From 5e0649dc65fe33e8cf38823350e9d7951f6a6346 Mon Sep 17 00:00:00 2001 From: Junio C Hamano Date: Sun, 30 Jul 2017 14:45:13 -0700 Subject: Git 2.7.6 Signed-off-by: Junio C Hamano --- Documentation/RelNotes/2.7.6.txt | 25 +++++++++++++++++++++++++ 1 file changed, 25 insertions(+) create mode 100644 Documentation/RelNotes/2.7.6.txt (limited to 'Documentation') diff --git a/Documentation/RelNotes/2.7.6.txt b/Documentation/RelNotes/2.7.6.txt new file mode 100644 index 000000000..4c6d1dcd4 --- /dev/null +++ b/Documentation/RelNotes/2.7.6.txt @@ -0,0 +1,25 @@ +Git v2.7.6 Release Notes +======================== + +Fixes since v2.7.5 +------------------ + + * A "ssh://..." URL can result in a "ssh" command line with a + hostname that begins with a dash "-", which would cause the "ssh" + command to instead (mis)treat it as an option. This is now + prevented by forbidding such a hostname (which will not be + necessary in the real world). + + * Similarly, when GIT_PROXY_COMMAND is configured, the command is + run with host and port that are parsed out from "ssh://..." URL; + a poorly written GIT_PROXY_COMMAND could be tricked into treating + a string that begins with a dash "-". This is now prevented by + forbidding such a hostname and port number (again, which will not + be necessary in the real world). + + * In the same spirit, a repository name that begins with a dash "-" + is also forbidden now. + +Credits go to Brian Neel at GitLab, Joern Schneeweisz of Recurity +Labs and Jeff King at GitHub. + -- cgit v1.2.1 From 8d7f72f176ea133c16e55f386a0b79a1cd46ff69 Mon Sep 17 00:00:00 2001 From: Junio C Hamano Date: Sun, 30 Jul 2017 14:49:08 -0700 Subject: Git 2.8.6 Signed-off-by: Junio C Hamano --- Documentation/RelNotes/2.8.6.txt | 4 ++++ 1 file changed, 4 insertions(+) create mode 100644 Documentation/RelNotes/2.8.6.txt (limited to 'Documentation') diff --git a/Documentation/RelNotes/2.8.6.txt b/Documentation/RelNotes/2.8.6.txt new file mode 100644 index 000000000..d8db55d92 --- /dev/null +++ b/Documentation/RelNotes/2.8.6.txt @@ -0,0 +1,4 @@ +Git v2.8.6 Release Notes +======================== + +This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 -- cgit v1.2.1 From 4d4165b80d6b91a255e2847583bd4df98b5d54e1 Mon Sep 17 00:00:00 2001 From: Junio C Hamano Date: Sun, 30 Jul 2017 14:53:25 -0700 Subject: Git 2.9.5 Signed-off-by: Junio C Hamano --- Documentation/RelNotes/2.9.5.txt | 4 ++++ 1 file changed, 4 insertions(+) create mode 100644 Documentation/RelNotes/2.9.5.txt (limited to 'Documentation') diff --git a/Documentation/RelNotes/2.9.5.txt b/Documentation/RelNotes/2.9.5.txt new file mode 100644 index 000000000..668313ae5 --- /dev/null +++ b/Documentation/RelNotes/2.9.5.txt @@ -0,0 +1,4 @@ +Git v2.9.5 Release Notes +======================== + +This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 -- cgit v1.2.1 From 0bfff8146f8c055fd95af4567286929ba8216fa7 Mon Sep 17 00:00:00 2001 From: Junio C Hamano Date: Sun, 30 Jul 2017 15:00:04 -0700 Subject: Git 2.10.4 Signed-off-by: Junio C Hamano --- Documentation/RelNotes/2.10.4.txt | 4 ++++ 1 file changed, 4 insertions(+) create mode 100644 Documentation/RelNotes/2.10.4.txt (limited to 'Documentation') diff --git a/Documentation/RelNotes/2.10.4.txt b/Documentation/RelNotes/2.10.4.txt new file mode 100644 index 000000000..ee8142ad2 --- /dev/null +++ b/Documentation/RelNotes/2.10.4.txt @@ -0,0 +1,4 @@ +Git v2.10.4 Release Notes +========================= + +This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 -- cgit v1.2.1 From 3b827444811d7eddeddd44850f5dbbb4d59747f5 Mon Sep 17 00:00:00 2001 From: Junio C Hamano Date: Sun, 30 Jul 2017 15:02:37 -0700 Subject: Git 2.11.3 Signed-off-by: Junio C Hamano --- Documentation/RelNotes/2.11.3.txt | 4 ++++ 1 file changed, 4 insertions(+) create mode 100644 Documentation/RelNotes/2.11.3.txt (limited to 'Documentation') diff --git a/Documentation/RelNotes/2.11.3.txt b/Documentation/RelNotes/2.11.3.txt new file mode 100644 index 000000000..4e3b78d0e --- /dev/null +++ b/Documentation/RelNotes/2.11.3.txt @@ -0,0 +1,4 @@ +Git v2.11.3 Release Notes +========================= + +This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 -- cgit v1.2.1 From 3d9c5b5c4461957fbbc0479e037990db04ebb740 Mon Sep 17 00:00:00 2001 From: Junio C Hamano Date: Sun, 30 Jul 2017 15:06:06 -0700 Subject: Git 2.12.4 Signed-off-by: Junio C Hamano --- Documentation/RelNotes/2.12.4.txt | 4 ++++ 1 file changed, 4 insertions(+) create mode 100644 Documentation/RelNotes/2.12.4.txt (limited to 'Documentation') diff --git a/Documentation/RelNotes/2.12.4.txt b/Documentation/RelNotes/2.12.4.txt new file mode 100644 index 000000000..3f5693822 --- /dev/null +++ b/Documentation/RelNotes/2.12.4.txt @@ -0,0 +1,4 @@ +Git v2.12.4 Release Notes +========================= + +This release forward-ports the fix for "ssh://..." URL from Git v2.7.6 -- cgit v1.2.1