Browse Source
-----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAABCAAGBQJZflhUAAoJELC16IaWr+bLDyAP/jWDc9ic8S1ZH8W4ijAB24vP YRyQ1gbnRLhpEpbHYCUp7Uw9mrJBfdwYFlqxGJPH4JZL9qYLJUe5DJMWi5uAEptg tYPpPMLV5hgvGICwJbOaS5NlNf2NzLjRvzziOpUnE5CcR5Bw7doCPk4Uw6AVvAvK 0x/6KDNLdKCBl3ZIoLdp9eW2PrTfYx6AK+Wf9oEgdMSB9+23acL7R/QEmH7oh9gl BS0riRQVHnku5akybMnRjeba7SvdhJlIV8rPc4WpuMRz0g2lPzOKQ+okeRtdQrfi REdEZ920EJR65KtxUgxYLrpPpmdRBxNI0jXC3Sm2Kac85MLvjFqhaosBWhTQuoOf tra68Gb9WSVkKLwRhRBYOG+dx00m1UETs7cYm6pw37RiMss1pcZWNdzjNNouVEEp 3LBXcPJSpCbEjI+U/H2CqLqCk9gMfKLJXB9hK4b9jBcB9yrON2d75tPMhOcNx+Ej x6vZ4Zql6r1Bhe8y7T6KMnLe6vdli8Vrd7Tj5btogcEUmVfRQVHZzV94utevv9A5 UEXLeCjJSjcY7rYtTdSLXgESioHW8WNfG+TPiyxjujSybtxGKmkcrSGCrugT26K8 UT5VH2mYJOuHRtWnjWEEEhjayaXLv0mHNQ5XVfNDNPEFqRBQmIhLhcIf/aOF6r+F 4Q6qN9QceJUEiaFnHsyO =ZBXN -----END PGP SIGNATURE----- Merge tag 'v2.12.4' into maintmaint
Junio C Hamano
8 years ago
13 changed files with 126 additions and 2 deletions
@ -0,0 +1,4 @@
@@ -0,0 +1,4 @@
|
||||
Git v2.10.4 Release Notes |
||||
========================= |
||||
|
||||
This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 |
@ -0,0 +1,4 @@
@@ -0,0 +1,4 @@
|
||||
Git v2.11.3 Release Notes |
||||
========================= |
||||
|
||||
This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 |
@ -0,0 +1,4 @@
@@ -0,0 +1,4 @@
|
||||
Git v2.12.4 Release Notes |
||||
========================= |
||||
|
||||
This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 |
@ -0,0 +1,25 @@
@@ -0,0 +1,25 @@
|
||||
Git v2.7.6 Release Notes |
||||
======================== |
||||
|
||||
Fixes since v2.7.5 |
||||
------------------ |
||||
|
||||
* A "ssh://..." URL can result in a "ssh" command line with a |
||||
hostname that begins with a dash "-", which would cause the "ssh" |
||||
command to instead (mis)treat it as an option. This is now |
||||
prevented by forbidding such a hostname (which will not be |
||||
necessary in the real world). |
||||
|
||||
* Similarly, when GIT_PROXY_COMMAND is configured, the command is |
||||
run with host and port that are parsed out from "ssh://..." URL; |
||||
a poorly written GIT_PROXY_COMMAND could be tricked into treating |
||||
a string that begins with a dash "-". This is now prevented by |
||||
forbidding such a hostname and port number (again, which will not |
||||
be necessary in the real world). |
||||
|
||||
* In the same spirit, a repository name that begins with a dash "-" |
||||
is also forbidden now. |
||||
|
||||
Credits go to Brian Neel at GitLab, Joern Schneeweisz of Recurity |
||||
Labs and Jeff King at GitHub. |
||||
|
@ -0,0 +1,4 @@
@@ -0,0 +1,4 @@
|
||||
Git v2.8.6 Release Notes |
||||
======================== |
||||
|
||||
This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 |
@ -0,0 +1,4 @@
@@ -0,0 +1,4 @@
|
||||
Git v2.9.5 Release Notes |
||||
======================== |
||||
|
||||
This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 |
Loading…
Reference in new issue