Claude Code Daily Briefing - 2026-09-25
Release Summary
| Version | Date | Key Changes |
|---|---|---|
| v2.1.282 | 9/24 | Batch of security fixes for macOS symlink paths and NUL-byte permission rules, plus maxProseWidth and more — 80+ changes |
| v2.1.281 | 9/23 | Attribution hiding option, expanded Auto mode coverage, and more — 180+ changes (covered in the 9/24 briefing) |
| v2.1.280 | 9/22 | Claude Opus 5.5 launch, Pro/Team Standard default model switched to Opus (covered in the 9/23 briefing) |
v2.1.282 landed on 9/24, just a day after v2.1.281 on 9/23. This release is notable less for new features than for security-related stability fixes around macOS symlinks, permission rules, and managed settings.
New Features & Practical Usage
New maxProseWidth setting — control response line width directly on wide terminals (v2.1.282)
On ultra-wide monitors or wide tmux panes, Claude Code’s prose used to stretch across the full width of the screen, which actually made it harder to read — now you can set that width separately. Tables and code blocks are unaffected by this setting and still use the full screen width as before.
{
"maxProseWidth": 100
}
If you keep Claude Code open on a wide screen all day, this setting lets you narrow just the prose to a comfortable width while leaving tables and code full-width, an easy readability win. Full release notes
readiness_grace_seconds added to the Claude app gateway — stay ready through brief DB outages (v2.1.282)
Setting store.readiness_grace_seconds in a self-hosted Claude app gateway config means a brief database outage, like a Postgres failover, no longer flips the /readyz health check to not-ready immediately — readiness holds for the configured grace period instead.
{
"store": {
"readiness_grace_seconds": 30
}
}
If you operate a self-hosted gateway that routes traffic based on /readyz in Kubernetes or similar, this option prevents a few seconds of DB failover from marking whole pods unready and cutting off traffic. Full release notes
Developer Workflow Tips
Always quote CLAUDE_PLUGIN_ROOT in plugin hooks (v2.1.282)
claude plugin validate now warns when a shell-form hook uses ${CLAUDE_PLUGIN_ROOT} without quotes. That’s because an unquoted reference can silently break if the plugin is installed at a path containing a space.
{
"hooks": {
"PreToolUse": [
{ "hooks": [{ "type": "command", "command": "\"${CLAUDE_PLUGIN_ROOT}/scripts/check.sh\"" }] }
]
}
}
Making a habit of running claude plugin validate before shipping internal plugins will catch hook breakage caused by spaces in macOS or Windows usernames ahead of time. Full release notes
sandbox.network.allowLocalBinding — when a local dev server hangs in the macOS sandbox (v2.1.282)
When a local dev server can’t bind to a port and hangs inside a macOS sandbox, Claude now points directly to sandbox.network.allowLocalBinding as the likely culprit setting.
{
"sandbox": {
"network": {
"allowLocalBinding": true
}
}
}
If your team frequently runs npm run dev or a local API server with the sandbox enabled, it’s worth documenting this setting in CLAUDE.md or your project’s settings.json ahead of time instead of tracking down the cause every time. Full release notes
Security & Limitations
Claude service status — all services operational as of 9/25 (9/25)
A direct check of the official status.claude.com shows that as of 9/25, claude.ai, Claude Console, Claude API, Claude Code, Claude Cowork, and Claude for Government are all Operational, with no active incidents. Since the most recent incident, elevated errors for multiple models on 9/22, was resolved, service has now run stably for three straight days.
Given that service stability held up well through a week of back-to-back releases and a model launch, this is a good time to keep things on the normal track without any special action. Claude Status
Batch of permission security fixes, including a macOS symlink issue that let network mounts be read (v2.1.282)
When reading CLAUDE.md and rules files at startup, a symlink inside a repository could previously reach macOS’s /Network (a network mount) via .. or a kernel path like /.vol, or a rules symlink pointing at macOS’s /home would be listed as-is — both are now fixed. A bug where a NUL byte mixed into a permission rule made it match everything like a wildcard has also been fixed; such rules now match nothing.
In managed settings, a typo in a boolean lockdown key like disableClaudeAiConnectors or allowManagedPermissionRulesOnly used to cause the entire lockdown to be silently ignored, and a mistake in just one of the permissions, autoMode, worktree, or attribution settings would cause the whole block to be ignored — both are now fixed, so typos are flagged by name at startup while the remaining valid settings still apply. Project and local settings files can also no longer set telemetry-enabling, endpoint, or content-capture variables like CLAUDE_CODE_ENABLE_TELEMETRY or OTEL_LOG_*, and which variables were ignored this way can be checked via the startup notice, /status, or claude doctor.
Organizations that share repositories across many people or clone external repos should update to the latest version, since this release closes off a number of bypass paths via symlinks or malformed permission rules. If you’ve been using organization-managed settings to tightly control telemetry or permissions, this is also a good moment to check whether a typo had quietly left a lockdown open. Full release notes
Ecosystem & Plugins
Whiteboard (YC W26) — an open-source design IDE that connects Claude Code and Codex to a canvas (9/25)
A desktop app where humans and coding agents design software together on a single canvas, connecting to Claude Code or Codex via SDK so the agent can draw diagrams directly on the canvas. It links diagrams, like sequence diagrams and entity-relationship diagrams, to actual code navigation, so design discussions and implementation don’t drift apart.
