-
-
Notifications
You must be signed in to change notification settings - Fork 5.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Escape git fetch remote #19487
Escape git fetch remote #19487
Conversation
-> #19490 |
* giteaofficial/main: User specific repoID or xorm builder conditions for issue search (go-gitea#19475) Add notags to fetch (go-gitea#19487)
Was a CVE requested for this issue? Because this looks exploitable. |
@mweinelt one was requested, pending assignment |
already reported |
Will there be a patch for 1.15.11? And do you have an EOL policy somewhere? |
https://github.com/go-gitea/gitea/blob/main/CONTRIBUTING.md#release-cycle
Although it's not very obvious, it means that the latest stable releases would get updates implicitly. At the moment, the latest stable release is 1.16 |
well here is the backport: #19728 - but we will not make a new release for v1.15.x |
feel free to cherry-pick the commit if you relay on 1.15 ... but you should really upgrade anyway the build fails at #19728 ... so well it's EOL for sure!!! |
as title