pub fn git_failure_detail(
stderr: &[u8],
stdout: &[u8],
status: ExitStatus,
) -> StringExpand description
Build a human-readable failure detail from a git subprocess’s captured
output. Prefers stderr (where git writes diagnostics), falls back to
stdout (some errors — e.g. a git add index lock — print there), then to
the exit status when both are empty. Control and ANSI escape bytes are
stripped so a hostile remote’s error text can’t manipulate the terminal
(#307), and the result is credential-scrubbed via sanitize_git_url so a
URL with embedded credentials never echoes the secret to the terminal or
logs (#312).