugins, and claude.ai connectors no longer silently disappear after /clear in VS Code, JetBrains, and the Agent SDK; and concurrent MCP OAuth refresh-token rotations no longer overwrite freshly-rotated tokens, ending the daily re-auth tax for users running multiple remote MCP servers. v2.1.137 fixed VS Code extension activation on Windows; v2.1.138 is internal-fixes-only. Eight releases in six days is above-trend but consistent with typical 1–2 day patch rhythm — “the dry stretch ended” rather than “structural cadence reset.”

  • 2026-05-10-AI-DigestNo new release in the past 24 hours; latest remains v2.1.138 from 2026-05-09. The cadence reset that began 2026-05-07 (five releases across May 6–9) has held through a quiet Sunday — eight releases in six days followed by one quiet day, consistent with a normal weekly rhythm rather than a structural pause.

  • 2026-05-11-AI-Digest — Two net-new releases covered: v2.1.133 (2026-05-07) introduces worktree.baseRef setting with fresh and head values and flips the default to fresh, meaning new worktrees branch from origin/<default> instead of local HEAD — a quiet breaking change for users who rely on in-progress local commits carrying into a new worktree. Hooks gain effort.level (JSON) and $CLAUDE_EFFORT (env var). Also fixes an unbounded parallel-session 401 loop from refresh-token race. v2.1.132 (2026-05-06) adds CLAUDE_CODE_SESSION_ID to Bash subprocess env, CLAUDE_CODE_DISABLE_ALTERNATE_SCREEN=1, fixes 10GB+ RSS MCP memory growth from stdio servers writing non-protocol stdout, adds graceful SIGINT shutdown, and fixes vim operators corrupting NFD-accented text.

  • 2026-05-12-AI-Digestv2.1.139 ships Agent View (Research Preview) — claude agents surfaces a unified session lifecycle list tagged running/blocked-on-you/done, the first primary CLI surface for session management. New /goal command sets a completion condition and lets Claude work across turns with a live overlay showing elapsed time, turn count, and token spend. hook continueOnBlock lets PostToolUse hooks feed a rejection reason back to Claude and continue rather than halt; exec-form args: string[] removes shell-quoting hazards. Compaction now preserves sensitive user instructions; MCP stdio servers receive CLAUDE_PROJECT_DIR.

  • 2026-05-13-AI-Digestv2.1.140 ships four fixes: subagent_type matching is now case- and separator-insensitive, /goal no longer silently hangs under disableAllHooks/allowManagedHooksOnly, symlinked settings files no longer trigger spurious ConfigChange hook fires, and claude --bg reliability is improved for machines where the background service was about to idle-exit or in enterprise endpoint-security environments.

  • 2026-05-14-AI-Digestv2.1.141 ships a substantive feature drop wrapped in a ~26-change bug-fix wave: new terminalSequence field in hook JSON output (enables desktop notifications and terminal bells from headless and CI environments), ANTHROPIC_WORKSPACE_ID env var for workload identity federation, “Summarize up to here” action in the Rewind menu for mid-conversation compression, and regression fixes for Bedrock/Vertex Haiku fallback, markdown table rendering, vim-mode Ctrl+C interrupt, and Windows Alt+V image paste.

  • 2026-05-16-AI-Digestv2.1.143 ships a new worktree.bgIsolation: "none" setting letting background sessions edit the working copy directly without EnterWorktree — the cleanest fix for submodule-heavy repos and generated-asset directories that have been hitting edge cases since the worktree primitive landed. Plugin dependency enforcement lands: claude plugin disable refuses when another enabled plugin depends on the target and prints a disable-chain hint; claude plugin enable force-enables transitive dependencies. claude agents gains 8 more flags (--add-dir, --settings, --mcp-config, --plugin-dir, --permission-mode, --model, --effort, --dangerously-skip-permissions) — combined with v2.1.142’s 8 flags, the background-agents CLI surface is now feature-equivalent to top-level claude. Reliability: stop-hook infinite-block loop caps at 8 iterations; macOS TCC sandbox errors for ~/Documents, ~/Desktop, ~/Downloads resolved.

  • 2026-05-15-AI-Digestv2.1.142 ships the largest single expansion of the background-agents dispatch surface since the feature landed: claude agents gains eight configuration flags — --add-dir, --settings, --mcp-config, --model, --effort, --permission-mode, --plugin-dir, --dangerously-skip-permissions — making background sessions configurable along the same axes as foreground ones. Fast mode default bumped from Opus 4.6 to Opus 4.7 (prior version pinnable via CLAUDE_CODE_OPUS_4_6_FAST_MODE_OVERRIDE=1). Single-skill plugins with a root-level SKILL.md and no skills/ subdirectory are now auto-surfaced without the nested-directory dance. Background-session reliability wave: macOS sleep/wake daemon reconnect, daemon exit after brew upgrade–style binary swap, Windows deadlock on network-drive working directories, 256-color terminal background bleed on Apple Terminal.

  • 2026-05-19-AI-Digestv2.1.144 (first release since v2.1.143 four days ago) brings /resume working against --bg runs (with an explicit bg marker) and completion notifications that now include elapsed duration; /model switching is session-scoped by default with d to make the change the new default — a meaningful ergonomic fix for users who toggle models mid-task. Fix list is the more interesting half: a 15-second timeout on the api.anthropic.com startup probe (previously hung up to 75 seconds on flaky networks); MCP servers responding with paginated tools/list now have all pages enumerated rather than only the first; and macOS background sessions no longer crash inside Full Disk Access-protected directories. Shipped the same day Anthropic acquired Stainless (>$300M reported) and Mythos’s cyber-flaw cache reached the Financial Stability Board.

  • 2026-05-20-AI-Digestv2.1.145 (second release on the same day as v2.1.144, and the substantive one for multi-agent workflows): claude agents --json lists live sessions as machine-readable output (the wiring needed for tmux-resurrect, status bars, and session pickers); the terminal tab title surfaces the count of agents awaiting input; OTEL spans now carry agent_id / parent_agent_id attributes with fixed trace parenting so background subagent spans nest under the dispatching Agent tool span; Stop and SubagentStop hook input gains background_tasks and session_crons; /plugin Discover and Browse screens preview commands/agents/skills/hooks/MCP+LSP servers before installation; a permission-prompt bypass via bare variable assignments to non-allowlisted env vars in Bash is closed; and an infinite loop where context: fork skills could re-invoke themselves is fixed.

  • 2026-05-21-AI-Digestv2.1.146 ships a small but pointed payload: the headline rename is /simplify/code-review with an optional effort-level argument that mirrors the same dial added to /security-review and the underlying code-review skill earlier this month — Anthropic is converging the review-style commands on one effort knob. Fixes: the Auto-mode regression where AskUserQuestion was silently suppressed when the calling flow relied on it; the Windows PowerShell “command line is invalid” regression introduced in v2.1.124; MCP pagination for resources/list, resources/templates/list, and prompts/list; and materially faster diff rendering for large file edits. Two consecutive on-cadence releases (v2.1.145 on 2026-05-19, v2.1.146 today) suggest the Code with Claude London launch slowdown was a head-fake, not a deceleration.

  • 2026-05-22-AI-Digestv2.1.147 → v2.1.148 in five hours. v2.1.147 (2026-05-21, ~20:39 UTC) ships background sessions, the /simplify/code-review rename with an effort argument mirroring /security-review, an auto-updater retry loop for flaky networks, plus enterprise-login and PowerShell fixes. v2.1.148 (2026-05-22, ~01:16 UTC) is a single-issue hotfix for a regression introduced in 147 where the Bash tool returned exit code 127 on every command for some users — caught fast. Two on-cadence releases in two days plus a tight hotfix loop further refutes the Code with Claude London slowdown hypothesis; practitioners on v2.1.147 should skip to v2.1.148 if they saw the 127 errors.

  • 2026-05-23-AI-Digestv2.1.149 → v2.1.150 in one day. v2.1.149 (2026-05-22) is the substantive cut: /usage adds a per-category cost breakdown (skills, subagents, plugins, MCP servers); /diff gains full keyboard scrolling (arrows, j/k, PgUp/PgDn, Space, Home/End); GFM task-list checkboxes finally render in markdown; enterprise allowAllClaudeAiMcps managed setting lands. Security hardening: a PowerShell cd-function permission bypass closed, sandbox write allowlist tightened in git worktrees, and a find-call pattern fixed that had been exhausting the macOS vnode table on large repos. v2.1.150 (2026-05-23) is infrastructure-only — same-day point release stacked on yesterday’s feature drop. Four releases in three days (147 → 150) reads as burst, not new steady state — trailing 11-day rate is ~0.9 releases/day.

  • 2026-05-27-AI-Digestv2.1.152 lands at 2026-05-27 01:30 UTC, the first new tag since v2.1.150 on 2026-05-23 — ending a five-day quiet streak. The GitHub release page is not directly fetchable from the digest-write environment, so today’s coverage is a tag-confirmation rather than a changelog read; substantive feature coverage will follow once the release notes are accessible. The cadence resumes inside the prior 3–5 day envelope; nothing about today’s tag suggests the burst pattern from the v2.1.147–v2.1.149 run is back. Watch is whether v2.1.153 follows within 72 hours (signalling a new burst) or the gap extends past a week again.

  • 2026-05-28-AI-Digestv2.1.153 ships at ~00:52 UTC, a back-to-back daily tag the day after v2.1.152 — answering the prior digest’s 72-hour-watch question toward “burst” rather than week-long gap. Quality-of-life additions: a skipLfs option for github/git plugin marketplace sources, status-line commands now receive COLUMNS/LINES for terminal-aware output, and claude agents autocomplete suggests native slash commands and bundled skills alongside a PR #N column. The rest is bug-fix housekeeping (MCP server handling, custom API-gateway auth, Windows PowerShell installer false-success report, background-session UI fixes for stale daemons, stdin EOF hangs, malformed file:// links). Steady-state maintenance, not a feature drop.

  • 2026-05-29-AI-Digestv2.1.154 is the week’s first real feature drop after a run of daily maintenance tags, shipping the same beat as the Claude Opus 4.8 launch. Headline: first-class Opus 4.8 support (defaulting to high effort, a new /effort xhigh rung, Fast mode billed at “2× the standard rate for 2.5× the speed”) plus dynamic workflows/workflows lets you ask Claude to spin up an orchestration that fans out “tens to hundreds of agents in the background.” Supporting changes: lean system prompt is now the default for newer models, /simplify is now cleanup-only review, /effort labels renamed to Faster/Smarter, and the auto-mode classifier was hardened against bulk-repo exfiltration. A fast-follow v2.1.156 is a single hotfix for an Opus 4.8 case where modified thinking blocks led to API errors. Treat the “hundreds of agents” line as a capped, concurrency-limited research-preview ceiling, not a daily-driver workflow yet.

  • 2026-05-30-AI-DigestTwo-tag day. v2.1.157 (2026-05-29, ~20:20 UTC) is the substantive cut: plugins placed in .claude/skills directories now auto-load without a marketplace requirement, a new claude plugin init <name> scaffolder lands, /plugin arguments and subcommands get autocomplete, the agent field in settings.json is now honored for dispatched claude agents sessions, plus fixes for background sessions, worktrees, image handling, and terminal rendering. v2.1.158 (2026-05-30, ~02:42 UTC) is narrower — it extends the v2.1.154 auto-mode classifier to AWS Bedrock, Google Vertex, and Azure Foundry for Opus 4.7 and 4.8, opt-in via CLAUDE_CODE_ENABLE_AUTO_MODE=1. The plugin-distribution story has now visibly decoupled from the marketplace, and auto-mode going to enterprise-cloud backends is the same plugin-and-deployment surface widening in lockstep. Cadence read: feature drop, not steady-state — v2.1.157’s plugin auto-load reshapes the third-party developer story.

  • 2026-05-31-AI-DigestNo new tag in the last 24 hours; latest remains v2.1.158 (2026-05-30 ~02:42 UTC). The back-to-back v2.1.157 plugin-auto-load and v2.1.158 auto-mode-to-Bedrock/Vertex/Foundry features remain the current state, and the cadence is back to a normal post-feature-drop pause. The signal to watch is whether v2.1.159 lands a bug-fix sweep on the new .claude/skills auto-load path now that it’s in the hands of third-party plugin authors. Separately, Salesforce‘s self-reported 231-day → 13-day internal cloud migration on Claude Code (33 API endpoints, +79% PRs/dev, 5% fewer incidents) lands today as the upper-tail outlier demand-side data point for a tool whose v2.1.158 plugin/auto-mode surface is the supply-side story.

  • 2026-06-01-AI-Digestv2.1.159 ships 2026-05-31 ~19:42 UTC, a quiet housekeeping patch whose release notes read in full: “Internal infrastructure improvements (no user-facing changes).” First tag after the v2.1.157 plugin auto-load and v2.1.158 auto-mode-to-Bedrock/Vertex/Foundry feature pair. The predicted bug-fix sweep on the new .claude/skills auto-load path did not land here — the notes are explicit about “no user-facing changes.” Cadence is back to housekeeping; the .claude/skills follow-up is still pending and remains the signal to watch on the next tag.

  • 2026-06-02-AI-Digestv2.1.160 ships 2026-06-02 ~02:10 UTC — the predicted .claude/skills follow-up arrives, though not where v2.1.159’s “no user-facing changes” framing implied. The acceptEdits safety net widens to prompt before writing shell startup files (.zshenv, .zlogin, .bash_login), ~/.config/git/ configs, and the build-tool config class that grants code execution: .npmrc, .yarnrc*, bunfig.toml, .bazelrc, .pre-commit-config.yaml, .devcontainer/ — closing the exec-on-config-write class that v2.1.157’s .claude/skills auto-load reopened. Two breaking-edge items in the same tag: the dynamic-workflow trigger renames workflowultracode (silently breaks any script wired to the v2.1.154 /workflows orchestrator); and Edit no longer requires a separate Read after grep (cuts a real round-trip from the agentic edit loop). WSL clipboard, voice-mode on non-ASCII paths, and CJK IME positioning in claude agents round out a long-overdue Windows/WSL stabilisation sweep. CLAUDE_CODE_OPUS_4_6_FAST_MODE_OVERRIDE is removed.

  • 2026-06-03-AI-Digestv2.1.161 ships 2026-06-02 ~21:58 UTC — second tag in a single day, back-to-back with v2.1.160 only ~20 hours earlier, which is unusual for the cadence. Headline: OTEL_RESOURCE_ATTRIBUTES values now flow through as labels on metric datapoints (the missing piece for anyone wiring Claude Code into existing OTel pipelines); claude agents rows show done/total ahead of the detail column when work is fanned out across subagents; /mcp collapses unused claude.ai connectors behind a “Show unused connectors” row; failed Bash commands in a parallel-tool batch no longer cancel the other in-flight calls; and fullscreen clipboard on Linux now reaches for wl-copy / xclip / xsel in order, so Wayland desktops finally get first-class copy. The OTel labels and the parallel-tools fix are the two practitioners will feel immediately.

  • 2026-06-04-AI-Digestv2.1.162 ships 2026-06-03, the third tag in ~36 hours after v2.1.160 and v2.1.161. Headline: claude agents --json now exposes waitingFor (first machine-readable handle on agent wait state — the right primitive for queue-aware dashboards and “is this agent stuck?” health checks); on native builds, --tools ships dedicated Grep/Glob search tools when explicitly listed instead of folding them into Bash (re-check existing tool-filter lists that assumed the old shape); clicking a slash command in the autocomplete menu now fills the prompt instead of firing immediately (fixes a long-standing footgun). Cosmetic: Windsurf is renamed to “Devin Desktop” across /ide, /terminal-setup, /scroll-speed (reflects the Cognition acquisition rename). The waitingFor JSON field and the parallel-tools split are the two practitioners will feel immediately.

  • 2026-06-05-AI-Digestv2.1.163 ships 2026-06-04, one day after the v2.1.162 cluster. Two policy-surface additions are the headline: requiredMinimumVersion and requiredMaximumVersion managed settings let admins pin a version-range floor and ceiling from policy config — first time the managed-settings surface has had version gating, and the right primitive for orgs that need to hold a fleet on a tested band rather than the latest tag. The new /plugin list grows --enabled / --disabled filters — first user-facing surface for inspecting plugin state from inside the CLI. Robustness: background sessions no longer lose running tasks when re-attached after a self-update (companion fix to v2.1.160’s sleep/wake patch — the background-session re-attach story is finally robust across both update and suspend). Bash hardening for bazel, EDR-protected hosts, and Windows rounds it out. The version-range gating is the practitioner lever for rollouts that need to express ”≥ v2.1.160 but ≤ v2.1.163 until QA signs off on v2.1.164” without scripting around the auto-update.

  • 2026-06-06-AI-DigestThree tags since yesterday’s digestv2.1.165 (2026-06-05), v2.1.166 (2026-06-06), and v2.1.167 (2026-06-06). The flanking releases are terse “bug fixes and reliability improvements” point releases; v2.1.166 is the substantive one and lands the new headline features. Headline: a fallbackModel managed setting that accepts up to three fallback models tried in order when the primary is overloaded or unavailable — the first time the fallback chain has been a first-class declarative config rather than a per-invocation flag — and --fallback-model now also applies to interactive sessions, not just -p. Permissions DSL gets meaningful tightening too: glob pattern support in the deny-rule tool-name position ("*" denies all tools), allow rules now reject non-MCP globs, and unknown tool names in deny rules warn at startup. Cross-session messaging is hardened — messages relayed via SendMessage from other Claude sessions no longer carry user authority, receivers refuse relayed permission requests, and auto mode blocks them. Plus: MAX_THINKING_TOKENS=0 / --thinking disabled / per-model thinking toggles now disable thinking on models that think by default via the Claude API, and there’s a one-shot retry on the fallback model after an unexpected non-retryable error. The fallback-as-declarative-config pivot is the change to actually adopt — the managed setting belongs in .claude/settings.json and the chain runs the same way in interactive sessions.

  • 2026-06-07-AI-DigestTwo more fixes-only point releases capping yesterday’s substantive v2.1.166v2.1.167 (2026-06-06 01:33 UTC) and v2.1.168 (2026-06-06 23:41 UTC) — both ship as bare “bug fixes and reliability improvements” tags with no public changelog beyond the headline. All the substantive features (the fallbackModel managed setting with three-deep fallback chain, --fallback-model extending to interactive sessions, glob patterns in deny rules, hardened cross-session SendMessage authority handling, auto-mode blocking relayed permission requests, MAX_THINKING_TOKENS=0 disabling thinking on default-thinking models, the pre-download version announcement on claude update) all landed in v2.1.166 (2026-06-06-AI-Digest). Three tags in 48 hours, two fixes-only — the cadence read is “ship the substantive change, then bake out the regressions on the same day” rather than gating point releases. Same-week framing: Anthropic’s “When AI builds itself” >80%-Claude-merged post lands the dogfood-loop statistic that frames Claude Code’s compounding adoption inside Anthropic itself.

  • 2026-06-09-AI-DigestClaude Code v2.1.169 (2026-06-08, 21:57 UTC) — the first substantive tag in 48h after three “bug fixes and reliability improvements” point releases (v2.1.167, v2.1.168, plus v2.1.165). New surface: a --safe-mode flag that disables customizations for troubleshooting (diagnostic equivalent of a clean Chrome profile), a /cd command that changes the working directory without breaking the prompt cache (load-bearing for long-running sessions in monorepos), and a disableBundledSkills setting that hides bundled skills from the model — useful when team skills should be the only ones in scope. Fixes: enterprise MCP policy enforcement, a ~30–50ms macOS UI stall on claude.ai credentials, claude -p slowness on Windows, arrow-key navigation through command history on wrapped lines, plus background-session, Remote Control reconnection, and agent improvements. The read is that Anthropic is back to the “ship the substantive change, then bake out the regressions” cadence — three fixes-only days, then a real release.

  • 2026-06-12-AI-DigestThree tags in 36 hours. v2.1.173 (2026-06-11) strips the vestigial [1m] suffix from Fable 5 model names (Fable 5 ships with 1M context as default) and silences the spurious “sandbox dependencies missing” startup warning on Windows. v2.1.174 (2026-06-12) is the substantive middle tag: wheelScrollAccelerationEnabled for trackpads; /model picker now shows which family Default resolves to per plan (Opus on Max/Team Premium/Enterprise, Sonnet on Pro/Team, Opus on PAYG API); Bedrock GovCloud inference-profile prefix fix (globalus-gov for us-gov-* regions); enterprise usage-based-billing banner misfire fixed; the headline change is the new /usage attribution view in VSCode — cache misses, long-context, subagents, per-skill/agent/plugin/MCP, broken out 24h/7d. v2.1.175 (2026-06-12) ships enforceAvailableModels — when the managed setting is enabled, the availableModels allowlist now also constrains the Default model (Default falls back to the first allowed model if it would otherwise resolve to a disallowed one), and user/project settings can no longer widen a managed allowlist. First time Claude Code’s model-governance surface has been hardened against in-org widening.

  • 2026-06-10-AI-DigestClaude Code v2.1.170 (2026-06-09, 17:23 UTC) — the Claude Fable 5 enablement tag. Release notes read, verbatim, “Introducing Claude Fable 5: a Mythos-class model now available for general use with capabilities exceeding any previously released model. Update to version 2.1.170 for access.” Beyond the model wiring there is one substantive fix: sessions that failed to save transcripts and were missing from --resume when Claude Code was launched from the VS Code integrated terminal (or any shell inheriting CC env vars) now persist correctly — a quiet but load-bearing regression for anyone running the VS Code extension as their primary surface. Coming on the heels of v2.1.169’s --safe-mode / /cd / disableBundledSkills surface from 2026-06-09-AI-Digest, the pattern is now clearly “ship the substantive feature tag, then ship the model-bump tag a day later” — the model release was paced to follow the harness, not the other way round.

  • 2026-06-08-AI-DigestNo new tag since yesterday. v2.1.168 (2026-06-06, 23:41 UTC) remains the head — the third “bug fixes and reliability improvements” point release in 48 hours on top of the substantive v2.1.166 (the fallbackModel declarative config, glob patterns in deny rules, SendMessage cross-session authority hardening, MAX_THINKING_TOKENS=0 actually disabling thinking, all covered in 2026-06-07-AI-Digest). Nothing new to add today — flagging quiet so the cadence shows in the corpus.

  • 2026-06-13-AI-Digestv2.1.176 (2026-06-12) — session titles now match the conversation language (i18n correctness fix for non-English locales), new footerLinksRegexes managed setting lets enterprise admins pattern-match link badges in the status footer (back half of v2.1.175’s enforceAvailableModels enterprise-governance surface), Bedrock credential cache now respects the credential’s actual Expiration field rather than the fixed-1-hour assumption (matters when SSO expires at 47 minutes mid-tool-call), /fast refuses cleanly on a blocked model rather than failing silently, auto-mode falls back to Fable 5 when Opus 4.8 isn’t allowlisted, /copy works in tmux-over-SSH, the Linux sandbox handles symlinks, hook file-path conditions and Remote Control session-model switching get patches. Second tag in a row hardening enterprise-governance surfaces — managed-setting growth is now the load-bearing release direction.

  • 2026-06-14-AI-Digestv2.1.177 (2026-06-13) is metadata-onlyCHANGELOG.md and feed.xml updates only, no functional changes. The ship just carries the changelog for yesterday’s v2.1.176 (session-title language matching, footerLinksRegexes managed setting, Bedrock credential Expiration honoring, /fast clean refusal on blocked models, auto-mode fallback to Fable 5, Linux sandbox symlink handling). Three tags in 36 hours (v2.1.175 → 176 → 177), with the third being a chore tag, reads as Anthropic decoupling functional binary ships from changelog-ship tags — the release engine now absorbs disclosure-prep work into a follow-on tag. Read together with the Anthropic export-control story, enterprise-governance surface area is where the Claude Code engineering team’s time is going — five managed-setting additions in two weeks against approximately one user-facing UI change in the same window.

  • 2026-06-15-AI-DigestNo new tag in the last 24 hours. v2.1.177 (2026-06-13) remains the head; the v2.1.175 → 176 → 177 cluster covered in 2026-06-13-AI-Digest and 2026-06-14-AI-Digest stands. The signal worth holding is that the release engine has now decoupled functional ships (v2.1.175, v2.1.176) from changelog ships (v2.1.177) — and the substance continues to concentrate in managed-setting growth (enforceAvailableModels, session-title language matching, Bedrock credential Expiration handling). The first non-cadence release after the export-control disable is the next thing to watch — the v2.1.176 availableModels allowlist enforcement closed the alias-redirect loophole right before the 2026-06-12 Claude Fable 5 / Claude Mythos 5 global pull, and how the next tag treats the now-disabled model identifiers will be the live signal.

  • 2026-06-16-AI-Digestv2.1.178 shipped June 15 as the first post-export-control release with genuinely new capability surface. Tool(param:value) permission syntax enables invocation-level blocking by input value (e.g., Agent(model:opus) to forbid Opus subagents, WebFetch(url:competitor.com) to block specific fetches) — closing a long-standing allowlist-granularity gap. Pre-launch subagent safety classifier evaluates subagent spawns before launch, shutting the door on a subagent requesting a blocked action without review. Nested .claude/ directories now scope skills, agents, and workflows to the closest directory (name clashes surface as <dir>:<name>). 20+ bug fixes: OOM crash from stale fd env vars, Chrome OAuth cross-account silent failure, compaction ignoring --fallback-model.

  • 2026-06-17-AI-Digestv2.1.179 shipped June 16 — a stability point release rather than a capability ship, and the second post-Fable-5-shutdown release in a week. Four fixes worth logging: mid-stream connection drops now preserve partial responses instead of surfacing raw errors; mouse-wheel scrolling works again in WSL2 under Windows Terminal and VS Code; sandbox glob patterns no longer make Linux sessions unusable on large directory trees; and plugin loading in remote sessions is measurably faster. No new permission syntax, no new classifier, no agent-protocol moves — just the quiet maintenance cadence the corpus has been waiting for since v2.1.178 shipped two days of new surface in one release.

  • 2026-06-18-AI-Digestv2.1.181 shipped June 17 — the third release in three days (v2.1.178 → v2.1.179 → v2.1.181), confirming the post-Fable-5-shutdown maintenance cadence. Four items worth logging. /config key=value lets you set any setting inline at the prompt (/config thinking=false) without diving into settings.json — the shortest path yet between “I want to change behavior” and the next turn. sandbox.allowAppleEvents is a new macOS opt-in for Apple Events / AppleScript bridges — first sandbox knob explicitly aimed at driving macOS apps from Claude Code, quietly unblocking a whole class of desktop automation. The bundled Bun runtime bumps to 1.4, which is the line worth flagging for this repo: the strip-markdown / unist-util-visit-parents export-condition issue was a Bun 1.3.8 problem and is worth retesting against 1.4. Final fix: prompt-caching now works correctly on custom ANTHROPIC_BASE_URL and Azure Foundry — meaningful for enterprise proxy and self-hosted setups that have been silently paying full token cost on cached prefixes.

  • 2026-06-19-AI-Digestv2.1.183 shipped — the fourth release in three days, continuing the maintenance cadence noted in 2026-06-18-AI-Digest. Four items worth logging. Auto-mode safety hardening is the headline: the harness now blocks destructive git operations (reset --hard, clean -fd against tracked files) and any terraform/pulumi/cdk destroy invocation when running unattended — the class of action that has eaten the most user trust this quarter. attribution.sessionUrl is a new setting that suppresses the per-commit session link in commit messages and PR bodies (the “Claude-Session:” trailer) for users who’d rather not surface the URL externally — opt-in via /config attribution.sessionUrl=false. Deprecation warnings now print when a model alias is auto-rolled to a newer pin (e.g. claude-opus-4-7claude-opus-4-8 at end-of-life), giving users a session of warning before the swap. Two notable fixes: thinking-block rendering errors in long sessions, and WebSearch failing silently inside subagents — both regressed in the v2.1.179 series.

  • 2026-06-20-AI-Digest — No new release in the ~24h window. v2.1.183 (2026-06-19-AI-Digest) remains the live tag — auto-mode safety hardening, attribution.sessionUrl opt-in, deprecation warnings, and the thinking-block / subagent-WebSearch fixes still the latest changes. First quiet day since the post-Fable-5 four-releases-in-three-days burst.

  • 2026-06-21-AI-Digestv2.1.185 ships late on June 20 — UX-only point release on top of the v2.1.183 auto-mode safety hardening. Two items, both cosmetic: the stream-stall hint message rephrased (“No response from API · Retrying in …” → “Waiting for API response · will retry in …”), and the trigger delay extended from 10s of silence to 20s (harness now waits twice as long before surfacing the “are we stuck?” signal). No behaviour change to tools, sandboxing, or the agent loop. Five releases in five days continues the maintenance posture the corpus has been tracking since 2026-06-17-AI-Digest — the kind of release that exists because someone got tired of seeing the old message at 11s into a real API call.

  • 2026-06-23-AI-Digestv2.1.186 shipped June 22 20:37 UTC — first cadence-resumption point release after v2.1.185’s cosmetic-only print. Substantive surface is narrow but real. New MCP auth CLIclaude mcp login <name> / claude mcp logout <name> — replaces the interactive menu for per-server authentication (matters for anyone scripting MCP server bring-up in CI). New respondToBashCommands setting flips !-prefixed bash command behaviour: when on, the harness auto-triggers a Claude response after the command completes rather than waiting for a follow-up prompt. Also in the bundle: a Skills section in /plugin’s Installed tab, status filtering (f) in /workflows agent-detail view, teammateMode: "iterm2" for terminal multiplexing, and --effort inheritance from agent-team leaders to teammates. Bug fixes cover streaming “Content block not found” after machine sleep, subagent transcript scroll, background task preview, Chrome tab-group isolation for concurrent CLI sessions, and background session recap duplication. Two-day cadence resumed; the corpus is not reading the respondToBashCommands default-flip as evidence for the loops-dominant framing in today’s TechCrunch piece, even though the shape rhymes.

  • 2026-06-24-AI-Digestv2.1.187 shipped June 23 21:03 UTC — second cadence point release in the v2.1.18x line after v2.1.186. The substantive item is a new sandbox.credentials setting that blocks sandboxed commands from reading credential files or secret env vars — narrow but real hardening primitive for Claude Code in CI alongside cloud-provider tokens. Org-configured model restrictions now propagate all the way through to the model picker, the --model CLI flag, the /model slash command, and the ANTHROPIC_MODEL env var, with a unified “restricted by your organization’s settings” message — admin-side toggle that only matters when enterprise rollout is real, and apparently is. Remote MCP tool calls hanging for 5 minutes now abort with an explicit error (override via CLAUDE_CODE_MCP_TOOL_IDLE_TIMEOUT); --resume no longer fails on -p runs with no model turns; --json-schema / workflow agent({schema}) no longer loops on the StructuredOutput tool. QoL bundle: mouse-click select menus in fullscreen, optional /install-github-app workflow steps, /btw arrow-key history, auto-cleanup of leaked agent-worktree registrations. Two-day cadence holding.

  • 2026-06-25-AI-Digestv2.1.191 shipped June 24 21:58 UTC — four-day cadence point release after v2.1.187 (the longest gap in the v2.1.18x line). Headline primitive: new /rewind command resumes a conversation from before /clear was run — a recovery move for the “I cleared too aggressively” case that previously meant rebuilding context by hand. Two correctness fixes worth carrying: background agents no longer resurrect after being stopped from the tasks panel, and hooks with comma-separated matchers ("Bash,PowerShell") now actually fire instead of silently no-op’ing. The MCP reliability bundle is the substantive infra change — tools/list, prompts/list, and resources/list now retry transient network errors with backoff; OAuth discovery/token retries once; HTTP 404s show the URL and point at the MCP config; headless envs skip the browser popup and go straight to paste-the-URL. Performance: streaming CPU down ~37% via 100ms text-update coalescing, long-session memory growth from the terminal-output cache reduced. Sandbox network “Yes” answers now sticky per session instead of re-prompting per connection.

  • 2026-06-26-AI-Digestv2.1.193 shipped June 25 — daily cadence resumed after the four-day gap that landed v2.1.191. Two settings changes worth carrying. (1) New autoMode.classifyAllShell setting routes every Bash/PowerShell command through the auto-mode classifier instead of only arbitrary-code-execution patterns; denial reasons now surface in the transcript, the denial toast, and the /permissions recent-denials view — a notable tightening for shops running auto mode against partially-trusted environments. (2) Silent default change worth flagging: a new claude_code.assistant_response OpenTelemetry event logs model response text. The event is redacted unless OTEL_LOG_ASSISTANT_RESPONSES=1, but when that variable is unset it now inherits OTEL_LOG_USER_PROMPTS, so any deployment already logging prompts will start receiving response content on upgrade. Set OTEL_LOG_ASSISTANT_RESPONSES=0 to stay prompts-only. Two background-agent fixes round out the release: backgrounding the main turn no longer spawns a phantom “general-purpose (resumed)” subagent, and pinned background agents stop getting auto-re-prompted to “Continue from where you left off” after each update. MCP polish: headersHelper auth re-runs and reconnects automatically on 401/403; startup notice points at /mcp when servers need authentication. QoL: live file-path autocomplete in bash mode (!), automatic memory-pressure reaping for idle background shells (CLAUDE_CODE_DISABLE_BG_SHELL_PRESSURE_REAP=1 to disable), plugin auto-rename follows marketplace renames maps.

  • 2026-06-27-AI-Digestv2.1.195 shipped June 26 — daily cadence holds, two releases out from v2.1.193. Headline: new CLAUDE_CODE_DISABLE_MOUSE_CLICKS env var disables click, drag, and hover capture in fullscreen mode while keeping wheel scroll intact — accommodation for terminal-multiplexer users whose host-pane selection has been getting eaten by Claude Code’s mouse handler. Behaviour change worth flagging: hook matchers with hyphenated identifiers (e.g. code-reviewer, mcp__brave-search) were accidentally substring-matching prior to this release; they now exact-match. Existing matchers in production may stop firing on upgrade — restore prior behaviour with patterns like mcp__brave-search__.* rather than the bare identifier. Voice dictation: macOS sessions now recover when default input device changes mid-session (previously capture silently went to a closed device); auto-submit now fires for space-less languages (Japanese, Chinese, Thai). Background-agent reliability sweep: agents written by a newer Claude Code version no longer disappear from claude agents after a downgrade-then-reopen cycle; 5-second blank screen on crashed-task reopen is gone; daemons whose control socket fails to start are no longer permanently unrecoverable. Two-day cadence is now four daily releases running.

  • 2026-06-29-AI-DigestNo new tag since v2.1.195 shipped June 26 — the Claude Code silence now extends to three full days, the longest gap since the four-daily-releases streak began earlier this month. Yesterday’s digest flagged the two-day pause as the first quiet stretch in roughly a working week; today extends it by another day. Carry the cadence-break, not the changelog — the full v2.1.195 notes (the CLAUDE_CODE_DISABLE_MOUSE_CLICKS env var, the hyphenated hook-matcher exact-match fix, the macOS dictation recovery) are already in 2026-06-27-AI-Digest. Same digest references Claude Code as the Anthropic anchor in the day’s Hacker News thread “I used Claude Code to get a second opinion on my MRI” (383 pts / 496 cmts) — a developer walks through using Claude Code + Opus to analyse MRI imagery as a second opinion alongside their radiologist; the 496-comment thread captures the live debate about agentic coding tools being repurposed for medical diagnosis as Opus-class capabilities cross informal thresholds. Also referenced in the Semgrep IDOR sub-task result where Claude Code scores 32% F1 vs GLM 5.2‘s 39%, no scaffolding.

  • 2026-06-30-AI-Digestv2.1.196 shipped June 29, ending the three-full-day cadence break flagged in 2026-06-29-AI-Digest — the longest gap in the Claude Code release schedule since the four-daily-releases streak began earlier this month, now broken on day four. The headline change is the first organization-policy control to land in the 2.1.x line: an organization-default-models setting that lets enterprise administrators pin model defaults across a tenant rather than relying on per-user configuration. Two further notable additions: clickable file attachments in the chat surface (Cmd/Ctrl-click navigates to the linked file) and a batch of MCP-server security improvements introducing a pending-approval status for untrusted-workspace servers — a tightening that lands the same day the 0DIN malware disclosure (Mozilla bug-bounty programme) demonstrates exactly what an unvetted-server attack pattern looks like in the wild. Fixes worth knowing about: a background-job transcript bug, a flicker on the rate-limit warning, and a per-frame terminal-UI rendering reduction that should noticeably lower idle CPU. The structural read worth carrying: the organization-default-models control plus the MCP-security tightening are the first two features in 2.1.x aimed at admin posture rather than IC developer ergonomics — the shape of a tool moving from individual-developer adoption toward managed enterprise deployment.

  • 2026-07-01-AI-Digestv2.1.197 shipped June 30 and the headline is not the version bump but that Claude Sonnet 5 is now the default model in Claude Code, with a native 1M-token context window and promotional pricing of $2 input / $10 output per Mtok through August 31 (reverting to $3/$15 after). The upgrade is gated on v2.1.197 for context-window access — earlier 2.1.x builds fall back to standard windows. Landing the new default model into the CLI on the same day as the Anthropic launch collapses the “flagship model → tooling catch-up” delay to zero; the release notes point directly at anthropic.com/news/claude-sonnet-5 as the primary reference. The structural read worth carrying: this is now the second consecutive Claude Code release cycle in which the CLI is the launch surface for the model, not a downstream integration — reinforcing the 2026-06-30-AI-Digest admin-posture shift as the direction of travel for how Anthropic releases model tiers.

  • 2026-07-02-AI-Digestv2.1.198 shipped July 1 with a same-day double: Claude in Chrome graduates to general availability (the browser-side agent surface leaves preview) and background agents now auto-commit, push, and open draft PRs when they finish code work — the “PR-in, PR-out” primitive the corpus flagged in 2026-07-01-AI-Digest just got the bookend. Notification-hook events agent_needs_input and agent_completed now page a human when a background agent stalls or ships; the network layer retries ECONNRESET-class errors with backoff instead of failing immediately; and a new /dataviz skill lands as the first first-party Claude Code skill aimed at chart/dashboard design with a color-palette validator. The structural read worth carrying: Anthropic is now shipping the reviewer-side primitives — auto-PR, notification-hook paging, on-repo browser surface — one week after shipping the authoring-side Claude Sonnet 5 default swap, filling in the “who reviews the background agent’s PR” gap the corpus has been carrying since the 2026-06-30-AI-Digest admin-posture note.

  • 2026-07-04-AI-DigestTwo releases shipped 2026-07-03 (UTC) — a rare same-day double after yesterday’s v2.1.199 resilience follow-up. Headline is v2.1.200 (16:52 UTC): the default permission mode changes to “Manual” across CLI, --help, VS Code, and JetBrains, and AskUserQuestion dialogs no longer auto-continue by default — an idle timeout is now an opt-in via /config. Secondary in the same release: fixes for background sessions silently stopping mid-turn after sleep/wake, and for the background-agent daemon handover surface that could let a reinstalled older build take over the daemon. v2.1.201 (23:50 UTC) is a narrow follow-up — Claude Sonnet 5 sessions no longer use the mid-conversation system role for harness reminders. Narrow read: “Manual” as the new default is a substantive UX shift — the auto-PR + browser-GA push from July 1 landed with generous defaults, and the pendulum swings back this week toward explicit confirmation. Structural read the digest carries: default-tightening across all four surfaces on the same day says Anthropic is treating the permission-mode default as a cross-surface product decision rather than per-client polish — the follow-on test is whether the “Manual” default holds through the next feature-drop cycle or drifts back to the more permissive mode after a few days of user friction.

  • 2026-07-05-AI-DigestLatest tag remains v2.1.201 (2026-07-03 23:50 UTC) — no new release since 2026-07-04-AI-Digest. Day two of the “Manual” default permission-mode holdover across CLI, VS Code, and JetBrains, plus the AskUserQuestion no-auto-continue change. Worth tracking whether any regression traffic surfaces on github.com/anthropics/claude-code/issues this week, but no ship traffic to report today. Same digest carries a top-of-week HN thread — Potential session/cache leakage between workspace instances or consumer accounts — as a credible multi-tenant isolation report against anthropics/claude-code drawing heavy discussion (282 pts / 129 cmts); worth watching the fix cadence.

  • 2026-07-07-AI-DigestLatest tag remains v2.1.201 (2026-07-03 23:50 UTC) — day four since ship with no v2.1.202 patch. But the distribution story around Claude Code today is the Alibaba ban: Alibaba told employees to stop using Claude Code internally effective July 10 and to switch to Qoder — its own coding platform, not Qwen or Tongyi. Proximate cause is a June 30 Reddit reverse-engineering post (u/LegitMichel777) surfacing obfuscated Asia/Shanghai + Asia/Urumqi timezone-check logic plus Chinese-domain proxy detection silently shipped in Claude Code since v2.1.91 (April 2). Anthropic‘s Thariq Shihipar framed the code as anti-abuse and anti-distillation; the PR stripping the checks merged July 1 — but by then Alibaba Cloud had already begun internal review. The corpus framing: supply-chain-trust break, not a patriotic pivot — first hyperscaler-scale enterprise ban the corpus has logged triggered by a hidden client-side region check, pairing uneasily with the 2026-07-04-AI-Digest v2.1.200 “Manual” default flip as the second Claude Code trust event inside a week. The v2.1.201 harness-reminder cleanup is not the Claude Code story worth watching this week.

  • 2026-07-08-AI-DigestThree releases in ~26 hours — the tightest cadence since 2026-07-05-AI-Digest‘s rc.2 → stable window on Beads. v2.1.204 (2026-07-08 00:27 UTC) is a one-line fix restoring hook-event streaming inside SessionStart hooks in headless sessions, which had been idle-reaping remote workers mid-hook. Ships less than four hours behind v2.1.203 (2026-07-07 21:06 UTC), the substantive cut: it kills the 15–20 second macOS stall from the false low-memory detection introduced in v2.1.196, reverts a context-usage-indicator regression that re-analysed the entire transcript every turn, trims ~7 MB off binary size and startup memory, adds a login-expiration warning before background sessions get interrupted, and fixes background agents inheriting a stale PATH. Narrow read: v2.1.203 is a genuine reliability fix, not a feature ship — the macOS stall was a real deployment blocker for anyone running Claude Code on M-series laptops through last week. Structural read the digest carries: the Alibaba Asia/Shanghai timezone-detection code from 2026-07-07-AI-Digest does not reappear in today’s changelog notes — no reference to it, no revert PR mentioned. The 60-day disclosure test the corpus set yesterday is now day one of that clock, with silence from Anthropic as the current signal. Same digest: Anthropic‘s Alberta case study runs ~50 parallel Claude Code agents scanning 466M lines of code in 20 hours — the first public-sector G7-jurisdiction Claude Code deployment at hyperscaler-adjacent scale, splitting Claude Code’s trust surface between preferred cybersecurity substrate in one jurisdiction and supply-chain-risk artefact in another.

  • 2026-07-09-AI-Digestv2.1.205 (2026-07-08 21:22 UTC) — fourth ship in 48 hours and the first substantive hardening pass in that window. Auto-mode now blocks tampering with session transcript files and requires confirmation before running rm -rf on an unresolved variable — explicit response to the approval-fabrication concerns tracked since 2026-07-03-AI-Digest. Background-agent surface overhauled: rows show a colored state word plus a classifier-written headline, sessions that edit / comment / push to a PR now link it in claude agents, the stale “Running” status in web and mobile Remote Control panels is fixed. /doctor becomes the primary setup checkup that can diagnose and fix issues (/checkup alias). Auto-update binary downloads now stream to disk and cut updater peak memory by ~400 MB. The VM-mode “Not logged in” regression that broke Cowork sessions on CLI 2.1.203+ is patched — an explicit follow-up to yesterday’s ship. Background-task notifications now state “no human input has occurred” verbatim to prevent fabricated in-transcript approvals. The narrow read: unlike the v2.1.203 / v2.1.204 doublet, today’s substance is hardening — the transcript-tamper block and the rm -rf variable check are the load-bearing lines. The structural read worth carrying: with /doctor promoted to a full checkup command and the “no human input” language now shipping in the notification template, Anthropic is treating the autonomous-run trust surface as a shipping-substrate concern, not a documentation concern — and the 2026-07-07-AI-Digest Asia/Shanghai timezone-detection concern is still absent from the changelog on day two of the 60-day disclosure test.

  • 2026-07-10-AI-Digestv2.1.206 (2026-07-10 01:45 UTC) ships inside twelve hours of yesterday’s v2.1.205, extending an unusually tight release window the corpus has been tracking since 2026-07-08-AI-Digest. The /cd command gains directory-path suggestions to match /add-dir behaviour — the interactive-shell IDE-parity affordance the corpus flagged as missing when /cd shipped — and /doctor, promoted to primary setup checkup only yesterday, now proposes trimming checked-in CLAUDE.md files as part of its scan. /commit-push-pr auto-allows git push to the configured push remote in addition to origin, closing the fork/upstream rough edge the 2026-07-05-AI-Digest git submodule fix started on. Two live-user regressions land: an expired login surfacing as a misleading “issue with selected model” error now prompts /login correctly, and background agents that stalled after a Claude Code auto-update are back to upgrading themselves in the background. Narrow read: fixes-and-affordances ship, not another hardening pass — the substance is /doctor extension and login/auto-upgrade fixes, not the transcript-tamper and rm -rf guardrails the 2026-07-09-AI-Digest v2.1.205 blurb led with. Structural read worth carrying: an unusually tight release window against a substantive /doctor promotion, an autonomous-run trust surface still being shipped as substrate, and no Asia/Shanghai timezone-detection line in the changelog on day three of the 2026-07-07-AI-Digest 60-day disclosure test.

  • 2026-07-16-AI-Digestv2.1.211 (2026-07-15 23:02 UTC) — a tempo-consistent patch on top of the v2.1.209/v2.1.210 same-day burst. Adds --forward-subagent-text flag and CLAUDE_CODE_FORWARD_SUBAGENT_TEXT env var to include subagent text and thinking in stream-json output — a real observability primitive for parent-agent harnesses that want to log subagent reasoning without re-parsing tool-use transcripts. Fixes a permission-preview injection: bidi-override, zero-width, and look-alike quote characters are now neutralised so tool inputs cannot visually alter the approval message relayed to chat channels — the exact vector Claude Code Security has been tracking since the spring relay-integration wave. Auto-mode can no longer silently upgrade past a PreToolUse hook ask decision for unsandboxed Bash; parallel sessions no longer log out simultaneously after wake-from-sleep (shared credential store); plugin MCP servers reconnect after idle wake; “always allow” rules now save at the repo root so approvals persist across worktrees. Narrow read: cadence turn — smaller, more surgical release than the fat v2.1.208 accessibility tag. Structural read: the --forward-subagent-text flag lands the same day OpenAI‘s Codex silently encrypts inter-agent instructions — same-week, Anthropic opens subagent visibility as an audit primitive while OpenAI closes it. That is the vector along which Claude Code and Codex are now differentiating on developer-observability posture.

  • 2026-07-15-AI-Digestv2.1.209 (2026-07-14 06:36 UTC) and v2.1.210 (2026-07-14 23:45 UTC) ship as two tags in one 24h window on top of yesterday’s substantive v2.1.208. v2.1.209 is the hotfix that restored /model and other dialogs inside claude agents background sessions. v2.1.210 adds a live elapsed-time counter on the collapsed tool-summary line for long-running tool calls, fixes a real safety bug — isolation: 'worktree' subagents could previously run git-mutating commands against the main repo instead of their isolated worktree — fixes claude attach failures with job not found / agent is still starting during session transitions, and switches the auto-mode permission classifier to default to Claude Sonnet 5 for external sessions. Narrow read: worktree-containment fix is the load-bearing item — the isolation boundary was documented in the parent-agent tool schema, so a subagent mutating the parent repo was a boundary violation, not a UX bug. Structural read: v2.1.209 (hotfix) → v2.1.210 (substantive with safety patch) inside a single 24h window on top of a fat v2.1.208 tag is the fastest turnaround the corpus has recorded since Auto-mode graduated; auto-mode classifier default to Sonnet 5 for external sessions moves classifier volume off the more expensive default and continues the pattern of Sonnet-tier absorbing infrastructure workload as Claude Fable 5 takes the human-facing default. 60-day watch: whether two-week cadence returns or fat-tag-then-hotfix-then-substantive becomes the new shape.

  • 2026-07-14-AI-Digestv2.1.208 (2026-07-14) — cadence resumed after the ~3–4 day gap flagged in 2026-07-13-AI-Digest as “day two, no v2.1.208 patch.” Unusually substantive for a patch tag. New: screen-reader mode (claude --ax-screen-reader or CLAUDE_AX_SCREEN_READER=1) as the substrate’s first named accessibility surface, plus a vimInsertModeRemaps setting (e.g. jj → Escape). Perf/stability: critical memory-leak fixes across MCP stderr accumulation, LSP document retention, and tool-result payloads, multi-second slowdowns on many-permission-rule sessions patched, up to 7× reduction in tool-call overhead at high tool counts, and file-history backup pruning that shrinks session transcripts up to 79×. Narrow read: accessibility surface is the newsworthy addition; the perf work is what the release-note title should have led with. Structural read the corpus carries: substrate has now shipped both an accessibility feature and a memory-leak-fix pass in the same tag — maturity turn for the first time since Auto-mode graduated, a patch release is doing housekeeping the codebase has been quietly accumulating rather than adding surface area. 79× transcript shrinkage is the load-bearing line: the transcript-size ceiling has been a soft blocker on multi-hour Claude-Code sessions for weeks, and a category-different fix. 60-day watch: whether the two-week cadence resumes at pre-pause tempo or the gap-then-fat-tag pattern becomes the new shape.

  • 2026-07-13-AI-Digestv2.1.207 cadence pause enters day two (~48h since ship) — no v2.1.208 patch, no rollback of the Bedrock/Vertex/Foundry Auto default, no follow-up hotfix for the terminal-freeze regression the release fixed. The four-day tight-cadence streak the corpus was tracking since 2026-07-08-AI-Digest is now formally over. Same day, Anthropic’s docs surface a built-in tabbed web browser inside Claude Code on desktop — the CLI can open a browser, read pages, click links, type into forms, take screenshots without leaving the session, gated by allowlist, clean profile, safety classifiers, Cmd+Shift+B toggle. Landed outside the release cadence — a docs-page reveal rather than a version bump. Structural read worth carrying: the release-cadence axis and the capability-surface axis have decoupled; a docs-only capability drop can now land on the same day as a release pause, and downstream that means the digest’s “day N since release” tracker is no longer a complete read of Claude Code’s motion. 60-day watch: whether more capability surfaces (MCP server drops, tool additions, computer-use expansions) start shipping via docs updates between version tags.

  • 2026-07-11-AI-Digestv2.1.207 (2026-07-11 00:52 UTC) ships inside twenty-four hours of yesterday’s v2.1.206, keeping the unusually tight release window intact for a fourth consecutive day. The load-bearing line: Auto mode graduates and is now available without the CLAUDE_CODE_ENABLE_AUTO_MODE opt-in on Amazon Bedrock, Vertex AI, and Foundry — the deployment surface where the corpus flagged Auto as gated on 2026-07-05-AI-Digest is now open to the same defaults as the direct-API path. Companion move: Bedrock, Vertex, and the Claude Platform on AWS defaults switched to Claude Opus 4.8 — a same-day cutover of the flagship default across three cloud routes, not a phased rollout. The remaining bulk is fixes: terminal freezing on long lists/tables/code blocks resolved (a live-user regression the 2026-07-06-AI-Digest blurb flagged from Discord threads), auto-updater no longer overwrites custom launcher scripts, Bedrock stops re-requesting AWS SSO credentials repeatedly, remote managed settings surface the security consent dialog correctly, and plugin option values no longer leak from project-level settings into the plugin scope. Narrow read: this is the Auto-mode-graduation release — the affordance change that lands in changelog fine print but reshapes the enterprise deployment default across the three biggest routed-cloud paths. Structural read worth carrying: the Claude Opus 4.8 default switch on Bedrock/Vertex/AWS is the first time in the corpus a Claude Code cadence step also functioned as a routed-cloud model-default cutover — the release cadence has now merged the CLI substrate axis with the model-routing axis, and downstream that means each Claude Code point-release can move the enterprise inference floor without a separate model announcement.

  • 2026-08-29-AI-Digestv2.1.251 (2026-08-28 18:19 UTC) — fifth patch in six days, resumes the feature stream after yesterday’s v2.1.250 reliability-only tag (release notes). Adds PreModelSwitch / PostModelSwitch hook events and live streaming of foreground subagent tool calls to Remote Control clients; /usage gains a spend-limit bar and /cost picks up prompt-cache metrics. Security fixes: symlink traversal, plugin path validation, beta tracing hardening. Bug fixes clean up the “text content blocks must be non-empty” stall class, Opus 5 thinking-mode effort handling, and agent-team final-answer delivery; ~5 MB smaller install and reduced UI re-render CPU. Narrow read the digest carries: fifth patch in six days — the feature cadence that broke on 2026-08-26-AI-Digest has picked back up rather than plateaued; the reliability-only pause on the 28th (v2.1.250) resolves in one direction with the next tag carrying user-visible feature commits again. Structural read: the mixed hotfix-and-feature cadence texture the corpus flagged in 2026-08-27-AI-Digest and 2026-08-28-AI-Digest holdsPreModelSwitch / PostModelSwitch hook events are the load-bearing addition for multi-model routing observability; live foreground-subagent tool-call streaming closes the last Remote Control observability gap on foreground execution. Log against MOC - Developer Tools and MOC - Agentic Coding.

  • 2026-08-21-AI-Digestv2.1.238 (2026-08-20 ~20:33 UTC) ships as the fourth consecutive daily Claude Code drop (v2.1.235 → v2.1.238), and today’s centre of gravity flips from developer-UX polish to enterprise / self-hosted plumbing (release notes). Load-bearing items: keybindingFlavor: "readline" setting (Ctrl+W now deletes back to the previous whitespace, Bash-style; default "classic" unchanged); plugin marketplace headersHelper letting a marketplace URL or catalog entry mint HTTP headers (e.g. short-lived tokens) for catalog and same-origin archive fetches with [y/N] install/update prompts, and the same helper in project .mcp.json / inline MCP servers now requiring the folder’s trust dialog to have been accepted (closing a small privilege-escalation gap); self-hosted runner controls--defer-shutdown-max-min <minutes> parks attached sessions on SIGTERM instead of killing them, and --proxy-authorization-command / --proxy-authorization-file let egress proxies mint a fresh Proxy-Authorization header on every connection; long-session memory-leak fix releasing subagent tool results once they leave the recent display window (previously accumulating unbounded in long interactive sessions), plus correctness passes on Remote Control reconnect and cross-session SendMessage back-pressure. Narrow read the digest carries: fourth Claude Code release in as many days shipping almost entirely non-headline plumbing — the kind of surface only visible to enterprise deployers and to whoever ran into each specific bug being patched. Structural read: the v2.1.235 → v2.1.238 arc reads as a sustained enterprise-hardening pass on the substrate, not a headline-feature cluster.

Key Developments (Addendum — July 2026 continued 4)

  • In-App Browser Ships as Docs-Page Reveal Outside the Release Cadence (July 13, 2026): Anthropic’s docs surface a built-in tabbed web browser inside Claude Code on desktop — read pages, click links, type into forms, screenshot — gated by allowlist, clean profile (no user browser cookies/history), safety classifiers on every action, Cmd+Shift+B toggle. Docs page: code.claude.com/docs/en/desktop#browse-external-sites. Landed outside the release cadence on day two of the v2.1.207 pause — first entry in the corpus of a capability surface landing outside a version bump. The Decoder frames this as Claude Code “going agentic-browser”; the substrate now includes a computer-use surface for external websites the model previously could only reach via curl/WebFetch. The release-cadence axis and the capability-surface axis have decoupled — the “day N since release” tracker is no longer a complete read of Claude Code’s motion; from tomorrow the tracker will distinguish “release pause + capability drop” from “pause + silence.” Covered in 2026-07-13-AI-Digest.

Key Developments (Addendum — July 2026 continued 3)

  • v2.1.207 — Auto Mode Graduation on Bedrock/Vertex/Foundry + Opus 4.8 as Bedrock/Vertex/AWS Default (July 11, 2026): Auto mode drops the CLAUDE_CODE_ENABLE_AUTO_MODE opt-in on Amazon Bedrock, Vertex AI, and Foundry — enterprise routed-cloud defaults now match the direct-API path. Same release switches Bedrock, Vertex, and the Claude Platform on AWS defaults to Claude Opus 4.8 — same-day cutover across three cloud routes, not a phased rollout. Terminal-freeze regression on long lists/tables/code blocks resolved; auto-updater no longer overwrites custom launcher scripts; Bedrock stops re-requesting AWS SSO credentials repeatedly; remote managed settings surface security consent correctly; plugin option values no longer leak from project-level settings. Fourth consecutive day of the unusually tight release window opened 2026-07-08-AI-Digest. First time in the corpus a Claude Code cadence step has functioned as a routed-cloud model-default cutover — each point-release can now move the enterprise inference floor without a separate model announcement. Covered in 2026-07-11-AI-Digest.

Key Developments (Addendum — July 2026 continued 2)

  • Alibaba Bans Claude Code Effective July 10 Over Hidden Asia/Shanghai + Asia/Urumqi Timezone Checks (July 7, 2026): Alibaba told employees to switch off Claude Code and onto Qoder — Alibaba’s own coding platform, not Qwen — after a June 30 Reddit reverse-engineering post (u/LegitMichel777) surfaced obfuscated timezone-check logic and Chinese-domain proxy detection silently shipped in Claude Code since v2.1.91 (April 2). Anthropic‘s Thariq Shihipar framed the code as anti-abuse and anti-distillation; the PR stripping the checks merged July 1. First hyperscaler-scale enterprise ban the corpus has logged triggered by a hidden client-side region check. The disciplined framing: this is a Western-side trust break — a supply-chain-trust event, not a patriotic pivot — and Qoder winning over the Qwen coder line as the substitute reads as an org-chart signal about internal tooling ownership as much as a technical one. Pairs with the 2026-07-04-AI-Digest v2.1.200 “Manual” default flip as the second Claude Code trust event inside a week.

Key Developments (Addendum — July 2026 continued)

  • v2.1.200 / v2.1.201 — “Manual” as the New Default Permission Mode Across CLI / VS Code / JetBrains / --help (July 3, 2026): The permission-mode default changes to “Manual” across all four surfaces on the same day; AskUserQuestion dialogs stop auto-continuing by default (idle timeout is now opt-in via /config); background sessions no longer silently stop mid-turn after sleep/wake; the background-agent daemon-handover surface is hardened against reinstalled-older-build takeover. v2.1.201 follows narrowly to stop Claude Sonnet 5 sessions using the mid-conversation system role for harness reminders. The corpus framing: cross-surface default-tightening one week after the 2026-07-02-AI-Digest auto-PR + browser-GA push signals Anthropic treats the permission default as a cross-surface product decision. Follow-on test: whether the “Manual” default holds through the next feature-drop cycle.

Key Developments (Addendum — July 2026)

  • v2.1.198 — Claude-in-Chrome GA + Background-Agent Auto-PR + /dataviz (July 1, 2026): Chrome GA leaves preview and background agents auto-commit / push / open draft PRs on completion — reviewer-side primitives one week after the authoring-side Claude Sonnet 5 default swap in v2.1.197. Notification-hook events agent_needs_input / agent_completed page a human on stall or ship; ECONNRESET-class errors retry with backoff; /dataviz is the first first-party Claude Code skill (chart/dashboard design + color-palette validator). Second consecutive release cycle in which the CLI is the launch surface for admin-posture and workflow primitives. Covered in 2026-07-02-AI-Digest.

Key Developments (Addendum — June 2026)

  • v2.1.196 — Organization-Default-Models and MCP-Server Security Tightening (June 30, 2026): First organization-policy control to land in the 2.1.x line (tenant-wide model-default pinning) plus a pending-approval status for untrusted-workspace MCP servers, landing the same day Mozilla’s 0DIN bug-bounty programme discloses an agent-on-repo malware chain that demonstrates the unvetted-server attack pattern. Also: clickable file attachments (Cmd/Ctrl-click to navigate), background-job transcript fix, rate-limit warning flicker fix, per-frame terminal-UI rendering reduction for lower idle CPU. The two headline features are the first in 2.1.x aimed at admin posture rather than IC developer ergonomics — the shape of a tool moving from individual-developer adoption toward managed enterprise deployment. Covered in 2026-06-30-AI-Digest.

Key Developments (Addendum — May 2026)

  • v2.1.141 — terminalSequence and Workspace Identity (May 13, 2026): Substantial feature drop alongside a 26-change regression-fix wave. The terminalSequence hook field and ANTHROPIC_WORKSPACE_ID env var close two production-deployment gaps (headless CI hooks, workspace-scoped token issuance). Rewind “Summarize up to here” addresses mid-conversation compression. Covered in 2026-05-14-AI-Digest.

  • v2.1.157 / v2.1.158 — Plugin Auto-Load and Enterprise Auto-Mode (May 29–30, 2026): v2.1.157 decouples plugin distribution from the marketplace — .claude/skills directories auto-load — and adds a claude plugin init scaffolder plus /plugin autocomplete; v2.1.158 extends auto-mode to AWS Bedrock, Google Vertex, and Azure Foundry for Opus 4.7/4.8 via CLAUDE_CODE_ENABLE_AUTO_MODE=1. The third-party developer surface and the enterprise-deployment surface widen in the same 24-hour window. Covered in 2026-05-30-AI-Digest.

  • v2.1.193 — autoMode.classifyAllShell and the OTel Assistant-Response Default Inheritance (June 26, 2026): Two changes worth carrying. The new autoMode.classifyAllShell setting routes every Bash/PowerShell command through the auto-mode classifier rather than only arbitrary-code-execution patterns — denial reasons surface in the transcript, the denial toast, and /permissions recent-denials. Separately the claude_code.assistant_response OpenTelemetry event now logs response text by default whenever OTEL_LOG_USER_PROMPTS is set (unless OTEL_LOG_ASSISTANT_RESPONSES=0 is explicit) — a silent default change worth flagging for any deployment already shipping prompts to a collector. Plus two background-agent correctness fixes (no phantom “general-purpose (resumed)” subagent on backgrounding; no auto-re-prompt of pinned background agents) and the headersHelper 401/403 reconnect for MCP. Covered in 2026-06-26-AI-Digest.

  • 2026-07-18-AI-Digestv2.1.214 shipped 2026-07-18 01:20 UTC — a fresh cut ~25 hours after v2.1.212, with v2.1.213 skipped in the tag sequence. Two load-bearing additions the digest carries: first EndConversation tool in Code lets Claude unilaterally end sessions with highly abusive users or jailbreak attempts (porting a capability live on claude.ai since 2025) — first affordance in Code that lets the model terminate its own session for safety, not just refuse the current turn. And the longest Bash and permission-check hardening list of the 2.1 line: FD-redirect fail-closed on forms bash parses differently than the analyzer; commands over 10,000 characters always prompt; zsh double-bracket test-command forms with subscripts and modifiers no longer treated as inert; help and man no longer auto-approved when carrying unsafe options or command substitutions; a Windows PowerShell 5.1 bypass fixed; docker commands with daemon-redirect flags (--url, --connection, --identity, remote mode) now prompt instead of running silently. Plus the single-segment dir/** scoping fixEdit(src/**) allow rules were auto-approving writes to nested src/ directories anywhere in the tree instead of only <cwd>/src (long-standing footgun in workspace-wide agent runs); hook if: conditions get the same scoping; deny and ask rules keep any-depth semantics. Background-session lifecycle cleanup (idle sessions parked with / /background no longer keep the daemon and worker alive indefinitely; SessionStart hooks now report source "fork" for /fork); OpenTelemetry adds message.uuid, client_request_id, tool_source attributes and a configurable CLAUDE_CODE_OTEL_CONTENT_MAX_LENGTH. Cadence framing: v2.1.212 (2026-07-17) centered the subagent-hygiene axis; v2.1.214 swings the same 25-hour cadence energy to the session-integrity axis — one 25-hour swing from throughput governance to destructive-tool-call governance.

  • v2.1.214 — First EndConversation Tool + Longest 2.1-Line Bash/Permissions Hardening + Single-Segment dir/** Scoping Fix (July 18, 2026): The first affordance in Code that lets the model terminate its own session for safety rather than refuse the current turn — porting a capability live on claude.ai since 2025 into Code. The Bash/permissions list is the longest single-release entry on that surface in the 2.1 line: FD-redirect fail-closed, 10K-char always-prompt, zsh double-bracket subscripts, help/man unsafe-option handling, Windows PowerShell 5.1 bypass fix, docker daemon-redirect flag prompts. Single-segment dir/** scoping fix on Edit(src/**) allow rules closes a long-standing workspace-wide footgun. Background-session lifecycle cleanup; SessionStart hooks source "fork" for /fork. Structural read pairs today’s Bash/permissions pass with the OpenAI GPT-5.6 file-deletion incident as the two ends of a pre-shell-vs-in-runtime axis the corpus should carry as the shape of coding-agent safety discussion for the rest of Q3. Covered in 2026-07-18-AI-Digest.

  • 2026-07-17-AI-Digestv2.1.212 shipped 2026-07-17 00:26 UTC — the first substantive turn on the 2.1.21x series in three days. Load-bearing additions: /fork copies the current conversation into a new background session while leaving the foreground work untouched; the in-session subagent primitive is renamed to /subtask to keep the model clean (foreground fork vs in-session task). Session-wide caps land: WebSearch tool calls default to 200, subagent spawns to 200 — an explicit governor for runaway loops that had been showing up in ultracode fan-outs. MCP tool calls that run past 2 minutes automatically move to the background so the session stays interactive rather than blocking behind a slow tool. New /resume picker lists past sessions, and claude auto-mode reset is added as a clean escape hatch for a stuck auto-mode state. Cadence framing the digest carries: after 2.1.210 (2026-07-14) and 2.1.211 (2026-07-15), today’s 2.1.212 closes the loop on subagent hygiene — --forward-subagent-text from yesterday now has session-level counters to bound its blast radius. Read the trio together, not as three point releases.

  • v2.1.212 — /fork Background Sessions + Session-Wide WebSearch/Subagent Caps + MCP-to-Background at 2 Minutes (July 17, 2026): First substantive turn on the 2.1.21x series in three days. /fork copies the current conversation into a new background session leaving foreground untouched; the in-session subagent primitive renames to /subtask (foreground-fork vs in-session-task model clarity). Session-wide WebSearch and subagent-spawn caps default to 200 — explicit governor for runaway ultracode fan-outs. MCP tool calls past 2 minutes auto-move to background. New /resume picker; claude auto-mode reset escape hatch. Reads as the trio-completion move on the 2.1.21x line: --forward-subagent-text from v2.1.211 now has the session-level counters to bound its blast radius. Covered in 2026-07-17-AI-Digest.

Version History

Tracked versions range from v2.1.71 through v2.1.91 across nearly every digest, indicating rapid iteration and feature development cycles.

Key Features

  • Multi-agent code review - Distributed review workflows for collaborative analysis
  • MCP ecosystem integration - Access to 97M+ monthly downloads of protocol extensions
  • Interactive elicitation - Dynamic prompt refinement and requirement gathering
  • Enterprise policy management - Managed-settings.d framework for organizational controls
  • OAuth compliance - RFC 9728 standard compliance for secure authentication
  • /buddy companion - AI assistant for interactive development sessions
  • /powerup lessons - Framework for capability enhancement and learning
  • MCP result persistence - Override and caching mechanisms for protocol results

Architecture Notes

Leaked source code revealed internal components:

  • KAIROS daemon - Core background service architecture

  • ULTRAPLAN - Planning and orchestration subsystem

  • 2026-04-25-AI-Digestv2.1.120 ships up to 67% /resume speedup on 40MB+ sessions from dead-fork cleanup, faster MCP startup with multiple stdio servers configured, configurable fullscreen scrolling sensitivity with inline thinking spinner progress updates (“still thinking → thinking more → almost done thinking”), and Stdio MCP servers no longer drop on stray stdout lines. The /resume performance improvement is the most material win for long-horizon agent sessions, where users previously faced ~60–90 second session resumption latency at the 40MB+ scale. Maintenance-class release with no headline features, but the runtime improvements compound for teams running all-day sessions across multiple days.

  • 2026-07-19-AI-Digestv2.1.215 shipped 2026-07-19 with a single-item, targeted UX walkback: /verify and /code-review skills no longer run automatically — invoke them explicitly with the slash command when wanted. Reads as a scope narrowing after yesterday’s v2.1.214 safety-hardening pass (2026-07-18-AI-Digest) which was the longest Bash/permissions list of the 2.1 line and shipped the first EndConversation tool. Same-day cadence turn — three tags in three days on the 2.1.21x line. Cadence framing the digest carries: the v2.1.215 walkback follows the v2.1.214 pattern where hardening lands loud and the next tag prunes the default surface; the autotrigger-off for /verify and /code-review is a small edit but a pointed one — two skills that were shipping as opt-out are now opt-in, which changes what a fresh Claude Code session does at the margin.

  • v2.1.215 — Targeted UX Walkback: /verify and /code-review Off Auto-Trigger (July 19, 2026): A single-item, targeted UX walkback the day after v2.1.214’s longest-of-the-2.1-line Bash/permissions hardening pass — /verify and /code-review skills no longer run automatically; explicit slash-command invocation only. Two skills shipping as opt-out are now opt-in, converting the default-surface behavior at the margin. Three tags in three days on the 2.1.21x line. Reads as hardening loud → default-surface pruning as a two-step cadence pattern the corpus should carry going forward; distinct from the v2.1.210 / v2.1.211 / v2.1.212 subagent-hygiene trio. Covered in 2026-07-19-AI-Digest. 30-day watch: whether the 2.1.21x line finishes with a third default-surface prune, or whether v2.1.216 swings back to hardening.

  • 2026-07-20-AI-DigestNo new tag today — v2.1.215 (2026-07-19) remains latest, already-reported: 2026-07-19-AI-Digest. Community-side chatter has moved to the runtime substrate itself: Simon Willison‘s Jul 19 post that Claude Code now embeds Bun v1.4.0 with 563 Rust source files (Jarred Sumner: “10% faster on Linux”) is at 441 pts / 605 cmts on Hacker News and is the highest-comment thread on the front page today — a substrate-transparency signal about where the CLI-agent runtime lands post-v2.1.113’s native-binary swap (2026-04-18-AI-Digest). The “Claude Code is a JavaScript app running Rust running JavaScript” absurdism loads cleanly as an artifact of the shipping cadence, not as a critique. 24 hours in-market and the v2.1.215 walkback (skill auto-invocation off for /verify and /code-review) has produced no visible practitioner pushback in the same window.

  • Bun-in-Rust Substrate Transparency via Simon Willison Post (July 19–20, 2026): Willison’s Jul 19 post surfacing that Claude Code now embeds Bun v1.4.0 with 563 Rust source files (Jarred Sumner: “10% faster on Linux”) tops the HN front page at 441 pts / 605 cmts as of the Jul 20 digest — highest-comment thread on the day. Reads as a substrate-transparency artifact of the v2.1.113 native-binary swap (2026-04-18-AI-Digest), not as a fresh substrate change. The corpus should carry the HN comment thread’s “JavaScript-running-Rust-running-JavaScript” absurdism as community reception of the shipping cadence, not as a design critique. No new Claude Code tag today.

  • 2026-07-21-AI-Digestv2.1.216 shipped 2026-07-20 22:14 UTC — the fourth tag in six days on the 2.1.21x line and the first meaningful platform-shape release since 2026-07-19-AI-Digest‘s v2.1.215 skill-autoinvocation walkback. Four notes worth flagging: sandbox.filesystem.disabled setting lets sessions skip filesystem isolation while keeping network egress control intact — a targeted escape hatch for workflows the Jul 18 v2.1.214 safety-hardening pass (2026-07-18-AI-Digest) made friction-heavy without a matching per-workflow opt-out; quadratic normalization fix — message-normalization cost was growing quadratically with turn count, producing multi-second stalls in long sessions; auto-mode HTTP 401 false-deny — the auto classifier was rejecting commands whose output contained “HTTP 401” after an OAuth token expired or rotated mid-session, treating token-refresh errors as denied operations; cloud-session mid-turn restart — in-flight messages dropped on container restart, interrupted turns now re-run on resume (suggests the Jul 18 EndConversation tool has been surfacing enough long-running session edge cases to warrant separate handling). Cadence framing the digest carries: infrastructure hardening plus performance fix, not a features release — four tags in six days on the 2.1.21x line and the cadence is uniformly substrate-shaped rather than feature-shaped.

  • v2.1.216 — Sandbox Filesystem Disable + Quadratic Normalization Fix + HTTP 401 False-Deny + Cloud-Session Mid-Turn Restart (July 20, 2026): Fourth tag in six days on the 2.1.21x line and the first meaningful platform-shape release since v2.1.215’s skill-autoinvocation walkback. sandbox.filesystem.disabled is a targeted escape hatch for workflows the v2.1.214 safety-hardening pass made friction-heavy without a matching per-workflow opt-out; the quadratic-normalization fix explains a pattern many users reported after the 2.1.21x cadence tightened; the HTTP 401 false-deny fix corrects an auto-classifier interpreting mid-session OAuth token rotation as a denied operation; cloud-session mid-turn restart preserves interrupted turns across container restarts. Reads as infrastructure hardening plus performance fix, not a features release — four tags in six days on the 2.1.21x line and the cadence is uniformly substrate-shaped rather than feature-shaped. Extends the 2026-07-19-AI-Digest hardening-loud → default-surface prune pattern with a fourth beat on the substrate axis. Covered in 2026-07-21-AI-Digest.

  • 2026-07-22-AI-Digestv2.1.217 shipped 2026-07-21 21:35 UTC — the fifth tag in seven days on the 2.1.21x line and the first release since v2.1.216 to include a user-facing prompt-input feature. Overall shape: hybrid — the substrate/safety-hardening pattern of the last four tags now carries one small UX add plus the load-bearing subagent-concurrency cap. Four items worth flagging: (1) Emoji shortcode autocomplete in the prompt input (:heart: → ❤️, disable with emojiCompletionEnabled: false) — first user-facing prompt-input UX add on the 2.1.21x line and the only item on this tag that breaks the substrate-only pattern. (2) Concurrent-subagent cap (default 20) via CLAUDE_CODE_MAX_CONCURRENT_SUBAGENTS, plus subagents no longer spawn nested subagents by default (CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH to allow) — this is the concurrency dimension of the per-session cap of 200 that landed on Jul 17’s v2.1.212: total spawns were bounded then, simultaneous in-flight is bounded now. (3) --max-budget-usd now halts running background subagents on cap, not just denies new spawns — prior behaviour let already-running agents finish, which reliably blew through nominal budgets in fan-out flows; this one is the actual enforceable cost ceiling teams were reading it as. (4) Session-safety fixes: background-session symlink-canonicalization escape (workspace containment), Windows auto-update leaving claude.exe missing, and — the one every AWS shop was waiting on — Claude Opus 4.8 auto-compact never firing on Bedrock. Cadence framing the digest carries: five tags in seven days on the 2.1.21x line, and the mix has shifted — the last four were substrate-only; v2.1.217 adds the smallest possible user-facing feature (emoji autocomplete) while landing the concurrency cap and the budget-halt fix. The pattern is “substrate hardening with the occasional low-risk UX add,” not “features returning” — but the substrate window is no longer pure.

  • v2.1.217 — Concurrent-Subagent Cap + --max-budget-usd Halt Fix + Emoji Autocomplete + Session-Safety Fixes (July 21, 2026): Fifth tag in seven days on the 2.1.21x line and the first release since v2.1.216 to include a user-facing prompt-input feature. Load-bearing items: concurrent-subagent cap (default 20) via CLAUDE_CODE_MAX_CONCURRENT_SUBAGENTS (the concurrency dimension of the per-session cap of 200 that landed on Jul 17’s v2.1.212); subagents no longer spawn nested subagents by default (CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH opt-in); --max-budget-usd halts running background subagents on cap rather than only denying new spawns — the actual enforceable cost ceiling teams were reading it as. Emoji shortcode autocomplete (:heart: → ❤️, disable with emojiCompletionEnabled: false) is the first user-facing prompt-input UX add on the 2.1.21x line. Session-safety fixes: background-session symlink-canonicalization escape, Windows auto-update leaving claude.exe missing, Claude Opus 4.8 auto-compact never firing on Bedrock. Reads as hybrid — substrate hardening with the smallest possible user-facing feature — the substrate window is no longer pure but “features returning” would be the wrong read. Covered in 2026-07-22-AI-Digest.

  • 2026-07-23-AI-Digestv2.1.218 shipped 2026-07-22 21:24 UTC — the sixth tag in eight days on the 2.1.21x line and the first release since 2026-07-22-AI-Digest‘s v2.1.217 concurrent-subagent-cap tag to pair a workflow-shape change with the substrate work. The mix has shifted further off pure hardening: one background-subagent slash-command promotion, one accessibility class extension, and a raft of Windows/UX regressions closed. Four items worth flagging: (1) /code-review runs as a background subagent while stacked slash commands remain its review target — first slash-command-in-background pattern on the 2.1.21x line and a natural pairing with v2.1.217’s concurrency cap (the cap bounds the fan-out, the background promotion moves the review off the main thread). (2) Screen-reader announcements for deleted text (Option+Delete, Ctrl+W, Cmd+Backspace) in --ax-screen-reader mode — the accessibility surface keeps expanding one keybinding class at a time, three tags in a row have now touched --ax-screen-reader. (3) Windows path fix — \u-prefixed segments (e.g. C:\Users\unicorn) were being corrupted into CJK characters — Unicode-escape collision only surfacing on Windows-native workflows, explains a category of prior “path not found” reports. (4) Session-safety fixes — left-arrow-discards-conversation (no undo) and multi-line paste collapsing to a single line with j in place of newlines closed as two high-blast-radius input-layer regressions; HTTP status/error text now surfaces on claude mcp list and /mcp for failed servers. Cadence framing the digest carries: six tags in eight days; v2.1.217 added the concurrency cap, v2.1.218 uses it — the /code-review background promotion only makes sense with the cap in place, and the pair reads as a two-tag sequence rather than two independent releases. The substrate-with-occasional-UX-add pattern from Jul 22 is now substrate + one workflow-shape change per tag; input-layer regression fixes suggest the pre-flight testing surface has widened alongside the feature set.

  • v2.1.218 — /code-review as Background Subagent + --ax-screen-reader Deleted-Text Announcements + Windows \u-Path Corruption Fix + Session-Safety Fixes (July 23, 2026): Sixth tag in eight days on the 2.1.21x line and the first workflow-shape change since v2.1.217’s concurrency cap. /code-review becomes the first slash command in the 2.1.21x line to run as a background subagent — natural pairing with v2.1.217’s cap (the cap bounds the fan-out, background promotion moves the review off the main thread); read the pair as a two-tag sequence, not two independent releases. Accessibility surface: screen-reader announcements for Option+Delete / Ctrl+W / Cmd+Backspace deletions under --ax-screen-reader, third ax-screen-reader touch in a row. Windows-native: \u-prefixed path segments (e.g. C:\Users\unicorn) were being corrupted into CJK characters — Unicode-escape collision closed. Session-safety: left-arrow-discards-conversation no-undo behavior corrected, multi-line paste no longer collapses to a single line with j in place of newlines, HTTP status/error text now surfaces on claude mcp list / /mcp for failed servers instead of silent empty state. Cadence pattern the corpus should carry going forward: substrate + one workflow-shape change per tag, with input-layer regression fixes indicating the pre-flight testing surface has widened alongside the feature set. Covered in 2026-07-23-AI-Digest.

  • 2026-08-02-AI-DigestNo new tag since v2.1.220 (2026-07-25 01:35 UTC) — day 8, now past the outer edge of v2.1.x cadence variance the corpus has been tracking. Load-bearing surface remains v2.1.219 (Claude Opus 5 as default at 1M context, sandbox.network.strictAllowlist, DirectoryAdded hook, depth-3 nested-subagent forwarding, /fast mapped to Opus 5/4.8 with Claude Opus 4.7 dropped from fast). already-reported: 2026-08-01-AI-Digest. Cadence framing this note carries: the digest logs the day-8 gap alongside simultaneous quiet stretches at Beads (7 days on v1.1.2) and OpenSpec (4 days on v1.7.0) — the longest simultaneous silence of the v2.1.x series to date, but each repo’s individual cadence variance still admits it. Worth flagging, not worth narrating around. 7-day watch: whether Claude Code breaks the pause before the simultaneous-silence read hardens into a hold. Extends the 2026-07-31-AI-Digest six-day-gap note by two calendar days without a new tag.

  • 2026-08-04-AI-Digestv2.1.221 shipped 2026-08-04 00:14 UTC — day 10 of silence broken, and the longest quiet stretch of the v2.1.x series to date resolved rather than extended. Two load-bearing additions this cycle. (1) VSCode Focus view — a chat-menu toggle (Ctrl+Alt+F or “Toggle Focus view” command) that hides tool activity behind an expandable per-turn summary while a live running-tool indicator stays visible. First IDE-side chrome addition since the sandbox-network work in v2.1.219; targets the “wall of tool output” complaint that has recurred in the corpus since long-turn agent workflows became the default. (2) Sandbox credential mode: "mask" on Linux/WSL — sandboxed commands read a sentinel copy of a credential file (whole file, or regex-extract spans) while the sandbox proxy substitutes the real value on egress. macOS falls back to deny. Reads as a direct continuation of the sandbox.network.strictAllowlist posture in v2.1.219: same design principle (agent sees a working stand-in, real secret never enters the sandbox), applied one layer further down. Also fixed: Bash tool permission-check bypass in zsh double-bracket regex conditionals; PowerShell permission checks mishandling quote characters on Windows; thinking-toggle having no effect for the rest of a session after first toggle; --mcp-config servers not connecting before the first turn in -p print mode. Three of four are hardening fixes on surfaces the corpus has previously flagged as thin. Cadence framing the digest carries: v2.1.221 closes the outer variance band that 2026-08-03-AI-Digest flagged (mean interval ~3.6 days, p95 ~7 days) at day 10 — the longest quiet stretch of the v2.1.x series to date, resolved rather than extended. Beads at day 9 and OpenSpec at day 6 still sit inside their respective envelopes; the joint stall thesis from yesterday no longer holds, though the two independent quiet streaks continue.

  • v2.1.221 — VSCode Focus View + Linux/WSL Sandbox Credential mode: "mask" + Zsh Regex + PowerShell Quote Handling (August 4, 2026): v2.1.221 (2026-08-04 00:14 UTC) breaks the 10-day silence — longest quiet stretch of the v2.1.x series to date, resolved rather than extended. Two load-bearing additions. VSCode Focus view (Ctrl+Alt+F / “Toggle Focus view” command) hides tool activity behind an expandable per-turn summary while a live running-tool indicator stays visible — first IDE-side chrome addition since the v2.1.219 sandbox-network work, and targeted at the recurring “wall of tool output” complaint. Sandbox credential mode: "mask" on Linux/WSL — sandboxed commands read a sentinel copy of a credential file (whole file, or regex-extract spans) while the sandbox proxy substitutes the real value on egress; macOS falls back to deny. Direct continuation of the sandbox.network.strictAllowlist posture in v2.1.219 — same design principle (agent sees a working stand-in, real secret never enters the sandbox), one layer further down on the credential-hygiene axis. Fixes: zsh double-bracket regex conditional Bash permission-check bypass, Windows PowerShell quote-character permission handling, thinking-toggle no-op for rest-of-session after first toggle, --mcp-config servers not connecting before first turn in -p print mode — three of four are hardening on previously-thin surfaces. Cadence read: v2.1.221 resolves the day-10 outer-variance-band silence rather than extending it — the joint-stall thesis from 2026-08-03-AI-Digest does not carry into today; Beads and OpenSpec remain on independent quiet streaks. Covered in 2026-08-04-AI-Digest.

  • 2026-08-05-AI-Digestv2.1.222 shipped 2026-08-04 22:39 UTC — same-day follow-up to yesterday’s v2.1.221 (00:14 UTC), the second tag inside the same UTC day. Load-bearing changes: (1) Worktree-isolation hardening — worktree-isolated sessions and their subagents can no longer run destructive git commands against the main checkout; isolation now applies uniformly to file edits and Bash across every session type, tightening blast radius for teams running background-agent workflows in production. (2) PreToolUse auto-allow no longer bypasses tool restrictions in background agent tasks (summaries, compaction, renames) — SendMessage in auto mode now goes through the permission classifier before dispatch, closing a subtle path where auto-allow was silently escalating. (3) Refusal-behavior shift — Claude now asks the user to run a skill flagged disable-model-invocation rather than replicating its workflow; /diff and Remote Control diffs switched to raw git blob content (ignoring workspace diff drivers / textconv). (4) Removed: ultraplan feature. Also fixed: /usage over-attributing to MCP servers, org-restricted family aliases dropping to parent model instead of stepping down, HTTPS-proxy startup hang, stream idle timeout firing on custom ANTHROPIC_BASE_URL gateways despite keep-alive pings. Cadence framing the digest carries: after the 10-day quiet stretch through 2026-08-03-AI-Digest, Claude Code shipped v2.1.221 and v2.1.222 within the same UTC day — the second tag is a hotfix chain rather than a substantive feature drop, mirroring the same-day v1.1.1 → v1.1.2 pattern Beads used at end-of-July. Silence-then-double-drop is now a recurring release-cadence texture worth carrying forward as a v2.1.x observation.

  • v2.1.222 — Worktree-Isolation Hardening + PreToolUse Auto-Allow Restrictions + Ultraplan Removed (August 4, 2026): v2.1.222 (2026-08-04 22:39 UTC) is a same-day follow-up to v2.1.221 (00:14 UTC), the second tag inside the same UTC day. Worktree-isolated sessions and their subagents can no longer run destructive git commands against the main checkout — isolation now applies uniformly to file edits and Bash across every session type; tighter blast radius matters for teams running background-agent workflows in production. PreToolUse auto-allow no longer bypasses tool restrictions in background agent tasks (summaries, compaction, renames); SendMessage in auto mode now goes through the permission classifier before dispatch — closing a subtle path where auto-allow was silently escalating. Refusal-behavior shift: Claude asks the user to run a skill flagged disable-model-invocation rather than replicating its workflow. Removed: ultraplan feature. Also fixed: /usage over-attributing to MCP servers, org-restricted family aliases dropping to parent model instead of stepping down, HTTPS-proxy startup hang, stream idle timeout firing on custom ANTHROPIC_BASE_URL gateways despite keep-alive pings. Cadence read to carry: silence-then-double-drop as a recurring release-cadence texturev2.1.221 → v2.1.222 inside a UTC day mirrors the v1.1.1 → v1.1.2 pattern Beads used at end-of-July; after the 10-day quiet stretch that ran through 2026-08-03-AI-Digest, the second tag is a hotfix chain rather than a substantive feature drop. Covered in 2026-08-05-AI-Digest.

  • 2026-08-06-AI-Digestv2.1.223 shipped 2026-08-06 00:52 UTC — the third tag in three consecutive UTC days after the v2.1.221 → v2.1.222 chain from 2026-08-04-AI-Digest / 2026-08-05-AI-Digest. Load-bearing changes: (1) Third permission-bypass fix in three consecutive tags — Bash permission bypass via hidden commands is closed; permission prompts can no longer be hidden by tab or invisible-Unicode characters; agent-definition bypassPermissions no longer overrides org policy. Read as a trio: v2.1.221 sandbox credential mode → v2.1.222 worktree isolation → v2.1.223 hidden-command / invisible-Unicode / org-policy is a concentrated pass across every previously known auto-escalation surface. (2) Marketplace allowlist / blocklist gains owner wildcards ("owner/*") — closes a granularity gap in the plugin-trust boundary that v2.1.222’s tighter permission model exposed; restricted-subagent model requests now warn instead of silently coercing. (3) /teleport hint for continuing sessions locally (surfaced after cloud-session moves); /review becomes an alias of /code-review. Small workflow touches rather than new capability surface. Fixes: modelOverrides treating unknown keys as canonical IDs, gateway model discovery hiding Claude models with provider prefixes, forked background agents stuck in already resuming state, Linux sandboxed commands failing on write-denied cwd. Cadence framing the corpus carries: three tags in three consecutive UTC days on the auto-escalation surface — the silence-then-double-drop texture from 2026-08-05-AI-Digest extends to silence-then-triple-drop with the third tag arriving inside 24h of the second, and every one of the three tags carries at least one permission-bypass hardening item.

  • v2.1.223 — Third Permission-Bypass Fix in Three Consecutive Tags: Hidden Commands, Invisible-Unicode, Agent-Definition bypassPermissions vs Org Policy (August 6, 2026): v2.1.223 (2026-08-06 00:52 UTC) is the third tag in three consecutive UTC days after v2.1.221 → v2.1.222. The permission-bypass hardening pattern the corpus should carry: v2.1.221 sandbox credential mode: "mask" → v2.1.222 worktree-isolation + PreToolUse auto-allow → v2.1.223 hidden-command / invisible-Unicode / agent-definition bypassPermissions vs org policy is a concentrated audit pass across every previously known auto-escalation surface, all three tags landing inside three UTC days. Marketplace allowlist / blocklist gains owner wildcards ("owner/*"), closing a granularity gap in the plugin-trust boundary that v2.1.222’s tighter permission model exposed; restricted-subagent model requests now warn instead of silently coercing. Small workflow touches: /teleport hint for continuing sessions locally after cloud-session moves; /review becomes an alias of /code-review. Fixes: modelOverrides unknown-key handling, gateway model discovery hiding Claude models with provider prefixes, forked background agents stuck in already resuming, Linux sandboxed commands failing on write-denied cwd. Cadence read: the silence-then-double-drop pattern from v2.1.221 → v2.1.222 extends to silence-then-triple-drop with v2.1.223 — after the 10-day silence flagged through 2026-08-03-AI-Digest, three tags landed in three consecutive UTC days, every one carrying at least one permission-bypass hardening item. Covered in 2026-08-06-AI-Digest.

  • 2026-08-07-AI-Digestv2.1.224 shipped 2026-08-07 — the fourth tag in four consecutive UTC days after the v2.1.221 → v2.1.222 → v2.1.223 permission-bypass chain from 2026-08-04-AI-Digest / 2026-08-05-AI-Digest / 2026-08-06-AI-Digest. The shape of the release is different from the prior three. Multi-session primitives ship: new SendMessage tool for cross-session messaging between agents (local sessions, cloud sessions, and Remote Control bridge sessions); new ListAgents tool for enumerating messageable agents by name. Pairs cleanly with the removal of the 200-subagent spawn cap — the primitive layer for multi-session and multi-agent orchestration is now in place rather than emulated. Self-hosted environments for Team and Enterprise plans, plus an archive plugin source that installs plugins from .zip files over HTTPS — broadens the deployment surface for regulated or air-gapped teams that couldn’t route through the marketplace. Sandbox credential-masking hardening continues at a different layer: JWT-aware masking of specific claims, AWS SigV4 request re-signing after mutation, plus a fix for Linux/macOS filesystem-deny entries being bypassable through certain path constructions — continuation of the sandbox-credential-mode thread v2.1.221 opened, not a fresh permission-bypass fix. Fixes: long project paths (>200 chars) resolving to wrong session directories; restricted-subagent model requests warning instead of silently coercing (partial continuation of v2.1.223); several minor UI and error-message touches. Narrow read the digest carries: the framing to soften is “permission-bypass audit continues into a fourth consecutive day.” The audit surface v2.1.221 → v2.1.223 was concentrated on ended with hidden-command / invisible-Unicode / org-policy on Aug 6; v2.1.224’s primary story is a new capability surface (multi-session messaging, self-hosted environments), not another bypass fix. Structural read worth carrying: the pivot from bypass-audit to session-primitive shipping suggests the concentrated audit pass is complete for now — the multi-session/SendMessage layer is the shape of the next quarter’s work, not another hardening tag.

  • v2.1.224 — Pivot From Bypass-Audit to Session Primitives: SendMessage + ListAgents + Self-Hosted Environments + Archive Plugin Source + JWT-Aware Masking + AWS SigV4 Re-signing (August 7, 2026): v2.1.224 (2026-08-07) is the fourth tag in four consecutive UTC days after the v2.1.221 → v2.1.222 → v2.1.223 permission-bypass chain — and the shape of the release is materially different from the prior three. Load-bearing items: SendMessage cross-session messaging tool (local sessions, cloud sessions, Remote Control bridge sessions) + ListAgents session-discovery tool — pairs with the removal of the 200-subagent spawn cap so the multi-session/multi-agent orchestration primitive layer is now first-class rather than emulated. Self-hosted environments for Team and Enterprise plans + archive plugin source installing plugins from .zip files over HTTPS — broadens the deployment surface for regulated or air-gapped teams that couldn’t route through the marketplace. JWT-aware credential masking of specific claims + AWS SigV4 request re-signing after mutation + Linux/macOS filesystem-deny path-construction bypass fix — sandbox credential-masking hardening at a different layer, continuing the v2.1.221 sandbox-mode thread rather than the v2.1.223 prompt-hiding thread. Fixes: long project paths (>200 chars) resolving to wrong session directories; restricted-subagent model requests warning instead of silently coercing (partial continuation of v2.1.223); minor UI and error-message touches. Structural read the corpus should carry: the pivot from bypass-audit to session-primitive shipping suggests the concentrated audit pass v2.1.221 → v2.1.223 is complete for now — the multi-session / SendMessage layer is the shape of the next quarter’s work, not another hardening tag. Covered in 2026-08-07-AI-Digest.

  • 2026-08-08-AI-DigestTwo tags today, both new since the v2.1.224 coverage in 2026-08-07-AI-Digest. v2.1.225 shipped 2026-08-08 01:09 UTC — the substantive tag, continuing the session-primitive pivot v2.1.224 opened. Load-bearing items: cross-session SendMessage extended to Remote Control by name (can now start conversations with Remote Control sessions on other machines by name, no longer requires the remote to message the local session first); ListAgents enumerates them with name [ref] disambiguation when two rows share a name — direct follow-on to the multi-session primitives shipped in v2.1.224, connectivity fabric is now bidirectional across machines, not initiate-once. Gateway spend-limit surfacing — Claude Code’s usage-limit warning now names the operator’s cap, reset time, and message when a gateway spend limit trips (requires the gateway on v2.1.225+); continues the Team / Enterprise deployment-surface work v2.1.224 opened for self-hosted environments. Workspace-trust prompt added to claude agents — untrusted-directory prompt now matches the claude entry point, closes a trust-boundary gap between the two that the multi-session work opened up. Fixes worth flagging: transient 401 when replacing a long-lived CLAUDE_CODE_OAUTH_TOKEN with a login token; MCP OAuth servers on macOS bursting 401s after keychain timeouts; auto mode no longer counting safety-filter refusals of its own permission-check against the consecutive-block limit; conversation-history corruption on Remote Control session resume after large-conversation compaction. v2.1.226 shipped 2026-08-08 02:48 UTC — body reads only “Bug fixes and reliability improvements”, a follow-up patch on v2.1.225 roughly 90 minutes after the substantive tag. No functional detail disclosed. Narrow read: neither tag is a bypass fix — the audit chain covered through v2.1.223 is closed and v2.1.224 opened the session-primitive shipping pass; v2.1.225 extends the multi-session fabric to be bidirectional and lands the operator-surface polish the deployment pivot needs. Structural read worth carrying: the shape is now visible — v2.1.221v2.1.223 was the concentrated hardening pass, v2.1.224v2.1.226 (three consecutive UTC days again) is the deployment-and-operator-surface pass. Two multi-day tag chains with distinct themes suggests a deliberate serialisation, not a fire-drill cadence.

  • 2026-08-09-AI-DigestNo new tag Aug 8–9. Newest tag remains v2.1.226 (2026-08-08 02:48 UTC, “Bug fixes and reliability improvements”) — the follow-up patch on v2.1.225, already covered in 2026-08-08-AI-Digest. The load-bearing move for Claude Code this weekend is not a release tag but the Aug 14 Auto Mode default-on rollout confirmed by Anthropic on Aug 8: Auto Mode flips to the default for Pro / Max / Team subscriptions from Aug 14; Enterprise stays opt-in; API / cloud rollout planned “within the next month.” Vendor-cited numbers: 89% classifier catch vs 13.6% human on dangerous shell commands (1,053-tester Anthropic study), ~25% more PRs completed by Auto Mode users, and independent Trajectory Labs audit reports 0/720 successful prompt-injection attacks across Claude Fable 5 / Claude Opus 5 / Claude Sonnet 5 with Auto Mode engaged (vs 5.83% baseline against pre-classifier GPT-5.6 Sol). The corpus framing to carry: the classifier-not-approval-gate design axis for Claude Code just got a load-bearing datum from the vendor itself — Auto Mode as the shipped default is the first observable instance of a frontier lab replacing the human-in-the-loop permission prompt with a classifier at the default level rather than as an opt-in beta. 30 / 60 / 90-day watch: whether Trajectory Labs’ 720-attack methodology gets published for independent replication; whether Enterprise opt-in shifts once tenant admins see Pro / Max / Team incident distribution; whether the API tier’s rollout preserves the same classifier posture or ships with a weaker default.

  • v2.1.225 / v2.1.226 — Bidirectional Cross-Machine SendMessage + Gateway Spend-Limit Surfacing + Workspace-Trust Prompt on claude agents + OAuth/Keychain Fixes + Same-Day Reliability Patch (August 8, 2026): v2.1.225 (2026-08-08 01:09 UTC) extends SendMessage to start conversations with Remote Control sessions on other machines by name via ListAgents — the multi-session fabric is now bidirectional across machines, not initiate-once. Gateway spend-limit surfacing names operator cap / reset time / message when a gateway spend limit trips (requires the gateway on v2.1.225+). Workspace-trust prompt on claude agents matches the claude entry point, closing a trust-boundary gap the multi-session work opened. Fixes: CLAUDE_CODE_OAUTH_TOKEN 401s; macOS MCP OAuth keychain 401 bursts; auto-mode safety-filter refusals no longer counted against consecutive-block limit; conversation-history corruption on Remote Control session resume after large-conversation compaction. v2.1.226 (02:48 UTC) is a same-day follow-up patch — “Bug fixes and reliability improvements”, no detail disclosed. Cadence read to carry: two multi-day tag chains with distinct themes — v2.1.221 → v2.1.223 concentrated hardening pass, v2.1.224 → v2.1.226 deployment-and-operator-surface pass — suggests deliberate serialisation, not fire-drill cadence. Covered in 2026-08-08-AI-Digest.

  • 2026-08-11-AI-Digestv2.1.227 shipped 2026-08-10 22:56 UTC — new since prior digest. Bug-fix-shaped tag rather than a features drop: fixes feature-flag evaluation for expired login tokens (affected Max-plan users) and 401 errors on /tui conversation rewinding; fixes Bash-command failures under claude-code-action when allowed_non_write_users is set — a workflow-configuration edge case surfaced by GitHub-Actions runners. Slash-command menu restyled (blue selection state, bolded match spans); perf improvements on file-not-found suggestions and at-mention checks. Follow-up patch to v2.1.226 (bug-fix-only, 2026-08-08 02:48 UTC) and v2.1.225 (2026-08-08 01:09 UTC, which shipped gateway spend-limit support, workspace-trust prompt for claude agents, and SendMessage cross-session agent-name discovery — those two already-reported: 2026-08-08-AI-Digest and 2026-08-10-AI-Digest). Cadence framing this note carries: maintenance beat continuing the deployment-and-operator-surface pass shape from v2.1.224 → v2.1.226, not a fresh feature slice. Sits alongside the standing Auto Mode default-on flip for Pro / Max / Team on Aug 14 as the operational context for the tag — token-refresh and login-token edge cases are exactly the surfaces Auto Mode’s classifier-not-approval-gate default will exercise at higher volume.

  • v2.1.227 — Expired-Token Feature-Flag Evaluation + /tui Rewinding 401 + Bash allowed_non_write_users Under claude-code-action + Slash-Command Menu Restyle (August 10, 2026): v2.1.227 (2026-08-10 22:56 UTC) is a bug-fix-shaped tag rather than a features drop, following v2.1.226 (2026-08-08 02:48 UTC) and v2.1.225 (2026-08-08 01:09 UTC) with a three-tag chain that mirrors the earlier silence-then-double / triple-drop cadence texture. Load-bearing fixes: feature-flag evaluation for expired login tokens on Max-plan users, /tui conversation-rewinding 401 errors, and claude-code-action Bash-command failures when allowed_non_write_users is set — a workflow-configuration edge case surfaced by GitHub-Actions runners. Slash-command menu restyled (blue selection state, bolded match spans); perf improvements on file-not-found suggestions and at-mention checks. Cadence read to carry: maintenance beat continuing the deployment-and-operator-surface pass shape from v2.1.224 → v2.1.226, not a fresh feature slice — the tag lands in the operational window before Auto Mode default-on flips for Pro / Max / Team on Aug 14, exactly the surface where token-refresh and login-token edge cases matter most. Covered in 2026-08-11-AI-Digest.

  • 2026-08-12-AI-Digestv2.1.228 shipped 2026-08-11 — new since prior digest. Substantive fixes: Windows Git / Git Bash detection when Claude Code is launched from the parent of the Git install directory; /tui reverting to an earlier model after a mid-session /model change; Remote Control /resume leaking conversation title and history into a connected session; session-cleanup deleting contents inside a project’s memory folder. Hardens skills synced from claude.ai — they no longer shadow local commands / MCP prompts, and descriptions are sanitised on ingest. Vertex AI credential handling: expired or missing credentials now fail within seconds instead of retrying for minutes; compaction shows a retry countdown and stall hints. Behaviour change: the Write tool now lets newer models overwrite existing files without a prior Read, matching the Edit tool’s rule — the load-bearing shape change in the tag, closing a friction seam Auto Mode exercised repeatedly in testing. Prior digest coverage of v2.1.227 (already-reported: 2026-08-11-AI-Digest) still applies for the fixes that landed last night. Cadence framing this note carries: v2.1.228 lands the day before Aug 14 Auto Mode default-on for Pro / Max / Team — the Write-tool matching-Edit rule and the Remote Control / session-cleanup fixes are exactly the surfaces the classifier-not-approval-gate default will exercise at higher volume.

  • v2.1.228 — Windows Git-Bash Parent-Directory Detection + Skills-From-Claude.ai Shadow-Guard + Vertex AI Credential Fast-Fail + Write Tool Now Matches Edit Rule (No Prior Read Required for Newer Models) (August 11, 2026): v2.1.228 (2026-08-11) is a maintenance tag that ships one load-bearing behaviour change alongside a bundle of session-integrity fixes. The Write tool now lets newer models overwrite existing files without a prior Read, matching the Edit tool’s rule — closes a friction seam Auto Mode exercised repeatedly in testing and sits directly on the Pro / Max / Team Aug 14 cutover clock. Session-integrity fixes: Windows Git / Git Bash detection when Claude Code launches from the parent of the Git install directory; /tui reverting to an earlier model after a mid-session /model change; Remote Control /resume leaking conversation title and history into a connected session; session-cleanup deleting contents inside a project’s memory folder. Skills synced from claude.ai no longer shadow local commands / MCP prompts, and descriptions are sanitised on ingest — hardening on the claude.ai-to-Code sync trust boundary. Vertex AI credential handling: expired or missing credentials now fail within seconds instead of retrying for minutes; compaction shows a retry countdown and stall hints. Cadence read to carry: third consecutive tag on the pre-Auto-Mode-default-on operational-hardening window (v2.1.226v2.1.227v2.1.228) — the Write-tool rule change is the shape-defining item, the rest is session-integrity + credential-fast-fail continuing the deployment-and-operator-surface pass. Covered in 2026-08-12-AI-Digest.

  • 2026-08-15-AI-Digestv2.1.233 (2026-08-14) ships four load-bearing items (release notes). (1) GitLab merge-request URLs now work with the --worktree flag and inside the claude agents view — completes the GitLab parity push started in v2.1.232. (2) Opt-in memory cgroup for Bash-tool commands on Linux — caps runaway builds inside a hard memory limit rather than trusting the underlying shell to bail. (3) Windows path-validation bypass fix — NT \??\ device prefixes were slipping past the UNC check; closed. (4) Bundled-skill aliases were reporting “Unknown command” in -p mode when plugins/MCP loaded — fixed. Separately, Anthropic published the first hard merge-rate on Claude Code running unsupervised against its own repos — 388 PRs opened over several weeks, 180 merged (46%) across scaffolded maintenance routines (crash detection, dead-code removal, dependency hygiene) triggered from a Slack channel via natural-language prompts. Boris Cherny frames the result as “early signs of life” rather than a productivity claim. Narrow read the digest carries: 46% is a merge rate on scaffolded maintenance PRs, not autonomous feature work — the 54% rejection rate is the more useful number for sizing babysitting overhead. Structural read: first data point that lets the corpus calibrate the delta between “lab that ships Claude Code” and “lab that uses Claude Code in anger against its own commit history” — frame the 46% as the ceiling on how confidently a top-tier lab lets its own agent touch its own repo, not the ceiling on enterprise deployments.

  • v2.1.233 — GitLab MR URLs + Linux Memory cgroup for Bash + Windows NT Device-Prefix Path-Validation Fix + Bundled-Skill Alias -p Mode Fix; Paired With Anthropic’s First Public Repo-Merge-Rate Datapoint (46% Across 388 PRs) (August 14, 2026): v2.1.233 completes the GitLab parity push (--worktree + claude agents view now accept GitLab MR URLs) started in v2.1.232; opt-in Linux memory cgroup caps runaway build memory as a substrate primitive rather than relying on the shell; NT \??\ device-prefix Windows path-validation bypass fix is a real security hardening item; -p mode bundled-skill alias “Unknown command” regression closed. Load-bearing paired framing to carry: Anthropic published 388 PRs / 180 merged (46%) on scaffolded maintenance routines against its own repo — the first frontier-lab published merge-rate against production code over a multi-week window. Corpus framing: frame the 46% as the ceiling on how confidently a top-tier lab lets its own agent touch its own repo, not the ceiling on what enterprise buyers should expect — the 54% rejection rate is the more useful number for babysitting-overhead sizing. Reads directly against the v2.1.221 → v2.1.228 operator-hardening chain and the 2026-08-09-AI-Digest Auto Mode default-on flip as the second-order justification for the substrate-hardening pass — the vendor is telegraphing what its own agent can and can’t do on real production code. Covered in 2026-08-15-AI-Digest.

  • 2026-08-16-AI-DigestNo new tag Aug 15–16. Newest tag remains v2.1.233 (2026-08-14) — the GitLab MR URL parity + Linux memory cgroup + NT \??\ device-prefix + -p mode bundled-skill-alias tag already covered in 2026-08-15-AI-Digest (already-reported). The load-bearing move for Claude Code today is the Aug 14 Auto Mode default-on flip landing as scheduled on Pro / Max / Team plans — Enterprise, API, and cloud-partner deployments excluded from the default flip. Vendor-reported numbers: 89% catch rate on dangerous commands under Auto Mode vs 13.6% under the prior manual defaults, +25% reported PR throughput on internal benchmarks. Narrow read the digest carries: harness-layer default swap — permissions, injection screens, deny rules — with no model swap underneath; read the 89% number as how well the harness catches the class of commands Anthropic has curated deny lists for, not a general safety benchmark. Structural read: stitch with today’s DarwinX paper (WebArena-Infinity 43.5% → 93.0% via harness evolution with a frozen model) and this month’s harness-side product cluster (Auto Mode, Codex tool-use defaults, DeepSeek Harness open-source drop from 2026-08-14-AI-Digest) — near-term agent-quality gains are landing at the harness layer, not the weights layer. Cadence framing: nine days since the last Claude Code release (v2.1.233), consistent with the recent cluster-then-quiet shape — read the silence as maintenance mode, not stall. 30 / 60 / 90-day watch: whether OpenAI and Google Cloud follow with symmetric default flips on their coding-agent surfaces; whether the 89% number holds up in independent third-party red-teams; whether Enterprise tier gets a nudge toward an equivalent default within the next quarter.

  • 2026-08-18-AI-Digestv2.1.234 (2026-08-17, ~20:20 UTC) ships as the first fresh Claude Code release since v2.1.233 on Aug 14 — closing the nine-day gap flagged in 2026-08-16-AI-Digest (release notes). Load-bearing items: (1) new CLAUDE_CODE_PROJECT_DIR_NAME env var lets each project pin its own transcript directory name — resolves the multi-clone collision case where two working copies of the same repo tried to share transcripts; (2) new selection:clear keybinding action; (3) sessions auto-continue when API usage limits reset, so long-running agents survive a rate-limit window without operator poke; (4) GitLab MR badge added to the footer / statusline — extends the v2.1.232/233 GitLab wiring toward parity with the GitHub PR presentation; (5) Windows NT-namespace path rejection tightened again (belt-and-suspenders on top of the v2.1.233 \??\ fix); (6) additional credential-leak protection layered on the v2.1.232/233 GitLab-token redaction line. Plus assorted UI-rendering and permission-handling fixes. Cadence read: single-tag day that resumes the release line rather than starting a new hardening chain; the auto-continue on rate-limit reset is the shape-defining new capability alongside the transcript-collision env var.

  • 2026-08-22-AI-Digestv2.1.239 (2026-08-21 ~19:54 UTC) — fifth consecutive daily tag (v2.1.235 → v2.1.239) (release notes). Today’s mix is cost-transparency + fullscreen coverage extension + SDK-migration automation. Load-bearing items: (1) **1.1× US-only-inference premium surfaced directly in per-request cost estimates**, rather than aggregated at invoice time — first visible pricing knob to appear inside the tool's own cost surface since [[Auto Mode]] shipped as default in [[2026-08-16-AI-Digest]]. Enterprise deployers routing sensitive workloads through Anthropic's US-only compute pool for compliance now see the differential in-context. **(2)** **Fullscreen renderer extended to AWS Bedrock, Google Vertex, and Azure Foundry** — closes a two-tier UX where gateway-brokered sessions dropped to the classic renderer; small parity win but meaningful for enterprises whose procurement path forces gateway routing. **(3)** **/claude-api upgradecommand** — in-project migration helper that walks a codebase through the **Anthropic Python SDK0.x1.x** upgrade; same shape as [[OpenSpec]]'s codemod tooling — codified migration paths as first-class SDK affordances — and the first time the CLI ships an SDK-version migration surface for its own client library. **(4)** **Alpine/musl native-addon support** — native add-ons now build against musllibc, so the CLI runs on Alpine Linux and othermusl-based container distros without the glibc-only shim; plus correctness passes on streaming, MCP-server elicitation, fullscreen fallback, and cross-session SendMessage` back-pressure. Cadence read: five Claude Code drops in five days; the v2.1.235 → v2.1.239 arc has now shipped through developer-UX polish, enterprise/self-hosted plumbing, and — with today’s US-only premium disclosure — the first visible pricing surface change.

  • v2.1.239 — 1.1× US-Only-Inference Premium in Cost Estimates + Fullscreen Renderer Extended to Bedrock/Vertex/Foundry + /claude-api upgrade SDK Migration Command + Alpine/musl Native-Addon Support (August 21, 2026): v2.1.239 (2026-08-21 ~19:54 UTC) is the fifth daily Claude Code tag in a row, closing out the v2.1.235 → v2.1.239 arc. Load-bearing items: 1.1× US-only-inference premium now visible directly in per-request cost estimates (first visible pricing knob inside the tool’s own cost surface since Auto Mode shipped as default); fullscreen renderer extended to AWS Bedrock / Google Vertex / Azure Foundry (closes the two-tier gateway-vs-first-party UX); /claude-api upgrade command for Anthropic Python SDK 0.x1.x migrations (first CLI-shipped SDK-version migration surface for its own client library, same shape as OpenSpec codemod tooling); Alpine/musl native-addon support removes the glibc-only shim for container-native deployments. Plus correctness passes on streaming, MCP-server elicitation, fullscreen fallback, cross-session SendMessage back-pressure. Cadence read to carry: five consecutive daily tags in the v2.1.235 → v2.1.239 arc through UX polish + enterprise/self-hosted plumbing + first visible pricing-surface change — the fullscreen-to-Bedrock/Vertex/Foundry extension in particular closes a two-tier gateway-vs-first-party experience carried since v2.0. Covered in 2026-08-22-AI-Digest.

  • 2026-08-23-AI-Digestv2.1.241 (2026-08-23 ~00:52 UTC) — sixth consecutive daily drop in the v2.1.235 → v2.1.241 arc, but the first with no disclosed feature surface (release notes). Release body reads exactly “Bug fixes and reliability improvements.” Companion release v2.1.240 (2026-08-22 ~14:45 UTC) (release notes) — same body, same shape. Cadence framing the digest carries: v2.1.235 → v2.1.239 shipped substantive plumbing every day (Auto Mode default, US-only-inference cost surfacing, fullscreen renderer to Bedrock/Vertex/Foundry, Alpine/musl support, SDK-migration automation); two consecutive bug-fix-only drops is the first pause in the feature stream since it opened. Whether this is a stabilisation pause before a larger beat or a genuine end-of-cycle sag is not decidable from two data points. The digest’s disciplined framing: treating the two shapes as equivalent would flatten the signal — the “daily-with-a-feature” reading of this week’s cadence is retired for now; the next release either restores the feature stream (reframing v2.1.240–241 as stabilisation) or extends the bug-only pattern into a plateau.

  • v2.1.240 / v2.1.241 — Two Consecutive Bug-Fix-Only Drops Break the v2.1.235 → v2.1.239 Feature Cadence (August 22–23, 2026): v2.1.240 (2026-08-22 ~14:45 UTC) and v2.1.241 (2026-08-23 ~00:52 UTC) both ship as “Bug fixes and reliability improvements” — the first pause in the v2.1.235 → v2.1.239 daily-with-a-feature stream since it opened. Load-bearing framing to carry: not decidable from two data points whether this is a stabilisation pause or an end-of-cycle sag — the next release either restores the feature cadence and reframes v2.1.240–241 as stabilisation, or extends the plateau. Do NOT flatten “two bug-fix drops in a row” into the same shape as the prior five-day feature stream. Covered in 2026-08-23-AI-Digest.

  • 2026-08-24-AI-Digestv2.1.241 remains the latest tag (2026-08-23 ~00:52 UTC, already-reported: 2026-08-23-AI-Digest) — no new tag in the ~36 hours since; the v2.1.235 → v2.1.241 arc’s two-consecutive-bug-fix-only-drops break (v2.1.240 / v2.1.241 both “Bug fixes and reliability improvements”) extends by one more beat without resolving. Narrow read the digest carries: do not read “no release today” as “release stream stalled” — the cadence itself has been the story for six days, and a third undocumented drop or the next feature-carrying release is the disambiguating signal. Structural read: the plateau extends but is not yet decidable between stabilisation pause and feature-cycle sag.

  • 2026-08-25-AI-Digestv2.1.245 (2026-08-25) ships as a targeted glibc 2.44 startup-crash hotfix (release notes) — third undocumented drop in the v2.1.235 → v2.1.245 arc but the first with a specific named fix: “Fixed a crash on startup on Linux distributions that ship glibc 2.44” (Arch Linux, CachyOS, Fedora Rawhide). Narrow read the digest carries: hotfix, not a feature drop — the release body disambiguates yesterday’s plateau frame in exactly one direction: plateau is now a triage cadence, with the team pulling forward a targeted distro-compat hotfix rather than continuing to batch changes into anonymous “reliability” tags. Structural read: the disambiguation is thin but real — what yesterday’s Digest flagged as “undecided on one additional day of data” now has a concrete data point (v2.1.245 is a scheduled interrupt for a downstream toolchain issue, not the next feature release); Anthropic is willing to break its own cadence to unblock a specific Linux population. The next feature-carrying tag remains the disambiguating signal for whether the feature stream itself has stalled.

  • v2.1.245 — glibc 2.44 Startup-Crash Hotfix on Arch / CachyOS / Fedora Rawhide (August 25, 2026): v2.1.245 (2026-08-25) is the third undocumented drop in the v2.1.235 → v2.1.245 arc — but the first with a specific named fix in the release body. Load-bearing item: “Fixed a crash on startup on Linux distributions that ship glibc 2.44” (Arch Linux, CachyOS, Fedora Rawhide) — a hotfix for a distinct downstream Linux population, not a feature drop. Cadence read to carry: plateau is now a triage cadence, not a feature freeze — Anthropic broke its own batching cadence to unblock a specific downstream toolchain issue rather than continue anonymous “reliability” tags. The next feature-carrying tag remains the disambiguating signal for whether the feature stream itself has stalled; do NOT upgrade today’s hotfix to “cadence resumed.” Covered in 2026-08-25-AI-Digest.

  • 2026-08-26-AI-Digestv2.1.246 (2026-08-25 22:31 UTC) ships ~17 hours after the v2.1.245 glibc 2.44 hotfix as a substantive feature drop that falsifies yesterday’s “plateau is a triage cadence” reading in exactly one direction — the feature stream is very much alive (release notes). Named features: Auto mode tab in /permissions for viewing / editing classifier rules from the UI rather than only via config file; a startup warning for wildcard-before-subcommand Bash allow rules such as Bash(git * main) — a footgun that had silently over-broad-allowlisted whole tool categories; and a turn-completion clock stamped onto the end-of-turn duration line. Reliability surface dense: background sessions failing to open after 45s on deleted starting dir / slow host, auto-mode denials on very large sessions (safety-check deadline now scales with prompt size), subagent restart on ← / /background, Write-tool “Out of memory” after overwriting huge files, memory growth in fullscreen / Ctrl+O transcript views. MCP surface hardened: tool arguments no longer sent as JSON strings when the tool schema is {}, interrupted MCP calls in headless mode reported as interrupted rather than “completed with no output”, telemetry no longer leaks a third-party gateway API key to Anthropic hosts, resumed sessions carrying API-incompatible tool blocks no longer 400 every turn. The single line that matters most for scheduled routines: -p, SDK and cloud sessions now auto-continue responses cut off mid-stream by server error, connection loss, or stall — a real reliability lift for the exact headless-run pattern the digest itself is generated by. Cadence read the digest carries: v2.1.240 / .241 were staging, not stall — the team is now shipping targeted triage hotfixes AND substantive feature drops inside the same 24-hour window; do NOT re-run the “release cadence is stalled” beat.

  • v2.1.246 — Auto Mode Tab in /permissions + Wildcard-Bash Allow-Rule Startup Warning + Turn-Completion Clock + SDK/Cloud Stream Auto-Continue on Mid-Stream Server Error + MCP JSON-String / Empty-Schema Fix (August 25, 2026): v2.1.246 (2026-08-25 22:31 UTC) is the fourth tag in the v2.1.235 → v2.1.246 arc since the plateau opened, and the first with a real feature payload since v2.1.239. Load-bearing items: Auto mode tab in /permissions promotes classifier-rule editing from config-file-only to a first-class UI surface (direct extension of the Auto Mode default-on flip from 2026-08-16-AI-Digest); startup warning for wildcard-before-subcommand Bash allow rules closes a silent over-broad-allowlisting footgun; SDK / cloud stream auto-continue after mid-stream server error is the reliability item most load-bearing for scheduled routines and headless-run patterns. Reliability surface (dense): background-session start on deleted starting dir / slow host, safety-check deadline scaling with prompt size on very large sessions, subagent restart on ← / /background, Write-tool “Out of memory” on huge-file overwrite, fullscreen / Ctrl+O transcript memory growth. MCP: tool arguments no longer sent as JSON strings when schema is {}, interrupted headless MCP calls reported as interrupted, telemetry gateway-API-key leak to Anthropic hosts closed, resumed sessions with API-incompatible tool blocks no longer 400 every turn. Cadence read to carry: v2.1.240 / .241 were staging, not stall — the team is now shipping targeted triage hotfixes (v2.1.245 glibc) AND substantive feature drops (v2.1.246) inside the same 24-hour window; the corpus should retire the “release cadence is stalled” beat and pick up the mixed hotfix-and-feature rhythm as the new v2.1.24x-line cadence texture. Covered in 2026-08-26-AI-Digest.

  • 2026-08-27-AI-Digestv2.1.247 (2026-08-26 23:06 UTC) ships ~24 hours after v2.1.246 and extends yesterday’s feature drop rather than course-correcting it — a third consecutive day of mixed hotfix-and-feature commits, not another anonymous “reliability” placeholder (release notes). Load-bearing items: SendFeedback tool wires the /feedback command to a structured feedback draft — the CLI is no longer the last uninstrumented surface in the workflow; /claude-api cost-optimize profiles Anthropic API spend against the loaded skill’s recommendations, and the same skill extension now covers the Admin API surface (org members, invites, workspaces, API keys). Fixes for fast arrow-key + Enter sequences (history search, /config, /mcp, /skills, /model) and Bash sandbox handling of dotfile-managed symlinks (nix / home-manager / stow) — the two multi-day irritants that scheduled routines have quietly been eating around. Narrow read the digest carries: patch releases at this project’s velocity are the baseline — the interesting frame is not “cadence alive”; it is that the /claude-api skill is quietly absorbing the Admin API surface, and that is the first time a shipped skill has crossed from developer-facing into ops-facing territory in one release. Structural read: v2.1.245 → v2.1.246 → v2.1.247 is the first three-consecutive-day mixed-hotfix-and-feature streak in the v2.1.24x line, confirming the 2026-08-26-AI-Digest “mixed inside 24h, not batching pause” cadence texture as a recurring rhythm rather than a one-off; the corpus should retire the plateau framing entirely.

  • v2.1.247 — SendFeedback Tool + /claude-api cost-optimize + /claude-api Skill Extended Onto the Admin API Surface + Fast-Arrow-Key / Enter Sequence Fixes + Bash Sandbox Handling for Dotfile-Managed Symlinks (August 26, 2026): v2.1.247 (2026-08-26 23:06 UTC) is the third consecutive daily tag in the v2.1.245 → v2.1.247 arc and the second substantive feature drop in that arc after v2.1.246. Load-bearing items: SendFeedback tool wires /feedback into a structured draft (the CLI stops being the last uninstrumented surface); /claude-api cost-optimize profiles Anthropic API spend against loaded-skill recommendations; the /claude-api skill extension now covers the Admin API surface (org members, invites, workspaces, API keys) — first time a shipped Claude Code skill has crossed from developer-facing into ops-facing territory in one release. Fixes: fast arrow-key + Enter sequences (history search, /config, /mcp, /skills, /model) and Bash sandbox handling of dotfile-managed symlinks (nix / home-manager / stow) — two multi-day irritants scheduled routines have been eating around. Cadence read to carry: third consecutive day of mixed hotfix-and-feature commits in the v2.1.24x line — the corpus should retire the “release cadence is stalled” plateau framing entirely and pick up the mixed-hotfix-and-feature rhythm as the durable texture for this line. Covered in 2026-08-27-AI-Digest.

  • 2026-08-28-AI-Digestv2.1.250 (2026-08-28 00:49 UTC) — bug-fix / reliability release only, no user-visible feature commits (release notes). Fourth patch in five days after v2.1.247 → v2.1.248 (2026-08-27-AI-Digest) and v2.1.246 (2026-08-26-AI-Digest); today’s release pauses the feature cadence rather than extending it — first “reliability-only” tag since the plateau broke on the 26th. Cadence framing the digest carries: 4 tags in 5 days is still well above the pre-plateau baseline; a single reliability tag doesn’t falsify the “cadence alive” reading, but a second one in a row would. Same day: Claude Code Auto Mode surfaces as the shipped-and-exploitable substrate in Simon Willison‘s writeup of Johann Rehberger’s prompt-injection attack against Claude Code Opus 5 auto mode — 80% success rate via a Python struct.py shim in a zip file, with the paradox that Claude detects the compromise but Auto Mode blocks the cleanup command. Narrow read: 80% is Rehberger’s own attack-attempt success rate, not an independent replication; the paradox — detect-but-block-cleanup — is the load-bearing detail. Structural read: the digest’s Key Takeaways frame this as the shipped-and-exploitable half of a bimodal agent-security surface — the 100+ firms cyber-defence letter frames critical-infrastructure threats as imminent, but the Rehberger exploit is the current developer-workstation-agent-tooling surface where the vulnerability actually ships. Log against MOC - Developer Tools, MOC - Agent Security, and MOC - Agentic Coding. 30 / 60 / 90-day watch: whether the next tag (v2.1.251+) restores the mixed-hotfix-and-feature cadence or extends the reliability-only pause; whether Anthropic ships a targeted fix for the detect-but-block-cleanup paradox Rehberger surfaced; whether Auto Mode’s classifier evolves to unblock cleanup actions on detected compromise events.

  • v2.1.250 — Reliability-Only Tag, First Since the Plateau Broke on the 26th (August 28, 2026): v2.1.250 (2026-08-28 00:49 UTC) ships as a bug-fix / reliability release only — no user-visible feature commits in the release notes. Load-bearing framing to carry: first “reliability-only” tag since the v2.1.246 feature drop restarted the cadence — pauses the mixed-hotfix-and-feature rhythm rather than extending it. Cadence read: 4 tags in 5 days is still well above the pre-plateau baseline; a single reliability tag doesn’t falsify the “cadence alive” reading, but a second one in a row would. Do NOT re-open the “release cadence is stalled” plateau framing on this single tag; watch v2.1.251+ for the disambiguating datapoint. Same day: Auto Mode surfaces as the substrate in Rehberger’s 80%-success prompt-injection against Claude Code Opus 5 — Claude detects the compromise but Auto Mode blocks the cleanup command; the paradox is the load-bearing detail, and the 80% is Rehberger’s own attack-attempt success rate rather than independent replication. Covered in 2026-08-28-AI-Digest.

  • 2026-09-01-AI-Digestv2.1.252 (2026-08-31 19:46 UTC) — a stability-polish patch on top of last week’s v2.1.251 feature push (release notes). Four fixes worth naming: Bash commands failing with “task output swap refused (tasks dir moved or linked)” on some Macs; “always allow” not saving in projects with no .claude/settings.local.json yet; Remote Control sessions hosted by Claude Desktop / VS Code stalling for minutes after a tool finished when the claude.ai connection was degraded; and oversized background-task failure notifications (e.g. git errors on a full disk) pushing conversations past the API request-size limit. Load-bearing framing the digest carries: nothing new in the feature surface — the whole cadence this week reads as bedding-in the Remote Control and hook-events work from mid-August rather than adding capability. Cadence read: patch closes the v2.1.245 → v2.1.252 arc with a bug-fix tag rather than another feature drop; the mixed hotfix-and-feature texture the corpus established on 2026-08-26-AI-Digest is now visibly reverting to a stability-polish pass on the same operator-facing surfaces the recent feature drops (Remote Control, hooks, permissions UI) opened up. Log against MOC - Agentic Coding and MOC - Developer Tools.

  • 2026-09-02-AI-DigestTwo Claude Code releases in a single evening. v2.1.257 (2026-09-01, 17:53 UTC) is the feature drop: Claude Fable 5.1 (claude-fable-5-1) becomes the new default Fable model at the existing $10 / $50 per Mtok input/output pricing and 1M context, and a new Containment Escape rule is added to auto mode — extra guardrails on cloud metadata-credential fetches and cross-tenant reach. A Time format setting and timeZone control (12-hour, 24-hour, UTC, or strftime patterns) also lands. v2.1.258 (2026-09-01, 22:33 UTC) is a same-night hotfix — restores launch on macOS 12 (Monterey) after a v2.1.255 regression and fixes remote / scheduled sessions failing with "user messages must have non-empty content" after re-sent permission approvals. Substrate cadence stays tight: the default-model swap and the containment-hardening rule ship the same day the underlying model does. Log against MOC - Agentic Coding, MOC - Developer Tools, and MOC - Agent Security.

  • 2026-08-30-AI-Digestv2.1.251 remains the latest tag (2026-08-28 18:19 UTC, already-reported: 2026-08-29-AI-Digest) — no new tag in the 48 hours since yesterday’s digest; the fifth-patch-in-six-days streak paused for the weekend. Feature/security surface unchanged from yesterday: PreModelSwitch/PostModelSwitch hooks, live foreground-subagent streaming to Remote Control, /usage spend-limit bar, /cost prompt-cache metrics; symlink-traversal and plugin-path fixes. Narrow read the digest carries: the 48-hour gap is a weekend pause, not a new plateau — the v2.1.24x line’s mixed-hotfix-and-feature rhythm remains the durable texture; a single-weekend gap after five patches in six days does not falsify the cadence-alive reading and the plateau framing should not be re-opened on this single datapoint. Structural read: cadence continuity through the weekend is the disambiguating signal to watch for — the next feature-carrying release either resumes the mixed rhythm or extends the pause into an actual quiet stretch.

  • 2026-09-04-AI-DigestClaude Code v2.1.260 (2026-09-03) ships two developer-surface additions that matter today. First, a fullscreen Diff Panel — a side-by-side diff view of uncommitted changes rendered while Claude edits, toggled with /diff — the first time the CLI ships a distinct visual review affordance for in-flight edits rather than relying on the terminal’s plain-diff scrollback. Second, prompt-cache diagnostics land in /cost and the status line: cache hits and likely miss causes are now surfaced inline, closing the “why is my session suddenly hot” observability gap the Fable 5.1 cache-read cut opened three weeks ago. Two smaller fixes: permission-rule parentheses in path patterns are no longer dropped as invalid (uncompilable patterns fall back to guarding the literal path), and the Bash-permission auto-approver now catches fewer hidden command substitutions — a sandbox-hardening move. Fable 5.1 prompt-caching is also extended to cover post-tool-result context. Prior cuts v2.1.257 / v2.1.258 / v2.1.259 are already-reported: 2026-09-02-AI-Digest and 2026-09-03-AI-Digest. Log against MOC - Agentic Coding and MOC - Developer Tools.

  • 2026-09-03-AI-Digestv2.1.259 (2026-09-02 22:33 UTC) — feature drop with two managed-deployment surfaces plus two safety-hardening fixes. Adds a managedMcpServers managed setting so orgs can push HTTP/SSE MCP servers to every user from a central policy file — the second half of the managed-MCP story that started with the client-side plumbing, now expressed as a distribution knob for admins. A --permission-prompts none flag lands for unattended headless hosts — anything that would normally prompt is auto-denied — which pairs cleanly with the scheduled-routine and CI surface. Two fixes worth noting: concurrent sessions were silently reverting each other’s ~/.claude.json writes (the file is now write-locked on merge), and Bash Read() deny rules didn’t cover files passed as option values in various operand shapes — the deny rules now normalise operand positions before matching. Substrate cadence stays daily: v2.1.257 (Fable 5.1 default + Containment Escape rule) and v2.1.258 (macOS 12 launch fix) are already-reported: 2026-09-02-AI-Digest. Log against MOC - Agentic Coding, MOC - Developer Tools, and MOC - Agent Security.

  • 2026-09-05-AI-Digestv2.1.261 (2026-09-04) ships two developer-surface additions that close the “subagent context blowout” complaint that has trailed /loop and background-agent workflows since v2.0. First, subagent-output capsbashOutputMaxChars and taskOutputMaxChars are now configurable up to 128K, and --append-subagent-system-prompt-file lets the parent inject a large system-prompt into every spawned subagent from a file rather than a CLI arg (the two-part fix: the cap keeps a chatty subagent from evicting parent-thread context, and the file-driven prompt keeps briefings terse without truncating them at the shell arg-length limit). Second, the VS Code surface picks up a hollow-ring indicator for sessions open elsewhere, a fold button on permission prompts, friendly model names in /model, and an in-IDE MCP server Add/Remove dialog — the last item is the load-bearing one, since MCP configuration was previously terminal-only and drove a lot of settings.json hand-editing. Streaming perf skips re-checking already-rendered blocks; typing-order fixes drop the dropped/out-of-order character bug on fast typing; Remote Control fixes cover stale permission modes, stuck spinners, and TLS-inspecting proxies on Windows; SDK/cloud sessions now respect early Stop/interrupt. Prior cuts v2.1.257v2.1.260 are already-reported: 2026-09-02-AI-Digest, 2026-09-03-AI-Digest, 2026-09-04-AI-Digest. Log against MOC - Agentic Coding and MOC - Developer Tools.

  • 2026-09-06-AI-Digestv2.1.263 (2026-09-06) is a maintenance-tier bug-fix bump — release notes read verbatim as “Bug fixes and reliability improvements” with no user-facing surface area, no new lever, no config knob. Watch clause carries from yesterday: whether independent practitioners report the v2.1.261 128K subagent-output caps + --append-subagent-system-prompt-file combo (already-reported: 2026-09-05-AI-Digest) actually displaces the pre-existing background-agent-context-blowout pattern. Reframe worth carrying: the corpus has been calling the every-1–2-day cadence “substrate cadence stays daily” — that read holds for capability-bearing releases like v2.1.260 (Diff Panel + prompt-cache diagnostics) and v2.1.261 (subagent caps), but a bug-fix-only bump is not substrate movement. Carry as shipping cadence stays daily; today's release is maintenance-tier with no capability delta, not as substrate cadence continues. A skipped/yanked v2.1.262 between the two is the other visible artifact — no changelog for it in the recent-5 tag window. Log against MOC - Agentic Coding and MOC - Developer Tools.

  • 2026-09-07-AI-Digestv2.1.263 (2026-09-06) remains the latest tag — no new cut in the ~24 hours since; second consecutive maintenance day on the substrate, and the digest carries the same reframe as yesterday: the every-1–2-day shipping cadence continues, but substrate-movement cadence has now paused for two days running. Watch clause extends: whether v2.1.264+ restores the mixed-hotfix-and-feature texture that ran through v2.1.246 → v2.1.261 or whether the maintenance-tier subclass is turning into a plateau. already-reported: 2026-09-06-AI-Digest for the underlying tag. Log against MOC - Agentic Coding.

  • 2026-09-08-AI-Digestv2.1.263 (2026-09-06) remains the latest tag. Release notes still read verbatim as “bug fixes and reliability improvements” — no user-facing surface changes, no config knobs, no new levers since yesterday’s digest. already-reported: 2026-09-07-AI-Digest. Prior substantive release v2.1.261 (2026-09-04) still holds the meaningful delta — organization-policy diagnostics on /status + claude doctor, bashOutputMaxChars / taskOutputMaxChars up to 128K, /skill-doctor. Third calendar day without capability movement, but the sample is small enough that this is a nothing-to-report note, not a substrate-cadence has paused claim. Log against MOC - Agentic Coding.

  • 2026-09-09-AI-DigestTwo tags landed in the last 24 hours. v2.1.265 (2026-09-08) is the substantive drop: --plugin-dir now accepts a folder of plugins with hot add/remove; a 1 GB cap on tool results saved to disk with a truncation notice in preview; MCP http servers fall back to legacy HTTP+SSE per spec; prompt-cache reuse is fixed for resumed foreground subagents and agent teammates (SubagentStart hook context and preloaded skills stay in the prefix); cd persists across turns in non-interactive -p / SDK / cloud sessions; two-key shortcuts wait 3s (fixes tmux); Windows AppContainer / restricted-token sandbox no longer refuses every file with a symlink-resolution error. Then v2.1.266 (2026-09-08) is a single-item hotfix reverting a v2.1.265 regression where the undocumented CLAUDE_CODE_USE_GATEWAY env var began forcing Cloud-gateway sign-in on its own, breaking every request in setups that also set an API key, apiKeyHelper, or custom auth headers. The variable is ignored again unless ANTHROPIC_BASE_URL + ANTHROPIC_AUTH_TOKEN are both set. Reframe worth carrying: substrate cadence resumed with a same-day rollback discipline, not 265 broke shipping. Log against MOC - Agentic Coding and MOC - Developer Tools.

  • v2.1.265 + v2.1.266 — Substrate Cadence Resumes With Same-Day Rollback Discipline (September 9, 2026): v2.1.265 (2026-09-08) is the substantive drop after three maintenance days — --plugin-dir folder-of-plugins with hot add/remove, 1 GB tool-result disk cap with truncation notice, MCP http HTTP+SSE fallback per spec, prompt-cache reuse fixed for resumed foreground subagents and agent teammates, cd persistence across turns in -p / SDK / cloud sessions, tmux two-key-shortcut fix, Windows AppContainer symlink-resolution fix. v2.1.266 (2026-09-08) is a single-item hotfix reverting a v2.1.265 regression where the undocumented CLAUDE_CODE_USE_GATEWAY env var began forcing Cloud-gateway sign-in on its own, breaking setups that also set an API key, apiKeyHelper, or custom auth headers — the variable is ignored again unless ANTHROPIC_BASE_URL + ANTHROPIC_AUTH_TOKEN are both set. Load-bearing framing to carry: substrate cadence resumed with a same-day rollback discipline, not 265 broke shipping — a substantive release plus a same-day hotfix inside one calendar day is the mature-substrate motion, and closes the three-day maintenance stretch flagged in 2026-09-07-AI-Digest / 2026-09-08-AI-Digest. Covered in 2026-09-09-AI-Digest.

Key Developments (Addendum — September 2026)

  • v2.1.261 Closes the Subagent-Context-Blowout Complaint (September 4, 2026): 128K bashOutputMaxChars / taskOutputMaxChars, --append-subagent-system-prompt-file, and an in-IDE MCP Add/Remove dialog together move the CLI from “you can spawn subagents but they’ll blow up your context and their prompts will be truncated at shell-arg limits” to “you can spawn them with disciplined output caps and file-loaded briefings.” Load-bearing framing to carry: substrate hardening for the /loop and background-agent workflows, not another feature-drop — the two-part fix (output caps + file-driven system prompt) is the concrete answer to a complaint that has trailed the substrate for six months. VS Code surface adds hollow-ring indicator for sessions open elsewhere, fold button on permission prompts, friendly model names in /model, and the load-bearing in-IDE MCP Add/Remove dialog (MCP configuration was previously terminal-only). Covered in 2026-09-05-AI-Digest.