{"version":"2.1.285","anchor":"git-remote-url-parsing-rejects-some-unsafe-forms","canonical_anchor":"git-remote-url-parsing-rejects-some-unsafe-forms","heading":"Git remote addresses in some unsafe forms are now ignored","tier":"notice","area":"Git","url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285\/e\/git-remote-url-parsing-rejects-some-unsafe-forms","release_url":"https:\/\/changelogs.core-directive.com\/v\/2.1.285","markdown":"### Git remote addresses in some unsafe forms are now ignored\n\nClaude Code now refuses to read some unsafe git remote addresses, such as ones that look like command options\n\n**Unclear.** Exactly which address forms are now rejected is not clear.\n\n**What**\n\nA git remote is the address of the online copy of a repository. When Claude Code reads that address, it now rejects some unsafe forms before trying to match it, for example addresses that look like command options. Before, only the normal pattern matching was applied.\n\n**Why**\n\nThis is hardening against a crafted address being used to slip unexpected instructions into commands.\n\n- Area: Git\n- Tier: You'll notice\n- Useful: 1\/5\n- Signal: 1\/5"}