Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
81 commits
Select commit Hold shift + click to select a range
eeccd46
build(deps): bump actions/setup-dotnet from 5.1.0 to 5.2.0
dependabot[bot] Mar 5, 2026
32e7ff7
Added support for cachyos
BartekDeveloper Mar 10, 2026
42bf6e9
github/gitlab: use correct param order
mjcheetham Mar 31, 2026
51a2379
streamextensions: fix a bug in multi-var reset handling
mjcheetham Mar 31, 2026
20734ab
github: handle empty domain or enterprise hints
mjcheetham Mar 31, 2026
453ae23
github: do not filter accounts outside of dotcom
mjcheetham Mar 31, 2026
817f5e3
diagnose: fix network diag to await HTTP requests
mjcheetham Mar 31, 2026
774af8e
macos: add die function to notarize.sh script
mjcheetham Mar 31, 2026
66c6ef0
build(deps): bump actions/github-script from 8 to 9
dependabot[bot] Apr 10, 2026
b47259c
Bump Tmds.DBus.Protocol from 0.16.0 to 0.21.3
dependabot[bot] Apr 22, 2026
a78b60d
Added support for cachyos (#2284)
mjcheetham Apr 23, 2026
265c4ac
Initial plan
Copilot Apr 23, 2026
868bf00
build(deps): bump actions/github-script from 8 to 9 (#2315)
mjcheetham Apr 23, 2026
ed13a29
Bump Tmds.DBus.Protocol from 0.16.0 to 0.21.3 (#2316)
mjcheetham Apr 23, 2026
95502ae
Add dark theme support to OAuth authentication response pages
Copilot Apr 23, 2026
50cdad4
Fix Bitbucket dark mode footer-logo background
Copilot Apr 23, 2026
632413f
Dark theme support for OAuth authentication response pages (#2325)
mjcheetham Apr 23, 2026
bb00416
http: fix SYSLIB0057 warning for X509Certificate2Collection.Import
mjcheetham Apr 23, 2026
5d85055
git: drain stderr on IsInsideRepository
mjcheetham Mar 31, 2026
86fd16e
windows: fix layout.ps1 if symboloutput is not set
mjcheetham Mar 31, 2026
2226933
oauth: pass cancellation token to in-proc device code UI
mjcheetham Mar 31, 2026
91362eb
trace2: fix main thread identification
mjcheetham Mar 31, 2026
143ce42
trace2: fix crash in perf format for large elapsed times
mjcheetham Mar 31, 2026
d637224
http: use correct http.sslAutoClientCert setting name
mjcheetham Mar 31, 2026
782aada
trace2: fix incomplete disposal of writers on cleanup
mjcheetham Mar 31, 2026
a79ad38
git: fix crash when reading stderr from non-redirected processes
mjcheetham Mar 31, 2026
0c1fe0d
environment: check execute permission in TryLocateExecutable
mjcheetham Mar 31, 2026
fa7b374
windows: fix en-dash characters in installer Exec command
mjcheetham Mar 31, 2026
2fa6482
Fix several small bugs that an AI agent detected (#2303)
mjcheetham Apr 27, 2026
279df7a
http: fix SYSLIB0057 warning for X509Certificate2Collection.Import (#…
mjcheetham Apr 28, 2026
7a2cb70
build(deps): bump actions/setup-dotnet from 5.1.0 to 5.2.0 (#2282)
mjcheetham Apr 28, 2026
d8846d1
VERSION: bump to 2.8.0
mjcheetham Apr 28, 2026
d7778f9
install: update install-from-source to use .NET 10.0
mjcheetham Apr 28, 2026
9c6697e
ci: update debian container to bookworm for .NET 10 support
mjcheetham Apr 28, 2026
14737f4
ci: run install-from-source validation on pull requests
mjcheetham Apr 28, 2026
95f6bf5
install: update install-from-source to use .NET 10.0 (#2330)
mjcheetham Apr 28, 2026
3854378
Release 2.8.0 (#2329)
mjcheetham Apr 28, 2026
e62235a
release: install .NET 8 SDK for ESRP codesigning on macOS and Linux
mjcheetham Apr 28, 2026
d5e8a34
release: install .NET 8 SDK for ESRP codesigning on macOS and Linux (…
mjcheetham Apr 28, 2026
c289984
Port release fixes into main (#2332)
mjcheetham Apr 28, 2026
3abada6
release: run nuget publish job on windows
mjcheetham Apr 28, 2026
c4be6b2
release: run nuget publish job on windows (#2333)
mjcheetham Apr 28, 2026
7158f0f
fix(setup): sync index of matching helper entry
becm May 22, 2026
8421cb7
fix(setup): avoid adding redundant guard entry
becm May 22, 2026
3524619
test(setup): add special cases for `configure`
becm May 22, 2026
88cc045
build(deps): bump actions/setup-dotnet from 5.2.0 to 5.3.0
dependabot[bot] May 28, 2026
312354b
Fix detection of configured GCM helper (#2349)
mjcheetham Jun 2, 2026
5e80db1
globals.json: specify the SDK version precisely
dscho Jun 4, 2026
3a559b8
VERSION: bump to 2.9.0
mjcheetham Jun 18, 2026
ea84a25
oauth: support non-query response modes
mjcheetham Jun 17, 2026
6cefbd9
generic-oauth: add response mode setting
mjcheetham Jun 18, 2026
16e9c7f
msal: update to latest MSAL 4.82.2
mjcheetham Jun 18, 2026
29e2f82
msauth: resolve auth flow before selecting redirect URI
mjcheetham Jun 18, 2026
913b89a
build(deps): bump actions/setup-dotnet from 5.2.0 to 5.3.0 (#2352)
dscho Jun 19, 2026
825f14f
build(deps): bump actions/checkout from 6 to 7
dependabot[bot] Jun 19, 2026
78f669f
build(deps): bump actions/checkout from 6 to 7 (#2358)
dscho Jun 19, 2026
a4743f9
Merge pull request #15 from git-ecosystem/msal-update
mjcheetham Jun 19, 2026
2774321
Merge pull request #17 from git-ecosystem/msal-redirecturi
mjcheetham Jun 19, 2026
194ba29
Merge pull request #16 from git-ecosystem/oauth-form-post
mjcheetham Jun 19, 2026
7bb63e8
build(deps): bump actions/setup-dotnet from 5.3.0 to 5.4.0
dependabot[bot] Jun 26, 2026
16a5741
build(deps): bump actions/setup-dotnet from 5.3.0 to 5.4.0 (#2361)
dscho Jun 28, 2026
69fc517
docs: fix broken links identified by linting
mjcheetham Jun 29, 2026
2377102
docs: fix broken links identified by linting (#2364)
mjcheetham Jun 30, 2026
dcb5fd1
linux: use the appropriate PGP key to sign the Debian packages
dscho Jul 7, 2026
73696fa
browser: open AbsoluteUri to avoid double-escaping
mjcheetham Jul 6, 2026
ac43912
linux: adjust the instructions how to verify the signatures
dscho Jul 7, 2026
cd57ef8
linux: fix instructions where to download the latest archive
dscho Jul 7, 2026
e3e079e
esrp: use new Linux signing key (#2373)
mjcheetham Jul 7, 2026
90884de
Merge pull request #21 from git-ecosystem/url-escape-fix
mjcheetham Jul 7, 2026
4f4d572
VERSION: bump to 2.9.1
mjcheetham Jul 7, 2026
6760f0e
release: manually force CFS on release builds
mjcheetham Jul 7, 2026
2fe99b8
Merge branch 'sec-release_2.9.0'
mjcheetham Jul 14, 2026
e788575
build(deps): bump github/codeql-action from 4 to 4.37.4
dependabot[bot] Aug 3, 2026
fd1ba4c
build(deps): bump DavidAnson/markdownlint-cli2-action
dependabot[bot] Aug 5, 2026
5887161
lint-docs: explicitly limit permissions to read-only
dscho Aug 14, 2026
b685a11
build(deps): bump lycheeverse/lychee-action from 2.8.0 to 2.9.0
dependabot[bot] Jul 9, 2026
31958be
build(deps): bump github/codeql-action from 4 to 4.37.4 (#2399)
dscho Aug 14, 2026
75419b2
build(deps): bump DavidAnson/markdownlint-cli2-action from 23.0.0 to …
dscho Aug 14, 2026
10f818b
build(deps): bump lycheeverse/lychee-action from 2.8.0 to 2.9.0 (#2374)
dscho Aug 14, 2026
f9ae22b
build(deps): bump github/codeql-action from 4.37.4 to 4.37.6
dependabot[bot] Aug 14, 2026
86e98ce
build(deps): bump github/codeql-action from 4.37.4 to 4.37.6 (#2409)
dscho Aug 15, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
11 changes: 11 additions & 0 deletions .azure-pipelines/nuget.config
Original file line number Diff line number Diff line change
@@ -0,0 +1,11 @@
<?xml version="1.0" encoding="utf-8"?>
<!--
This Nuget config file is only used in release builds to redirect all
NuGet package sources to the Central Feed Services (CFS) feed.
-->
<configuration>
<packageSources>
