Repository navigation
Release 0.19
xsyetopz edited this page Oct 5, 2026
·
2 revisions
Released 2026-10-03. Adds guards for infrastructure, dependency, and TLS commands, a delegation note, desktop notices, and auto-clear at 100k tokens. A version in parentheses marks a later patch of this line, and an entry with no version comes from 0.19.0.
-
DesignSync: a call that changes a Claude Design project asks first, unless the session started the/design-syncskill. The tool description requires that skill, and a 0.18.1 session uploaded files without it. The read methods pass.guard_bashcontrols it. - Bash guard, infrastructure: asks before commands that destroy resources or apply changes with no review.
Examples are
terraform destroy,terraform apply -auto-approve,pulumi destroy,cdk destroy,kubectl delete,helm uninstall,aws s3 rm --recursive,gcloud … delete,az … delete, andfly apps destroy. The reason names the target when a file shows it, such as the kubeconfig context,AWS_PROFILE, or the Terraform workspace. - Bash guard, dependencies: asks before a command adds a new dependency.
Examples are
npm install <name>,pip install <name>,uv add,cargo add, andgo get. The reason names each package and asks Claude to check that it exists and that the task needs it. A bare install, a requirements file, an editable install, and a lockfile install pass. - Bash guard, TLS: asks before a command turns off TLS checks.
Examples are
curl -k,wget --no-check-certificate,NODE_TLS_REJECT_UNAUTHORIZED=0,GIT_SSL_NO_VERIFY,git config http.sslVerify false, andpip --trusted-host. - Bash guard, tests: asks before
rmorgit rmremoves a tracked test file, and beforemvmoves it. The database reset ask also coversprisma db push --accept-data-lossanddrizzle-kit push --force. - Edit guard, proofs: asks when an edit adds a proof escape in a
.lean,.v,.thy,.agda, or.idrfile. Examples aresorry,admit,Admitted,axiom,postulate, andnative_decide. - Edit guard, TLS: asks when an edit turns off TLS checks in code, such as
verify=False,rejectUnauthorized: false, orInsecureSkipVerify: true. - Test-edit approval: one approved ask for a test edit (removed assertions or a skip marker) passes the other test-edit asks until the next message of the user.
A removed or moved test file is a separate kind, with its own approval.
A denied ask records nothing.
user-prompt-submit/clear-ask-approvals.mjsends the approval at the next user message, and task notifications do not end it.
- Two working rules: Claude edits files with
EditorWriteand not with shell scripts, and follows the limits that a tool description gives. A skill or command is named only when it is in the skill list of the session. - Verification gate: counts more check forms.
Examples are
lake build,coqc,verilator --lint-only,yosys,pio test,idf.py build,west build,dbt test,sqlfluff lint,jupyter nbconvert --execute, andgodot --headless. -
context_compaction_handoff(on by default): before a main-conversation compaction, the main model writes a handoff note. dotclaude saves it under.claude/handoffs/and adds it to the compacted conversation. If the model gives no note in 60 seconds, the compaction runs without it. -
context_auto_clear(on by default): from 100k tokens of main context, the next typed prompt saves a handoff note and runs/clear.- The prompt then comes back as the prompt of the user, and the
SessionStart(clear)hook adds the full note. - If the note fails, the prompt goes on with no clear.
- The status line shows
clearin red from that size. - With the option off, the context note asks Claude for a handoff, as before.
- The prompt then comes back as the prompt of the user, and the
-
notify_desktop(on by default): sends a desktop notification when the main agent ends a turn, when Claude asks a question, and when Claude Code asks for a permission.- The new
Notificationhooknotification/notify-permission.mjssends the permission notice. It shows the task, the short session ID, and the repository, throughterminal-notifierorosascript. - A notice with no answer gets one reminder after 5 minutes.
- A question gets one notification, and a turn that the user stops with Esc gets none. When neither sender exists, nothing shows and nothing fails.
- The new
- Delegation note (0.19.1): Claude gets one note for each message after 12 read calls in the main conversation.
- The count starts at the last user message, and an
Agentcall between the reads resets it. A read call isRead,Grep,Glob, or a Bash command that only reads. - The note gives the rest of the reading to
dotclaude:investigatorand the edits todotclaude:implementer. - Since 2026-09-28 the median message had 1 read call, and 12 is about the 83rd percentile.
-
usage_notescontrols it, andDELEGATION_NOTE_READSinhooks/lib/_budget.mjssets the bound.
- The count starts at the last user message, and an
-
scripts/usage-report.mjs: prints the delegation share. It gives subagent runs per 100 main turns, runs by agent type, and the tool-result tokens that enter the main context for each session. It also lists the latest subagent runs with their cost and the first line of their hand-back. The--runsflag sets how many. - Evals (0.19.1): role evals
t5-investigateandt5-web-research, and thejust eval-agent <model> <effort>recipe that runs them at a subagent model and effort.
-
scripts/usage-report.mjsreads the context bound fromMAIN_CONTEXT_TOKENS. - Working rules, investigation: check a correction against the evidence, and treat a cause that the user suggests as a hypothesis. Change nothing when a reproduction shows no defect, and take constants from a source.
- Working rules, code and report: reuse existing mechanisms, and keep compatibility only for a named consumer. Label substitutes, check the named outcome, and fix a failing check at its cause. The final report names workarounds, substitutes, and the level that each check reached.
- Subagent rule: it now routes work to agents (0.19.1). Before, it kept work in the main conversation, and the main agent did almost all work itself. The main conversation coordinates. It gives the reading of more than a few files, log scans, and multi-file edits to a subagent. The agent descriptions now say when to delegate.
-
model_lock(0.19.1): with the option on, the definition of a dotclaude agent sets its model. dotclaude removes amodelthat anAgentcall gives, and no deny reason names a model to use. Before, 175implementerruns used Opus 5.5 because a call setmodel: "opus". -
investigatorandweb-researcher(0.19.1): run on Sonnet 5.5 atmedium, from Opus 5.5 atmediumandlow. They mostly read and summarize. The cost guidance of Anthropic gives such steps to a cheaper model, withmediumas the start for multi-step tool use. -
reverse-engineer: stays on Opus 5.5, because it has no role eval and a wrong reading of machine code is expensive to find later. It marks a value that it did not recover as unknown. -
reviewerreads staged changes, flags weakened checks and packages that do not exist, and has a newcommentslens for pull request review comments. -
web-researcherquotes the passage that it cites and searches for sources that contradict the claim. Theslicesskill checks a finding at itspath:linebefore a fix agent starts. -
/dotclaude:setup(0.19.1): uses CodeGraph through thecodegraph explorecommand and removes thecodegraphMCP server aftercodegraph install.- The MCP server sends fixed instructions that tell Claude not to give lookups to a subagent, and no setting turns them off.
- Each run also removes a
codegraphMCP server that is registered, for example aftercodegraph upgradeadds it again. - The agents run
codegraph explorethrough Bash, and no agent lists the MCP tool.
- Bash guard parser: reads quotes, heredocs, and command substitutions in one pass.
- Before, three scanners with different quote rules let these commands pass: a command after a here-string
<<<, a$(...)inside double quotes, a quoted{that split agit push --force, and a$(...)in an unquoted heredoc body. - These forms now get a finding: a heredoc
<<inside((...)), acasepattern)inside$(...), an unquoted{after a command name,$'\x72'and octal escapes, a shell option value before-c, and nesting past the parse limit. - One list of interpreters, with versioned names such as
python3.12, controls the scan of inline code. The guard reads the code only from-e,-c, or--eval, and it also scans a heredoc that goes topython3 -ornode -. -
uv run,uvx,uv tool run,poetry run,pdm run, andpipenv runare wrappers. The guard checks the command that they start, also after global flags such asuv --directory x run. - An ignore-bypass search that would walk large ignored directories gets a deny reason that keeps the flag and asks for named or excluded directories.
-
git push --force-with-leaseasks with a reason that names the lease.
- Before, three scanners with different quote rules let these commands pass: a command after a here-string
- Verification gate, classes: sorts each check into
run(tests, build, type check) orstatic(lint, format, analyzers).- After a code edit, a
staticcheck alone does not satisfy the gate or the task gate when the project has a test command. - A failed
runcheck stays reported until a laterruncheck passes, also when a lint run passes after it. A run of the project own test command counts as a check.
- After a code edit, a
- Verification gate, forms:
- Workspace and toolchain forms count, for example
pnpm -r test,npm --prefix app run build,yarn workspace web test,cargo +nightly test, anddeno task test. - Task runner names count, for example
turbo run test,nx run-many -t test,nx run web:lint,moon run :test,mise run lint,rake spec,./gradlew :app:jvmTest, andmvn verify. A name that only fixes or formats, such aslint:fixorspotlessApply, does not count.npm cidoes not count. - The gate reads the command inside a launcher, for example
npx,bunx,pnpm dlx,bundle exec,rustup run,conda run,nix develop -c,docker run,docker compose run,python -m, andc8. - A command that shows help, a version, or a list, skips the run, or changes files does not count.
Examples are
pytest --collect-only,cargo test --no-run,make -n test,eslint --fix,ruff format, andnpm run lint:fix. -
--dry-runis a no-check flag only for tools that skip the run with it, such asmake,just,gradle,turbo,mocha, andrspec. For a formatter,--dry-runis the check. - Detection is in
hooks/lib/_check-command.mjs. It covers the usual check tools of Python, JavaScript, Rust, Go, the JVM, Swift, .NET, C and C++, Ruby, PHP, Elixir, Haskell, Dart, Lua, shell, Nix, and infrastructure. A formatter counts only in its check form, such asprettier --check,gofmt -l, orblack --check.
- Workspace and toolchain forms count, for example
- Assertion ask exception: the Edit and Bash guards no longer drop the assertion ask when the last prompt asks to remove tests.
A regex on the words of the prompt decided that, and it fails on other wordings and other languages.
One approval now covers the other asks of its kind until the next user message.
io.session.lastPrompthad no other caller, so it is removed too. - Fast-compact integration (Jev by TypeSafe): users report that Jev compacts badly, and the dotclaude eval found its picks no better than keeping the newest outputs.
/dotclaude:setupno longer offers, installs, configures, or reports it.
- Change attribution (0.19.1): Claude finds the tool call that made a change before it says who made it.
Claude says that it does not know when it finds no call.
Before, the
handoffskill told Claude to name each other uncommitted change as the work of the user. Claude then called a file that it had made "not this session's work", and the next session repeated the claim. The working rules, the subagent conventions, and thehandoffskill have the check. -
/dotclaude:setuppreview (0.19.1): theCLAUDE.mdpreview lists the lines that the new block drops and says that a later dotclaude version removed them on purpose. A 0.19.0 session read the# Compact instructionssection, which 0.18.1 removed, as the user's text, and it moved the end marker to keep it. -
/dotclaude:setupcleanup (0.19.1): removes the# Compact instructionssection from~/.claude/CLAUDE.mdwhen it sits outside the block as an exact copy of an earlier dotclaude version. The compaction hook sends the same priorities. A section that the user changed stays. - Nested-instructions hook: stops at the root of a git worktree.
In
.claude/worktrees/*, it loaded the mainCLAUDE.mdagain, 192 times in 193 runs. -
DOTCLAUDE_DEBUG: with it set, an action error in the module engine reaches Claude Code. Without it, the action is skipped as before, because an engine hook error skips all of dotclaude for the event. - Inline code guard: code that starts a shell command as an argument list got no finding, for example
subprocess.run(['rm', '-rf', '/'])orsystem("rm", "-rf", "/"). The guard now also checks each comma-separated run of string literals as one command, backtick bodies, Perlqxandqw, Ruby%xand%w, and AppleScriptdo shell script. -
scripts/sandbox.mjs: removed eachDOTCLAUDE_variable, also one that the user set on the command line, such asDOTCLAUDE_DEBUG.
Previous: Release 0.18 · Next: Release 0.20
- Get started
- Guides
- Reference
- Develop
- Concepts and evidence
- Changelog
- Other