← All reports

Changes on 2026-03-16

18 total changes in 3 runs

21:46 EST

🤖 AI Batch Analysis

```markdown 1. **Overall Summary** 本次更新(2.1.77)主要侧重于**性能优化**(启动与恢复速度大幅提升)和**关键安全性修复**(修复了权限绕过漏洞),同时显著改善了 **Vim 与 tmux 环境下的兼容性**及用户体验。 2. **Key Themes** * **安全与权限强化**:修复了 `PreToolUse` 钩子可能绕过 `deny` 权限规则的严重漏洞,以及复合 Bash 命令(如 `cd src && npm test`)保存单一规则导致的失效问题。 * **性能与稳定性**:修复了自动更新器可能导致数 GB 内存泄漏的问题;macOS 启动提速约 60ms,`--resume` 加载速度提升 45% 并降低内存峰值。 * **终端与编辑器兼容性**:修复了 Vim 模式下按键失灵、tmux 会话崩溃/剪贴板失效、以及 iTerm2 和 xterm.js 终端下的多项渲染与交互问题。 * **功能增强**:提升了 Claude Opus 4.6 和 Sonnet 4.6 的输出 Token 上限;新增 `/copy N` 命令;改进了插件验证工具 `claude plugin validate`。 * **Agent 行为变更**:移除了 Agent 工具的 `resume` 参数,改为使用 `SendMessage` 自动恢复。 3. **Impact Level** **High** * **Reasoning**:此次更新修复了可能导致安全策略失效(绕过 `deny` 规则)和系统资源耗尽(内存泄漏)的高严重性问题。同时,Agent 工具的 API 变更要求开发者修改相关代码,且 `--resume` 的性能提升对大型项目工作流影响显著。 4. **Action Items for Developers** * **修改 Agent 调用代码**:停止在 Agent 工具中使用 `resume` 参数,改用 `SendMessage({to: agentId})` 来恢复已停止的 Agent。 * **验证插件配置**:使用改进后的 `claude plugin validate` 命令检查你的技能和 Agent 配置,修复 YAML 解析错误或架构违规。 * **更新命令脚本**:将脚本中的 `/fork` 命令逐步迁移至新的 `/branch` 命令(虽然 `/fork` 仍作为别名可用)。 * **测试复杂 Bash 命令**:在更新后重新测试包含 `&&` 或 `;` 的复合命令,确认 "Always Allow" 权限规则是否正确拆分和应用。 ```
💭 Model Reasoning
1. **Analyze the Request:** * **Role:** World-class programmer analyzing documentation changes. * **Input:** A diff from `CHANGELOG.md.md` (version 2.1.77). * **Output Format:** Concise, insightful analysis in Markdown. * **Language:** Chinese. * **Structure:** 1. Overall Summary (1-2 sentences). 2. Key Themes (bullets). 3. Impact Level (Low/Medium/High/Breaking) with reasoning. 4. Action Items for Developers (max 5 bullets). 2. **Analyze the Input (Diff):** * **Version:** 2.1.77. * **New Features/Enhancements:** * Increased output token limits (Opus 4.6 default to 64k, upper bound to 128k). * New sandbox filesystem setting `allowRead`. * `/copy` command accepts index (`/copy N`). * Faster startup (macOS ~60ms). * Faster `--resume` (up to 45% faster, less memory). * Auto-naming sessions from plan content. * Improved `claude plugin validate`. * Renamed `/fork` to `/branch` (alias exists). * VSCode improvements (plan titles, option+click hint). * **Bug Fixes (Security/Permissions):** * Fixed "Always Allow" for compound bash commands (saving single rule -> per subcommand). This is a major security/UX fix. * Fixed `PreToolUse` hooks bypassing `deny` rules (Critical security fix). * Fixed Write tool line ending conversions (CRLF). * Fixed `--resume` truncating history (Data loss risk). * **Bug Fixes (Stability/Memory):** * Fixed auto-updater memory leak (tens of GBs). * Fixed memory growth in long sessions. * Fixed race condition deleting worktrees. * Fixed background bash tasks exceeding 5GB. * **Bug Fixes (UI/UX/Terminal):** * Fixed Vim mode issues (Backspace/Delete, status line). * Fixed tmux compatibility (crashes, clipboard, colors). * Fixed IDE integration connection. * Fixed CJK character clipping. * Fixed input deadlock. * **API/Tooling Changes:** * Agent tool no longer accepts `resume` parameter (Breaking change behavior). * `SendMessage` auto-resumes agents. 3. **Drafting the Analysis (Internal Monologue -> Translation to Chinese):** * **Overall Summary:** This release (2.1.77) focuses heavily on stability, performance improvements (startup/resume speed), and critical security fixes regarding permissions. It also introduces minor feature enhancements and resolves numerous UI/terminal compatibility issues (especially for Vim and tmux). * **Key Themes:** * *Security & Permissions:* Fixes to bash command permissions ("Always Allow") and `PreToolUse` hooks bypassing denials. * *Performance & Stability:* Faster startup/resume, fixed memory leaks (auto-updater), and handling large files/tasks. * *Terminal/Editor Compatibility:* Major fixes for Vim, tmux, and various terminal emulators (iTerm2, VS Code). * *Feature Tweaks:* Increased token limits, `/copy` index support, renamed `/fork`. * **Impact Level:** High. * *Reasoning:* The fixes to `PreToolUse` bypassing `deny` rules and the memory leak in the auto-updater are critical. The performance gains are significant. The changes to Agent tool parameters require attention from plugin developers. * **Action Items:** * Review agent-related code: Update to use `SendMessage({to: agentId})` instead of the `resume` parameter in the Agent tool. * Update documentation/scripts: Note that `/fork` is now primarily `/branch`. * Test complex bash workflows: Verify that permission prompts behave correctly with compound commands. * Plugin developers: Use the improved `claude plugin validate` to catch schema errors. 4. **Refining the Chinese Output:** * *Summary:* 本次更新(2.1.77)主要侧重于**性能提升**(启动和恢复速度显著加快)、**关键安全修复**(权限系统漏洞)以及**终端兼容性**的大幅改进(特别是 Vim 和 tmux 支持)。 * *Themes:* * **安全与权限**:修复了 "Always Allow" 在复合命令中的错误逻辑,以及 `PreToolUse` 钩子可能绕过 `deny` 规则的严重漏洞。 * **性能与稳定性**:修复了自动更新器的内存泄漏问题,提升了 macOS 启动速度和 `--resume` 恢复速度。 * **终端与编辑器体验**:解决了 Vim 模式按键失效、tmux 会话崩溃/剪贴板问题及 CJK 字符显示异常。 * **功能迭代**:提升了 Claude Opus/Sonnet 的输出 Token 限制,增强了插件验证工具。 * *Impact:* **High** (高)。 * *Reasoning:* 修复了绕过 `deny` 权限规则的安全漏洞以及严重的内存泄漏问题。Agent 工具参数变更涉及开发层面的修改,且性能提升对日常使用体验影响显著。 * *Action Items:* * **更新 Agent 调用逻辑**:如果你使用了 Agent 工具的 `resume` 参数,请改为使用 `SendMessage({to: agentId})` 来恢复已停止的 Agent。 * **检查权限设置**:重新测试包含复合命令(如 `cd src && npm test`)的 Bash 工具,确认权限提示逻辑已修复。 * **使用新工具验证插件**:运行 `claude plugin validate` 以检查新的 Skill 和 Agent frontmatter 规范。 * **注意命令别名**:将脚本中的 `/fork` 命令更新为 `/branch`(虽然旧命令仍可用,但建议迁移)。 5. **Final Polish:** Check against constraints (concise, markdown, max 5 action items). * *Self-Correction during drafting:* Ensure I explicitly mention the `resume` parameter removal as it's a breaking change behavior. Make sure to highlight the "Always Allow" fix as it's annoying for developers. 6. **Final Output Generation** (Matches the thought process above).