<clear />
<add key="CFS" value="https://pkgs.dev.azure.com/mseng/1ES/_packaging/1ES_PublicPackages/nuget/v3/index.json" />
</packageSources>
</configuration>
56 changes: 53 additions & 3 deletions .azure-pipelines/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -134,6 +134,15 @@ extends:
artifactName: '${{ dim.runtime }}'
steps:
- checkout: self
- task: CopyFiles@2
displayName: 'Use Central Feed Services (CFS)'
inputs:
SourceFolder: '$(Build.SourcesDirectory)\.azure-pipelines'
Contents: 'nuget.config'
TargetFolder: '$(Build.SourcesDirectory)'
Overwrite: true
- task: NuGetAuthenticate@1
displayName: 'Authenticate to NuGet feeds'
- task: PowerShell@2
displayName: 'Read version file'
inputs:
Expand Down Expand Up @@ -295,12 +304,26 @@ extends:
artifactName: '${{ dim.runtime }}'
steps:
- checkout: self
- task: CopyFiles@2
displayName: 'Use Central Feed Services (CFS)'
inputs:
SourceFolder: '$(Build.SourcesDirectory)/.azure-pipelines'
Contents: 'nuget.config'
TargetFolder: '$(Build.SourcesDirectory)'
Overwrite: true
- task: NuGetAuthenticate@1
displayName: 'Authenticate to NuGet feeds'
- task: Bash@3
displayName: 'Read version file'
inputs:
targetType: inline
script: |
echo "##vso[task.setvariable variable=version;isReadOnly=true]$(cat ./VERSION | sed -E 's/.[0-9]+$//')"
- task: UseDotNet@2
displayName: 'Use .NET 8 SDK (ESRP dependency)'
inputs:
packageType: sdk
version: '8.x'
- task: UseDotNet@2
displayName: 'Use .NET 10 SDK'
inputs:
Expand Down Expand Up @@ -565,12 +588,26 @@ extends:
artifactName: '${{ dim.runtime }}'
steps:
- checkout: self
- task: CopyFiles@2
displayName: 'Use Central Feed Services (CFS)'
inputs:
SourceFolder: '$(Build.SourcesDirectory)/.azure-pipelines'
Contents: 'nuget.config'
TargetFolder: '$(Build.SourcesDirectory)'
Overwrite: true
- task: NuGetAuthenticate@1
displayName: 'Authenticate to NuGet feeds'
- task: Bash@3
displayName: 'Read version file'
inputs:
targetType: inline
script: |
echo "##vso[task.setvariable variable=version;isReadOnly=true]$(cat ./VERSION | sed -E 's/.[0-9]+$//')"
- task: UseDotNet@2
displayName: 'Use .NET 8 SDK (ESRP dependency)'
inputs:
packageType: sdk
version: '8.x'
- task: UseDotNet@2
displayName: 'Use .NET 10 SDK'
inputs:
Expand Down Expand Up @@ -629,7 +666,7 @@ extends:
inlineOperation: |
[
{
"KeyCode": "CP-453387-Pgp",
"KeyCode": "CP-500207-Pgp",
"OperationCode": "LinuxSign",
"ToolName": "sign",
"ToolVersion": "1.0",
Expand Down Expand Up @@ -663,6 +700,15 @@ extends:
artifactName: 'dotnet-tool'
steps:
- checkout: self
- task: CopyFiles@2
displayName: 'Use Central Feed Services (CFS)'
inputs:
SourceFolder: '$(Build.SourcesDirectory)\.azure-pipelines'
Contents: 'nuget.config'
TargetFolder: '$(Build.SourcesDirectory)'
Overwrite: true
- task: NuGetAuthenticate@1
displayName: 'Authenticate to NuGet feeds'
- task: PowerShell@2
displayName: 'Read version file'
inputs:
Expand Down Expand Up @@ -862,9 +908,13 @@ extends:
dependsOn: release_validation
condition: and(succeeded(), eq('${{ parameters.nuget }}', true))
pool:
# Run on Windows so the underlying NuGetCommand@2 task can use the
# native nuget.exe. On Ubuntu 24.04+ the legacy NuGet task fails
# because Mono is no longer available.
# See https://aka.ms/nuget-task-mono.
name: GitClientPME-1ESHostedPool-intel-pc
image: ubuntu-x86_64-ado1es
os: linux
image: win-x86_64-ado1es
os: windows
variables:
version: $[dependencies.release_validation.outputs['version.value']]
templateContext:
Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/codeql-analysis.yml
Original file line number Diff line number Diff line change
Expand Up @@ -22,21 +22,21 @@ jobs:
language: [ 'csharp' ]

