{"version":"2.1.283","anchor":"git-remote-url-check-now-requires-https-plain-http-refus","canonical_anchor":"git-remote-url-check-now-requires-https-plain-http-refus","heading":"Git remotes using plain http:\/\/ are now refused","tier":"notice","area":"Git","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283\/e\/git-remote-url-check-now-requires-https-plain-http-refus","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283","markdown":"### Git remotes using plain http:\/\/ are now refused\n\nWhen Claude Code looks up a repository's git remote URL, it now accepts only https:\/\/ (or file:\/\/ where allowed) and refuses http:\/\/\n\n**Unclear.** It is not known which feature uses this remote lookup.\n\n**What**\n\nClaude Code has a routine that reads a repository's remote address from git's settings (`clone.defaultRemoteName` and `remote.<name>.url`). It now accepts the address only if it starts with `https:\/\/`, or `file:\/\/` where that is allowed. Addresses starting with `http:\/\/`, which were accepted before, are now refused.\n\n**Why**\n\nRepositories whose remote uses plain `http:\/\/` will be refused by whatever feature uses this lookup. It looks like a security tightening.\n\n- Area: Git\n- Names: `clone.defaultRemoteName`\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}