Evidence record / claude-code

A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.

2026-07-01-claude-code-v2-1-195-hook-matchers-with-hyphenated-identifiers-e-g-c

v2.1.195: Hook matchers with hyphenated identifiers (e.g. code-reviewer, mcp__brave-search) now exact-match instead of accidentally substring-matching; external plugins enabled only by project .claude/settings.json now require explicit install consent on every loader path. (channel: tagged-release, 2026-06-26). Operator consequence: Behavior-changing hook fix: teams using hyphenated hook matchers may see hooks stop matching things they previously (incorrectly) matched - use mcp__brave-search__.* to match all tools from a hyphenated MCP server. Plugin install-consent fix closes a path where a project settings file could enable an external plugin without consent - re-audit trust of project-scoped plugins. Full receipted detail lives in harvest/watchlist.md.

Receipt

Finding metadata

Run: 2026-07-01-weekly-digest-2026-06-24_2026-07-01-frontier-v0

Finding ID: 2026-07-01-claude-code-v2-1-195-hook-matchers-with-hyphenated-identifiers-e-g-c

Source links

Primary links, including exact changelog lines when available.

Versioned source: run artifact