VOOZH about

URL: https://phabricator.wikimedia.org/T205039

⇱ ⚓ T205039 Release MediaWiki 1.27.6/1.30.2/1.31.2/1.32.2


Maniphest T205039

Release MediaWiki 1.27.6/1.30.2/1.31.2/1.32.2
Closed, ResolvedPublic

Description

Previous release work: T199021

Tracking for activities actually pertaining to making the release of MediaWiki 1.27.6/1.30.2/1.31.2/1.32.1

Related Objects

StatusSubtypeAssignedTask
ResolveddancyT302086 Set scap minimum python version to 3.7
ResolvedNoneT247045 Migrate all of production metal and VMs to Buster or later
ResolvedakosiarisT249724 Track and remove jessie based container images from production
ResolvedJdforrester-WMFT224908 Drop jessie testing support
ResolvedJdforrester-WMFT224907 Drop php55 testing support
ResolvedReedyT205039 Release MediaWiki 1.27.6/1.30.2/1.31.2/1.32.2
ResolvedReedyT205041 Tracking bug for 1.27.6/1.30.2/1.31.2/1.32.2 security release
ResolvedBawolffT197279 Direct POST to Special:ChangeEmail will bypass reauth check
ResolvedAnomieT204729 Potential enwiki DOS due to slow WatchedItemStore::countVisitingWatchersMultiple
ResolvedBawolffT207603 CVE-2019-12471: Loading JS from user space where the username is not a registered account is dangerous and should be banned
ResolvedBawolffT208881 CSS using var() to create exponential sized calc() on wiki page will crash visitor's browser
ResolvedLegoktmT199540 Forbid blocking IP ranges as big as /1 and /2, as done on ruwikiquote using the API
Resolved Lucas_Werkmeister_WMDET212118 API responses for unpatrolled or (not) autopatrolled recent changes require privileges but may be cached publicly
ResolvedBawolffT209794 Need to make a limit of count of attempts to change email address
ResolvedsbassettT222036 Exposed suppressed username or log in Special:EditTags
ResolvedsbassettT222038 Exposed suppressed log in RevisionDelete page
ResolvedJdforrester-WMFT221739 Patch jQuery due to CVE-2019-11358
ResolvedsbassettT25227 Use token when logging out
ResolvedsbassettT221868 Send out wikitech-l post for T25227 ("Use token when logging out")
ResolvedReedyT205042 Write and send release announcements for 1.27.6/1.30.2/1.31.2/1.32.2 security releases
ResolvedReedyT205043 Write and send pre-release Announcements for MediaWiki 1.27.6/1.30.2/1.31.2/1.32.2
ResolvedJdforrester-WMFT205044 Update onwiki release notes for 1.27.6/1.30.2/1.31.2/1.32.2
ResolvedReedyT205046 Update HISTORY in master after 1.27.6/1.30.2/1.31.2/1.32.2
ResolvedReedyT205047 Tag MW 1.27.6/1.30.2/1.31.2/1.32.2
ResolvedReedyT224499 RELEASE-NOTES for 1.27.6/1.30.2/1.31.2/1.32.2
ResolvedJdforrester-WMFT224912 Update MediaWiki.org links and versions
ResolvedJdforrester-WMFT224913 EOL REL1_27 and REL1_30 onwiki
ResolvedReedyT225201 Formally announce EOL of MW 1.27 and 1.30
ResolvedReedyT225149 Update CVEs and publish them
ResolvedReedyT205048 Obtain CVEs for 1.27.6/1.30.2/1.31.2/1.32.2 security releases

Event Timeline

Reedy renamed this task from Release MediaWiki 1.27.6/1.30.2/1.31.2 to Release MediaWiki 1.27.6/1.30.2/1.31.2/1.32.1.Feb 13 2019, 2:23 AM
Reedy updated the task description. (Show Details)
Comment Actions

! In T213595#4972704, @greg wrote:

! In T213595#4949955, @Legoktm wrote:
Can we bundle the planned security release with this?

Did that ^ happen?

I'm not aware of any security patches that landed in 1.32.1 but I haven't announced the release yet if we want to rebuild the tarballs it's fine with me.

Comment Actions

What does anyone want to do? It's going to take probably a week or two to get things finished off with other stuff going on...

Do we want to wait with 1.32.1? Or get that out of the door, and do a 1.32.2 a few weeks later?

I know that doesn't look particularly great; though it would be worse as two security releases in a short period

Comment Actions

Well, I already built the 1.32.1 tarballs but I haven't announced the release officially nor have I pushed the tags to git. I don't have a strong opinion either way.

Comment Actions

Let's do separate releases. We want to do these more frequently anyway, right?

Reedy renamed this task from Release MediaWiki 1.27.6/1.30.2/1.31.2/1.32.1 to Release MediaWiki 1.27.6/1.30.2/1.31.2/1.32.2.Apr 30 2019, 6:28 PM
Reedy changed the visibility from "Custom Policy" to "Public (No Login Required)".Jun 6 2019, 3:58 PM
Content licensed under Creative Commons Attribution-ShareAlike (CC BY-SA) 4.0 unless otherwise noted; code licensed under GNU General Public License (GPL) 2.0 or later and other open source licenses. By using this site, you agree to the Terms of Use, Privacy Policy, and Code of Conduct. · Wikimedia Foundation · Privacy Policy · Code of Conduct · Terms of Use · Disclaimer · CC-BY-SA · GPL · Credits