If you’ve found it tedious to explain design reviews or architecture discussions to Claude Code in words every time, this kind of visualization layer, where the agent draws the explanation directly on a canvas, is worth trying. GeekNews
Community News
- Making Claude.ai three times faster in two weeks (9/24): By improving the core flows that make up 95% of all user activity — launching the app, starting a conversation, loading an existing conversation, and sending a message — on both web and desktop, Anthropic cut the time from opening the webpage to being able to type from 3.1 seconds to 0.55 seconds at the 75th percentile. Loading speed for long responses improved as well. This is a hands-on engineering case study from Anthropic showing how to identify and aggressively optimize the core user flows of a large web application. GeekNews
- Rails World 2026 opening keynote — DHH says AI agents are reshaping the developer’s role (9/25): DHH argued that AI agents are changing the economics of writing code, and that the developer’s role is shifting from writing code by hand to defining and producing the outcomes you want. He described how 37signals has shifted to treating hand-written code as the exception. For teams that use agentic tools like Claude Code as part of daily work, this talk is worth revisiting for how it reframes what a developer’s job actually is. GeekNews
- Contrastive Language Model (CLM) released — another System 1 model in Jev’s lineage (9/25): CLM is a System 1 model that uses contrastive learning to compare embeddings of the current state against candidate actions and picks the highest-scoring one; the released CLM-8B is described as matching Jev’s performance on computer-use, gaming, and tool-calling tasks while achieving lower latency. Following the Jev architecture analysis and practical uses like jgrep covered in the 9/19–24 briefings, this is another entrant in the growing category of System 1 models that return fast judgments instead of generating sentences. GeekNews
Minor Changes
All items below are from v2.1.282 (9/24).
- Fixed a bug where a
:*in the middle of a Bash permission rule was ignored — it now behaves consistently with--allowedToolsacross every settings file source, and a startup warning explains the matching behavior. - Added the
allowClaudeInChromeWithManagedMcpmanaged setting, which letsclaude --chromerun alongside an exclusivemanaged-mcp.json. - Web search is now available for new models not yet recognized on Vertex AI.
- Fixed a bug where a command approved via a restored approval prompt on a restarted remote session worker could run twice.
- Added a scrollbar to the
/feedbackdraft list that appears on mouse-over in fullscreen mode. - [Claude Code on the web] Added “Open Repository” and “Open Compare Page” links to the repository menu for cloud sessions using repositories hosted on non-GitHub Git servers.
- [Claude Code on the web] You can now connect a running cloud session to an additional repository under a different GitHub owner, such as a fork’s upstream (including sessions started from Slack).
Recommended Reads
- The hidden history of the Windows scrollbar’s Scroll Here shortcut (9/25): This piece points out that beyond line/page scrolling and dragging, the Windows scrollbar has always had a Scroll Here right-click menu and a Shift+click gesture for jumping straight to a position. What’s interesting is that this old feature, letting you specify a destination directly instead of dragging the thumb a long distance, has been forgotten by most users. Since even everyday tools can hide shortcuts like this, it’s worth checking scrollable lists in Claude Code, like
/skillsor/plugin, for hidden shortcuts such as Home, End, PgUp, and PgDn. GeekNews - The LLM policy I want for GNOME (9/24): This personal proposal argues that GNOME’s LLM policy should be designed as a social norm that signals what behavior the community welcomes or rejects, rather than a rulebook that micromanages how development is done. The core point is that instead of trying to police the AI-usage ratio of every individual commit, the policy should focus on protecting the open-source community’s values of human-centered collaboration, privacy, and control. If your organization is drafting rules around how much Claude Code can be used, this approach — settling on shared norms before detailed rules — is worth referencing. GeekNews
- VSCode’s SSH agent is out of its mind (2025) (9/24): This is a critique arguing that instead of using commands already available in the remote environment, VSCode’s SSH remote editing feature quietly downloads and runs an agent, including a Node binary, via Bash code. It points out that the remote agent connects back to local VSCode over a WebSocket through SSH port forwarding, and that this entire setup operates with almost no explanation given to the user. Since many people attach Claude Code to remote servers through VSCode, this is worth reading to check exactly what binaries a remote extension downloads and runs, and from where. GeekNews
Interesting Projects & Tools
- Show GN: TODO Flow — open source for turning selected TODOs into parallel coding-agent work, verification, and review (9/25): When running multiple development tasks with Claude or the Codex CLI, this tool lets you track task status and verification evidence outside the chat session. You register a work plan, select which TODOs to run, and each task proceeds in its own separate Git worktree, with progress visible on a local dashboard. For teams running several Claude Code sessions in parallel and struggling to keep track of progress, this workflow tool is worth a look. GeekNews