[ANNOUNCE] Gerrit 3.1.6 w/ accounts security fix on HTTP

41 views
Skip to first unread message

Luca Milanesio

unread,
Jun 8, 2020, 9:30:51 AM6/8/20
to Repo and Gerrit Discussion, Luca Milanesio
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Gerrit version 3.1.6 is now available.
This release includes security fixes for the Issue 12717 (Deny access over HTTP for disabled accounts).
If you are using websession-flatfile, websession-broker or high-availability plugins with Gerrit, you must upgrade them too to the latest version of the stable-3.1 branch.

Please see the release notes for details.

Release Notes:
https://www.gerritcodereview.com/3.1.html#316

Documentation:
http://gerrit-documentation.storage.googleapis.com/Documentation/3.1.6/index.html

Log of changes since 3.1.6:
https://gerrit.googlesource.com/gerrit/+log/v3.1.5..v3.1.6?no-merges

Download:
https://gerrit-releases.storage.googleapis.com/gerrit-3.1.6.war

SHA1:
e33198bed1ba477d0b4de349eae77305dbc264f0

SHA256:
fda12c06369e585b5aedce62838e371abc4382c3b340ad4bb3d2512b4b49479e

MD5:
6da81a6bfe7d7680b5775037c9a81a83

Maintainers' public keys:
https://www.gerritcodereview.com/releases/public-keys.md
-----BEGIN PGP SIGNATURE-----

iQGzBAEBCgAdFiEETYfnMJcTx9Zrd8+/cHkSkHVi6ksFAl7ePUwACgkQcHkSkHVi
6kuMGgwAmea0QLCrgAHSY5xwiBiVRjCLo2f+IFOb6c2m3agWwo+tcLYY7RrKPk+W
fayMvSpXUKgt69IJSLzHKE2yZ7nHCTEVogdjwCwROCNKr+deh0nOBYCtHtuJR8u/
IpX8t7W4u1IluUcVFfo/vYfCc/JhSvJMBwPZzr9KIIT/Yb8cjZ4qcijVUSBR6tz5
RSD1aoAshH4jNSwwGvmCgUUQj8ymLbknS5visVkyFafKzx7USfFpk6yepmv01hRN
K0VZbl3N3j01y5DMp7bp8Sk17P45pUNqzh52UEWF/7b3cnlPNUIW6lNfzXITZ3eq
YizS0ERW5PRaCdZWWFC8LnLEq40thzicRvYm+AkjtZlBMRjSEunz7d6qYz0YR3zs
fcpdo6Szhmn6B9wMd857+cAkH2K9pXLzulljh/JZSb5KDB46t4nFZ5zpf8hFxVxT
dkVD6aLJkER5Uljx8OaEqLjLCdfBhkKRYZk/wBgc+O12pzyNwN3Ocm6icwtR6D7I
dsW9L1dn
=cI3u
-----END PGP SIGNATURE-----

Luca Milanesio

unread,
Jun 9, 2020, 5:57:08 PM6/9/20
to Repo and Gerrit Discussion, Luca Milanesio
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Binary packages (Deb / Rpm) of Gerrit version 3.1.6 are now available
=====================================================================

How to install/upgrade: 3.1.6
*****************************

If you have a previous version of Gerrit 2.1x installed via native packages:

(on Debian / Ubuntu)
apt-get update & apt-get install gerrit=3.1.6-1

(on CentOS / RedHat)
yum clean all && yum install gerrit-3.1.6-1

(on Fedora)
dnf clean all && dnf install gerrit-3.1.6-1

If it is a new installation and you don't have the GerritForge/BinTray repositories
configured, please follow the instructions at:
http://gitenterprise.me/2015/02/27/gerrit-2-10-rpm-and-debian-packages-available/

Docker images
*************

Gerrit is distributed on DockerHub at:
https://hub.docker.com/r/gerritcodereview/gerrit/

The following tags have been published
3.1.6 => 3.1.6-centos7
3.1.6-centos7
3.1.6-ubuntu18

More information on how to use Gerrit Docker image for testing, staging, and production at:
https://gerrit.googlesource.com/docker-gerrit

MacOS native package
********************

MacOS Gerrit native installer is available for download at:

https://gerritforge.com/gerrit/mac/gerrit-installer-3.1.6.pkg

SHA1:
438694932471acae7420d101363fae3d64895190

SHA256:
910c573af27618426bff978519290e83badca31f70ad0d8dfa15b8751dfab5cf

-----BEGIN PGP SIGNATURE-----

iQGzBAEBCgAdFiEETYfnMJcTx9Zrd8+/cHkSkHVi6ksFAl7gBYsACgkQcHkSkHVi
6kvfsQv9EIhwunxEQ0SUiYL3zNDQSviRrI16nOdE6tu4WxuKOQlaef9tmqa4ozJj
zkgPcLGD9yCFaI7QAjA1yVvWoIM9okHDF++9Uc9yYXmMZzycCqZcVCaF9ODXPdyt
pN77pYT8tDJNDmpQyuMYlG9poqRU0TSk/clgyGQjtQGXGLiyRwgEIBM1mvBC1UpZ
ldL5BDZU6f5rHL52LOcaPpDJRo7USryqFeEo+2k16cmy0Hz798ErmQw9A96Gt+q7
xP9vR+hFtIcWMsuOkefq71F4EZ5CigOpBUlM73o1OG4I85BkMYjjmJo5cSTj1zGG
pHy89LCuGTaSwvX53yHq7EsDDOtDinRLd2f2gGYbTlhr7d/jcJEgpadzBWbrVj03
MlgXj3KONWHfk0WMx5A2OMsq5K14rXEjbPmeH3sK8+sgL8h/U4Ofrb6ibgg89jOm
Tj3t3ZPIzMjqbkpxg/o6U1WSQaZFd9Nu3gM98bZK7+CGH+Y0PlIGdNlqPzrNuQAT
ilJf7alX
=4QlH
-----END PGP SIGNATURE-----
Reply all
Reply to author
Forward
0 new messages