steps:
- uses: actions/checkout@v6
- uses: actions/checkout@v7

- name: Setup .NET
uses: actions/setup-dotnet@v5.1.0
uses: actions/setup-dotnet@v5.4.0
with:
dotnet-version: 10.0.x

# Initializes the CodeQL tools for scanning.
- name: Initialize CodeQL
uses: github/codeql-action/init@v4
uses: github/codeql-action/init@v4.37.6
with:
languages: ${{ matrix.language }}

- run: |
dotnet build

- name: Perform CodeQL Analysis
uses: github/codeql-action/analyze@v4
uses: github/codeql-action/analyze@v4.37.6
12 changes: 6 additions & 6 deletions .github/workflows/continuous-integration.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,10 +25,10 @@ jobs:
os: windows-11-arm

steps:
- uses: actions/checkout@v6
- uses: actions/checkout@v7

- name: Setup .NET
uses: actions/setup-dotnet@v5.1.0
uses: actions/setup-dotnet@v5.4.0
with:
dotnet-version: 10.0.x

Expand Down Expand Up @@ -82,10 +82,10 @@ jobs:
runtime: [ linux-x64, linux-arm64, linux-arm ]

steps:
- uses: actions/checkout@v6
- uses: actions/checkout@v7

- name: Setup .NET
uses: actions/setup-dotnet@v5.1.0
uses: actions/setup-dotnet@v5.4.0
with:
dotnet-version: 10.0.x

Expand Down Expand Up @@ -126,10 +126,10 @@ jobs:
runtime: [ osx-x64, osx-arm64 ]

steps:
- uses: actions/checkout@v6
- uses: actions/checkout@v7

- name: Setup .NET
uses: actions/setup-dotnet@v5.1.0
uses: actions/setup-dotnet@v5.4.0
with:
dotnet-version: 10.0.x

Expand Down
11 changes: 7 additions & 4 deletions .github/workflows/lint-docs.yml
Original file line number Diff line number Diff line change
Expand Up @@ -13,14 +13,17 @@ on:
- '**.md'
- '.github/workflows/lint-docs.yml'

permissions:
contents: read

jobs:
lint-markdown:
name: Lint markdown files
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: actions/checkout@v7

- uses: DavidAnson/markdownlint-cli2-action@ce4853d43830c74c1753b39f3cf40f71c2031eb9
- uses: DavidAnson/markdownlint-cli2-action@21c1be1b93ad9ed58fa840aacc3f279cde2a72ff
with:
globs: |
"**/*.md"
Expand All @@ -30,12 +33,12 @@ jobs:
name: Check for broken links
runs-on: ubuntu-latest
steps:
- uses: actions/checkout@v6
- uses: actions/checkout@v7

