← All reports

Changes on 2026-10-06

35 total changes in 3 runs

18:11 EST

🤖 AI Batch Analysis

以下是对此次文档变更的批量分析摘要: ### 1. 总体摘要 此次更新主要集中在**企业级安全合规、Agent 行为优化以及稳定性修复**三个方面。文档新增了详细的数据流出路径映射表,强化了沙箱隔离策略,并明确了子代理中 `effort` 参数的优先级逻辑。同时,针对企业网络环境(代理、SSO)和后台会话的稳定性进行了多项关键修复。 ### 2. 关键变更主题 * **企业级安全与可观测性增强** * **核心新增**:在 `monitoring-usage.md` 中新增了“Map egress paths to managed controls and events”章节,提供了详细的表格,将 Bash、MCP、Hooks、Plugins 等可能的数据流出路径与对应的托管设置及监控事件一一映射。这对合规审计和 SIEM 集成至关重要。 * **数据保留检查**:新增了如何验证“数据清理扫描”是否按预期运行的指南,帮助确认机器是否正确应用了托管的数据保留策略。 * **沙箱隔离策略升级** * **全进程边界**:文档澄清并建议,为了对整个 Claude Code 进程(包括原本在沙箱外运行的进程)进行隔离,应将本地模式运行在 **Sandbox Runtime** 或 **Dev Container** 内部。 * **后台会话隔离**:明确了后台会话的 Bash 命令也会受其独立设置中的沙箱配置约束。 * **Agent 与模型行为优化** * **Effort 参数逻辑**:明确了子代理中的 `effort` 设置会覆盖会话级别,但**不会**覆盖 `CLAUDE_CODE_EFFORT_LEVEL` 环境变量。 * **模型能力查询**:模型 API 响应中新增了 `capabilities.thinking.types.disabled` 字段,用于查询模型是否支持关闭 thinking 模式。 * **稳定性与网络环境修复** * **企业网络**:修复了 `NO_PROXY` 在设置 `HTTPS_PROXY` 时被忽略的问题;优化了 AWS SSO 在企业 VPN/代理环境下的登录循环说明。 * **安全漏洞修复**:修复了 macOS/Windows 上 PDF 读取可能通过链接交换导致的文件越权漏洞,以及 UNC 路径下 PreToolUse hook 可能绕过权限提示的安全问题。 * **后台任务**:修复了后台会话崩溃后计划任务丢失、进程重启后待处理唤醒丢失的问题。 ### 3. 影响等级 **中 / 高** * **理由**: * **高**:新增的数据流出路径映射表和全进程沙箱隔离指南对负责安全和合规的企业开发者至关重要。安全漏洞修复(PDF 读取、UNC 路径)建议尽快采纳。 * **中**:Agent 参数逻辑的变更和众多 Bug 修复(如代理支持、后台任务稳定性)显著改善了开发体验,但通常不涉及破坏性变更。 ### 4. 开发者行动建议 * **审查监控策略**:如果你负责企业部署或合规,请查阅 `monitoring-usage.md` 新增的映射表,配置相应的托管设置和 SIEM 事件收集。 * **更新安全配置**:考虑利用新的“全进程边界”指南,通过 Sandbox Runtime 或 Dev Container 进一步加强隔离环境;评估是否需要更新代理设置以适配 `NO_PROXY` 修复。 * **检查 Agent 配置**:审查子代理定义,确保 `effort` 参数的行为符合预期(注意环境变量拥有更高优先级)。 * **排查网络问题**:如果在企业环境下遇到 AWS SSO 标签页无限弹出,请参考更新后的文档移除 `awsAuthRefresh` 并改用手动登录。 * **利用新 CLI 参数**:使用 `claude plugin install --marketplace <source>` 简化插件安装流程。
💭 Model Reasoning
1. **Analyze the Request:** * **Role:** World-class programmer, expert in developer tools/documentation. * **Task:** Analyze a batch of documentation changes (13 pages) and provide a summary. * **Format:** Markdown, concise, insightful. * **Focus:** What matters to developers. * **Language:** Chinese (as requested: "请用中文回复"). * **Output Structure:** Overall Summary, Key Themes, Impact Level, Action Items. 2. **Analyze the Diff Content (Page by Page):** * `amazon-bedrock.md`: Clarification on AWS SSO login loops. Explains *why* it loops (network interruption -> auth failure -> retry). Suggests manual login. * `costs.md`: Updated intro text to specify this page covers "Claude Code usage only" and links to Help Center for other product limits. Scope clarification. * `discover-plugins.md`: Minor grammar change ("For every" -> "For the other"). Very low impact. * `monitoring-usage.md`: * Update to `files_past_cutoff` definition (includes stale synced folders). * **New Section:** "Map egress paths to managed controls and events". This is huge for security/compliance. Maps Bash, MCP, Hooks, Plugins, WebFetch, etc., to settings keys and events. * **New Section:** "Check the retention sweep". How to verify cleanup settings are working. * `sandboxing.md`: * Added "Background sessions" to sandbox scope explanation. * Added "A boundary around the whole process" section explaining how to sandbox the *entire* process using the sandbox runtime or dev container. * `security.md`: Updated recommendation for isolation. Explicitly mentions running the whole process in sandbox runtime or dev container (linking to the new section in `sandboxing.md`). * `statusline.md`: Clarification on `effort` field in JSON status line (absent when no level is set, vs inheriting). * `sub-agents.md`: Updated `effort` parameter description. Clarifies it overrides the session level but *not* the `CLAUDE_CODE_EFFORT_LEVEL` environment variable. * `about-claude/models/overview.md`: Added details about `capabilities.thinking.types.disabled` in the model response object. * `agents-and-tools/tool-use/implement-tool-use.md`: Image URL encoding fix (`tool_choice.png`). Technical detail, likely irrelevant to function. * `agents-and-tools/tool-use/web-search-tool.md`: Updated links to Managed Agents docs (renamed/moved sections like `tools-web-restrictions`). * `agents-and-tools/tool-use/web-fetch-tool.md`: Same as above, updated links. * `CHANGELOG.md.md`: * Version 2.1.292. * New CLI flag: `--marketplace`. * New Agent tool param: `effort`. * New Env var: `CLAUDE_CODE_OVERLOADED_RETRY_BASE_DELAY_MS`. * New Event: `prompt.autocomplete`. * **Fixes (Many):** Permission mode issues, sandbox read-deny path fixes, PDF security fixes (file swap), cache tampering fixes, `NO_PROXY` fix, subagent effort fix, background session fixes, etc. * **Security Fixes:** PreToolUse hook bypass fix for UNC paths. 3. **Synthesize & Categorize:** * *Theme 1: Security & Compliance (Enterprise focus).* The `monitoring-usage.md` update is significant here. Mapping egress paths to controls helps enterprise developers track data flow. Sandbox updates help with isolation. * *Theme 2: Agent/Model Refinement.* Updates to `effort` handling in sub-agents (env var takes precedence) and new `effort` param in Agent tool. Model capabilities API update (`thinking.types.disabled`). * *Theme 3: Reliability & Bug Fixes.* Changelog lists extensive fixes: proxy support (`NO_PROXY`), background session recovery, sandbox security fixes, PDF security, plugin loading logic. * *Theme 4: Documentation Maintenance.* Link fixes, clarifying text for AWS SSO, and clarifying costs scope. 4. **Draft the Content (in Chinese):** * *Overall Summary:* This batch focuses heavily on enterprise security compliance (monitoring egress paths), hardening sandbox isolation, and refining agent behavior (effort levels). It also includes numerous bug fixes affecting networking, background sessions, and plugin stability. * *Key Themes:* * **Security & Compliance:** Added a comprehensive table in `monitoring-usage.md` mapping data egress paths (Bash, MCP, Hooks, etc.) to managed controls and events. Clarified how to sandbox the *entire* process, not just sub-processes. * **Agent Behavior:** Refined how `effort` levels work in sub-agents (env vars override session settings) and added `effort` to the Agent tool API. * **Reliability Fixes:** Major fixes for corporate network environments (AWS SSO loops, `NO_PROXY`), security gaps (PDF read-swapping, UNC path permissions), and background session persistence. * **Model API:** Added model capability info regarding `thinking: {type: "disabled"}`. * *Impact Level:* **Medium/High**. * *Reasoning:* The security monitoring additions are high value for enterprise admins. The bug fixes resolve annoying edge cases (loops, proxy issues) and security vulnerabilities (sandbox escape, file swap). The API changes are additive. * *Action Items:* * Review the new "Map egress paths" section if implementing observability/SIEM. * Update sub-agent configurations if relying on `effort` inheritance (env vars now take precedence). * Update CLI scripts if using `claude plugin install` (new `--marketplace` flag). * Apply updates if experiencing AWS SSO login loops or Proxy issues. 5. **Refine Language (Self-Correction during drafting):** * Make sure to distinguish between "Claude Code" (the editor tool) and "Claude" (the API). The changes cover both. * Ensure "Egress paths" is translated or explained clearly (数据流出路径). * Highlight the security fixes in the changelog as they are actionable for security-conscious teams. 6. **Final Polish (Markdown Structure):** * **Overall Summary:** (Drafted above) * **Key Themes:** * 企业级安全与合规性 * Agent 与模型能力增强 * 稳定性与网络环境修复 * 文档澄清与链接修正 * **Impact Level:** High (Security/Enterprise focus) -> Medium (General dev). Let's go with **Medium/High**. * **Action Items:** 1. Check monitoring docs for egress mapping. 2. Verify effort level config. 3. Apply security updates/restart. 4. Handle AWS SSO loop workaround. 5. Use new plugin flag. 7. **Final Output Generation** (Proceed to generate response based on these points). * *Self-Correction on `sub-agents.md`:* The change is that the `effort` setting in the frontmatter does *not* override the env var. This is a behavioral clarification. * *Self-Correction on `monitoring-usage.md`:* The new section is quite long and detailed. It's a very significant change for enterprise compliance. 8. **Constructing the Chinese response.** (Translating concepts accurately). * "Egress paths" -> 数据流出路径 / 出站路径. * "Managed settings" -> 托管设置. * "Sandbox runtime" -> 沙箱运行时. (Drafting the response now...)

📚 Claude Code GitHub

13:46 EST

🤖 AI Batch Analysis

## 文档变更分析 ### 1. 总体摘要 移除了 `hooks.md` 中关于 exit-2 hook 默认行为的一条说明:原先文档指出,不输出 JSON 的 exit-2 hook **始终**会在拦截消息中附带原始提示文本。该句已被删除,暗示该默认行为已发生变化。 ### 2. 关键主题 - **Hook 拦截消息行为变更**:`suppressOriginalPrompt` 选项的默认语义可能已调整,exit-2 hook 不再隐式地将原始提示文本写入拦截消息。 - **安全/隐私相关**:此文档区域涉及敏感提示文本在磁盘和消息中的暴露方式,变更直接影响开发者对拦截后数据残留的预期。 ### 3. 影响级别:**Medium** **理由**:这不是 API 签名层面的破坏性变更,但改变了 exit-2 hook 的一个**隐式默认行为**。依赖"exit-2 不输出 JSON 时自动附带原始提示"这一行为的开发者,可能会发现拦截消息内容与预期不符。属于行为语义变更,需关注但不会导致编译/运行时错误。 ### 4. 开发者行动项 - 审查所有使用 exit code 2 拦截提示的 hook 脚本,确认其对 `suppressOriginalPrompt` 的依赖逻辑是否受影响。 - 若你的 exit-2 hook **没有**输出 JSON,且你**希望**拦截消息中保留原始提示文本,现在可能需要显式处理(不设置 `suppressOriginalPrompt` 或输出相应 JSON)。 - 若你**不希望**原始提示出现在拦截消息中,确保在 `hookSpecificOutput` 中显式设置 `"suppressOriginalPrompt": true`,不再依赖隐式行为。 - 重新测试所有 blocking hook 的拦截消息输出,验证实际行为与文档一致。
💭 Model Reasoning
Let me analyze this documentation change carefully. The diff shows a single change in hooks.md: the removal of the final sentence from a paragraph about blocked prompts. **Removed text:** "An exit-2 hook that prints no JSON always gets the prompt text in its block message." This sentence described the default behavior when an exit-2 hook doesn't print JSON — it would always include the original prompt text in the block message. By removing this sentence, the documentation no longer explicitly states this default behavior. This could mean: 1. The behavior has changed — perhaps exit-2 hooks that print no JSON no longer automatically include the prompt text in the block message (maybe `suppressOriginalPrompt` now defaults to `true` for exit-2 hooks without JSON output). 2. Or it could just be a documentation cleanup removing redundant/unnecessary detail. Given the context, the sentence was explaining a specific edge case behavior. Its removal likely indicates a behavior change — that exit-2 hooks without JSON output no longer always get the prompt text appended. This is a behavioral change that developers relying on exit-2 hooks should be aware of.

📚 Claude Code

00:26 EST

🤖 AI Batch Analysis

### 总体概述 本次更新涉及 21 个页面,主要重点在于**桌面应用体验的重构**(特别是代码审查和浏览器工具)、**CLI 命令灵活性的增强**(支持按会话名称操作),以及**文档的技术债务清理**(移除了大量针对旧版本的前置条件说明)。同时,CHANGELOG 显示修复了 v2.1.291 中导致云会话数据丢失和权限提示失效的重要回归问题。 ### 关键变更主题 * **桌面应用(Desktop)UI/UX 重大调整**: * **代码审查流程变更**:不再使用 Diff 视图中的“Review code”按钮,改为使用 `/code-review` 命令,审查结果以卡片形式呈现,并支持“逐步演练”或“一键修复”。 * **服务器与浏览器管理**:开发服务器控制移至“Dev servers”菜单;浏览器持久化(Cookie)设置移至 Browser 窗格的 `⋮` 菜单。 * **CI 监控增强**:CI 状态栏更新了“自动修复”和“自动合并”的文案与交互,明确了自动处理审查评论的行为。 * **CLI 功能增强**: * `claude attach` 和 `claude logs` 命令现在支持使用**会话名称**(Session Name)而不仅仅是 ID,方便脚本和手动操作(需 v2.1.290+)。 * **配置与插件迁移**: * 明确了 `AGENTS.md` 相关插件 ID 从 `agents-md@builtin` 迁移至 `cc-plugin-agents-md@builtin`,并保留了向后兼容性说明。 * **文档规范化清理**: * 系统性地移除了诸如“Requires Claude Code v2.1.193 or later”的版本限制描述,表明这些特性已成为当前稳定版本的标准行为,使文档更简洁。 ### 影响等级:中 **理由**: * **高影响点**:桌面应用的代码审查工作流发生了显著变化(从 UI 按钮变为命令),用户需要适应新的操作习惯。 * **低影响点**:CLI 的增强是向后兼容的,文档清理和 Slack 的说明更新主要是信息修正,不破坏现有功能。v2.1.291 的 bug 修复属于维护性更新。 ### 开发者行动建议 * **适应新的代码审查流程**:如果使用 Claude Code Desktop,请停止在 Diff 视图寻找“Review code”按钮,改为在提示框输入 `/code-review` 来触发审查和修复。 * **更新 CLI 脚本习惯**:利用新增的会话名称功能,通过 `claude attach <name>` 或 `claude logs <name>` 更直观地管理后台会话。 * **排查网络代理问题**:如果在企业代理环境下遇到 API 请求异常,尝试设置 `CLAUDE_CODE_GZIP_REQUEST_BODIES=0` 环境变量以禁用 gzip 压缩。 * **检查插件配置**:如果你手动编辑过 `settings.json` 中的 `pluginConfigs`,确认 `cc-plugin-agents-md@builtin` 的配置是否符合预期。 * **留意 Slack 集成状态**:管理员需注意旧版 Slack 集成(Claude Code in Slack)与新版 Claude Tag 的适用范围区分,避免配置混淆。
💭 Model Reasoning
1. **Analyze the Request:** * **Role:** World-class programmer analyzing documentation changes. * **Task:** Analyze 21 pages of documentation changes as a single batch. * **Output Format:** Markdown. * **Language:** Chinese. * **Content:** Overall Summary, Key Themes, Impact Level, Action Items. * **Constraint:** Concise, insightful, developer-focused. 2. **Scan the Diff Data (Page by Page):** * `checkpointing.md`: Minor wording changes (e.g., "except messages..." -> "The prompts you sent...", "To remove..." -> "To undo..."). Simplification of checkpointing logic explanations. * `cli-reference.md`: * `claude attach <id|name>` and `claude logs <id|name>` now accept session names (v2.1.290). * `--dangerously-load-development-channels` warning about behavior with `-p`. * `common-workflows.md`: Text polish ("comprehensive" -> "improve", "easy" -> "often"). * `costs.md`: Text polish ("easily" -> "find"). * `desktop.md` (Major changes): * Dev server UI changed (moved to "Dev servers" menu). * Browser persistence/cookies moved to "⋮" menu. * Code review workflow changed significantly: Moved from a "Review code" button in the diff view to a `/code-review` command that produces a "Code review" card. * CI status/Auto-fix/Auto-merge UI updates (new toggles, specific wording changes). * Workspace arrangement