blob: 8fa73cfce7fa2d56f49b4fe76854dc298bd42d86 [file] [log] [blame]
Git v2.12.5 Release Notes
Fixes since v2.12.4
* "git cvsserver" no longer is invoked by "git daemon" by default,
as it is old and largely unmaintained.
* Various Perl scripts did not use safe_pipe_capture() instead of
backticks, leaving them susceptible to end-user input. They have
been corrected.
Credits go to joernchen <> for finding the
unsafe constructs in "git cvsserver", and to Jeff King at GitHub for
finding and fixing instances of the same issue in other scripts.