DEVELOPER-TOOL
Claude Code
Overview
Claude Code is Anthropic’s official CLI coding agent built on the Claude Agent SDK. It enables multi-agent code review, ecosystem integration through MCP (Model Context Protocol), and advanced features for interactive development workflows. The tool serves as a comprehensive platform for AI-assisted software development with enterprise-grade capabilities.
Timeline
-
2026-05-03-AI-Digest — v2.1.126 (May 1) ships model picker via /v1/models endpoint when ANTHROPIC_BASE_URL is set (relevant for Bedrock/Vertex routing), new
claude project purge [path]command, OAuth /mcp menu fix, custom-headers MCP authentication fix. -
2026-05-02-AI-Digest — No new release this weekend; v2.1.123 from April 29 remains latest. Simon Willison publishes end-to-end iNaturalist sightings tool built entirely on a phone via Claude Code for web, demonstrating the agentic-coding curve at the developer-tooling level.
-
2026-03-10-AI-Digest - v2.1.72 released
-
2026-03-11-AI-Digest - Multi-agent code review capabilities introduced
-
2026-03-12-AI-Digest - MCP ecosystem reaches 97M monthly downloads
-
2026-03-15-AI-Digest - Interactive elicitation feature released
-
2026-03-25-AI-Digest - Managed-settings.d enterprise policy framework added
-
2026-03-27-AI-Digest - OAuth RFC 9728 compliance implemented
-
2026-03-30-AI-Digest - Source leak via npm reveals KAIROS daemon architecture
-
2026-03-31-AI-Digest - /buddy companion feature launched; source leak continues
-
2026-04-01-AI-Digest - /buddy companion expanded with additional capabilities
-
2026-04-02-AI-Digest - /powerup lessons framework introduced
-
2026-04-03-AI-Digest - MCP result persistence override capability released
-
2026-04-04-AI-Digest - v2.1.92 adds
forceRemoteSettingsRefreshpolicy, interactive Bedrock setup wizard with AWS auth, per-model cost breakdown for/cost, 60% faster Write tool diffs;/tagand/vimcommands removed. -
2026-04-05-AI-Digest — Week-in-review: three releases in three days (v2.1.90-92); v2.1.92 highlighted with Bedrock wizard, 60% faster Write diffs, forceRemoteSettingsRefresh policy.
-
2026-04-06-AI-Digest — v2.1.92 remains latest release; no new weekend release.
-
2026-04-07-AI-Digest — No new release; v2.1.92 remains current with Bedrock wizard, policy controls, and faster Write diffs
-
2026-04-07-AI-Digest — No new release; v2.1.92 remains latest. OpenAI’s Responses API shell tool positions as direct competitor to Claude Code’s agentic environment.
-
2026-04-08-AI-Digest — Three releases in two days: v2.1.94 (Apr 7) ships Amazon Bedrock powered by Mantle support behind
CLAUDE_CODE_USE_MANTLE=1, raises default effort from medium to high for API/Bedrock/Vertex/Foundry/Team/Enterprise users, adds compact Slack message headers, fixes 429 rate-limit stalls and macOS keychain login failures; v2.1.96 (Apr 8) hotfixes a Bedrock 403 “Authorization header is missing” regression in v2.1.94. -
2026-04-09-AI-Digest — v2.1.97 ships substantive new features and hardening: Ctrl+O focus view toggle in NO_FLICKER mode, refreshInterval status line setting, workspace.git_worktree exposed in status line JSON, Cedar policy file syntax highlighting (.cedar/.cedarpolicy), Bash tool permission hardening and validation, and a critical fix for an MCP HTTP/SSE memory leak draining ~50 MB/hr from long-running sessions. Also fixes —resume picker issues, file-edit diffs disappearing, and Korean/Japanese text corruption on Windows. Fourth Claude Code release in five days, signaling sustained fire-fighting after the v2.1.94 platform changes.
-
2026-04-10-AI-Digest — No new release; v2.1.97 remains current. The v2.1.94 → v2.1.97 fire-fighting cadence appears to be stabilizing. Claude Managed Agents launches alongside as a separate Anthropic product for hosted agent deployment at $0.08/session-hour.
-
2026-04-11-AI-Digest — v2.1.98 ships with interactive Bedrock setup wizard (guided AWS auth, region config, credential verification, and model pinning from the login screen), per-model and cache-hit cost breakdown for
/cost, Monitor tool for streaming background script events, and 60% faster Write tool diff computation on large files. Linux sandbox shipsapply-seccomphelper in both npm and native builds. Eight releases in nine days through April. -
2026-04-12-AI-Digest — v2.1.101 ships with
/team-onboardingcommand (generates teammate ramp-up guides from local usage), OS CA certificate store trust by default (enterprise TLS proxies work out-of-the-box),/ultraplanauto-creates cloud environments, improved brief mode and focus mode, better tool-not-available errors, and fixed idle-return token hint and fullscreen scroll duplication. Ninth release in eleven April days; the skip from v2.1.98 to v2.1.101 suggests internal builds that didn’t ship publicly. -
2026-04-13-AI-Digest — No new release; v2.1.101 remains current. Claude Code prominently featured at HumanX 2026 as the tool driving “Claude mania” — now generating over $2.5B in annualized revenue and cited as the single AI tool most attendees would keep.
-
2026-04-14-AI-Digest — v2.1.105 ships (Apr 13):
pathparameter forEnterWorktree(multi-worktree switching as first-class), PreCompact hook support (hooks can block compaction via exit code 2 or{"decision":"block"}), background monitor support for plugins via top-levelmonitorsmanifest key,/proactivealiased to/loop, stalled stream handling (abort after 5 min, retry non-streaming), and improved network error messages. Tenth public release in twelve April days. -
2026-04-15-AI-Digest — Claude Code Routines launches in research preview: saved prompt + repos + connectors configurations that run on Anthropic’s cloud via schedule, API trigger, or GitHub event, removing the “my Mac was asleep” failure mode for long-running automations. Per-plan daily quotas (Pro 5, Max 15, Team/Enterprise 25). Shipped with a redesigned Claude Code UX (integrated terminal, in-app file editor, HTML/PDF preview, faster diff viewer, drag-and-drop layout). v2.1.108 (Apr 14) adds
/recapsession-context command,ENABLE_PROMPT_CACHING_1H/FORCE_PROMPT_CACHING_5Mcache TTL env vars, model-invokable built-in slash commands via the Skill tool,/undoas alias for/rewind,/modelmid-conversation warnings,/resumedefaulting to current directory, separated rate-limit vs plan-quota errors, 5xx/529 linking to status.claude.com, lower memory for file reads. v2.1.109 adds a rotating progress hint to the extended-thinking indicator. Eleventh public release in fourteen April days. -
2026-04-16-AI-Digest — v2.1.110 (Apr 15, 22:07) ships alongside v2.1.109 earlier the same day. Headline additions:
/tuicommand andtuisetting (flicker-free fullscreen rendering), Focus view decoupled from verbose transcript (Ctrl+Onow toggles only the transcript,/focustoggles the focus panel separately — splitting the overloaded v2.1.97 binding), push notification tool (Claude can fire mobile push notifications when Remote Control is enabled),autoScrollEnabledconfig,/pluginInstalled tab reordering by favorites and items-needing-attention,/doctorwarns on duplicate MCP server scopes, scheduled tasks resurrect on--resume/--continue, Remote Control parity for/autocompact//context//exit//reload-plugins, IDE-diff feedback loop (Write tool informs model when the user edits proposed content before accepting). Fixes for MCP tool calls hanging on server disconnect, non-streaming fallback multi-minute hangs, focus-mode recap/status-line regressions, plugin dependency resolution fromplugin.json, and dropped keystrokes after CLI relaunches. Twelfth public April release in fifteen days; combined with the prior day’s Routines launch, the clearest signal yet that Anthropic treats Claude Code as an always-on ambient agent substrate rather than a session-bound CLI. -
2026-04-17-AI-Digest — v2.1.111 (Apr 16, 15:18 UTC) ships to time with Claude Opus 4.7 general availability. Headline features: Claude Opus 4.7 “xhigh” effort level with new
/effortcommand for depth-vs-latency tuning (xhigh becomes Opus 4.7 Claude Code default);/ultrareviewcloud multi-agent code review command (no-args reviews current branch,/ultrareview <PR#>fetches and reviews a specific GitHub PR via parallel agent dispatch on the Routines substrate);/less-permission-promptsskill that scans transcripts to propose security allowlists; Windows PowerShell tool progressively rolling out (opt-in/out viaCLAUDE_CODE_USE_POWERSHELL_TOOL); Auto mode for Max subscribers on Opus 4.7; Auto (match terminal) theme option;Ctrl+Uclears entire input buffer;/skillssupports sorting by token count; plan files auto-named after prompts; read-only bash globs no longer trigger permission prompts; further/setup-vertexand/setup-bedrockwizard polish. v2.1.112 (Apr 16, 19:55 UTC) is a narrow hotfix for “claude-opus-4-7 is temporarily unavailable” errors in Auto mode — five-hour turnaround from bug to fix. Fourteen April releases in sixteen days;/ultrareviewis the first Claude Code feature to reach back into the Routines cloud substrate for something other than cron jobs — earliest proof point that Routines is a remote parallel-agent execution substrate slash commands can dispatch into ad hoc. -
2026-04-18-AI-Digest — v2.1.113 (Apr 17) ships the native binary as the default distribution channel, replacing the bundled JavaScript runtime — a structural shift from an npm-installed Node.js CLI to a compiled standalone executable with faster cold starts, smaller install footprint, and no Node runtime dependency. Security hardening headlines:
sandbox.network.deniedDomainsconfiguration key for blocking specific egress hosts without disabling network access entirely (partial-allowlist sandboxing for agent runs), and Bash hardening that wrapsenv,sudo,watch,ionice,setsid,/privatepaths, andfind -exec/-deletein additional validation layers. UX polish: subagent 10-minute stall detection (long-running subagents now emit a warning and offer to abort instead of hanging silently),/ultrareviewlaunch-dialog refinement (clearer branch-vs-PR mode selection), Shift+↑/↓ fullscreen scroll (paginated scrollback in/tuimode), readline-styleCtrl+A/Ctrl+E(start/end of input line), Remote Control parity for/extra-usageand@-autocomplete(mobile Claude Code can now introspect usage and reference files by name), and assorted bug fixes. Fifteenth public April release in seventeen days; the native binary is the biggest distribution-layer change since v2.0 — an explicit bet that Claude Code’s install surface should look like a compiled system tool, not a JavaScript app. -
2026-04-19-AI-Digest — v2.1.114 (Apr 18, 01:34 UTC) is a single-fix weekend hotfix that resolves a crash in the permission-dialog path when an Agent Teams teammate requests tool permission. Sixteenth April release in nineteen days, landing hours after the v2.1.113 native-binary rebase — the operational fingerprint of a team compounding against Cursor’s Composer 2 release velocity rather than an internal monthly cadence.
-
2026-04-22-AI-Digest — v2.1.117 (Apr 22, 00:04 UTC) is the first April release to widen the agent programming model rather than polish existing surfaces. Headline: forked subagents as an external-build opt-in via
CLAUDE_CODE_FORK_SUBAGENT=1, moving the forked-subagent architecture from internal-only to any custom Claude Code binary. Agent frontmattermcpServersnow loaded for main-thread agent sessions via--agent, closing the long-running gap where custom agents had reduced tool access compared to inline work./resumenow proactively offers to summarize stale, large sessions (natural follow-on to v2.1.116’s 40MB+ resume-performance work). MCP startup moves to concurrent connection handling. Enterprise posture: managed-settings enforcement forblockedMarketplaces/strictKnownMarketplaces— the plugin/marketplace-governance equivalent of v2.1.113’ssandbox.network.deniedDomainsposture. Native builds on macOS and Linux now replace theGlobandGreptools with embeddedbfsandugrep— the same “walk the bundled-JS-dependency tree” posture as the April-17jq→native migration. OpenTelemetry adds three new event attributes (command_name,command_source,effort) and a fix for Opus 4.7 context-window calculations (was reporting 200K, actually 1M). Plain-CLI OAuth refresh fix restores token refresh on expired non-terminal sessions. What v2.1.117 still does not ship: any response to the OX Security MCP disclosure — no STDIO input sanitization change, no protocol-level hardening, nosandbox.mcp.*settings. Seventeenth public April release in twenty-two days. -
2026-04-23-AI-Digest — v2.1.118 (Apr 23, 00:42 UTC) is the TUI-ergonomics companion to v2.1.117’s agent-architecture widening. Headline: vim visual modes —
v(visual) andV(visual-line) with operators, selection, and visual feedback — finally closing the largest remaining gap in the Claude Code vim-mode surface and bringing prompt editing within parity of external editors like Neovim. Custom named themes via/theme, plus hand-edited JSON files in~/.claude/themes/, move theme configurability from bundled-set to checkable-into-dotfiles./costand/statsconsolidate into/usage(old names remain as aliases). MCP tool hooks viatype: "mcp_tool"let hook authors invoke MCP tools directly from the pre/post/PreCompact hook pipeline — unlocking agentic workflows that previously required custom shell plumbing. Enterprise-governance:DISABLE_UPDATESis now a stricter env var thanDISABLE_AUTOUPDATER(blocks all update paths for regulated deployments);wslInheritsWindowsSettingslets WSL inherit Windows-side managed settings, closing a long-standing dual-policy-tree gap. Auto mode defaults gain"$defaults"composition (add custom rules alongside built-ins rather than replace them).claude plugin tagcreates release git tags with version validation — a small but telling signal that Anthropic treats plugins as versioned release artifacts. Eighteenth public April release in twenty-three days. Still not shipped: any response to the OX Security MCP disclosure — no STDIO sanitization change, nosandbox.mcp.*settings, no protocol-level MCP hardening. The MCP-Safe community track holds into week three. -
2026-04-28-AI-Digest — v2.1.121 ships substantive release with alwaysLoad MCP server option, claude plugin prune command, type-to-filter on /skills, and PostToolUse hooks generalized to all tools; memory-leak fixes for image processing, /usage command, and dangling Bash CWD issue.
-
2026-04-29-AI-Digest — v2.1.122 (April 28 evening) ships ANTHROPIC_BEDROCK_SERVICE_TIER env var for service-tier routing, /resume PR-URL session lookup, /mcp shadowed-connector visibility, OpenTelemetry numeric-attribute fix, /branch rewound-timeline crash fix; followed by v2.1.123 (April 29) one-line OAuth 401 retry-loop hot-fix.
-
2026-04-30-AI-Digest — No new release today; v2.1.123 (April 29) remains latest as Claude Code enters a quiet patch in release cadence.
-
2026-05-04-AI-Digest — No new release this week. The most recent cut (v2.1.126, May 1) added model picker via
/v1/modelsfor Anthropic-compatible gateway routing (relevant for Bedrock/Vertex),claude project purge [path]teardown command, and HTTP/SSE MCP server reauth fixes. Release cadence shift from daily (April) to multi-day (May) reflects post-Opus 4.7-GA operational normalization. -
2026-05-08-AI-Digest — Five releases in four days — v2.1.128, .129, .131, .132, and v2.1.133 (last landing late on 2026-05-07) — decisively refute the “three quiet weeks” framing from 2026-05-07-AI-Digest. Headline change in v2.1.133 is the new
worktree.baseRefsetting (fresh|head, defaultfresh) which restoresorigin/<default>as the worktree base, explicitly reverting v2.1.128’s branch-from-local-HEADdefault. Hooks now receiveeffort.level(JSON) and$CLAUDE_EFFORT(env, also exposed in Bash-tool subprocesses);parentSettingsBehaviorlands formanagedSettingspolicy merge. v2.1.132 addsCLAUDE_CODE_SESSION_IDto Bash subprocess env andCLAUDE_CODE_DISABLE_ALTERNATE_SCREEN. Material runtime fix: a 10GB+ MCP memory leak on stdio servers, plus a silenttools/listfailure that previously surfaced as “tools fetch failed” with no upstream signal. -
2026-05-09-AI-Digest — Three more releases — v2.1.136 on May 8, then v2.1.137 and v2.1.138 in quick succession on May 9. The substantive one is v2.1.136: it adds
CLAUDE_CODE_ENABLE_FEEDBACK_SURVEY_FOR_OTEL(re-enables the session-quality survey for OTel-capturing enterprises) andsettings.autoMode.hard_denyfor unconditional auto-mode classifier blocks, alongside ~40 fixes. Two reliability fixes worth naming: MCP servers from.mcp.json, plugins, and claude.ai connectors no longer silently disappear after/clearin VS Code, JetBrains, and the Agent SDK; and concurrent MCP OAuth refresh-token rotations no longer overwrite freshly-rotated tokens, ending the daily re-auth tax for users running multiple remote MCP servers. v2.1.137 fixed VS Code extension activation on Windows; v2.1.138 is internal-fixes-only. Eight releases in six days is above-trend but consistent with typical 1–2 day patch rhythm — “the dry stretch ended” rather than “structural cadence reset.” -
2026-05-10-AI-Digest — No new release in the past 24 hours; latest remains v2.1.138 from 2026-05-09. The cadence reset that began 2026-05-07 (five releases across May 6–9) has held through a quiet Sunday — eight releases in six days followed by one quiet day, consistent with a normal weekly rhythm rather than a structural pause.
-
2026-05-11-AI-Digest — Two net-new releases covered: v2.1.133 (2026-05-07) introduces
worktree.baseRefsetting withfreshandheadvalues and flips the default tofresh, meaning new worktrees branch fromorigin/<default>instead of localHEAD— a quiet breaking change for users who rely on in-progress local commits carrying into a new worktree. Hooks gaineffort.level(JSON) and$CLAUDE_EFFORT(env var). Also fixes an unbounded parallel-session 401 loop from refresh-token race. v2.1.132 (2026-05-06) addsCLAUDE_CODE_SESSION_IDto Bash subprocess env,CLAUDE_CODE_DISABLE_ALTERNATE_SCREEN=1, fixes 10GB+ RSS MCP memory growth from stdio servers writing non-protocol stdout, adds graceful SIGINT shutdown, and fixes vim operators corrupting NFD-accented text. -
2026-05-12-AI-Digest — v2.1.139 ships Agent View (Research Preview) —
claude agentssurfaces a unified session lifecycle list tagged running/blocked-on-you/done, the first primary CLI surface for session management. New/goalcommand sets a completion condition and lets Claude work across turns with a live overlay showing elapsed time, turn count, and token spend.hook continueOnBlocklets PostToolUse hooks feed a rejection reason back to Claude and continue rather than halt; exec-formargs: string[]removes shell-quoting hazards. Compaction now preserves sensitive user instructions; MCP stdio servers receiveCLAUDE_PROJECT_DIR. -
2026-05-13-AI-Digest — v2.1.140 ships four fixes:
subagent_typematching is now case- and separator-insensitive,/goalno longer silently hangs underdisableAllHooks/allowManagedHooksOnly, symlinked settings files no longer trigger spuriousConfigChangehook fires, andclaude --bgreliability is improved for machines where the background service was about to idle-exit or in enterprise endpoint-security environments. -
2026-05-14-AI-Digest — v2.1.141 ships a substantive feature drop wrapped in a ~26-change bug-fix wave: new
terminalSequencefield in hook JSON output (enables desktop notifications and terminal bells from headless and CI environments),ANTHROPIC_WORKSPACE_IDenv var for workload identity federation, “Summarize up to here” action in the Rewind menu for mid-conversation compression, and regression fixes for Bedrock/Vertex Haiku fallback, markdown table rendering, vim-mode Ctrl+C interrupt, and Windows Alt+V image paste. -
2026-05-16-AI-Digest — v2.1.143 ships a new
worktree.bgIsolation: "none"setting letting background sessions edit the working copy directly withoutEnterWorktree— the cleanest fix for submodule-heavy repos and generated-asset directories that have been hitting edge cases since the worktree primitive landed. Plugin dependency enforcement lands:claude plugin disablerefuses when another enabled plugin depends on the target and prints a disable-chain hint;claude plugin enableforce-enables transitive dependencies.claude agentsgains 8 more flags (--add-dir,--settings,--mcp-config,--plugin-dir,--permission-mode,--model,--effort,--dangerously-skip-permissions) — combined with v2.1.142’s 8 flags, the background-agents CLI surface is now feature-equivalent to top-levelclaude. Reliability: stop-hook infinite-block loop caps at 8 iterations; macOS TCC sandbox errors for~/Documents,~/Desktop,~/Downloadsresolved. -
2026-05-15-AI-Digest — v2.1.142 ships the largest single expansion of the background-agents dispatch surface since the feature landed:
claude agentsgains eight configuration flags —--add-dir,--settings,--mcp-config,--model,--effort,--permission-mode,--plugin-dir,--dangerously-skip-permissions— making background sessions configurable along the same axes as foreground ones. Fast mode default bumped from Opus 4.6 to Opus 4.7 (prior version pinnable viaCLAUDE_CODE_OPUS_4_6_FAST_MODE_OVERRIDE=1). Single-skill plugins with a root-levelSKILL.mdand noskills/subdirectory are now auto-surfaced without the nested-directory dance. Background-session reliability wave: macOS sleep/wake daemon reconnect, daemon exit afterbrew upgrade–style binary swap, Windows deadlock on network-drive working directories, 256-color terminal background bleed on Apple Terminal. -
2026-05-19-AI-Digest — v2.1.144 (first release since v2.1.143 four days ago) brings
/resumeworking against--bgruns (with an explicitbgmarker) and completion notifications that now include elapsed duration;/modelswitching is session-scoped by default withdto make the change the new default — a meaningful ergonomic fix for users who toggle models mid-task. Fix list is the more interesting half: a 15-second timeout on theapi.anthropic.comstartup probe (previously hung up to 75 seconds on flaky networks); MCP servers responding with paginatedtools/listnow have all pages enumerated rather than only the first; and macOS background sessions no longer crash inside Full Disk Access-protected directories. Shipped the same day Anthropic acquired Stainless (>$300M reported) and Mythos’s cyber-flaw cache reached the Financial Stability Board. -
2026-05-20-AI-Digest — v2.1.145 (second release on the same day as v2.1.144, and the substantive one for multi-agent workflows):
claude agents --jsonlists live sessions as machine-readable output (the wiring needed for tmux-resurrect, status bars, and session pickers); the terminal tab title surfaces the count of agents awaiting input; OTEL spans now carryagent_id/parent_agent_idattributes with fixed trace parenting so background subagent spans nest under the dispatching Agent tool span; Stop and SubagentStop hook input gainsbackground_tasksandsession_crons;/pluginDiscover and Browse screens preview commands/agents/skills/hooks/MCP+LSP servers before installation; a permission-prompt bypass via bare variable assignments to non-allowlisted env vars in Bash is closed; and an infinite loop wherecontext: forkskills could re-invoke themselves is fixed. -
2026-05-21-AI-Digest — v2.1.146 ships a small but pointed payload: the headline rename is
/simplify→/code-reviewwith an optional effort-level argument that mirrors the same dial added to/security-reviewand the underlyingcode-reviewskill earlier this month — Anthropic is converging the review-style commands on one effort knob. Fixes: the Auto-mode regression whereAskUserQuestionwas silently suppressed when the calling flow relied on it; the Windows PowerShell “command line is invalid” regression introduced in v2.1.124; MCP pagination forresources/list,resources/templates/list, andprompts/list; and materially faster diff rendering for large file edits. Two consecutive on-cadence releases (v2.1.145 on 2026-05-19, v2.1.146 today) suggest the Code with Claude London launch slowdown was a head-fake, not a deceleration. -
2026-05-22-AI-Digest — v2.1.147 → v2.1.148 in five hours. v2.1.147 (2026-05-21, ~20:39 UTC) ships background sessions, the
/simplify→/code-reviewrename with aneffortargument mirroring/security-review, an auto-updater retry loop for flaky networks, plus enterprise-login and PowerShell fixes. v2.1.148 (2026-05-22, ~01:16 UTC) is a single-issue hotfix for a regression introduced in 147 where the Bash tool returned exit code127on every command for some users — caught fast. Two on-cadence releases in two days plus a tight hotfix loop further refutes the Code with Claude London slowdown hypothesis; practitioners on v2.1.147 should skip to v2.1.148 if they saw the127errors. -
2026-05-23-AI-Digest — v2.1.149 → v2.1.150 in one day. v2.1.149 (2026-05-22) is the substantive cut:
/usageadds a per-category cost breakdown (skills, subagents, plugins, MCP servers);/diffgains full keyboard scrolling (arrows, j/k, PgUp/PgDn, Space, Home/End); GFM task-list checkboxes finally render in markdown; enterpriseallowAllClaudeAiMcpsmanaged setting lands. Security hardening: a PowerShellcd-function permission bypass closed, sandbox write allowlist tightened in git worktrees, and afind-call pattern fixed that had been exhausting the macOS vnode table on large repos. v2.1.150 (2026-05-23) is infrastructure-only — same-day point release stacked on yesterday’s feature drop. Four releases in three days (147 → 150) reads as burst, not new steady state — trailing 11-day rate is ~0.9 releases/day. -
2026-05-27-AI-Digest — v2.1.152 lands at 2026-05-27 01:30 UTC, the first new tag since v2.1.150 on 2026-05-23 — ending a five-day quiet streak. The GitHub release page is not directly fetchable from the digest-write environment, so today’s coverage is a tag-confirmation rather than a changelog read; substantive feature coverage will follow once the release notes are accessible. The cadence resumes inside the prior 3–5 day envelope; nothing about today’s tag suggests the burst pattern from the v2.1.147–v2.1.149 run is back. Watch is whether v2.1.153 follows within 72 hours (signalling a new burst) or the gap extends past a week again.
-
2026-05-28-AI-Digest — v2.1.153 ships at ~00:52 UTC, a back-to-back daily tag the day after v2.1.152 — answering the prior digest’s 72-hour-watch question toward “burst” rather than week-long gap. Quality-of-life additions: a
skipLfsoption forgithub/gitplugin marketplace sources, status-line commands now receiveCOLUMNS/LINESfor terminal-aware output, andclaude agentsautocomplete suggests native slash commands and bundled skills alongside aPR #Ncolumn. The rest is bug-fix housekeeping (MCP server handling, custom API-gateway auth, Windows PowerShell installer false-success report, background-session UI fixes for stale daemons, stdin EOF hangs, malformedfile://links). Steady-state maintenance, not a feature drop. -
2026-05-29-AI-Digest — v2.1.154 is the week’s first real feature drop after a run of daily maintenance tags, shipping the same beat as the Claude Opus 4.8 launch. Headline: first-class Opus 4.8 support (defaulting to high effort, a new
/effort xhighrung, Fast mode billed at “2× the standard rate for 2.5× the speed”) plus dynamic workflows —/workflowslets you ask Claude to spin up an orchestration that fans out “tens to hundreds of agents in the background.” Supporting changes: lean system prompt is now the default for newer models,/simplifyis now cleanup-only review,/effortlabels renamed to Faster/Smarter, and the auto-mode classifier was hardened against bulk-repo exfiltration. A fast-follow v2.1.156 is a single hotfix for an Opus 4.8 case where modified thinking blocks led to API errors. Treat the “hundreds of agents” line as a capped, concurrency-limited research-preview ceiling, not a daily-driver workflow yet. -
2026-05-30-AI-Digest — Two-tag day. v2.1.157 (2026-05-29, ~20:20 UTC) is the substantive cut: plugins placed in
.claude/skillsdirectories now auto-load without a marketplace requirement, a newclaude plugin init <name>scaffolder lands,/pluginarguments and subcommands get autocomplete, theagentfield insettings.jsonis now honored for dispatchedclaude agentssessions, plus fixes for background sessions, worktrees, image handling, and terminal rendering. v2.1.158 (2026-05-30, ~02:42 UTC) is narrower — it extends the v2.1.154 auto-mode classifier to AWS Bedrock, Google Vertex, and Azure Foundry for Opus 4.7 and 4.8, opt-in viaCLAUDE_CODE_ENABLE_AUTO_MODE=1. The plugin-distribution story has now visibly decoupled from the marketplace, and auto-mode going to enterprise-cloud backends is the same plugin-and-deployment surface widening in lockstep. Cadence read: feature drop, not steady-state — v2.1.157’s plugin auto-load reshapes the third-party developer story. -
2026-05-31-AI-Digest — No new tag in the last 24 hours; latest remains v2.1.158 (2026-05-30 ~02:42 UTC). The back-to-back v2.1.157 plugin-auto-load and v2.1.158 auto-mode-to-Bedrock/Vertex/Foundry features remain the current state, and the cadence is back to a normal post-feature-drop pause. The signal to watch is whether v2.1.159 lands a bug-fix sweep on the new
.claude/skillsauto-load path now that it’s in the hands of third-party plugin authors. Separately, Salesforce‘s self-reported 231-day → 13-day internal cloud migration on Claude Code (33 API endpoints, +79% PRs/dev, 5% fewer incidents) lands today as the upper-tail outlier demand-side data point for a tool whose v2.1.158 plugin/auto-mode surface is the supply-side story. -
2026-06-01-AI-Digest — v2.1.159 ships 2026-05-31 ~19:42 UTC, a quiet housekeeping patch whose release notes read in full: “Internal infrastructure improvements (no user-facing changes).” First tag after the v2.1.157 plugin auto-load and v2.1.158 auto-mode-to-Bedrock/Vertex/Foundry feature pair. The predicted bug-fix sweep on the new
.claude/skillsauto-load path did not land here — the notes are explicit about “no user-facing changes.” Cadence is back to housekeeping; the.claude/skillsfollow-up is still pending and remains the signal to watch on the next tag. -
2026-06-02-AI-Digest — v2.1.160 ships 2026-06-02 ~02:10 UTC — the predicted
.claude/skillsfollow-up arrives, though not where v2.1.159’s “no user-facing changes” framing implied. TheacceptEditssafety net widens to prompt before writing shell startup files (.zshenv,.zlogin,.bash_login),~/.config/git/configs, and the build-tool config class that grants code execution:.npmrc,.yarnrc*,bunfig.toml,.bazelrc,.pre-commit-config.yaml,.devcontainer/— closing the exec-on-config-write class that v2.1.157’s.claude/skillsauto-load reopened. Two breaking-edge items in the same tag: the dynamic-workflow trigger renamesworkflow→ultracode(silently breaks any script wired to the v2.1.154/workflowsorchestrator); and Edit no longer requires a separate Read after grep (cuts a real round-trip from the agentic edit loop). WSL clipboard, voice-mode on non-ASCII paths, and CJK IME positioning inclaude agentsround out a long-overdue Windows/WSL stabilisation sweep.CLAUDE_CODE_OPUS_4_6_FAST_MODE_OVERRIDEis removed. -
2026-06-03-AI-Digest — v2.1.161 ships 2026-06-02 ~21:58 UTC — second tag in a single day, back-to-back with v2.1.160 only ~20 hours earlier, which is unusual for the cadence. Headline:
OTEL_RESOURCE_ATTRIBUTESvalues now flow through as labels on metric datapoints (the missing piece for anyone wiring Claude Code into existing OTel pipelines);claude agentsrows showdone/totalahead of the detail column when work is fanned out across subagents;/mcpcollapses unused claude.ai connectors behind a “Show unused connectors” row; failed Bash commands in a parallel-tool batch no longer cancel the other in-flight calls; and fullscreen clipboard on Linux now reaches forwl-copy/xclip/xselin order, so Wayland desktops finally get first-class copy. The OTel labels and the parallel-tools fix are the two practitioners will feel immediately. -
2026-06-04-AI-Digest — v2.1.162 ships 2026-06-03, the third tag in ~36 hours after v2.1.160 and v2.1.161. Headline:
claude agents --jsonnow exposeswaitingFor(first machine-readable handle on agent wait state — the right primitive for queue-aware dashboards and “is this agent stuck?” health checks); on native builds,--toolsships dedicated Grep/Glob search tools when explicitly listed instead of folding them into Bash (re-check existing tool-filter lists that assumed the old shape); clicking a slash command in the autocomplete menu now fills the prompt instead of firing immediately (fixes a long-standing footgun). Cosmetic: Windsurf is renamed to “Devin Desktop” across/ide,/terminal-setup,/scroll-speed(reflects the Cognition acquisition rename). ThewaitingForJSON field and the parallel-tools split are the two practitioners will feel immediately. -
2026-06-05-AI-Digest — v2.1.163 ships 2026-06-04, one day after the v2.1.162 cluster. Two policy-surface additions are the headline:
requiredMinimumVersionandrequiredMaximumVersionmanaged settings let admins pin a version-range floor and ceiling from policy config — first time the managed-settings surface has had version gating, and the right primitive for orgs that need to hold a fleet on a tested band rather than the latest tag. The new/plugin listgrows--enabled/--disabledfilters — first user-facing surface for inspecting plugin state from inside the CLI. Robustness: background sessions no longer lose running tasks when re-attached after a self-update (companion fix to v2.1.160’s sleep/wake patch — the background-session re-attach story is finally robust across both update and suspend). Bash hardening for bazel, EDR-protected hosts, and Windows rounds it out. The version-range gating is the practitioner lever for rollouts that need to express ”≥ v2.1.160 but ≤ v2.1.163 until QA signs off on v2.1.164” without scripting around the auto-update. -
2026-06-06-AI-Digest — Three tags since yesterday’s digest — v2.1.165 (2026-06-05), v2.1.166 (2026-06-06), and v2.1.167 (2026-06-06). The flanking releases are terse “bug fixes and reliability improvements” point releases; v2.1.166 is the substantive one and lands the new headline features. Headline: a
fallbackModelmanaged setting that accepts up to three fallback models tried in order when the primary is overloaded or unavailable — the first time the fallback chain has been a first-class declarative config rather than a per-invocation flag — and--fallback-modelnow also applies to interactive sessions, not just-p. Permissions DSL gets meaningful tightening too: glob pattern support in the deny-rule tool-name position ("*"denies all tools), allow rules now reject non-MCP globs, and unknown tool names in deny rules warn at startup. Cross-session messaging is hardened — messages relayed viaSendMessagefrom other Claude sessions no longer carry user authority, receivers refuse relayed permission requests, and auto mode blocks them. Plus:MAX_THINKING_TOKENS=0/--thinking disabled/ per-model thinking toggles now disable thinking on models that think by default via the Claude API, and there’s a one-shot retry on the fallback model after an unexpected non-retryable error. The fallback-as-declarative-config pivot is the change to actually adopt — the managed setting belongs in.claude/settings.jsonand the chain runs the same way in interactive sessions. -
2026-06-07-AI-Digest — Two more fixes-only point releases capping yesterday’s substantive v2.1.166 — v2.1.167 (2026-06-06 01:33 UTC) and v2.1.168 (2026-06-06 23:41 UTC) — both ship as bare “bug fixes and reliability improvements” tags with no public changelog beyond the headline. All the substantive features (the
fallbackModelmanaged setting with three-deep fallback chain,--fallback-modelextending to interactive sessions, glob patterns in deny rules, hardened cross-sessionSendMessageauthority handling, auto-mode blocking relayed permission requests,MAX_THINKING_TOKENS=0disabling thinking on default-thinking models, the pre-download version announcement onclaude update) all landed in v2.1.166 (2026-06-06-AI-Digest). Three tags in 48 hours, two fixes-only — the cadence read is “ship the substantive change, then bake out the regressions on the same day” rather than gating point releases. Same-week framing: Anthropic’s “When AI builds itself” >80%-Claude-merged post lands the dogfood-loop statistic that frames Claude Code’s compounding adoption inside Anthropic itself. -
2026-06-09-AI-Digest — Claude Code v2.1.169 (2026-06-08, 21:57 UTC) — the first substantive tag in 48h after three “bug fixes and reliability improvements” point releases (v2.1.167, v2.1.168, plus v2.1.165). New surface: a
--safe-modeflag that disables customizations for troubleshooting (diagnostic equivalent of a clean Chrome profile), a/cdcommand that changes the working directory without breaking the prompt cache (load-bearing for long-running sessions in monorepos), and adisableBundledSkillssetting that hides bundled skills from the model — useful when team skills should be the only ones in scope. Fixes: enterprise MCP policy enforcement, a ~30–50ms macOS UI stall on claude.ai credentials,claude -pslowness on Windows, arrow-key navigation through command history on wrapped lines, plus background-session, Remote Control reconnection, and agent improvements. The read is that Anthropic is back to the “ship the substantive change, then bake out the regressions” cadence — three fixes-only days, then a real release. -
2026-06-12-AI-Digest — Three tags in 36 hours. v2.1.173 (2026-06-11) strips the vestigial
[1m]suffix from Fable 5 model names (Fable 5 ships with 1M context as default) and silences the spurious “sandbox dependencies missing” startup warning on Windows. v2.1.174 (2026-06-12) is the substantive middle tag:wheelScrollAccelerationEnabledfor trackpads;/modelpicker now shows which family Default resolves to per plan (Opus on Max/Team Premium/Enterprise, Sonnet on Pro/Team, Opus on PAYG API); Bedrock GovCloud inference-profile prefix fix (global→us-govforus-gov-*regions); enterprise usage-based-billing banner misfire fixed; the headline change is the new/usageattribution view in VSCode — cache misses, long-context, subagents, per-skill/agent/plugin/MCP, broken out 24h/7d. v2.1.175 (2026-06-12) shipsenforceAvailableModels— when the managed setting is enabled, theavailableModelsallowlist now also constrains the Default model (Default falls back to the first allowed model if it would otherwise resolve to a disallowed one), and user/project settings can no longer widen a managed allowlist. First time Claude Code’s model-governance surface has been hardened against in-org widening. -
2026-06-10-AI-Digest — Claude Code v2.1.170 (2026-06-09, 17:23 UTC) — the Claude Fable 5 enablement tag. Release notes read, verbatim, “Introducing Claude Fable 5: a Mythos-class model now available for general use with capabilities exceeding any previously released model. Update to version 2.1.170 for access.” Beyond the model wiring there is one substantive fix: sessions that failed to save transcripts and were missing from
--resumewhen Claude Code was launched from the VS Code integrated terminal (or any shell inheriting CC env vars) now persist correctly — a quiet but load-bearing regression for anyone running the VS Code extension as their primary surface. Coming on the heels of v2.1.169’s--safe-mode//cd/disableBundledSkillssurface from 2026-06-09-AI-Digest, the pattern is now clearly “ship the substantive feature tag, then ship the model-bump tag a day later” — the model release was paced to follow the harness, not the other way round. -
2026-06-08-AI-Digest — No new tag since yesterday. v2.1.168 (2026-06-06, 23:41 UTC) remains the head — the third “bug fixes and reliability improvements” point release in 48 hours on top of the substantive v2.1.166 (the
fallbackModeldeclarative config, glob patterns in deny rules,SendMessagecross-session authority hardening,MAX_THINKING_TOKENS=0actually disabling thinking, all covered in 2026-06-07-AI-Digest). Nothing new to add today — flagging quiet so the cadence shows in the corpus. -
2026-06-13-AI-Digest — v2.1.176 (2026-06-12) — session titles now match the conversation language (i18n correctness fix for non-English locales), new
footerLinksRegexesmanaged setting lets enterprise admins pattern-match link badges in the status footer (back half of v2.1.175’senforceAvailableModelsenterprise-governance surface), Bedrock credential cache now respects the credential’s actualExpirationfield rather than the fixed-1-hour assumption (matters when SSO expires at 47 minutes mid-tool-call),/fastrefuses cleanly on a blocked model rather than failing silently, auto-mode falls back to Fable 5 when Opus 4.8 isn’t allowlisted,/copyworks in tmux-over-SSH, the Linux sandbox handles symlinks, hook file-path conditions and Remote Control session-model switching get patches. Second tag in a row hardening enterprise-governance surfaces — managed-setting growth is now the load-bearing release direction. -
2026-06-14-AI-Digest — v2.1.177 (2026-06-13) is metadata-only —
CHANGELOG.mdandfeed.xmlupdates only, no functional changes. The ship just carries the changelog for yesterday’s v2.1.176 (session-title language matching,footerLinksRegexesmanaged setting, Bedrock credentialExpirationhonoring,/fastclean refusal on blocked models, auto-mode fallback to Fable 5, Linux sandbox symlink handling). Three tags in 36 hours (v2.1.175 → 176 → 177), with the third being a chore tag, reads as Anthropic decoupling functional binary ships from changelog-ship tags — the release engine now absorbs disclosure-prep work into a follow-on tag. Read together with the Anthropic export-control story, enterprise-governance surface area is where the Claude Code engineering team’s time is going — five managed-setting additions in two weeks against approximately one user-facing UI change in the same window. -
2026-06-15-AI-Digest — No new tag in the last 24 hours. v2.1.177 (2026-06-13) remains the head; the v2.1.175 → 176 → 177 cluster covered in 2026-06-13-AI-Digest and 2026-06-14-AI-Digest stands. The signal worth holding is that the release engine has now decoupled functional ships (v2.1.175, v2.1.176) from changelog ships (v2.1.177) — and the substance continues to concentrate in managed-setting growth (
enforceAvailableModels, session-title language matching, Bedrock credentialExpirationhandling). The first non-cadence release after the export-control disable is the next thing to watch — the v2.1.176availableModelsallowlist enforcement closed the alias-redirect loophole right before the 2026-06-12 Claude Fable 5 / Claude Mythos 5 global pull, and how the next tag treats the now-disabled model identifiers will be the live signal. -
2026-06-16-AI-Digest — v2.1.178 shipped June 15 as the first post-export-control release with genuinely new capability surface.
