Claude Code v2.1.222 fixes worktree destructive-git-command and hook-bypass safety gaps
Anthropic
Following yesterday's v2.1.221 (Focus view, sandbox credential masking), Anthropic shipped Claude Code v2.1.222 on August 4, fixing two safety gaps: worktree-isolated sessions and subagents could run destructive git commands against the main checkout, and PreToolUse auto-allow hooks could be bypassed by tools running in background tasks.
Why it matters
Closes real safety gaps for isolated and background Claude Code sessions running unattended.
Importance: 1/5
Patch-level safety bug fix following a minor release from yesterday, not a flagship change.
Sources
official
Claude Code changelog