<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
	>

<channel>
	<title>The Gitorious Blog</title>
	<atom:link href="http://blog.gitorious.org/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.gitorious.org</link>
	<description></description>
	<lastBuildDate>Tue, 23 Apr 2013 09:40:32 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
<cloud domain='blog.gitorious.org' port='80' path='/?rsscloud=notify' registerProcedure='' protocol='http-post' />
<image>
		<url>http://1.gravatar.com/blavatar/d042fdf355205cf1c86adce5e94f7f8b?s=96&#038;d=http%3A%2F%2Fs2.wp.com%2Fi%2Fbuttonw-com.png</url>
		<title>The Gitorious Blog</title>
		<link>http://blog.gitorious.org</link>
	</image>
	<atom:link rel="search" type="application/opensearchdescription+xml" href="http://blog.gitorious.org/osd.xml" title="The Gitorious Blog" />
	<atom:link rel='hub' href='http://blog.gitorious.org/?pushpress=hub'/>
		<item>
		<title>Gitorious is featured on the GitMinutes podcast</title>
		<link>http://blog.gitorious.org/2013/04/17/gitorious-is-featured-on-the-gitminutes-podcast/</link>
		<comments>http://blog.gitorious.org/2013/04/17/gitorious-is-featured-on-the-gitminutes-podcast/#comments</comments>
		<pubDate>Wed, 17 Apr 2013 07:22:16 +0000</pubDate>
		<dc:creator>Marius Mathiesen</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.gitorious.org/?p=1036</guid>
		<description><![CDATA[GitMinutes is a fairly new podcast about Git, with weekly episodes featuring interviews with people doing all kinds of things with Git. This podcast is a great way to keep track of what&#8217;s happening in the Git community. I&#8217;m in this week&#8217;s episode, talking about Gitorious and Git infrastructure. I had a great time chatting [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.gitorious.org&#038;blog=7191337&#038;post=1036&#038;subd=gitorious&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p><a href="http://www.gitminutes.com/">GitMinutes</a> is a fairly new podcast about Git, with weekly episodes featuring interviews with people doing all kinds of things with Git. This podcast is a great way to keep track of what&#8217;s happening in the Git community.</p>
<p>I&#8217;m in this week&#8217;s episode, talking about Gitorious and Git infrastructure. I had a great time chatting with Thomas from GitMinutes, and you&#8217;ll find the current episode <a href="http://episodes.gitminutes.com/2013/04/gitminutes-04-marius-mathiesen-on.html">here. </a></p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/gitorious.wordpress.com/1036/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/gitorious.wordpress.com/1036/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.gitorious.org&#038;blog=7191337&#038;post=1036&#038;subd=gitorious&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.gitorious.org/2013/04/17/gitorious-is-featured-on-the-gitminutes-podcast/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/983dc27817acd9318b9d67e2e320c96d?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">zmalltalker</media:title>
		</media:content>
	</item>
		<item>
		<title>An update about Gitorious v3.0</title>
		<link>http://blog.gitorious.org/2013/04/02/an-update-about-gitorious-v3-0/</link>
		<comments>http://blog.gitorious.org/2013/04/02/an-update-about-gitorious-v3-0/#comments</comments>
		<pubDate>Tue, 02 Apr 2013 12:12:44 +0000</pubDate>
		<dc:creator>Marius Mathiesen</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.gitorious.org/?p=1025</guid>
		<description><![CDATA[When we merged the Rails 3 branch into next back in January it was our intention that this would become Gitorious 3.0, with few user-visible features. Our plan was to ship 3.1 shortly after, including the new code browser we started working on last year. The upgrade to rails 3 was done mainly to enable [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.gitorious.org&#038;blog=7191337&#038;post=1025&#038;subd=gitorious&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>When we merged the Rails 3 branch into next <a href="http://blog.gitorious.org/2013/01/04/gitorious-3-0-lands-in-the-next-branch/">back in January</a> it was our intention that this would become Gitorious 3.0, with few user-visible features. Our plan was to ship 3.1 shortly after, including <a href="http://blog.gitorious.org/2012/09/14/browsing-local-repositories-with-dolt/">the new code browser</a> we started working on last year.</p>
<p>The upgrade to rails 3 was done mainly to enable us to run the code browser asynchronously, and we have put a lot of effort into making it possible to run an asynchronous web server alongside the Gitorious Rails application. Despite these efforts we were never able to get the stability we need with this setup. To make matters worse, the speed benefits from running asynchronously haven&#8217;t been as big as we had hoped. Because of this we have decided to make some changes to our plans:</p>
<h3>Gitorious 3 will include the new code browser</h3>
<p>We felt that shipping a new major without any major user-facing changes doesn&#8217;t make any sense. Since the updated code browser is so close to being merged, we&#8217;ll wait with tagging the 3.0 version until the new code browser has been merged into the next branch. We feel it&#8217;s worth waiting for:</p>
<p><a href="http://gitorious.files.wordpress.com/2012/08/gitorious-syntax-highlighting1.png"><img class="alignnone  wp-image-586" alt="New Gitorious UI sketch - syntax highlighting" src="http://gitorious.files.wordpress.com/2012/08/gitorious-syntax-highlighting1.png?w=668&#038;h=729" width="668" height="729" /></a></p>
<h3>The code browser in Gitorious 3 will not be asynchronous</h3>
<p>We will change the code browser so it no longer runs asynchronously; rather it will be a <a href="http://rack.github.com/">Rack</a> application running inside Gitorious. The git repository access is still done using <a href="https://github.com/libgit2/libgit2">libgit2</a>/<a href="https://github.com/libgit2/rugged">rugged</a>, which gives great speed and stability gains, and we will finally get proper syntax highlighting courtesy of <a href="http://pygments.org/">Pygments</a>.</p>
<p>We hope to tag Gitorious 3.0 before the end of April, and will deploy it to gitorious.org as soon as it&#8217;s been tagged. It will feature:</p>
<ul>
<li>Rails 3.2</li>
<li>Partial new UI</li>
<li>Significantly improved repository browser (Dolt)</li>
<li>New syntax highlighting, along with support for vast numbers of new languages</li>
<li>Readme-rendering for repositories</li>
<li>A JSON/HTTP based API, more details soon!</li>
<li>Ruby 1.9 support</li>
</ul>
<p>Shortly after 3.0 lands we will keep working on propagating the UI upgrade to other parts of the application.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/gitorious.wordpress.com/1025/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/gitorious.wordpress.com/1025/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.gitorious.org&#038;blog=7191337&#038;post=1025&#038;subd=gitorious&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.gitorious.org/2013/04/02/an-update-about-gitorious-v3-0/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/983dc27817acd9318b9d67e2e320c96d?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">zmalltalker</media:title>
		</media:content>

		<media:content url="http://gitorious.files.wordpress.com/2012/08/gitorious-syntax-highlighting1.png" medium="image">
			<media:title type="html">New Gitorious UI sketch - syntax highlighting</media:title>
		</media:content>
	</item>
		<item>
		<title>Gitorious v2.4.12 is released (security update)</title>
		<link>http://blog.gitorious.org/2013/03/19/gitorious-v2-4-12-is-released-security-update/</link>
		<comments>http://blog.gitorious.org/2013/03/19/gitorious-v2-4-12-is-released-security-update/#comments</comments>
		<pubDate>Tue, 19 Mar 2013 12:15:32 +0000</pubDate>
		<dc:creator>Thomas Kjeldahl Nilsson</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.gitorious.org/?p=1015</guid>
		<description><![CDATA[Three new vulnerabilities have been fixed for Ruby on Rails, on which Gitorious is built. Read the original Ruby on Rails sec-list announcements for further details. The steps for upgrading are, as usual (from within the root gitorious clone/source directory): git fetch --tags git merge v2.4.12 git submodule update --init bundle install We advise all users running [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.gitorious.org&#038;blog=7191337&#038;post=1015&#038;subd=gitorious&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Three new vulnerabilities have been fixed for Ruby on Rails, on which Gitorious is built. Read <a href="https://groups.google.com/forum/?fromgroups#!forum/rubyonrails-security">the original Ruby on Rails sec-list announcements</a> for further details.</p>
<p>The steps for upgrading are, as usual (from within the root gitorious clone/source directory):</p>
<pre>git fetch --tags

git merge v2.4.12

git submodule update --init

bundle install</pre>
<p>We advise all users running their own Gitorious servers to upgrade immediately. Note that the Gitorious Community Edition installer has also been updated to install v2.4.12 now.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/gitorious.wordpress.com/1015/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/gitorious.wordpress.com/1015/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.gitorious.org&#038;blog=7191337&#038;post=1015&#038;subd=gitorious&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.gitorious.org/2013/03/19/gitorious-v2-4-12-is-released-security-update/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/b7c56fe7d8c78f52dcdfb4025e1a78f7?s=96&#38;d=http%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">thomanil</media:title>
		</media:content>
	</item>
		<item>
		<title>Gitorious v2.4.10 has been released</title>
		<link>http://blog.gitorious.org/2013/03/04/gitorious-v2-4-10-has-been-released/</link>
		<comments>http://blog.gitorious.org/2013/03/04/gitorious-v2-4-10-has-been-released/#comments</comments>
		<pubDate>Mon, 04 Mar 2013 08:54:28 +0000</pubDate>
		<dc:creator>Marius Mathiesen</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.gitorious.org/?p=1013</guid>
		<description><![CDATA[&#160; As a refreshing change from the security-related versions of Gitorious over the last weeks, we&#8217;re glad to announce that version 2.4.10 of Gitorious was just released. This release contains fixes several bugs in Gitorious, among these: Fix broken pushes with sync messaging adapter Fix layout for global system message Fix mass-assignment related bugs Include [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.gitorious.org&#038;blog=7191337&#038;post=1013&#038;subd=gitorious&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>&nbsp;</p>
<p>As a refreshing change from the security-related versions of Gitorious over the last weeks, we&#8217;re glad to announce that version 2.4.10 of Gitorious was just released. This release contains fixes several bugs in Gitorious, among these:</p>
<ul>
<li>Fix broken pushes with sync messaging adapter</li>
<li>Fix layout for global system message</li>
<li>Fix mass-assignment related bugs</li>
<li>Include repositories in Project XML output</li>
<li>Fix broken User avatar upload</li>
<li>Finally fix the double merge request versions</li>
<li>Make bin/bundle work when bundle needs update(s)</li>
</ul>
<p>Furthermore, you may place global git hooks on a location specified in gitorious.yml.</p>
<p>The steps for upgrading are, as usual:</p>
<ul>
<li>git fetch origin</li>
<li>git merge v2.4.10</li>
<li>git submodule update</li>
<li>bundle install</li>
<li>touch tmp/restart.txt (assuming you’re using Passenger. For non-Passenger deployments, restart your application server like you normally do)</li>
</ul>
<p>Happy upgrades!</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/gitorious.wordpress.com/1013/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/gitorious.wordpress.com/1013/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.gitorious.org&#038;blog=7191337&#038;post=1013&#038;subd=gitorious&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.gitorious.org/2013/03/04/gitorious-v2-4-10-has-been-released/feed/</wfw:commentRss>
		<slash:comments>5</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/983dc27817acd9318b9d67e2e320c96d?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">zmalltalker</media:title>
		</media:content>
	</item>
		<item>
		<title>Gitorious went down this morning</title>
		<link>http://blog.gitorious.org/2013/02/26/gitorious-went-down-this-morning/</link>
		<comments>http://blog.gitorious.org/2013/02/26/gitorious-went-down-this-morning/#comments</comments>
		<pubDate>Tue, 26 Feb 2013 08:06:08 +0000</pubDate>
		<dc:creator>Marius Mathiesen</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.gitorious.org/?p=1008</guid>
		<description><![CDATA[Our frontend web server went down at 6:24CET this morning, we will be updating this post as we bring the server back up. Here&#8217;s what we know right now: At 6:24 CET a Kernel oops occured. The alarms at our hosting provider went off, and the server was booted.  Since the file system keeping the [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.gitorious.org&#038;blog=7191337&#038;post=1008&#038;subd=gitorious&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Our frontend web server went down at 6:24CET this morning, we will be updating this post as we bring the server back up. Here&#8217;s what we know right now:</p>
<ul>
<li><span style="line-height:13px;">At 6:24 CET a <a href="http://en.wikipedia.org/wiki/Linux_kernel_oops">Kernel oops</a> occured. The alarms at our hosting provider went off, and the server was booted. </span></li>
<li>Since the file system keeping the repositories hasn&#8217;t had a full consistency check since August 2012 a fsck was started</li>
<li>When fsck hadn&#8217;t completed at 8:00 CET, the server was routinely rebooted, and another fsck process was started at 8:04 CET</li>
<li>The last time we ran a full fsck on the file system, it took about 2.5 hours. Since then, however, we have installed dedicated storage for our servers, and this has higher IO capacity than the one we were running from in August last year.</li>
<li>10:06 CET: The server is back up. We will upgrade the kernel and do another reboot, hopefully the kernel issue we encountered earlier today has been resolved. Expect a few minutes downtime in a few minutes</li>
<li>10:13 CET: All systems are running again, with an updated kernel</li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/gitorious.wordpress.com/1008/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/gitorious.wordpress.com/1008/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.gitorious.org&#038;blog=7191337&#038;post=1008&#038;subd=gitorious&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.gitorious.org/2013/02/26/gitorious-went-down-this-morning/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/983dc27817acd9318b9d67e2e320c96d?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">zmalltalker</media:title>
		</media:content>
	</item>
		<item>
		<title>Improved and updated the Gitorious CE Installer (v2.4.9)</title>
		<link>http://blog.gitorious.org/2013/02/15/improved-and-updated-the-gitorious-ce-installer-v2-4-9/</link>
		<comments>http://blog.gitorious.org/2013/02/15/improved-and-updated-the-gitorious-ce-installer-v2-4-9/#comments</comments>
		<pubDate>Fri, 15 Feb 2013 13:43:15 +0000</pubDate>
		<dc:creator>Thomas Kjeldahl Nilsson</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.gitorious.org/?p=992</guid>
		<description><![CDATA[We&#8217;ve closed a number of recent security issues related to Ruby and Rails (which Gitorious depends on). The Community Edition Installer has lagged behind a bit but is, as of today, upgraded to install the latest version of Gitorious (v2.4.9). The update also includes our current recommended default settings plus some improvements to the installer itself. Short story: [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.gitorious.org&#038;blog=7191337&#038;post=992&#038;subd=gitorious&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>We&#8217;ve closed a number of recent security issues related to Ruby and Rails (which Gitorious depends on). The <a href="http://getgitorious.com/installer">Community Edition Installer</a> has lagged behind a bit but is, as of today, upgraded to install the latest version of Gitorious (v2.4.9). The update also includes our current recommended default settings plus some improvements to the installer itself.</p>
<p><strong>Short story</strong>: following the steps outlined at <a href="http://getgitorious.com/installer">http://getgitorious.com/installer</a> on a fresh CentOS 6 server will ensure that you end up with the latest version of Gitorious installed.</p>
<p><strong>Already running on an older version of Gitorious and need to upgrade?</strong> Follow the standard installation procedure outlined <a href="http://blog.gitorious.org/2013/02/13/2-4-9-fixes-regression-in-2-4-8/">here</a>.</p>
<p>Please let us know if you run into any issues with the installer: the Gitorious team can be reached at <a href="mailto:support@gitorious.org">support@gitorious.org</a></p>
<p><strong>Changelog for the installer:</strong></p>
<blockquote>
<pre>Update to Gitorious v2.4.9 &amp; improve installer

Brings the installer up to Gitorious v2.4.9, uses the current most
sensible default settings for that version, fixes recent Rails and
Ruby-related security issues and improves the installer itself.

Breakdown:

- Using resque instead of ActiveMq

- Using nginx+unicorn instead of apache+passenger

- Use latest version of Gitorious

- Includes fixes for recent Ruby/Rails security issues

- Using thinking sphinx instead of ultrasphinx

- Installer no longer nukes existing Ruby/Rubygems

- Installer logs puppet operations

- More robust puppet apply operation

- Truly random generated db/rails passwords

- Only create random db password on first run

- Remove unneeded git proxy, use git daemon directly</pre>
</blockquote>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/gitorious.wordpress.com/992/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/gitorious.wordpress.com/992/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.gitorious.org&#038;blog=7191337&#038;post=992&#038;subd=gitorious&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.gitorious.org/2013/02/15/improved-and-updated-the-gitorious-ce-installer-v2-4-9/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://2.gravatar.com/avatar/b7c56fe7d8c78f52dcdfb4025e1a78f7?s=96&#38;d=http%3A%2F%2F2.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">thomanil</media:title>
		</media:content>
	</item>
		<item>
		<title>2.4.9 fixes regression in 2.4.8</title>
		<link>http://blog.gitorious.org/2013/02/13/2-4-9-fixes-regression-in-2-4-8/</link>
		<comments>http://blog.gitorious.org/2013/02/13/2-4-9-fixes-regression-in-2-4-8/#comments</comments>
		<pubDate>Wed, 13 Feb 2013 14:00:27 +0000</pubDate>
		<dc:creator>Christian Johansen</dc:creator>
				<category><![CDATA[Release]]></category>

		<guid isPermaLink="false">http://blog.gitorious.org/?p=990</guid>
		<description><![CDATA[I inadvertently broke creating new projects with yesterday&#8217;s 2.4.8 release. I have deployed a fix on gitorious.org, and just tagged 2.4.9. 2.4.9 also addresses a bug in Gitorious&#8217; log graph visualization. We made some sweeping changes yesterday, by changing attr_protected (which was the recent target of a Rails vulnerability) to attr_accessible &#8211; basically changing from [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.gitorious.org&#038;blog=7191337&#038;post=990&#038;subd=gitorious&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>I inadvertently broke creating new projects with yesterday&#8217;s 2.4.8 release. I have deployed a fix on gitorious.org, and just tagged 2.4.9. 2.4.9 also addresses a bug in Gitorious&#8217; log graph visualization.</p>
<p>We made some sweeping changes yesterday, by changing <code>attr_protected</code> (which was the recent target of a Rails vulnerability) to <code>attr_accessible</code> &#8211; basically changing from black-listing to white-listing in what parameters can be posted to Gitorious and set on DB-backed models. It seems that one case was not covered by automatic tests, and was not discovered immediately.</p>
<p>Sorry for the inconvenience.</p>
<p>To upgrade your Gitorious, follow the regular procedure:</p>
<p>* git fetch origin<br />
* git merge v2.4.9<br />
* git submodule update<br />
* bin/bundle install<br />
* bin/rake assets:clear<br />
* touch tmp/restart.txt (assuming you’re using Passenger. For non-Passenger deployments, restart your application server like you normally do)</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/gitorious.wordpress.com/990/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/gitorious.wordpress.com/990/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.gitorious.org&#038;blog=7191337&#038;post=990&#038;subd=gitorious&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.gitorious.org/2013/02/13/2-4-9-fixes-regression-in-2-4-8/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6e7ddb6784d284c385f3f0f307ebf90d?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">cjohansen</media:title>
		</media:content>
	</item>
		<item>
		<title>Gitorious v2.4.8 is released</title>
		<link>http://blog.gitorious.org/2013/02/12/gitorious-v2-4-8-is-released/</link>
		<comments>http://blog.gitorious.org/2013/02/12/gitorious-v2-4-8-is-released/#comments</comments>
		<pubDate>Tue, 12 Feb 2013 09:55:45 +0000</pubDate>
		<dc:creator>Christian Johansen</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.gitorious.org/?p=988</guid>
		<description><![CDATA[Three new vulnerabilities have been fixed for Ruby on Rails, on which Gitorious is built. Read the original announcements for further details. All users running their own Gitorious servers should upgrade immediately. The steps for upgrading are, as usual: git fetch origin git merge v2.4.8 git submodule update bundle install touch tmp/restart.txt (assuming you’re using [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.gitorious.org&#038;blog=7191337&#038;post=988&#038;subd=gitorious&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Three new vulnerabilities have been fixed for Ruby on Rails, on which Gitorious is built. Read <a href="https://groups.google.com/forum/?fromgroups#!forum/rubyonrails-security">the original announcements</a> for further details. All users running their own Gitorious servers should upgrade immediately.</p>
<p>The steps for upgrading are, as usual:</p>
<ul>
<li>git fetch origin</li>
<li>git merge v2.4.8</li>
<li>git submodule update</li>
<li>bundle install</li>
<li>touch tmp/restart.txt (assuming you’re using Passenger. For non-Passenger deployments, restart your application server like you normally do)</li>
</ul>
<p>If you&#8217;re running on the next branch, that has been updated as well. Just pull from mainline, then restart your server, and you&#8217;re all set.</p>
<p>You will note that the advisory and the v2.4.8 tag were both signed with our PGP key, as part of the Security Policy <a href="http://en.gitorious.org/security/">described at our security page</a>. By signing release tags and security advisories you can verify that these were in fact issued by the Gitorious team.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/gitorious.wordpress.com/988/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/gitorious.wordpress.com/988/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.gitorious.org&#038;blog=7191337&#038;post=988&#038;subd=gitorious&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.gitorious.org/2013/02/12/gitorious-v2-4-8-is-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6e7ddb6784d284c385f3f0f307ebf90d?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">cjohansen</media:title>
		</media:content>
	</item>
		<item>
		<title>Gitorious v2.4.7 was just released</title>
		<link>http://blog.gitorious.org/2013/02/06/gitorious-v2-4-7-was-just-released/</link>
		<comments>http://blog.gitorious.org/2013/02/06/gitorious-v2-4-7-was-just-released/#comments</comments>
		<pubDate>Wed, 06 Feb 2013 09:11:41 +0000</pubDate>
		<dc:creator>Marius Mathiesen</dc:creator>
				<category><![CDATA[Uncategorized]]></category>

