ClaudeUpdates.dev
Update Claude Code
ClaudeUpdates.dev
356 releases|Latest v2.1.223|Last Update Aug 06, 2026
Update Claude Code
v2.1.222Older
2.1.221
2.1.222
2.1.223
2.1.222
2.1.223
← Back to all releases

v2.1.223 Claude Code Release Notes

Aug 6, 2026Source: Anthropic changelog
Claude's Analysisby Sonnet 4.6
Full Analysis

Security pass closes permission bypasses (hidden Bash commands, sandbox escapes); /code-review replaces /review, and /teleport bridges cloud sessions to local machines.

Changes
19
Total Changes (vs Average)
1.6×
Version Type
Patch
Release Focus
Bug Fixes
Day Since Prior Release
1
Release # This Month
#3 of 3
Bug Fix Ratio
63%
Post-Release Edits
—
Change Category
Ecosystem Impact
Plugins/Skills has appeared in 9 of the last 10 releases; this one continues that cadence with marketplace owner-wildcard controls for allowing or blocking entire GitHub org repos.
Key Themes
4Security & Permission Hardening|6Session Resume & Sandbox Reliability|4Model ID & Context Window Handling|5Code Review & New Additions
May Help If You've Noticed
Resuming a session after switching folders came back completely empty
A resumed session failed every turn or froze on an unresponsive error screen
A forked background agent stayed stuck 'already resuming' the rest of the session
Claude Code occasionally hung while running a git push
Sandboxed commands wouldn't start in certain restricted folders on Linux

Changes in Claude Code v2.1.223

Added3 changes

  • •Added owner wildcard entries ("owner/*") to the strictKnownMarketplaces and blockedMarketplaces managed settings for allowing or blocking all marketplace repos under a GitHub org
  • •Added a warning when workflow agents, forked skills, slash commands, or resumed background agents' requested subagent model is restricted and the parent model runs instead
  • •Added a /teleport hint in cloud sessions showing how to continue locally with claude --teleport <session id>

Fixed12 changes

  • •Fixed a Bash permission bypass where a crafted command could hide parts of itself from permission checks
  • •Fixed permission prompts so commands padded with tabs or invisible Unicode can no longer hide part of the command from the approval dialog
  • •Fixed workflow scripts being able to use dynamic import() to run code outside the workflow sandbox
  • •Fixed a permission gap where an agent definition's bypassPermissions mode ignored the org bypass-permissions disable policy
  • •Fixed resuming a session after a mid-session /cd coming back empty
  • •Fixed gateway model discovery hiding Claude models registered under provider-prefixed IDs such as vertex_ai/claude-* or bedrock/anthropic.claude-*
  • •Fixed modelOverrides keys that aren't Anthropic model IDs being treated as the session's canonical model ID; unknown keys are now ignored as documented
  • •Fixed managed settings: server-delivered settings no longer disable the env block of a machine-local managed-settings.json or MDM profile; admin env now merges per key
  • •Fixed sandboxed commands failing to start on Linux when sandbox.filesystem.denyWrite covers the working directory
  • •Fixed forked background agents getting stuck "already resuming" for the rest of the session when rebuilding the fork's parent prompt failed during resume
  • •Fixed a resumed session failing every turn, or leaving the interactive app on an unresponsive error screen, when its history held a malformed diagnostics attachment
  • •Fixed a rare hang when parsing unusual git push output

Changed4 changes

  • •Changed CLAUDE_CODE_DISABLE_1M_CONTEXT to hold every Claude model with a native 1M window to 200K via auto-compaction, not just a fixed list; a startup warning now appears when auto-compaction isn't holding the session to 200K
  • •Changed auto-compact to keep sessions on unrecognized model IDs within the assumed context window instead of letting them grow past it; set CLAUDE_CODE_DISABLE_UNKNOWN_MODEL_WINDOW_ENFORCEMENT=1 to restore the previous behavior
  • •Changed /review to be an alias of /code-review, which reviews the current diff or a PR (/code-review <level> <pr#>); use /code-review ultra for a deep cloud review
  • •Changed /code-review with no effort level to reuse the level you typed last; type a level like /code-review high to change it

← v2.1.222
All Releases