The git rpms
Find a file
Todd Zullinger d90a306a79 update to 2.34.3 (#2073414, CVE-2022-24765)
Per the upstream release notes from 2.30.3¹:

    This release addresses the security issue CVE-2022-24765.

     * CVE-2022-24765:
       On multi-user machines, Git users might find themselves
       unexpectedly in a Git worktree, e.g. when another user created a
       repository in `C:\.git`, in a mounted network drive or in a
       scratch space. Merely having a Git-aware prompt that runs `git
       status` (or `git diff`) and navigating to a directory which is
       supposedly not a Git worktree, or opening such a directory in an
       editor or IDE such as VS Code or Atom, will potentially run
       commands defined by that other user.

and 2.30.4²:

    This release contains minor fix-ups for the changes that went into
    Git 2.30.3, which was made to address CVE-2022-24765.

     * The code that was meant to parse the new `safe.directory`
       configuration variable was not checking what configuration
       variable was being fed to it, which has been corrected.

     * '*' can be used as the value for the `safe.directory` variable to
       signal that the user considers that any directory is safe.

¹ https://github.com/git/git/raw/v2.30.3/Documentation/RelNotes/2.30.3.txt
² https://github.com/git/git/raw/v2.30.4/Documentation/RelNotes/2.30.4.txt
2022-04-18 15:00:52 -04:00
.gitignore Check upstream GPG signatures in %prep 2016-03-27 21:31:56 -04:00
.mailmap Add .mailmap for git shortlog output 2017-11-28 21:27:36 -05:00
0001-t-lib-gpg-use-with-colons-when-parsing-gpgsm-output.patch fix gpgsm issues with gnupg-2.3 2021-11-25 05:52:09 -05:00
0002-t-lib-gpg-reload-gpg-components-after-updating-trust.patch fix gpgsm issues with gnupg-2.3 2021-11-25 05:52:09 -05:00
0003-t-lib-gpg-kill-all-gpg-components-not-just-gpg-agent.patch fix gpgsm issues with gnupg-2.3 2021-11-25 05:52:09 -05:00
0004-t4202-match-gpgsm-output-from-GnuPG-2.3.patch fix gpgsm issues with gnupg-2.3 2021-11-25 05:52:09 -05:00
0005-gpg-interface-match-SIG_CREATED-if-it-s-the-first-li.patch fix gpgsm issues with gnupg-2.3 2021-11-25 05:52:09 -05:00
git-cvsimport-Ignore-cvsps-2.2b1-Branches-output.patch Update to git-1.6.2.2 2009-04-04 20:47:17 +00:00
git-gui.desktop Update to git-1.6.3.2 2009-06-06 01:45:16 +00:00
git.rpmlintrc lint: ignore "no-binary" warning for main git package 2020-12-07 11:41:54 -05:00
git.skip-test-patterns update to 2.34.0 2021-11-24 23:23:19 -05:00
git.socket use systemd instead of xinetd (bz 737183) 2013-04-30 14:25:37 -04:00
git.spec update to 2.34.3 (#2073414, CVE-2022-24765) 2022-04-18 15:00:52 -04:00
git.xinetd.in Rename %gitcoredir to %gitexecdir; upstream uses the latter 2017-11-12 13:15:13 -05:00
git@.service.in daemon: use --log-destination=stderr with systemd 2018-04-11 23:19:00 -04:00
gitweb-httpd.conf Rename gitweb httpd config file 2018-03-19 11:08:38 -04:00
gitweb.conf.in Update to git-1.6.6.1 2010-01-31 21:05:27 +00:00
gpgkey-junio.asc update Junio's GPG key (with extended expiration) 2021-02-08 21:58:40 -05:00
print-failed-test-output print-failed-test-output: minor improvements 2019-02-11 22:47:30 -05:00
sources update to 2.34.3 (#2073414, CVE-2022-24765) 2022-04-18 15:00:52 -04:00