Evidence record / claude-code

A dated record of one change, kept so the writing that cites it can be checked. Compiled from the sources listed below by the research run, not written for reading. The judgment lives in the issues that cite it, below.

2026-09-21-claude-code-restricted-and-permission-prompts-none-refuse-instead-of-asking

2.1.248 (2026-08-27) added --restricted (CLAUDE_CODE_RESTRICTED=1): it removes the built-in tools that run commands or code and WebFetch unless named in --tools, fences file tools to the working directory, refuses bypassPermissions, refuses cloud sessions, and loads only managed settings and --settings. 2.1.259 (2026-09-02) added --permission-prompts none: anything that would prompt is denied while the active permission mode, including auto mode, keeps deciding. 2.1.268 made PermissionRequest hooks fire under --print; 2.1.269 made stream-json permission_denials include path-scoped Read, Edit and Write denials; 2.1.277 made -p exit 1 on an internal error instead of hanging.

Channel: tagged-release (2.1.248 and 2.1.259; both on stable 2.1.267). Half: capability.

Operator consequence: Use --restricted -p for graders and untrusted-input review jobs; the --tools allowlist is the only way to restore a removed tool. Use --permission-prompts none for cron and CI where an ask must fail closed. Adapters that reconciled permission_denials were undercounting before 2.1.269.

Receipt

Finding metadata

Run: 2026-09-21-weekly-digest-2026-08-20_2026-09-21-frontier-v0

Finding ID: 2026-09-21-claude-code-restricted-and-permission-prompts-none-refuse-instead-of-asking

Profile citations

Source links

Primary links, including exact changelog lines when available.

Versioned source: run artifact