<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
		<title>GitHub Enterprise Releases</title>
		<description>GitHub Enterprise Releases available for download</description>
		<link>https://enterprise.github.com/releases</link>
		
		
			
		  
				<item>
					<title>3.20.3</title>
					<description></description>
					<pubDate>Tue, 26 May 2026 16:03:20 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.20.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.20.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.19.7</title>
					<description></description>
					<pubDate>Tue, 26 May 2026 16:03:19 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.19.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.19.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.18.10</title>
					<description></description>
					<pubDate>Tue, 26 May 2026 16:03:18 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.18.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.18.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.17.16</title>
					<description></description>
					<pubDate>Tue, 26 May 2026 16:03:17 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.17.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.17.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.16.19</title>
					<description></description>
					<pubDate>Tue, 26 May 2026 16:03:16 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.16.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.16.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.21.0</title>
					<description></description>
					<pubDate>Tue, 12 May 2026 16:03:21 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.21.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.21.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.20.2</title>
					<description></description>
					<pubDate>Thu, 07 May 2026 16:03:20 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.20.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.20.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.19.6</title>
					<description></description>
					<pubDate>Thu, 07 May 2026 16:03:19 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.19.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.19.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.18.9</title>
					<description></description>
					<pubDate>Thu, 07 May 2026 16:03:18 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.18.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.18.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.17.15</title>
					<description></description>
					<pubDate>Thu, 07 May 2026 16:03:17 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.17.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.17.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.16.18</title>
					<description></description>
					<pubDate>Thu, 07 May 2026 16:03:16 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.16.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.16.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.20.1</title>
					<description></description>
					<pubDate>Tue, 21 Apr 2026 16:03:20 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.20.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.20.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.19.5</title>
					<description></description>
					<pubDate>Tue, 21 Apr 2026 16:03:19 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.19.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.19.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.18.8</title>
					<description></description>
					<pubDate>Tue, 21 Apr 2026 16:03:18 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.18.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.18.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.17.14</title>
					<description></description>
					<pubDate>Tue, 21 Apr 2026 16:03:17 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.17.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.17.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.16.17</title>
					<description></description>
					<pubDate>Tue, 21 Apr 2026 16:03:16 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.16.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.16.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.15.21</title>
					<description></description>
					<pubDate>Tue, 21 Apr 2026 16:03:15 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.15.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.15.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.26</title>
					<description></description>
					<pubDate>Tue, 21 Apr 2026 16:03:14 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.26</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.26</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.20.0</title>
					<description></description>
					<pubDate>Tue, 17 Mar 2026 16:03:20 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.20.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.20.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.19.4</title>
					<description></description>
					<pubDate>Fri, 13 Mar 2026 08:00:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.19.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.19.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.18.7</title>
					<description></description>
					<pubDate>Fri, 13 Mar 2026 08:00:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.18.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.18.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.17.13</title>
					<description></description>
					<pubDate>Fri, 13 Mar 2026 08:00:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.17.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.17.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.16.16</title>
					<description></description>
					<pubDate>Fri, 13 Mar 2026 08:00:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.16.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.16.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.15.20</title>
					<description></description>
					<pubDate>Fri, 13 Mar 2026 08:00:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.15.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.15.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.25</title>
					<description></description>
					<pubDate>Fri, 13 Mar 2026 08:00:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.25</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.25</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.19.2</title>
					<description></description>
					<pubDate>Tue, 10 Feb 2026 16:03:19 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.19.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.19.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.18.5</title>
					<description></description>
					<pubDate>Tue, 10 Feb 2026 16:03:18 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.18.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.18.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.17.11</title>
					<description></description>
					<pubDate>Tue, 10 Feb 2026 16:03:17 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.17.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.17.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.16.14</title>
					<description></description>
					<pubDate>Tue, 10 Feb 2026 16:03:16 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.16.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.16.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.15.18</title>
					<description></description>
					<pubDate>Tue, 10 Feb 2026 16:03:15 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.15.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.15.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.23</title>
					<description></description>
					<pubDate>Tue, 10 Feb 2026 16:03:14 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.23</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.23</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.19.1</title>
					<description></description>
					<pubDate>Tue, 06 Jan 2026 16:03:19 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.19.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.19.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.18.4</title>
					<description></description>
					<pubDate>Tue, 06 Jan 2026 16:03:18 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.18.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.18.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.17.10</title>
					<description></description>
					<pubDate>Tue, 06 Jan 2026 16:03:17 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.17.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.17.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.16.13</title>
					<description></description>
					<pubDate>Tue, 06 Jan 2026 16:03:16 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.16.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.16.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.15.17</title>
					<description></description>
					<pubDate>Tue, 06 Jan 2026 16:03:15 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.15.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.15.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.22</title>
					<description></description>
					<pubDate>Tue, 06 Jan 2026 16:03:14 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.19.0</title>
					<description></description>
					<pubDate>Tue, 09 Dec 2025 16:03:19 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.19.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.19.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.18.3</title>
					<description></description>
					<pubDate>Tue, 09 Dec 2025 16:03:18 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.18.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.18.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.17.9</title>
					<description></description>
					<pubDate>Tue, 09 Dec 2025 16:03:17 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.17.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.17.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.16.12</title>
					<description></description>
					<pubDate>Tue, 09 Dec 2025 16:03:16 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.16.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.16.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.15.16</title>
					<description></description>
					<pubDate>Tue, 09 Dec 2025 16:03:15 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.15.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.15.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.21</title>
					<description></description>
					<pubDate>Tue, 09 Dec 2025 16:03:14 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.18.2</title>
					<description></description>
					<pubDate>Tue, 02 Dec 2025 16:03:18 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.18.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.18.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.17.8</title>
					<description></description>
					<pubDate>Tue, 02 Dec 2025 16:03:17 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.17.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.17.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.16.11</title>
					<description></description>
					<pubDate>Tue, 02 Dec 2025 16:03:16 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.16.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.16.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.15.15</title>
					<description></description>
					<pubDate>Tue, 02 Dec 2025 16:03:15 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.15.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.15.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.20</title>
					<description></description>
					<pubDate>Tue, 02 Dec 2025 16:03:14 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.18.1</title>
					<description></description>
					<pubDate>Mon, 10 Nov 2025 20:00:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.18.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.18.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.17.7</title>
					<description></description>
					<pubDate>Mon, 10 Nov 2025 20:00:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.17.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.17.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.16.10</title>
					<description></description>
					<pubDate>Mon, 10 Nov 2025 20:00:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.16.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.16.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.15.14</title>
					<description></description>
					<pubDate>Mon, 10 Nov 2025 20:00:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.15.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.15.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.19</title>
					<description></description>
					<pubDate>Mon, 10 Nov 2025 20:00:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.18.0</title>
					<description></description>
					<pubDate>Tue, 14 Oct 2025 16:03:18 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.18.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.18.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.17.6</title>
					<description></description>
					<pubDate>Tue, 09 Sep 2025 16:03:17 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.17.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.17.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.16.9</title>
					<description></description>
					<pubDate>Tue, 09 Sep 2025 16:03:16 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.16.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.16.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.15.13</title>
					<description></description>
					<pubDate>Tue, 09 Sep 2025 16:03:15 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.15.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.15.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.18</title>
					<description></description>
					<pubDate>Tue, 09 Sep 2025 16:03:14 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.17.5</title>
					<description></description>
					<pubDate>Mon, 25 Aug 2025 12:00:00 -0700</pubDate>
					<link>https://enterprise.github.com/releases/3.17.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.17.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.16.8</title>
					<description></description>
					<pubDate>Mon, 25 Aug 2025 12:00:00 -0700</pubDate>
					<link>https://enterprise.github.com/releases/3.16.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.16.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.15.12</title>
					<description></description>
					<pubDate>Mon, 25 Aug 2025 12:00:00 -0700</pubDate>
					<link>https://enterprise.github.com/releases/3.15.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.15.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.17</title>
					<description></description>
					<pubDate>Mon, 25 Aug 2025 12:00:00 -0700</pubDate>
					<link>https://enterprise.github.com/releases/3.14.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.17.4</title>
					<description></description>
					<pubDate>Tue, 29 Jul 2025 16:03:17 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.17.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.17.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.16.7</title>
					<description></description>
					<pubDate>Tue, 29 Jul 2025 16:03:16 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.16.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.16.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.15.11</title>
					<description></description>
					<pubDate>Tue, 29 Jul 2025 16:03:15 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.15.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.15.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.16</title>
					<description></description>
					<pubDate>Tue, 29 Jul 2025 16:03:14 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.17.3</title>
					<description></description>
					<pubDate>Tue, 15 Jul 2025 16:03:17 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.17.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.17.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.16.6</title>
					<description></description>
					<pubDate>Tue, 15 Jul 2025 16:03:16 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.16.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.16.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.15.10</title>
					<description></description>
					<pubDate>Tue, 15 Jul 2025 16:03:15 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.15.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.15.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.15</title>
					<description></description>
					<pubDate>Tue, 15 Jul 2025 16:03:14 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.17.2</title>
					<description></description>
					<pubDate>Tue, 01 Jul 2025 16:03:17 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.17.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.17.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.16.5</title>
					<description></description>
					<pubDate>Tue, 01 Jul 2025 16:03:16 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.16.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.16.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.15.9</title>
					<description></description>
					<pubDate>Tue, 01 Jul 2025 16:03:15 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.15.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.15.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.14</title>
					<description></description>
					<pubDate>Tue, 01 Jul 2025 16:03:14 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.17.1</title>
					<description></description>
					<pubDate>Wed, 18 Jun 2025 16:03:17 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.17.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.17.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.16.4</title>
					<description></description>
					<pubDate>Wed, 18 Jun 2025 16:03:16 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.16.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.16.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.15.8</title>
					<description></description>
					<pubDate>Wed, 18 Jun 2025 16:03:15 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.15.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.15.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.13</title>
					<description></description>
					<pubDate>Wed, 18 Jun 2025 16:03:14 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.13.16</title>
					<description></description>
					<pubDate>Wed, 18 Jun 2025 16:03:13 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.13.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.13.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.17.0</title>
					<description></description>
					<pubDate>Tue, 03 Jun 2025 16:03:17 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.17.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.17.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.16.3</title>
					<description></description>
					<pubDate>Tue, 27 May 2025 16:03:16 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.16.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.16.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.15.7</title>
					<description></description>
					<pubDate>Tue, 27 May 2025 16:03:15 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.15.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.15.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.12</title>
					<description></description>
					<pubDate>Tue, 27 May 2025 16:03:14 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.13.15</title>
					<description></description>
					<pubDate>Tue, 27 May 2025 16:03:13 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.13.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.13.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.16.2</title>
					<description></description>
					<pubDate>Thu, 17 Apr 2025 16:03:16 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.16.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.16.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.15.6</title>
					<description></description>
					<pubDate>Thu, 17 Apr 2025 16:03:15 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.15.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.15.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.11</title>
					<description></description>
					<pubDate>Thu, 17 Apr 2025 16:03:14 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.13.14</title>
					<description></description>
					<pubDate>Thu, 17 Apr 2025 16:03:13 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.13.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.13.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.16.1</title>
					<description></description>
					<pubDate>Tue, 25 Mar 2025 16:03:16 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.16.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.16.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.15.5</title>
					<description></description>
					<pubDate>Tue, 25 Mar 2025 16:03:15 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.15.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.15.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.10</title>
					<description></description>
					<pubDate>Tue, 25 Mar 2025 16:03:14 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.13.13</title>
					<description></description>
					<pubDate>Tue, 25 Mar 2025 16:03:13 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.13.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.13.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.12.17</title>
					<description></description>
					<pubDate>Tue, 25 Mar 2025 16:03:12 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.12.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.12.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.16.0</title>
					<description></description>
					<pubDate>Tue, 11 Mar 2025 16:00:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.16.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.16.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.15.4</title>
					<description></description>
					<pubDate>Tue, 04 Mar 2025 16:03:15 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.15.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.15.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.9</title>
					<description></description>
					<pubDate>Tue, 04 Mar 2025 16:03:14 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.13.12</title>
					<description></description>
					<pubDate>Tue, 04 Mar 2025 16:03:13 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.13.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.13.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.12.16</title>
					<description></description>
					<pubDate>Tue, 04 Mar 2025 16:03:12 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.12.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.12.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.15.3</title>
					<description></description>
					<pubDate>Tue, 18 Feb 2025 16:03:15 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.15.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.15.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.8</title>
					<description></description>
					<pubDate>Tue, 18 Feb 2025 16:03:14 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.13.11</title>
					<description></description>
					<pubDate>Tue, 18 Feb 2025 16:03:13 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.13.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.13.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.12.15</title>
					<description></description>
					<pubDate>Tue, 18 Feb 2025 16:03:12 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.12.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.12.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.15.2</title>
					<description></description>
					<pubDate>Tue, 21 Jan 2025 16:03:15 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.15.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.15.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.7</title>
					<description></description>
					<pubDate>Tue, 21 Jan 2025 16:03:14 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.13.10</title>
					<description></description>
					<pubDate>Tue, 21 Jan 2025 16:03:13 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.13.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.13.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.12.14</title>
					<description></description>
					<pubDate>Tue, 21 Jan 2025 16:03:12 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.12.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.12.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.15.1</title>
					<description></description>
					<pubDate>Tue, 17 Dec 2024 16:03:15 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.15.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.15.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.6</title>
					<description></description>
					<pubDate>Tue, 17 Dec 2024 16:03:14 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.13.9</title>
					<description></description>
					<pubDate>Tue, 17 Dec 2024 16:03:13 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.13.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.13.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.12.13</title>
					<description></description>
					<pubDate>Tue, 17 Dec 2024 16:03:12 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.12.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.12.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.11.19</title>
					<description></description>
					<pubDate>Tue, 17 Dec 2024 16:03:11 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.11.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.11.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.15.0</title>
					<description></description>
					<pubDate>Tue, 03 Dec 2024 16:03:15 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.15.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.15.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.5</title>
					<description></description>
					<pubDate>Tue, 03 Dec 2024 16:03:14 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.13.8</title>
					<description></description>
					<pubDate>Tue, 03 Dec 2024 16:03:13 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.13.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.13.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.12.12</title>
					<description></description>
					<pubDate>Tue, 03 Dec 2024 16:03:12 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.12.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.12.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.11.18</title>
					<description></description>
					<pubDate>Tue, 03 Dec 2024 16:03:11 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.11.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.11.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.4</title>
					<description></description>
					<pubDate>Thu, 24 Oct 2024 16:03:14 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.3</title>
					<description></description>
					<pubDate>Thu, 24 Oct 2024 16:03:14 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.13.7</title>
					<description></description>
					<pubDate>Thu, 24 Oct 2024 16:03:13 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.13.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.13.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.13.6</title>
					<description></description>
					<pubDate>Thu, 24 Oct 2024 16:03:13 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.13.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.13.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.12.11</title>
					<description></description>
					<pubDate>Thu, 24 Oct 2024 16:03:12 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.12.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.12.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.11.17</title>
					<description></description>
					<pubDate>Thu, 24 Oct 2024 16:03:11 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.11.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.11.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.2</title>
					<description></description>
					<pubDate>Thu, 10 Oct 2024 16:03:14 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.13.5</title>
					<description></description>
					<pubDate>Thu, 10 Oct 2024 16:03:13 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.13.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.13.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.12.10</title>
					<description></description>
					<pubDate>Thu, 10 Oct 2024 16:03:12 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.12.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.12.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.11.16</title>
					<description></description>
					<pubDate>Thu, 10 Oct 2024 16:03:11 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.11.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.11.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.1</title>
					<description></description>
					<pubDate>Mon, 23 Sep 2024 16:03:14 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.13.4</title>
					<description></description>
					<pubDate>Mon, 23 Sep 2024 16:03:13 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.13.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.13.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.12.9</title>
					<description></description>
					<pubDate>Mon, 23 Sep 2024 16:03:12 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.12.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.12.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.11.15</title>
					<description></description>
					<pubDate>Mon, 23 Sep 2024 16:03:11 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.11.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.11.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.10.17</title>
					<description></description>
					<pubDate>Mon, 23 Sep 2024 16:03:10 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.10.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.10.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.14.0</title>
					<description></description>
					<pubDate>Tue, 27 Aug 2024 16:03:14 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.14.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.14.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.13.3</title>
					<description></description>
					<pubDate>Tue, 20 Aug 2024 16:03:13 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.13.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.13.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.12.8</title>
					<description></description>
					<pubDate>Tue, 20 Aug 2024 16:03:12 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.12.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.12.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.11.14</title>
					<description></description>
					<pubDate>Tue, 20 Aug 2024 16:03:11 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.11.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.11.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.10.16</title>
					<description></description>
					<pubDate>Tue, 20 Aug 2024 16:03:10 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.10.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.10.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.13.2</title>
					<description></description>
					<pubDate>Wed, 17 Jul 2024 16:03:13 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.13.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.13.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.12.7</title>
					<description></description>
					<pubDate>Wed, 17 Jul 2024 16:03:12 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.12.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.12.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.11.13</title>
					<description></description>
					<pubDate>Wed, 17 Jul 2024 16:03:11 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.11.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.11.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.10.15</title>
					<description></description>
					<pubDate>Wed, 17 Jul 2024 16:03:10 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.10.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.10.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.9.18</title>
					<description></description>
					<pubDate>Wed, 17 Jul 2024 16:03:09 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.9.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.9.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.13.0</title>
