Fail the Hook Closed. Stable Only Stepped to v2.1.286.

At a glance

  • A new Claude Code setting lets a guard hook that crashes, hangs or never starts block the action instead of waving it through, and it had not reached npm's stable channel at 6:01 AM ET today.
  • Claude Code's stable channel moved one step on Thursday, to a build that does not have that setting.
  • Codex's new release matters most as a sandbox fix for Linux and Windows 10, and its new worktree tools stay off unless you turn the feature on.
  • Copilot CLI's new release lets managed policy keep every session on manual approval, while Gemini CLI and Cursor shipped nothing new.

The common thread this Friday is guards that fail quietly, since a Claude Code hook that never starts has acted much like one that said yes. Claude Code v2.1.295 adds a way to make those failures block, but the npm stable channel only stepped from v2.1.285 to v2.1.286 on Thursday, so most fleets still let a dead hook through. Treat today as the day to canary Claude Code v2.1.295 and fail your most important hooks closed, pin Codex v0.162.0 where the Linux sandbox denies more than one file, and move Copilot CLI to v1.0.94 while leaving the v1.0.95 pre-releases alone.

Top Stories

1. Claude Code v2.1.295 can block when a hook never runs

Anthropic published Claude Code v2.1.295 to npm at 2:22 PM ET Thursday and posted the GitHub release at 3:48 PM ET. The first line of its changelog adds onFailure: "block" for command and HTTP hooks, so a hook that cannot start, times out, or exits with an unexpected code blocks the action instead of letting it through. The changelog does not define an unexpected exit code. At 6:01 AM ET today the hooks reference still did not mention onFailure and still called exit codes other than 2 non-blocking errors, so the changelog and the GitHub release are the only official sources for now.

This is not the v2.1.288 change we covered on 3 Oct, which blocks a call when Claude Code cannot work out which hooks apply. The new field covers the hook process itself. The changelog calls it an addition and states no default, so our reading is that a hook without it keeps the old pass-through behavior. The release names command and HTTP hooks only, not prompt or agent hooks.

The same release gives Claude apps gateway operators two controls. An optional models list on any upstream means only the listed models are sent there, on failover too, and one * in an entry acts as a wildcard. A timeouts.upstream_ttfb_ms value on cloud upstreams caps how long a stream may take to start, after which the request fails over or gets a 502.

At 6:01 AM ET today npm latest and next both pointed to v2.1.295 and stable pointed to v2.1.286, and Anthropic’s native installer pointers matched. That v2.1.286 build was published on 30 Sep and reached the npm stable tag on Thursday. It retries on the previous model of the same tier when the API refuses your alias and disconnects Remote Control when org policy turns it off, but it has neither onFailure nor the gateway controls.

Practical dev impact: If claude --version prints v2.1.286, a guard hook that fails to start still lets the action through. Canary v2.1.295 on a few machines, restart the session, and add onFailure only to the command and HTTP hooks you truly want to fail closed, because a broken script will then stop work until someone fixes it. Keep the fleet on its channel until the canary has run a normal day, and on a gateway write the models list before relying on failover.

2. Codex v0.162.0 is a sandbox pin, not a worktree rollout

OpenAI released Codex v0.162.0 on GitHub at 2:55 PM ET Thursday and on npm at 3:01 PM ET, and it was npm latest at 6:01 AM ET today. The fixes that matter change sandbox behavior. Linux sandbox startup with multiple denied files is fixed, sandbox setup now rejects a sandbox-construction executable that is writable, and ripgrep configuration can no longer weaken deny-glob masks. On Windows 10, ordinary drive-letter file access works again.

The new tools for creating and listing managed Git worktrees only appear when the worktrees feature is enabled, and only for trusted local projects.

Practical dev impact: Pin v0.162.0 on Linux agents whose sandbox denies more than one file and on Windows 10 seats that lost drive-letter access. Leave the worktrees feature off on repositories that hold secrets until you know what it creates, and keep the v0.163.0 alpha builds off fleet machines.

3. Copilot CLI v1.0.94 lets policy force Manual Approval

GitHub released Copilot CLI v1.0.94 at 4:28 PM ET Thursday, npm had it a minute later, and it was npm latest at 6:01 AM ET today. Managed policy can now disable Assisted Permissions and keep sessions in Manual Approval mode, and the CLI shows a policy warning when managed settings suppress startup bypass-permission flags. Where Assisted Permissions is still allowed, it now sends visible shell code to the permission judge instead of asking for approvals it did not need. The release notes do not name the policy key, so check GitHub’s managed settings docs rather than guessing one.

At 6:01 AM ET npm prerelease pointed to v1.0.95-2, the newest of three Thursday-evening pre-releases, posted at 10:33 PM ET. It only fixes copilot config support for sandbox credential injectHosts keys.

