2.1.223

Claude Code 2.1.223 - リリースノート

2026年8月6日
Claude Code

日本語サマリー

以下は指定されたリリースノートの日本語要約です。

⚠️ 破壊的変更・セキュリティ修正

セキュリティ修正

  • Bash権限バイパスの修正: 細工されたコマンドによる権限チェックの回避を防止。
  • コマンドの偽装防止: タブや不可視のUnicode文字で承認ダイアログからコマンドの一部を隠す問題を修正。
  • ワークフローサンドボックスの脱獄防止: 動的 import() を用いたサンドボックス外でのコード実行をブロック。
  • 権限設定のギャップ修正: bypassPermissions モードが組織のポリシー(bypass-permissions無効化設定)を無視する問題を修正。

破壊的変更・仕様変更

  • modelOverrides において、AnthropicのモデルIDではない未知のキーを無視するよう仕様変更(以前はセッションの正規モデルIDとして誤って扱われていた)。
  • CLAUDE_CODE_DISABLE_1M_CONTEXT の適用範囲を固定リストから、ネイティブで1Mコンテキストを持つすべてのClaudeモデルに拡大。

🚀 新機能・改善

  • マーケットプレース設定の改善: strictKnownMarketplaces と blockedMarketplaces で、GitHub org配下のすべてのリポジトリを許可・ブロックするワイルドカード ("owner/*") をサポート。
  • テレポート機能の追加: クラウドセッションで claude --teleport <session id> を用いてローカルに継続するための /teleport ヒントを追加。
  • レビューコマンドの統合: /review を /code-review のエイリアスに変更(/code-review ultra で詳細なクラウドレビューが可能)。また、effort levelを省略した場合は直前の設定が再利用されるように変更。

🐛 バグ修正

  • セッション途中での /cd 実行後にセッションをレジュームすると空になる問題を修正。
  • Gatewayでのモデル検出において、vertex_ai/claude-* や bedrock/anthropic.claude-* のようなプロバイダープレフィックス付きIDのClaudeモデルが非表示になる問題を修正。
  • Linux環境において、sandbox.filesystem.denyWrite が作業ディレクトリをカバーしている際にサンドボックスコマンドが起動失敗する問題を修正。
  • 親プロンプトの再構築に失敗した際、フォークされたバックグラウンドエージェントが「already resuming」でスタックする問題を修正。
  • 不正な診断アタッチメントにより、セッション復元後のターンがすべて失敗する問題を修正。
  • サーバーから配信される設定が、ローカルの managed-settings.json やMDMプロファイルの env ブロックを無効化しないよう修正(管理者のenv設定はキーごとにマージされるようになりました)。
  • 認識されないモデルIDで auto-compact が効かずコンテキストウィンドウを超過する問題を修正(CLAUDE_CODE_DISABLE_UNKNOWN_MODEL_WINDOW_ENFORCEMENT=1 で従来の挙動に変更可能)。

原文(Release Notes)

What's changed

  • Added owner wildcard entries ("owner/*") to the strictKnownMarketplaces and blockedMarketplaces managed settings for allowing or blocking all marketplace repos under a GitHub org
  • Added a warning when workflow agents, forked skills, slash commands, or resumed background agents' requested subagent model is restricted and the parent model runs instead
  • Added a /teleport hint in cloud sessions showing how to continue locally with claude --teleport <session id>
  • Fixed a Bash permission bypass where a crafted command could hide parts of itself from permission checks
  • Fixed permission prompts so commands padded with tabs or invisible Unicode can no longer hide part of the command from the approval dialog
  • Fixed workflow scripts being able to use dynamic import() to run code outside the workflow sandbox
  • Fixed a permission gap where an agent definition's bypassPermissions mode ignored the org bypass-permissions disable policy
  • Fixed resuming a session after a mid-session /cd coming back empty
  • Fixed gateway model discovery hiding Claude models registered under provider-prefixed IDs such as vertex_ai/claude-* or bedrock/anthropic.claude-*
  • Fixed modelOverrides keys that aren't Anthropic model IDs being treated as the session's canonical model ID; unknown keys are now ignored as documented
  • Fixed managed settings: server-delivered settings no longer disable the env block of a machine-local managed-settings.json or MDM profile; admin env now merges per key
  • Fixed sandboxed commands failing to start on Linux when sandbox.filesystem.denyWrite covers the working directory
  • Fixed forked background agents getting stuck "already resuming" for the rest of the session when rebuilding the fork's parent prompt failed during resume
  • Fixed a resumed session failing every turn, or leaving the interactive app on an unresponsive error screen, when its history held a malformed diagnostics attachment
  • Fixed a rare hang when parsing unusual git push output
  • Changed CLAUDE_CODE_DISABLE_1M_CONTEXT to hold every Claude model with a native 1M window to 200K via auto-compaction, not just a fixed list; a startup warning now appears when auto-compaction isn't holding the session to 200K
  • Changed auto-compact to keep sessions on unrecognized model IDs within the assumed context window instead of letting them grow past it; set CLAUDE_CODE_DISABLE_UNKNOWN_MODEL_WINDOW_ENFORCEMENT=1 to restore the previous behavior
  • Changed /review to be an alias of /code-review, which reviews the current diff or a PR (/code-review <level> <pr#>); use /code-review ultra for a deep cloud review
  • Changed /code-review with no effort level to reuse the level you typed last; type a level like /code-review high to change it