[ANNOUNCE] Gerrit 3.10.1 w/ Security Fixes

169 views
Skip to first unread message

Luca Milanesio

unread,
Aug 8, 2024, 11:35:29 PM8/8/24
to Repo and Gerrit Discussion, Luca Milanesio
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Gerrit version 3.10.1 is now available.

Includes security fixes;
please see the release notes for details.

Release Notes:
https://www.gerritcodereview.com/3.10.html#3101

Documentation:
http://gerrit-documentation.storage.googleapis.com/Documentation/3.10.1/index.html

Log of changes since 3.10.1:
https://gerrit.googlesource.com/gerrit/+log/v3.10.0..v3.10.1?no-merges

Download:
https://gerrit-releases.storage.googleapis.com/gerrit-3.10.1.war

SHA1:
3269d5112475eee9e0664f76d394329dac74f482

SHA256:
81638d8e99ff62b487b5a6da708fbb028f6919ea9c89a95169a71ad9cb79a033

MD5:
e1a89d160f268f9914044862c6c50c50

Maintainers' public keys:
https://www.gerritcodereview.com/releases/public-keys.md

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEmCU49QQ43XtIE8giC0731aK2mH4FAma1jhsACgkQC0731aK2
mH6JuRAAieCmWqzihIExC/c0e6B/f311TbkWqlK6vhqRwGnbNiNDWqL+KLvQjpua
4kfMxzVL3kMA6XjGY1SANAHx4s5lW/qa8mgTYfocs+p+qxbzHCvQF7TZhPUDDRfw
Y6RSFefZHgpVrBKRsLjZhqCg7lAA2zH6xgBSF3XA2F//8sa36ok1oeLDQ0Siy+/4
RUm+VyFPYsJLZnHkyTLkjGwVDiajKcYVDr9u9+MgovSkDZHG+2GR0QpXztOWOHKg
YSCJMZFGUL9GHxkjz1mGhEHC+NnZ4bsXKWR912naNXzOtBKFtQRX9xiIFXz/rbhn
GtZQyLbmV02/RJfoy6x6HGccjTAyPZoWbOSoO+WavUMd7o1AdHDikZzdONhXvtnZ
cUtslc/47lJzgKDChO8rw//GggTqvGxCkCoRUjBwMJSLSW6zrEvDs0xucgJ37YNL
3Y9Ahed70aVATLJHW2+A2/vAeZA85CWq6BIWKYzDBXbx2+qtJ4nbxDQxlH9bn2HV
YnjOQxlkMCHjKiD+7hoMf7QgO/DHK7wZq6Vj/noZP017jKTB2vTdgNGFYMv7Of8H
xmgPyvr5X4/GPm4UqYoxc9bGcnrcNXwqW8CxRA52hvj31yC/XvEx6xMRGYN7Md39
9a7CFh9Ez8G4TZ9E9dHjdgewI+B9YG79it7ApUPXlid3ip3ukEc=
=p6Pe
-----END PGP SIGNATURE-----

Luca Milanesio

unread,
Aug 8, 2024, 11:53:52 PM8/8/24
to Repo and Gerrit Discussion, Luca Milanesio
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Binary packages (Deb / Rpm) of Gerrit version 3.10.1 have been released
=========================================================================

How to install/upgrade: 3.10.1
*****************************

If you have a previous version of Gerrit 3.x installed via native packages:

(on Debian / Ubuntu)
apt-get update && apt-get install gerrit=3.10.1-1

(on AlmaLinux / RedHat)
yum clean all && yum install gerrit-3.10.1-1

(on Fedora)
dnf clean all && dnf install gerrit-3.10.1-1

If it is a new installation and you don't have the GerritForge repositories
configured, or if you are upgrading to ARM-64, please follow the instructions at:
https://gitenterprise.me/2022/11/23/arm-64-welcomes-gerrit-code-review/

Docker images
*************

Gerrit is distributed on DockerHub at:
https://hub.docker.com/r/gerritcodereview/gerrit/

The following tags have been published for amd64 and arm64:
latest => 3.10.1
3.10.1 => 3.10.1-almalinux9
3.10.1-almalinux9
3.10.1-ubuntu22

More information on how to use Gerrit Docker image for testing, staging, and production at:
https://gerrit.googlesource.com/docker-gerrit

MacOS native package
********************

MacOS Gerrit native installer is available for download at:

https://gerritforge.com/gerrit/mac/gerrit-installer-3.10.1.pkg

SHA1:
55a3ff1fede10efce29c771cdc1d10113d1a1ae8

SHA256:
54cfaf252ac5b922cbfc5c06cd12971af8720c84a06d93e773be26080526d67d

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCAAdFiEEmCU49QQ43XtIE8giC0731aK2mH4FAma1kpIACgkQC0731aK2
mH6fLQ/9EQYg+3nVedgQqddGdXOhK9c64YtnsKuwOzkHymi6rL8OzGip53HkARUU
an1hWnKXVMc0aQFBSqapvUNOCYCA7vsBWpJXMaohDelunsgGsXDYTvFDHclsA5o6
+K5p30GoTlJq4HkZoUi8XUV92Ka/ozM68/HKXb/uekkcOd+Uj6LPhtqBvtZ5iwCH
RHYJ2Eu6cMvznHfKpMrIK1XKpSZbIiusjT7Vm6Pt6lT0aZsl5I5M70Go+yH6HTlJ
d74xd3teast5TtFtOvJzQCa2SqpXOeiBgKiTYG4bPElsCji6JvVJS0vi/GkSaXCE
t7RvKSmW/4spvR1eBnBdmFCen/mvBERzzjXlZK1yY8CV0DnPvsbcysbN8CFbTkr3
bQE3GR30bG3Cm0dlmJg+xyq3sG6gNUWwsy01dgk4GmXaUN95t7Og8utUXEhAbEaZ
nqevp3H2H7PuvHaaP9dSc9mToR/rCF3OKG97wsLswZq0gqn003eF66X6ivuIvqfn
eVuoTS3B0tWjbHQy5k5ZeZyVz4O7SNm3wk6XQBGriyhirc7gfxWK3IVkqyeombFP
/IvSNXFKtIIJE4oldd5ICU3XI9nhMbT3bPoOl1QWQHcGMSVIMkU84GqMOdo7fTxX
iv5N5AkACKcAONlcDLIN3libQM/EYhQMYrMvanHbcx3dZ8b2kYU=
=mCn9
-----END PGP SIGNATURE-----

lucamilanesio

unread,
Sep 10, 2024, 5:17:48 PM9/10/24
to Repo and Gerrit Discussion
On Friday, August 9, 2024 at 4:53:52 AM UTC+1 Luca Milanesio wrote:
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Binary packages (Deb / Rpm) of Gerrit version 3.10.1 have been released
=========================================================================

I made a tagging mistake on the docker-gerrit project and as a result, the Docker images gerritcodereview/gerrit*:3.10.1 ended up including the v3.10.0, as reported in [1].

The problem has been now resolved:
- The incorrect tag has been removed and regenerated
- I have republished the images on Dockerhub

Apologies for the confusion.

Luca.

Reply all
Reply to author
Forward
0 new messages