Sync with 2.43.6
* maint-2.43: Git 2.43.6 Git 2.42.4 Git 2.41.3 Git 2.40.4 credential: disallow Carriage Returns in the protocol by default credential: sanitize the user prompt credential_format(): also encode <host>[:<port>] t7300: work around platform-specific behaviour with long paths on MinGW compat/regex: fix argument order to calloc(3) mingw: drop bogus (and unneeded) declaration of `_pgmptr` ci: remove 'Upload failed tests' directories' step from linux32 jobs
This commit is contained in:
5
Documentation/RelNotes/2.40.4.txt
Normal file
5
Documentation/RelNotes/2.40.4.txt
Normal file
@ -0,0 +1,5 @@
|
||||
Git v2.40.4 Release Notes
|
||||
=========================
|
||||
|
||||
This release lets Git refuse to accept URLs that contain control
|
||||
sequences. This addresses CVE-2024-50349 and CVE-2024-52006.
|
6
Documentation/RelNotes/2.41.3.txt
Normal file
6
Documentation/RelNotes/2.41.3.txt
Normal file
@ -0,0 +1,6 @@
|
||||
Git v2.41.3 Release Notes
|
||||
=========================
|
||||
|
||||
This release merges up the fix that appears in v2.40.4 to address
|
||||
the security issues CVE-2024-50349 and CVE-2024-52006; see the
|
||||
release notes for that version for details.
|
6
Documentation/RelNotes/2.42.4.txt
Normal file
6
Documentation/RelNotes/2.42.4.txt
Normal file
@ -0,0 +1,6 @@
|
||||
Git v2.42.4 Release Notes
|
||||
=========================
|
||||
|
||||
This release merges up the fix that appears in v2.40.4 and v2.41.3
|
||||
to address the security issues CVE-2024-50349 and CVE-2024-52006;
|
||||
see the release notes for these versions for details.
|
7
Documentation/RelNotes/2.43.6.txt
Normal file
7
Documentation/RelNotes/2.43.6.txt
Normal file
@ -0,0 +1,7 @@
|
||||
Git v2.43.6 Release Notes
|
||||
=========================
|
||||
|
||||
This release merges up the fix that appears in v2.40.4, v2.41.3
|
||||
and v2.42.4 to address the security issues CVE-2024-50349 and
|
||||
CVE-2024-52006; see the release notes for these versions for
|
||||
details.
|
@ -14,6 +14,17 @@ credential.useHttpPath::
|
||||
or https URL to be important. Defaults to false. See
|
||||
linkgit:gitcredentials[7] for more information.
|
||||
|
||||
credential.sanitizePrompt::
|
||||
By default, user names and hosts that are shown as part of the
|
||||
password prompt are not allowed to contain control characters (they
|
||||
will be URL-encoded by default). Configure this setting to `false` to
|
||||
override that behavior.
|
||||
|
||||
credential.protectProtocol::
|
||||
By default, Carriage Return characters are not allowed in the protocol
|
||||
that is used when Git talks to a credential helper. This setting allows
|
||||
users to override this default.
|
||||
|
||||
credential.username::
|
||||
If no username is set for a network authentication, use this username
|
||||
by default. See credential.<context>.* below, and
|
||||
|
Reference in New Issue
Block a user