93f8548f6a
- Constrained git configuration for smart-HTTP requests by explicitly overriding proxy, sslVerify, and credential helpers across all relevant path suffixes. - Prevented potential credential capture by disabling repo-configured credential helpers that could otherwise execute malicious commands during authentication challenges. - Hardened git operations against attacker-injected proxies by exhaustively blanking configuration keys for all identifiable git request endpoints. - Excluded sslCAInfo/sslCAPath from overrides to prevent premature TLS negotiation failure while maintaining security via mandatory proxy neutralization.