Page MenuHomeMiraheze

Upgrade git to 2.17.1
Closed, ResolvedPublic

Description

https://blogs.msdn.microsoft.com/devops/2018/05/29/announcing-the-may-2018-git-security-vulnerability/

This applies to the servers, but also to all of us who use the miraheze/mediawiki repo. There's a bug in git that allows arbitrary code execution with submodules. We need the entire team to be secure, too.

Also safe are new versions v2.13.7, v2.14.4, v2.15.2 and v2.16.4.

Event Timeline

I did salt -E ".*" cmd.run "apt-get -t stretch-backports install git -y" which installed git 2.17.0 but 2.17.1 is shown on https://packages.debian.org/stretch-backports/git but it's not installing with apt-get -t stretch-backports install git -y. I did do a apt-get update to make sure and still dosen't install 2.17.1

I updated my git's earlier today with homebrew without realising it was security update.

2.17.1 is now able to be downloaded just upgraded misc1.

John assigned this task to Paladox.
John changed the visibility from "Custom Policy" to "Public (No Login Required)".
John changed the edit policy from "Custom Policy" to "All Users".