[BUG] ask permission rule for Bash(git push *) not triggering confirmation prompt
Preflight Checklist
- [x] I have searched existing issues and this hasn't been reported yet
- [x] This is a single bug report (please file separate reports for different bugs)
- [x] I am using the latest version of Claude Code
What's Wrong?
Description
Environment
- Claude Code version: (run claude --version to get this)
- OS: macOS 24.6.0
What happened
I have the following rule in .claude/settings.json:
"ask": ["Bash(rm )", "Bash(mv )", "Bash(git push *)"]
Claude ran git push twice in the same session without triggering a confirmation prompt. The ask rule was silently bypassed.
Expected behavior
Claude should pause and ask for user confirmation before executing any command matching Bash(git push *).
Actual behavior
git push ran without any prompt. The commands that executed were:
git push
(plain push with no additional arguments)
Steps to reproduce
- Add "Bash(git push *)" to the ask array in .claude/settings.json
- In a session, ask Claude to push a branch
- Observe that git push runs without a confirmation prompt
Additional context
The * glob may not be matching a bare git push with no trailing arguments, which could explain why the rule isn't firing. If the pattern requires at least one argument after push, a bare git push would slip through.
---
That last "Additional context" line is worth including — it gives the maintainers a plausible root cause to investigate (glob matching behavior on commands with no trailing args).
What Should Happen?
Claude should pause and ask for user confirmation before executing any command matching Bash(git push *).
Error Messages/Logs
Steps to Reproduce
- Add "Bash(git push *)" to the ask array in .claude/settings.json
- In a session, ask Claude to push a branch
- Observe that git push runs without a confirmation prompt
Claude Model
None
Is this a regression?
Yes, this worked in a previous version
Last Working Version
_No response_
Claude Code Version
2.1.145 (Claude Code)
Platform
Anthropic API
Operating System
macOS
Terminal/Shell
Terminal.app (macOS)
Additional Information
The * glob may not be matching a bare git push with no trailing arguments, which could explain why the rule isn't firing. If the pattern requires at least one argument after push, a bare git push would slip through.