Follow Discord
Sweep 25 Sep 2026 · 19:33Z Build v2.1.283 504 read Stable v2.1.274 Latest v2.1.283 Next v2.1.283 Feeds RSS JSON llms.txt llms-full.txt Unofficial

Claude Code v2.1.283 ·

Self-hosted runner routes git per host between Anthropic-managed git and the machine's own credentials

The self-hosted runner can now split git hosts between Anthropic-managed git and direct access, and its --use-anthropic-git-proxy warning no longer says github.com only

Group of 2 You'll notice Improvements
JSON All of v2.1.283
You'll noticeTier: how much it should matter to you
3Useful: my rating, 1 to 5
4Signal: worth watching, 1 to 5
Self-Hosted RunnersArea: what it touches
ImprovementsKind: in v2.1.283,
What probably matters to youSection of the release

What

The self-hosted runner (the program that runs Claude Code sessions on a machine you manage) can now treat different git hosts differently within one session. Which hosts go where is decided by the server, in the work item's tool_config (governed_git with a host split, hostSplit). There is no client flag for it.

  • The runner reads governed_hosts and direct_hosts from the work item. Sources on governed hosts go through the Anthropic git mount and the session relay. Sources on direct or unlisted hosts use the machine's own git rewrite and credentials.
  • gitConfig is enabled only when the governed list is not empty, and the gh path shim only when a particular host is governed. Whether the REST mount URL is passed through also depends on the governed hosts, and that URL must pass an extra check or the runner falls back to the older git flow with a warning.
  • The runner sets up per-session git CA bundle files (certificate files git uses to trust servers) and passes a childGitEnvironment to the session process and to the checkout and post-session hooks.
  • The log line saying governed git is active now includes the per-host routing.
  • New warnings: malformed host entries are ignored; GIT_ASKPASS answers for every host, so a machine credential could pass through the relay; direct-host sources under --use-anthropic-git-proxy need credentials stored where that flag does not reach; a governed-host URL that cannot be routed through the mount (for example one on a nonstandard port) falls back to this machine's own credentials.
  • The --use-anthropic-git-proxy warning no longer gives "a source host other than github.com" as an example reason. It now says "a source host the server does not route through Anthropic-managed git, or a server that predates the opt-in".

Why

Operators of self-hosted runners can mix hosts handled by Anthropic-managed git and hosts that use the machine's own credentials in the same session. The warnings point out where credentials might leak through the relay or where a host silently falls back to local credentials.

How sure we are
Something disagreesSomething we can check disagrees with this entry, or the writer said they could not settle it.
The writer flagged doubtWhich server setting turns on the host split is not established.

See this entry in the whole of v2.1.283 →

Feedback