Practical dev impact: Canary v1.0.94 if your organization does not want a model judging which shell commands to approve, and expect every session to ask for approval once the policy is on. Developers whose bypass flag is suppressed now see a warning instead of silently losing it. Nothing in the v1.0.95 pre-release notes we read changes a permission decision, so keep those builds off fleet machines.

4. Gemini CLI and Cursor did not move

At 6:01 AM ET today Gemini CLI npm latest was still v0.63.0 and preview still v0.64.0-preview.0, both published Tuesday, and only the nightly tag had moved. Cursor’s changelog still leads with Remote Control for local agents, which we covered on Wednesday.

Practical dev impact: Leave Gemini CLI on v0.63.0 and keep Wednesday’s Cursor Remote Control decision; neither gives you a reason to touch a pin today.

Practical Impact Analysis

Most of today’s work is telling a guard that said yes from a guard that never ran, and onFailure is the first official way to make Claude Code treat the two differently. Because it lives only on v2.1.295, the honest position for a stable fleet is that its hooks are still best effort, so a small canary is worth more than a policy memo. Failing closed has a cost, though. A hook that depends on a network call or a slow disk will start blocking work once you add the field, so set a sensible timeout first and add onFailure only to the handlers that guard something you cannot undo.

Codex and Copilot CLI moved in the same direction from different sides. Codex tightened what its Linux sandbox lets through and fixed a Windows 10 regression, while Copilot CLI gave admins a switch to keep a human on every approval. Both pins remove risk rather than add features. In all three tools the new behavior only helps machines that actually run the new build, so check versions rather than trusting the channel you think a machine follows.

Tutorial

Check the channels first, since these tags move without notice. The install lines are commented out so you can run the checks safely and uncomment one on purpose, on the channel it names.

bash Tutorial
#!/usr/bin/env bash
# 1. Read the channel pointers and local versions.
npm view @anthropic-ai/claude-code dist-tags --json
npm view @openai/codex dist-tags --json
npm view @github/copilot dist-tags --json
claude --version   # onFailure needs v2.1.295 or later
codex --version
copilot --version

# 2. Optional canaries. Leave stable fleets (npm stable was v2.1.286 at 6:01 AM ET) alone.
# Claude Code, npm latest at 6:01 AM ET, adds onFailure; npm installs only:
# npm install -g @anthropic-ai/claude-code@2.1.295
# Codex, npm latest at 6:01 AM ET:
# npm install -g @openai/codex@0.162.0
# Copilot CLI, npm latest at 6:01 AM ET:

... click "Show full code" below to expand
▸ Show full code (16 lines)
#!/usr/bin/env bash
# 1. Read the channel pointers and local versions.
npm view @anthropic-ai/claude-code dist-tags --json
npm view @openai/codex dist-tags --json
npm view @github/copilot dist-tags --json
claude --version   # onFailure needs v2.1.295 or later
codex --version
copilot --version

# 2. Optional canaries. Leave stable fleets (npm stable was v2.1.286 at 6:01 AM ET) alone.
# Claude Code, npm latest at 6:01 AM ET, adds onFailure; npm installs only:
# npm install -g @anthropic-ai/claude-code@2.1.295
# Codex, npm latest at 6:01 AM ET:
# npm install -g @openai/codex@0.162.0
# Copilot CLI, npm latest at 6:01 AM ET:
# npm install -g @github/copilot@1.0.94

Restart Claude Code and expect v2.1.295. Native installs follow their own channel pointers, so trust claude --version over the tag and do not mix npm and native installs on one machine. The hooks reference does not document onFailure yet, and the changelog names the key, the value "block" and the hook types but not where the key goes, so we are not printing a sample config. Set a timeout on the hook first, and confirm the placement on one canary machine before you copy it anywhere.

To test it, rename the hook’s script in a scratch project so the hook cannot start, ask Claude to run the command it guards, confirm the call is blocked, then put the script back. This test is our suggestion, not Anthropic’s, and we have not run it.

Recommended AI prompt

Copy this paragraph into ChatGPT, Claude, Gemini, Grok, or whatever AI you use.

I use Claude Code hooks as guard rails. Claude Code v2.1.295 added an onFailure setting with the value "block" for command and HTTP hooks, so a hook that cannot start, times out, or exits with an unexpected code blocks the action instead of letting it through, and the hooks documentation does not describe the setting yet. The npm stable channel was on v2.1.286, which does not have it, at 6:01 AM ET on 9 October 2026. I will paste my hooks configuration, the scripts the hooks run, and the output of claude --version below. For each hook, tell me whether it guards something I could not undo and should fail closed, what in the script could make it fail to start or time out, and what timeout to set before I add onFailure. Do not invent other setting names or values, and ask me for anything you need instead of guessing.

Go deeper in Grok

Explore each Top Story in Grok. Links open in a new tab. On phones, the same link may open the Grok app if you have it installed (via your device's normal link handling).

Article: Fail the Hook Closed. Stable Only Stepped to v2.1.286.

Privacy: links open grok.com in your session only. AIDevPulse does not run your prompts through our API.

Leave a Comment