- name: Run link checker
# For any troubleshooting, see:
# https://github.com/lycheeverse/lychee/blob/master/docs/TROUBLESHOOTING.md
uses: lycheeverse/lychee-action@8646ba30535128ac92d33dfc9133794bfdd9b411
uses: lycheeverse/lychee-action@e7477775783ea5526144ba13e8db5eec57747ce8
with:
# user-agent: if a user agent is not specified, some websites (e.g.
# GitHub Docs) return HTTP errors which Lychee will interpret as
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/maintainer-absence.yml
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,7 @@ jobs:
name: create-issue
runs-on: ubuntu-latest
steps:
- uses: actions/github-script@v8
- uses: actions/github-script@v9
with:
script: |
const startDate = new Date('${{ github.event.inputs.startDate }}');
Expand Down
7 changes: 5 additions & 2 deletions .github/workflows/validate-install-from-source.yml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,9 @@ on:
push:
branches:
- main
pull_request:
branches:
- main

jobs:
docker:
Expand All @@ -15,7 +18,7 @@ jobs:
matrix:
vector:
- image: ubuntu
- image: debian:bullseye
- image: debian:bookworm
- image: fedora
# Centos no longer officially maintains images on Docker Hub. However,
# tgagor is a contributor who pushes updated images weekly, which should
Expand All @@ -42,7 +45,7 @@ jobs:
GNUPGHOME=/root/.gnupg tdnf install tar -y # needed for `actions/checkout`
fi

- uses: actions/checkout@v6
- uses: actions/checkout@v7

- run: |
sh "${GITHUB_WORKSPACE}/src/linux/Packaging.Linux/install-from-source.sh" -y
Expand Down
7 changes: 4 additions & 3 deletions Directory.Packages.props
Original file line number Diff line number Diff line change
Expand Up @@ -14,9 +14,9 @@
<PackageVersion Include="Avalonia.Win32" Version="11.1.3" />

<!-- Microsoft Identity -->
<PackageVersion Include="Microsoft.Identity.Client" Version="4.65.0" />
<PackageVersion Include="Microsoft.Identity.Client.Broker" Version="4.65.0" />
<PackageVersion Include="Microsoft.Identity.Client.Extensions.Msal" Version="4.65.0" />
<PackageVersion Include="Microsoft.Identity.Client" Version="4.84.2" />
<PackageVersion Include="Microsoft.Identity.Client.Broker" Version="4.84.2" />
<PackageVersion Include="Microsoft.Identity.Client.Extensions.Msal" Version="4.84.2" />

<!-- MSBuild -->
<PackageVersion Include="Microsoft.Build.Framework" Version="16.0.461" />
Expand All @@ -25,6 +25,7 @@
<!-- Other -->
<PackageVersion Include="System.CommandLine" Version="2.0.0-beta4.22272.1" />
<PackageVersion Include="System.Text.Json" Version="8.0.5" />
<PackageVersion Include="Tmds.DBus.Protocol" Version="0.21.3" />
<PackageVersion Include="Tools.InnoSetup" Version="6.3.1" GeneratePathProperty="true" />

<!-- Testing -->
Expand Down
2 changes: 1 addition & 1 deletion VERSION
Original file line number Diff line number Diff line change
@@ -1 +1 @@
2.7.3.0
2.9.1.0
2 changes: 1 addition & 1 deletion docs/credstores.md
Original file line number Diff line number Diff line change
Expand Up @@ -277,7 +277,7 @@ Note that you'll want to ensure that another credential helper is placed before
GCM in the `credential.helper` Git configuration or else you will be prompted to
enter your credentials every time you interact with a remote repository.

