Re: [Wikitech-l] MediaWiki security release: 1.19.2 and 1.18.5

2012-08-31 Thread Siebrand Mazeland (WMF)
Thanks, Chris. What's the reason for releasing before adding code to git? Correct me if I'm wrong, but were the point releases and the announcements also made before the fixes for the vulnerabilities hit master? If so, are you sure that's a good idea? On Fri, Aug 31, 2012 at 7:07 PM, Chris Steip

Re: [Wikitech-l] MediaWiki security release: 1.19.2 and 1.18.5

2012-08-31 Thread Chris Steipp
REL1_19 is merged and tagged now. Apologies for the delay. I'm still working on getting REL1_18 finished. On Fri, Aug 31, 2012 at 3:59 AM, Niklas Laxström wrote: > On 31 August 2012 07:55, Chris Steipp wrote: >> I would like to announce the release of MediaWiki 1.19.2 and 1.18.5. >> These relea

Re: [Wikitech-l] MediaWiki security release: 1.19.2 and 1.18.5

2012-08-31 Thread Niklas Laxström
On 31 August 2012 07:55, Chris Steipp wrote: > I would like to announce the release of MediaWiki 1.19.2 and 1.18.5. > These releases fix 6 security related bugs that could affect users of > MediaWiki. Download links are given at the end of this email. I don't see updates in git REL1_19 branch nor

[Wikitech-l] MediaWiki security release: 1.19.2 and 1.18.5

2012-08-30 Thread Chris Steipp
I would like to announce the release of MediaWiki 1.19.2 and 1.18.5. These releases fix 6 security related bugs that could affect users of MediaWiki. Download links are given at the end of this email. * Wikipedia administrator Writ Keeper discovered a stored XSS (HTML injection) vulnerability. Thi