forked from git/git
-
Notifications
You must be signed in to change notification settings - Fork 2.6k
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
Git for Windows v2.35.2 Changes since Git for Windows v2.35.1(2) (February 1st 2022) This version addresses CVE-2022-24765 and CVE-2022-24767. New Features * Comes with Git v2.35.2. Bug Fixes * The uninstaller was hardened to avoid a vulnerability when running under the SYSTEM account, addressing CVE-2022-24767. Signed-off-by: Victoria Dye <[email protected]>
- Loading branch information
Showing
14 changed files
with
309 additions
and
12 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,24 @@ | ||
Git v2.30.2 Release Notes | ||
========================= | ||
|
||
This release addresses the security issue CVE-2022-24765. | ||
|
||
Fixes since v2.30.2 | ||
------------------- | ||
|
||
* Build fix on Windows. | ||
|
||
* Fix `GIT_CEILING_DIRECTORIES` with Windows-style root directories. | ||
|
||
* CVE-2022-24765: | ||
On multi-user machines, Git users might find themselves | ||
unexpectedly in a Git worktree, e.g. when another user created a | ||
repository in `C:\.git`, in a mounted network drive or in a | ||
scratch space. Merely having a Git-aware prompt that runs `git | ||
status` (or `git diff`) and navigating to a directory which is | ||
supposedly not a Git worktree, or opening such a directory in an | ||
editor or IDE such as VS Code or Atom, will potentially run | ||
commands defined by that other user. | ||
|
||
Credit for finding this vulnerability goes to 俞晨东; The fix was | ||
authored by Johannes Schindelin. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,6 @@ | ||
Git v2.31.2 Release Notes | ||
========================= | ||
|
||
This release merges up the fixes that appear in v2.30.3 to address | ||
the security issue CVE-2022-24765; see the release notes for that | ||
version for details. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,6 @@ | ||
Git v2.32.1 Release Notes | ||
========================= | ||
|
||
This release merges up the fixes that appear in v2.30.3 and | ||
v2.31.2 to address the security issue CVE-2022-24765; see the | ||
release notes for these versions for details. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,15 @@ | ||
Git v2.33.2 Release Notes | ||
========================= | ||
|
||
This release merges up the fixes that appear in v2.30.3, v2.31.2 | ||
and v2.32.1 to address the security issue CVE-2022-24765; see | ||
the release notes for these versions for details. | ||
|
||
In addition, it contains the following fixes: | ||
|
||
* Squelch over-eager warning message added during this cycle. | ||
|
||
* A bug in "git rebase -r" has been fixed. | ||
|
||
* One CI task based on Fedora image noticed a not-quite-kosher | ||
construct recently, which has been corrected. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,6 @@ | ||
Git v2.34.2 Release Notes | ||
========================= | ||
|
||
This release merges up the fixes that appear in v2.30.3, v2.31.2, | ||
v2.32.1 and v2.33.2 to address the security issue CVE-2022-24765; | ||
see the release notes for these versions for details. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,7 @@ | ||
Git v2.35.2 Release Notes | ||
========================= | ||
|
||
This release merges up the fixes that appear in v2.30.3, | ||
v2.31.2, v2.32.1, v2.33.2 and v2.34.2 to address the security | ||
issue CVE-2022-24765; see the release notes for these versions | ||
for details. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,27 @@ | ||
safe.directory:: | ||
These config entries specify Git-tracked directories that are | ||
considered safe even if they are owned by someone other than the | ||
current user. By default, Git will refuse to even parse a Git | ||
config of a repository owned by someone else, let alone run its | ||
hooks, and this config setting allows users to specify exceptions, | ||
e.g. for intentionally shared repositories (see the `--shared` | ||
option in linkgit:git-init[1]). | ||
+ | ||
This is a multi-valued setting, i.e. you can add more than one directory | ||
via `git config --add`. To reset the list of safe directories (e.g. to | ||
override any such directories specified in the system config), add a | ||
`safe.directory` entry with an empty value. | ||
+ | ||
This config setting is only respected when specified in a system or global | ||
config, not when it is specified in a repository config or via the command | ||
line option `-c safe.directory=<path>`. | ||
+ | ||
The value of this setting is interpolated, i.e. `~/<path>` expands to a | ||
path relative to the home directory and `%(prefix)/<path>` expands to a | ||
path relative to Git's (runtime) prefix. | ||
+ | ||
Due to the permission model on Windows where ACLs are used instead of | ||
Unix' simpler permission model, it can be a bit tricky to figure out why | ||
a directory is considered unsafe. To help with this, Git will provide | ||
more detailed information when the environment variable | ||
`GIT_TEST_DEBUG_UNSAFE_DIRECTORIES` is set to `true`. |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Oops, something went wrong.