)]}'
{
  "commit": "5532ebdeb7ac56d952addb94ea9741d3c8f5b6f6",
  "tree": "ecabfba07ded9ef567af1545e686b71f30cfbee0",
  "parents": [
    "76a681ce9c20e2827ebc02ca8c29fa6a3e946190",
    "379e51d1ae668a1f26d50eb59b3f8befc1eb8883"
  ],
  "author": {
    "name": "Johannes Schindelin",
    "email": "johannes.schindelin@gmx.de",
    "time": "Mon Sep 16 13:26:40 2019 +0200"
  },
  "committer": {
    "name": "Johannes Schindelin",
    "email": "johannes.schindelin@gmx.de",
    "time": "Thu Dec 05 15:37:08 2019 +0100"
  },
  "message": "Merge branch \u0027fix-mingw-quoting-bug\u0027\n\nThis patch fixes a vulnerability in the Windows-specific code where a\nsubmodule names ending in a backslash were quoted incorrectly, and that\nbug could be abused to insert command-line parameters e.g. to `ssh` in a\nrecursive clone.\n\nNote: this bug is Windows-only, as we have to construct a command line\nfor the process-to-spawn, unlike Linux/macOS, where `execv()` accepts an\nalready-split command line.\n\nWhile at it, other quoting issues are fixed as well.\n\nSigned-off-by: Johannes Schindelin \u003cjohannes.schindelin@gmx.de\u003e\n",
  "tree_diff": []
}
