Claude Code

‘--force’ No Longer Slips Through Silently—The Last Confirmation Claude Code v2.1.229 Adds to Commit-to-PR Automation

‘--force’ No Longer Slips Through Silently—The Last Confirmation Claude Code v2.1.229 Adds to Commit-to-PR Automation

Claude Code v2.1.229 removes destructive git flags—such as --force, --amend, and --no-verify—from auto-approval in the commands generated by /commit-push-pr. It also covers new safeguards for unattended operation and cost optimizations for workflows.

By FF
『--force』は、もう黙って通らない──Claude Code v2.1.229が、コミットからPRまで任せる自動化に残した最後の確認

『--force』は、もう黙って通らない──Claude Code v2.1.229が、コミットからPRまで任せる自動化に残した最後の確認

Claude Code v2.1.229 が、/commit-push-pr で生成する git 操作のうち --force・--amend・--no-verify などの破壊的フラグを自動承認から外しました。無人運用の歯止めとワークフローのコスト最適化も併せて解説します。

FF
Your Local Claude Code Conversations Are Now Part of the Corporate Audit Log — Anthropic Opens a Read Path Into "Local Sessions"

Your Local Claude Code Conversations Are Now Part of the Corporate Audit Log — Anthropic Opens a Read Path Into "Local Sessions"

On August 11, Anthropic expanded its Compliance API for auditing so that session records from Claude Code and Cowork running on employees' machines can be read out. Agent conversations that once stayed local now fall within the scope of corporate audits — here's how it works, and the tension between

By FF
手元のClaude Codeの会話が、企業の監査簿に載る──Anthropicが開いた「ローカルセッション」の読み出し口

手元のClaude Codeの会話が、企業の監査簿に載る──Anthropicが開いた「ローカルセッション」の読み出し口

Anthropicが8月11日、監査用のCompliance APIを拡張し、社員のマシン上で動くClaude Code/Coworkのセッション記録を読み出せるようにした。手元で完結していたエージェントの会話が企業の監査対象に入る——その仕組みと、統制とプライバシーの緊張を整理する。

FF
Quarantining Cloud-Synced "Convenience" on Your Own Machine — How Claude Code v2.1.228 Closed the Gaps in Synced-Skill Overreach and Remote-Resume Peeking

Quarantining Cloud-Synced "Convenience" on Your Own Machine — How Claude Code v2.1.228 Closed the Gaps in Synced-Skill Overreach and Remote-Resume Peeking

Claude Code v2.1.228 is out. It closes gaps in "convenience coming from outside"—barring synced cloud skills from overreaching, stopping remote-resume from peeking at conversations, and preventing cleanup from deleting memory—while loosening the Write tool by one notch to allow overwriting unread fi

By FF
クラウドから同期した「便利」を、自分のマシンで検疫する──Claude Code v2.1.228が塞いだ、同期スキルの越権と遠隔再開の覗き見

クラウドから同期した「便利」を、自分のマシンで検疫する──Claude Code v2.1.228が塞いだ、同期スキルの越権と遠隔再開の覗き見

Claude Code v2.1.228 が公開。クラウド同期スキルの越権禁止、Remote Control 再開時の会話の覗き見、後片付けによるメモリ削除など「外から入る便利」の穴を塞ぐ一方、Write ツールは未読でも上書き可能へと一段緩めた。無人運用者の実務対応もまとめる。

FF
An Expired Login Was Nudging Max Users Toward Paid Usage — How Claude Code v2.1.227 Closed a Billing Mix-Up and a Total CI Wipeout

An Expired Login Was Nudging Max Users Toward Paid Usage — How Claude Code v2.1.227 Closed a Billing Mix-Up and a Total CI Wipeout

Claude Code v2.1.227 is mostly bug fixes. But it closes two holes that are easy to overlook in unattended operation: one that wrongly nudged Max users toward pay-as-you-go billing via an expired token, and one that wiped out every Bash command in CI on GitHub runners. Here's what to double-check.

By FF
期限切れログインが、Maxユーザーを「課金」へ誘っていた──Claude Code v2.1.227が塞いだ料金の取り違えとCIの全滅

期限切れログインが、Maxユーザーを「課金」へ誘っていた──Claude Code v2.1.227が塞いだ料金の取り違えとCIの全滅

Claude Code v2.1.227は不具合修正が中心。だが期限切れトークンでMaxユーザーを誤って従量課金へ誘う穴と、GitHubランナーでBashが全滅するCIの穴という、無人運用で見過ごしやすい二つを塞いだ。確認しておきたい点をまとめる。

FF
Stop Clicking "Yes" to Approve: On August 14, Claude Code Switches Its Default from Human Confirmation to an AI Checkpoint

Stop Clicking "Yes" to Approve: On August 14, Claude Code Switches Its Default from Human Confirmation to an AI Checkpoint

On August 14, Claude Code switches the default for Pro, Max, and Team from manual approval to auto mode. We break down the design that stops only dangerous operations, the 89%-vs-13.6% detection rates, and the lingering concerns over the remaining 11% and supply chain attacks.

By FF
「はい」を押し続ける承認をやめる──Claude Codeが8月14日、既定を人の確認からAIの検問へ切り替える

「はい」を押し続ける承認をやめる──Claude Codeが8月14日、既定を人の確認からAIの検問へ切り替える

Claude Code が8月14日、Pro・Max・Team の既定を手動承認からオートモードへ切り替える。分類器が危険な操作だけを止める設計と、89%対13.6%という検知率、そして残る11%とサプライチェーンへの懸念を整理する。

FF
When a “Handy Extension” Becomes the Way In──Anthropic Puts an Enterprise Checkpoint on Claude Code Skills and Plugins

When a “Handy Extension” Becomes the Way In──Anthropic Puts an Enterprise Checkpoint on Claude Code Skills and Plugins

On August 6, Anthropic added a malicious-content review (Enterprise, beta) targeting third-party Claude Code skills and plugins. Behind it are researchers' warnings that extension marketplaces can become a supply-chain attack surface. Here's how it works and what adopters can do to protect themselve

By FF
「便利な拡張」が、そのまま侵入口になる──Claude Codeのスキルとプラグインに、Anthropicが企業向けの検問を置いた

「便利な拡張」が、そのまま侵入口になる──Claude Codeのスキルとプラグインに、Anthropicが企業向けの検問を置いた

8月6日、AnthropicがClaude Codeの第三者スキル/プラグインを対象にした悪性コンテンツ検査(Enterprise・ベータ)を追加。背景には「拡張マーケットプレイスは供給網の攻撃面になる」という研究者の警告があります。仕組みと、導入側の自衛策を整理します。

FF