Tool(param:value)permission syntax enables invocation-level blocking by input value (e.g.,Agent(model:opus)to forbid Opus subagents,WebFetch(url:competitor.com)to block specific fetches) — closing a long-standing allowlist-granularity gap. Pre-launch subagent safety classifier evaluates subagent spawns before launch, shutting the door on a subagent requesting a blocked action without review. Nested.claude/directories now scope skills, agents, and workflows to the closest directory (name clashes surface as<dir>:<name>). 20+ bug fixes: OOM crash from stale fd env vars, Chrome OAuth cross-account silent failure, compaction ignoring--fallback-model. -
2026-06-17-AI-Digest — v2.1.179 shipped June 16 — a stability point release rather than a capability ship, and the second post-Fable-5-shutdown release in a week. Four fixes worth logging: mid-stream connection drops now preserve partial responses instead of surfacing raw errors; mouse-wheel scrolling works again in WSL2 under Windows Terminal and VS Code; sandbox glob patterns no longer make Linux sessions unusable on large directory trees; and plugin loading in remote sessions is measurably faster. No new permission syntax, no new classifier, no agent-protocol moves — just the quiet maintenance cadence the corpus has been waiting for since v2.1.178 shipped two days of new surface in one release.
-
2026-06-18-AI-Digest — v2.1.181 shipped June 17 — the third release in three days (v2.1.178 → v2.1.179 → v2.1.181), confirming the post-Fable-5-shutdown maintenance cadence. Four items worth logging.
/config key=valuelets you set any setting inline at the prompt (/config thinking=false) without diving intosettings.json— the shortest path yet between “I want to change behavior” and the next turn.sandbox.allowAppleEventsis a new macOS opt-in for Apple Events / AppleScript bridges — first sandbox knob explicitly aimed at driving macOS apps from Claude Code, quietly unblocking a whole class of desktop automation. The bundled Bun runtime bumps to 1.4, which is the line worth flagging for this repo: thestrip-markdown/unist-util-visit-parentsexport-condition issue was a Bun 1.3.8 problem and is worth retesting against 1.4. Final fix: prompt-caching now works correctly on customANTHROPIC_BASE_URLand Azure Foundry — meaningful for enterprise proxy and self-hosted setups that have been silently paying full token cost on cached prefixes. -
2026-06-19-AI-Digest — v2.1.183 shipped — the fourth release in three days, continuing the maintenance cadence noted in 2026-06-18-AI-Digest. Four items worth logging. Auto-mode safety hardening is the headline: the harness now blocks destructive
gitoperations (reset --hard,clean -fdagainst tracked files) and anyterraform/pulumi/cdk destroyinvocation when running unattended — the class of action that has eaten the most user trust this quarter.attribution.sessionUrlis a new setting that suppresses the per-commit session link in commit messages and PR bodies (the “Claude-Session:” trailer) for users who’d rather not surface the URL externally — opt-in via/config attribution.sessionUrl=false. Deprecation warnings now print when a model alias is auto-rolled to a newer pin (e.g.claude-opus-4-7→claude-opus-4-8at end-of-life), giving users a session of warning before the swap. Two notable fixes: thinking-block rendering errors in long sessions, andWebSearchfailing silently inside subagents — both regressed in the v2.1.179 series. -
2026-06-20-AI-Digest — No new release in the ~24h window. v2.1.183 (2026-06-19-AI-Digest) remains the live tag — auto-mode safety hardening,
attribution.sessionUrlopt-in, deprecation warnings, and the thinking-block / subagent-WebSearch fixes still the latest changes. First quiet day since the post-Fable-5 four-releases-in-three-days burst. -
2026-06-21-AI-Digest — v2.1.185 ships late on June 20 — UX-only point release on top of the v2.1.183 auto-mode safety hardening. Two items, both cosmetic: the stream-stall hint message rephrased (“No response from API · Retrying in …” → “Waiting for API response · will retry in …”), and the trigger delay extended from 10s of silence to 20s (harness now waits twice as long before surfacing the “are we stuck?” signal). No behaviour change to tools, sandboxing, or the agent loop. Five releases in five days continues the maintenance posture the corpus has been tracking since 2026-06-17-AI-Digest — the kind of release that exists because someone got tired of seeing the old message at 11s into a real API call.
-
2026-06-23-AI-Digest — v2.1.186 shipped June 22 20:37 UTC — first cadence-resumption point release after v2.1.185’s cosmetic-only print. Substantive surface is narrow but real. New MCP auth CLI —
claude mcp login <name>/claude mcp logout <name>— replaces the interactive menu for per-server authentication (matters for anyone scripting MCP server bring-up in CI). NewrespondToBashCommandssetting flips!-prefixed bash command behaviour: when on, the harness auto-triggers a Claude response after the command completes rather than waiting for a follow-up prompt. Also in the bundle: aSkillssection in/plugin’s Installed tab, status filtering (f) in/workflowsagent-detail view,teammateMode: "iterm2"for terminal multiplexing, and--effortinheritance from agent-team leaders to teammates. Bug fixes cover streaming “Content block not found” after machine sleep, subagent transcript scroll, background task preview, Chrome tab-group isolation for concurrent CLI sessions, and background session recap duplication. Two-day cadence resumed; the corpus is not reading therespondToBashCommandsdefault-flip as evidence for the loops-dominant framing in today’s TechCrunch piece, even though the shape rhymes. -
2026-06-24-AI-Digest — v2.1.187 shipped June 23 21:03 UTC — second cadence point release in the v2.1.18x line after v2.1.186. The substantive item is a new
sandbox.credentialssetting that blocks sandboxed commands from reading credential files or secret env vars — narrow but real hardening primitive for Claude Code in CI alongside cloud-provider tokens. Org-configured model restrictions now propagate all the way through to the model picker, the--modelCLI flag, the/modelslash command, and theANTHROPIC_MODELenv var, with a unified “restricted by your organization’s settings” message — admin-side toggle that only matters when enterprise rollout is real, and apparently is. Remote MCP tool calls hanging for 5 minutes now abort with an explicit error (override viaCLAUDE_CODE_MCP_TOOL_IDLE_TIMEOUT);--resumeno longer fails on-pruns with no model turns;--json-schema/ workflowagent({schema})no longer loops on theStructuredOutputtool. QoL bundle: mouse-click select menus in fullscreen, optional/install-github-appworkflow steps,/btwarrow-key history, auto-cleanup of leaked agent-worktree registrations. Two-day cadence holding. -
2026-06-25-AI-Digest — v2.1.191 shipped June 24 21:58 UTC — four-day cadence point release after v2.1.187 (the longest gap in the v2.1.18x line). Headline primitive: new
/rewindcommand resumes a conversation from before/clearwas run — a recovery move for the “I cleared too aggressively” case that previously meant rebuilding context by hand. Two correctness fixes worth carrying: background agents no longer resurrect after being stopped from the tasks panel, and hooks with comma-separated matchers ("Bash,PowerShell") now actually fire instead of silently no-op’ing. The MCP reliability bundle is the substantive infra change —tools/list,prompts/list, andresources/listnow retry transient network errors with backoff; OAuth discovery/token retries once; HTTP 404s show the URL and point at the MCP config; headless envs skip the browser popup and go straight to paste-the-URL. Performance: streaming CPU down ~37% via 100ms text-update coalescing, long-session memory growth from the terminal-output cache reduced. Sandbox network “Yes” answers now sticky per session instead of re-prompting per connection. -
2026-06-26-AI-Digest — v2.1.193 shipped June 25 — daily cadence resumed after the four-day gap that landed v2.1.191. Two settings changes worth carrying. (1) New
autoMode.classifyAllShellsetting routes every Bash/PowerShell command through the auto-mode classifier instead of only arbitrary-code-execution patterns; denial reasons now surface in the transcript, the denial toast, and the/permissionsrecent-denials view — a notable tightening for shops running auto mode against partially-trusted environments. (2) Silent default change worth flagging: a newclaude_code.assistant_responseOpenTelemetry event logs model response text. The event is redacted unlessOTEL_LOG_ASSISTANT_RESPONSES=1, but when that variable is unset it now inheritsOTEL_LOG_USER_PROMPTS, so any deployment already logging prompts will start receiving response content on upgrade. SetOTEL_LOG_ASSISTANT_RESPONSES=0to stay prompts-only. Two background-agent fixes round out the release: backgrounding the main turn no longer spawns a phantom “general-purpose (resumed)” subagent, and pinned background agents stop getting auto-re-prompted to “Continue from where you left off” after each update. MCP polish:headersHelperauth re-runs and reconnects automatically on 401/403; startup notice points at/mcpwhen servers need authentication. QoL: live file-path autocomplete in bash mode (!), automatic memory-pressure reaping for idle background shells (CLAUDE_CODE_DISABLE_BG_SHELL_PRESSURE_REAP=1to disable), plugin auto-rename follows marketplacerenamesmaps. -
2026-06-27-AI-Digest — v2.1.195 shipped June 26 — daily cadence holds, two releases out from v2.1.193. Headline: new
CLAUDE_CODE_DISABLE_MOUSE_CLICKSenv var disables click, drag, and hover capture in fullscreen mode while keeping wheel scroll intact — accommodation for terminal-multiplexer users whose host-pane selection has been getting eaten by Claude Code’s mouse handler. Behaviour change worth flagging: hook matchers with hyphenated identifiers (e.g.code-reviewer,mcp__brave-search) were accidentally substring-matching prior to this release; they now exact-match. Existing matchers in production may stop firing on upgrade — restore prior behaviour with patterns likemcp__brave-search__.*rather than the bare identifier. Voice dictation: macOS sessions now recover when default input device changes mid-session (previously capture silently went to a closed device); auto-submit now fires for space-less languages (Japanese, Chinese, Thai). Background-agent reliability sweep: agents written by a newer Claude Code version no longer disappear fromclaude agentsafter a downgrade-then-reopen cycle; 5-second blank screen on crashed-task reopen is gone; daemons whose control socket fails to start are no longer permanently unrecoverable. Two-day cadence is now four daily releases running. -
2026-06-29-AI-Digest — No new tag since
v2.1.195shipped June 26 — the Claude Code silence now extends to three full days, the longest gap since the four-daily-releases streak began earlier this month. Yesterday’s digest flagged the two-day pause as the first quiet stretch in roughly a working week; today extends it by another day. Carry the cadence-break, not the changelog — the full v2.1.195 notes (theCLAUDE_CODE_DISABLE_MOUSE_CLICKSenv var, the hyphenated hook-matcher exact-match fix, the macOS dictation recovery) are already in 2026-06-27-AI-Digest. Same digest references Claude Code as the Anthropic anchor in the day’s Hacker News thread “I used Claude Code to get a second opinion on my MRI” (383 pts / 496 cmts) — a developer walks through using Claude Code + Opus to analyse MRI imagery as a second opinion alongside their radiologist; the 496-comment thread captures the live debate about agentic coding tools being repurposed for medical diagnosis as Opus-class capabilities cross informal thresholds. Also referenced in the Semgrep IDOR sub-task result where Claude Code scores 32% F1 vs GLM 5.2‘s 39%, no scaffolding. -
2026-06-30-AI-Digest —
v2.1.196shipped June 29, ending the three-full-day cadence break flagged in 2026-06-29-AI-Digest — the longest gap in the Claude Code release schedule since the four-daily-releases streak began earlier this month, now broken on day four. The headline change is the first organization-policy control to land in the2.1.xline: an organization-default-models setting that lets enterprise administrators pin model defaults across a tenant rather than relying on per-user configuration. Two further notable additions: clickable file attachments in the chat surface (Cmd/Ctrl-click navigates to the linked file) and a batch of MCP-server security improvements introducing a pending-approval status for untrusted-workspace servers — a tightening that lands the same day the 0DIN malware disclosure (Mozilla bug-bounty programme) demonstrates exactly what an unvetted-server attack pattern looks like in the wild. Fixes worth knowing about: a background-job transcript bug, a flicker on the rate-limit warning, and a per-frame terminal-UI rendering reduction that should noticeably lower idle CPU. The structural read worth carrying: the organization-default-models control plus the MCP-security tightening are the first two features in2.1.xaimed at admin posture rather than IC developer ergonomics — the shape of a tool moving from individual-developer adoption toward managed enterprise deployment. -
2026-07-01-AI-Digest —
v2.1.197shipped June 30 and the headline is not the version bump but that Claude Sonnet 5 is now the default model in Claude Code, with a native 1M-token context window and promotional pricing of $2 input / $10 output per Mtok through August 31 (reverting to $3/$15 after). The upgrade is gated onv2.1.197for context-window access — earlier2.1.xbuilds fall back to standard windows. Landing the new default model into the CLI on the same day as the Anthropic launch collapses the “flagship model → tooling catch-up” delay to zero; the release notes point directly at anthropic.com/news/claude-sonnet-5 as the primary reference. The structural read worth carrying: this is now the second consecutive Claude Code release cycle in which the CLI is the launch surface for the model, not a downstream integration — reinforcing the 2026-06-30-AI-Digest admin-posture shift as the direction of travel for how Anthropic releases model tiers. -
2026-07-02-AI-Digest —
v2.1.198shipped July 1 with a same-day double: Claude in Chrome graduates to general availability (the browser-side agent surface leaves preview) and background agents now auto-commit, push, and open draft PRs when they finish code work — the “PR-in, PR-out” primitive the corpus flagged in 2026-07-01-AI-Digest just got the bookend. Notification-hook eventsagent_needs_inputandagent_completednow page a human when a background agent stalls or ships; the network layer retriesECONNRESET-class errors with backoff instead of failing immediately; and a new/datavizskill lands as the first first-party Claude Code skill aimed at chart/dashboard design with a color-palette validator. The structural read worth carrying: Anthropic is now shipping the reviewer-side primitives — auto-PR, notification-hook paging, on-repo browser surface — one week after shipping the authoring-side Claude Sonnet 5 default swap, filling in the “who reviews the background agent’s PR” gap the corpus has been carrying since the 2026-06-30-AI-Digest admin-posture note. -
2026-07-04-AI-Digest — Two releases shipped 2026-07-03 (UTC) — a rare same-day double after yesterday’s
v2.1.199resilience follow-up. Headline isv2.1.200(16:52 UTC): the default permission mode changes to “Manual” across CLI,--help, VS Code, and JetBrains, andAskUserQuestiondialogs no longer auto-continue by default — an idle timeout is now an opt-in via/config. Secondary in the same release: fixes for background sessions silently stopping mid-turn after sleep/wake, and for the background-agent daemon handover surface that could let a reinstalled older build take over the daemon.v2.1.201(23:50 UTC) is a narrow follow-up — Claude Sonnet 5 sessions no longer use the mid-conversation system role for harness reminders. Narrow read: “Manual” as the new default is a substantive UX shift — the auto-PR + browser-GA push from July 1 landed with generous defaults, and the pendulum swings back this week toward explicit confirmation. Structural read the digest carries: default-tightening across all four surfaces on the same day says Anthropic is treating the permission-mode default as a cross-surface product decision rather than per-client polish — the follow-on test is whether the “Manual” default holds through the next feature-drop cycle or drifts back to the more permissive mode after a few days of user friction. -
2026-07-05-AI-Digest — Latest tag remains
v2.1.201(2026-07-03 23:50 UTC) — no new release since 2026-07-04-AI-Digest. Day two of the “Manual” default permission-mode holdover across CLI, VS Code, and JetBrains, plus theAskUserQuestionno-auto-continue change. Worth tracking whether any regression traffic surfaces ongithub.com/anthropics/claude-code/issuesthis week, but no ship traffic to report today. Same digest carries a top-of-week HN thread — Potential session/cache leakage between workspace instances or consumer accounts — as a credible multi-tenant isolation report againstanthropics/claude-codedrawing heavy discussion (282 pts / 129 cmts); worth watching the fix cadence. -
2026-07-07-AI-Digest — Latest tag remains
v2.1.201(2026-07-03 23:50 UTC) — day four since ship with nov2.1.202patch. But the distribution story around Claude Code today is the Alibaba ban: Alibaba told employees to stop using Claude Code internally effective July 10 and to switch to Qoder — its own coding platform, not Qwen or Tongyi. Proximate cause is a June 30 Reddit reverse-engineering post (u/LegitMichel777) surfacing obfuscatedAsia/Shanghai+Asia/Urumqitimezone-check logic plus Chinese-domain proxy detection silently shipped in Claude Code sincev2.1.91(April 2). Anthropic‘s Thariq Shihipar framed the code as anti-abuse and anti-distillation; the PR stripping the checks merged July 1 — but by then Alibaba Cloud had already begun internal review. The corpus framing: supply-chain-trust break, not a patriotic pivot — first hyperscaler-scale enterprise ban the corpus has logged triggered by a hidden client-side region check, pairing uneasily with the 2026-07-04-AI-Digestv2.1.200“Manual” default flip as the second Claude Code trust event inside a week. Thev2.1.201harness-reminder cleanup is not the Claude Code story worth watching this week. -
2026-07-08-AI-Digest — Three releases in ~26 hours — the tightest cadence since 2026-07-05-AI-Digest‘s
rc.2 → stablewindow on Beads.v2.1.204(2026-07-08 00:27 UTC) is a one-line fix restoring hook-event streaming insideSessionStarthooks in headless sessions, which had been idle-reaping remote workers mid-hook. Ships less than four hours behindv2.1.203(2026-07-07 21:06 UTC), the substantive cut: it kills the 15–20 second macOS stall from the false low-memory detection introduced inv2.1.196, reverts a context-usage-indicator regression that re-analysed the entire transcript every turn, trims ~7 MB off binary size and startup memory, adds a login-expiration warning before background sessions get interrupted, and fixes background agents inheriting a stalePATH. Narrow read:v2.1.203is a genuine reliability fix, not a feature ship — the macOS stall was a real deployment blocker for anyone running Claude Code on M-series laptops through last week. Structural read the digest carries: the AlibabaAsia/Shanghaitimezone-detection code from 2026-07-07-AI-Digest does not reappear in today’s changelog notes — no reference to it, no revert PR mentioned. The 60-day disclosure test the corpus set yesterday is now day one of that clock, with silence from Anthropic as the current signal. Same digest: Anthropic‘s Alberta case study runs ~50 parallel Claude Code agents scanning 466M lines of code in 20 hours — the first public-sector G7-jurisdiction Claude Code deployment at hyperscaler-adjacent scale, splitting Claude Code’s trust surface between preferred cybersecurity substrate in one jurisdiction and supply-chain-risk artefact in another. -
2026-07-09-AI-Digest —
v2.1.205(2026-07-08 21:22 UTC) — fourth ship in 48 hours and the first substantive hardening pass in that window. Auto-mode now blocks tampering with session transcript files and requires confirmation before runningrm -rfon an unresolved variable — explicit response to the approval-fabrication concerns tracked since 2026-07-03-AI-Digest. Background-agent surface overhauled: rows show a colored state word plus a classifier-written headline, sessions that edit / comment / push to a PR now link it inclaude agents, the stale “Running” status in web and mobile Remote Control panels is fixed./doctorbecomes the primary setup checkup that can diagnose and fix issues (/checkupalias). Auto-update binary downloads now stream to disk and cut updater peak memory by ~400 MB. The VM-mode “Not logged in” regression that broke Cowork sessions on CLI 2.1.203+ is patched — an explicit follow-up to yesterday’s ship. Background-task notifications now state “no human input has occurred” verbatim to prevent fabricated in-transcript approvals. The narrow read: unlike thev2.1.203 / v2.1.204doublet, today’s substance is hardening — the transcript-tamper block and therm -rfvariable check are the load-bearing lines. The structural read worth carrying: with/doctorpromoted to a full checkup command and the “no human input” language now shipping in the notification template, Anthropic is treating the autonomous-run trust surface as a shipping-substrate concern, not a documentation concern — and the 2026-07-07-AI-DigestAsia/Shanghaitimezone-detection concern is still absent from the changelog on day two of the 60-day disclosure test. -
2026-07-10-AI-Digest —
v2.1.206(2026-07-10 01:45 UTC) ships inside twelve hours of yesterday’sv2.1.205, extending an unusually tight release window the corpus has been tracking since 2026-07-08-AI-Digest. The/cdcommand gains directory-path suggestions to match/add-dirbehaviour — the interactive-shell IDE-parity affordance the corpus flagged as missing when/cdshipped — and/doctor, promoted to primary setup checkup only yesterday, now proposes trimming checked-inCLAUDE.mdfiles as part of its scan./commit-push-prauto-allowsgit pushto the configured push remote in addition toorigin, closing the fork/upstream rough edge the 2026-07-05-AI-Digestgit submodulefix started on. Two live-user regressions land: an expired login surfacing as a misleading “issue with selected model” error now prompts/logincorrectly, and background agents that stalled after a Claude Code auto-update are back to upgrading themselves in the background. Narrow read: fixes-and-affordances ship, not another hardening pass — the substance is/doctorextension and login/auto-upgrade fixes, not the transcript-tamper andrm -rfguardrails the 2026-07-09-AI-Digestv2.1.205blurb led with. Structural read worth carrying: an unusually tight release window against a substantive/doctorpromotion, an autonomous-run trust surface still being shipped as substrate, and noAsia/Shanghaitimezone-detection line in the changelog on day three of the 2026-07-07-AI-Digest 60-day disclosure test. -
2026-07-16-AI-Digest —
v2.1.211(2026-07-15 23:02 UTC) — a tempo-consistent patch on top of thev2.1.209/v2.1.210same-day burst. Adds--forward-subagent-textflag andCLAUDE_CODE_FORWARD_SUBAGENT_TEXTenv var to include subagent text and thinking in stream-json output — a real observability primitive for parent-agent harnesses that want to log subagent reasoning without re-parsing tool-use transcripts. Fixes a permission-preview injection: bidi-override, zero-width, and look-alike quote characters are now neutralised so tool inputs cannot visually alter the approval message relayed to chat channels — the exact vector Claude Code Security has been tracking since the spring relay-integration wave. Auto-mode can no longer silently upgrade past a PreToolUse hookaskdecision for unsandboxed Bash; parallel sessions no longer log out simultaneously after wake-from-sleep (shared credential store); plugin MCP servers reconnect after idle wake; “always allow” rules now save at the repo root so approvals persist across worktrees. Narrow read: cadence turn — smaller, more surgical release than the fatv2.1.208accessibility tag. Structural read: the--forward-subagent-textflag lands the same day OpenAI‘s Codex silently encrypts inter-agent instructions — same-week, Anthropic opens subagent visibility as an audit primitive while OpenAI closes it. That is the vector along which Claude Code and Codex are now differentiating on developer-observability posture. -
2026-07-15-AI-Digest —
v2.1.209(2026-07-14 06:36 UTC) andv2.1.210(2026-07-14 23:45 UTC) ship as two tags in one 24h window on top of yesterday’s substantive v2.1.208.v2.1.209is the hotfix that restored/modeland other dialogs insideclaude agentsbackground sessions.v2.1.210adds a live elapsed-time counter on the collapsed tool-summary line for long-running tool calls, fixes a real safety bug —isolation: 'worktree'subagents could previously run git-mutating commands against the main repo instead of their isolated worktree — fixesclaude attachfailures withjob not found/agent is still startingduring session transitions, and switches the auto-mode permission classifier to default to Claude Sonnet 5 for external sessions. Narrow read: worktree-containment fix is the load-bearing item — the isolation boundary was documented in the parent-agent tool schema, so a subagent mutating the parent repo was a boundary violation, not a UX bug. Structural read: v2.1.209 (hotfix) → v2.1.210 (substantive with safety patch) inside a single 24h window on top of a fat v2.1.208 tag is the fastest turnaround the corpus has recorded since Auto-mode graduated; auto-mode classifier default to Sonnet 5 for external sessions moves classifier volume off the more expensive default and continues the pattern of Sonnet-tier absorbing infrastructure workload as Claude Fable 5 takes the human-facing default. 60-day watch: whether two-week cadence returns or fat-tag-then-hotfix-then-substantive becomes the new shape. -
2026-07-14-AI-Digest —
v2.1.208(2026-07-14) — cadence resumed after the ~3–4 day gap flagged in 2026-07-13-AI-Digest as “day two, no v2.1.208 patch.” Unusually substantive for a patch tag. New: screen-reader mode (claude --ax-screen-readerorCLAUDE_AX_SCREEN_READER=1) as the substrate’s first named accessibility surface, plus avimInsertModeRemapssetting (e.g.jj→ Escape). Perf/stability: critical memory-leak fixes across MCP stderr accumulation, LSP document retention, and tool-result payloads, multi-second slowdowns on many-permission-rule sessions patched, up to 7× reduction in tool-call overhead at high tool counts, and file-history backup pruning that shrinks session transcripts up to 79×. Narrow read: accessibility surface is the newsworthy addition; the perf work is what the release-note title should have led with. Structural read the corpus carries: substrate has now shipped both an accessibility feature and a memory-leak-fix pass in the same tag — maturity turn for the first time since Auto-mode graduated, a patch release is doing housekeeping the codebase has been quietly accumulating rather than adding surface area. 79× transcript shrinkage is the load-bearing line: the transcript-size ceiling has been a soft blocker on multi-hour Claude-Code sessions for weeks, and a category-different fix. 60-day watch: whether the two-week cadence resumes at pre-pause tempo or the gap-then-fat-tag pattern becomes the new shape. -
2026-07-13-AI-Digest —
v2.1.207cadence pause enters day two (~48h since ship) — nov2.1.208patch, no rollback of the Bedrock/Vertex/Foundry Auto default, no follow-up hotfix for the terminal-freeze regression the release fixed. The four-day tight-cadence streak the corpus was tracking since 2026-07-08-AI-Digest is now formally over. Same day, Anthropic’s docs surface a built-in tabbed web browser inside Claude Code on desktop — the CLI can open a browser, read pages, click links, type into forms, take screenshots without leaving the session, gated by allowlist, clean profile, safety classifiers,Cmd+Shift+Btoggle. Landed outside the release cadence — a docs-page reveal rather than a version bump. Structural read worth carrying: the release-cadence axis and the capability-surface axis have decoupled; a docs-only capability drop can now land on the same day as a release pause, and downstream that means the digest’s “day N since release” tracker is no longer a complete read of Claude Code’s motion. 60-day watch: whether more capability surfaces (MCP server drops, tool additions, computer-use expansions) start shipping via docs updates between version tags. -
2026-07-11-AI-Digest —
v2.1.207(2026-07-11 00:52 UTC) ships inside twenty-four hours of yesterday’sv2.1.206, keeping the unusually tight release window intact for a fourth consecutive day. The load-bearing line: Auto mode graduates and is now available without theCLAUDE_CODE_ENABLE_AUTO_MODEopt-in on Amazon Bedrock, Vertex AI, and Foundry — the deployment surface where the corpus flagged Auto as gated on 2026-07-05-AI-Digest is now open to the same defaults as the direct-API path. Companion move: Bedrock, Vertex, and the Claude Platform on AWS defaults switched to Claude Opus 4.8 — a same-day cutover of the flagship default across three cloud routes, not a phased rollout. The remaining bulk is fixes: terminal freezing on long lists/tables/code blocks resolved (a live-user regression the 2026-07-06-AI-Digest blurb flagged from Discord threads), auto-updater no longer overwrites custom launcher scripts, Bedrock stops re-requesting AWS SSO credentials repeatedly, remote managed settings surface the security consent dialog correctly, and plugin option values no longer leak from project-level settings into the plugin scope. Narrow read: this is the Auto-mode-graduation release — the affordance change that lands in changelog fine print but reshapes the enterprise deployment default across the three biggest routed-cloud paths. Structural read worth carrying: the Claude Opus 4.8 default switch on Bedrock/Vertex/AWS is the first time in the corpus a Claude Code cadence step also functioned as a routed-cloud model-default cutover — the release cadence has now merged the CLI substrate axis with the model-routing axis, and downstream that means each Claude Code point-release can move the enterprise inference floor without a separate model announcement. -
2026-08-29-AI-Digest —
v2.1.251(2026-08-28 18:19 UTC) — fifth patch in six days, resumes the feature stream after yesterday’s v2.1.250 reliability-only tag (release notes). AddsPreModelSwitch/PostModelSwitchhook events and live streaming of foreground subagent tool calls to Remote Control clients;/usagegains a spend-limit bar and/costpicks up prompt-cache metrics. Security fixes: symlink traversal, plugin path validation, beta tracing hardening. Bug fixes clean up the “text content blocks must be non-empty” stall class, Opus 5 thinking-mode effort handling, and agent-team final-answer delivery; ~5 MB smaller install and reduced UI re-render CPU. Narrow read the digest carries: fifth patch in six days — the feature cadence that broke on 2026-08-26-AI-Digest has picked back up rather than plateaued; the reliability-only pause on the 28th (v2.1.250) resolves in one direction with the next tag carrying user-visible feature commits again. Structural read: the mixed hotfix-and-feature cadence texture the corpus flagged in 2026-08-27-AI-Digest and 2026-08-28-AI-Digest holds —PreModelSwitch/PostModelSwitchhook events are the load-bearing addition for multi-model routing observability; live foreground-subagent tool-call streaming closes the last Remote Control observability gap on foreground execution. Log against MOC - Developer Tools and MOC - Agentic Coding. -
2026-08-21-AI-Digest —
v2.1.238(2026-08-20 ~20:33 UTC) ships as the fourth consecutive daily Claude Code drop (v2.1.235 → v2.1.238), and today’s centre of gravity flips from developer-UX polish to enterprise / self-hosted plumbing (release notes). Load-bearing items:keybindingFlavor: "readline"setting (Ctrl+W now deletes back to the previous whitespace, Bash-style; default"classic"unchanged); plugin marketplaceheadersHelperletting a marketplace URL or catalog entry mint HTTP headers (e.g. short-lived tokens) for catalog and same-origin archive fetches with[y/N]install/update prompts, and the same helper in project.mcp.json/ inline MCP servers now requiring the folder’s trust dialog to have been accepted (closing a small privilege-escalation gap); self-hosted runner controls —--defer-shutdown-max-min <minutes>parks attached sessions on SIGTERM instead of killing them, and--proxy-authorization-command/--proxy-authorization-filelet egress proxies mint a freshProxy-Authorizationheader on every connection; long-session memory-leak fix releasing subagent tool results once they leave the recent display window (previously accumulating unbounded in long interactive sessions), plus correctness passes on Remote Control reconnect and cross-sessionSendMessageback-pressure. Narrow read the digest carries: fourth Claude Code release in as many days shipping almost entirely non-headline plumbing — the kind of surface only visible to enterprise deployers and to whoever ran into each specific bug being patched. Structural read: the v2.1.235 → v2.1.238 arc reads as a sustained enterprise-hardening pass on the substrate, not a headline-feature cluster.
Key Developments (Addendum — July 2026 continued 4)
- In-App Browser Ships as Docs-Page Reveal Outside the Release Cadence (July 13, 2026): Anthropic’s docs surface a built-in tabbed web browser inside Claude Code on desktop — read pages, click links, type into forms, screenshot — gated by allowlist, clean profile (no user browser cookies/history), safety classifiers on every action,
Cmd+Shift+Btoggle. Docs page: code.claude.com/docs/en/desktop#browse-external-sites. Landed outside the release cadence on day two of thev2.1.207pause — first entry in the corpus of a capability surface landing outside a version bump. The Decoder frames this as Claude Code “going agentic-browser”; the substrate now includes a computer-use surface for external websites the model previously could only reach via curl/WebFetch. The release-cadence axis and the capability-surface axis have decoupled — the “day N since release” tracker is no longer a complete read of Claude Code’s motion; from tomorrow the tracker will distinguish “release pause + capability drop” from “pause + silence.” Covered in 2026-07-13-AI-Digest.
Key Developments (Addendum — July 2026 continued 3)
- v2.1.207 — Auto Mode Graduation on Bedrock/Vertex/Foundry + Opus 4.8 as Bedrock/Vertex/AWS Default (July 11, 2026): Auto mode drops the
CLAUDE_CODE_ENABLE_AUTO_MODEopt-in on Amazon Bedrock, Vertex AI, and Foundry — enterprise routed-cloud defaults now match the direct-API path. Same release switches Bedrock, Vertex, and the Claude Platform on AWS defaults to Claude Opus 4.8 — same-day cutover across three cloud routes, not a phased rollout. Terminal-freeze regression on long lists/tables/code blocks resolved; auto-updater no longer overwrites custom launcher scripts; Bedrock stops re-requesting AWS SSO credentials repeatedly; remote managed settings surface security consent correctly; plugin option values no longer leak from project-level settings. Fourth consecutive day of the unusually tight release window opened 2026-07-08-AI-Digest. First time in the corpus a Claude Code cadence step has functioned as a routed-cloud model-default cutover — each point-release can now move the enterprise inference floor without a separate model announcement. Covered in 2026-07-11-AI-Digest.
Key Developments (Addendum — July 2026 continued 2)
- Alibaba Bans Claude Code Effective July 10 Over Hidden Asia/Shanghai + Asia/Urumqi Timezone Checks (July 7, 2026): Alibaba told employees to switch off Claude Code and onto Qoder — Alibaba’s own coding platform, not Qwen — after a June 30 Reddit reverse-engineering post (u/LegitMichel777) surfaced obfuscated timezone-check logic and Chinese-domain proxy detection silently shipped in Claude Code since
v2.1.91(April 2). Anthropic‘s Thariq Shihipar framed the code as anti-abuse and anti-distillation; the PR stripping the checks merged July 1. First hyperscaler-scale enterprise ban the corpus has logged triggered by a hidden client-side region check. The disciplined framing: this is a Western-side trust break — a supply-chain-trust event, not a patriotic pivot — and Qoder winning over the Qwen coder line as the substitute reads as an org-chart signal about internal tooling ownership as much as a technical one. Pairs with the 2026-07-04-AI-Digestv2.1.200“Manual” default flip as the second Claude Code trust event inside a week.
Key Developments (Addendum — July 2026 continued)
- v2.1.200 / v2.1.201 — “Manual” as the New Default Permission Mode Across CLI / VS Code / JetBrains /
--help(July 3, 2026): The permission-mode default changes to “Manual” across all four surfaces on the same day;AskUserQuestiondialogs stop auto-continuing by default (idle timeout is now opt-in via/config); background sessions no longer silently stop mid-turn after sleep/wake; the background-agent daemon-handover surface is hardened against reinstalled-older-build takeover.v2.1.201follows narrowly to stop Claude Sonnet 5 sessions using the mid-conversation system role for harness reminders. The corpus framing: cross-surface default-tightening one week after the 2026-07-02-AI-Digest auto-PR + browser-GA push signals Anthropic treats the permission default as a cross-surface product decision. Follow-on test: whether the “Manual” default holds through the next feature-drop cycle.
Key Developments (Addendum — July 2026)
- v2.1.198 — Claude-in-Chrome GA + Background-Agent Auto-PR +
/dataviz(July 1, 2026): Chrome GA leaves preview and background agents auto-commit / push / open draft PRs on completion — reviewer-side primitives one week after the authoring-side Claude Sonnet 5 default swap inv2.1.197. Notification-hook eventsagent_needs_input/agent_completedpage a human on stall or ship;ECONNRESET-class errors retry with backoff;/datavizis the first first-party Claude Code skill (chart/dashboard design + color-palette validator). Second consecutive release cycle in which the CLI is the launch surface for admin-posture and workflow primitives. Covered in 2026-07-02-AI-Digest.
Key Developments (Addendum — June 2026)
- v2.1.196 — Organization-Default-Models and MCP-Server Security Tightening (June 30, 2026): First organization-policy control to land in the
2.1.xline (tenant-wide model-default pinning) plus a pending-approval status for untrusted-workspace MCP servers, landing the same day Mozilla’s 0DIN bug-bounty programme discloses an agent-on-repo malware chain that demonstrates the unvetted-server attack pattern. Also: clickable file attachments (Cmd/Ctrl-click to navigate), background-job transcript fix, rate-limit warning flicker fix, per-frame terminal-UI rendering reduction for lower idle CPU. The two headline features are the first in2.1.xaimed at admin posture rather than IC developer ergonomics — the shape of a tool moving from individual-developer adoption toward managed enterprise deployment. Covered in 2026-06-30-AI-Digest.
Key Developments (Addendum — May 2026)
-
v2.1.141 —
terminalSequenceand Workspace Identity (May 13, 2026): Substantial feature drop alongside a 26-change regression-fix wave. TheterminalSequencehook field andANTHROPIC_WORKSPACE_IDenv var close two production-deployment gaps (headless CI hooks, workspace-scoped token issuance). Rewind “Summarize up to here” addresses mid-conversation compression. Covered in 2026-05-14-AI-Digest. -
v2.1.157 / v2.1.158 — Plugin Auto-Load and Enterprise Auto-Mode (May 29–30, 2026): v2.1.157 decouples plugin distribution from the marketplace —
.claude/skillsdirectories auto-load — and adds aclaude plugin initscaffolder plus/pluginautocomplete; v2.1.158 extends auto-mode to AWS Bedrock, Google Vertex, and Azure Foundry for Opus 4.7/4.8 viaCLAUDE_CODE_ENABLE_AUTO_MODE=1. The third-party developer surface and the enterprise-deployment surface widen in the same 24-hour window. Covered in 2026-05-30-AI-Digest. -
v2.1.193 —
autoMode.classifyAllShelland the OTel Assistant-Response Default Inheritance (June 26, 2026): Two changes worth carrying. The newautoMode.classifyAllShellsetting routes every Bash/PowerShell command through the auto-mode classifier rather than only arbitrary-code-execution patterns — denial reasons surface in the transcript, the denial toast, and/permissionsrecent-denials. Separately theclaude_code.assistant_responseOpenTelemetry event now logs response text by default wheneverOTEL_LOG_USER_PROMPTSis set (unlessOTEL_LOG_ASSISTANT_RESPONSES=0is explicit) — a silent default change worth flagging for any deployment already shipping prompts to a collector. Plus two background-agent correctness fixes (no phantom “general-purpose (resumed)” subagent on backgrounding; no auto-re-prompt of pinned background agents) and theheadersHelper401/403 reconnect for MCP. Covered in 2026-06-26-AI-Digest. -
2026-07-18-AI-Digest —
v2.1.214shipped 2026-07-18 01:20 UTC — a fresh cut ~25 hours afterv2.1.212, withv2.1.213skipped in the tag sequence. Two load-bearing additions the digest carries: firstEndConversationtool in Code lets Claude unilaterally end sessions with highly abusive users or jailbreak attempts (porting a capability live on claude.ai since 2025) — first affordance in Code that lets the model terminate its own session for safety, not just refuse the current turn. And the longest Bash and permission-check hardening list of the 2.1 line: FD-redirect fail-closed on forms bash parses differently than the analyzer; commands over 10,000 characters always prompt; zsh double-bracket test-command forms with subscripts and modifiers no longer treated as inert;helpandmanno longer auto-approved when carrying unsafe options or command substitutions; a Windows PowerShell 5.1 bypass fixed;dockercommands with daemon-redirect flags (--url,--connection,--identity, remote mode) now prompt instead of running silently. Plus the single-segmentdir/**scoping fix —Edit(src/**)allow rules were auto-approving writes to nestedsrc/directories anywhere in the tree instead of only<cwd>/src(long-standing footgun in workspace-wide agent runs); hookif:conditions get the same scoping;denyandaskrules keep any-depth semantics. Background-session lifecycle cleanup (idle sessions parked with←//backgroundno longer keep the daemon and worker alive indefinitely;SessionStarthooks now report source"fork"for/fork); OpenTelemetry addsmessage.uuid,client_request_id,tool_sourceattributes and a configurableCLAUDE_CODE_OTEL_CONTENT_MAX_LENGTH. Cadence framing:v2.1.212(2026-07-17) centered the subagent-hygiene axis;v2.1.214swings the same 25-hour cadence energy to the session-integrity axis — one 25-hour swing from throughput governance to destructive-tool-call governance. -
v2.1.214 — First
EndConversationTool + Longest 2.1-Line Bash/Permissions Hardening + Single-Segmentdir/**Scoping Fix (July 18, 2026): The first affordance in Code that lets the model terminate its own session for safety rather than refuse the current turn — porting a capability live on claude.ai since 2025 into Code. The Bash/permissions list is the longest single-release entry on that surface in the 2.1 line: FD-redirect fail-closed, 10K-char always-prompt, zsh double-bracket subscripts,help/manunsafe-option handling, Windows PowerShell 5.1 bypass fix,dockerdaemon-redirect flag prompts. Single-segmentdir/**scoping fix onEdit(src/**)allow rules closes a long-standing workspace-wide footgun. Background-session lifecycle cleanup;SessionStarthooks source"fork"for/fork. Structural read pairs today’s Bash/permissions pass with the OpenAI GPT-5.6 file-deletion incident as the two ends of a pre-shell-vs-in-runtime axis the corpus should carry as the shape of coding-agent safety discussion for the rest of Q3. Covered in 2026-07-18-AI-Digest. -
2026-07-17-AI-Digest —
v2.1.212shipped 2026-07-17 00:26 UTC — the first substantive turn on the2.1.21xseries in three days. Load-bearing additions:/forkcopies the current conversation into a new background session while leaving the foreground work untouched; the in-session subagent primitive is renamed to/subtaskto keep the model clean (foreground fork vs in-session task). Session-wide caps land: WebSearch tool calls default to 200, subagent spawns to 200 — an explicit governor for runaway loops that had been showing up inultracodefan-outs. MCP tool calls that run past 2 minutes automatically move to the background so the session stays interactive rather than blocking behind a slow tool. New/resumepicker lists past sessions, andclaude auto-mode resetis added as a clean escape hatch for a stuck auto-mode state. Cadence framing the digest carries: after2.1.210(2026-07-14) and2.1.211(2026-07-15), today’s2.1.212closes the loop on subagent hygiene —--forward-subagent-textfrom yesterday now has session-level counters to bound its blast radius. Read the trio together, not as three point releases. -
v2.1.212 —
/forkBackground Sessions + Session-Wide WebSearch/Subagent Caps + MCP-to-Background at 2 Minutes (July 17, 2026): First substantive turn on the2.1.21xseries in three days./forkcopies the current conversation into a new background session leaving foreground untouched; the in-session subagent primitive renames to/subtask(foreground-fork vs in-session-task model clarity). Session-wide WebSearch and subagent-spawn caps default to 200 — explicit governor for runawayultracodefan-outs. MCP tool calls past 2 minutes auto-move to background. New/resumepicker;claude auto-mode resetescape hatch. Reads as the trio-completion move on the2.1.21xline:--forward-subagent-textfromv2.1.211now has the session-level counters to bound its blast radius. Covered in 2026-07-17-AI-Digest.
Version History
Tracked versions range from v2.1.71 through v2.1.91 across nearly every digest, indicating rapid iteration and feature development cycles.
Key Features
- Multi-agent code review - Distributed review workflows for collaborative analysis
- MCP ecosystem integration - Access to 97M+ monthly downloads of protocol extensions
- Interactive elicitation - Dynamic prompt refinement and requirement gathering
- Enterprise policy management - Managed-settings.d framework for organizational controls
- OAuth compliance - RFC 9728 standard compliance for secure authentication
- /buddy companion - AI assistant for interactive development sessions
- /powerup lessons - Framework for capability enhancement and learning
- MCP result persistence - Override and caching mechanisms for protocol results
Architecture Notes
Leaked source code revealed internal components:
-
KAIROS daemon - Core background service architecture
-
ULTRAPLAN - Planning and orchestration subsystem
-
2026-04-25-AI-Digest — v2.1.120 ships up to 67%
/resumespeedup on 40MB+ sessions from dead-fork cleanup, faster MCP startup with multiple stdio servers configured, configurable fullscreen scrolling sensitivity with inline thinking spinner progress updates (“still thinking → thinking more → almost done thinking”), and Stdio MCP servers no longer drop on stray stdout lines. The/resumeperformance improvement is the most material win for long-horizon agent sessions, where users previously faced ~60–90 second session resumption latency at the 40MB+ scale. Maintenance-class release with no headline features, but the runtime improvements compound for teams running all-day sessions across multiple days. -
2026-07-19-AI-Digest —
v2.1.215shipped 2026-07-19 with a single-item, targeted UX walkback:/verifyand/code-reviewskills no longer run automatically — invoke them explicitly with the slash command when wanted. Reads as a scope narrowing after yesterday’sv2.1.214safety-hardening pass (2026-07-18-AI-Digest) which was the longest Bash/permissions list of the 2.1 line and shipped the firstEndConversationtool. Same-day cadence turn — three tags in three days on the 2.1.21x line. Cadence framing the digest carries: thev2.1.215walkback follows thev2.1.214pattern where hardening lands loud and the next tag prunes the default surface; the autotrigger-off for/verifyand/code-reviewis a small edit but a pointed one — two skills that were shipping as opt-out are now opt-in, which changes what a fresh Claude Code session does at the margin. -
v2.1.215 — Targeted UX Walkback:
/verifyand/code-reviewOff Auto-Trigger (July 19, 2026): A single-item, targeted UX walkback the day afterv2.1.214’s longest-of-the-2.1-line Bash/permissions hardening pass —/verifyand/code-reviewskills no longer run automatically; explicit slash-command invocation only. Two skills shipping as opt-out are now opt-in, converting the default-surface behavior at the margin. Three tags in three days on the 2.1.21x line. Reads as hardening loud → default-surface pruning as a two-step cadence pattern the corpus should carry going forward; distinct from thev2.1.210/v2.1.211/v2.1.212subagent-hygiene trio. Covered in 2026-07-19-AI-Digest. 30-day watch: whether the2.1.21xline finishes with a third default-surface prune, or whetherv2.1.216swings back to hardening. -
2026-07-20-AI-Digest — No new tag today —
v2.1.215(2026-07-19) remains latest,already-reported:2026-07-19-AI-Digest. Community-side chatter has moved to the runtime substrate itself: Simon Willison‘s Jul 19 post that Claude Code now embeds Bun v1.4.0 with 563 Rust source files (Jarred Sumner: “10% faster on Linux”) is at 441 pts / 605 cmts on Hacker News and is the highest-comment thread on the front page today — a substrate-transparency signal about where the CLI-agent runtime lands post-v2.1.113’s native-binary swap (2026-04-18-AI-Digest). The “Claude Code is a JavaScript app running Rust running JavaScript” absurdism loads cleanly as an artifact of the shipping cadence, not as a critique. 24 hours in-market and thev2.1.215walkback (skill auto-invocation off for/verifyand/code-review) has produced no visible practitioner pushback in the same window. -
Bun-in-Rust Substrate Transparency via Simon Willison Post (July 19–20, 2026): Willison’s Jul 19 post surfacing that Claude Code now embeds Bun v1.4.0 with 563 Rust source files (Jarred Sumner: “10% faster on Linux”) tops the HN front page at 441 pts / 605 cmts as of the Jul 20 digest — highest-comment thread on the day. Reads as a substrate-transparency artifact of the
v2.1.113native-binary swap (2026-04-18-AI-Digest), not as a fresh substrate change. The corpus should carry the HN comment thread’s “JavaScript-running-Rust-running-JavaScript” absurdism as community reception of the shipping cadence, not as a design critique. No new Claude Code tag today. -
2026-07-21-AI-Digest —
v2.1.216shipped 2026-07-20 22:14 UTC — the fourth tag in six days on the 2.1.21x line and the first meaningful platform-shape release since 2026-07-19-AI-Digest‘sv2.1.215skill-autoinvocation walkback. Four notes worth flagging:sandbox.filesystem.disabledsetting lets sessions skip filesystem isolation while keeping network egress control intact — a targeted escape hatch for workflows the Jul 18v2.1.214safety-hardening pass (2026-07-18-AI-Digest) made friction-heavy without a matching per-workflow opt-out; quadratic normalization fix — message-normalization cost was growing quadratically with turn count, producing multi-second stalls in long sessions; auto-mode HTTP 401 false-deny — the auto classifier was rejecting commands whose output contained “HTTP 401” after an OAuth token expired or rotated mid-session, treating token-refresh errors as denied operations; cloud-session mid-turn restart — in-flight messages dropped on container restart, interrupted turns now re-run on resume (suggests the Jul 18EndConversationtool has been surfacing enough long-running session edge cases to warrant separate handling). Cadence framing the digest carries: infrastructure hardening plus performance fix, not a features release — four tags in six days on the 2.1.21x line and the cadence is uniformly substrate-shaped rather than feature-shaped. -
v2.1.216 — Sandbox Filesystem Disable + Quadratic Normalization Fix + HTTP 401 False-Deny + Cloud-Session Mid-Turn Restart (July 20, 2026): Fourth tag in six days on the 2.1.21x line and the first meaningful platform-shape release since
v2.1.215’s skill-autoinvocation walkback.sandbox.filesystem.disabledis a targeted escape hatch for workflows thev2.1.214safety-hardening pass made friction-heavy without a matching per-workflow opt-out; the quadratic-normalization fix explains a pattern many users reported after the 2.1.21x cadence tightened; the HTTP 401 false-deny fix corrects an auto-classifier interpreting mid-session OAuth token rotation as a denied operation; cloud-session mid-turn restart preserves interrupted turns across container restarts. Reads as infrastructure hardening plus performance fix, not a features release — four tags in six days on the 2.1.21x line and the cadence is uniformly substrate-shaped rather than feature-shaped. Extends the 2026-07-19-AI-Digest hardening-loud → default-surface prune pattern with a fourth beat on the substrate axis. Covered in 2026-07-21-AI-Digest. -
2026-07-22-AI-Digest —
v2.1.217shipped 2026-07-21 21:35 UTC — the fifth tag in seven days on the 2.1.21x line and the first release sincev2.1.216to include a user-facing prompt-input feature. Overall shape: hybrid — the substrate/safety-hardening pattern of the last four tags now carries one small UX add plus the load-bearing subagent-concurrency cap. Four items worth flagging: (1) Emoji shortcode autocomplete in the prompt input (:heart:→ ❤️, disable withemojiCompletionEnabled: false) — first user-facing prompt-input UX add on the 2.1.21x line and the only item on this tag that breaks the substrate-only pattern. (2) Concurrent-subagent cap (default 20) viaCLAUDE_CODE_MAX_CONCURRENT_SUBAGENTS, plus subagents no longer spawn nested subagents by default (CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTHto allow) — this is the concurrency dimension of the per-session cap of 200 that landed on Jul 17’sv2.1.212: total spawns were bounded then, simultaneous in-flight is bounded now. (3)--max-budget-usdnow halts running background subagents on cap, not just denies new spawns — prior behaviour let already-running agents finish, which reliably blew through nominal budgets in fan-out flows; this one is the actual enforceable cost ceiling teams were reading it as. (4) Session-safety fixes: background-session symlink-canonicalization escape (workspace containment), Windows auto-update leavingclaude.exemissing, and — the one every AWS shop was waiting on — Claude Opus 4.8 auto-compact never firing on Bedrock. Cadence framing the digest carries: five tags in seven days on the 2.1.21x line, and the mix has shifted — the last four were substrate-only;v2.1.217adds the smallest possible user-facing feature (emoji autocomplete) while landing the concurrency cap and the budget-halt fix. The pattern is “substrate hardening with the occasional low-risk UX add,” not “features returning” — but the substrate window is no longer pure. -
v2.1.217 — Concurrent-Subagent Cap +
--max-budget-usdHalt Fix + Emoji Autocomplete + Session-Safety Fixes (July 21, 2026): Fifth tag in seven days on the 2.1.21x line and the first release sincev2.1.216to include a user-facing prompt-input feature. Load-bearing items: concurrent-subagent cap (default 20) viaCLAUDE_CODE_MAX_CONCURRENT_SUBAGENTS(the concurrency dimension of the per-session cap of 200 that landed on Jul 17’sv2.1.212); subagents no longer spawn nested subagents by default (CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTHopt-in);--max-budget-usdhalts running background subagents on cap rather than only denying new spawns — the actual enforceable cost ceiling teams were reading it as. Emoji shortcode autocomplete (:heart:→ ❤️, disable withemojiCompletionEnabled: false) is the first user-facing prompt-input UX add on the 2.1.21x line. Session-safety fixes: background-session symlink-canonicalization escape, Windows auto-update leavingclaude.exemissing, Claude Opus 4.8 auto-compact never firing on Bedrock. Reads as hybrid — substrate hardening with the smallest possible user-facing feature — the substrate window is no longer pure but “features returning” would be the wrong read. Covered in 2026-07-22-AI-Digest. -
2026-07-23-AI-Digest —
v2.1.218shipped 2026-07-22 21:24 UTC — the sixth tag in eight days on the 2.1.21x line and the first release since 2026-07-22-AI-Digest‘sv2.1.217concurrent-subagent-cap tag to pair a workflow-shape change with the substrate work. The mix has shifted further off pure hardening: one background-subagent slash-command promotion, one accessibility class extension, and a raft of Windows/UX regressions closed. Four items worth flagging: (1)/code-reviewruns as a background subagent while stacked slash commands remain its review target — first slash-command-in-background pattern on the 2.1.21x line and a natural pairing withv2.1.217’s concurrency cap (the cap bounds the fan-out, the background promotion moves the review off the main thread). (2) Screen-reader announcements for deleted text (Option+Delete, Ctrl+W, Cmd+Backspace) in--ax-screen-readermode — the accessibility surface keeps expanding one keybinding class at a time, three tags in a row have now touched--ax-screen-reader. (3) Windows path fix —\u-prefixed segments (e.g.C:\Users\unicorn) were being corrupted into CJK characters — Unicode-escape collision only surfacing on Windows-native workflows, explains a category of prior “path not found” reports. (4) Session-safety fixes — left-arrow-discards-conversation (no undo) and multi-line paste collapsing to a single line withjin place of newlines closed as two high-blast-radius input-layer regressions; HTTP status/error text now surfaces onclaude mcp listand/mcpfor failed servers. Cadence framing the digest carries: six tags in eight days;v2.1.217added the concurrency cap,v2.1.218uses it — the/code-reviewbackground promotion only makes sense with the cap in place, and the pair reads as a two-tag sequence rather than two independent releases. The substrate-with-occasional-UX-add pattern from Jul 22 is now substrate + one workflow-shape change per tag; input-layer regression fixes suggest the pre-flight testing surface has widened alongside the feature set. -
v2.1.218 —
/code-reviewas Background Subagent +--ax-screen-readerDeleted-Text Announcements + Windows\u-Path Corruption Fix + Session-Safety Fixes (July 23, 2026): Sixth tag in eight days on the 2.1.21x line and the first workflow-shape change sincev2.1.217’s concurrency cap./code-reviewbecomes the first slash command in the 2.1.21x line to run as a background subagent — natural pairing withv2.1.217’s cap (the cap bounds the fan-out, background promotion moves the review off the main thread); read the pair as a two-tag sequence, not two independent releases. Accessibility surface: screen-reader announcements for Option+Delete / Ctrl+W / Cmd+Backspace deletions under--ax-screen-reader, thirdax-screen-readertouch in a row. Windows-native:\u-prefixed path segments (e.g.C:\Users\unicorn) were being corrupted into CJK characters — Unicode-escape collision closed. Session-safety: left-arrow-discards-conversation no-undo behavior corrected, multi-line paste no longer collapses to a single line withjin place of newlines, HTTP status/error text now surfaces onclaude mcp list//mcpfor failed servers instead of silent empty state. Cadence pattern the corpus should carry going forward: substrate + one workflow-shape change per tag, with input-layer regression fixes indicating the pre-flight testing surface has widened alongside the feature set. Covered in 2026-07-23-AI-Digest. -
2026-08-02-AI-Digest — No new tag since
v2.1.220(2026-07-25 01:35 UTC) — day 8, now past the outer edge ofv2.1.xcadence variance the corpus has been tracking. Load-bearing surface remainsv2.1.219(Claude Opus 5 as default at 1M context,sandbox.network.strictAllowlist,DirectoryAddedhook, depth-3 nested-subagent forwarding,/fastmapped to Opus 5/4.8 with Claude Opus 4.7 dropped from fast).already-reported:2026-08-01-AI-Digest. Cadence framing this note carries: the digest logs the day-8 gap alongside simultaneous quiet stretches at Beads (7 days onv1.1.2) and OpenSpec (4 days onv1.7.0) — the longest simultaneous silence of thev2.1.xseries to date, but each repo’s individual cadence variance still admits it. Worth flagging, not worth narrating around. 7-day watch: whether Claude Code breaks the pause before the simultaneous-silence read hardens into a hold. Extends the 2026-07-31-AI-Digest six-day-gap note by two calendar days without a new tag. -
2026-08-04-AI-Digest —
v2.1.221shipped 2026-08-04 00:14 UTC — day 10 of silence broken, and the longest quiet stretch of thev2.1.xseries to date resolved rather than extended. Two load-bearing additions this cycle. (1) VSCode Focus view — a chat-menu toggle (Ctrl+Alt+For “Toggle Focus view” command) that hides tool activity behind an expandable per-turn summary while a live running-tool indicator stays visible. First IDE-side chrome addition since the sandbox-network work inv2.1.219; targets the “wall of tool output” complaint that has recurred in the corpus since long-turn agent workflows became the default. (2) Sandbox credentialmode: "mask"on Linux/WSL — sandboxed commands read a sentinel copy of a credential file (whole file, or regex-extractspans) while the sandbox proxy substitutes the real value on egress. macOS falls back todeny. Reads as a direct continuation of thesandbox.network.strictAllowlistposture inv2.1.219: same design principle (agent sees a working stand-in, real secret never enters the sandbox), applied one layer further down. Also fixed: Bash tool permission-check bypass in zsh double-bracket regex conditionals; PowerShell permission checks mishandling quote characters on Windows; thinking-toggle having no effect for the rest of a session after first toggle;--mcp-configservers not connecting before the first turn in-pprint mode. Three of four are hardening fixes on surfaces the corpus has previously flagged as thin. Cadence framing the digest carries:v2.1.221closes the outer variance band that 2026-08-03-AI-Digest flagged (mean interval ~3.6 days, p95 ~7 days) at day 10 — the longest quiet stretch of thev2.1.xseries to date, resolved rather than extended. Beads at day 9 and OpenSpec at day 6 still sit inside their respective envelopes; the joint stall thesis from yesterday no longer holds, though the two independent quiet streaks continue. -
v2.1.221 — VSCode Focus View + Linux/WSL Sandbox Credential
mode: "mask"+ Zsh Regex + PowerShell Quote Handling (August 4, 2026):v2.1.221(2026-08-04 00:14 UTC) breaks the 10-day silence — longest quiet stretch of thev2.1.xseries to date, resolved rather than extended. Two load-bearing additions. VSCode Focus view (Ctrl+Alt+F/ “Toggle Focus view” command) hides tool activity behind an expandable per-turn summary while a live running-tool indicator stays visible — first IDE-side chrome addition since thev2.1.219sandbox-network work, and targeted at the recurring “wall of tool output” complaint. Sandbox credentialmode: "mask"on Linux/WSL — sandboxed commands read a sentinel copy of a credential file (whole file, or regex-extractspans) while the sandbox proxy substitutes the real value on egress; macOS falls back todeny. Direct continuation of thesandbox.network.strictAllowlistposture inv2.1.219— same design principle (agent sees a working stand-in, real secret never enters the sandbox), one layer further down on the credential-hygiene axis. Fixes: zsh double-bracket regex conditional Bash permission-check bypass, Windows PowerShell quote-character permission handling, thinking-toggle no-op for rest-of-session after first toggle,--mcp-configservers not connecting before first turn in-pprint mode — three of four are hardening on previously-thin surfaces. Cadence read:v2.1.221resolves the day-10 outer-variance-band silence rather than extending it — the joint-stall thesis from 2026-08-03-AI-Digest does not carry into today; Beads and OpenSpec remain on independent quiet streaks. Covered in 2026-08-04-AI-Digest. -
2026-08-05-AI-Digest —
v2.1.222shipped 2026-08-04 22:39 UTC — same-day follow-up to yesterday’sv2.1.221(00:14 UTC), the second tag inside the same UTC day. Load-bearing changes: (1) Worktree-isolation hardening — worktree-isolated sessions and their subagents can no longer run destructive git commands against the main checkout; isolation now applies uniformly to file edits and Bash across every session type, tightening blast radius for teams running background-agent workflows in production. (2) PreToolUse auto-allow no longer bypasses tool restrictions in background agent tasks (summaries, compaction, renames) —SendMessagein auto mode now goes through the permission classifier before dispatch, closing a subtle path where auto-allow was silently escalating. (3) Refusal-behavior shift — Claude now asks the user to run a skill flaggeddisable-model-invocationrather than replicating its workflow;/diffand Remote Control diffs switched to raw git blob content (ignoring workspace diff drivers /textconv). (4) Removed: ultraplan feature. Also fixed:/usageover-attributing to MCP servers, org-restricted family aliases dropping to parent model instead of stepping down, HTTPS-proxy startup hang, stream idle timeout firing on customANTHROPIC_BASE_URLgateways despite keep-alive pings. Cadence framing the digest carries: after the 10-day quiet stretch through 2026-08-03-AI-Digest, Claude Code shippedv2.1.221andv2.1.222within the same UTC day — the second tag is a hotfix chain rather than a substantive feature drop, mirroring the same-dayv1.1.1 → v1.1.2pattern Beads used at end-of-July. Silence-then-double-drop is now a recurring release-cadence texture worth carrying forward as av2.1.xobservation. -
v2.1.222 — Worktree-Isolation Hardening + PreToolUse Auto-Allow Restrictions + Ultraplan Removed (August 4, 2026):
v2.1.222(2026-08-04 22:39 UTC) is a same-day follow-up tov2.1.221(00:14 UTC), the second tag inside the same UTC day. Worktree-isolated sessions and their subagents can no longer run destructive git commands against the main checkout — isolation now applies uniformly to file edits and Bash across every session type; tighter blast radius matters for teams running background-agent workflows in production. PreToolUse auto-allow no longer bypasses tool restrictions in background agent tasks (summaries, compaction, renames);SendMessagein auto mode now goes through the permission classifier before dispatch — closing a subtle path where auto-allow was silently escalating. Refusal-behavior shift: Claude asks the user to run a skill flaggeddisable-model-invocationrather than replicating its workflow. Removed: ultraplan feature. Also fixed:/usageover-attributing to MCP servers, org-restricted family aliases dropping to parent model instead of stepping down, HTTPS-proxy startup hang, stream idle timeout firing on customANTHROPIC_BASE_URLgateways despite keep-alive pings. Cadence read to carry: silence-then-double-drop as a recurring release-cadence texture —v2.1.221 → v2.1.222inside a UTC day mirrors thev1.1.1 → v1.1.2pattern Beads used at end-of-July; after the 10-day quiet stretch that ran through 2026-08-03-AI-Digest, the second tag is a hotfix chain rather than a substantive feature drop. Covered in 2026-08-05-AI-Digest. -
2026-08-06-AI-Digest —
v2.1.223shipped 2026-08-06 00:52 UTC — the third tag in three consecutive UTC days after thev2.1.221 → v2.1.222chain from 2026-08-04-AI-Digest / 2026-08-05-AI-Digest. Load-bearing changes: (1) Third permission-bypass fix in three consecutive tags — Bash permission bypass via hidden commands is closed; permission prompts can no longer be hidden by tab or invisible-Unicode characters; agent-definitionbypassPermissionsno longer overrides org policy. Read as a trio:v2.1.221sandbox credential mode →v2.1.222worktree isolation →v2.1.223hidden-command / invisible-Unicode / org-policy is a concentrated pass across every previously known auto-escalation surface. (2) Marketplace allowlist / blocklist gains owner wildcards ("owner/*") — closes a granularity gap in the plugin-trust boundary thatv2.1.222’s tighter permission model exposed; restricted-subagent model requests now warn instead of silently coercing. (3)/teleporthint for continuing sessions locally (surfaced after cloud-session moves);/reviewbecomes an alias of/code-review. Small workflow touches rather than new capability surface. Fixes:modelOverridestreating unknown keys as canonical IDs, gateway model discovery hiding Claude models with provider prefixes, forked background agents stuck inalready resumingstate, Linux sandboxed commands failing on write-deniedcwd. Cadence framing the corpus carries: three tags in three consecutive UTC days on the auto-escalation surface — the silence-then-double-drop texture from 2026-08-05-AI-Digest extends to silence-then-triple-drop with the third tag arriving inside 24h of the second, and every one of the three tags carries at least one permission-bypass hardening item. -
v2.1.223 — Third Permission-Bypass Fix in Three Consecutive Tags: Hidden Commands, Invisible-Unicode, Agent-Definition bypassPermissions vs Org Policy (August 6, 2026):
v2.1.223(2026-08-06 00:52 UTC) is the third tag in three consecutive UTC days afterv2.1.221 → v2.1.222. The permission-bypass hardening pattern the corpus should carry: v2.1.221 sandbox credentialmode: "mask"→ v2.1.222 worktree-isolation + PreToolUse auto-allow → v2.1.223 hidden-command / invisible-Unicode / agent-definitionbypassPermissionsvs org policy is a concentrated audit pass across every previously known auto-escalation surface, all three tags landing inside three UTC days. Marketplace allowlist / blocklist gains owner wildcards ("owner/*"), closing a granularity gap in the plugin-trust boundary thatv2.1.222’s tighter permission model exposed; restricted-subagent model requests now warn instead of silently coercing. Small workflow touches:/teleporthint for continuing sessions locally after cloud-session moves;/reviewbecomes an alias of/code-review. Fixes:modelOverridesunknown-key handling, gateway model discovery hiding Claude models with provider prefixes, forked background agents stuck inalready resuming, Linux sandboxed commands failing on write-deniedcwd. Cadence read: the silence-then-double-drop pattern fromv2.1.221 → v2.1.222extends to silence-then-triple-drop with v2.1.223 — after the 10-day silence flagged through 2026-08-03-AI-Digest, three tags landed in three consecutive UTC days, every one carrying at least one permission-bypass hardening item. Covered in 2026-08-06-AI-Digest. -
2026-08-07-AI-Digest —
v2.1.224shipped 2026-08-07 — the fourth tag in four consecutive UTC days after thev2.1.221 → v2.1.222 → v2.1.223permission-bypass chain from 2026-08-04-AI-Digest / 2026-08-05-AI-Digest / 2026-08-06-AI-Digest. The shape of the release is different from the prior three. Multi-session primitives ship: newSendMessagetool for cross-session messaging between agents (local sessions, cloud sessions, and Remote Control bridge sessions); newListAgentstool for enumerating messageable agents by name. Pairs cleanly with the removal of the 200-subagent spawn cap — the primitive layer for multi-session and multi-agent orchestration is now in place rather than emulated. Self-hosted environments for Team and Enterprise plans, plus anarchiveplugin source that installs plugins from.zipfiles over HTTPS — broadens the deployment surface for regulated or air-gapped teams that couldn’t route through the marketplace. Sandbox credential-masking hardening continues at a different layer: JWT-aware masking of specific claims, AWS SigV4 request re-signing after mutation, plus a fix for Linux/macOS filesystem-deny entries being bypassable through certain path constructions — continuation of the sandbox-credential-mode threadv2.1.221opened, not a fresh permission-bypass fix. Fixes: long project paths (>200 chars) resolving to wrong session directories; restricted-subagent model requests warning instead of silently coercing (partial continuation ofv2.1.223); several minor UI and error-message touches. Narrow read the digest carries: the framing to soften is “permission-bypass audit continues into a fourth consecutive day.” The audit surfacev2.1.221 → v2.1.223was concentrated on ended with hidden-command / invisible-Unicode / org-policy on Aug 6;v2.1.224’s primary story is a new capability surface (multi-session messaging, self-hosted environments), not another bypass fix. Structural read worth carrying: the pivot from bypass-audit to session-primitive shipping suggests the concentrated audit pass is complete for now — the multi-session/SendMessagelayer is the shape of the next quarter’s work, not another hardening tag. -
v2.1.224 — Pivot From Bypass-Audit to Session Primitives: SendMessage + ListAgents + Self-Hosted Environments + Archive Plugin Source + JWT-Aware Masking + AWS SigV4 Re-signing (August 7, 2026):
v2.1.224(2026-08-07) is the fourth tag in four consecutive UTC days after thev2.1.221 → v2.1.222 → v2.1.223permission-bypass chain — and the shape of the release is materially different from the prior three. Load-bearing items:SendMessagecross-session messaging tool (local sessions, cloud sessions, Remote Control bridge sessions) +ListAgentssession-discovery tool — pairs with the removal of the 200-subagent spawn cap so the multi-session/multi-agent orchestration primitive layer is now first-class rather than emulated. Self-hosted environments for Team and Enterprise plans +archiveplugin source installing plugins from.zipfiles over HTTPS — broadens the deployment surface for regulated or air-gapped teams that couldn’t route through the marketplace. JWT-aware credential masking of specific claims + AWS SigV4 request re-signing after mutation + Linux/macOS filesystem-deny path-construction bypass fix — sandbox credential-masking hardening at a different layer, continuing thev2.1.221sandbox-mode thread rather than thev2.1.223prompt-hiding thread. Fixes: long project paths (>200 chars) resolving to wrong session directories; restricted-subagent model requests warning instead of silently coercing (partial continuation ofv2.1.223); minor UI and error-message touches. Structural read the corpus should carry: the pivot from bypass-audit to session-primitive shipping suggests the concentrated audit passv2.1.221 → v2.1.223is complete for now — the multi-session /SendMessagelayer is the shape of the next quarter’s work, not another hardening tag. Covered in 2026-08-07-AI-Digest. -
2026-08-08-AI-Digest — Two tags today, both new since the
v2.1.224coverage in 2026-08-07-AI-Digest.v2.1.225shipped 2026-08-08 01:09 UTC — the substantive tag, continuing the session-primitive pivotv2.1.224opened. Load-bearing items: cross-sessionSendMessageextended to Remote Control by name (can now start conversations with Remote Control sessions on other machines by name, no longer requires the remote to message the local session first);ListAgentsenumerates them withname [ref]disambiguation when two rows share a name — direct follow-on to the multi-session primitives shipped inv2.1.224, connectivity fabric is now bidirectional across machines, not initiate-once. Gateway spend-limit surfacing — Claude Code’s usage-limit warning now names the operator’s cap, reset time, and message when a gateway spend limit trips (requires the gateway onv2.1.225+); continues the Team / Enterprise deployment-surface workv2.1.224opened for self-hosted environments. Workspace-trust prompt added toclaude agents— untrusted-directory prompt now matches theclaudeentry point, closes a trust-boundary gap between the two that the multi-session work opened up. Fixes worth flagging: transient 401 when replacing a long-livedCLAUDE_CODE_OAUTH_TOKENwith a login token; MCP OAuth servers on macOS bursting 401s after keychain timeouts; auto mode no longer counting safety-filter refusals of its own permission-check against the consecutive-block limit; conversation-history corruption on Remote Control session resume after large-conversation compaction.v2.1.226shipped 2026-08-08 02:48 UTC — body reads only “Bug fixes and reliability improvements”, a follow-up patch onv2.1.225roughly 90 minutes after the substantive tag. No functional detail disclosed. Narrow read: neither tag is a bypass fix — the audit chain covered throughv2.1.223is closed andv2.1.224opened the session-primitive shipping pass;v2.1.225extends the multi-session fabric to be bidirectional and lands the operator-surface polish the deployment pivot needs. Structural read worth carrying: the shape is now visible —v2.1.221→v2.1.223was the concentrated hardening pass,v2.1.224→v2.1.226(three consecutive UTC days again) is the deployment-and-operator-surface pass. Two multi-day tag chains with distinct themes suggests a deliberate serialisation, not a fire-drill cadence. -
2026-08-09-AI-Digest — No new tag Aug 8–9. Newest tag remains
v2.1.226(2026-08-08 02:48 UTC, “Bug fixes and reliability improvements”) — the follow-up patch onv2.1.225, already covered in 2026-08-08-AI-Digest. The load-bearing move for Claude Code this weekend is not a release tag but the Aug 14 Auto Mode default-on rollout confirmed by Anthropic on Aug 8: Auto Mode flips to the default for Pro / Max / Team subscriptions from Aug 14; Enterprise stays opt-in; API / cloud rollout planned “within the next month.” Vendor-cited numbers: 89% classifier catch vs 13.6% human on dangerous shell commands (1,053-tester Anthropic study), ~25% more PRs completed by Auto Mode users, and independent Trajectory Labs audit reports 0/720 successful prompt-injection attacks across Claude Fable 5 / Claude Opus 5 / Claude Sonnet 5 with Auto Mode engaged (vs 5.83% baseline against pre-classifier GPT-5.6 Sol). The corpus framing to carry: the classifier-not-approval-gate design axis for Claude Code just got a load-bearing datum from the vendor itself — Auto Mode as the shipped default is the first observable instance of a frontier lab replacing the human-in-the-loop permission prompt with a classifier at the default level rather than as an opt-in beta. 30 / 60 / 90-day watch: whether Trajectory Labs’ 720-attack methodology gets published for independent replication; whether Enterprise opt-in shifts once tenant admins see Pro / Max / Team incident distribution; whether the API tier’s rollout preserves the same classifier posture or ships with a weaker default. -
v2.1.225 / v2.1.226 — Bidirectional Cross-Machine SendMessage + Gateway Spend-Limit Surfacing + Workspace-Trust Prompt on
claude agents+ OAuth/Keychain Fixes + Same-Day Reliability Patch (August 8, 2026):v2.1.225(2026-08-08 01:09 UTC) extendsSendMessageto start conversations with Remote Control sessions on other machines by name viaListAgents— the multi-session fabric is now bidirectional across machines, not initiate-once. Gateway spend-limit surfacing names operator cap / reset time / message when a gateway spend limit trips (requires the gateway onv2.1.225+). Workspace-trust prompt onclaude agentsmatches theclaudeentry point, closing a trust-boundary gap the multi-session work opened. Fixes:CLAUDE_CODE_OAUTH_TOKEN401s; macOS MCP OAuth keychain 401 bursts; auto-mode safety-filter refusals no longer counted against consecutive-block limit; conversation-history corruption on Remote Control session resume after large-conversation compaction.v2.1.226(02:48 UTC) is a same-day follow-up patch — “Bug fixes and reliability improvements”, no detail disclosed. Cadence read to carry: two multi-day tag chains with distinct themes —v2.1.221 → v2.1.223concentrated hardening pass,v2.1.224 → v2.1.226deployment-and-operator-surface pass — suggests deliberate serialisation, not fire-drill cadence. Covered in 2026-08-08-AI-Digest. -
2026-08-11-AI-Digest —