[access-windows-credential-manager]: https://support.microsoft.com/en-us/windows/accessing-credential-manager-1b5c916a-6a16-889f-8581-fc16e8165ac0
[access-windows-credential-manager]: https://support.microsoft.com/en-US/Windows/Security/credential-manager-in-windows
[aws-cloudshell]: https://aws.amazon.com/cloudshell/
[azure-cloudshell]: https://docs.microsoft.com/azure/cloud-shell/overview
[cmdkey]: https://docs.microsoft.com/en-us/windows-server/administration/windows-commands/cmdkey
Expand Down
24 changes: 24 additions & 0 deletions docs/generic-oauth.md
Original file line number Diff line number Diff line change
Expand Up @@ -42,6 +42,7 @@ following values in your Git configuration:
- Client Secret (optional)
- Redirect URL (optional, defaults to `http://127.0.0.1`)
- Scopes (optional)
- Response Mode (optional, defaults to `query`)
- OAuth Endpoints
- Authorization Endpoint
- Token Endpoint
Expand All @@ -62,6 +63,7 @@ git config --global credential.<HOST>.oauthAuthorizeEndpoint <AuthEndpoint>
git config --global credential.<HOST>.oauthTokenEndpoint <TokenEndpoint>
git config --global credential.<HOST>.oauthScopes <Scopes>
git config --global credential.<HOST>.oauthDeviceEndpoint <DeviceEndpoint>
git config --global credential.<HOST>.oauthResponseMode <ResponseMode>
```

**Example commands:**
Expand All @@ -83,13 +85,35 @@ git config --global credential.<HOST>.oauthDeviceEndpoint <DeviceEndpoint>
oauthScopes = "code:write profile:read"
oauthDefaultUserName = "OAUTH"
oauthUseClientAuthHeader = false
oauthResponseMode = "query"
```

### Additional configuration

Depending on the specific implementation of OAuth with your Git host you may
also need to specify additional behavior.

#### Response mode

The response mode controls how the authorization server returns the response to
the loopback redirect URI once the user has authenticated. GCM supports the
following values:

- `query` (default) - parameters are returned in the redirect URI query string.
- `fragment` - parameters are returned in the redirect URI fragment.
- `form_post` - parameters are returned as an auto-submitting HTML form that is
POSTed to the redirect URI, as described by the
[OAuth 2.0 Form Post Response Mode][form-post-spec] specification.

Most hosts use the default `query` mode. Only set this if your host requires a
specific response mode:

```shell
git config --global credential.<HOST>.oauthResponseMode <query|fragment|form_post>
```

[form-post-spec]: https://openid.net/specs/oauth-v2-form-post-response-mode-1_0.html

#### Token user name

If your Git host requires that you specify a username to use with OAuth tokens
Expand Down
2 changes: 1 addition & 1 deletion docs/github-apideprecation.md
Original file line number Diff line number Diff line change
Expand Up @@ -143,6 +143,6 @@ the new token-based authentication requirements **DO NOT** apply to GHES:
[windows-cli-save-pat-image]: img/windows-cli-save-pat.png
[vs-2019]: https://docs.microsoft.com/en-us/visualstudio/install/update-visual-studio?view=vs-2019
[vs-2017]: https://docs.microsoft.com/en-us/visualstudio/install/update-visual-studio?view=vs-2017
[windows-credential-manager]: https://support.microsoft.com/en-us/windows/accessing-credential-manager-1b5c916a-6a16-889f-8581-fc16e8165ac0
[windows-credential-manager]: https://support.microsoft.com/en-US/Windows/Security/credential-manager-in-windows
[windows-gui-add-pat-image]: img/windows-gui-add-pat.png
[windows-gui-credentials-image]: img/windows-gui-credentials.png
2 changes: 1 addition & 1 deletion docs/install.md
Original file line number Diff line number Diff line change
Expand Up @@ -210,7 +210,7 @@ the preferred install method for Linux because you can use it to install on any
distribution][dotnet-supported-distributions]. You
can also use this method on macOS if you so choose.

**Note:** Make sure you have installed [version 8.0 of the .NET
**Note:** Make sure you have installed [version 10.0 of the .NET
SDK][dotnet-install] before attempting to run the following `dotnet tool`
commands. After installing, you will also need to follow the output instructions
to add the tools directory to your `PATH`.
Expand Down
Loading
Loading