Shipped. Daily  |  Friday, May 22, 2026

Claude Code shipped twice on Friday: a Bash hotfix at midnight, then a security-and-transparency drop at dinner.

Lead

Claude Code v2.1.149: four security patches and the /usage breakdown you actually needed

Four security fixes in one drop. PowerShell permission bypass via built-in cd functions. Git worktrees sandbox write allowlist covering the entire repo root instead of scoped paths. PowerShell prefix/wildcard allow rules incorrectly pre-approving native executables. A permission-analysis gap from stale variable tracking for PWD/OLDPWD/DIRSTACK. These are sandbox and permission-boundary issues: the kind that compound when Claude Code runs with broad access on systems adjacent to production.

Beyond the security work: /usage now shows cost broken down by category (skills, subagents, plugins, per-MCP-server) rather than a single opaque total. Useful for any workflow heavy on agent chains. /diff gains keyboard navigation (arrows, j/k, PgUp/PgDn). GFM task list checkboxes now render in markdown output. Enterprise gets allowAllClaudeAiMcps for cloud MCP connectors via managed settings.

The day opened with v2.1.148, a one-liner: Bash tool was returning exit code 127 on every command. A regression from v2.1.147. Fixed within hours of the window opening.

Release Log
C Claude Code
Claude Code v2.1.149
Major drop. /usage now shows per-category cost breakdown: skills, subagents, plugins, per-MCP-server. /diff gains keyboard navigation. Markdown renders GFM task list checkboxes. Enterprise: allowAllClaudeAiMcps managed setting for claude.ai cloud MCP connectors. Four security fixes: PowerShell cd bypass, git worktree sandbox scope, wildcard pre-approval gap, stale PWD variable tracking. Also fixes find exhausting macOS vnode table on large trees, managed-settings dialog freeze, and /ultraplan remote session creation errors.
How to use: claude update. The /usage breakdown and /diff navigation are live immediately.
Claude Code v2.1.148
Critical hotfix. Bash tool was returning exit code 127 (command not found) on every invocation: a regression introduced in v2.1.147. Any workflow depending on shell command execution was broken until this landed.
How to use: claude update. If you're on v2.1.147 and Bash commands are failing, this is why.
E Agent SDKs
Python SDK v0.104.1
Bug fix: encrypted_content was not being carried through the beta compaction accumulator during streaming. Affects users of extended thinking with context compaction enabled.
How to use: pip install anthropic==0.104.1
Quiet on the Wire

Python SDK v0.104.0 and TypeScript SDK v0.98.0 (both May 21, ~16:00 EDT) landed just outside today's window. Both add the thinking-token-count beta: estimated token counts for thinking block deltas during streaming. Check yesterday's sweep or the SDK releases directly.

No model announcements. No API release notes (docs.anthropic.com returned 403 in this sweep). The Anthropic news page showed nothing new within the window: the KPMG alliance (May 19) and Gates Foundation partnership (May 14) remain the week's headline stories.

Stay on the frontier

Get Shipped. in your inbox.

Daily digest at 9 PM ET. Weekly magazine every Friday morning. Six labs, one feed. No spam, one-click unsubscribe.