Skip to content

Commit e6b8aab

Browse files
dcramerclaude
andauthored
chore: Expand Claude Code default permissions (#703)
Expands the default allowed permissions in `.claude/settings.json` from 17 to 136 entries, covering common development workflows for this repository. The previous settings were minimal and required frequent manual approval for standard operations. This update pre-approves read-only and commonly-used commands to improve developer experience with Claude Code. **Added permissions:** - File/directory operations (ls, find, cat, tree, mkdir, rm, mv, chmod) - Full git command coverage (status, log, diff, show, branch, stash, fetch, pull, add, commit, push, checkout, restore, reset, rebase, bisect, rm, clone) - GitHub CLI for PRs, issues, runs, and workflows - pnpm/Node.js toolchain (run, test, build, dev, install, add, list, why, outdated, update, exec, workspace/filter commands, turbo, vitest, tsx) - TypeScript and Biome linting commands - Cloudflare Wrangler deployment commands - Utility commands (grep, rg, jq, sort, awk, sed, curl, lsof, ps, pkill, timeout, tee) - WebFetch domains for framework documentation (Cloudflare, Hono, React, Zod, Vercel AI SDK, GitHub, npm) - MCP tool permissions for Sentry integrations - WebSearch capability Excludes npm/npx commands since this repo uses pnpm exclusively. --------- Co-authored-by: Claude <noreply@anthropic.com>
1 parent f59e80c commit e6b8aab

1 file changed

Lines changed: 135 additions & 12 deletions

File tree

‎.claude/settings.json‎

Lines changed: 135 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,23 +1,146 @@
11
{
22
"permissions": {
33
"allow": [
4+
"Bash(ls:*)",
5+
"Bash(pwd:*)",
6+
"Bash(find:*)",
7+
"Bash(file:*)",
8+
"Bash(stat:*)",
9+
"Bash(wc:*)",
10+
"Bash(head:*)",
11+
"Bash(tail:*)",
12+
"Bash(cat:*)",
13+
"Bash(tree:*)",
14+
"Bash(mkdir:*)",
15+
"Bash(rm:*)",
16+
"Bash(mv:*)",
17+
"Bash(chmod:*)",
18+
"Bash(git status:*)",
19+
"Bash(git log:*)",
20+
"Bash(git diff:*)",
21+
"Bash(git show:*)",
22+
"Bash(git branch:*)",
23+
"Bash(git remote:*)",
24+
"Bash(git tag:*)",
25+
"Bash(git stash:*)",
26+
"Bash(git stash list:*)",
27+
"Bash(git stash push:*)",
28+
"Bash(git rev-parse:*)",
29+
"Bash(git fetch:*)",
30+
"Bash(git pull:*)",
31+
"Bash(git add:*)",
32+
"Bash(git commit:*)",
33+
"Bash(git push:*)",
34+
"Bash(git checkout:*)",
35+
"Bash(git restore:*)",
36+
"Bash(git reset:*)",
37+
"Bash(git rebase:*)",
38+
"Bash(git bisect:*)",
39+
"Bash(git rm:*)",
40+
"Bash(git clone:*)",
41+
"Bash(gh pr view:*)",
42+
"Bash(gh pr list:*)",
43+
"Bash(gh pr checks:*)",
44+
"Bash(gh pr diff:*)",
45+
"Bash(gh pr create:*)",
46+
"Bash(gh pr comment:*)",
47+
"Bash(gh pr merge:*)",
48+
"Bash(gh pr checkout:*)",
49+
"Bash(gh issue view:*)",
50+
"Bash(gh issue list:*)",
51+
"Bash(gh issue create:*)",
52+
"Bash(gh issue comment:*)",
53+
"Bash(gh issue edit:*)",
54+
"Bash(gh run view:*)",
55+
"Bash(gh run list:*)",
56+
"Bash(gh run logs:*)",
57+
"Bash(gh repo view:*)",
58+
"Bash(gh api:*)",
59+
"Bash(gh workflow:*)",
60+
"Bash(node:*)",
61+
"Bash(pnpm run:*)",
62+
"Bash(pnpm test:*)",
63+
"Bash(pnpm build:*)",
64+
"Bash(pnpm dev:*)",
65+
"Bash(pnpm install:*)",
66+
"Bash(pnpm add:*)",
67+
"Bash(pnpm list:*)",
68+
"Bash(pnpm why:*)",
69+
"Bash(pnpm outdated)",
70+
"Bash(pnpm update:*)",
71+
"Bash(pnpm exec:*)",
72+
"Bash(pnpm -w run:*)",
73+
"Bash(pnpm -r list:*)",
74+
"Bash(pnpm --filter:*)",
75+
"Bash(pnpm turbo:*)",
76+
"Bash(pnpm vitest:*)",
77+
"Bash(pnpx vitest:*)",
78+
"Bash(pnpx tsx:*)",
79+
"Bash(pnpm tsc:*)",
80+
"Bash(pnpm exec tsc:*)",
81+
"Bash(pnpm run typecheck:*)",
82+
"Bash(pnpm typecheck:*)",
83+
"Bash(pnpm run check:*)",
84+
"Bash(pnpm -w run lint:*)",
85+
"Bash(pnpm -w run lint:fix)",
86+
"Bash(pnpm lint:*)",
87+
"Bash(pnpm biome lint:*)",
88+
"Bash(biome lint:*)",
89+
"Bash(pnpx wrangler:*)",
90+
"Bash(pnpx wrangler versions upload:*)",
91+
"Bash(pnpx wrangler delete:*)",
92+
"Bash(grep:*)",
93+
"Bash(rg:*)",
94+
"Bash(jq:*)",
95+
"Bash(sort:*)",
96+
"Bash(awk:*)",
97+
"Bash(sed:*)",
98+
"Bash(curl:*)",
99+
"Bash(lsof:*)",
100+
"Bash(ps:*)",
101+
"Bash(pkill:*)",
102+
"Bash(timeout:*)",
103+
"Bash(tee:*)",
104+
"Bash(xargs kill:*)",
4105
"WebFetch(domain:mcp.sentry.dev)",
5106
"WebFetch(domain:docs.sentry.io)",
6107
"WebFetch(domain:develop.sentry.dev)",
7108
"WebFetch(domain:modelcontextprotocol.io)",
8109
"WebFetch(domain:docs.anthropic.com)",
9-
"Bash(grep:*)",
10-
"Bash(jq:*)",
11-
"Bash(pnpx vitest:*)",
12-
"Bash(pnpm test:*)",
13-
"Bash(pnpm run typecheck:*)",
14-
"Bash(pnpm run check:*)",
15-
"Bash(pnpm run:*)",
16-
"Bash(pnpx tsx:*)",
17-
"Bash(gh pr checks:*)",
18-
"Bash(gh pr view:*)",
19-
"Bash(gh run view:*)",
20-
"Bash(git status:*)"
110+
"WebFetch(domain:developers.cloudflare.com)",
111+
"WebFetch(domain:hono.dev)",
112+
"WebFetch(domain:react.dev)",
113+
"WebFetch(domain:zod.dev)",
114+
"WebFetch(domain:sdk.vercel.ai)",
115+
"WebFetch(domain:ai-sdk.dev)",
116+
"WebFetch(domain:github.com)",
117+
"WebFetch(domain:api.github.com)",
118+
"WebFetch(domain:raw.githubusercontent.com)",
119+
"WebFetch(domain:www.npmjs.com)",
120+
"WebFetch(domain:localhost)",
121+
"mcp__sentry__search_docs",
122+
"mcp__sentry__get_doc",
123+
"mcp__sentry__search_events",
124+
"mcp__sentry__search_issues",
125+
"mcp__sentry__get_issue_details",
126+
"mcp__sentry__analyze_issue_with_seer",
127+
"mcp__sentry__find_organizations",
128+
"mcp__sentry__find_projects",
129+
"mcp__sentry__find_releases",
130+
"mcp__sentry__whoami",
131+
"mcp__sentry-dev__find_projects",
132+
"mcp__sentry-dev__find_organizations",
133+
"mcp__sentry-dev__whoami",
134+
"mcp__spotlight__get_errors",
135+
"mcp__spotlight__get_local_errors",
136+
"WebSearch",
137+
"Skill(sentry-skills:commit)",
138+
"Skill(sentry-skills:create-pr)",
139+
"Skill(sentry-skills:code-review)",
140+
"Skill(sentry-skills:find-bugs)",
141+
"Skill(sentry-skills:deslop)",
142+
"Skill(sentry-skills:iterate-pr)",
143+
"Skill(sentry-skills:claude-settings-audit)"
21144
],
22145
"deny": []
23146
},

0 commit comments

Comments
 (0)