{"version":"2.1.283","anchor":"sandboxed-git-remote-handling-no-longer-permits-plain-http","canonical_anchor":"sandboxed-git-remote-handling-no-longer-permits-plain-http","heading":"Restricted git operations now refuse plain http remotes","tier":"notice","area":"Git","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283\/e\/sandboxed-git-remote-handling-no-longer-permits-plain-http","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.283","markdown":"### Restricted git operations now refuse plain http remotes\n\nClaude Code's sanitized git operations now allow only https, plus file where permitted, and refuse plain http:\/\/ remotes\n\n**Unclear.** Which feature runs these git operations is not stated.\n\n**What**\n\nFor certain git operations, Claude Code runs git with a cleaned-up environment. That environment now lets git use only:\n\n- https\n\n- file, where file access is allowed\n\nPlain http is no longer permitted, and a remote address must start with `https:\/\/` (or `file:\/\/` where allowed). A plain `http:\/\/` remote is refused. Credential variables are still blanked as before.\n\n**Why**\n\nThis stops git from fetching over unencrypted connections in this path. If you rely on an `http:\/\/` remote here, it will now be refused.\n\n- Area: Git\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}