Browse Source
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAABCAAGBQJZfleHAAoJELC16IaWr+bLxB8QANsdFCtO+/PFnda2CmadVt/J d4AGMSu+cD74aUp5wzMscROCggn3vMHVeDMdVJ3ihcY6nLjJRy0EC/VJ5yTpSGli iq2GjmoH/oTS2tq2JWbTe86VMVYAzuWlWyowwH6OymDLkBQcAOap1WfUHTmKehUi BV2br1x15c7hRGToFqN8yed39iVmQoDJ5ETTBgFqkVyVHDdlyc81FRt0RfiA2x3N nm5/gOOWvH5X4Cyu7yP2C9GSV9p1mufEtw1DNwp+MV3n3wa2P4wJeNnYYmW85hpS ZzuWEM9QcU3fbShHxHcwHCyy2imXUUsfm1/Y6rCH3ZVSzo1icz5ghL2rnmcxdZvS JMp60EKbaapUiIkI23R2Yvlh81J5frwOp739DYytlai3rZF7le9KYGQnsUrv95Ie CvFGr3Btiy3oEVOP7xRiGnGtThmVRP4mFsIIIgf3YsBJqRXRwxqn1D6jbkHBqu7z VfFnpp63BsKY59Udo1qilkxS2qQ35gAS+TNczPV9D0m3n3bZ5UXEMuonahAE5YwG d20wBNOd86oK4khtMWcxXx4BBx+tlA99FfQOgxvn3XWnHmTAJE3+L0uEajZpEpcU gkHLo0EutMY+xmX9+jwszmBS9gNL9xzFADtAoYIoAsmpaD7jBJsTjwyzstTyXLvr 5jcZT/hyX4iZtOUlC67J =fCBm -----END PGP SIGNATURE----- Merge tag 'v2.11.3' into maint-2.12 Git 2.11.3maint

11 changed files with 116 additions and 0 deletions
@ -0,0 +1,4 @@
@@ -0,0 +1,4 @@
|
||||
Git v2.10.4 Release Notes |
||||
========================= |
||||
|
||||
This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 |
@ -0,0 +1,4 @@
@@ -0,0 +1,4 @@
|
||||
Git v2.11.3 Release Notes |
||||
========================= |
||||
|
||||
This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 |
@ -0,0 +1,25 @@
@@ -0,0 +1,25 @@
|
||||
Git v2.7.6 Release Notes |
||||
======================== |
||||
|
||||
Fixes since v2.7.5 |
||||
------------------ |
||||
|
||||
* A "ssh://..." URL can result in a "ssh" command line with a |
||||
hostname that begins with a dash "-", which would cause the "ssh" |
||||
command to instead (mis)treat it as an option. This is now |
||||
prevented by forbidding such a hostname (which will not be |
||||
necessary in the real world). |
||||
|
||||
* Similarly, when GIT_PROXY_COMMAND is configured, the command is |
||||
run with host and port that are parsed out from "ssh://..." URL; |
||||
a poorly written GIT_PROXY_COMMAND could be tricked into treating |
||||
a string that begins with a dash "-". This is now prevented by |
||||
forbidding such a hostname and port number (again, which will not |
||||
be necessary in the real world). |
||||
|
||||
* In the same spirit, a repository name that begins with a dash "-" |
||||
is also forbidden now. |
||||
|
||||
Credits go to Brian Neel at GitLab, Joern Schneeweisz of Recurity |
||||
Labs and Jeff King at GitHub. |
||||
|
@ -0,0 +1,4 @@
@@ -0,0 +1,4 @@
|
||||
Git v2.8.6 Release Notes |
||||
======================== |
||||
|
||||
This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 |
@ -0,0 +1,4 @@
@@ -0,0 +1,4 @@
|
||||
Git v2.9.5 Release Notes |
||||
======================== |
||||
|
||||
This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 |
Loading…
Reference in new issue