Claude Code is Anthropic’s coding-agent tool. A GitHub issue alleges that a recent version automatically inserted a private Claude session identifier into six commits pushed to a public repository, creating an information-disclosure and repository-provenance concern; a separate discussion confirms that Claude Code adds some attribution metadata to commits by default. The supplied snippets do not independently establish the broader claim that shareable session URLs are appended to every commit and pull-request description, nor that Anthropic has confirmed or is reviewing that exact behavior.
2026-08-31T19:06:59Z
The episode has stabilized into a known, configurable Claude Code provenance default with documented controls, not a demonstrated public-session leak. Repeated discussion adds no new exposure test or product change, so the actionable behavior is absorbed while the stronger privacy claim remains unproven.
2026-08-31T12:35:32Z
The refreshed comments add no access test, Anthropic response, or change to the documented controls; they only repeat the established consent-versus-provenance debate. Session-link insertion remains corroborated and configurable, while public exposure of session contents remains unproven.
2026-08-31T09:31:04Z
The refreshed comments add no new reproduction details, access test, Anthropic response, or change to the documented opt-out. The configurable provenance behavior remains corroborated, while public exposure of session contents remains unproven and discussion is fully repetitive.
2026-08-31T07:23:21Z
Continued refreshed commentary with no new access test, Anthropic response, or reproduction beyond the documented opt-out; discussion is now fully repetitive and cooling further.
2026-08-31T06:30:17Z
The refreshed discussion adds no access test, version-specific reproduction, Anthropic response, or change to the documented opt-out. The configurable provenance behavior remains corroborated, while actual public exposure of session contents remains unproven and commentary is now repetitive.
2026-08-31T05:23:45Z
The refreshed comments add no access test, version-specific reproduction, Anthropic response, or change to the documented opt-out. The unwanted session-link metadata behavior remains corroborated, but public exposure of session contents is still unproven and discussion has become repetitive.
2026-08-31T04:28:40Z
The refreshed discussion remains repetitive and adds no access test, Anthropic response, or change to the documented opt-out. Session-link insertion is corroborated, while public exposure of session contents remains unproven.
2026-08-31T02:27:48Z
The refreshed discussion adds no access test, Anthropic response, or change to the documented opt-out; it remains repetitive debate over provenance and consent. Session-link insertion is corroborated, while public exposure of session contents remains unproven.
2026-08-31T01:29:32Z
The refreshed comments add no access test, version-specific reproduction, or Anthropic response and continue the established provenance-versus-privacy debate. Session-link insertion and its opt-out remain corroborated, while public exposure of session contents remains unproven.
2026-08-31T00:31:26Z
The refreshed discussion adds no independent access test, version-specific reproduction, or Anthropic response. The configurable metadata behavior remains corroborated, while public exposure of session contents remains unproven and discussion is repetitive.
2026-08-30T23:33:33Z
The refreshed discussion adds no access test, version-specific reproduction, or Anthropic response; it remains repetitive amplification of the established configurable metadata behavior. Session-link insertion is corroborated, but public exposure of session contents remains unproven.
2026-08-30T22:31:09Z
Refreshed comments continue the established debate over attribution, visibility, and responsibility without adding an access test, Anthropic response, or new reproduction details. The configurable metadata behavior remains corroborated, while public exposure of session contents remains unproven.
2026-08-30T21:32:02Z
Refreshed comments remain repetitive debate over attribution and responsibility, without a new access test, version-specific reproduction, or Anthropic response. The configurable session-link default is still corroborated, while actual public exposure of session contents remains unproven.
2026-08-30T20:35:54Z
The new evidence broadens the pattern of contested Claude Code Git metadata defaults to co-author attribution, but does not strengthen the claim that session URLs expose session contents. The insertion behavior remains corroborated and configurable; the privacy consequence remains unproven.
2026-08-30T20:23:27Z
evidence attached: hn.story.49502101 — An independent user report highlights a related Claude Code repository-provenance concern around default authorship metadata.
2026-08-30T19:43:05Z
The refreshed comments only repeat the existing provenance-versus-privacy debate and add no access test, version-specific reproduction, or Anthropic response. Session-link insertion remains corroborated and actionable, but public exposure is still unproven and the discussion is cooling into repetition.
2026-08-30T18:33:41Z
Independent user accounts now corroborate that Claude Code inserts session-link attribution into real commit and PR workflows, and a settings-based opt-out makes the behavior immediately actionable. The concern is now an unwanted provenance default rather than a demonstrated public-session leak, since access remains separately controlled and untested.
2026-08-30T18:23:28Z
evidence attached: reddit.post.1w2omfu — A direct user report links the behavior to Anthropic’s issue tracker and documents a concrete settings-based mitigation, materially strengthening the provenance and privacy concern.
2026-08-30T17:29:11Z
The refreshed comments add user reaction, including subscription cancellation, but no new reproduction details, access test, Anthropic response, or mitigation. The case remains about potentially unwanted provenance metadata; public session exposure is still unproven, and discussion is now repetitive.
2026-08-30T16:31:56Z
The refreshed discussion mainly repeats the already-known split between useful provenance and unwanted metadata; it adds no reproducible version details, Anthropic response, or evidence that linked sessions become publicly accessible. The insertion behavior remains anecdotally supported, while the claimed privacy exposure is still unproven.
2026-08-30T15:35:36Z
Multiple commenters now describe seeing session links in real Claude Code workflows, providing anecdotal corroboration that insertion is not isolated. Their reports also suggest session visibility remains separately controlled, shifting the concern toward undisclosed provenance metadata while public exposure remains unproven.
2026-08-30T14:32:18Z
The refreshed comments deepen the provenance-versus-privacy debate but still provide no independent reproduction, public-access test, or Anthropic response. The case remains an actionable single-user report rather than evidence of a broadly confirmed default or exposure.
2026-08-30T13:31:31Z
The expanded discussion remains attribution debate and speculative reaction rather than independent reproduction of session-link insertion or proof that linked sessions are publicly accessible. The actionable original report still stands, but the case has gained attention rather than substance.
2026-08-30T13:30:21Z
grounded: converges/medium — The alleged default exposes exactly the boundary Scott draws between provenance-bearing commits and separately governed raw session history: provenance should b
2026-08-30T13:28:05Z
origin walked (codex/luna, conf 0.98): anchor hn.story.49498201 -> echo.github.773e61521f by joka-7
2026-08-30T13:25:46Z
case created — The linked issue identifies a concrete, reproducible coding-agent metadata behavior with immediate privacy and provenance implications.