Claude Code has released version 2.1.223, focusing on security and usability improvements. Key updates include fixes for permission bypass vulnerabilities in Bash commands and workflow scripts, enhancing security measures. The release also improves session management and model ID handling, ensuring smoother operation and error handling. These updates aim to provide a more secure and reliable experience for developers using Claude Code.
Read originalEarlier coverage that leads up to this article, and what followed. Lines connect each piece to the closest one after it, converging here.
Claude Code Releases · July 19, 2026 · Same story
Claude Code Releases · August 6, 2026 · Same story
This release significantly tightens the security model for Claude Code plugins by exposing server tool IDs and approval ceilings to hook functions, allowing developers to build more granular permission checks. It also stabilizes long-running agent sessions by fixing critical bugs in subagent resume logic and scheduled task persistence after compaction. For plugin authors, the new validation flags ensure gating hooks are properly configured before deployment. These changes make the platform safer for enterprise use while reducing friction for complex automated workflows.
This release stabilizes the core session management of Claude Code, specifically targeting the fragile state of resumed conversations where context or thinking traces were previously lost. It also patches critical reliability issues in the Model Context Protocol (MCP) integration, ensuring tool calls don't duplicate or hang indefinitely when remote servers misbehave. The addition of $.ui.selection() for mods and better GitHub CLI handling in cloud sessions shows a focus on developer workflow friction rather than new capabilities. These are necessary maintenance updates that make the tool more robust for heavy daily use.
This release quietly closes the hardware gap for local inference by adding default support for CUDA 13 and ROCm 10.0 alongside existing CUDA 12 builds. NVIDIA users can now leverage newer driver stacks without manual configuration, while AMD GPU owners finally get first-class parity with the same ease of use previously reserved for CUDA. Apple Silicon KleidiAI is disabled in this specific build, a notable regression for Mac users who rely on that optimization. The inclusion of Snapdragon and OpenVINO binaries further broadens the reach to edge devices and Intel hardware. It’s less about new features and more about llama.cpp solidifying its position as the universal runtime for every major accelerator.
This release quietly cements llama.cpp as the universal inference runtime by finally bringing first-class ROCm 10.0 support to both Linux and Windows. AMD GPU users no longer need workarounds, effectively closing a long-standing parity gap with NVIDIA's CUDA ecosystem. The inclusion of Snapdragon AI stack binaries for Linux marks a strategic push into ARM-based edge devices, while the simultaneous addition of CUDA 13 builds ensures compatibility with the latest driver stacks. By standardizing these hardware backends across major operating systems, the project removes friction for developers deploying models on diverse non-NVIDIA hardware.