Finding · claude-code
Build Tool Config Write Protection
What Changed
acceptEdits Mode now prompts before writing build-tool config files granting code execution (.npmrc, .yarnrc*, bunfig.toml, .bazelrc, .pre-commit-config.yaml, .devcontainer/, etc.)
Operator Implication
Build tool configuration files that grant code execution now require confirmation even in acceptEdits mode, mitigating supply-chain attacks
Receipt
- [acceptEdits Mode: Now prompts before writing build-tool config files granting code execution (
.npmrc,.yarnrc*,bunfig.toml,.bazelrc, `.pre-commit-conf](https://code.claude.com/docs/en/changelog)
Finding metadata
Run: 2026-06-03-weekly-digest-2026-05-28_2026-06-03-frontier-v0
Finding ID: 2026-06-02-claude-code-build-tool-config-protection
Accepted signals
Source links
Primary links, including exact changelog lines when available.
Versioned source: run artifact