Skip to content

Upgrade to libgit2 v1.9.7 to fix CVE-2026-5917 #992

Description

@AHSauge

https://github.com/libgit2/libgit2/releases/tag/v1.9.7 fixes CVE-2026-5917, a critical level severity issue in libgit2 related to remote code execution

Prior releases such as v1.9.5 also fix security issues in libgit2. Given that this is a bundled dependency, it requires an update in Gittyup itself unless USE_SYSTEM_LIBGIT2=ON is used.
@Murmele Would it be possible to release an update here?

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions