1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
|
gitolite3 (3.6.12-1) unstable; urgency=medium
* New upstream version.
-- David Bremner <bremner@debian.org> Fri, 25 Dec 2020 19:15:23 -0400
gitolite3 (3.6.11-2) unstable; urgency=medium
* Point Vcs-* to salsa
-- David Bremner <bremner@debian.org> Fri, 25 Jan 2019 08:32:05 -0400
gitolite3 (3.6.11-1) unstable; urgency=medium
* Bug fix: "CVE-2018-20683: security issue in optional bundle helper
('rsync' command)", thanks to Salvatore Bonaccorso
(Closes: #918849).
* Convert to source format 3.0 (quilt).
* Bump debhelper compat to 9
-- David Bremner <bremner@debian.org> Fri, 25 Jan 2019 08:15:17 -0400
gitolite3 (3.6.9-1) unstable; urgency=high
* New upstream version
* Bug fix: "CVE-2018-16976: prevent access to repos which are in the
process of being migrated", thanks to Salvatore Bonaccorso (Closes:
#908699).
-- David Bremner <bremner@debian.org> Sat, 15 Sep 2018 12:37:48 -0300
gitolite3 (3.6.7-2) unstable; urgency=medium
* Bug fix: "[INTL:pt_BR] Brazilian Portuguese debconf templates
translation", thanks to Adriano Rafael Gomes (Closes: #811528).
-- David Bremner <bremner@debian.org> Wed, 05 Jul 2017 22:12:35 -0300
gitolite3 (3.6.7-1) unstable; urgency=medium
* New upstream release
* update debian/README.Debian, drop bitrotted v2 upgrade
instructions. Mention name of default user (gitolite3).
* drop postint fix for pre 3.5.1 permissions
-- David Bremner <bremner@debian.org> Mon, 03 Jul 2017 21:09:50 -0300
gitolite3 (3.6.6-1) unstable; urgency=medium
* New upstream release
* Bug fix: "uninstallable without . in @INC", explicitely look for
'./foo'. (Closes: #837036).
-- David Bremner <bremner@debian.org> Tue, 13 Sep 2016 20:31:39 -0300
gitolite3 (3.6.4-2) unstable; urgency=medium
* depend on openssh-client (Closes: #834153).
-- David Bremner <bremner@debian.org> Sun, 14 Aug 2016 14:09:11 +0900
gitolite3 (3.6.4-1) unstable; urgency=medium
* New upstream release
* Fix bug in 3.6.3 that allows authorized users to create refs they
should not be able to, in certain special configurations of wild
repos. See commit be5c2f5752 for more info.
-- David Bremner <bremner@debian.org> Fri, 04 Dec 2015 21:12:01 -0400
gitolite3 (3.6.3-3) experimental; urgency=medium
* Bug fix: "inconsistently set execute bits on the gitolite script
files", thanks to Christoph Anton Mitterer (Closes: #779252).
* Assert compliance with Debian policy 3.9.6
* Add dependence 'openssh-server |' so there's a real package
instead of just a virtual one.
-- David Bremner <bremner@debian.org> Sun, 28 Jun 2015 10:57:55 +0200
gitolite3 (3.6.3-2) experimental; urgency=medium
* Move main config file to /etc
* Remove (broken) support for reconfiguration / multiple users.
-- David Bremner <bremner@debian.org> Sat, 27 Jun 2015 09:44:25 +0200
gitolite3 (3.6.3-1) unstable; urgency=medium
* New upstream release (Closes: #773811).
* Bug fix: "should Depends: libjson-perl", thanks to Heiko Noordhof
(Closes: #780671).
* Bug fix: "please add git-daemon-sysvinit as an alternative Suggests",
thanks to Christoph Anton Mitterer (Closes: #779263).
* Bug fix: "gitolite creates /var/lib/gitolite3/.ssh/authorized_keys
with u+x mode", thanks to Christoph Anton Mitterer (Closes: #778725).
-- David Bremner <bremner@debian.org> Tue, 23 Jun 2015 20:24:57 +0200
gitolite3 (3.6.1-3) unstable; urgency=medium
* Bug fix: "please make the build reproducible", thanks to Chris Lamb
(Closes: #777060).
-- David Bremner <bremner@debian.org> Wed, 04 Feb 2015 18:26:53 +0100
gitolite3 (3.6.1-2) unstable; urgency=low
[ Rhonda D'Vine ]
* The "l10n R us" release:
- Updated German translation by myself
- Updated Japanese by victory (closes: #719509)
- Updated French by Christian Perrier (closes: #719777)
- Updated Russian by Yuri Kozlov (closes: #722125)
- Updated Portuguese by Américo Monteiro (closes: #729824)
- Updated Danish by Joe Hansen (closes: #739792)
- New Turkish translation by Mert Dirik (closes: #759876)
- Updated Dutch by Frans Spiesschaert (closes: #764599)
- Updated Czech by Michal Simunek (closes: #768271)
- Updated Swedish by Martin Bagge (closes: #768455)
- Updated Italian by Beatrice Torracca (closes: #769447)
-- David Bremner <bremner@debian.org> Fri, 14 Nov 2014 21:04:22 +0100
gitolite3 (3.6.1-1) unstable; urgency=low
* New upstream release (Closes: #755784)
-- David Bremner <bremner@debian.org> Mon, 06 Oct 2014 12:30:00 +0200
gitolite3 (3.6-1) unstable; urgency=low
* New upstream release
* Depend on ssh-server instead of openssh-server (Closes: #735176).
-- David Bremner <bremner@debian.org> Sun, 25 May 2014 20:09:36 -0300
gitolite3 (3.5.3.1-2) unstable; urgency=medium
* Bug fix: "broken directory check", thanks to Daniel Baumann,
Martin Haaß (Closes: #737823, #734979).
-- David Bremner <bremner@debian.org> Wed, 26 Mar 2014 11:18:42 -0300
gitolite3 (3.5.3.1-1) unstable; urgency=medium
* New upstream release
* This release removes world+group read permissions from
~gitolite3/repositories, and world+group read+execute permissions from
~gitolite3/repositories/{gitolite-admin,testing}. This corrects a
local information leak present in (at least) version 3.5.2-1 (see
CVE-2013-7203)
-- David Bremner <bremner@debian.org> Sat, 04 Jan 2014 07:30:51 -0400
gitolite3 (3.5.2-1) unstable; urgency=low
* New upstream release
-- David Bremner <bremner@debian.org> Tue, 30 Jul 2013 22:47:45 -0300
gitolite3 (3.5.1+4-1) experimental; urgency=low
* New upstream snapshot (commit: 2f48a3e0e169e)
(closes: #673867, #673850)
* Ask for admin key with priority high (closes: #699490)
-- David Bremner <bremner@debian.org> Sat, 18 May 2013 17:59:21 -0300
gitolite (2.3-1) unstable; urgency=low
* New upstream release (closes: #669633), containing fix for:
- forgot authkeys can have blank lines also (closes: #653994)
- nitpick on redirection sorting applied (closes: #654022)
* Use sensible-editor instead of ${EDITOR:-vi} in gl-setup (closes: #654178)
* Add Dutch debconf translation done by Jeroen Schot (closes: #661583)
* Bump Standards-Version to 3.9.3.
-- Gerfried Fuchs <rhonda@debian.org> Tue, 24 Apr 2012 18:06:09 +0200
gitolite (2.2-1) unstable; urgency=low
* New Upstream version.
* Do a chown -R on the tmpdir directory for the admin key (LP: #886524)
* Doh, really remove resetting the adminkey from the debconf config file,
sorry (closes: #621680)
* Install contrib files into examples doc directory (closes: #645668)
-- Gerfried Fuchs <rhonda@debian.org> Mon, 19 Dec 2011 08:57:14 +0100
gitolite (2.0.3-2) unstable; urgency=low
* Move the fix permission snippet to the end so that the templates and
md5sums control files also get proper permissions. Thanks to Stefano
Rivera for notifying me about it.
* Updated debian/copyright file.
* Add recommended targets build-arch and build-indep to debian/rules.
-- Gerfried Fuchs <rhonda@debian.org> Tue, 27 Sep 2011 11:23:18 +0200
gitolite (2.0.3-1) unstable; urgency=low
* New Upstream version, containing fix for setting gitweb/gitdaemon
permissions on wildcard repos (closes: #635497)
* Bump Standards-Version to 3.9.2.
* Reset debconf adminkey to empty after extraction in postinst, not before
asking in config so that preseeding works (closes: #626465)
* Adjust debconf questions to priority medium to make them more likely to be
seen by admins (closes: #610765)
* Use hardcoded admin.pub keyname for admin, the filename given might not
have .pub extension.
* Only initialize when an admin key was given (closes: #610765, #617896)
-- Gerfried Fuchs <rhonda@debian.org> Tue, 06 Sep 2011 13:31:23 +0200
gitolite (2.0-1) unstable; urgency=low
* New Upstream version.
* Remove alternative on ssh-server, the used SSH_ORIGINAL_COMMAND
environment variable is set only by openssh-server.
* Change "conf" directory from /etc/gitolite to /usr/share/gitolite/conf,
these files aren't meant to get edited directly (closes: #611857)
* Also remove them as conffiles.
* Remove disable-interactive-mode patch, call gl-setup with -q instead.
* Refresh other patches.
-- Gerfried Fuchs <rhonda@debian.org> Thu, 24 Mar 2011 00:11:38 +0100
gitolite (1.5.7-2) unstable; urgency=high
* cherry-pick 4ce00a commit to fix security issue related to ACDs.
-- Gerfried Fuchs <rhonda@debian.org> Sun, 27 Feb 2011 19:39:15 +0100
gitolite (1.5.7-1) unstable; urgency=low
* New Upstream version.
* Bump Standards-Version to 3.9.1.
* Refresh fix-.ssh-permissions patch.
* Rewrite debian/copyright in DEP5 format.
* Fix debian/watch to download tarball instead of zipball.
* New patch disable-interactive-mode which disables interactive mode in
gl-setup script on new install.
-- Gerfried Fuchs <rhonda@debian.org> Sat, 15 Jan 2011 00:53:50 +0100
gitolite (1.5.4-2) unstable; urgency=low
* Re-add -p to mkdir for .ssh dir (LP: #634718)
* New/updated debconf translations:
- Portuguese by Américo Monteiro, sorry for taking the wrong file in the
former upload (closes: #595312)
- Japanese by Hideki Yamane (closes: #595457)
- Vietnamese by Clytie Siddall (closes: #598592)
-- Gerfried Fuchs <rhonda@debian.at> Tue, 05 Oct 2010 22:11:58 +0200
gitolite (1.5.4-1) unstable; urgency=low
* New Upstream version.
* Apply patches from l10n-english team to improve the package description
and debconf questions. Thanks! (closes: #588870)
* Added/updated debconf translation:
- Spanish by Omar Campagne (closes: #587247)
- French by Thomas Blein (closes: #587556, #590850, #594309)
- Portuguese by Américo Monteiro (closes: #587462)
- Swedish by Martin Bagge (closes: #587537, #589271)
- German by myself
- Russian by Yuri Kozlov (closes: #589249)
- Czech by Michal Šimůnek (closes: #589277)
- Slovak by Slavko (closes: #593058)
- Danish by Joe Hansen (closes: #593272)
- Italian by Vincenzo Campanella (closes: #593669)
* Fix a final minor issue in the debconf template that could be
misunderstood.
* Change packaging licensing to WTFPLv2.
-- Gerfried Fuchs <rhonda@debian.at> Mon, 30 Aug 2010 21:01:46 +0200
gitolite (1.5.3-1) unstable; urgency=low
[ Gerfried Fuchs ]
* New Upstream release.
* Added debconf translations:
- French by Thomas Blein (closes: #580022)
- Swedish by Martin Bagge (closes: #580144)
- Portuguese by Américo Monteiro (closes: #580442)
* Added Vcs-* control fields.
* Don't chown /etc/gitolite/* anymore, it's not needed.
* Test for $GITDIR/.gitolite.rc instead of only $GITDIR for creation check
(closes: #582200)
* Enhance debian/templates text.
[ Teemu Matilainen ]
* debian/control: Prefer new git package in Depends
* debian/rule: Generate and install the VERSION file (closes: #582201)
* debian/gl-setup: Use exec in gl-setup
* debian/config, debian/templates: Default to empty key
* debian/watch: Mangle Github urls to also download the tarball
-- Gerfried Fuchs <rhonda@debian.at> Thu, 24 Jun 2010 21:14:04 +0200
gitolite (1.4.2-1) unstable; urgency=low
* New Upstream release.
* Add patch fix-.ssh-permissions to set tight permissions on created .ssh
directory.
-- Gerfried Fuchs <rhonda@debian.at> Thu, 29 Apr 2010 19:35:02 +0200
gitolite (1.3-2) unstable; urgency=low
* Create the user with --shell /bin/bash instead of /bin/false to make the
package actually work.
* Install debian/gl-setup as wrapper script.
* Remove awkward hack for gl-setup calling in postinst, fixed because of
above two changes.
* Add German debconf translation, replaced some placeholders in the
template.
-- Gerfried Fuchs <rhonda@debian.at> Fri, 09 Apr 2010 18:00:07 +0200
gitolite (1.3-1) unstable; urgency=low
* Initial release (closes: #550817)
-- Gerfried Fuchs <rhonda@debian.at> Thu, 08 Apr 2010 23:56:44 +0200
|