fix: revert git clone http redirection forbidden (#38530)

Revert to 1.26 behavior.

Incomplete, HandleGitCmdHTTPRedirection can be improved
This commit is contained in:
wxiaoguang
2026-07-20 18:04:23 +08:00
committed by GitHub
parent 2fec2affc4
commit 6525e6df15
4 changed files with 24 additions and 11 deletions
+1 -3
View File
@@ -151,9 +151,7 @@ func Clone(ctx context.Context, from, to string, opts CloneRepoOptions) error {
}
cmd := gitcmd.NewCommand().AddArguments("clone")
// Never follow HTTP redirects: no clone caller needs them, and a remote redirecting to an
// otherwise-blocked address would be an SSRF vector (e.g. migrating from an attacker URL).
cmd.AddArguments("-c", "http.followRedirects=false")
HandleGitCmdHTTPRedirection(cmd, from, to)
if opts.SkipTLSVerify {
cmd.AddArguments("-c", "http.sslVerify=false")
}