iusrepo / wishlist

meta repo for IUS new package requests
33 stars 8 forks source link

git 2.30.2 #299

Closed dexxtreme closed 3 years ago

dexxtreme commented 3 years ago

What new package do you want?

git 2.30.2 / git230

Why?

A newly announced security vulnerability affects all versions of git between 2.15 and 2.30.2 => https://github.blog/2021-03-09-git-clone-vulnerability-announced/

Testing

I agree to test the new package to ensure that it works as expected. Once I am satisfied with the results of my testing I will comment on this issue with the word "STABLE" to get it promoted to the stable repos.

carlwgeorge commented 3 years ago

Hey @dexxtreme! The git project also backported the fix to multiple earlier versions, including 2.22.5 and 2.24.4. Our git222 and git224 packages have been updated to the relevant versions. Packages are available in ius-testing.

There is still demand for a newer git package for other reasons, but we can track that over in #297.