Timeline
Claude Code 2.1.224 removes the old 200-subagent cap, enabling truly parallel workflows.
Scored 78.9% on Terminal-Bench 2.1 and 88.6% on SWE-bench Verified with Opus 4.6
Released version 2.1.221 with credential masking, VSCode Focus view, and 20 security fixes
Claude Code shifts to a policy-controlled execution layer with deterministic security workflows
Shift to a policy-controlled execution layer in the harness, enforcing deterministic security workflows
Open-source plugin 'dont-let-me' released for Claude Code, Codex, and OpenCode
Production-readiness audit revealed 3 security gaps: fail-open resolver, unpinned servers, opt-in least-privilege
litellm@1.82.8 package was hijacked on PyPI through a compromised maintainer account
Compromised by malicious code inserted by the TeamPCP/Lapsus$ hacking group, leading to a widespread supply-chain attack affecting thousands of companies.
Malicious version 1.38.2 of LiteLLM was uploaded to PyPI containing code to steal API keys and credentials