2.1.205

Claude Code 2.1.205 - リリースノート

2026年7月8日
Claude Code

日本語サマリー

Claude Code 2.1.205 リリースノート要約

⚠️ セキュリティ修正および破壊的変更

  • セッション改ざん防止: セッションのトランスクリプトファイル(log)を改ざんする操作をブロックする auto mode ルールを追加。
  • 不正承認の防止: background task の通知において「人間の入力がない」ことを明記するようにし、トランスクリプト内の偽の承認(in-transcript approvals)が実行されるのを防止。
  • 破壊的データ削除の回避: auto mode を改善し、コンテキストから解決できない変数に対して rm -rf を実行する前に確認を求めるように変更。
  • パストラバーサル(ディレクトリ外削除)修正: Windows環境において、NTFS junction やディレクトリシンボリックリンクが存在する場合に worktree 削除が範囲外のファイルを消去してしまう重大なバグを修正。

✨ 機能向上・追加

  • /doctor を、問題の診断と修復が可能な包括的なセットアップチェック機能にアップグレード(/checkup はそのエイリアス)。
  • background agent が既存のPRへ編集・マージ・コメント・pushを行った際、claude agents 上でそのPRへリンクするように改善。
  • agent view の表示を改善し、生のツール呼び出しテキストではなく、状態を示すカラーテキストと見出しを表示するように変更。
  • 自動アップデート時のバイナリダウンロードをディスクストリーミングに変更し、アップデータのピーク時メモリ使用量を約 400 MB 削減。
  • 名称予約: "Claude Browser" および "Claude Preview" の MCP サーバー名を予約済みとし、ユーザー設定の MCP サーバーでこれらの名前を登録できないように変更。

🐛 バグ修正

  • --json-schema に無効なスキーマを指定した際に無構造の出力を生成したり、format キーワード使用時に弾かれる問題を修正。
  • Claudeの動作中にメッセージを送信し、--max-turns の制限でターンが終了した際にそのメッセージが消失する問題を修正。
  • SendMessage で再開した background agents が、リスト上で "failed" や "completed" のまま表示される問題を修正。
  • claude attach 実行時に、background agent がアップグレードによる再起動中だった場合にエラーになる問題を修正(復帰を待機するように修正)。
  • 出力が 30K のインライン制限を超える Bash コール内で作成された PR が、session-to-PR リンクに反映されない問題を修正。
  • サーバー名にサポート外の文字が含まれていると claude mcp add-from-claude-desktop がスタックする問題を修正(無効な名前を報告し、残りをインポート続行するよう変更)。
  • ある plugin の LSP server が初期化に失敗した際、別の plugin の有効な LSP server が同一のファイル拡張子を処理できなくなる問題を修正。
  • Webおよびモバイルの Remote Control パネルにおいて、background tasks のステータスが古い "Running" のまま固定される問題を修正。
  • コマンド実行中に起動ディレクトリが削除・ロック・アンマウントされた際に Windows で発生するクラッシュを修正。
  • Cowork VM-mode の local-agent sessions が "Not logged in" エラーで開始できない問題を修正。

原文(Release Notes)

What's changed

  • Added an auto mode rule that blocks tampering with session transcript files
  • Fixed --json-schema silently producing unstructured output when the schema was invalid, and schemas using the format keyword being rejected
  • Fixed a message sent while Claude was working being silently lost when the turn ended at the --max-turns limit
  • Fixed Windows worktree removal deleting files outside the worktree when an NTFS junction or directory symlink existed inside it
  • Fixed background agents staying shown as "failed" or "completed" in the agent list after being resumed with SendMessage
  • Fixed background jobs flipping from "needs input" back to "working" in the agent list when the agent's turn contained no readable text
  • Fixed claude attach erroring when a background agent was mid-upgrade restart instead of waiting for it to come back
  • Fixed session-to-PR linking missing a PR created in a Bash call whose output exceeded the 30K inline limit
  • Fixed claude mcp add-from-claude-desktop getting stuck when a server name contains unsupported characters; invalid names are now reported and remaining servers still import
  • Fixed a plugin LSP server that fails to initialize preventing a valid LSP server from another plugin handling the same file extension
  • Fixed a Windows crash when the directory Claude was launched from is deleted, locked, or unmounted while a command is running
  • Fixed a crash when a file watcher was closed while a directory scan was still in flight
  • Fixed project verify skills being rewritten on every session instead of only when a documented command changed
  • Fixed the agent view rendering one line too high and clipping its header when the job list slightly overflowed the screen
  • Fixed background tasks in the web and mobile Remote Control panels showing stale "Running" status by forwarding full task state on every membership change
  • Improved auto mode to ask before running rm -rf on a variable it can't resolve from context
  • Auto-update binary downloads now stream to disk instead of buffering in memory, cutting the updater's peak memory usage by roughly 400 MB
  • Background task notifications now explicitly state that no human input has occurred, preventing fabricated in-transcript approvals from being acted on
  • Improved agent view: sessions that edit, merge, comment on, or push to an existing PR now link it in claude agents
  • Improved agent view: rows now show a colored state word and a classifier-written headline instead of raw tool call text, and the peek opens with full status including the exact ask for blocked sessions
  • /doctor is now a full setup checkup that can diagnose and fix issues; /checkup is its alias
  • Reserved the "Claude Browser" MCP server name (alongside "Claude Preview") ahead of the Claude Desktop pane rename; user-configured MCP servers can no longer register under either name
  • Fixed Cowork VM-mode local-agent sessions failing to start with "Not logged in · Please run /login" on CLI 2.1.203+