← All reports

Changes on 2026-08-29

22 total changes in 2 runs

15:05 EST

🤖 AI Batch Analysis

### 1. Overall Summary 本次文档更新主要引入了针对模型切换的 Hooks 事件,增强了云环境中 API 凭据安全性的说明,并修正了技能管理菜单的快捷键交互错误,同时补充了关于数据保留和监控指标的新细节。 ### 2. Key Themes * **新增模型切换 Hooks**:引入了 `PreModelSwitch` 和 `PostModelSwitch` 两个新事件,允许开发者在模型变更前后进行拦截、控制或注入上下文,提升了自动化工作流的控制力。 * **云环境安全增强说明**:明确了在 Anthropic 托管的云环境中,API 密钥和 Git 凭据均保存在沙箱之外,通过安全代理附加到请求中,进一步隔离了敏感信息。 * **数据保留与监控优化**:阐明桌面端和 Cowork 会话的记录默认豁免于 30 天清理限制,并新增了 `transcripts_exempted_desktop` 监控指标以跟踪此类豁免数据。 * **功能限制澄清**:明确指出在云端会话中,Claude Code 不会启动插件的语言服务器(LSP),因此无法使用代码智能功能。 * **合规性细节**:当使用 CMEK(客户托管加密密钥)并配置 LLM 网关或自定义 Base URL 时,CMEK 不适用于 Claude Code 的操作遥测数据。 ### 3. Impact Level **Medium** **Reasoning**: 虽然大部分是文档清理和说明性更新,但引入新的 Hooks 事件为开发者提供了新的编程接口和扩展能力。此外,关于凭据安全和合规性的澄清对于企业级部署和敏感项目开发具有重要参考价值。技能菜单快捷键的修正属于 UX 体验的小幅改善。 ### 4. Action Items for Developers * **利用新 Hooks**:查看 Hooks 指南,利用 `PreModelSwitch` 和 `PostModelSwitch` 实现模型切换的权限控制或自动化逻辑。 * **检查云端限制**:如果在云端使用 Claude Code,请注意代码智能(LSP)插件将不可用,需调整开发习惯。 * **更新操作习惯**:在使用 `/skills` 菜单保存设置时,使用 `Esc` 键而非 `Enter` 键。 * **监控合规数据**:如果是企业用户,检查监控日志中的 `transcripts_exempted_desktop` 指标,了解本地数据保留情况。 * **审查安全配置**:如果使用 LLM 网关和 CMEK,请通过 `DISABLE_TELEMETRY` 配置以确保完全关闭遥测以满足合规要求。
💭 Model Reasoning
1. **Analyze the Request:** * **Role:** World-class programmer analyzing documentation changes. * **Output:** Concise, insightful analysis in Markdown format. * **Focus:** What matters to developers. * **Language:** Chinese (as per specific instruction "请用中文回复"). * **Input:** A batch of 12 documentation page diffs. * **Required Structure:** 1. Overall Summary (1-2 sentences). 2. Key Themes (bullets). 3. Impact Level (Low/Medium/High/Breaking) with reasoning. 4. Action Items (bullets, max 5). 2. **Analyze the Diffs (Page by Page):** * **`claude-code-on-the-web.md`**: * *Change*: Updated "Credential protection" section. Added "API credentials" bullet. Clarified that in Anthropic-hosted envs, API keys added to cloud envs stay outside the sandbox and are attached to requests after they leave. Self-hosted envs don't have these API credentials. * *Implication*: Security enhancement/clarification. Developers using web/cloud environments now know their API keys are safer (not directly in the sandbox). * **`data-usage.md`**: * *Change*: Added a note about transcript retention. Sessions started/continued in Claude Desktop or Cowork are exempt from the 30-day local caching limit by default. * *Implication*: Data retention policy change/clarification. Local disk usage might differ based on client type. * **`discover-plugins.md`**: * *Change*: Added note that in cloud sessions, Claude Code doesn't start plugin language servers, so the LSP tool isn't available there. * *Implication*: Functional limitation awareness for cloud users. * **`hooks.md`**: * *Change*: Added `PreModelSwitch` and `PostModelSwitch` hooks to the lifecycle diagram and event table. Updated exit code 0 description to include `PostModelSwitch`. Updated permission decision logic for `PreModelSwitch` (allow/deny/ask). * *Implication*: New feature: Model switching hooks. Allows developers to intercept and control model changes programmatically. * **`hooks-guide.md`**: * *Change*: Similar to `hooks.md`. Added `PreModelSwitch` and `PostModelSwitch` to event table. Updated exit code 0 docs. Updated `permissionDecision` logic for `PreModelSwitch`. * *Implication*: Reinforces the new model switching hook capability and how to use it. * **`monitoring-usage.md`**: * *Change*: Updated `skip_reason` to include `desktopSessionCleanupPeriodDays`. Added `transcripts_exempted_desktop` metric. * *Implication*: Better monitoring for the new Desktop/Cowork transcript exemption logic introduced in `data-usage.md`. * **`overview.md`**: * *Change*: Removed redundant `theme={null}` attributes from code blocks. * *Implication*: Markdown cleanup. No functional change. * **`plugins-reference.md`**: * *Change*: Added `PreModelSwitch` and `PostModelSwitch` to the event table. * *Implication*: Consistency update for plugins supporting the new hook types. * **`setup.md`**: * *Change*: Removed redundant `theme={null}` attributes. * *Implication*: Markdown cleanup. * **`skills.md`**: * *Change*: Corrected key shortcut for saving in `/skills` menu. Changed from `Enter` to `Esc`. * *Implication*: UX correction. Developers were likely confused if they pressed Enter and nothing happened (or it did something else). * **`slash-commands.md`**: * *Change*: Same correction as `skills.md`. `Enter` -> `Esc` for saving skill overrides. * *Implication*: UX correction. * **`third-party-integrations.md`**: * *Change*: Added note about CMEK (Customer-Managed Encryption Keys). If using CMEK with LLM gateways/custom base URLs, CMEK doesn't apply to Claude Code's operational telemetry. Suggests `DISABLE_TELEMETRY` via managed settings. * *Implication*: Security/Compliance nuance. Important for enterprise security teams. 3. **Synthesize Key Themes:** * **Model Switching Hooks:** The biggest technical addition. `PreModelSwitch` and `PostModelSwitch` hooks allow fine-grained control over model changes. * **Security & Credentials:** Clarifications on how API keys are handled in the cloud (outside sandbox) and telemetry behavior with CMEK. * **Data Retention & Monitoring:** Desktop/Cowork sessions exempt from standard cleanup; new metrics added. * **UX Fixes:** Corrected key bindings (`Esc` instead of `Enter`) in skill menus. * **Functional Limitations:** LSP plugins don't run in cloud sessions. 4. **Determine Impact Level:** * *Low/ Medium*. * Most changes are clarifications or small fixes. * The new hooks (`PreModelSwitch`) are a "Medium" impact feature for advanced users/integrators, but not a "Breaking" change. * Overall, I'd lean towards **Medium** because of the new hooks and the credential security update, which affects how people architect secure deployments. 5. **Draft Action Items (in Chinese):** * Review hooks documentation to utilize the new `PreModelSwitch`/`PostModelSwitch` events for workflow automation. * Check monitoring logs for the new `transcripts_exempted_desktop` metric. * Note the corrected `Esc` key shortcut when managing skills. * Be aware that LSP features are unavailable in cloud sessions. * Update security protocols regarding API key handling and CMEK telemetry if using custom gateways. 6. **Draft the Response (in Chinese):** * *Summary*: 本次更新引入了模型切换的 Hooks,增强了云环境中的凭据安全性说明,并修正了部分 UI 交互和 Markdown 格式问题。 * *Themes*: * 新增 `PreModelSwitch` 和 `PostModelSwitch` Hooks,允许拦截和控制模型变更。 * 澄清云环境中 API 密钥的安全隔离机制(沙箱外)。 * 桌面端/协作端会话记录清理规则的更新与监控指标增强。 * 修复技能菜单中的键盘快捷键错误(Esc 代替 Enter)。 * *Impact*: Medium. 新增 Hooks 提供了更强的控制能力,安全说明的澄清对企业用户很重要,其他主要是错误修正。 * *Action Items*: * 利用新 Hooks 实现模型切换的自动化控制或审计。 * 检查监控数据中的 `transcripts_exempted_desktop` 指标。 * 使用 `/skills` 菜单时注意按 `Esc` 保存设置。 * 留意云端会话不支持 LSP 插件的限制。 7. **Refine and Polish:** Ensure the tone is professional and concise. * *Self-Correction during drafting*: The CMEK point in `third-party-integrations.md` is subtle but important for compliance. I should mention it in the themes or summary. The "API credentials" section in `claude-code-on-the-web.md` is actually a significant security clarification—keys are proxied, not just hidden. 8. **Final Output Generation** (Proceed to generate markdown).
06:40 EST

🤖 AI Batch Analysis

### 整体摘要 本次文档更新主要侧重于**安全性增强**和**行为澄清**。最显著的变化是 Claude Code 现在会在将本地仓库上传到云端会话时自动排除敏感凭证文件(如 `.env`、密钥等)。此外,文档还优化了网络代理处理的说明,改进了调试日志的区分度,并澄清了过期会话恢复时的行为限制。 ### 关键主题 * **安全性增强(云端上传)**:在 macOS、Linux 和 WSL 上使用 `--cloud` 上传非 GitHub 仓库时,Claude Code 现在会自动排除包含凭据或密钥的文件(如 `.env`、`*.tfvars`、`id_rsa`、`*.pem`),并明确列出被排除的文件名。 * **调试日志精确化**:在监控和遥测部分,文档现在明确区分了 `[3P telemetry]`(用户配置的第三方导出器错误)和 `[Anthropic telemetry]`(Anthropic 自身的运营遥测),帮助开发者更准确地排查配置问题。 * **网络配置优化**:明确说明 Claude Code 的 WebSocket 连接不会通过代理连接 `localhost`、`::1` 或 `127.0.0.0/8`,因此无需在 `NO_PROXY` 中配置这些回环地址。 * **会话恢复行为澄清**:明确指出当云会话 VM 被回收后,重新打开会话虽然可以恢复对话历史,但**不会**恢复当时正在运行的后台工作(如子代理和 Shell 命令)。 * **措辞与格式调整**:多处文档进行了措辞微调(如去除了 "powerful" 等形容词),并修复了 `overview.md` 中代码块元数据的重复问题。 ### 影响等级:中等 **理由**:本次更新包含一项重要的安全改进(自动排除敏感文件),直接影响了数据隐私保护。其他更改主要是关于排查错误的澄清和网络配置的最佳实践说明。虽然不涉及破坏性变更,但安全特性的引入值得开发者关注。 ### 开发者行动项 1. **审查云端上传行为**:如果您使用 `claude --cloud` 且未连接 GitHub,请知晓敏感文件(`.env`、密钥)现在会被自动排除上传,确保这符合您的工作流预期。 2. **优化排查策略**:在配置 OpenTelemetry 或监控时,若遇到导出问题,请在调试日志中专门搜索 `[3P telemetry]` 标签,忽略 `[Anthropic telemetry]` 相关信息。 3. **清理代理配置**:检查您的代理环境变量,可以移除针对 `localhost` 或 `127.0.0.1` 的 `NO_PROXY` 设置,因为 Claude Code 已自动处理。 4. **注意会话持久化**:在依赖长时间运行的后台任务时,请注意云会话的不活跃回收机制会导致这些任务丢失,需在重新连接后手动重启。
💭 Model Reasoning
1. **Analyze the Request:** * **Role:** World-class programmer analyzing documentation changes. * **Input:** A batch of documentation changes (10 pages) showing diffs. * **Output Format:** Markdown, Chinese language. * **Structure:** Overall Summary, Key Themes, Impact Level, Action Items. 2. **Analyze the Diffs (Page by Page):** * **Page: `claude-code-on-the-web.md`** * *Change 1:* Security improvement. When bundling local repos for cloud sessions, Claude Code now explicitly excludes sensitive files (`.env`, `*.tfvars`, `id_rsa`, `*.pem`) from uploads on macOS/Linux/WSL. It names the files excluded. * *Change 2:* New error message added for organization policy verification failure. * *Change 3:* Clarification that background work (subagents, shell commands) is *not* restored when reopening an expired session. * **Page: `gitlab-ci-cd.md`** * *Change:* Phrasing update from "enables powerful CI/CD workflows" to "In a GitLab pipeline, Claude Code can:". Minor wording polish. * **Page: `jetbrains.md`** * *Change:* Wording polish in the warning about accepting connections from all network interfaces. Changed "when loopback genuinely cannot work" to "when loopback can't work". * **Page: `monitoring-usage.md`** * *Change 1:* Debugging guidance updated. Distinguishes between `[3P telemetry]` errors (your configured exporter) and `[Anthropic telemetry]` (operational, not a problem). * *Change 2:* Wording change: "provides detailed insights" -> "describes... in detail". * *Change 3:* Updated error reference to `[3P telemetry]` export errors. * **Page: `network-config.md`** * *Change:* Optimization detail. WebSocket connections to localhost (`localhost`, `::1`, `127.0.0.0/8`) are automatically bypassed from proxy configuration, so manual `NO_PROXY` entries aren't needed. * **Page: `overview.md`** * *Change 1:* Syntax highlighting metadata clutter (`theme={null}` repeated many times). Looks like a markdown generator artifact change. Content remains the same. * *Change 2:* Wording change in link text: "orchestrate subagents at scale" -> "orchestrate many subagents at once". * **Page: `sandboxing.md`** * *Change 1:* Wording change: "leverages operating system security primitives" -> "uses operating system security primitives". * *Change 2:* Security warning update. Changed "powerful system services" to "system services". * **Page: `skills.md`** * *Change:* Wording change: "One powerful pattern" -> "One pattern". Downplaying the superlative slightly. * **Page: `slash-commands.md`** * *Change:* Wording change: "One powerful pattern" -> "One pattern". Consistent with `skills.md`. * **Page: `third-party-integrations.md`** * *Change:* Header change. "Leverage MCP for integrations" -> "Use MCP for integrations" with an explicit ID added. 