2.1.207

Claude Code 2.1.207 - リリースノート

2026年7月11日
Claude Code

日本語サマリー

Claude Code 2.1.207 リリースノート要約

⚠️ 破壊的変更・セキュリティ修正

  • セキュリティ修正(シェルインジェクション対策): Plugin hooks/monitors/MCP headersHelperにおいて、shell-formコマンド内での ${user_config.*} の使用を拒否するように変更。Hooksではexec form(args配列)や $CLAUDE_PLUGIN_OPTION_<KEY> の使用が必要、monitors等ではスクリプト内で値を読み込む必要があります。
  • 破壊的変更(設定ファイル): auto modeが .claude/settings.local.json の autoMode を読み込まなくなりました。代わりに ~/.claude/settings.json を使用してください。
  • 破壊的変更(プラグイン設定): project-levelの .claude/settings.json から pluginConfigs の値を読み込まなくなりました(user, --settings, managed settings のみ有効)。
  • セキュリティ修正(権限昇格・同意バグ): 非対話型実行時(claude -p, SDK)において、リモートの管理設定がセキュリティ同意ダイアログを表示せずに恒久的に承認済みとして記録される問題を修正しました。

💡 新機能・重要な変更

  • Auto modeのデフォルト提供: Bedrock, Vertex AI, Foundry で CLAUDE_CODE_ENABLE_AUTO_MODE のオプトインなしで Auto mode が利用可能に(設定の disableAutoMode で無効化可能)。
  • デフォルトモデル変更: Bedrock, Vertex, Claude Platform on AWS のデフォルトモデルが Claude Opus 4.8 に変更されました。
  • /usage-credits の入力強化: 不正な値の入力をエラーで拒否するように変更。また、$1,000を超える金額入力にはタイピングによる確認が必須になりました。

🛠️ バグ修正

  • パフォーマンス改善: リスト、表、コードブロック等を含む非常に長いストリーミング応答中に発生していた、ターミナルのフリーズやキー入力ラグを修正しました。
  • Windows環境のハングアップ解消: AWSクレデンシャルの解決が停止した際に無期限フリーズする問題を修正し、60秒のストールガードが発動するようにしました。
  • 設定ファイルの上書き防止: リリースのたびに ~/.local/bin/claude のカスタムランチャースクリプトが上書きされる問題を修正(/doctor が外部管理を報告するように変更)。
  • Git設定のクリーンアップ: 最後の worktree.sparsePaths が削除された後、.git/config に extensions.worktreeConfig が残り go-gitツール等を破壊する問題を修正しました。
  • 各種不具合修正: agent teamsの mailbox エラーによるクラッシュループ、Remote Control のネットワーク復帰時のステータスロスト、Bedrockでの AWS SSO クレデンシャルの過剰な再要求など、多数の不具合を修正しました。

原文(Release Notes)

What's changed

  • Auto mode is now available without CLAUDE_CODE_ENABLE_AUTO_MODE opt-in on Bedrock, Vertex AI, and Foundry; disable via disableAutoMode in settings
  • Fixed the terminal freezing and keystrokes lagging while streaming responses containing very long lists, tables, paragraphs, or code blocks
  • Fixed remote managed settings from a non-interactive run (claude -p, the SDK) being permanently recorded as consented without ever showing the security consent dialog
  • Fixed spurious prompt-injection warnings triggered by benign system-generated conversation updates
  • Fixed the auto-updater overwriting a custom launcher script or symlink at ~/.local/bin/claude on every release; /doctor now reports an externally managed launcher
  • Fixed compound commands with cd prompting for permission when the only output redirect was to /dev/null
  • Fixed the transcript jumping above the start of the answer when a response finishes streaming
  • Fixed extensions.worktreeConfig being left in the repo's .git/config (breaking go-git tools like tea) after the last worktree.sparsePaths worktree was removed
  • Fixed malformed bracket patterns in rules globs, skill paths, .ignore, and .worktreeinclude breaking file reads, file suggestions, and worktree creation
  • Fixed a crash loop in agent teams where a malformed teammate mailbox message caused repeated errors every second until the mailbox file was manually deleted
  • Fixed background sessions auto-named by accepting a plan not showing that name on their agent-view row
  • Fixed background sessions that entered a git worktree resuming blank after a cold reopen from the agent list
  • Fixed Remote Control task status updates being lost when the connection recovered from a network interruption or credential refresh
  • Fixed Remote Control sessions hosted by the desktop app not showing background agent and workflow progress on mobile and web
  • Fixed Deep research runs labeling every Fetch-phase agent "unknown" — chips now show the source hostname
  • Fixed Bedrock repeatedly requesting fresh AWS SSO credentials from IAM Identity Center on every API request
  • Improved agent view: pasting the same text again now expands the collapsed [Pasted text #N] placeholder instead of adding a second one
  • Improved agent view: blocked session peeks now lead with the question and show a worded staleness clock (waiting 3m) instead of the same timestamp twice
  • Changed Bedrock, Vertex, and Claude Platform on AWS to default to Claude Opus 4.8
  • Changed auto mode to no longer read autoMode from .claude/settings.local.json (repo-resident); use ~/.claude/settings.json instead
  • Fixed an indefinite hang on Windows when AWS credential resolution stalls (e.g. a stuck credential_process): the 60-second stall guard now fires instead of waiting forever.
  • Plugin hooks/monitors/MCP headersHelper: ${user_config.*} in shell-form commands is now rejected (shell-injection fix). Hooks: use exec form (args array) or $CLAUDE_PLUGIN_OPTION_<KEY>; monitors and headersHelper: read the value inside the script (config file or the server's env block).
  • Plugin option values (pluginConfigs) are no longer read from project-level .claude/settings.json; only user, --settings, and managed settings are honored
  • Fixed /usage-credits amount inputs silently stripping malformed values (e.g. a pasted timestamp) to digits; malformed amounts are now rejected with an error, and amounts over $1,000 require a typed confirmation