2.1.236
Claude Code 2.1.236 - リリースノート
2026年8月19日
Claude Code
日本語サマリー
Claude Code 2.1.236 リリースノート要約
破壊的変更・セキュリティ
- Sandbox セキュリティ修正:macOS でワイルドカード read-deny ルール(例:
**/.env)が、許可された読み取り領域内で優先されるようになり、マッチしたディレクトリ内のファイルも対象に。ファイル改名によるバイパスも不可能に - スラッシュコマンドの typo や未対応コマンドで Enter を押すと、曖昧な近似一致を実行せずエラー報告するよう変更(prefix・alias は従来通り動作)
- auto mode の git status チェックが
status.showUntrackedFiles=no設定で誤って clean と報告される問題を修正
新機能
ANTHROPIC_DEFAULT_MODEL環境変数を追加:新規セッションの開始モデルを設定(/modelによる選択は優先・永続化)SendMessageにnotify_when_idleを追加:アイドル時の一回限り通知を要求可能(macOS / Linux、オプトイン)/goal:長時間のバックグラウンド処理で待機中のセッションが、30分後(以降 1h, 2h)に自動チェックイン- [VSCode] トランスクリプトのスクリーンリーダー対応を追加
主な修正
- 2.1.229 以降、セッションが切替先のディレクトリ削除後に clipboard copy・バックグラウンド処理・MCP ログが壊れる問題を修正
- fullscreen renderer が一度失敗すると以後起動不能になる問題を修正(クラシック renderer へフォールバック)
/modelピッカーがターミナル高さを超えて描画される問題を修正- サブプロセス起動失敗時(例: WSL での
powershell.exe)の unhandled promise rejection を修正(2.1.234 の回帰) - managed-settings 承認プロンプトが表示されないまま最初のキー入力を承認として扱う問題を修正
- tmux (iTerm 統合) でタブタイトルが 960ms ごとに点滅する問題を修正
改善
- 起動パフォーマンス向上(session counter をバックグラウンド書き込みに)
- auto mode の改善:
Monitorallow rules を auto mode 中は適用外に、Bedrock / Vertex AI / Foundry でも Claude API と同等の分類デフォルトを使用 /usageが Team / Enterprise メンバーに usage-credits の支出行を表示- SIGTERM(print/SDK モード)で中断されたターンや偽の tool denial を記録しないよう修正(終了コード 143 は維持)
- Remote Control が CLI 終了・ターミナルクローズ後、数秒で offline を検知
- セッション recap(自動・
/recap)を 400 文字に制限
原文(Release Notes)
What's changed
- Added
ANTHROPIC_DEFAULT_MODELenvironment variable: sets the model new sessions start on, while a/modelpick still overrides it and persists across restarts (unlikeANTHROPIC_MODEL)- Added
notify_when_idleto cross-sessionSendMessage: ask another Claude Code session on this machine to send one notice when it next goes idle — opt-in, one-shot, no polling (macOS and Linux)- Sandbox: on macOS, wildcard read-deny rules (e.g.
**/.env) now take precedence inside allowed read regions, cover matched directories' contents, and can't be bypassed by renaming the denied file- Fixed clipboard copy, background housekeeping, background sessions, and local MCP logs breaking after the directory a session had switched into was removed (since 2.1.229)
- Fixed the fullscreen renderer failing permanently after a single failed start: it now falls back to the classic renderer instead of exiting on every subsequent launch
- Fixed the
/modelpicker rendering taller than the terminal: it now shows only as many models as fit the window, with the rest reachable by scrolling- Fixed
SendMessagecalls being rejected when a malformed closing tag left the message text inside the summary field- Fixed unhandled promise rejections when a subprocess fails to start, for example
powershell.exeon WSL with Windows interop disabled (regression in 2.1.234)- Fixed fullscreen mode sometimes not showing a newly sent message until the next update after the terminal was resized
- Fixed a blank band that could remain above the prompt after clearing a multi-line prompt, and panes not repainting after resizing the terminal away and back, in fullscreen mode
- Fixed the managed-settings approval prompt sometimes not appearing at startup while still capturing the first keypress as approval
- Fixed terminal tab titles jumping in tmux (iTerm tmux integration): the title is now written only when its text changes instead of animating every 960ms
- Fixed an unclear error when the cloud environments list came back empty or malformed
- Fixed the Fable 5 first-time usage-credits prompt auto-selecting the fallback model after 60 seconds with no answer when using Remote Control
- Fixed spinner tips never appearing, with a repeated background error, when the cached guest-pass reward in
~/.claude.jsonwas malformed- Fixed skills hot-reload in SDK/VS Code sessions raising an error on every skills change after the session's working directory was deleted (2.1.229+)
- Fixed self-hosted runner sessions released on idle, retire, or startup timeout occasionally resuming on another runner before the post-session hook had finished
- Fixed the Clawd mascot's eyes and feet rendering unevenly in iTerm2 at some font sizes
- Fixed occasional runaway session recaps: recap text (automatic and
/recap) is now capped at 400 characters, cut at a word boundary- Improved startup performance: the session counter is now written in the background
- Improved auto mode:
Monitorallow rules are now set aside while auto mode is active, so Monitor commands are reviewed the same way Bash commands are- Improved auto mode on Bedrock, Vertex AI, and Foundry, and when telemetry is disabled: the classifier now uses the same defaults as on the Claude API, including severity-scored classification
- Improved auto mode: the git status check can no longer be fooled by a repo's
status.showUntrackedFiles=nosetting into reporting a clean tree- Changed the
/modelpicker to highlight only the newest model's name, so the highlight marks the new release rather than an arbitrary subset of the list/goal: an idle session whose goal is parked behind long-running background work now checks in automatically after 30 minutes (then 1h, 2h) instead of waiting for you to return/usagenow shows the usage-credits spend row for Team and Enterprise members, and shows a capped row at 0% before anything is spent- SIGTERM in print/SDK mode no longer records an interrupted turn or synthetic tool denials before exiting; running commands are still terminated and the process still exits with code 143
- Pressing Enter on a slash-command typo or a command unavailable in this session now reports it instead of running the closest fuzzy match; prefixes and aliases still run
- Remote Control now marks a session offline within seconds when the CLI exits or its terminal closes
SendMessagenow refuses further messages to a session up front once a rapid burst would exceed what that session's inbox accepts, instead of reporting them sent while they were dropped- Aligned the session title chip on the prompt border with the footer's right edge
- Right-aligned footer items (goal indicator, session state, background agent status) and truncated notices now share a consistent right margin with the rest of the prompt area
- [VSCode] Added screen reader support for the transcript: live announcements for replies, permission requests, errors, and status changes, plus per-turn heading navigation