DEFAULT_ENV_ALLOWLIST
constDEFAULT_ENV_ALLOWLIST: readonlystring[]
Defined in: src/core/env.ts:79
Curated allowlist of environment variables inherited by default.
These are variables Git (and the tools it shells out to, such as ssh and credential helpers) commonly needs to operate. The list intentionally excludes arbitrary application secrets so they are not silently forwarded to Git subprocesses.
Security notes:
- The SSH agent vars (
SSH_AUTH_SOCK,SSH_AGENT_PID) and SSH/TLS transport config (GIT_SSH_COMMAND,GIT_SSL_CAINFO, …) are inherited by default so Git-over-SSH and fetch/push keep working out of the box. For an HTTPS-only application that does not want to expose the SSH agent, drop it withinheritEnv: { remove: ['SSH_AUTH_SOCK', 'SSH_AGENT_PID'] }. - The most credential-prone helpers (
GIT_ASKPASS,SSH_ASKPASS,GIT_PROXY_COMMAND) are intentionally NOT in the default allowlist; opt them back in explicitly (inheritEnv: ['GIT_ASKPASS']) only when you trust the value.
Variable names are matched case-insensitively on Windows.