Skip to content

Mark SECURITY-3590 as also fixed in Git Client Plugin 6.2.1 and 6.1.4#887

Merged
Kevin-CB merged 2 commits intojenkins-infra:masterfrom
MarkEWaite:git-client-6.2.1-fixes-security-3590-also
Sep 5, 2025
Merged

Mark SECURITY-3590 as also fixed in Git Client Plugin 6.2.1 and 6.1.4#887
Kevin-CB merged 2 commits intojenkins-infra:masterfrom
MarkEWaite:git-client-6.2.1-fixes-security-3590-also

Conversation

@MarkEWaite
Copy link
Contributor

@MarkEWaite MarkEWaite commented Sep 4, 2025

Mark SECURITY-3590 as also fixed in Git Client Plugin 6.2.1 and 6.1.4

SECURITY-3590 is fixed by backporting the changes from Git Client Plugin 6.3.3

Backport from commit 20090a86c3ebc72e5283c882de73e3a4459137bb

Git Client Plugin 6.2.1 and 6.1.4 also include fixes to support command line git 2.51.0. Those changes were originally from pull requests:

Fixed in 6.2.1 by pull request:

Fixed in 6.1.4 by pull request

Testing done

I've run interactive tests with the Git Client Plugin 6.2.1 incremental build and with the Git Client Plugin 6.1.4 development build and found no issues.

https://www.jenkins.io/security/advisory/2025-09-03/#SECURITY-3590 is
fixed by backporting the changes from Git Client Plugin 6.3.3

Backport from commit 20090a86c3ebc72e5283c882de73e3a4459137bb

Git Client Plugin 6.2.1 also includes fixes to support command line
git 2.51.0.  Those changes were originally from pull requests:

* jenkinsci/git-client-plugin#1326
* jenkinsci/git-client-plugin#1327

Fixed by pull request:

* jenkinsci/git-client-plugin#1332

Testing done:

I've run interactive tests with Git Client Plugin 6.2.1 incremental
build and found no issues.
@MarkEWaite MarkEWaite added the metadata This PR changes metadata (suspensions, labels, etc.) label Sep 4, 2025
@MarkEWaite MarkEWaite requested a review from a team as a code owner September 4, 2025 10:36
@MarkEWaite MarkEWaite added the metadata This PR changes metadata (suspensions, labels, etc.) label Sep 4, 2025
@MarkEWaite MarkEWaite marked this pull request as draft September 4, 2025 10:43
@MarkEWaite
Copy link
Contributor Author

I've made a mistake. The change for plugin BOM line 2.492.x needs to be on Git Client Plugin 6.1.x, not 6.2.x. I've placed this pull request into draft mode while I make that correction.

https://www.jenkins.io/security/advisory/2025-09-03/#SECURITY-3590 is
fixed by backporting the changes from Git Client Plugin 6.3.3

Backport from commit 20090a86c3ebc72e5283c882de73e3a4459137bb

Git Client Plugin 6.1.4 also includes fixes to support command line
git 2.51.0.  Those changes were originally from pull requests:

* jenkinsci/git-client-plugin#1326
* jenkinsci/git-client-plugin#1327

Fixed by pull request:

* jenkinsci/git-client-plugin#1333

Testing done:

I've run interactive tests with a Git Client Plugin 6.1.4 development
build and found no issues.  Details are described in pull request:

* jenkinsci/git-client-plugin#1333
@MarkEWaite MarkEWaite marked this pull request as ready for review September 4, 2025 13:45
@MarkEWaite
Copy link
Contributor Author

Mistake is corrected and this pull request has been updated to note that 6.1.4 includes the fix for SECURITY-3590 as well.

@MarkEWaite MarkEWaite changed the title Mark SECURITY-3590 as also fixed in Git Client Plugin 6.2.1 Mark SECURITY-3590 as also fixed in Git Client Plugin 6.2.1 and 6.1.4 Sep 4, 2025
Copy link
Contributor

@Kevin-CB Kevin-CB left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I reviewed the regex, it looks correct

@Kevin-CB Kevin-CB merged commit 82543ab into jenkins-infra:master Sep 5, 2025
2 checks passed
@MarkEWaite MarkEWaite deleted the git-client-6.2.1-fixes-security-3590-also branch January 2, 2026 13:24
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

metadata This PR changes metadata (suspensions, labels, etc.)

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants