What
The self-hosted runner (the program that runs Claude Code sessions on a machine you manage) can now treat different git hosts differently within one session. Which hosts go where is decided by the server, in the work item's tool_config (governed_git with a host split, hostSplit). There is no client flag for it.
- The runner reads
governed_hostsanddirect_hostsfrom the work item. Sources on governed hosts go through the Anthropic git mount and the session relay. Sources on direct or unlisted hosts use the machine's own git rewrite and credentials. gitConfigis enabled only when the governed list is not empty, and theghpath shim only when a particular host is governed. Whether the REST mount URL is passed through also depends on the governed hosts, and that URL must pass an extra check or the runner falls back to the older git flow with a warning.- The runner sets up per-session git CA bundle files (certificate files git uses to trust servers) and passes a
childGitEnvironmentto the session process and to the checkout and post-session hooks. - The log line saying governed git is active now includes the per-host routing.
- New warnings: malformed host entries are ignored;
GIT_ASKPASSanswers for every host, so a machine credential could pass through the relay; direct-host sources under--use-anthropic-git-proxyneed credentials stored where that flag does not reach; a governed-host URL that cannot be routed through the mount (for example one on a nonstandard port) falls back to this machine's own credentials. - The
--use-anthropic-git-proxywarning no longer gives "a source host other than github.com" as an example reason. It now says "a source host the server does not route through Anthropic-managed git, or a server that predates the opt-in".
Why
Operators of self-hosted runners can mix hosts handled by Anthropic-managed git and hosts that use the machine's own credentials in the same session. The warnings point out where credentials might leak through the relay or where a host silently falls back to local credentials.
Which server setting turns on the host split is not established.