{"version":"2.1.284","anchor":"git-url-safety-check-tolerates-leading-whitespacecontrol-ch","canonical_anchor":"git-url-safety-check-tolerates-leading-whitespacecontrol-ch","heading":"Risky git and ssh addresses are now caught even when padded with spaces or tabs","tier":"notice","area":"Permissions","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284\/e\/git-url-safety-check-tolerates-leading-whitespacecontrol-ch","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.284","markdown":"### Risky git and ssh addresses are now caught even when padded with spaces or tabs\n\nClaude Code's check for dangerous ssh, git and file addresses now ignores leading spaces and hidden tabs or line breaks before matching\n\n**Unclear.** It is not clear which Claude Code feature, such as plugin sources from git, relies on this check.\n\n**What**\n\nClaude Code checks certain addresses to see whether they start with a risky scheme, such as `ssh:\/\/`, `git:\/\/`, `git+ssh:\/\/`, `ssh+git:\/\/` or `file:\/\/`. The scheme is the part before `:\/\/` that says how to connect.\n\nBefore, the check only matched when the address began exactly with one of those schemes. It now first removes leading spaces and invisible control characters, and ignores tabs and line breaks inside the scheme. An address written as a space followed by `ssh:`, a tab, then `\/\/` is now recognised as ssh.\n\n**Why**\n\nThis closes a gap where extra whitespace could slip an ssh address past the check. Ssh addresses can be abused to make your computer run commands, so catching them matters.\n\n- Area: Permissions\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}