diff --git a/ReleaseNotes/ReleaseNotes-2.1.9.txt b/ReleaseNotes/ReleaseNotes-2.1.9.txt new file mode 100644 index 0000000000..728d7cc901 --- /dev/null +++ b/ReleaseNotes/ReleaseNotes-2.1.9.txt @@ -0,0 +1,16 @@ +Release notes for Gerrit 2.1.9 +============================== + +There are no schema changes from link:ReleaseNotes-2.1.8.html[2.1.8]. + +link:https://gerrit-releases.storage.googleapis.com/gerrit-2.1.9.war[https://gerrit-releases.storage.googleapis.com/gerrit-2.1.9.war] + +Bug Fixes +--------- +* Patch JGit security hole ++ +The security hole may permit a modified Git client to gain access +to hidden or deleted branches if the user has read permission on +at least one branch in the repository. Access requires knowing a +SHA-1 to request, which may be discovered out-of-band from an issue +tracker or gitweb instance. diff --git a/ReleaseNotes/ReleaseNotes-2.4.3.txt b/ReleaseNotes/ReleaseNotes-2.4.3.txt new file mode 100644 index 0000000000..c9c2d2cb2e --- /dev/null +++ b/ReleaseNotes/ReleaseNotes-2.4.3.txt @@ -0,0 +1,16 @@ +Release notes for Gerrit 2.4.3 +============================== + +There are no schema changes from link:ReleaseNotes-2.4.2.html[2.4.2]. + +link:https://gerrit-releases.storage.googleapis.com/gerrit-2.4.3.war[https://gerrit-releases.storage.googleapis.com/gerrit-2.4.3.war] + +Bug Fixes +--------- +* Patch JGit security hole ++ +The security hole may permit a modified Git client to gain access +to hidden or deleted branches if the user has read permission on +at least one branch in the repository. Access requires knowing a +SHA-1 to request, which may be discovered out-of-band from an issue +tracker or gitweb instance. diff --git a/ReleaseNotes/ReleaseNotes-2.5.5.txt b/ReleaseNotes/ReleaseNotes-2.5.5.txt new file mode 100644 index 0000000000..57b6d248ab --- /dev/null +++ b/ReleaseNotes/ReleaseNotes-2.5.5.txt @@ -0,0 +1,16 @@ +Release notes for Gerrit 2.5.5 +============================== + +There are no schema changes from link:ReleaseNotes-2.5.4.html[2.5.4]. + +link:https://gerrit-releases.storage.googleapis.com/gerrit-2.5.5.war[https://gerrit-releases.storage.googleapis.com/gerrit-2.5.5.war] + +Bug Fixes +--------- +* Patch JGit security hole ++ +The security hole may permit a modified Git client to gain access +to hidden or deleted branches if the user has read permission on +at least one branch in the repository. Access requires knowing a +SHA-1 to request, which may be discovered out-of-band from an issue +tracker or gitweb instance. diff --git a/ReleaseNotes/ReleaseNotes-2.6.1.txt b/ReleaseNotes/ReleaseNotes-2.6.1.txt new file mode 100644 index 0000000000..e163b43de7 --- /dev/null +++ b/ReleaseNotes/ReleaseNotes-2.6.1.txt @@ -0,0 +1,16 @@ +Release notes for Gerrit 2.6.1 +============================== + +There are no schema changes from link:ReleaseNotes-2.6.html[2.6]. + +link:https://gerrit-releases.storage.googleapis.com/gerrit-2.6.1.war[https://gerrit-releases.storage.googleapis.com/gerrit-2.6.1.war] + +Bug Fixes +--------- +* Patch JGit security hole ++ +The security hole may permit a modified Git client to gain access +to hidden or deleted branches if the user has read permission on +at least one branch in the repository. Access requires knowing a +SHA-1 to request, which may be discovered out-of-band from an issue +tracker or gitweb instance. diff --git a/ReleaseNotes/ReleaseNotes-2.7.txt b/ReleaseNotes/ReleaseNotes-2.7.txt index 9a290650b0..15875e3271 100644 --- a/ReleaseNotes/ReleaseNotes-2.7.txt +++ b/ReleaseNotes/ReleaseNotes-2.7.txt @@ -4,8 +4,7 @@ Release notes for Gerrit 2.7 Gerrit 2.7 is now available: -link:http://code.google.com/p/gerrit/downloads/detail?name=gerrit-2.7.war[ -http://code.google.com/p/gerrit/downloads/detail?name=gerrit-2.7.war] +link:https://gerrit-releases.storage.googleapis.com/gerrit-2.7-rc2.war[https://gerrit-releases.storage.googleapis.com/gerrit-2.7-rc2.war] Schema Change diff --git a/ReleaseNotes/index.txt b/ReleaseNotes/index.txt index 61657688d4..cc58317090 100644 --- a/ReleaseNotes/index.txt +++ b/ReleaseNotes/index.txt @@ -14,11 +14,13 @@ Version 2.7.x [[2_6]] Version 2.6.x ------------- +* link:ReleaseNotes-2.6.1.html[2.6.1] * link:ReleaseNotes-2.6.html[2.6] [[2_5]] Version 2.5.x ------------- +* link:ReleaseNotes-2.5.5.html[2.5.5] * link:ReleaseNotes-2.5.4.html[2.5.4] * link:ReleaseNotes-2.5.3.html[2.5.3] * link:ReleaseNotes-2.5.2.html[2.5.2] @@ -28,6 +30,7 @@ Version 2.5.x [[2_4]] Version 2.4.x ------------- +* link:ReleaseNotes-2.4.3.html[2.4.3] * link:ReleaseNotes-2.4.2.html[2.4.2] * link:ReleaseNotes-2.4.1.html[2.4.1] * link:ReleaseNotes-2.4.html[2.4] @@ -50,6 +53,7 @@ Version 2.2.x [[2_1]] Version 2.1.x ------------- +* link:ReleaseNotes-2.1.9.html[2.1.9] * link:ReleaseNotes-2.1.8.html[2.1.8] * link:ReleaseNotes-2.1.7.2.html[2.1.7.2] * link:ReleaseNotes-2.1.7.html[2.1.7]