You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Fixes a credential-leak vulnerability in go-git's smart-HTTP transport
where authentication credentials could be forwarded to a redirect target
on a different host. Patched in v5.18.0, which adds `followRedirects`
configuration defaulting to `initial`.
Sourcebot clones only trusted code hosts over HTTPS, so practical
exposure is low, but bumping removes the advisory.
Co-authored-by: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
0 commit comments