Claude Code 2.1.295 makes hooks fail closed
Claude Code 2.1.295 adds `onFailure: "block"` for command and HTTP hooks, so missing executables, timeouts, and unexpected failures block guarded actions instead of allowing them through. The opt-in change strengthens policy enforcement while preserving fail-open behavior for existing hooks.
This is a small configuration switch with outsized operational impact: policy hooks only work as controls when their own failures are treated as denials.
- –Use it for deterministic gates protecting secrets, deployments, destructive commands, or compliance checks.
- –Leave logging, formatting, and notification hooks fail-open so transient outages do not halt development.
- –Existing hooks retain the `continue` default, so teams must explicitly add `onFailure: "block"` and test broken paths and timeouts.
- –The setting applies to command and HTTP hooks; it complements, rather than replaces, Claude Code’s permissions and sandboxing.
DISCOVERED
1h ago
2026-10-11
PUBLISHED
1h ago
2026-10-11
RELEVANCE
AUTHOR
DIY Smart Code