Browse Source
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAABCAAGBQJZhM4RAAoJELC16IaWr+bLzGcQAOh3MYjKeZ4V2XghvFlzXHOa 8Q2/PiLuPxDoVJan7h4HZXnHdT1DRY8QFwLR88vwxqXSeuVMhJYdfmo8qkIeCI++ ZldLoEX08UhXWRUS/0Inr3f9BgAYqILSi7k8CNTV/pNkwQh4+mWsBvJ7ma+PgO0I +1ErShop2ciWC9mwlqvQp7AA7+eUisAXeIDULUtE57JrAXIpl49vhPOWMDw4wPIf 8U+Pk5rchivbjKGDHRYf5/Qb/UVx3kraPbEBHxAu9tEUnn5RcTsPZd5WvQLdZeya EjKI9VPsmhhoYj+U2KcsSaJ1g2vQheh529yDF0lxeHWa03T+ItROCJNMNoLrUq+v D28fH3Z3y3B1Sv3v9hKsLO1t4O4Q03hsTga05omNc1utnYmNC1aDu5EQ0LGnmcgR ToLSnnzO8hrqaYYnOG6EzYnbltxKr7MyNIh62MjSvOgKD5RgZ/OREO+Z1GmyEDWv NdrcgCGOJTVAEdiEN5gD2JZCoCE/iAmQWpshktD4Y+lcejl4/rdVHNlLB35sCC6y Gcn1d8sRrmAI290tdlMu+1+77H3es7eSGPvm0V65gMDcin5M0ZCjpPMj4rKN4P6v sTVUM4u5cSwfswkAlPB9nBs+/9IdtD+aP1SN8Fi2Nv4EGjYyD+Xr32aJomv8wQ7I 81smo0FkWMCnGzG8quyx =fMiT -----END PGP SIGNATURE----- Merge tag 'v2.14.1'maint

16 changed files with 135 additions and 3 deletions
@ -0,0 +1,4 @@
@@ -0,0 +1,4 @@
|
||||
Git v2.10.4 Release Notes |
||||
========================= |
||||
|
||||
This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 |
@ -0,0 +1,4 @@
@@ -0,0 +1,4 @@
|
||||
Git v2.11.3 Release Notes |
||||
========================= |
||||
|
||||
This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 |
@ -0,0 +1,4 @@
@@ -0,0 +1,4 @@
|
||||
Git v2.12.4 Release Notes |
||||
========================= |
||||
|
||||
This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 |
@ -0,0 +1,4 @@
@@ -0,0 +1,4 @@
|
||||
Git v2.13.5 Release Notes |
||||
========================= |
||||
|
||||
This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 |
@ -0,0 +1,4 @@
@@ -0,0 +1,4 @@
|
||||
Git v2.14.1 Release Notes |
||||
========================= |
||||
|
||||
This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 |
@ -0,0 +1,25 @@
@@ -0,0 +1,25 @@
|
||||
Git v2.7.6 Release Notes |
||||
======================== |
||||
|
||||
Fixes since v2.7.5 |
||||
------------------ |
||||
|
||||
* A "ssh://..." URL can result in a "ssh" command line with a |
||||
hostname that begins with a dash "-", which would cause the "ssh" |
||||
command to instead (mis)treat it as an option. This is now |
||||
prevented by forbidding such a hostname (which will not be |
||||
necessary in the real world). |
||||
|
||||
* Similarly, when GIT_PROXY_COMMAND is configured, the command is |
||||
run with host and port that are parsed out from "ssh://..." URL; |
||||
a poorly written GIT_PROXY_COMMAND could be tricked into treating |
||||
a string that begins with a dash "-". This is now prevented by |
||||
forbidding such a hostname and port number (again, which will not |
||||
be necessary in the real world). |
||||
|
||||
* In the same spirit, a repository name that begins with a dash "-" |
||||
is also forbidden now. |
||||
|
||||
Credits go to Brian Neel at GitLab, Joern Schneeweisz of Recurity |
||||
Labs and Jeff King at GitHub. |
||||
|
@ -0,0 +1,4 @@
@@ -0,0 +1,4 @@
|
||||
Git v2.8.6 Release Notes |
||||
======================== |
||||
|
||||
This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 |
@ -0,0 +1,4 @@
@@ -0,0 +1,4 @@
|
||||
Git v2.9.5 Release Notes |
||||
======================== |
||||
|
||||
This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 |
@ -1 +1 @@
@@ -1 +1 @@
|
||||
Documentation/RelNotes/2.14.0.txt |
||||
Documentation/RelNotes/2.14.1.txt |
Loading…
Reference in new issue