[ANNOUNCE] Gerrit 2.16.21 w/ accounts security fix on HTTP

39 views
Skip to first unread message

Luca Milanesio

unread,
Jun 8, 2020, 7:53:13 AM6/8/20
to Repo and Gerrit Discussion, Luca Milanesio
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Gerrit version 2.16.21 is now available.
This release includes security fixes for the Issue 12717 (Deny access over HTTP for disabled accounts).
If you are using websession-flatfile or high-availability plugins with Gerrit, you must upgrade them too to the latest version of the stable-2.16 branch.

Please see the release notes for details.

Release Notes:
https://www.gerritcodereview.com/2.16.html#21621

Documentation:
http://gerrit-documentation.storage.googleapis.com/Documentation/2.16.21/index.html

Log of changes since 2.16.21:
https://gerrit.googlesource.com/gerrit/+log/v2.16.20..v2.16.21?no-merges

Download:
https://gerrit-releases.storage.googleapis.com/gerrit-2.16.21.war

SHA1:
d02c2841e122faf8eaba070b0e0d21eaa0d12226

SHA256:
f5072cbb0b7127a13d9c5316cc3151bd1ead337d35ec070eac4916c10391c518

MD5:
b0edeb3a823e72bd3f7135f232d4d781

Maintainers' public keys:
https://www.gerritcodereview.com/releases/public-keys.md
-----BEGIN PGP SIGNATURE-----

iQGzBAEBCgAdFiEETYfnMJcTx9Zrd8+/cHkSkHVi6ksFAl7VKrUACgkQcHkSkHVi
6kuu8gv9GaxYFnzHmpT7Lp3pgT/tYUsW0mDAJ8jTL8nIOP8cITVVGsUdlSXjvNmK
0hdsxieQL6n23yOEdadB95nzu7nZf4GmCouusYTPEPShU7GOJh1AlvPxE4iaWssP
0myZj1pFCo42ESiaTnBtyX8ZpgF+y/1jk1HDySAPdbx9VqNkxKSEyLEf3lh/rkJF
Kw3rFzMOaKr/TaOuR4OqTr6l26AS/GgV9KeTnOncVDH5SXZJMQFDMp5eF+fglt0N
suBs56OU6lTjAitURe7p5Kb2F31cmFYPEI2tB77FH2smCChBHOG+B9OaO+pY2P0m
oYXjOwaSXEt5vycIfjAxZ4GY8PP8Leo5uC8i5DvTHbkAXrHQ6sJGyQQT5oT8zSY0
XO/DnHIPg1fU4yCNz4ykpkTDPqnW+YuuW4w22XwONsqpf66xfdjfk0bQ4obwXBdl
i9JZBTrrUjyWHlbEYC5w0TSGpHJtt19b88d6r5wZaHKqHn//Ma0orlSQbdX/pDSK
KNaM6Wx7
=oMmU
-----END PGP SIGNATURE-----

Luca Milanesio

unread,
Jun 9, 2020, 5:46:44 PM6/9/20
to Repo and Gerrit Discussion, Luca Milanesio
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Binary packages (Deb / Rpm) of Gerrit version 2.16.21 are now available
=======================================================================

How to install/upgrade: 2.16.21
*******************************

If you have a previous version of Gerrit 2.1x installed via native packages:

(on Debian / Ubuntu)
apt-get update & apt-get install gerrit=2.16.21-1

(on CentOS / RedHat)
yum clean all && yum install gerrit-2.16.21-1

(on Fedora)
dnf clean all && dnf install gerrit-2.16.21-1

If it is a new installation and you don't have the GerritForge/BinTray repositories
configured, please follow the instructions at:
http://gitenterprise.me/2015/02/27/gerrit-2-10-rpm-and-debian-packages-available/

Docker images
*************

Gerrit is distributed on DockerHub at:
https://hub.docker.com/r/gerritcodereview/gerrit/

The following tags have been published
2.16.21 => 2.16.21-centos7
2.16.21-centos7
2.16.21-ubuntu16

More information on how to use Gerrit Docker image for testing, staging, and production at:
https://gerrit.googlesource.com/docker-gerrit

MacOS native package
********************

MacOS Gerrit native installer is available for download at:

https://gerritforge.com/gerrit/mac/gerrit-installer-2.16.21.pkg

SHA1:
f39ea9c41e98c54950df2cb5f2b81418fcd4f3c3

SHA256:
3431805951cfc33d305e1f2c6a82eafe12477f9255309ba8e024683f8896f954
-----BEGIN PGP SIGNATURE-----

iQGzBAEBCgAdFiEETYfnMJcTx9Zrd8+/cHkSkHVi6ksFAl7gAvoACgkQcHkSkHVi
6kvEwwv/dUJdkN3P5fkUIG+eiiDxktQA6/Bkggdyg6DvhqbWy+JVVxkd6Ev8s6et
uUVjWahAazt7aP/14GyIrsCb1Ct80eCLimrnD+w3gJxQ+W91f0C8asqPmHSnOYpL
ymHlZbu8ZqLesP14tXSvH9uFaQSjMSbqMS4Qymp4IrNQpksDCo2/LCXk14OATd1f
/zGg75bcFnKH+euU9Wn21b0v7T5Q9n4YQZGMiwMSXqo7MKFgZvrianWu8yPzLoWw
h3A5j/kKSGaMDF5GOmg5KT1+cl7/gPkovy3+Kj8S3NllCl1/cjzCl6CvT7UXUzJl
Cpcf64YvcybNh2MMR5nTTCsfuHuOoru4hd9N75+CmMlIL9qV97Ry0KuGei8aoGr5
O/9IxTJ9dGC4CFXoj8pOxX4OJIZC0M28XF7dLlOOg44k4izSuyK/rToNsdC58mC8
22AbYgZi8e2DWBF9KmmZPo4fzzVWiIgIuYXhTS+jR3V5GklmfE66cllI8NOnMAns
OFg5iqsQ
=N03p
-----END PGP SIGNATURE-----
Reply all
Reply to author
Forward
0 new messages