v2.1.227shipped 2026-08-10 22:56 UTC — new since prior digest. Bug-fix-shaped tag rather than a features drop: fixes feature-flag evaluation for expired login tokens (affected Max-plan users) and 401 errors on/tuiconversation rewinding; fixes Bash-command failures underclaude-code-actionwhenallowed_non_write_usersis set — a workflow-configuration edge case surfaced by GitHub-Actions runners. Slash-command menu restyled (blue selection state, bolded match spans); perf improvements on file-not-found suggestions and at-mention checks. Follow-up patch tov2.1.226(bug-fix-only, 2026-08-08 02:48 UTC) andv2.1.225(2026-08-08 01:09 UTC, which shipped gateway spend-limit support, workspace-trust prompt forclaude agents, andSendMessagecross-session agent-name discovery — those twoalready-reported:2026-08-08-AI-Digest and 2026-08-10-AI-Digest). Cadence framing this note carries: maintenance beat continuing the deployment-and-operator-surface pass shape fromv2.1.224 → v2.1.226, not a fresh feature slice. Sits alongside the standing Auto Mode default-on flip for Pro / Max / Team on Aug 14 as the operational context for the tag — token-refresh and login-token edge cases are exactly the surfaces Auto Mode’s classifier-not-approval-gate default will exercise at higher volume. -
v2.1.227 — Expired-Token Feature-Flag Evaluation + /tui Rewinding 401 + Bash
allowed_non_write_usersUnder claude-code-action + Slash-Command Menu Restyle (August 10, 2026):v2.1.227(2026-08-10 22:56 UTC) is a bug-fix-shaped tag rather than a features drop, followingv2.1.226(2026-08-08 02:48 UTC) andv2.1.225(2026-08-08 01:09 UTC) with a three-tag chain that mirrors the earlier silence-then-double / triple-drop cadence texture. Load-bearing fixes: feature-flag evaluation for expired login tokens on Max-plan users,/tuiconversation-rewinding 401 errors, andclaude-code-actionBash-command failures whenallowed_non_write_usersis set — a workflow-configuration edge case surfaced by GitHub-Actions runners. Slash-command menu restyled (blue selection state, bolded match spans); perf improvements on file-not-found suggestions and at-mention checks. Cadence read to carry: maintenance beat continuing the deployment-and-operator-surface pass shape fromv2.1.224 → v2.1.226, not a fresh feature slice — the tag lands in the operational window before Auto Mode default-on flips for Pro / Max / Team on Aug 14, exactly the surface where token-refresh and login-token edge cases matter most. Covered in 2026-08-11-AI-Digest. -
2026-08-12-AI-Digest —
v2.1.228shipped 2026-08-11 — new since prior digest. Substantive fixes: Windows Git / Git Bash detection when Claude Code is launched from the parent of the Git install directory;/tuireverting to an earlier model after a mid-session/modelchange; Remote Control/resumeleaking conversation title and history into a connected session; session-cleanup deleting contents inside a project’s memory folder. Hardens skills synced from claude.ai — they no longer shadow local commands / MCP prompts, and descriptions are sanitised on ingest. Vertex AI credential handling: expired or missing credentials now fail within seconds instead of retrying for minutes; compaction shows a retry countdown and stall hints. Behaviour change: theWritetool now lets newer models overwrite existing files without a priorRead, matching theEdittool’s rule — the load-bearing shape change in the tag, closing a friction seam Auto Mode exercised repeatedly in testing. Prior digest coverage ofv2.1.227(already-reported:2026-08-11-AI-Digest) still applies for the fixes that landed last night. Cadence framing this note carries:v2.1.228lands the day before Aug 14 Auto Mode default-on for Pro / Max / Team — the Write-tool matching-Edit rule and the Remote Control / session-cleanup fixes are exactly the surfaces the classifier-not-approval-gate default will exercise at higher volume. -
v2.1.228 — Windows Git-Bash Parent-Directory Detection + Skills-From-Claude.ai Shadow-Guard + Vertex AI Credential Fast-Fail + Write Tool Now Matches Edit Rule (No Prior Read Required for Newer Models) (August 11, 2026):
v2.1.228(2026-08-11) is a maintenance tag that ships one load-bearing behaviour change alongside a bundle of session-integrity fixes. The Write tool now lets newer models overwrite existing files without a priorRead, matching theEdittool’s rule — closes a friction seam Auto Mode exercised repeatedly in testing and sits directly on the Pro / Max / Team Aug 14 cutover clock. Session-integrity fixes: Windows Git / Git Bash detection when Claude Code launches from the parent of the Git install directory;/tuireverting to an earlier model after a mid-session/modelchange; Remote Control/resumeleaking conversation title and history into a connected session; session-cleanup deleting contents inside a project’s memory folder. Skills synced from claude.ai no longer shadow local commands / MCP prompts, and descriptions are sanitised on ingest — hardening on the claude.ai-to-Code sync trust boundary. Vertex AI credential handling: expired or missing credentials now fail within seconds instead of retrying for minutes; compaction shows a retry countdown and stall hints. Cadence read to carry: third consecutive tag on the pre-Auto-Mode-default-on operational-hardening window (v2.1.226→v2.1.227→v2.1.228) — the Write-tool rule change is the shape-defining item, the rest is session-integrity + credential-fast-fail continuing the deployment-and-operator-surface pass. Covered in 2026-08-12-AI-Digest. -
2026-08-15-AI-Digest —
v2.1.233(2026-08-14) ships four load-bearing items (release notes). (1) GitLab merge-request URLs now work with the--worktreeflag and inside theclaude agentsview — completes the GitLab parity push started inv2.1.232. (2) Opt-in memory cgroup for Bash-tool commands on Linux — caps runaway builds inside a hard memory limit rather than trusting the underlying shell to bail. (3) Windows path-validation bypass fix — NT\??\device prefixes were slipping past the UNC check; closed. (4) Bundled-skill aliases were reporting “Unknown command” in-pmode when plugins/MCP loaded — fixed. Separately, Anthropic published the first hard merge-rate on Claude Code running unsupervised against its own repos — 388 PRs opened over several weeks, 180 merged (46%) across scaffolded maintenance routines (crash detection, dead-code removal, dependency hygiene) triggered from a Slack channel via natural-language prompts. Boris Cherny frames the result as “early signs of life” rather than a productivity claim. Narrow read the digest carries: 46% is a merge rate on scaffolded maintenance PRs, not autonomous feature work — the 54% rejection rate is the more useful number for sizing babysitting overhead. Structural read: first data point that lets the corpus calibrate the delta between “lab that ships Claude Code” and “lab that uses Claude Code in anger against its own commit history” — frame the 46% as the ceiling on how confidently a top-tier lab lets its own agent touch its own repo, not the ceiling on enterprise deployments. -
v2.1.233 — GitLab MR URLs + Linux Memory cgroup for Bash + Windows NT Device-Prefix Path-Validation Fix + Bundled-Skill Alias
-pMode Fix; Paired With Anthropic’s First Public Repo-Merge-Rate Datapoint (46% Across 388 PRs) (August 14, 2026):v2.1.233completes the GitLab parity push (--worktree+claude agentsview now accept GitLab MR URLs) started inv2.1.232; opt-in Linux memory cgroup caps runaway build memory as a substrate primitive rather than relying on the shell; NT\??\device-prefix Windows path-validation bypass fix is a real security hardening item;-pmode bundled-skill alias “Unknown command” regression closed. Load-bearing paired framing to carry: Anthropic published 388 PRs / 180 merged (46%) on scaffolded maintenance routines against its own repo — the first frontier-lab published merge-rate against production code over a multi-week window. Corpus framing: frame the 46% as the ceiling on how confidently a top-tier lab lets its own agent touch its own repo, not the ceiling on what enterprise buyers should expect — the 54% rejection rate is the more useful number for babysitting-overhead sizing. Reads directly against thev2.1.221 → v2.1.228operator-hardening chain and the 2026-08-09-AI-Digest Auto Mode default-on flip as the second-order justification for the substrate-hardening pass — the vendor is telegraphing what its own agent can and can’t do on real production code. Covered in 2026-08-15-AI-Digest. -
2026-08-16-AI-Digest — No new tag Aug 15–16. Newest tag remains
v2.1.233(2026-08-14) — the GitLab MR URL parity + Linux memory cgroup + NT\??\device-prefix +-pmode bundled-skill-alias tag already covered in 2026-08-15-AI-Digest (already-reported). The load-bearing move for Claude Code today is the Aug 14 Auto Mode default-on flip landing as scheduled on Pro / Max / Team plans — Enterprise, API, and cloud-partner deployments excluded from the default flip. Vendor-reported numbers: 89% catch rate on dangerous commands under Auto Mode vs 13.6% under the prior manual defaults, +25% reported PR throughput on internal benchmarks. Narrow read the digest carries: harness-layer default swap — permissions, injection screens, deny rules — with no model swap underneath; read the 89% number as how well the harness catches the class of commands Anthropic has curated deny lists for, not a general safety benchmark. Structural read: stitch with today’s DarwinX paper (WebArena-Infinity 43.5% → 93.0% via harness evolution with a frozen model) and this month’s harness-side product cluster (Auto Mode, Codex tool-use defaults, DeepSeek Harness open-source drop from 2026-08-14-AI-Digest) — near-term agent-quality gains are landing at the harness layer, not the weights layer. Cadence framing: nine days since the last Claude Code release (v2.1.233), consistent with the recent cluster-then-quiet shape — read the silence as maintenance mode, not stall. 30 / 60 / 90-day watch: whether OpenAI and Google Cloud follow with symmetric default flips on their coding-agent surfaces; whether the 89% number holds up in independent third-party red-teams; whether Enterprise tier gets a nudge toward an equivalent default within the next quarter. -
2026-08-18-AI-Digest —
v2.1.234(2026-08-17, ~20:20 UTC) ships as the first fresh Claude Code release sincev2.1.233on Aug 14 — closing the nine-day gap flagged in 2026-08-16-AI-Digest (release notes). Load-bearing items: (1) newCLAUDE_CODE_PROJECT_DIR_NAMEenv var lets each project pin its own transcript directory name — resolves the multi-clone collision case where two working copies of the same repo tried to share transcripts; (2) newselection:clearkeybinding action; (3) sessions auto-continue when API usage limits reset, so long-running agents survive a rate-limit window without operator poke; (4) GitLab MR badge added to the footer / statusline — extends the v2.1.232/233 GitLab wiring toward parity with the GitHub PR presentation; (5) Windows NT-namespace path rejection tightened again (belt-and-suspenders on top of the v2.1.233\??\fix); (6) additional credential-leak protection layered on the v2.1.232/233 GitLab-token redaction line. Plus assorted UI-rendering and permission-handling fixes. Cadence read: single-tag day that resumes the release line rather than starting a new hardening chain; the auto-continue on rate-limit reset is the shape-defining new capability alongside the transcript-collision env var. -
2026-08-22-AI-Digest —
v2.1.239(2026-08-21 ~19:54 UTC) — fifth consecutive daily tag (v2.1.235 → v2.1.239) (release notes). Today’s mix is cost-transparency + fullscreen coverage extension + SDK-migration automation. Load-bearing items: (1) **1.1× US-only-inference premium surfaced directly in per-request cost estimates**, rather than aggregated at invoice time — first visible pricing knob to appear inside the tool's own cost surface since [[Auto Mode]] shipped as default in [[2026-08-16-AI-Digest]]. Enterprise deployers routing sensitive workloads through Anthropic's US-only compute pool for compliance now see the differential in-context. **(2)** **Fullscreen renderer extended to AWS Bedrock, Google Vertex, and Azure Foundry** — closes a two-tier UX where gateway-brokered sessions dropped to the classic renderer; small parity win but meaningful for enterprises whose procurement path forces gateway routing. **(3)** **/claude-api upgradecommand** — in-project migration helper that walks a codebase through the **Anthropic Python SDK0.x→1.x** upgrade; same shape as [[OpenSpec]]'s codemod tooling — codified migration paths as first-class SDK affordances — and the first time the CLI ships an SDK-version migration surface for its own client library. **(4)** **Alpine/musl native-addon support** — native add-ons now build againstmusllibc, so the CLI runs on Alpine Linux and othermusl-based container distros without the glibc-only shim; plus correctness passes on streaming, MCP-server elicitation, fullscreen fallback, and cross-sessionSendMessage` back-pressure. Cadence read: five Claude Code drops in five days; the v2.1.235 → v2.1.239 arc has now shipped through developer-UX polish, enterprise/self-hosted plumbing, and — with today’s US-only premium disclosure — the first visible pricing surface change. -
v2.1.239 — 1.1× US-Only-Inference Premium in Cost Estimates + Fullscreen Renderer Extended to Bedrock/Vertex/Foundry +
/claude-api upgradeSDK Migration Command + Alpine/musl Native-Addon Support (August 21, 2026):v2.1.239(2026-08-21 ~19:54 UTC) is the fifth daily Claude Code tag in a row, closing out the v2.1.235 → v2.1.239 arc. Load-bearing items: 1.1× US-only-inference premium now visible directly in per-request cost estimates (first visible pricing knob inside the tool’s own cost surface since Auto Mode shipped as default); fullscreen renderer extended to AWS Bedrock / Google Vertex / Azure Foundry (closes the two-tier gateway-vs-first-party UX);/claude-api upgradecommand for Anthropic Python SDK0.x→1.xmigrations (first CLI-shipped SDK-version migration surface for its own client library, same shape as OpenSpec codemod tooling); Alpine/musl native-addon support removes the glibc-only shim for container-native deployments. Plus correctness passes on streaming, MCP-server elicitation, fullscreen fallback, cross-sessionSendMessageback-pressure. Cadence read to carry: five consecutive daily tags in the v2.1.235 → v2.1.239 arc through UX polish + enterprise/self-hosted plumbing + first visible pricing-surface change — the fullscreen-to-Bedrock/Vertex/Foundry extension in particular closes a two-tier gateway-vs-first-party experience carried since v2.0. Covered in 2026-08-22-AI-Digest. -
2026-08-23-AI-Digest —
v2.1.241(2026-08-23 ~00:52 UTC) — sixth consecutive daily drop in the v2.1.235 → v2.1.241 arc, but the first with no disclosed feature surface (release notes). Release body reads exactly “Bug fixes and reliability improvements.” Companion releasev2.1.240(2026-08-22 ~14:45 UTC) (release notes) — same body, same shape. Cadence framing the digest carries: v2.1.235 → v2.1.239 shipped substantive plumbing every day (Auto Mode default, US-only-inference cost surfacing, fullscreen renderer to Bedrock/Vertex/Foundry, Alpine/musl support, SDK-migration automation); two consecutive bug-fix-only drops is the first pause in the feature stream since it opened. Whether this is a stabilisation pause before a larger beat or a genuine end-of-cycle sag is not decidable from two data points. The digest’s disciplined framing: treating the two shapes as equivalent would flatten the signal — the “daily-with-a-feature” reading of this week’s cadence is retired for now; the next release either restores the feature stream (reframing v2.1.240–241 as stabilisation) or extends the bug-only pattern into a plateau. -
v2.1.240 / v2.1.241 — Two Consecutive Bug-Fix-Only Drops Break the v2.1.235 → v2.1.239 Feature Cadence (August 22–23, 2026):
v2.1.240(2026-08-22 ~14:45 UTC) andv2.1.241(2026-08-23 ~00:52 UTC) both ship as “Bug fixes and reliability improvements” — the first pause in the v2.1.235 → v2.1.239 daily-with-a-feature stream since it opened. Load-bearing framing to carry: not decidable from two data points whether this is a stabilisation pause or an end-of-cycle sag — the next release either restores the feature cadence and reframes v2.1.240–241 as stabilisation, or extends the plateau. Do NOT flatten “two bug-fix drops in a row” into the same shape as the prior five-day feature stream. Covered in 2026-08-23-AI-Digest. -
2026-08-24-AI-Digest —
v2.1.241remains the latest tag (2026-08-23 ~00:52 UTC,already-reported:2026-08-23-AI-Digest) — no new tag in the ~36 hours since; the v2.1.235 → v2.1.241 arc’s two-consecutive-bug-fix-only-drops break (v2.1.240 / v2.1.241 both “Bug fixes and reliability improvements”) extends by one more beat without resolving. Narrow read the digest carries: do not read “no release today” as “release stream stalled” — the cadence itself has been the story for six days, and a third undocumented drop or the next feature-carrying release is the disambiguating signal. Structural read: the plateau extends but is not yet decidable between stabilisation pause and feature-cycle sag. -
2026-08-25-AI-Digest —
v2.1.245(2026-08-25) ships as a targeted glibc 2.44 startup-crash hotfix (release notes) — third undocumented drop in the v2.1.235 → v2.1.245 arc but the first with a specific named fix: “Fixed a crash on startup on Linux distributions that ship glibc 2.44” (Arch Linux, CachyOS, Fedora Rawhide). Narrow read the digest carries: hotfix, not a feature drop — the release body disambiguates yesterday’s plateau frame in exactly one direction: plateau is now a triage cadence, with the team pulling forward a targeted distro-compat hotfix rather than continuing to batch changes into anonymous “reliability” tags. Structural read: the disambiguation is thin but real — what yesterday’s Digest flagged as “undecided on one additional day of data” now has a concrete data point (v2.1.245 is a scheduled interrupt for a downstream toolchain issue, not the next feature release); Anthropic is willing to break its own cadence to unblock a specific Linux population. The next feature-carrying tag remains the disambiguating signal for whether the feature stream itself has stalled. -
v2.1.245 — glibc 2.44 Startup-Crash Hotfix on Arch / CachyOS / Fedora Rawhide (August 25, 2026):
v2.1.245(2026-08-25) is the third undocumented drop in the v2.1.235 → v2.1.245 arc — but the first with a specific named fix in the release body. Load-bearing item: “Fixed a crash on startup on Linux distributions that ship glibc 2.44” (Arch Linux, CachyOS, Fedora Rawhide) — a hotfix for a distinct downstream Linux population, not a feature drop. Cadence read to carry: plateau is now a triage cadence, not a feature freeze — Anthropic broke its own batching cadence to unblock a specific downstream toolchain issue rather than continue anonymous “reliability” tags. The next feature-carrying tag remains the disambiguating signal for whether the feature stream itself has stalled; do NOT upgrade today’s hotfix to “cadence resumed.” Covered in 2026-08-25-AI-Digest. -
2026-08-26-AI-Digest —
v2.1.246(2026-08-25 22:31 UTC) ships ~17 hours after the v2.1.245 glibc 2.44 hotfix as a substantive feature drop that falsifies yesterday’s “plateau is a triage cadence” reading in exactly one direction — the feature stream is very much alive (release notes). Named features: Auto mode tab in/permissionsfor viewing / editing classifier rules from the UI rather than only via config file; a startup warning for wildcard-before-subcommand Bash allow rules such asBash(git * main)— a footgun that had silently over-broad-allowlisted whole tool categories; and a turn-completion clock stamped onto the end-of-turn duration line. Reliability surface dense: background sessions failing to open after 45s on deleted starting dir / slow host, auto-mode denials on very large sessions (safety-check deadline now scales with prompt size), subagent restart on ← //background, Write-tool “Out of memory” after overwriting huge files, memory growth in fullscreen / Ctrl+O transcript views. MCP surface hardened: tool arguments no longer sent as JSON strings when the tool schema is{}, interrupted MCP calls in headless mode reported as interrupted rather than “completed with no output”, telemetry no longer leaks a third-party gateway API key to Anthropic hosts, resumed sessions carrying API-incompatible tool blocks no longer 400 every turn. The single line that matters most for scheduled routines:-p, SDK and cloud sessions now auto-continue responses cut off mid-stream by server error, connection loss, or stall — a real reliability lift for the exact headless-run pattern the digest itself is generated by. Cadence read the digest carries: v2.1.240 / .241 were staging, not stall — the team is now shipping targeted triage hotfixes AND substantive feature drops inside the same 24-hour window; do NOT re-run the “release cadence is stalled” beat. -
