HomePhabricator

Upgrade JGit to 4.5.5.201812240535-r

Authored by David Ostrovsky <david@ostrovsky.org> on Dec 27 2018, 9:39 PM.

Description

Upgrade JGit to 4.5.5.201812240535-r

This release fixes an issue where AdvertiseRefsHook was not called for
git-upload-pack in protocol v0 bidirectional transports, meaning that
wants aren't validated and a user can fetch anything that is pointed
to by any ref (using fetch-by-sha1), as long as they can guess the
object name.

Bug: Issue 10262
Change-Id: I5c1af5c7c549e1796fe6347c1ec08797471393a1

Event Timeline

David Pursehouse <dpursehouse@collab.net> committed rGERRITDEPLOYbb3011f0b03c: Upgrade JGit to 4.5.5.201812240535-r (authored by David Ostrovsky <david@ostrovsky.org>).Jan 6 2019, 11:21 PM