Browse Source
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAABCAAGBQJZgNa+AAoJELC16IaWr+bLaMIP/1tHYbkQ/iMvYE8RpV5SXZOC nKm8IHP4Hu+05gmp874Gw3XtF+FELC53Q2nMc3L4mJ/ZSjuJOuein9aVisapBluw IZ8UaxmgN1NUA8gDVkXULNMJGDaOQw+VckMrEAI3A0uYXGY2eAiHR3Q+p0txhHb9 jfhSsnl7Rv3q6LeDOPMKpwPVT0+uxBklrli7YcIn9IssbQhAvDUpbZ0Ab/fEOH6j NDIsZZ8opEESsUE5WBCOVXKUYjZOpLLpU4dQXa+JBj019LRmUYxLgjGVt2BSuUh/ K8xe6/3P1FOQF1tMY4Bjb2iIUnc0wzIQYULn9dqJthV0Ybz0qwT5bTt4IYYKs86I /XjJPI9cAQHNirafyUyTrWy95HGnvYSyvmNC4a2ElvD24i/GKCuRQY7O5MCT3fjB 5jUH2VxxA5E1TvkeG4VHl0d8WZib+/4CWd0OwSXk9LJJC/C/OTUlBa2dakOpwtgS RNGM+8+gzzd5rv1/UL+vAiqtCYjDfU+uqsjP5fRnMyTZiCmbhRcdW9b1TRc4OMoe wpbSbz0L18IAsyqZ+KLhyZOCr5mxjrVCxV++efI+NhsRecmO5nbPNtRGKf7/AtAQ +e5hROZRSFwf8/bXoobcOvhpuvW36+0mVXxIOGIoYtXB6AdtvGFXi9TnC/rTLBZG zuj/z2fmgo3F0G2tnNxk =t0hU -----END PGP SIGNATURE----- Merge tag 'v2.13.5' into maintmaint

14 changed files with 130 additions and 2 deletions
@ -0,0 +1,4 @@
@@ -0,0 +1,4 @@
|
||||
Git v2.10.4 Release Notes |
||||
========================= |
||||
|
||||
This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 |
@ -0,0 +1,4 @@
@@ -0,0 +1,4 @@
|
||||
Git v2.11.3 Release Notes |
||||
========================= |
||||
|
||||
This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 |
@ -0,0 +1,4 @@
@@ -0,0 +1,4 @@
|
||||
Git v2.12.4 Release Notes |
||||
========================= |
||||
|
||||
This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 |
@ -0,0 +1,4 @@
@@ -0,0 +1,4 @@
|
||||
Git v2.13.5 Release Notes |
||||
========================= |
||||
|
||||
This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 |
@ -0,0 +1,25 @@
@@ -0,0 +1,25 @@
|
||||
Git v2.7.6 Release Notes |
||||
======================== |
||||
|
||||
Fixes since v2.7.5 |
||||
------------------ |
||||
|
||||
* A "ssh://..." URL can result in a "ssh" command line with a |
||||
hostname that begins with a dash "-", which would cause the "ssh" |
||||
command to instead (mis)treat it as an option. This is now |
||||
prevented by forbidding such a hostname (which will not be |
||||
necessary in the real world). |
||||
|
||||
* Similarly, when GIT_PROXY_COMMAND is configured, the command is |
||||
run with host and port that are parsed out from "ssh://..." URL; |
||||
a poorly written GIT_PROXY_COMMAND could be tricked into treating |
||||
a string that begins with a dash "-". This is now prevented by |
||||
forbidding such a hostname and port number (again, which will not |
||||
be necessary in the real world). |
||||
|
||||
* In the same spirit, a repository name that begins with a dash "-" |
||||
is also forbidden now. |
||||
|
||||
Credits go to Brian Neel at GitLab, Joern Schneeweisz of Recurity |
||||
Labs and Jeff King at GitHub. |
||||
|
@ -0,0 +1,4 @@
@@ -0,0 +1,4 @@
|
||||
Git v2.8.6 Release Notes |
||||
======================== |
||||
|
||||
This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 |
@ -0,0 +1,4 @@
@@ -0,0 +1,4 @@
|
||||
Git v2.9.5 Release Notes |
||||
======================== |
||||
|
||||
This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 |
Loading…
Reference in new issue