Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.283 ·

Self-hosted runners handle git certificates, TLS settings and credentials per source for governed git

Self-hosted runners using governed git now build a certificate bundle, move GIT_SSL_* into session git config and pass per-source git environments

Group of 5 You'll notice Improvements
JSON All of v2.1.283
You'll noticeTier: how much it should matter to you
2Useful: my rating, 1 to 5
2Signal: worth watching, 1 to 5
Self-Hosted RunnersArea: what it touches
ImprovementsKind: in v2.1.283,
ImprovementsSection of the release

What

A self-hosted runner is a machine you operate that runs Claude Code sessions. Governed git routes its git traffic through a git mount provided by Anthropic. Several things change in how these runners set up git:

  • Certificate file. When the operator has set GIT_SSL_CAINFO (a file of trusted certificate authorities, or CAs), the runner builds its own certificate file. It holds the machine's public CAs, read from /etc/ssl/certs/ca-certificates.crt or /etc/pki/tls/certs/ca-bundle.crt, plus the operator's CAs. The runner uses it for its own fetches from the mount.
  • Build failures. If the file can't be built, the runner prints a warning naming the reason: the file is unreadable, over 1 MiB, not PEM, holds TRUSTED CERTIFICATE blocks, no system roots were found, a write failed, or --capacity is above 1. The runner never builds the file when capacity is above 1.
  • Pushes on release. Before pushing outcome branches that include governed sources, the runner rebuilds this file. If that fails, it logs that the runner's own git keeps GIT_SSL_CAINFO.
  • Per-source git settings. Each source on the mount carries its own gitEnvironment. It is passed to checkout hooks, the reset and fetch helpers, and outcome-branch create, fetch, delete and push, as extra per-command git config entries and environment overrides.
  • Session environment. Runner sessions add gitEnvironment.envOverrides on top of the base environment.
  • TLS variables inside sessions. For governed sessions on git 2.31 or newer, the runner removes GIT_SSL_CAINFO and GIT_SSL_NO_VERIFY from the environment. It writes http.sslCAInfo and http.sslVerify=false into the session's git config instead, so the mount and governed hosts are still verified. On older git, or when the value is unusable, the variables stay in place. Each outcome prints a [runner:warn] explanation.
  • New warnings. They cover NO_PROXY entries that cover governed hosts, and client-certificate variables (GIT_SSL_CERT, GIT_SSL_KEY) that would be offered to the session relay.
  • Windows. The runner reads the server-delivered session variables without regard to upper or lower case.
  • Credential helpers. Git config entries exported into GIT_CONFIG_PARAMETERS may now have an empty value when the key matches credential.<scheme>://….helper. An empty value clears the inherited list of credential helpers (programs git asks for passwords). All other entries still refuse empty values or characters the shell would act on.

Why

Operators behind a proxy that inspects TLS traffic often set GIT_SSL_CAINFO to only their company's CA. The mount presents a public certificate, so fetches from it could fail. The runner now combines both sets of CAs and applies git credentials and settings per source. Operators should read the new warnings. Because the TLS settings now live in the session's git config, any per-host http.<url>.sslCAInfo or http.<url>.sslVerify the operator has set can take effect for that host.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhat the per-command git settings contain is not established.
Anthropic's release notes agreeSelf-hosted runner: Changed GIT_SSL_CAINFO and GIT_SSL_NO_VERIFY under Anthropic-managed git: the runner's own git always verifies…

See this entry in the whole of v2.1.283 →

Feedback