Evidence record / claude-code
A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the signals and issues that cite it, below.
2026-07-01-claude-code-v2-1-196-security-fix-claude-mcp-list-get-no-longer-spaw
v2.1.196: Security fix - claude mcp list/get no longer spawn .mcp.json servers that a repo self-approved via a committed .claude/settings.json; untrusted workspaces now show ‘Pending approval’. (channel: tagged-release, 2026-06-29). Operator consequence: Advisory-shape fix: a committed settings file could previously cause read-only MCP listing commands to spawn attacker-chosen MCP servers in an untrusted clone. Re-audit any workflow that runs claude mcp list/get against untrusted repos; upgrade to >= 2.1.196. Full receipted detail lives in harvest/watchlist.md.
Receipt
Finding metadata
Run: 2026-07-01-weekly-digest-2026-06-24_2026-07-01-frontier-v0
Finding ID: 2026-07-01-claude-code-v2-1-196-security-fix-claude-mcp-list-get-no-longer-spaw
Accepted signals
Source links
Primary links, including exact changelog lines when available.
Versioned source: run artifact