Skip to content
Oday Bakkour
Back to Knowledge Hub

AI Coding Tools Roundup: Claude Code 2.1.289 Tightens Permission Rules and Copilot CLI Adds an Environment Picker

Oday Bakkour profile photo
Oday Bakkour
3 min read
Share
AI Coding Tools Roundup: Claude Code 2.1.289 Tightens Permission Rules and Copilot CLI Adds an Environment Picker

The biggest change this weekend is a security-minded release: Claude Code 2.1.289 fixes several cases where permission rules were not enforced, as listed in the Claude Code releases. GitHub Copilot CLI also moved forward in its 1.0.92 pre-release series. Codex and OpenCode had no new stable release with notes.

Claude Code 2.1.289: Permission Rule Fixes

Version 2.1.289 was published on GitHub on October 3 as an immutable release. According to the changelog, the most important fixes concern deny and ask rules:

  • Bash deny and ask rules could miss a command placed behind an environment variable prefix with an expanded value, such as TZ="$HOME" rm -rf build, when the sandbox auto-allows commands.
  • A Bash deny or ask rule could also be skipped under sandbox auto-allow when a bare variable assignment came before the command.
  • Read deny rules were not applied to files that were @-mentioned, changed or selected in the IDE through a symlink.
  • A deny or ask rule on a nested part of a compound shell command did not hold over a user-installed mod's approval on managed machines.
  • A user-installed plugin could rewrite the descriptions of an organization-managed MCP server's sign-in tools.

The release also fixes terminal freezes on short code blocks with many unclosed script tags, reverts a 2.1.288 change to claude auth status in VS Code that may have made sign-outs more frequent, and adds agent.spawn for teammates plus idle and waiting states in the mods agent list. Many of the remaining fixes target plugin panes and mods, the system introduced in 2.1.287.

GitHub Copilot CLI 1.0.91 and 1.0.92

Per the Copilot CLI release page, version 1.0.91 (October 1) added copilot sandbox ca commands for managing proxy certificate authority trust and improved shell pipeline analysis. The 1.0.92 pre-releases (October 2) add a Ctrl+E environment picker for switching between local and cloud runs, network bypass prompts for sandboxed shell commands, Windows fixes for sandboxed temp files, and fixes for Git authentication with masked credentials.

Codex and OpenCode

The Codex releases page lists only 0.162.0 alpha builds with no notes. The last stable release with notes was 0.160.0 on October 2, covered by Releasebot, which added agent command center history browsing. On the OpenCode changelog, the latest entry is v1.18.34 from September 30, with no newer release.

What It Means for Developers

  • Update Claude Code to 2.1.289, especially if you rely on deny or ask rules together with sandbox auto-allow, or on IDE selections through symlinks.
  • Review your permission rules after upgrading and test them against commands with variable prefixes.
  • Copilot CLI users running sandboxed commands should expect new network bypass prompts in the 1.0.92 pre-release series.
  • Stay on stable Codex builds until notes appear for 0.162.0.

Resources & References

Add Oday Bakkour as a preferred source on Google

Comments

Share your thoughts and join the conversation

Leave a Comment

Loading comments...
RELATED
Claude Code 2.1.289 Fixes Bash Permission Rule Bypasses | Oday Bakkour