📚 Claude Code GitHub

15:52 EST

🤖 AI Batch Analysis

## 文档变更分析报告 ### 1. 整体摘要 本次更新主要优化了插件与 Hooks 的动态重载机制(现在支持 LSP 服务器热重载),并引入了 Extended Thinking 的 `display` 控制 API 以降低延迟。同时,对数据收集和反馈调查的控制进行了更细粒度的调整。 ### 2. 关键变更主题 - **插件与 Hooks 自动化增强**:文件监视器现在会自动检测并加载 Hooks 配置变更,无需手动审查或重启;`/reload-plugins` 现已支持热重载插件关联的 LSP 服务器,而不仅仅是 MCP 服务器和命令。 - **API 延迟优化**:新增 Extended Thinking 的 `display: "omitted"` 选项,允许在流式响应中跳过思考内容的传输,显著降低首字延迟(TTFT),适用于无需向用户展示思考过程的自动化场景。 - **隐私与控制细化**:明确了 Bedrock/Vertex/Foundry 环境下的默认行为——虽然默认禁用遥测,但会话质量调查除外;新增 `feedbackSurveyRate` 设置允许精确控制调查出现频率。 - **流式事件更新**:当使用 `display: "omitted"` 时,流式响应将不再发送 `thinking_delta` 事件,仅发送 `signature_delta`。 ### 3. 影响级别:中高 **理由**: - **插件开发者**:工作流显著简化,LSP 配置变更不再需要重启 Claude Code,大幅提升开发效率。 - **API 集成者**:新引入的 `display` 参数为高性能/延迟敏感的应用提供了重要的优化路径(需注意 SDK 类型支持情况)。 - **企业用户**:对第三方提供商下的数据收集行为有了更明确的控制权,有助于合规管理。 ### 4. 开发者行动项 - **插件开发**:利用 `/reload-plugins` 热重载 LSP 配置,无需重启会话即可测试变更。 - **API 调优**:对于不需要向终端用户展示“思考”内容的后台任务或自动化流程,设置 `thinking.display: "omitted"` 以减少首字延迟。 - **隐私配置**:在 Bedrock/Vertex/Foundry 环境中,若需完全禁用调查,请在设置中配置 `CLAUDE_CODE_DISABLE_FEEDBACK_SURVEY=1` 或调整 `feedbackSurveyRate`。 - **流式处理逻辑**:更新流式解析代码以处理 `content_block_start` 中新增的 `signature` 字段,并适配无 `thinking_delta` 事件的情况。 - **Hooks 管理**:移除关于 Hooks 变更需要手动审查的旧逻辑,依赖文件监视器的自动加载机制;若变更未生效,再考虑重启。
💭 Model Reasoning
用户希望我以世界级程序员的角度分析这批文档变更,并用中文提供简洁的洞察。我需要关注对开发者重要的内容。 让我分析这11页的变更: 1. **data-usage.md**: - 改进了反馈调查的控制机制 - 明确了Bedrock/Vertex/Foundry默认关闭非必要流量,但会话质量调查是个例外 - 添加了`feedbackSurveyRate`设置来控制调查频率 2. **discover-plugins.md**: - 插件安装后需要运行`/reload-plugins`来激活 - 改进了`/reload-plugins`的说明 3. **hooks.md**: - hooks的文件监视器现在自动检测变更,不需要手动审查 4. **hooks-guide.md**: - 与hooks.md类似,说明hooks变更会自动生效 5. **mcp.md**: - 插件MCP服务器的生命周期管理更新 - 插件变更后需要运行`/reload-plugins` 6. **plugins.md**: - `/reload-plugins`现在也能重新加载LSP服务器 - 之前需要完全重启 7. **settings.md**: - `feedbackSurveyRate`设置更新了说明 8. **build-with-claude/vision.md**: - 小幅语言改进 - 强调了文件大小限制 9. **build-with-claude/pdf-support.md**: - 小幅语言改进 - PDF大小限制说明 10. **build-with-claude/extended-thinking.md**: - 重大新增:`display`字段控制思考内容的显示 - 新增"omitted"选项可以减少延迟 - 提供了多语言代码示例 11. **build-with-claude/streaming.md**: - 与extended-thinking.md相关的流式更新 - 当`display: "omitted"`时没有`thinking_delta`事件 **关键主题**: 1. **插件和hooks的自动重载**:文件监视器现在自动检测变更,简化了开发工作流 2. **反馈调查控制**:更细粒度的控制,包括频率设置 3. **思考显示控制**:新增API功能,允许省略思考内容以减少延迟 4. **MCP服务器生命周期**:与插件重载集成 **影响级别**: - **中等到高**: - 插件开发者需要知道`/reload-plugins`的行为变化 - API使用者需要注意新的`display`字段用于思考控制 - hooks自动检测变更简化了开发流程 **开发者行动项**: 1. 了解`/reload-plugins`现在会重新加载LSP服务器(不仅仅是MCP) 2. 考虑使用新的`display: "omitted"`选项来减少延迟,如果不向用户展示思考内容 3. 注意hooks现在通过文件监视器自动更新,无需手动干预 4. 使用`feedbackSurveyRate`来控制反馈调查的频率 5. 对于大型文档/图片,注意文件大小限制 让我用中文整理成要求的markdown格式。

📚 Claude Code

13:56 EST

🤖 AI Batch Analysis

1. **Overall Summary** 本次文档更新主要围绕 **Hooks 权限系统的重大增强** 和 **插件子代理的安全限制** 展开。新的权限控制模型允许开发者通过 Hooks 进行细粒度的规则管理(如自动批准、模式切换),同时为了安全性,移除了插件子代理对敏感配置字段的支持。 2. **Key Themes** * **细粒度权限控制**: `PermissionRequest` Hook 引入了 `updatedPermissions` 数组,支持 `addRules`、`setMode`、`addDirectories` 等操作,并允许将更改持久化到不同层级的设置文件中。 * **安全加固**: 插件定义的子代理出于安全原因不再支持 `hooks`、`mcpServers` 和 `permissionMode` 字段,强制开发者将敏感逻辑移至本地配置。 * **自动化工作流**: 增加了通过 Hooks 自动批准特定权限(如 `ExitPlanMode`)的实战指南,减少了手动中断。 * **API 账务透明化**: 新增 API `402` 错误码及各层级用户的“月度消费上限”说明。 * **文档代码优化**: 优化了 Statusline 示例中的 Shell 脚本,使用更高效的 Bash 参数扩展替代管道操作。 3. **Impact Level** **Medium** * **Reasoning**: `PermissionRequest` Hook 的数据结构发生了显著变化(从简单的布尔建议转向结构化的规则数组),现有自定义 Hook 需要适配。此外,插件子代理的限制属于功能性缩减,插件开发者必须修改代码。API 变更仅为信息性补充。 4. **Action items for developers** * **适配新 Hook Schema**: 检查并更新现有的 `PermissionRequest` Hooks,将旧的 `permission_suggestions` 逻辑迁移至新的 `updatedPermissions` 结构(支持 `destination` 和 `type` 字段)。 * **重构插件代理**: 若您维护插件,请确保移除插件定义的 Subagent 中的 `hooks`、`mcpServers` 和 `permissionMode` frontmatter 字段,并在文档中引导用户将其添加至本地 `.claude` 配置。 * **实现自动批准**: 利用新的 `decision` 对象和 `setMode` 类型,编写 Hooks 以自动批准常用操作(如退出规划模式),提升开发流程度。 * **处理 API 错误**: 在 API 客户端中增加对 `402 billing_error` 的捕获和处理逻辑。 * **监控账单**: 根据新的“月度消费上限”表,审查您的 API 使用层级,防止服务因超出额度而中断。
💭 Model Reasoning
1. **Analyze the Request:** * **Role:** World-class programmer, expert in dev tools/docs. * **Task:** Analyze documentation changes as a single batch. * **Input:** 6 pages with diffs (hooks.md, hooks-guide.md, statusline.md, sub-agents.md, api/rate-limits.md, api/errors.md). * **Output Format:** Markdown, Chinese language, specific structure (Overall Summary, Key Themes, Impact Level, Action Items). 2. **Analyze the Diffs:** * **Page: hooks.md (+28 / -8)** * *Change:* Updated the `PermissionRequest` hook mechanism. It replaces the old `toolAlwaysAllow` in `permission_suggestions` with a more structured `addRules` approach. * *New Schema:* Introduced `updatedPermissions` with entry types (`addRules`, `replaceRules`, `removeRules`, `setMode`, `addDirectories`, `removeDirectories`). * *Destinations:* Added `destination` field (`session`, `localSettings`, `projectSettings`, `userSettings`) to control persistence. * *Significance:* Significant overhaul of how hooks handle permissions, moving from simple "allow/deny" to granular rule management (modes, directories) with persistent storage options. * **Page: hooks-guide.md (+18 / -0)** * *Change:* Added a new section "Auto-approve specific permission prompts". * *Content:* Examples of how to use `PermissionRequest` hooks to auto-approve `ExitPlanMode` or switch permission modes (e.g., to `acceptEdits`). * *Significance:* Practical guide on using the new granular permission control features introduced in `hooks.md`. It explicitly warns about security (narrow matchers). * **Page: statusline.md (+6 / -4)** * *Change:* Updated shell script examples for progress bars. * *Content:* Switched from using `printf ... | tr ' ' 'char'` to `printf -v var ...` and bash parameter expansion `${var// /char}`. * *Significance:* Code quality improvement (performance/readability) in documentation examples. `tr` involves subshells/pipes; the new way is pure bash and generally faster. This is a minor improvement to examples. * **Page: sub-agents.md (+1 / -0)** * *Change:* Added a note about security restrictions on Plugin subagents. * *Content:* Plugin subagents ignore `hooks`, `mcpServers`, and `permissionMode` frontmatter fields. * *Significance:* Breaking change/clarification for plugin developers. If a developer tried to define a custom hook or permission mode inside a plugin agent, it won't work anymore (or was clarified to not work). This is a security hardening measure. * **Page: api/rate-limits.md (+3 / -0)** * *Change:* Added "Monthly Spend Limit" column to the tier table. * *Content:* Explicitly states the cap per month for each tier. * *Significance:* Clarification on billing constraints for API users. * **Page: api/errors.md (+1 / -0)** * *Change:* Added 402 `billing_error` to the error list. * *Significance:* Standardization of billing error handling. 