{"version":"2.1.281","anchor":"git-env-hardening-classifies-toolchain-env-vars-as-a-directo","canonical_anchor":"git-env-hardening-classifies-toolchain-env-vars-as-a-directo","heading":"Git env hardening classifies toolchain env vars as a directory or a file","tier":null,"area":null,"url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281\/e\/git-env-hardening-classifies-toolchain-env-vars-as-a-directo","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.281","markdown":"### Git env hardening classifies toolchain env vars as a directory or a file\n\nGit environment hardening now sorts toolchain variables like `JAVA_HOME` as folders and `UV_PYTHON` as files\n\n**Unclear.** The finding does not say how each label changes the way a variable is treated.\n\n**What**\n\nWhen Claude Code runs git, it builds a restricted, hardened set of environment variables for it. Environment variables are named settings passed to programs. A new sorting step labels toolchain variables by what they point to:\n\n- Folders, such as `GOROOT`, `JAVA_HOME` and `VIRTUAL_ENV`.\n\n- Files, such as `JAVACMD`, `UV_PYTHON` and `SOPS_GPG_EXEC`.\n\nThe hardened environment builder now uses this sorting.\n\n**Why**\n\nIn practice, these variables are now handled according to whether they name a folder or a file when git runs."}