2.1.259

Claude Code 2.1.259 - リリースノート

2026年9月2日
Claude Code

日本語サマリー

Claude Code 2.1.259 リリースノート要約

⚠️ 破壊的変更・重要な仕様変更

  • allowedMcpServers の挙動変更:ユーザーが追加したサーバーのみを対象に。従来フィルタアウトされていた managed-mcp.json のサーバーがアップグレード後にロードされるようになった。ブロックし続けたい場合は deniedMcpServers を使用
  • 管理設定の解析失敗時は起動拒否:managed-settings ファイル、MDM plist、HKLM 値などが解析不能な場合、黙って無視せず起動を拒否しエラー元を表示

セキュリティ修正

  • Bash Read() deny ルールの強化:--ignore-revs-file=.env、-f.env、@file などのオプション値、git diff/git grep のファイル指定、cd DIR && cat FILE の複合コマンドもカバー。grep -r/cp -r で拒否ファイルを含むディレクトリを走査する場合は確認を要求

新機能

  • managedMcpServers 管理設定を追加:組織が全ユーザーに HTTP/SSE MCP サーバーを提供可能(.mcp.json と同じ形式、コマンド実行型はスキップ)
  • --permission-prompts none を追加:プロンプトが必要な操作を自動拒否(無人 headless 環境向け)
  • claude plugin validate に --json を追加(機械可読な検証レポート)
  • glab mr create/merge などの GitLab MR コマンドを認識し、ツール概要に MR !N 表示・フッターの MR バッジ更新

主なバグ修正

  • 複数セッションの同時実行で ~/.claude.json の変更が互いに巻き戻る問題を修正(workspace trust のリセットや MCP/プロジェクト状態の消失を解消)
  • OAuth トークンのリフレッシュ時にプロンプトキャッシュが無効化される問題(telemetry 無効セッション)を修正
  • --resume 失敗や --continue で空の会話が開く問題を修正(payload のない添付エントリーが原因)
  • カスタムコマンド・スキルの frontmatter model: が interactive セッションで無視される問題を修正
  • CLAUDE_CODE_MAX_CONTEXT_TOKENS が Vertex 形式(@YYYYMMDD サフィックス)のモデル ID で無視される問題を修正
  • リモート制御セッションで Stop がバックグラウンドエージェント・ワークフローを実際には停止しない問題を修正

その他改善

  • 長い応答のターミナルリサイズ・初回描画のパフォーマンス向上
  • /workflows のエージェント詳細で JSON 結果を色付き整形表示
  • VSCode のセッションリストにフィルター(Active、Needs input、Working、Completed)を追加

原文(Release Notes)

What's changed

  • Added managedMcpServers managed setting: organizations can provide HTTP/SSE MCP servers to every user (same entry shape as .mcp.json); entries that name a command to run are skipped
  • Added --permission-prompts none for unattended headless hosts: anything that would prompt is denied automatically while the active permission mode (including auto mode) keeps deciding
  • Added recognition of glab mr create/merge/close/reopen/note/update so GitLab merge requests show as MR !N in the collapsed tool summary and refresh the footer MR badge
  • Added --json to claude plugin validate for a machine-readable validation report
  • Fixed concurrent sessions silently reverting each other's ~/.claude.json changes — workspace trust no longer resets and MCP/project state is no longer lost when running many sessions at once
  • Fixed a conversation whose thinking was rejected once being rejected again on every later turn
  • Fixed Bash Read() deny rules not covering files given as option values (--ignore-revs-file=.env, -f.env, @file), git diff/git grep file operands, or cd DIR && cat FILE compounds; grep -r/cp -r over a directory holding a denied file now asks
  • Fixed the prompt cache being invalidated when the OAuth token refreshed in sessions with telemetry disabled
  • Fixed fullscreen mode showing a blank conversation after a long turn with hundreds of tool calls
  • Fixed auto mode running a turn on a model it doesn't support when a command or skill's frontmatter model: named one; the turn now keeps the session model
  • Fixed CLAUDE_CODE_MAX_CONTEXT_TOKENS being ignored for Vertex-style model IDs (@YYYYMMDD suffix) of model versions Claude Code doesn't recognize
  • Fixed the live output preview of a running shell command hiding its newest lines when an earlier line wrapped
  • Fixed a background GitHub connection check that ran on every launch for claude.ai users; the result is now remembered across launches
  • Fixed --resume failing (and --continue opening an empty conversation) when a saved session contains an attachment entry with no payload
  • Fixed frontmatter model: on custom commands and skills being ignored in interactive sessions
  • Fixed Artifact publishing failing once with an "unexpected parameter note" error in conversations continued from an older version
  • Fixed managed forceRemoteSettingsRefresh being ignored at startup when a policy helper configured by MDM or the managed settings file had already run
  • Fixed worktree isolation refusing hook-created worktrees on machines where git rev-parse fails with a message other than "not a git repository"
  • Fixed OpenTelemetry metrics and events from cloud sessions missing the user.email, organization.id, and user.account_uuid attributes
  • Fixed MCP servers that disconnect while their tools are being listed at startup showing as connected with no tools instead of reporting the error
  • Fixed the file edit permission dialog sometimes showing a changed line cut short with no indication
  • Fixed repository detection dropping a known repo identity after a transient git probe failure
  • Fixed managed settings silently going unenforced when the managed-settings file, a drop-in, the MDM plist, or the HKLM value cannot be parsed: Claude Code now refuses to start and names the source
  • Fixed Stop not actually stopping background agents and workflows in remote-control sessions: killed tasks now stay visible and re-stoppable until their processes exit
  • Fixed resuming a workflow run while its previous stopped run was still exiting, which could run duplicate copies of its agents
  • Fixed marketplace repo URLs on github.com with a trailing slash or dangling ?/# producing an unusable .git clone URL
  • Fixed blocking Stop hooks causing the turn after a block to lose the model's reasoning from that turn and, on some models, miss the prompt cache
  • Fixed remote (claude.ai) sessions taking 60 seconds to start a turn after a browser-hosted MCP server's page had gone away
  • Fixed worktree-isolated sessions refusing common Bash loops, xargs pipelines and launcher-wrapped commands that cannot reach the main checkout
  • Improved terminal resize and first-render performance for long responses by reusing text measurements
  • Improved /workflows agent detail: JSON outcomes are pretty-printed with syntax colors and real line breaks, and long outcomes fold behind an expand toggle
  • Improved headless/SDK session start: the first turn begins up to 50 ms sooner when MCP servers finish connecting
  • Improved /install-github-app to explain it is GitHub-only and point to the GitLab CI/CD docs when run inside a GitLab repository
  • Improved nested background subagent results to be saved in the parent subagent's transcript, so resumed subagents keep them and shared transcripts show the delivery
  • Changed allowedMcpServers to govern only servers users add: a literal managed-mcp.json server your allowlist used to filter out now loads on upgrade; use deniedMcpServers to keep it off
  • [VSCode] Added an Active quick filter and a status filter menu (Needs input, Working, Completed) to the session list sidebar
  • Fixed remote and scheduled sessions doing nothing after a connector-tool permission prompt was approved while the session was paused