-
Notifications
You must be signed in to change notification settings - Fork 2.6k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[New git version] v2.48.1 #5363
Comments
Cannot wait to shot 💉 it down straight into my twister 🪢 pair 🙄 |
I'm interested in this to avoid https://nvd.nist.gov/vuln/detail/CVE-2024-52006. I know that is marked as low but given the prevalence of other high vulnerabilities found in the Clone2Leak research, I suspect that there could be other vulnerabilities which this could prevent. |
Wasn't that fix backported into 2.47.1.2? |
No I don't think so. It was backported to 2.47.2. |
The linked release notes mention that CVE number under "Bug Fixes". |
Indeed, CVE-2024-52006 was addressed in v2.47.1(2), along with four other CVEs. Technically, it is not even correct to say that the fix was backported from v2.47.2 because Git for Windows v2.47.1(2) was built (and distributed to stakeholders well in advance of the public release) waaay before Git v2.47.2 was tagged. |
@dscho any ETA 🗓️ when new 🆕 release may drop? 🙄 |
@bricss nope, still busy with other things. |
I actually have the PR branch ready, but needed to do some clean-up first (which I hope to merge tomorrow). My best bet is that Git for Windows v2.48.1 will be released this coming Monday or Tuesday. |
And just as a side note: since there are no functional changes between the current |
@dscho FYI ℹ️
|
@bricss wow, thank you so much for paying attention and giving me a heads-up! |
https://github.com/git/git/releases/tag/v2.48.1
The text was updated successfully, but these errors were encountered: