[PATCH] 1.10 Release notes and FAQ around SHA-1
From: Jacek Materna <jacek_at_assembla.com>
Date: Mon, 8 May 2017 10:46:39 +0200
Team,
I wanted to start a discussion around the FAQ (and 1.10 rls. notes) as it
1) We should bias towards pro-active mitigation of this issue in docs/code
2) Consider patching 1.10 with de-duplication off by default ?
3) Remediation of the issue (if affected) should be a different topic? -
4) I am sure there are a number of other items this group can append to
>>>>>>>>>>>>>>
Subversion's use of SHA-1 in how it processes content is subject to hashing
Prevention:
Install a pre-commit hook that will reject new instances against known
The hook can be found here:
Best.
-- Jacek Materna CTO Assembla 210-410-7661Received on 2017-05-08 10:46:52 CEST |
This is an archived mail posted to the Subversion Dev mailing list.
This site is subject to the Apache Privacy Policy and the Apache Public Forum Archive Policy.