This seems to be an issue of git. It's very surprising that a git command would invoke its arguments in shell.
They should have used `popen` instead.
This is similar to python's subprocess with `shell=True`
Edit: I'm wrong!
> ls-remote has a parameter --upload-pack which can be used to execute a new shell
[1] pry(main)> system "echo", "$(whoami)"
$(whoami)
=> true
[2] pry(main)> system "git", "ls-remote", "--upload-pack=$(whoami)", "HEAD"
$(whoami) 'HEAD': USERNAME: command not found
fatal: Could not read from remote repository.
Please make sure you have the correct access rights
and the repository exists.
=> falseP.S. it seems that you have an extra space before `--upload-pack`.
Specifically, the problem here is that git, like almost every other CLI tool, tries to add as many features as possible to make it easy to use from a console. This (coupled with the fact that these things are never documented, as is the case here, unless <exec> is some idiom I'm supposed to be aware of) makes it harder to use in a correct manor (security bugs being a subset of possible problems).