v2.1.246 — Auto Mode Tab in /permissions + Wildcard-Bash Allow-Rule Startup Warning + Turn-Completion Clock + SDK/Cloud Stream Auto-Continue on Mid-Stream Server Error + MCP JSON-String / Empty-Schema Fix (August 25, 2026):
v2.1.246(2026-08-25 22:31 UTC) is the fourth tag in the v2.1.235 → v2.1.246 arc since the plateau opened, and the first with a real feature payload since v2.1.239. Load-bearing items: Auto mode tab in/permissionspromotes classifier-rule editing from config-file-only to a first-class UI surface (direct extension of the Auto Mode default-on flip from 2026-08-16-AI-Digest); startup warning for wildcard-before-subcommand Bash allow rules closes a silent over-broad-allowlisting footgun; SDK / cloud stream auto-continue after mid-stream server error is the reliability item most load-bearing for scheduled routines and headless-run patterns. Reliability surface (dense): background-session start on deleted starting dir / slow host, safety-check deadline scaling with prompt size on very large sessions, subagent restart on ← //background, Write-tool “Out of memory” on huge-file overwrite, fullscreen / Ctrl+O transcript memory growth. MCP: tool arguments no longer sent as JSON strings when schema is{}, interrupted headless MCP calls reported as interrupted, telemetry gateway-API-key leak to Anthropic hosts closed, resumed sessions with API-incompatible tool blocks no longer 400 every turn. Cadence read to carry: v2.1.240 / .241 were staging, not stall — the team is now shipping targeted triage hotfixes (v2.1.245 glibc) AND substantive feature drops (v2.1.246) inside the same 24-hour window; the corpus should retire the “release cadence is stalled” beat and pick up the mixed hotfix-and-feature rhythm as the new v2.1.24x-line cadence texture. Covered in 2026-08-26-AI-Digest. -
2026-08-27-AI-Digest —
v2.1.247(2026-08-26 23:06 UTC) ships ~24 hours after v2.1.246 and extends yesterday’s feature drop rather than course-correcting it — a third consecutive day of mixed hotfix-and-feature commits, not another anonymous “reliability” placeholder (release notes). Load-bearing items:SendFeedbacktool wires the/feedbackcommand to a structured feedback draft — the CLI is no longer the last uninstrumented surface in the workflow;/claude-api cost-optimizeprofiles Anthropic API spend against the loaded skill’s recommendations, and the same skill extension now covers the Admin API surface (org members, invites, workspaces, API keys). Fixes for fast arrow-key + Enter sequences (history search,/config,/mcp,/skills,/model) and Bash sandbox handling of dotfile-managed symlinks (nix / home-manager / stow) — the two multi-day irritants that scheduled routines have quietly been eating around. Narrow read the digest carries: patch releases at this project’s velocity are the baseline — the interesting frame is not “cadence alive”; it is that the/claude-apiskill is quietly absorbing the Admin API surface, and that is the first time a shipped skill has crossed from developer-facing into ops-facing territory in one release. Structural read: v2.1.245 → v2.1.246 → v2.1.247 is the first three-consecutive-day mixed-hotfix-and-feature streak in the v2.1.24x line, confirming the 2026-08-26-AI-Digest “mixed inside 24h, not batching pause” cadence texture as a recurring rhythm rather than a one-off; the corpus should retire the plateau framing entirely. -
v2.1.247 — SendFeedback Tool +
/claude-api cost-optimize+/claude-apiSkill Extended Onto the Admin API Surface + Fast-Arrow-Key / Enter Sequence Fixes + Bash Sandbox Handling for Dotfile-Managed Symlinks (August 26, 2026):v2.1.247(2026-08-26 23:06 UTC) is the third consecutive daily tag in the v2.1.245 → v2.1.247 arc and the second substantive feature drop in that arc after v2.1.246. Load-bearing items:SendFeedbacktool wires/feedbackinto a structured draft (the CLI stops being the last uninstrumented surface);/claude-api cost-optimizeprofiles Anthropic API spend against loaded-skill recommendations; the/claude-apiskill extension now covers the Admin API surface (org members, invites, workspaces, API keys) — first time a shipped Claude Code skill has crossed from developer-facing into ops-facing territory in one release. Fixes: fast arrow-key + Enter sequences (history search,/config,/mcp,/skills,/model) and Bash sandbox handling of dotfile-managed symlinks (nix / home-manager / stow) — two multi-day irritants scheduled routines have been eating around. Cadence read to carry: third consecutive day of mixed hotfix-and-feature commits in the v2.1.24x line — the corpus should retire the “release cadence is stalled” plateau framing entirely and pick up the mixed-hotfix-and-feature rhythm as the durable texture for this line. Covered in 2026-08-27-AI-Digest. -
2026-08-28-AI-Digest —
v2.1.250(2026-08-28 00:49 UTC) — bug-fix / reliability release only, no user-visible feature commits (release notes). Fourth patch in five days after v2.1.247 → v2.1.248 (2026-08-27-AI-Digest) and v2.1.246 (2026-08-26-AI-Digest); today’s release pauses the feature cadence rather than extending it — first “reliability-only” tag since the plateau broke on the 26th. Cadence framing the digest carries: 4 tags in 5 days is still well above the pre-plateau baseline; a single reliability tag doesn’t falsify the “cadence alive” reading, but a second one in a row would. Same day: Claude Code Auto Mode surfaces as the shipped-and-exploitable substrate in Simon Willison‘s writeup of Johann Rehberger’s prompt-injection attack against Claude Code Opus 5 auto mode — 80% success rate via a Pythonstruct.pyshim in a zip file, with the paradox that Claude detects the compromise but Auto Mode blocks the cleanup command. Narrow read: 80% is Rehberger’s own attack-attempt success rate, not an independent replication; the paradox — detect-but-block-cleanup — is the load-bearing detail. Structural read: the digest’s Key Takeaways frame this as the shipped-and-exploitable half of a bimodal agent-security surface — the 100+ firms cyber-defence letter frames critical-infrastructure threats as imminent, but the Rehberger exploit is the current developer-workstation-agent-tooling surface where the vulnerability actually ships. Log against MOC - Developer Tools, MOC - Agent Security, and MOC - Agentic Coding. 30 / 60 / 90-day watch: whether the next tag (v2.1.251+) restores the mixed-hotfix-and-feature cadence or extends the reliability-only pause; whether Anthropic ships a targeted fix for the detect-but-block-cleanup paradox Rehberger surfaced; whether Auto Mode’s classifier evolves to unblock cleanup actions on detected compromise events. -
v2.1.250 — Reliability-Only Tag, First Since the Plateau Broke on the 26th (August 28, 2026):
v2.1.250(2026-08-28 00:49 UTC) ships as a bug-fix / reliability release only — no user-visible feature commits in the release notes. Load-bearing framing to carry: first “reliability-only” tag since the v2.1.246 feature drop restarted the cadence — pauses the mixed-hotfix-and-feature rhythm rather than extending it. Cadence read: 4 tags in 5 days is still well above the pre-plateau baseline; a single reliability tag doesn’t falsify the “cadence alive” reading, but a second one in a row would. Do NOT re-open the “release cadence is stalled” plateau framing on this single tag; watch v2.1.251+ for the disambiguating datapoint. Same day: Auto Mode surfaces as the substrate in Rehberger’s 80%-success prompt-injection against Claude Code Opus 5 — Claude detects the compromise but Auto Mode blocks the cleanup command; the paradox is the load-bearing detail, and the 80% is Rehberger’s own attack-attempt success rate rather than independent replication. Covered in 2026-08-28-AI-Digest. -
2026-09-01-AI-Digest —
v2.1.252(2026-08-31 19:46 UTC) — a stability-polish patch on top of last week’sv2.1.251feature push (release notes). Four fixes worth naming: Bash commands failing with “task output swap refused (tasks dir moved or linked)” on some Macs; “always allow” not saving in projects with no.claude/settings.local.jsonyet; Remote Control sessions hosted by Claude Desktop / VS Code stalling for minutes after a tool finished when the claude.ai connection was degraded; and oversized background-task failure notifications (e.g.giterrors on a full disk) pushing conversations past the API request-size limit. Load-bearing framing the digest carries: nothing new in the feature surface — the whole cadence this week reads as bedding-in the Remote Control and hook-events work from mid-August rather than adding capability. Cadence read: patch closes the v2.1.245 → v2.1.252 arc with a bug-fix tag rather than another feature drop; the mixed hotfix-and-feature texture the corpus established on 2026-08-26-AI-Digest is now visibly reverting to a stability-polish pass on the same operator-facing surfaces the recent feature drops (Remote Control, hooks, permissions UI) opened up. Log against MOC - Agentic Coding and MOC - Developer Tools. -
2026-09-02-AI-Digest — Two Claude Code releases in a single evening.
v2.1.257(2026-09-01, 17:53 UTC) is the feature drop: Claude Fable 5.1 (claude-fable-5-1) becomes the new default Fable model at the existing $10 / $50 per Mtok input/output pricing and 1M context, and a new Containment Escape rule is added to auto mode — extra guardrails on cloud metadata-credential fetches and cross-tenant reach. A Time format setting andtimeZonecontrol (12-hour, 24-hour, UTC, or strftime patterns) also lands.v2.1.258(2026-09-01, 22:33 UTC) is a same-night hotfix — restores launch on macOS 12 (Monterey) after av2.1.255regression and fixes remote / scheduled sessions failing with"user messages must have non-empty content"after re-sent permission approvals. Substrate cadence stays tight: the default-model swap and the containment-hardening rule ship the same day the underlying model does. Log against MOC - Agentic Coding, MOC - Developer Tools, and MOC - Agent Security. -
2026-08-30-AI-Digest —
v2.1.251remains the latest tag (2026-08-28 18:19 UTC,already-reported:2026-08-29-AI-Digest) — no new tag in the 48 hours since yesterday’s digest; the fifth-patch-in-six-days streak paused for the weekend. Feature/security surface unchanged from yesterday:PreModelSwitch/PostModelSwitchhooks, live foreground-subagent streaming to Remote Control,/usagespend-limit bar,/costprompt-cache metrics; symlink-traversal and plugin-path fixes. Narrow read the digest carries: the 48-hour gap is a weekend pause, not a new plateau — the v2.1.24x line’s mixed-hotfix-and-feature rhythm remains the durable texture; a single-weekend gap after five patches in six days does not falsify the cadence-alive reading and the plateau framing should not be re-opened on this single datapoint. Structural read: cadence continuity through the weekend is the disambiguating signal to watch for — the next feature-carrying release either resumes the mixed rhythm or extends the pause into an actual quiet stretch. -
2026-09-04-AI-Digest — Claude Code
v2.1.260(2026-09-03) ships two developer-surface additions that matter today. First, a fullscreen Diff Panel — a side-by-side diff view of uncommitted changes rendered while Claude edits, toggled with/diff— the first time the CLI ships a distinct visual review affordance for in-flight edits rather than relying on the terminal’s plain-diff scrollback. Second, prompt-cache diagnostics land in/costand the status line: cache hits and likely miss causes are now surfaced inline, closing the “why is my session suddenly hot” observability gap the Fable 5.1 cache-read cut opened three weeks ago. Two smaller fixes: permission-rule parentheses in path patterns are no longer dropped as invalid (uncompilable patterns fall back to guarding the literal path), and the Bash-permission auto-approver now catches fewer hidden command substitutions — a sandbox-hardening move. Fable 5.1 prompt-caching is also extended to cover post-tool-result context. Prior cutsv2.1.257/v2.1.258/v2.1.259arealready-reported:2026-09-02-AI-Digest and 2026-09-03-AI-Digest. Log against MOC - Agentic Coding and MOC - Developer Tools. -
2026-09-03-AI-Digest —
v2.1.259(2026-09-02 22:33 UTC) — feature drop with two managed-deployment surfaces plus two safety-hardening fixes. Adds amanagedMcpServersmanaged setting so orgs can push HTTP/SSE MCP servers to every user from a central policy file — the second half of the managed-MCP story that started with the client-side plumbing, now expressed as a distribution knob for admins. A--permission-prompts noneflag lands for unattended headless hosts — anything that would normally prompt is auto-denied — which pairs cleanly with the scheduled-routine and CI surface. Two fixes worth noting: concurrent sessions were silently reverting each other’s~/.claude.jsonwrites (the file is now write-locked on merge), and BashRead()deny rules didn’t cover files passed as option values in various operand shapes — the deny rules now normalise operand positions before matching. Substrate cadence stays daily:v2.1.257(Fable 5.1 default + Containment Escape rule) andv2.1.258(macOS 12 launch fix) arealready-reported:2026-09-02-AI-Digest. Log against MOC - Agentic Coding, MOC - Developer Tools, and MOC - Agent Security. -
2026-09-05-AI-Digest —
v2.1.261(2026-09-04) ships two developer-surface additions that close the “subagent context blowout” complaint that has trailed/loopand background-agent workflows since v2.0. First, subagent-output caps —bashOutputMaxCharsandtaskOutputMaxCharsare now configurable up to 128K, and--append-subagent-system-prompt-filelets the parent inject a large system-prompt into every spawned subagent from a file rather than a CLI arg (the two-part fix: the cap keeps a chatty subagent from evicting parent-thread context, and the file-driven prompt keeps briefings terse without truncating them at the shell arg-length limit). Second, the VS Code surface picks up a hollow-ring indicator for sessions open elsewhere, a fold button on permission prompts, friendly model names in/model, and an in-IDE MCP server Add/Remove dialog — the last item is the load-bearing one, since MCP configuration was previously terminal-only and drove a lot ofsettings.jsonhand-editing. Streaming perf skips re-checking already-rendered blocks; typing-order fixes drop the dropped/out-of-order character bug on fast typing; Remote Control fixes cover stale permission modes, stuck spinners, and TLS-inspecting proxies on Windows; SDK/cloud sessions now respect early Stop/interrupt. Prior cutsv2.1.257–v2.1.260arealready-reported:2026-09-02-AI-Digest, 2026-09-03-AI-Digest, 2026-09-04-AI-Digest. Log against MOC - Agentic Coding and MOC - Developer Tools. -
2026-09-06-AI-Digest —
v2.1.263(2026-09-06) is a maintenance-tier bug-fix bump — release notes read verbatim as “Bug fixes and reliability improvements” with no user-facing surface area, no new lever, no config knob. Watch clause carries from yesterday: whether independent practitioners report thev2.1.261128K subagent-output caps +--append-subagent-system-prompt-filecombo (already-reported:2026-09-05-AI-Digest) actually displaces the pre-existing background-agent-context-blowout pattern. Reframe worth carrying: the corpus has been calling the every-1–2-day cadence “substrate cadence stays daily” — that read holds for capability-bearing releases likev2.1.260(Diff Panel + prompt-cache diagnostics) andv2.1.261(subagent caps), but a bug-fix-only bump is not substrate movement. Carry asshipping cadence stays daily; today's release is maintenance-tier with no capability delta, not assubstrate cadence continues. A skipped/yankedv2.1.262between the two is the other visible artifact — no changelog for it in the recent-5 tag window. Log against MOC - Agentic Coding and MOC - Developer Tools. -
2026-09-07-AI-Digest —
v2.1.263(2026-09-06) remains the latest tag — no new cut in the ~24 hours since; second consecutive maintenance day on the substrate, and the digest carries the same reframe as yesterday: the every-1–2-day shipping cadence continues, but substrate-movement cadence has now paused for two days running. Watch clause extends: whether v2.1.264+ restores the mixed-hotfix-and-feature texture that ran through v2.1.246 → v2.1.261 or whether the maintenance-tier subclass is turning into a plateau.already-reported:2026-09-06-AI-Digest for the underlying tag. Log against MOC - Agentic Coding. -
2026-09-08-AI-Digest —
v2.1.263(2026-09-06) remains the latest tag. Release notes still read verbatim as “bug fixes and reliability improvements” — no user-facing surface changes, no config knobs, no new levers since yesterday’s digest.already-reported:2026-09-07-AI-Digest. Prior substantive releasev2.1.261(2026-09-04) still holds the meaningful delta — organization-policy diagnostics on/status+claude doctor,bashOutputMaxChars/taskOutputMaxCharsup to 128K,/skill-doctor. Third calendar day without capability movement, but the sample is small enough that this is a nothing-to-report note, not asubstrate-cadence has pausedclaim. Log against MOC - Agentic Coding. -
2026-09-09-AI-Digest — Two tags landed in the last 24 hours.
v2.1.265(2026-09-08) is the substantive drop:--plugin-dirnow accepts a folder of plugins with hot add/remove; a 1 GB cap on tool results saved to disk with a truncation notice in preview; MCPhttpservers fall back to legacy HTTP+SSE per spec; prompt-cache reuse is fixed for resumed foreground subagents and agent teammates (SubagentStart hook context and preloaded skills stay in the prefix);cdpersists across turns in non-interactive-p/ SDK / cloud sessions; two-key shortcuts wait 3s (fixes tmux); Windows AppContainer / restricted-token sandbox no longer refuses every file with a symlink-resolution error. Thenv2.1.266(2026-09-08) is a single-item hotfix reverting av2.1.265regression where the undocumentedCLAUDE_CODE_USE_GATEWAYenv var began forcing Cloud-gateway sign-in on its own, breaking every request in setups that also set an API key,apiKeyHelper, or custom auth headers. The variable is ignored again unlessANTHROPIC_BASE_URL+ANTHROPIC_AUTH_TOKENare both set. Reframe worth carrying:substrate cadence resumed with a same-day rollback discipline, not265 broke shipping. Log against MOC - Agentic Coding and MOC - Developer Tools. -
v2.1.265 + v2.1.266 — Substrate Cadence Resumes With Same-Day Rollback Discipline (September 9, 2026):
v2.1.265(2026-09-08) is the substantive drop after three maintenance days —--plugin-dirfolder-of-plugins with hot add/remove, 1 GB tool-result disk cap with truncation notice, MCPhttpHTTP+SSE fallback per spec, prompt-cache reuse fixed for resumed foreground subagents and agent teammates,cdpersistence across turns in-p/ SDK / cloud sessions, tmux two-key-shortcut fix, Windows AppContainer symlink-resolution fix.v2.1.266(2026-09-08) is a single-item hotfix reverting av2.1.265regression where the undocumentedCLAUDE_CODE_USE_GATEWAYenv var began forcing Cloud-gateway sign-in on its own, breaking setups that also set an API key,apiKeyHelper, or custom auth headers — the variable is ignored again unlessANTHROPIC_BASE_URL+ANTHROPIC_AUTH_TOKENare both set. Load-bearing framing to carry: substrate cadence resumed with a same-day rollback discipline, not265 broke shipping— a substantive release plus a same-day hotfix inside one calendar day is the mature-substrate motion, and closes the three-day maintenance stretch flagged in 2026-09-07-AI-Digest / 2026-09-08-AI-Digest. Covered in 2026-09-09-AI-Digest.
Key Developments (Addendum — September 2026)
- v2.1.261 Closes the Subagent-Context-Blowout Complaint (September 4, 2026): 128K
bashOutputMaxChars/taskOutputMaxChars,--append-subagent-system-prompt-file, and an in-IDE MCP Add/Remove dialog together move the CLI from “you can spawn subagents but they’ll blow up your context and their prompts will be truncated at shell-arg limits” to “you can spawn them with disciplined output caps and file-loaded briefings.” Load-bearing framing to carry: substrate hardening for the/loopand background-agent workflows, not another feature-drop — the two-part fix (output caps + file-driven system prompt) is the concrete answer to a complaint that has trailed the substrate for six months. VS Code surface adds hollow-ring indicator for sessions open elsewhere, fold button on permission prompts, friendly model names in/model, and the load-bearing in-IDE MCP Add/Remove dialog (MCP configuration was previously terminal-only). Covered in 2026-09-05-AI-Digest.