Commit 0728a77dae
Verified · cmc ci/build: success ci/test: success ci/vuln: success
Layout: unified · split
internal/control/ghimport.go +3 −2
| @@ -136,11 +136,12 @@ func (g *ghClient) get(path string, out any) error { | ||
| 136 | 136 | |
| 137 | 137 | // pinnedClient reaches api's host only at its checked addresses, never |
| 138 | 138 | // through a proxy from the environment, and follows no redirect, as |
| 139 | // webhook delivery and repo import do. | |
| 139 | // webhook delivery and repo import do. Each import builds its own | |
| 140 | // client, so connections are not kept for reuse. | |
| 140 | 141 | func pinnedClient(api gitpin.Remote) *http.Client { |
| 141 | 142 | return &http.Client{ |
| 142 | 143 | Timeout: 30 * time.Second, |
| 143 | Transport: &http.Transport{Proxy: nil, DialContext: api.DialContext, TLSHandshakeTimeout: 10 * time.Second}, | |
| 144 | Transport: &http.Transport{Proxy: nil, DialContext: api.DialContext, TLSHandshakeTimeout: 10 * time.Second, DisableKeepAlives: true}, | |
| 144 | 145 | CheckRedirect: func(req *http.Request, _ []*http.Request) error { |
| 145 | 146 | return fmt.Errorf("refusing redirect to %s://%s; a renamed repository is imported under its new name", req.URL.Scheme, req.URL.Host) |
| 146 | 147 | }, |