AI产品精选

Claude Code v2.1.160:修复多项安全提示与WSL剪贴板问题

v2.1.160

精选理由

这次更新对 Claude Code 用户很关键——安全提示能防止意外执行恶意脚本,WSL 剪贴板修复解决了长期痛点,建议所有用户升级。

AI 摘要

Anthropic 发布了 Claude Code v2.1.160 更新,主要增强了安全性:在写入 shell 启动文件(如 .zshenv、.bash_login)和 Git 配置前会弹出确认提示,避免意外执行恶意命令。同时,acceptEdits 模式现在会在写入 .npmrc、.yarnrc、bunfig.toml 等构建工具配置文件前提示,这些文件可能授予代码执行权限。此外,修复了多个重要问题,包括 WSL 下复制选择不写入 Windows 剪贴板(改用 PowerShell 互操作替代 OSC 52)、后台会话恢复时丢失聊天历史、Windows 下 CJK 输入法显示位置错误等。性能方面,改进了打开近期不活跃后台会话的速度。

原文 · Claude Code: GitHub Releases

v2.1.160

What's changed Added a prompt before writing to shell startup files ( .zshenv , .zlogin , .bash_login ) and ~/.config/git/ , which could otherwise lead to unintended command execution acceptEdits mode now prompts before writing build-tool config files that grant code execution ( .npmrc , .yarnrc* , bunfig.toml , .bazelrc , .pre-commit-config.yaml , .devcontainer/ , etc.) Edit no longer requires a separate Read after viewing a file with grep : single-file grep / egrep / fgrep commands now satisfy the read-before-edit check Fixed copy-on-select not writing to the Windows clipboard on WSL — now uses PowerShell interop instead of OSC 52, which terminals like MobaXterm don't support Fixed restoring a completed session from claude agents dropping chat history and re-running the original prompt Fixed background sessions re-attached after overnight retire losing their conversation and re-running the original prompt Fixed claude --bg occasionally failing with "socket missing" when the background daemon was cold-starting on a loaded machine Fixed an issue on Windows where the directory a background session was started in could not be deleted after claude rm until the background daemon exited Fixed background agents that resumed work being shown under Completed in the agents list Fixed claude agents freezing for several seconds when returning to the session list due to the auto-updater re-checking on every exit Fixed Esc, arrow keys, and typing becoming unresponsive on Windows when attached to a background session or in the agent view while the host is under heavy CPU load Fixed background agents emitting terminal sync-output markers to terminals that don't support them (Apple Terminal, tmux), causing render artifacts when entering a running agent Fixed mouse wheel scrolling prompt history instead of the transcript right after opening a session from the agents list Fixed CJK IME composition appearing at the bottom-left of the screen instead of at the input caret in the claude agents view Fixed valid file:///C:/... links being rewritten to a broken path on Windows terminals with hyperlink support Fixed voice mode failing to connect when the project directory or branch name contains non-ASCII or special characters Fixed the auto mode unavailability message on third-party providers (Bedrock/Vertex/Foundry) to point to the CLAUDE_CODE_ENABLE_AUTO_MODE opt-in instead of incorrectly blaming the model Fixed /effort ultracode incorrectly blaming the dynamic workflows setting when the model cannot run xhigh; ultracode is no longer offered on models that do not support it Fixed model-not-found errors suggesting --model when running via the SDK or other hosts where the CLI flag doesn't apply Fixed Claude's past replies disappearing from scrollback when resuming a brief mode session with brief mode turned off Fixed vim mode p pasting on the line below instead of at the cursor when the register was yanked with v$ Improved performance of opening recently-inactive background agent sessions in claude agents Improved auto mode classifier latency by reducing reasoning on routine actions, lowering the chance of "could not evaluate this action" blocks Improved background-session teardown ( claude rm / stop , idle reap) to send SIGTERM to running shell subprocesses before SIGKILL, so cleanup handlers run Removed CLAUDE_CODE_OPUS_4_6_FAST_MODE_OVERRIDE ; the environment variable is now a no-op Removed the JetBrains plugin install suggestion from startup Renamed the dynamic-workflow trigger keyword from workflow to ultracode . The word "workflow" no longer triggers a run; asking for one in your own words still works. The trigger keyword is highlighted in violet in the prompt input