Evidence record / claude-code
A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.
2026-08-20-claude-code-2-1-236-macos-read-deny-wildcards-bind-2-1-238-trust-gates-mcp-headershelper
npm times year-confirmed: 2.1.235 2026-08-18, 2.1.236 2026-08-19, 2.1.238 2026-08-20. 2.1.239 is 2026-08-21, out of window. Changelog 2.1.235: Shift+Tab in the permission comment field approved the edit and granted session-wide edit. 2.1.236: macOS wildcard read-deny (e.g. **/.env) takes precedence inside allowed read regions and cannot be bypassed by renaming the denied file; auto mode git status can no longer be fooled by status.showUntrackedFiles=no. 2.1.238: project MCP headersHelper requires folder trust and runs without inherited credential env vars. stable dist-tag remains 2.1.231. In-window latest is 2.1.238. Countable versions between 2.1.231 and 2.1.238: 232, 233, 234, 235, 236, 237, 238 (seven). 2.1.230 is absent from npm time.
Channel: tagged-release (npm). Half: both.
Operator consequence: upgrade to 2.1.238 if you run latest. The stable channel still does not have these fixes. Inspect /permissions if you used the comment field on 2.1.234.
Receipt
Finding metadata
Run: 2026-08-20-brief-2026-08-17_2026-08-20-frontier-v0
Finding ID: 2026-08-20-claude-code-2-1-236-macos-read-deny-wildcards-bind-2-1-238-trust-gates-mcp-headershelper
Profile citations
- Claude Code / claim / macos-read-deny-and-mcp-headershelper
Source links
Primary links, including exact changelog lines when available.
Versioned source: run artifact