Follow-up to !255, found by re-scanning rather than by me.
Both git upload-pack invocations behind the smart HTTP transport were
still resolving from PATH. My rewrite matched exec.CommandContext with a
plain identifier for the context; these pass r.Context(), so the pattern
skipped them — and the fresh scan still reported two go:S4036 after I'd
claimed all 74.
That's the value of re-scanning before dismissing: I would otherwise have dismissed two findings as "already fixed" when they were not.
Closes #153