UI updates (how panes are opened). * `github-actions.md`: Text polish ("For comprehensive" -> "For"). * `headless.md`: Text polish ("just" -> "only"). * `hooks.md`: Removed version requirements for `prompt_id`, removed version requirements for `InstructionsLoaded` "lazily loaded" behavior. Added note about plugin ID change (`agents-md@builtin` -> `cc-plugin-agents-md@builtin`) in v2.1.285. * `interactive-mode.md`: Removed version requirements for memory pressure reaping and live file path autocomplete. Text polish regarding `respondToBashCommands`. * `memory.md`: * Table polish ("Just you" -> "Only you"). * Clarification on how subdirectory CLAUDE.md files load (Read/Write/Edit tool behavior). * Significant update regarding `AGENTS.md` plugin ID change from `agents-md@builtin` to `cc-plugin-agents-md@builtin` (v2.1.285) for backward compatibility. * `monitoring-usage.md`: Removed "Requires Claude Code v2.1.XXX or later" notes for various fields (OTEL_LOG_ASSISTANT_RESPONSES, host_owned_mcp, etc.). This suggests cleaning up docs to reflect the current stable baseline rather than tracking legacy version specifics. * `network-config.md`: Added a new tip about `CLAUDE_CODE_GZIP_REQUEST_BODIES=0` for proxies mishandling gzip. * `quickstart.md`: Text polish. Markdown formatting glitches (`theme={null}` repeated). * `sandboxing.md`: Text polish. * `settings.md`: Text polish ("just you" -> "only you"). * `skills.md`: Text polish ("instead of just tests" -> "instead of tests alone"). * `slack.md`: Major clarification on Claude Code in Slack vs Claude Tag availability. Added troubleshooting for "workspace isn't set up" and "legacy bot retired". * `slash-commands.md`: Text polish. * `statusline.md`: Removed version requirement for `prompt_id`. * `third-party-integrations.md`: Text polish. * `CHANGELOG.md.md`: v2.1.291 - Bug fixes (regression in cloud sessions permission prompts, lost messages on quit). 3. **Synthesize and Structure the Analysis:** * **Overall Summary:** The update focuses on UI refinements in the Desktop application (Browser/Code Review/CI features), CLI enhancements (session naming), and documentation cleanup (removing legacy version requirements). It also addresses specific bugs in the latest minor release (2.1.291). * **Key Themes:** * *Desktop UI Overhaul:* Significant changes to the Code Review workflow (now a command/card system), Dev Servers menu, and Browser persistence settings. * *CLI Usability:* `attach` and `logs` commands now support session names, not just IDs. * *Documentation Hygiene:* Systematic removal of specific version requirements (e.g., "Requires v2.1.193") for features that are now standard. * *Configuration/Plugins:* Clarification on the `AGENTS.md` plugin ID migration (`cc-plugin-agents-md@builtin`). * **Impact Level:** Medium. While mostly UI polish and doc cleanup, the Desktop Code Review workflow change is a behavioral shift for users. The Slack/Claude Tag clarification is important for org admins. * **Action Items:** * Update CLI scripts if they rely on exact command signatures or if you utilize the new session name feature. * Re-train muscle memory for Code Review in Desktop (use `/code-review` instead of a button). * Check settings if you manually configured the `AGENTS.md` plugin ID. * Review Network Config if using specific enterprise proxies that struggle with gzip. 4. **Drafting the Content (in Chinese):** * *Summary:* 本次更新主要集中在桌面应用(Desktop)的 UI 改进、CLI 命令功能的增强(支持按名称附加会话)以及文档的清理(移除过时的版本要求)。同时修复了 v2.1.291 中云会话退出时的数据丢失和权限提示 bug。 * *Themes:* * Desktop UI/UX 变更:代码审查流程从 Diff 视图的按钮变为 `/code-review` 命令及卡片视图;开发服务器和浏览器持久化设置位置调整。 * CLI 增强功能:`claude attach` 和 `claude logs` 命令现在支持使用会话名称(Session Name)而不仅仅是 ID。 * 配置与插件管理:明确了 `AGENTS.md` 插件 ID 的变更(从 `agents-md@builtin` 迁移至 `cc-plugin-agents-md@builtin`)。 * 文档清理:系统性地移除了针对旧版本(如 v2.1.193 等)的功能前置条件说明,反映出当前版本已包含这些特性。 * *Impact:* Medium. 代码审查流程的改变需要用户适应新的操作方式;CLI 的增强提高了可用性,但主要是非破坏性的。 * *Action Items:* * Desktop 用户需注意代码审查流程已迁移至 `/code-review` 命令。 * 检查企业网络代理配置,若遇到 gzip 问题可尝试新的环境变量 `CLAUDE_CODE_GZIP_REQUEST_BODIES`。 * 管理员需关注 Slack 中 Claude Code 与 Claude Tag 的区分说明。 * 若手动配置过 `AGENTS.md` 插件 ID,需确认是否需要更新配置。 5. **Refining the Output:** Ensure tone is professional, concise, and "world-class". Use markdown formatting properly. * *Refinement on "Themes":* Highlight the removal of version requirements as "Hygiene" or "Deprecation of legacy docs". * *Refinement on "Action Items":* Make them actionable. 6. **Final Polish (Self-Correction during drafting):** * The Slack change is actually quite specific to availability. It clarifies that the "legacy" bot is for Pro/Max users *only* if the workspace isn't on Claude Tag. * The CHANGELOG entry is crucial context for the "Why" behind some fixes (regressions in v2.1.290). 7. **Final Output Generation** (Translating thoughts to the final Chinese response). * *Summary:* 本次更新包含 21 个页面的变更,重点在于优化桌面应用的用户体验(特别是代码审查和服务器管理),增强 CLI 命令灵活性(支持会话名称),以及清理文档中的历史版本限制描述。同时修复了近期版本中导致云会话消息丢失和权限提示失效的回归问题。 * *Themes:* * **Desktop 体验重构**:代码审查流程从 Diff 视图按钮变为 `/code-review` 命令驱动的卡片视图;开发服务器和浏览器设置移至新的位置。 * **CLI 易用性提升**:`attach` 和 `logs` 命令现在支持通过名称而非仅 ID 识别会话。 * **配置迁移与兼容**:更新了 `AGENTS.md` 插件的 ID 命名规范,涉及 `cc-plugin-agents-md@builtin`。 * **文档规范化**:移除了大量“需要 v2.1.xxx 或更高版本”的限定词,表明这些特性已成为当前标准。 * *Impact:* Medium. * *Actions:* * Desktop 用户需重新学习代码审查操作,使用 `/code-review` 命令替代旧按钮。 * CLI 用户可利用新的名称匹配功能简化会话管理。 * 遇到代理 gzip 问题的用户可应用新的环境变量 `CLAUDE_CODE_GZIP_REQUEST_BODIES=0`。 * 管理员应审查 Slack 与 Claude Tag 的部署策略说明。 8. **Final Check:** Does it meet all constraints? Yes. Chinese, Markdown, Concise, Insightful. (Proceed to generate output based on step 7)

📚 Claude Code GitHub