Skip to content

Bump Git version on Windows to 2.55.0.windows.4 - #697

Open
github-actions[bot] wants to merge 2 commits into
masterfrom
updatecli_master_a9b520a64e19715d0db64eef4d745f71c310e6ce8883f842e49b6fe6ca7451aa
Open

Bump Git version on Windows to 2.55.0.windows.4#697
github-actions[bot] wants to merge 2 commits into
masterfrom
updatecli_master_a9b520a64e19715d0db64eef4d745f71c310e6ce8883f842e49b6fe6ca7451aa

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

Bump Git version on Windows

Update the Git Package Windows patch for Windows Nanoserver

changed lines [72] of file "windows/nanoserver/Dockerfile"

v2.55.0.windows.4
Changes since Git for Windows v2.55.0(3) (July 14th 2026)

Following the [MSYS2 project](https://www.msys2.org/news/#2026-02-28-dropping-support-for-windows-81), on which Git for Windows is based, Windows 8.1 support will be dropped after Git for Windows v2.55.

This is a security fix release, addressing CVE-2026-62960.

* [CVE-2026-62960](https://github.com/git-for-windows/git/security/advisories/GHSA-xrpg-8j9v-v282), Git for Windows: Attacker-controlled servers may advertise bundle URIs that point to network shares, causing Windows to transparently perform NTLM authentication and disclose the user's NTLMv2 hash. Since NTLM hashing is weak, the captured hash can potentially be brute-forced to recover the user's credentials. This is addressed by limiting the bundle URIs that `git clone` respects by the same [`protocol.<name>.allow`](https://git-scm.com/docs/git-config#Documentation/git-config.txt-protocolnameallow) rules as usual, which excludes `file://` URIs by default.

Filename | SHA-256
-------- | -------
Git-2.55.0.4-64-bit.exe | 0cbc0b34a74b3aff3ace0910328549155a770e228331b19cb1498218a120e7ff
Git-2.55.0.4-arm64.exe | 8d358f4d53a5a475570edca3124dc0d4f1a020321594984f58e6b04f86f50ec4
PortableGit-2.55.0.4-64-bit.7z.exe | 016e84230a3767f0c6b3788e79ba0c58a17377086801719d46700fca4f7b36b5
PortableGit-2.55.0.4-arm64.7z.exe | d69d0c6a3c5445553565ef74f1d9e22a9869f57c246111db347dd96c252b4da5
MinGit-2.55.0.4-64-bit.zip | 4e03f94c2ffbf70be337e005cee02661c732dbfc81031a078bda9299b9a7d644
MinGit-2.55.0.4-arm64.zip | 033eb6b927d804558ae479a6ae6c6ed86da42cabc0d424844a3e108c780a58cc
MinGit-2.55.0.4-32-bit.zip | 01bd8fc4cf00df3e278e09a036a003c698b512b68508a1163404ef138ed4ef93
MinGit-2.55.0.4-busybox-64-bit.zip | 255a8d6f43e330817ae1eb2599e153835383cdfb17759c5251318242b03ad3db
MinGit-2.55.0.4-busybox-32-bit.zip | 308e0a24c77fe72d466d2db1e23aea52ee2e4b6dc92f18db04020a9113171ea0
Git-2.55.0.4-64-bit.tar.bz2 | 5c22d52d59bc5d46a47ef5bd3d071723ee014eed219fb6337444acd0dcb8b910
Git-2.55.0.4-arm64.tar.bz2 | 7cc28b4431c9448c310d0093fbba5646517cd702690a9b965014d7df85319ad9
Update the Git Package Windows patch for Windows Server Core

changed lines [60] of file "windows/windowsservercore/Dockerfile"

v2.55.0.windows.4
Changes since Git for Windows v2.55.0(3) (July 14th 2026)

Following the [MSYS2 project](https://www.msys2.org/news/#2026-02-28-dropping-support-for-windows-81), on which Git for Windows is based, Windows 8.1 support will be dropped after Git for Windows v2.55.

This is a security fix release, addressing CVE-2026-62960.

* [CVE-2026-62960](https://github.com/git-for-windows/git/security/advisories/GHSA-xrpg-8j9v-v282), Git for Windows: Attacker-controlled servers may advertise bundle URIs that point to network shares, causing Windows to transparently perform NTLM authentication and disclose the user's NTLMv2 hash. Since NTLM hashing is weak, the captured hash can potentially be brute-forced to recover the user's credentials. This is addressed by limiting the bundle URIs that `git clone` respects by the same [`protocol.<name>.allow`](https://git-scm.com/docs/git-config#Documentation/git-config.txt-protocolnameallow) rules as usual, which excludes `file://` URIs by default.

Filename | SHA-256
-------- | -------
Git-2.55.0.4-64-bit.exe | 0cbc0b34a74b3aff3ace0910328549155a770e228331b19cb1498218a120e7ff
Git-2.55.0.4-arm64.exe | 8d358f4d53a5a475570edca3124dc0d4f1a020321594984f58e6b04f86f50ec4
PortableGit-2.55.0.4-64-bit.7z.exe | 016e84230a3767f0c6b3788e79ba0c58a17377086801719d46700fca4f7b36b5
PortableGit-2.55.0.4-arm64.7z.exe | d69d0c6a3c5445553565ef74f1d9e22a9869f57c246111db347dd96c252b4da5
MinGit-2.55.0.4-64-bit.zip | 4e03f94c2ffbf70be337e005cee02661c732dbfc81031a078bda9299b9a7d644
MinGit-2.55.0.4-arm64.zip | 033eb6b927d804558ae479a6ae6c6ed86da42cabc0d424844a3e108c780a58cc
MinGit-2.55.0.4-32-bit.zip | 01bd8fc4cf00df3e278e09a036a003c698b512b68508a1163404ef138ed4ef93
MinGit-2.55.0.4-busybox-64-bit.zip | 255a8d6f43e330817ae1eb2599e153835383cdfb17759c5251318242b03ad3db
MinGit-2.55.0.4-busybox-32-bit.zip | 308e0a24c77fe72d466d2db1e23aea52ee2e4b6dc92f18db04020a9113171ea0
Git-2.55.0.4-64-bit.tar.bz2 | 5c22d52d59bc5d46a47ef5bd3d071723ee014eed219fb6337444acd0dcb8b910
Git-2.55.0.4-arm64.tar.bz2 | 7cc28b4431c9448c310d0093fbba5646517cd702690a9b965014d7df85319ad9
GitHub Action workflow link
Updatecli logo

Created automatically by Updatecli

Options:

Most of Updatecli configuration is done via its manifest(s).

  • If you close this pull request, Updatecli will automatically reopen it, the next time it runs.
  • If you close this pull request and delete the base branch, Updatecli will automatically recreate it, erasing all previous commits made.

Feel free to report any issues at github.com/updatecli/updatecli.
If you find this tool useful, do not hesitate to star our GitHub repository as a sign of appreciation, and/or to tell us directly on our chat!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants