[BUG] ask permission rule for Bash(git push *) not triggering confirmation prompt

Status Open
Reported on v2.1.145
Maintainer reply None cached
Activity 0 comments · opened Aug 18, 2026

Preflight Checklist

  • [x] I have searched existing issues and this hasn't been reported yet
  • [x] This is a single bug report (please file separate reports for different bugs)
  • [x] I am using the latest version of Claude Code

What's Wrong?

Description

Environment

  • Claude Code version: (run claude --version to get this)
  • OS: macOS 24.6.0

What happened
I have the following rule in .claude/settings.json:

"ask": ["Bash(rm )", "Bash(mv )", "Bash(git push *)"]

Claude ran git push twice in the same session without triggering a confirmation prompt. The ask rule was silently bypassed.

Expected behavior
Claude should pause and ask for user confirmation before executing any command matching Bash(git push *).

Actual behavior
git push ran without any prompt. The commands that executed were:
git push
(plain push with no additional arguments)

Steps to reproduce

  1. Add "Bash(git push *)" to the ask array in .claude/settings.json
  2. In a session, ask Claude to push a branch
  3. Observe that git push runs without a confirmation prompt

Additional context
The * glob may not be matching a bare git push with no trailing arguments, which could explain why the rule isn't firing. If the pattern requires at least one argument after push, a bare git push would slip through.

---
That last "Additional context" line is worth including — it gives the maintainers a plausible root cause to investigate (glob matching behavior on commands with no trailing args).

What Should Happen?

Claude should pause and ask for user confirmation before executing any command matching Bash(git push *).

Error Messages/Logs

Steps to Reproduce

  1. Add "Bash(git push *)" to the ask array in .claude/settings.json
  2. In a session, ask Claude to push a branch
  3. Observe that git push runs without a confirmation prompt

Claude Model

None

Is this a regression?

Yes, this worked in a previous version

Last Working Version

_No response_

Claude Code Version

2.1.145 (Claude Code)

Platform

Anthropic API

Operating System

macOS

Terminal/Shell

Terminal.app (macOS)

Additional Information

The * glob may not be matching a bare git push with no trailing arguments, which could explain why the rule isn't firing. If the pattern requires at least one argument after push, a bare git push would slip through.

View original on GitHub ↗