3. **Synthesize and Structure:** * **Overall Summary:** The documentation update primarily focuses on significantly enhancing the granular control over permissions via hooks, tightening security for plugin subagents, and clarifying API billing limits. It refines examples for better code quality. * **Key Themes:** * *Enhanced Hook System:* Granular permission control (modes, directories, persistence). * *Security Hardening:* Restrictions on plugin subagents regarding hooks/MCP. * *API Clarity:* Billing limits and error codes. * *Code Quality:* Optimization of shell scripting examples. * **Impact Level:** **Medium**. * Reasoning: The permission hook changes are substantial (`addRules` replacing older structures, though the diff shows it evolving from `permission_suggestions` type definitions). The plugin subagent restriction is a potential breaking change for plugin authors. The API changes are informative. * **Action Items:** * Review and update custom `PermissionRequest` hooks to use the new `updatedPermissions` schema. * Plugin developers need to remove `hooks`/`mcpServers`/`permissionMode` from plugin subagent definitions and move them to global settings or local files. * API users should check billing limits in the updated table. * Developers can implement auto-approval workflows using the new hook examples. 4. **Drafting the Response (in Chinese):** * *Summary:* 本次文档更新主要集中在大幅增强 Hooks 对权限控制的细粒度管理能力,加强了插件子代理的安全性限制,并明确了 API 的账单限制。 * *Themes:* * Hooks 权限系统升级:从简单的允许/拒绝升级为支持规则增删改、模式切换及目录管理的复杂操作。 * 安全性限制:插件子代理不再支持特定敏感字段。 * API 账单透明化:明确了月度消费上限。 * *Impact:* Medium. 因为 Hooks 系统的 JSON 结构发生了显著变化,且插件开发者需要适配新的安全限制。 * *Actions:* 1. 更新 `PermissionRequest` hook 代码以适配新的 `updatedPermissions` 结构。 2. 插件开发者需移除插件子代理中的 `hooks`、`mcpServers` 等字段。 3. 利用新特性实现特定权限的自动批准(如 `ExitPlanMode`)。 4. API 调用者注意新增的 `402` 错误码及月度消费上限。 5. **Refining the Output:** * Make it concise and "world-class". Use precise terminology. * Highlight the distinction between the new hook schema (`addRules`, `destination`) and the old implicit behavior. * Ensure the plugin security note is highlighted as a necessary action for that specific group. 6. **Final Polish (Self-Correction during drafting):** * The statusline change is minor optimization. I'll group it under "Code Quality" or ignore it in the high-level summary if space is tight, but I'll mention it in themes or just focus on the big changes. *Decision:* Focus on the big changes in themes, maybe mention the statusline fix as a side note or omit if it's too trivial for a "world-class" summary. I will omit it from the main themes to keep focus on high impact, but it's part of the batch. Actually, the prompt asks for "Key Themes", so code quality in docs is a valid theme. 7. **Final Output Generation:** (matches the requested markdown structure).

📚 Claude Code

📚 Anthropic API