3. **Synthesize Findings:** * *Security/Privacy:* The most significant change is the automatic exclusion of credentials/keys (`.env`, keys) when uploading local repos to the cloud. Also, the localhost proxy bypass is a small but helpful networking optimization. * *Clarity/Debugging:* Better distinction between third-party telemetry errors and Anthropic's own telemetry in logs. Clarification on expired sessions not restoring background work. * *Wording/Style:* Many changes are stylistic (removing "powerful", "leverages", simplifying headers). The `theme={null}` artifact is likely a build tool update, not content change. * *Functionality:* No breaking API changes. Behavior improvements in bundling. 4. **Draft the Analysis (in Chinese):** * **Overall Summary:** The update focuses on security improvements (credential protection during cloud uploads), networking optimizations (localhost proxy handling), and clarification of behavior (session restoration, debugging logs). There are also numerous stylistic wording refinements. * **Key Themes:** * Enhanced Security: Automatic exclusion of sensitive files (`.env`, keys) during repo bundling for cloud sessions. * Debugging Precision: Clear distinction between user-configured telemetry errors and Anthropic's internal telemetry. * Networking: Automatic bypass of proxies for localhost WebSockets. * Session Behavior: Confirmation that background tasks (subagents) aren't restored in expired sessions. * **Impact Level:** Medium. The credential exclusion is a significant security/privacy enhancement. The rest are mostly clarifications and QoL improvements. * **Action Items:** * Review cloud session behavior: Know that `.env` and keys are now automatically excluded from uploads. * Debugging: Look for `[3P telemetry]` specifically when checking OTel export errors. * Networking: Remove unnecessary `localhost` entries from `NO_PROXY` if you have them. 5. **Refine Content:** * *Refining the "Security" point:* Make sure to mention the specific file types. * *Refining the "Impact" level:* "Medium" fits because the security change is important for users using `--cloud` without GitHub, but doesn't break existing code. * *Refining "Action Items":* Keep them practical. Don't worry about the wording changes in action items. 6. **Final Polish (Markdown):** * Summary: 本次更新主要集中在增强安全性(云端上传时自动排除敏感凭证)、网络配置优化(本地代理处理)以及行为说明的澄清(调试日志、会话恢复)。 * Themes: 安全性增强, 调试精确度, 网络优化, 行为澄清. * Impact: 中等. * Action Items: 1. 了解云端上传的凭证排除规则. 2. 调试时关注 `[3P telemetry]`. 3. 简化 `NO_PROXY` 配置. 7. **Final Review against constraints:** * Concise? Yes. * Insightful? Yes, points out the security implication. * Markdown? Yes. * Chinese? Yes. * Focus on developers? Yes. *(Self-Correction during drafting)*: The `theme={null}` changes in `overview.md` are clearly metadata noise. I should mention them briefly as "metadata/formatting" but focus analysis on the semantic changes. 8. **Output Generation.** (Proceed to generate the Chinese response).