Claude Code Hardens /ultrareview Uploads of Local Checkouts

Claude CodeView original changelog

Claude Code 2.1.285 changes how /ultrareview uploads a local checkout. Uncommitted credential files with names such as server:8443.key are no longer included, symbolic refs are left out, and partial clones, separate git directories and old git versions are handled explicitly. Several Windows, WSL and worktree upload failures were also fixed.

Key Takeaways

  • Uncommitted credential files with colons in the name, such as server:8443.key, are no longer included in /ultrareview uploads.
  • Symbolic refs are omitted from uploads, and a checkout on a symbolic-ref branch is refused with an explanation.
  • Uploading a local repository now requires git 2.31 or newer on macOS and Linux.
  • --separate-git-dir checkouts are refused instead of being uploaded with an older method.
  • Partial clones upload as a working-tree snapshot on git 2.31+, and are refused when files are missing on older git.
  • Windows, WSL and worktree upload failures involving odd file names and core.longpaths were fixed.

A fix that keeps credentials on the machine

/ultrareview uploads a working tree to be reviewed in the cloud, including uncommitted changes. Claude Code 2.1.285 fixes a case where those uploads included uncommitted changes to credential files whose name has a colon before the extension, such as server:8443.key. A related fix improves the credential-file check for file or folder names with many backup or editor marks, and removes a slowdown on some unusual file names. For anyone reviewing a repository that sits next to key material, this closes a way for sensitive files to leave the machine.

New rules for what gets uploaded

On macOS and Linux, /ultrareview now behaves more predictably, and in some cases more strictly:

  • Symbolic refs are left out of the upload, and a checkout whose current branch is a symbolic ref is refused with an explanation.
  • A local repository now requires git 2.31 or newer to upload, and checkouts made with --separate-git-dir are refused instead of being uploaded with an older method.
  • A partial clone is sent as a working-tree snapshot on git 2.31 or newer, rather than falling back or refusing because git looked too old.
  • On older git versions, a partial clone missing some working-tree files is refused rather than fetched; a clone made without --filter uploads normally.

Platform fixes

On WSL, uploads of a checkout on a Linux volume were refused when a changed file name had a colon or ended in a dot or space. On Windows, a linked worktree of a repository rooted at the home folder was uploaded incorrectly in some cases. Another fix handles a git worktree whose per-worktree config sets core.longpaths, and a misleading "core.worktree is set" error appearing when the project folder briefly could not be read is gone.