VOOZH about

URL: https://phabricator.wikimedia.org/T199021

⇱ ⚓ T199021 Release MediaWiki 1.27.5/1.29.3/1.30.1/1.31.1


Maniphest T199021

Release MediaWiki 1.27.5/1.29.3/1.30.1/1.31.1
Closed, ResolvedPublic

Description

Previous release work: T180272

Tracking for activities actually pertaining to making the release of MediaWiki 1.27.5/1.29.3/1.30.1/1.31.1

Related Objects

StatusSubtypeAssignedTask
ResolvedReedyT199021 Release MediaWiki 1.27.5/1.29.3/1.30.1/1.31.1
ResolvedReedyT181665 Tracking bug for 1.27.5/1.29.3/1.30.1/1.31.1 security release
ResolvedmatmarexT169545 $wgRateLimits (rate limit / ping limiter) entry for 'user' overrides that for 'newbie' (CVE-2018-0503)
ResolvedSamwilsonT187638 When a log event is (partially) hidden Special:Redirect/logid can link to the incorrect log and reveal hidden information (CVE-2018-0504)
ResolvedBawolffT194605 BotPassword can bypass CentralAuth's account lock (CVE-2018-0505)
ResolvedAnomieT194237 bot passwords should call checkLoginSecurityLevel
ResolvedLegoktmT199029 1.31.0 tarball is missing .htaccess files (CVE-2018-13258)
ResolvedReedyT199022 Write release announcements for 1.27.5/1.29.3/1.30.1/1.31.1 security releases
ResolvedReedyT199023 Write and send pre-release Announcements for MediaWiki 1.27.5/1.29.3/1.30.1/1.31.1
ResolvedReedyT199024 Update onwiki release notes for 1.27.5/1.29.3/1.30.1/1.31.1
ResolvedReedyT199025 Update HISTORY in master after 1.27.5/1.29.3/1.30.1/1.31.1
ResolvedReedyT199026 Tag MW 1.27.5/1.29.3/1.30.1/1.31.1
ResolvedMoritzMuehlenhoffT199027 Obtain CVEs for 1.27.5/1.29.3/1.30.1/1.31.1 security releases

Event Timeline

Comment Actions

Should probably decide if we're going to try and use the ideas in T196602: Streamline MW security release process

Legoktm subscribed.
Comment Actions

Status update:

  • T169545 - deployed, backports in phab by Reedy
  • T167937 - CR -1, needs a new patch.
  • T187638 - patches merged to all branches in Gerrit
  • T194605 - deployed, needs backports
  • T194237 - patches merged to all branches in Gerrit
  • T196386 - patch deployed/merged in Gerrit only for CentralAuth, still needs a patch for AntiSpoof itself. (extension isn't bundled though)
Comment Actions

Ok, let's get this done next week as @Legoktm has pretty much finished the prep work off

Reedy changed the visibility from "Custom Policy" to "Public (No Login Required)".Sep 20 2018, 9:35 PM
Content licensed under Creative Commons Attribution-ShareAlike (CC BY-SA) 4.0 unless otherwise noted; code licensed under GNU General Public License (GPL) 2.0 or later and other open source licenses. By using this site, you agree to the Terms of Use, Privacy Policy, and Code of Conduct. · Wikimedia Foundation · Privacy Policy · Code of Conduct · Terms of Use · Disclaimer · CC-BY-SA · GPL · Credits