Page MenuHomePhabricator

Write and send pre-release announcements for MediaWiki 1.31.7/1.33.3/1.34.1
Closed, ResolvedPublic

Description

Previous T233496

Hi all,

Tomorrow we will be issuing a security and maintenance release to all supported branches of MediaWiki.

The new releases will be:

- 1.34.1
- 1.33.3
- 1.31.7

This will resolve two minor issues in MediaWiki core, and also includes some fixes previously committed to git, including minor security and hardening patches along with bug fixes included for maintenance reasons.

We've noted that these issues are minor, and as such you don't need to apply them as quickly as with other security releases, if you're unable to do so. We therefore decided to continue with getting the security (and maintenance) release out for this quarter as planned, even with the global situation as is.

We will make the fixes available in these respective release branches, and also master. Tarballs will be available for the above mentioned point releases as well.

A summary of some of the security fixes that have gone into non bundled MediaWiki extensions will also follow.

Details

Due Date
Mar 25 2020, 12:00 PM

Event Timeline

Reedy created this task.Dec 10 2019, 10:53 PM
Restricted Application added a subscriber: Aklapper. · View Herald TranscriptDec 10 2019, 10:53 PM
sbassett removed sbassett as the assignee of this task.
sbassett triaged this task as Medium priority.
sbassett added a subscriber: sbassett.
Reedy updated the task description. (Show Details)Dec 10 2019, 11:00 PM
Reedy renamed this task from Write and send pre-release Announcements for MediaWiki 1.31.7/1.32.7/1.33.3/1.34.1 to Write and send pre-release Announcements for MediaWiki 1.31.7/1.33.3/1.34.1.Jan 23 2020, 1:09 PM
Reedy renamed this task from Write and send pre-release Announcements for MediaWiki 1.31.7/1.33.3/1.34.1 to Write and send pre-release announcements for MediaWiki 1.31.7/1.33.3/1.34.1.Feb 13 2020, 8:47 PM
chasemp added a subscriber: chasemp.

quick meta....which I already stomped on since I went ahead and did it, but should the security release work be tagged with Security-Team?

sbassett added a comment.EditedFeb 13 2020, 8:56 PM

quick meta....which I already stomped on since I went ahead and did it, but should the security release work be tagged with Security-Team?

I'd say that's fine, though @Reedy (and me for T240400) already know(s) what to do :) Perhaps this should go under the all-powerful 'watching' column?

chasemp assigned this task to Reedy.Feb 19 2020, 4:36 PM
chasemp moved this task from Incoming to In Progress on the Security-Team board.
Reedy set Due Date to Mar 25 2020, 12:00 PM.Mar 10 2020, 2:16 PM
Reedy updated the task description. (Show Details)Mar 24 2020, 2:37 PM
Reedy updated the task description. (Show Details)Mar 24 2020, 4:10 PM
Reedy updated the task description. (Show Details)Mar 25 2020, 7:05 PM
Reedy closed this task as Resolved.Mar 25 2020, 7:24 PM
Reedy updated the task description. (Show Details)
Reedy changed the visibility from "Custom Policy" to "Public (No Login Required)".