		<guid isPermaLink="false">http://blog.gitorious.org/?p=985</guid>
		<description><![CDATA[This morning we discovered a vulnerability in Gitorious which made us write this advisory on our mailing list and release version 2.4.7 of Gitorious. All users running their own Gitorious servers should upgrade immediately. The steps for upgrading are, as usual: git fetch origin git merge v2.4.7 git submodule update bundle install touch tmp/restart.txt (assuming [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.gitorious.org&#038;blog=7191337&#038;post=985&#038;subd=gitorious&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>This morning we discovered a vulnerability in Gitorious which made us write <a href="https://groups.google.com/group/gitorious/browse_thread/thread/3bf4941afab1acd9">this advisory</a> on our mailing list and release version 2.4.7 of Gitorious. All users running their own Gitorious servers should upgrade immediately.</p>
<p>The steps for upgrading are, as usual:</p>
<ul>
<li>git fetch origin</li>
<li>git merge v2.4.7</li>
<li>git submodule update</li>
<li>bundle install</li>
<li>touch tmp/restart.txt (assuming you’re using Passenger. For non-Passenger deployments, restart your application server like you normally do)</li>
</ul>
<p>If you&#8217;re running on the next branch, that has been updated as well. Just pull from mainline, then restart your server, and you&#8217;re all set.</p>
<p>You will note that the advisory and the v2.4.7 tag were both signed with our PGP key, as part of the Security Policy <a href="http://en.gitorious.org/security/">described at our security page</a>. By signing release tags and security advisories you can verify that these were in fact issued by the Gitorious team.</p>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/gitorious.wordpress.com/985/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/gitorious.wordpress.com/985/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.gitorious.org&#038;blog=7191337&#038;post=985&#038;subd=gitorious&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.gitorious.org/2013/02/06/gitorious-v2-4-7-was-just-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/983dc27817acd9318b9d67e2e320c96d?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">zmalltalker</media:title>
		</media:content>
	</item>
		<item>
		<title>Gitorious 2.4.6 has been released</title>
		<link>http://blog.gitorious.org/2013/01/29/gitorious-2-4-6-has-been-released/</link>
		<comments>http://blog.gitorious.org/2013/01/29/gitorious-2-4-6-has-been-released/#comments</comments>
		<pubDate>Tue, 29 Jan 2013 08:31:02 +0000</pubDate>
		<dc:creator>Christian Johansen</dc:creator>
				<category><![CDATA[Release]]></category>

		<guid isPermaLink="false">http://blog.gitorious.org/?p=981</guid>
		<description><![CDATA[Gitorious 2.4.6 has just been released, and all Gitorious servers should be updated immediately. This release brings Gitorious up to Rails version 2.3.16, which solves a severe vulnerability in Ruby on Rails. There&#8217;s more information about this vulnerability on the Ruby on Rails security mailing list. This release also fixes the less severe CVE-0155 from [...]<img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.gitorious.org&#038;blog=7191337&#038;post=981&#038;subd=gitorious&#038;ref=&#038;feed=1" width="1" height="1" />]]></description>
				<content:encoded><![CDATA[<p>Gitorious 2.4.6 has just been released, and all Gitorious servers should be updated <strong>immediately</strong>. This release brings Gitorious up to Rails version 2.3.16, which solves <strong>a severe vulnerability in Ruby on Rails</strong>. There&#8217;s more information about this vulnerability <a href="https://groups.google.com/forum/?fromgroups=#!topic/rubyonrails-security/1h2DR63ViGo">on the Ruby on Rails security mailing list</a>. This release also fixes the less severe CVE-0155 from two weeks ago.</p>
<p>To upgrade to this version, follow one of the three following alternative fixes</p>
<h3>If you&#8217;re running from a release in the 2.4 branch of Gitorious:</h3>
<p>To upgrade a server running one of the releases in the 2.4 series of Gitorious, follow these steps:</p>
<ul>
<li><span style="line-height:13px;">git fetch origin </span></li>
<li>git merge v2.4.6</li>
<li>bundle install</li>
<li>touch tmp/restart.txt (assuming you&#8217;re using Passenger. For non-Passenger deployments, restart your application server like you normally do)</li>
</ul>
<h3>If you&#8217;re running from the next branch of Gitorious (Rails 3)</h3>
<p>Guess what, you&#8217;re off the hook. This vulnerability does not affect Rails 3.2, which Gitorious 3 is built on.</p>
<h3>If you&#8217;re running neither of the versions above:</h3>
<p>If your server is not running from a version that can be upgraded, you can secure your server by following these manual steps</p>
<ul>
<li><span style="line-height:13px;">create the file config/initializers/fix_cve_2013_0333.rb inside your Gitorious installation with this content:</span></li>
</ul>
<pre>ActiveSupport::JSON.backend = "JSONGem"</pre>
<ul>
<li><span style="line-height:13px;">restart your application server</span></li>
</ul>
<br />  <a rel="nofollow" href="http://feeds.wordpress.com/1.0/gocomments/gitorious.wordpress.com/981/"><img alt="" border="0" src="http://feeds.wordpress.com/1.0/comments/gitorious.wordpress.com/981/" /></a> <img alt="" border="0" src="http://stats.wordpress.com/b.gif?host=blog.gitorious.org&#038;blog=7191337&#038;post=981&#038;subd=gitorious&#038;ref=&#038;feed=1" width="1" height="1" />]]></content:encoded>
			<wfw:commentRss>http://blog.gitorious.org/2013/01/29/gitorious-2-4-6-has-been-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
	
		<media:content url="http://0.gravatar.com/avatar/6e7ddb6784d284c385f3f0f307ebf90d?s=96&#38;d=http%3A%2F%2F0.gravatar.com%2Favatar%2Fad516503a11cd5ca435acc9bb6523536%3Fs%3D96&#38;r=G" medium="image">
			<media:title type="html">cjohansen</media:title>
		</media:content>
	</item>
	</channel>
</rss>