					<description></description>
					<pubDate>Tue, 18 Jun 2024 16:03:13 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.13.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.13.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.12.5</title>
					<description></description>
					<pubDate>Tue, 18 Jun 2024 16:03:12 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.12.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.12.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.11.11</title>
					<description></description>
					<pubDate>Tue, 18 Jun 2024 16:03:11 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.11.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.11.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.10.13</title>
					<description></description>
					<pubDate>Tue, 18 Jun 2024 16:03:10 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.10.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.10.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.9.16</title>
					<description></description>
					<pubDate>Tue, 18 Jun 2024 16:03:09 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.9.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.9.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.12.4</title>
					<description></description>
					<pubDate>Mon, 20 May 2024 21:00:12 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.12.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.12.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.11.10</title>
					<description></description>
					<pubDate>Mon, 20 May 2024 21:00:11 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.11.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.11.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.10.12</title>
					<description></description>
					<pubDate>Mon, 20 May 2024 21:00:10 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.10.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.10.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.9.15</title>
					<description></description>
					<pubDate>Mon, 20 May 2024 21:00:09 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.9.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.9.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.12.3</title>
					<description></description>
					<pubDate>Wed, 08 May 2024 16:03:12 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.12.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.12.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.11.9</title>
					<description></description>
					<pubDate>Wed, 08 May 2024 16:03:11 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.11.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.11.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.10.11</title>
					<description></description>
					<pubDate>Wed, 08 May 2024 16:03:10 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.10.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.10.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.9.14</title>
					<description></description>
					<pubDate>Wed, 08 May 2024 16:03:09 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.9.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.9.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.12.2</title>
					<description></description>
					<pubDate>Thu, 18 Apr 2024 16:03:12 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.12.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.12.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.11.8</title>
					<description></description>
					<pubDate>Thu, 18 Apr 2024 16:03:11 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.11.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.11.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.10.10</title>
					<description></description>
					<pubDate>Thu, 18 Apr 2024 16:03:10 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.10.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.10.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.9.13</title>
					<description></description>
					<pubDate>Thu, 18 Apr 2024 16:03:09 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.9.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.9.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.12.1</title>
					<description></description>
					<pubDate>Wed, 20 Mar 2024 16:03:12 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.12.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.12.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.11.7</title>
					<description></description>
					<pubDate>Wed, 20 Mar 2024 16:03:11 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.11.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.11.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.10.9</title>
					<description></description>
					<pubDate>Wed, 20 Mar 2024 16:03:10 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.10.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.10.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.9.12</title>
					<description></description>
					<pubDate>Wed, 20 Mar 2024 16:03:09 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.9.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.9.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.8.17</title>
					<description></description>
					<pubDate>Wed, 20 Mar 2024 16:03:08 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.8.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.8.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.12.0</title>
					<description></description>
					<pubDate>Tue, 05 Mar 2024 16:03:12 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.12.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.12.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.11.6</title>
					<description></description>
					<pubDate>Thu, 29 Feb 2024 16:03:11 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.11.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.11.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.10.8</title>
					<description></description>
					<pubDate>Thu, 29 Feb 2024 16:03:10 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.10.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.10.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.9.11</title>
					<description></description>
					<pubDate>Thu, 29 Feb 2024 16:03:09 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.9.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.9.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.8.16</title>
					<description></description>
					<pubDate>Thu, 29 Feb 2024 16:03:08 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.8.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.8.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.11.5</title>
					<description></description>
					<pubDate>Tue, 13 Feb 2024 16:03:11 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.11.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.11.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.10.7</title>
					<description></description>
					<pubDate>Tue, 13 Feb 2024 16:03:10 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.10.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.10.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.9.10</title>
					<description></description>
					<pubDate>Tue, 13 Feb 2024 16:03:09 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.9.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.9.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.8.15</title>
					<description></description>
					<pubDate>Tue, 13 Feb 2024 16:03:08 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.8.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.8.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.11.4</title>
					<description></description>
					<pubDate>Tue, 30 Jan 2024 16:03:11 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.11.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.11.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.10.6</title>
					<description></description>
					<pubDate>Tue, 30 Jan 2024 16:03:10 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.10.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.10.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.9.9</title>
					<description></description>
					<pubDate>Tue, 30 Jan 2024 16:03:09 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.9.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.9.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.8.14</title>
					<description></description>
					<pubDate>Tue, 30 Jan 2024 16:03:08 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.8.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.8.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.11.3</title>
					<description></description>
					<pubDate>Tue, 16 Jan 2024 16:03:11 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.11.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.11.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.10.5</title>
					<description></description>
					<pubDate>Tue, 16 Jan 2024 16:03:10 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.10.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.10.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.9.8</title>
					<description></description>
					<pubDate>Tue, 16 Jan 2024 16:03:09 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.9.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.9.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.8.13</title>
					<description></description>
					<pubDate>Tue, 16 Jan 2024 16:03:08 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.8.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.8.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.11.2</title>
					<description></description>
					<pubDate>Wed, 27 Dec 2023 16:03:11 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.11.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.11.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.11.1</title>
					<description></description>
					<pubDate>Thu, 21 Dec 2023 16:03:11 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.11.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.11.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.10.4</title>
					<description></description>
					<pubDate>Thu, 21 Dec 2023 16:03:10 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.10.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.10.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.9.7</title>
					<description></description>
					<pubDate>Thu, 21 Dec 2023 16:03:09 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.9.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.9.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.8.12</title>
					<description></description>
					<pubDate>Thu, 21 Dec 2023 16:03:08 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.8.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.8.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.7.19</title>
					<description></description>
					<pubDate>Thu, 21 Dec 2023 16:03:07 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.7.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.7.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.11.0</title>
					<description></description>
					<pubDate>Tue, 05 Dec 2023 16:03:11 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.11.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.11.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.10.3</title>
					<description></description>
					<pubDate>Thu, 12 Oct 2023 16:03:10 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.10.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.10.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.9.6</title>
					<description></description>
					<pubDate>Thu, 12 Oct 2023 16:03:09 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.9.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.9.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.8.11</title>
					<description></description>
					<pubDate>Thu, 12 Oct 2023 16:03:08 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.8.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.8.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.7.18</title>
					<description></description>
					<pubDate>Thu, 12 Oct 2023 16:03:07 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.7.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.7.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.10.2</title>
					<description></description>
					<pubDate>Fri, 22 Sep 2023 16:03:10 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.10.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.10.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.10.1</title>
					<description></description>
					<pubDate>Thu, 21 Sep 2023 16:03:10 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.10.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.10.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.9.5</title>
					<description></description>
					<pubDate>Thu, 21 Sep 2023 16:03:09 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.9.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.9.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.8.10</title>
					<description></description>
					<pubDate>Thu, 21 Sep 2023 16:03:08 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.8.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.8.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.7.17</title>
					<description></description>
					<pubDate>Thu, 21 Sep 2023 16:03:07 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.7.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.7.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.6.19</title>
					<description></description>
					<pubDate>Thu, 21 Sep 2023 16:03:06 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.6.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.6.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.10.0</title>
					<description></description>
					<pubDate>Tue, 29 Aug 2023 16:03:10 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.10.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.10.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.9.4</title>
					<description></description>
					<pubDate>Mon, 28 Aug 2023 16:03:09 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.9.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.9.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.8.9</title>
					<description></description>
					<pubDate>Mon, 28 Aug 2023 16:03:08 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.8.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.8.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.7.16</title>
					<description></description>
					<pubDate>Mon, 28 Aug 2023 16:03:07 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.7.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.7.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.6.18</title>
					<description></description>
					<pubDate>Mon, 28 Aug 2023 16:03:06 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.6.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.6.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.9.3</title>
					<description></description>
					<pubDate>Thu, 10 Aug 2023 16:03:09 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.9.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.9.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.8.8</title>
					<description></description>
					<pubDate>Thu, 10 Aug 2023 16:03:07 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.8.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.8.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.7.15</title>
					<description></description>
					<pubDate>Thu, 10 Aug 2023 16:03:07 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.7.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.7.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.6.17</title>
					<description></description>
					<pubDate>Thu, 10 Aug 2023 16:03:06 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.6.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.6.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.9.2</title>
					<description></description>
					<pubDate>Fri, 28 Jul 2023 16:03:08 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.9.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.9.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.8.7</title>
					<description></description>
					<pubDate>Fri, 28 Jul 2023 16:03:08 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.8.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.8.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.7.14</title>
					<description></description>
					<pubDate>Fri, 28 Jul 2023 16:03:08 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.7.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.7.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.9.1</title>
					<description></description>
					<pubDate>Tue, 18 Jul 2023 16:03:09 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.9.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.9.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.8.6</title>
					<description></description>
					<pubDate>Tue, 18 Jul 2023 16:03:08 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.8.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.8.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.7.13</title>
					<description></description>
					<pubDate>Tue, 18 Jul 2023 16:03:07 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.7.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.7.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.6.16</title>
					<description></description>
					<pubDate>Tue, 18 Jul 2023 16:03:06 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.6.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.6.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.9.0</title>
					<description></description>
					<pubDate>Thu, 29 Jun 2023 18:41:15 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.9.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.9.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.8.5</title>
					<description></description>
					<pubDate>Tue, 20 Jun 2023 16:03:08 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.8.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.8.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.7.12</title>
					<description></description>
					<pubDate>Tue, 20 Jun 2023 16:03:07 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.7.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.7.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.6.15</title>
					<description></description>
					<pubDate>Tue, 20 Jun 2023 16:03:06 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.6.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.6.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.5.19</title>
					<description></description>
					<pubDate>Tue, 20 Jun 2023 16:03:05 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.5.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.5.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.8.4</title>
					<description></description>
					<pubDate>Tue, 30 May 2023 16:03:08 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.8.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.8.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.7.11</title>
					<description></description>
					<pubDate>Tue, 30 May 2023 16:03:07 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.7.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.7.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.6.14</title>
					<description></description>
					<pubDate>Tue, 30 May 2023 16:03:06 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.6.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.6.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.5.18</title>
					<description></description>
					<pubDate>Tue, 30 May 2023 16:03:05 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.5.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.5.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.8.3</title>
					<description></description>
					<pubDate>Tue, 09 May 2023 16:03:08 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.8.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.8.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.7.10</title>
					<description></description>
					<pubDate>Tue, 09 May 2023 16:03:07 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.7.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.7.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.6.13</title>
					<description></description>
					<pubDate>Tue, 09 May 2023 16:03:06 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.6.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.6.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.5.17</title>
					<description></description>
					<pubDate>Tue, 09 May 2023 16:03:05 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.5.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.5.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.8.2</title>
					<description></description>
					<pubDate>Tue, 18 Apr 2023 16:03:08 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.8.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.8.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.5.16</title>
					<description></description>
					<pubDate>Tue, 18 Apr 2023 16:03:08 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.5.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.5.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.7.9</title>
					<description></description>
					<pubDate>Tue, 18 Apr 2023 16:03:07 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.7.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.7.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.6.12</title>
					<description></description>
					<pubDate>Tue, 18 Apr 2023 16:03:06 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.6.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.6.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.8.1</title>
					<description></description>
					<pubDate>Thu, 23 Mar 2023 16:03:08 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.8.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.8.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.7.8</title>
					<description></description>
					<pubDate>Thu, 23 Mar 2023 16:03:07 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.7.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.7.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.6.11</title>
					<description></description>
					<pubDate>Thu, 23 Mar 2023 16:03:06 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.6.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.6.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.5.15</title>
					<description></description>
					<pubDate>Thu, 23 Mar 2023 16:03:05 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.5.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.5.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.4.18</title>
					<description></description>
					<pubDate>Thu, 23 Mar 2023 16:03:04 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.4.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.4.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.8.0</title>
					<description></description>
					<pubDate>Tue, 07 Mar 2023 16:03:08 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.8.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.8.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.7.7</title>
					<description></description>
					<pubDate>Thu, 02 Mar 2023 16:03:07 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.7.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.7.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.6.10</title>
					<description></description>
					<pubDate>Thu, 02 Mar 2023 16:03:06 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.6.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.6.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.5.14</title>
					<description></description>
					<pubDate>Thu, 02 Mar 2023 16:03:05 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.5.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.5.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.4.17</title>
					<description></description>
					<pubDate>Thu, 02 Mar 2023 16:03:04 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.4.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.4.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.7.6</title>
					<description></description>
					<pubDate>Thu, 16 Feb 2023 16:03:07 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.7.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.7.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.6.9</title>
					<description></description>
					<pubDate>Thu, 16 Feb 2023 16:03:06 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.6.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.6.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.5.13</title>
					<description></description>
					<pubDate>Thu, 16 Feb 2023 16:03:05 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.5.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.5.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.4.16</title>
					<description></description>
					<pubDate>Thu, 16 Feb 2023 16:03:04 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.4.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.4.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.7.5</title>
					<description></description>
					<pubDate>Thu, 02 Feb 2023 16:03:07 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.7.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.7.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.6.8</title>
					<description></description>
					<pubDate>Thu, 02 Feb 2023 16:03:06 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.6.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.6.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.5.12</title>
					<description></description>
					<pubDate>Thu, 02 Feb 2023 16:03:05 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.5.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.5.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.4.15</title>
					<description></description>
					<pubDate>Thu, 02 Feb 2023 16:03:04 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.4.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.4.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.7.4</title>
					<description></description>
					<pubDate>Tue, 17 Jan 2023 16:03:07 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.7.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.7.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.6.7</title>
					<description></description>
					<pubDate>Tue, 17 Jan 2023 16:03:06 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.6.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.6.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.5.11</title>
					<description></description>
					<pubDate>Tue, 17 Jan 2023 16:03:05 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.5.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.5.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.4.14</title>
					<description></description>
					<pubDate>Tue, 17 Jan 2023 16:03:04 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.4.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.4.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.3.19</title>
					<description></description>
					<pubDate>Tue, 17 Jan 2023 16:03:03 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.3.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.3.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.7.3</title>
					<description></description>
					<pubDate>Thu, 12 Jan 2023 16:03:07 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.7.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.7.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.6.6</title>
					<description></description>
					<pubDate>Thu, 12 Jan 2023 16:03:06 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.6.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.6.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.5.10</title>
					<description></description>
					<pubDate>Thu, 12 Jan 2023 16:03:05 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.5.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.5.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.4.13</title>
					<description></description>
					<pubDate>Thu, 12 Jan 2023 16:03:04 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.4.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.4.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.3.18</title>
					<description></description>
					<pubDate>Thu, 12 Jan 2023 16:03:03 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.3.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.3.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.7.2</title>
					<description></description>
					<pubDate>Tue, 13 Dec 2022 16:03:07 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.7.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.7.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.6.5</title>
					<description></description>
					<pubDate>Tue, 13 Dec 2022 16:03:06 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.6.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.6.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.5.9</title>
					<description></description>
					<pubDate>Tue, 13 Dec 2022 16:03:05 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.5.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.5.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.4.12</title>
					<description></description>
					<pubDate>Tue, 13 Dec 2022 16:03:04 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.4.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.4.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.3.17</title>
					<description></description>
					<pubDate>Tue, 13 Dec 2022 16:03:03 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.3.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.3.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.7.1</title>
					<description></description>
					<pubDate>Tue, 22 Nov 2022 16:03:07 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.7.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.7.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.6.4</title>
					<description></description>
					<pubDate>Tue, 22 Nov 2022 16:03:06 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.6.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.6.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.5.8</title>
					<description></description>
					<pubDate>Tue, 22 Nov 2022 16:03:05 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.5.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.5.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.4.11</title>
					<description></description>
					<pubDate>Tue, 22 Nov 2022 16:03:04 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.4.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.4.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.3.16</title>
					<description></description>
					<pubDate>Tue, 22 Nov 2022 16:03:03 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.3.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.3.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.7.0</title>
					<description></description>
					<pubDate>Tue, 08 Nov 2022 16:03:07 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.7.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.7.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.6.3</title>
					<description></description>
					<pubDate>Tue, 25 Oct 2022 16:03:06 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.6.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.6.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.5.7</title>
					<description></description>
					<pubDate>Tue, 25 Oct 2022 16:03:05 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.5.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.5.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.4.10</title>
					<description></description>
					<pubDate>Tue, 25 Oct 2022 16:03:04 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.4.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.4.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.3.15</title>
					<description></description>
					<pubDate>Tue, 25 Oct 2022 16:03:03 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.3.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.3.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.2.20</title>
					<description></description>
					<pubDate>Tue, 25 Oct 2022 16:03:02 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.2.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.2.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.6.2</title>
					<description></description>
					<pubDate>Wed, 21 Sep 2022 16:03:06 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.6.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.6.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.5.6</title>
					<description></description>
					<pubDate>Wed, 21 Sep 2022 16:03:05 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.5.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.5.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.4.9</title>
					<description></description>
					<pubDate>Wed, 21 Sep 2022 16:03:04 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.4.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.4.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.3.14</title>
					<description></description>
					<pubDate>Wed, 21 Sep 2022 16:03:03 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.3.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.3.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.2.19</title>
					<description></description>
					<pubDate>Wed, 21 Sep 2022 16:03:02 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.2.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.2.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.6.1</title>
					<description></description>
					<pubDate>Tue, 30 Aug 2022 16:03:06 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.6.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.6.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.5.5</title>
					<description></description>
					<pubDate>Tue, 30 Aug 2022 16:03:05 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.5.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.5.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.4.8</title>
					<description></description>
					<pubDate>Tue, 30 Aug 2022 16:03:04 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.4.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.4.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.3.13</title>
					<description></description>
					<pubDate>Tue, 30 Aug 2022 16:03:03 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.3.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.3.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.2.18</title>
					<description></description>
					<pubDate>Tue, 30 Aug 2022 16:03:02 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.2.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.2.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.6.0</title>
					<description></description>
					<pubDate>Tue, 16 Aug 2022 16:03:06 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.6.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.6.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.5.4</title>
					<description></description>
					<pubDate>Thu, 11 Aug 2022 16:03:05 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.5.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.5.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.4.7</title>
					<description></description>
					<pubDate>Thu, 11 Aug 2022 16:03:04 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.4.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.4.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.3.12</title>
					<description></description>
					<pubDate>Thu, 11 Aug 2022 16:03:03 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.3.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.3.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.2.17</title>
					<description></description>
					<pubDate>Thu, 11 Aug 2022 16:03:02 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.2.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.2.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.5.3</title>
					<description></description>
					<pubDate>Thu, 21 Jul 2022 16:03:05 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.5.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.5.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.4.6</title>
					<description></description>
					<pubDate>Thu, 21 Jul 2022 16:03:04 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.4.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.4.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.3.11</title>
					<description></description>
					<pubDate>Thu, 21 Jul 2022 16:03:03 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.3.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.3.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.2.16</title>
					<description></description>
					<pubDate>Thu, 21 Jul 2022 16:03:02 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.2.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.2.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.5.2</title>
					<description></description>
					<pubDate>Tue, 28 Jun 2022 16:03:05 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.5.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.5.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.4.5</title>
					<description></description>
					<pubDate>Tue, 28 Jun 2022 16:03:04 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.4.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.4.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.3.10</title>
					<description></description>
					<pubDate>Tue, 28 Jun 2022 16:03:03 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.3.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.3.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.2.15</title>
					<description></description>
					<pubDate>Tue, 28 Jun 2022 16:03:02 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.2.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.2.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.5.1</title>
					<description></description>
					<pubDate>Thu, 09 Jun 2022 16:03:05 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.5.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.5.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.4.4</title>
					<description></description>
					<pubDate>Thu, 09 Jun 2022 16:03:04 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.4.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.4.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.3.9</title>
					<description></description>
					<pubDate>Thu, 09 Jun 2022 16:03:03 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.3.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.3.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.2.14</title>
					<description></description>
					<pubDate>Thu, 09 Jun 2022 16:03:02 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.2.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.2.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.1.22</title>
					<description></description>
					<pubDate>Thu, 09 Jun 2022 16:03:01 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.1.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.1.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.5.0</title>
					<description></description>
					<pubDate>Tue, 31 May 2022 16:03:05 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.5.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.5.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.4.3</title>
					<description></description>
					<pubDate>Tue, 17 May 2022 16:03:04 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.4.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.4.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.3.8</title>
					<description></description>
					<pubDate>Tue, 17 May 2022 16:03:03 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.3.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.3.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.2.13</title>
					<description></description>
					<pubDate>Tue, 17 May 2022 16:03:02 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.2.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.2.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.1.21</title>
					<description></description>
					<pubDate>Tue, 17 May 2022 16:03:01 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.1.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.1.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.4.2</title>
					<description></description>
					<pubDate>Wed, 20 Apr 2022 16:03:04 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.4.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.4.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.3.7</title>
					<description></description>
					<pubDate>Wed, 20 Apr 2022 16:03:03 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.3.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.3.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.2.12</title>
					<description></description>
					<pubDate>Wed, 20 Apr 2022 16:03:02 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.2.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.2.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.1.20</title>
					<description></description>
					<pubDate>Wed, 20 Apr 2022 16:03:01 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.1.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.1.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.4.1</title>
					<description></description>
					<pubDate>Mon, 04 Apr 2022 16:03:04 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.4.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.4.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.3.6</title>
					<description></description>
					<pubDate>Mon, 04 Apr 2022 16:03:03 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.3.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.3.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.2.11</title>
					<description></description>
					<pubDate>Mon, 04 Apr 2022 16:03:02 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.2.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.2.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.1.19</title>
					<description></description>
					<pubDate>Mon, 04 Apr 2022 16:03:01 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.1.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.1.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.4.0</title>
					<description></description>
					<pubDate>Tue, 15 Mar 2022 16:03:04 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.4.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.4.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.3.5</title>
					<description></description>
					<pubDate>Tue, 01 Mar 2022 16:03:03 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.3.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.3.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.2.10</title>
					<description></description>
					<pubDate>Tue, 01 Mar 2022 16:03:02 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.2.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.2.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.1.18</title>
					<description></description>
					<pubDate>Tue, 01 Mar 2022 16:03:01 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.1.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.1.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.3.4</title>
					<description></description>
					<pubDate>Thu, 17 Feb 2022 16:03:03 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.3.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.3.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.2.9</title>
					<description></description>
					<pubDate>Thu, 17 Feb 2022 16:03:02 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.2.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.2.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.1.17</title>
					<description></description>
					<pubDate>Thu, 17 Feb 2022 16:03:01 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.1.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.1.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.25</title>
					<description></description>
					<pubDate>Thu, 17 Feb 2022 16:03:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.25</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.25</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.3.3</title>
					<description></description>
					<pubDate>Tue, 01 Feb 2022 16:03:03 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.3.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.3.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.2.8</title>
					<description></description>
					<pubDate>Tue, 01 Feb 2022 16:03:02 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.2.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.2.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.1.16</title>
					<description></description>
					<pubDate>Tue, 01 Feb 2022 16:03:01 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.1.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.1.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.24</title>
					<description></description>
					<pubDate>Tue, 01 Feb 2022 16:03:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.24</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.24</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.3.2</title>
					<description></description>
					<pubDate>Wed, 12 Jan 2022 16:03:03 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.3.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.3.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.2.7</title>
					<description></description>
					<pubDate>Wed, 12 Jan 2022 16:03:02 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.2.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.2.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.1.15</title>
					<description></description>
					<pubDate>Wed, 12 Jan 2022 16:03:01 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.1.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.1.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.23</title>
					<description></description>
					<pubDate>Wed, 12 Jan 2022 16:03:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.23</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.23</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.3.1</title>
					<description></description>
					<pubDate>Mon, 13 Dec 2021 16:03:03 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.3.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.3.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.2.6</title>
					<description></description>
					<pubDate>Mon, 13 Dec 2021 16:03:02 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.2.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.2.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.1.14</title>
					<description></description>
					<pubDate>Mon, 13 Dec 2021 16:03:01 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.1.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.1.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.22</title>
					<description></description>
					<pubDate>Mon, 13 Dec 2021 16:03:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.3.0</title>
					<description></description>
					<pubDate>Tue, 07 Dec 2021 16:03:03 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.3.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.3.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.2.5</title>
					<description></description>
					<pubDate>Tue, 07 Dec 2021 16:03:02 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.2.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.2.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.1.13</title>
					<description></description>
					<pubDate>Tue, 07 Dec 2021 16:03:01 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.1.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.1.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.21</title>
					<description></description>
					<pubDate>Tue, 07 Dec 2021 16:03:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.2.4</title>
					<description></description>
					<pubDate>Tue, 23 Nov 2021 16:03:02 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.2.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.2.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.1.12</title>
					<description></description>
					<pubDate>Tue, 23 Nov 2021 16:03:01 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.1.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.1.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.20</title>
					<description></description>
					<pubDate>Tue, 23 Nov 2021 16:03:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.2.3</title>
					<description></description>
					<pubDate>Tue, 09 Nov 2021 16:03:02 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.2.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.2.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.1.11</title>
					<description></description>
					<pubDate>Tue, 09 Nov 2021 16:03:01 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.1.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.1.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.19</title>
					<description></description>
					<pubDate>Tue, 09 Nov 2021 16:03:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.2.2</title>
					<description></description>
					<pubDate>Thu, 28 Oct 2021 16:03:02 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.2.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.2.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.1.10</title>
					<description></description>
					<pubDate>Thu, 28 Oct 2021 16:03:01 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.1.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.1.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.18</title>
					<description></description>
					<pubDate>Thu, 28 Oct 2021 16:03:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.2.1</title>
					<description></description>
					<pubDate>Tue, 12 Oct 2021 16:03:02 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.2.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.2.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.1.9</title>
					<description></description>
					<pubDate>Tue, 12 Oct 2021 16:03:01 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.1.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.1.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.17</title>
					<description></description>
					<pubDate>Tue, 12 Oct 2021 16:03:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.2.0</title>
					<description></description>
					<pubDate>Tue, 28 Sep 2021 16:03:02 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.2.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.2.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.1.8</title>
					<description></description>
					<pubDate>Thu, 23 Sep 2021 16:03:01 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.1.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.1.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.16</title>
					<description></description>
					<pubDate>Thu, 23 Sep 2021 16:03:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.22.22</title>
					<description></description>
					<pubDate>Thu, 23 Sep 2021 16:02:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.22.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.22.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.1.7</title>
					<description></description>
					<pubDate>Tue, 07 Sep 2021 16:03:01 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.1.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.1.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.15</title>
					<description></description>
					<pubDate>Tue, 07 Sep 2021 16:03:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.22.21</title>
					<description></description>
					<pubDate>Tue, 07 Sep 2021 16:02:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.22.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.22.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.1.6</title>
					<description></description>
					<pubDate>Tue, 24 Aug 2021 16:03:01 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.1.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.1.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.14</title>
					<description></description>
					<pubDate>Tue, 24 Aug 2021 16:03:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.22.20</title>
					<description></description>
					<pubDate>Tue, 24 Aug 2021 16:02:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.22.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.22.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.1.5</title>
					<description></description>
					<pubDate>Tue, 10 Aug 2021 16:03:01 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.1.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.1.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.13</title>
					<description></description>
					<pubDate>Tue, 10 Aug 2021 16:03:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.22.19</title>
					<description></description>
					<pubDate>Tue, 10 Aug 2021 16:02:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.22.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.22.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.1.4</title>
					<description></description>
					<pubDate>Tue, 27 Jul 2021 16:03:01 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.1.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.1.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.12</title>
					<description></description>
					<pubDate>Tue, 27 Jul 2021 16:03:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.22.18</title>
					<description></description>
					<pubDate>Tue, 27 Jul 2021 16:02:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.22.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.22.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.1.3</title>
					<description></description>
					<pubDate>Wed, 14 Jul 2021 16:03:01 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.1.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.1.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.11</title>
					<description></description>
					<pubDate>Wed, 14 Jul 2021 16:03:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.22.17</title>
					<description></description>
					<pubDate>Wed, 14 Jul 2021 16:02:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.22.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.22.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.1.2</title>
					<description></description>
					<pubDate>Thu, 24 Jun 2021 16:03:01 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.1.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.1.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.10</title>
					<description></description>
					<pubDate>Thu, 24 Jun 2021 16:03:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.22.16</title>
					<description></description>
					<pubDate>Thu, 24 Jun 2021 16:02:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.22.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.22.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.1.1</title>
					<description></description>
					<pubDate>Thu, 10 Jun 2021 16:03:01 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.1.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.1.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.9</title>
					<description></description>
					<pubDate>Thu, 10 Jun 2021 16:03:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.22.15</title>
					<description></description>
					<pubDate>Thu, 10 Jun 2021 16:02:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.22.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.22.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.21.23</title>
					<description></description>
					<pubDate>Thu, 10 Jun 2021 16:02:21 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.21.23</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.21.23</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.1.0</title>
					<description></description>
					<pubDate>Thu, 03 Jun 2021 16:03:01 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.1.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.1.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.8</title>
					<description></description>
					<pubDate>Tue, 25 May 2021 16:03:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.22.14</title>
					<description></description>
					<pubDate>Tue, 25 May 2021 16:02:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.22.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.22.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.21.22</title>
					<description></description>
					<pubDate>Tue, 25 May 2021 16:02:21 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.21.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.21.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.7</title>
					<description></description>
					<pubDate>Thu, 13 May 2021 16:03:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.22.13</title>
					<description></description>
					<pubDate>Thu, 13 May 2021 16:02:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.22.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.22.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.21.21</title>
					<description></description>
					<pubDate>Thu, 13 May 2021 16:02:21 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.21.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.21.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.6</title>
					<description></description>
					<pubDate>Wed, 28 Apr 2021 16:00:43 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.22.12</title>
					<description></description>
					<pubDate>Wed, 28 Apr 2021 16:00:42 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.22.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.22.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.21.20</title>
					<description></description>
					<pubDate>Wed, 28 Apr 2021 16:00:41 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.21.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.21.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.5</title>
					<description></description>
					<pubDate>Wed, 14 Apr 2021 16:00:43 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.22.11</title>
					<description></description>
					<pubDate>Wed, 14 Apr 2021 16:00:42 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.22.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.22.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.21.19</title>
					<description></description>
					<pubDate>Wed, 14 Apr 2021 16:00:41 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.21.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.21.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.4</title>
					<description></description>
					<pubDate>Thu, 01 Apr 2021 16:00:43 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.22.10</title>
					<description></description>
					<pubDate>Thu, 01 Apr 2021 16:00:42 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.22.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.22.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.21.18</title>
					<description></description>
					<pubDate>Thu, 01 Apr 2021 16:00:41 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.21.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.21.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.3</title>
					<description></description>
					<pubDate>Tue, 23 Mar 2021 16:00:42 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.22.9</title>
					<description></description>
					<pubDate>Tue, 23 Mar 2021 16:00:42 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.22.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.22.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.21.17</title>
					<description></description>
					<pubDate>Tue, 23 Mar 2021 16:00:41 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.21.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.21.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.2</title>
					<description></description>
					<pubDate>Tue, 16 Mar 2021 16:00:43 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.22.8</title>
					<description></description>
					<pubDate>Tue, 16 Mar 2021 16:00:42 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.22.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.22.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.21.16</title>
					<description></description>
					<pubDate>Tue, 16 Mar 2021 16:00:41 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.21.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.21.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.1</title>
					<description></description>
					<pubDate>Tue, 02 Mar 2021 16:00:43 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.22.7</title>
					<description></description>
					<pubDate>Tue, 02 Mar 2021 16:00:42 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.22.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.22.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.21.15</title>
					<description></description>
					<pubDate>Tue, 02 Mar 2021 16:00:41 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.21.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.21.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.24</title>
					<description></description>
					<pubDate>Tue, 02 Mar 2021 16:00:40 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.24</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.24</guid>
				</item>
			
		
			
		  
				<item>
					<title>3.0.0</title>
					<description></description>
					<pubDate>Tue, 16 Feb 2021 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/3.0.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/3.0.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.22.6</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW:&lt;/strong&gt; High CPU usage could be triggered by a specially crafted request to the SVN bridge resulting in Denial of Service (DoS).&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Requests for some file resources like a zip archive or raw file could enter a redirection loop.&lt;/li&gt;
&lt;li&gt;A timeout could prevent some Issues and Pull Requests searches from providing complete search results.&lt;/li&gt;
&lt;li&gt;Custom tabs with non-alphabetic characters in small screens did not render correctly.&lt;/li&gt;
&lt;li&gt;An underlying behavior was causing failures when pushing content to a Git LFS-enabled repository.&lt;/li&gt;
&lt;li&gt;In some rare cases issues could cause a 500 error when accessed via the web interface.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Thu, 17 Dec 2020 16:00:42 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.22.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.22.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.21.14</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW:&lt;/strong&gt; High CPU usage could be triggered by a specially crafted request to the SVN bridge resulting in Denial of Service (DoS).&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Thu, 17 Dec 2020 16:00:41 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.21.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.21.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.23</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW:&lt;/strong&gt; High CPU usage could be triggered by a specially crafted request to the SVN bridge resulting in Denial of Service (DoS).&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.20&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.20 will be deprecated as of February 11, 2021&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Thu, 17 Dec 2020 16:00:40 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.23</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.23</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.22.5</title>
					<description></description>
					<pubDate>Thu, 03 Dec 2020 16:00:42 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.22.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.22.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.21.13</title>
					<description></description>
					<pubDate>Thu, 03 Dec 2020 16:00:41 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.21.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.21.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.22</title>
					<description></description>
					<pubDate>Thu, 03 Dec 2020 16:00:40 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.22.4</title>
					<description></description>
					<pubDate>Tue, 17 Nov 2020 16:00:42 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.22.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.22.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.21.12</title>
					<description></description>
					<pubDate>Tue, 17 Nov 2020 16:00:41 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.21.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.21.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.21</title>
					<description></description>
					<pubDate>Tue, 17 Nov 2020 16:00:40 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.22.3</title>
					<description></description>
					<pubDate>Tue, 03 Nov 2020 16:00:42 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.22.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.22.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.21.11</title>
					<description></description>
					<pubDate>Tue, 03 Nov 2020 16:00:41 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.21.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.21.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.20</title>
					<description></description>
					<pubDate>Tue, 03 Nov 2020 16:00:40 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.26</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM:&lt;/strong&gt; High CPU usage could be triggered by a specially crafted request to the SVN bridge resulting in Denial of Service (DoS).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW:&lt;/strong&gt; Incorrect token validation resulted in a reduced entropy for matching tokens during authentication. Analysis shows that in practice there&#39;s no significant security risk here.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Suspended users were included in the list of suggested users, potentially hiding unsuspended users.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.19&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.19 will be deprecated as of November 12, 2020&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 03 Nov 2020 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.26</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.26</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.22.2</title>
					<description></description>
					<pubDate>Tue, 20 Oct 2020 16:00:42 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.22.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.22.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.21.10</title>
					<description></description>
					<pubDate>Tue, 20 Oct 2020 16:00:41 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.21.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.21.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.19</title>
					<description></description>
					<pubDate>Tue, 20 Oct 2020 16:00:40 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.25</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The enterprise account &amp;quot;Confirm two-factor requirement policy&amp;quot; messaging was incorrect.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.19&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.19 will be deprecated as of November 12, 2020&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 20 Oct 2020 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.25</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.25</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.22.1</title>
					<description></description>
					<pubDate>Fri, 09 Oct 2020 16:00:42 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.22.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.22.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.21.9</title>
					<description></description>
					<pubDate>Fri, 09 Oct 2020 16:00:41 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.21.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.21.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.18</title>
					<description></description>
					<pubDate>Fri, 09 Oct 2020 16:00:40 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.24</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A user whose LDAP directory username standardizes to an existing GHES account login could authenticate into the existing account.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The NameID Format dropdown in the Management Console would be reset to &amp;quot;unspecified&amp;quot; after setting it to &amp;quot;persistent&amp;quot;.&lt;/li&gt;
&lt;li&gt;Saving settings via the &lt;a href=&quot;https://docs.github.com/en/enterprise-server@latest/admin/configuration/accessing-the-management-console&quot;&gt;management console&lt;/a&gt; would append a newline to the &lt;a href=&quot;https://docs.github.com/en/enterprise-server@latest/admin/configuration/configuring-tls&quot;&gt;TLS/SSL certificate and key&lt;/a&gt; files which triggered unnecessary reloading of some services.&lt;/li&gt;
&lt;li&gt;System logs for Dependency Graph were not rotating, allowing unbounded storage growth.&lt;/li&gt;
&lt;li&gt;When importing a repository with &lt;code&gt;ghe-migrator&lt;/code&gt;, an unexpected exception could occur when inconsistent data is present.&lt;/li&gt;
&lt;li&gt;When using &lt;code&gt;ghe-migrator&lt;/code&gt; to import PR review requests, records associated with deleted users would result in extraneous database records.&lt;/li&gt;
&lt;li&gt;When importing users with &lt;code&gt;ghe-migrator&lt;/code&gt;, an error of &amp;quot;Emails is invalid&amp;quot; would occur if the system-generated email address were longer than 100 characters.&lt;/li&gt;
&lt;li&gt;The Pull Request page could give an error if unexpected bytes were present in a data field.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Remove the requirement for SSH fingerprints in &lt;code&gt;ghe-migrator&lt;/code&gt; archives as it can always be computed.&lt;/li&gt;
&lt;li&gt;GitHub App Manifests now include the &lt;code&gt;request_oauth_on_install&lt;/code&gt; field.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.19&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.19 will be deprecated as of November 12, 2020&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Fri, 09 Oct 2020 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.24</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.24</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.22.0</title>
					<description></description>
					<pubDate>Wed, 23 Sep 2020 16:00:42 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.22.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.22.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.21.8</title>
					<description></description>
					<pubDate>Wed, 23 Sep 2020 16:00:41 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.21.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.21.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.17</title>
					<description></description>
					<pubDate>Wed, 23 Sep 2020 16:00:40 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.23</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;:  ImageMagick has been updated to address &lt;a href=&quot;https://www.debian.org/security/2020/dsa-4715&quot;&gt;DSA-4715-1&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.19&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.19 will be deprecated as of November 12, 2020&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 23 Sep 2020 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.23</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.23</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.21.7</title>
					<description></description>
					<pubDate>Tue, 08 Sep 2020 16:00:41 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.21.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.21.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.16</title>
					<description></description>
					<pubDate>Tue, 08 Sep 2020 16:00:40 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.22</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A service health check caused session growth resulting in filesystem inode exhaustion.&lt;/li&gt;
&lt;li&gt;Upgrading using a hotpatch could fail with an error: &lt;code&gt;&#39;libdbi1&#39; was not found&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 08 Sep 2020 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.21.6</title>
					<description></description>
					<pubDate>Wed, 26 Aug 2020 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.21.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.21.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.15</title>
					<description></description>
					<pubDate>Wed, 26 Aug 2020 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.21</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL:&lt;/strong&gt; A remote code execution vulnerability was identified in GitHub Pages that could be exploited when building a GitHub Pages site. User-controlled configuration of the underlying parsers used by GitHub Pages were not sufficiently restricted and made it possible to execute commands on the GitHub Enterprise Server instance. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance. This vulnerability affected all versions of GitHub Enterprise Server. The underlying issues contributing to this vulnerability were identified both internally and through the GitHub Security Bug Bounty program. We have issued CVE-2020-10518.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM:&lt;/strong&gt; An improper access control vulnerability was identified that allowed authenticated users of the instance to determine the names of unauthorized private repositories given their numerical IDs. This vulnerability did not allow unauthorized access to any repository content besides the name. This vulnerability affected all versions of GitHub Enterprise Server prior to 2.22 and has been assigned &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10517&quot;&gt;CVE-2020-10517&lt;/a&gt;. The vulnerability was reported via the &lt;a href=&quot;https://bounty.github.com&quot;&gt;GitHub Bug Bounty program&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A message was not logged when the ghe-config-apply process had finished running ghe-es-auto-expand.&lt;/li&gt;
&lt;li&gt;Excessive logging to the &lt;code&gt;syslog&lt;/code&gt; file could occur on high-availability replicas if the primary appliance is unavailable.&lt;/li&gt;
&lt;li&gt;Database re-seeding on a replica could fail with an error: &lt;code&gt;Got packet bigger than &#39;max_allowed_packet&#39;&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Syntax highlighting of some languages failed to render correctly.&lt;/li&gt;
&lt;li&gt;In some cases duplicate user data could cause a 500 error while running the ghe-license-usage script.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Removed the license seat count information on the administrative SSH MOTD due to a performance issue impacting GitHub Enterprise Server clusters.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 26 Aug 2020 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.21.5</title>
					<description></description>
					<pubDate>Wed, 12 Aug 2020 16:00:41 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.21.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.21.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.14</title>
					<description></description>
					<pubDate>Wed, 12 Aug 2020 16:00:40 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.20</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Recent changes to memory allocations could lead to a degradation in system performance&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 12 Aug 2020 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.25</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Recent changes to memory allocations could lead to a degradation in system performance&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.18&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.18 will be deprecated as of August 20, 2020&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 12 Aug 2020 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.25</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.25</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.21.4</title>
					<description></description>
					<pubDate>Tue, 11 Aug 2020 16:00:41 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.21.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.21.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.13</title>
					<description></description>
					<pubDate>Tue, 11 Aug 2020 16:00:40 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.19</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL:&lt;/strong&gt; A remote code execution vulnerability was identified in GitHub Pages that could allow an attacker to execute commands as part building a GitHub Pages site. This issue was due to an outdated and vulnerable dependency used in the Pages build process. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance.  This vulnerability affected all versions of GitHub Enterprise Server. To mitigate this vulnerability, Kramdown has been updated to address CVE-2020-14001.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH:&lt;/strong&gt; An attacker could inject a malicious argument into a Git sub-command when executed on GitHub Enterprise Server. This could allow an attacker to overwrite arbitrary files with partially user-controlled content and potentially execute arbitrary commands on the GitHub Enterprise Server instance. To exploit this vulnerability, an attacker would need permission to access repositories within the GitHub Enterprise Server instance. However, due to other protections in place, we could not identify a way to actively exploit this vulnerability. This vulnerability was reported through the GitHub Security Bug Bounty program.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The service memory allocation calculation could allocate an incorrect or unbounded memory allocation to a service resulting in poor system performance.&lt;/li&gt;
&lt;li&gt;The virtualization platform for oVirt KVM systems was not properly detected, causing problems during upgrades.&lt;/li&gt;
&lt;li&gt;GitHub Connect was using a deprecated GitHub.com API endpoint.&lt;/li&gt;
&lt;li&gt;Issues could not be sorted by &lt;em&gt;Recently updated&lt;/em&gt; on repositories migrated to a new instance.&lt;/li&gt;
&lt;li&gt;The 404 page contained GitHub.com contact and status links in the footer.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 11 Aug 2020 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.24</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL:&lt;/strong&gt; A remote code execution vulnerability was identified in GitHub Pages that could allow an attacker to execute commands as part building a GitHub Pages site. This issue was due to an outdated and vulnerable dependency used in the Pages build process. To exploit this vulnerability, an attacker would need permission to create and build a GitHub Pages site on the GitHub Enterprise Server instance.  This vulnerability affected all versions of GitHub Enterprise Server. To mitigate this vulnerability, Kramdown has been updated to address CVE-2020-14001.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH:&lt;/strong&gt; An attacker could inject a malicious argument into a Git sub-command when executed on GitHub Enterprise Server. This could allow an attacker to overwrite arbitrary files with partially user-controlled content and potentially execute arbitrary commands on the GitHub Enterprise Server instance. To exploit this vulnerability, an attacker would need permission to access repositories within the GitHub Enterprise Server instance. However, due to other protections in place, we could not identify a way to actively exploit this vulnerability. This vulnerability was reported through the GitHub Security Bug Bounty program.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The virtualization platform for oVirt KVM systems was not properly detected, causing problems during upgrades.&lt;/li&gt;
&lt;li&gt;The service memory allocation calculation could allocate an incorrect or unbounded memory allocation to a service resulting in poor system performance.&lt;/li&gt;
&lt;li&gt;Issues could not be sorted by &lt;em&gt;Recently updated&lt;/em&gt; on repositories migrated to a new instance.&lt;/li&gt;
&lt;li&gt;GitHub Connect was using a deprecated GitHub.com API endpoint.&lt;/li&gt;
&lt;li&gt;The 404 page contained GitHub.com contact and status links in the footer.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.18&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.18 will be deprecated as of August 20, 2020&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 11 Aug 2020 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.24</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.24</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.21.3</title>
					<description></description>
					<pubDate>Tue, 21 Jul 2020 16:00:41 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.21.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.21.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.12</title>
					<description></description>
					<pubDate>Tue, 21 Jul 2020 16:00:40 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.18</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub App Manifest creation flow was unusable in some scenarios when a SameSite Cookie policy was applied.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 21 Jul 2020 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.23</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub App Manifest creation flow was unusable in some scenarios when a SameSite Cookie policy was applied.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.18&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.18 will be deprecated as of August 20, 2020&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 21 Jul 2020 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.23</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.23</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.21.2</title>
					<description></description>
					<pubDate>Thu, 09 Jul 2020 16:00:41 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.21.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.21.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.11</title>
					<description></description>
					<pubDate>Thu, 09 Jul 2020 16:00:40 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.17</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM:&lt;/strong&gt; Updated nginx to 1.16.1 and addressed CVE-2019-20372. (updated 2020-07-22)&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Certain log files did not rotate every 7 days.&lt;/li&gt;
&lt;li&gt;Rapid reuse of webhook source ports resulted in rejected connections.&lt;/li&gt;
&lt;li&gt;Site Administrators could not unlock a repository more than once.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Thu, 09 Jul 2020 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.22</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM:&lt;/strong&gt; Updated nginx to 1.16.1 and addressed CVE-2019-20372. (updated 2020-07-22)&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Certain log files did not rotate every 7 days.&lt;/li&gt;
&lt;li&gt;Rapid reuse of webhook source ports resulted in rejected connections.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.18&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.18 will be deprecated as of August 20, 2020&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Thu, 09 Jul 2020 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.21.1</title>
					<description></description>
					<pubDate>Tue, 23 Jun 2020 16:00:41 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.21.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.21.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.10</title>
					<description></description>
					<pubDate>Tue, 23 Jun 2020 16:00:40 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.16</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Excessively large log events could lead to log forwarding instability when UDP was used as the transport mechanism.&lt;/li&gt;
&lt;li&gt;Automatic unsuspension of a user through SSO did not complete if the SSH keys attribute had keys already associated with the user&#39;s account.&lt;/li&gt;
&lt;li&gt;Previewing a GitHub App description written in markdown was not properly rendered.&lt;/li&gt;
&lt;li&gt;Webhooks could be triggered twice by a single commit via the web user interface.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 23 Jun 2020 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.21</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Excessively large log events could lead to log forwarding instability when UDP was used as the transport mechanism.&lt;/li&gt;
&lt;li&gt;Automatic unsuspension of a user through SSO did not complete if the SSH keys attribute had keys already associated with the user&#39;s account.&lt;/li&gt;
&lt;li&gt;Previewing a GitHub App description written in markdown was not properly rendered.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.18&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.18 will be deprecated as of August 20, 2020&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 23 Jun 2020 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.21.0</title>
					<description></description>
					<pubDate>Tue, 09 Jun 2020 16:00:41 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.21.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.21.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.9</title>
					<description></description>
					<pubDate>Tue, 02 Jun 2020 16:00:40 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.15</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH:&lt;/strong&gt; An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization member to escalate permissions and gain access to unauthorized repositories within an organization. This vulnerability affected all versions of GitHub Enterprise Server prior to 2.21.  We have issued &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10516&quot;&gt;CVE-2020-10516&lt;/a&gt; in response to this issue. The vulnerability was reported via the &lt;a href=&quot;https://bounty.github.com&quot;&gt;GitHub Bug Bounty program&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Internet-facing GitHub Enterprise Server instances could be indexed by search engines.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When pushing to a gist, an exception could be triggered during the post-receive hook.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 02 Jun 2020 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.20</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH:&lt;/strong&gt; An improper access control vulnerability was identified in the GitHub Enterprise Server API that allowed an organization member to escalate permissions and gain access to unauthorized repositories within an organization. This vulnerability affected all versions of GitHub Enterprise Server prior to 2.21.  We have issued &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-10516&quot;&gt;CVE-2020-10516&lt;/a&gt; in response to this issue. The vulnerability was reported via the &lt;a href=&quot;https://bounty.github.com&quot;&gt;GitHub Bug Bounty program&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Internet-facing GitHub Enterprise Server instances could be indexed by search engines.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 02 Jun 2020 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.8</title>
					<description></description>
					<pubDate>Tue, 19 May 2020 16:00:40 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.14</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;After the license file was updated, services were not properly reloaded causing functionality loss.&lt;/li&gt;
&lt;li&gt;Internal API requests updating Dependency Graph information could fail if the response body was too large.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;affiliations&lt;/code&gt; argument to some GraphQL repository connections was not respected.&lt;/li&gt;
&lt;li&gt;Automatic unsuspension of a user through SSO did not complete if the SAML email attribute had different casing than the GitHub user email.&lt;/li&gt;
&lt;li&gt;Restoring the membership of a user to an organization did not instrument the actor in webhook and audit log payloads.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When pushing to a gist, an exception could be triggered during the post-receive hook.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 19 May 2020 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.19</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;After the license file was updated, services were not properly reloaded causing functionality loss.&lt;/li&gt;
&lt;li&gt;Internal API requests updating Dependency Graph information could fail if the response body was too large.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;affiliations&lt;/code&gt; argument to some GraphQL repository connections was not respected.&lt;/li&gt;
&lt;li&gt;Automatic unsuspension of a user through SSO did not complete if the SAML email attribute had different casing than the GitHub user email.&lt;/li&gt;
&lt;li&gt;Restoring the membership of a user to an organization did not instrument the actor in webhook and audit log payloads.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 19 May 2020 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.25</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Restoring the membership of a user to an organization did not instrument the actor in webhook and audit log payloads.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.17&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.17 will be deprecated as of May 23, 2020&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 19 May 2020 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.25</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.25</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.7</title>
					<description></description>
					<pubDate>Tue, 05 May 2020 16:00:40 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.13</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;If a repository has the &amp;quot;automatically delete head branches&amp;quot; setting enabled, the head branch wasn&#39;t automatically deleted, when a pull request was merged by a GitHub App installation.&lt;/li&gt;
&lt;li&gt;When an organization member was reinstated, the webhook payload reported the &lt;code&gt;ghost&lt;/code&gt; user as the sender and not the actual user performing the reinstatement.&lt;/li&gt;
&lt;li&gt;If a repository has the &amp;quot;automatically delete head branches&amp;quot; setting enabled, the head branch wasn&#39;t automatically deleted where the head repository was different from the base repository.&lt;/li&gt;
&lt;li&gt;The garbage collection of temporary files could lead to a license validation error.&lt;/li&gt;
&lt;li&gt;In some situations, including when a repository is first created, the pre-receive hook would be run without a value populated for the GITHUB_REPO_PUBLIC environment variable.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When pushing to a gist, an exception could be triggered during the post-receive hook.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 05 May 2020 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.18</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;When an organization member was reinstated, the webhook payload reported the &lt;code&gt;ghost&lt;/code&gt; user as the sender and not the actual user performing the reinstatement.&lt;/li&gt;
&lt;li&gt;The garbage collection of temporary files could lead to a license validation error.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 05 May 2020 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.24</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;When an organization member was reinstated, the webhook payload reported the &lt;code&gt;ghost&lt;/code&gt; user as the sender and not the actual user performing the reinstatement.&lt;/li&gt;
&lt;li&gt;The garbage collection of temporary files could lead to a license validation error.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.17&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.17 will be deprecated as of May 23, 2020&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 05 May 2020 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.24</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.24</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.6</title>
					<description></description>
					<pubDate>Thu, 23 Apr 2020 16:00:40 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.12</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: OpenSSL has been updated to address &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1967&quot;&gt;CVE-2020-1967&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: Git has been updated to address &lt;a href=&quot;https://github.com/git/git/security/advisories/GHSA-qm7j-c969-7j4q&quot;&gt;CVE-2020-5260&lt;/a&gt; and &lt;a href=&quot;https://github.com/git/git/security/advisories/GHSA-hjc9-x69f-jqj7&quot;&gt;CVE-2020-11008&lt;/a&gt;. New restrictions prevent malicious repositories from being pushed to the server instance, protecting clients which have not yet been patched.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;:  ImageMagick has been updated to address &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10131&quot;&gt;CVE-2019-10131&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A mismatch in MySQL configurations could cause backups to fail in large installations.&lt;/li&gt;
&lt;li&gt;A periodic task to clean up old log files would fail and send error messages to the local root account.&lt;/li&gt;
&lt;li&gt;When a GitHub Enterprise Server license contained non-ASCII characters, a &lt;code&gt;GET&lt;/code&gt; request to the Management Console API &lt;code&gt;/setup/api/settings&lt;/code&gt; endpoint would result in an Internal Server Error.&lt;/li&gt;
&lt;li&gt;The recovery console would prompt for a root password, even if the root account was locked.&lt;/li&gt;
&lt;li&gt;When using the GraphQL&#39;s API for filtering issues assigned to a non-existent user, the message received would not be descriptive enough.&lt;/li&gt;
&lt;li&gt;A CODEOWNERS file with a leading UTF-8 Byte Order Mark would cause all codeowner rules to be ignored.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;When an external identity provider controlled user&#39;s site administrator status, users could not be demoted via the command line utility.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When pushing to a gist, an exception could be triggered during the post-receive hook.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Thu, 23 Apr 2020 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.17</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: OpenSSL has been updated to address &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1967&quot;&gt;CVE-2020-1967&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: Git has been updated to address &lt;a href=&quot;https://github.com/git/git/security/advisories/GHSA-qm7j-c969-7j4q&quot;&gt;CVE-2020-5260&lt;/a&gt; and &lt;a href=&quot;https://github.com/git/git/security/advisories/GHSA-hjc9-x69f-jqj7&quot;&gt;CVE-2020-11008&lt;/a&gt;. New restrictions prevent malicious repositories from being pushed to the server instance, protecting clients which have not yet been patched.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;:  ImageMagick has been updated to address &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10131&quot;&gt;CVE-2019-10131&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A mismatch in MySQL configurations could cause backups to fail in large installations.&lt;/li&gt;
&lt;li&gt;A periodic task to clean up old log files would fail and send error messages to the local root account.&lt;/li&gt;
&lt;li&gt;The recovery console would prompt for a root password, even if the root account was locked.&lt;/li&gt;
&lt;li&gt;When a GitHub Enterprise Server license contained non-ASCII characters, a &lt;code&gt;GET&lt;/code&gt; request to the Management Console API &lt;code&gt;/setup/api/settings&lt;/code&gt; endpoint would result in an Internal Server Error.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;When an external identity provider controlled user&#39;s site administrator status, users could not be demoted via the command line utility.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Thu, 23 Apr 2020 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.23</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: OpenSSL has been updated to address &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-1967&quot;&gt;CVE-2020-1967&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: Git has been updated to address &lt;a href=&quot;https://github.com/git/git/security/advisories/GHSA-qm7j-c969-7j4q&quot;&gt;CVE-2020-5260&lt;/a&gt; and &lt;a href=&quot;https://github.com/git/git/security/advisories/GHSA-hjc9-x69f-jqj7&quot;&gt;CVE-2020-11008&lt;/a&gt;. New restrictions prevent malicious repositories from being pushed to the server instance, protecting clients which have not yet been patched.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;:  ImageMagick has been updated to address &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10131&quot;&gt;CVE-2019-10131&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A mismatch in MySQL configurations could cause backups to fail in large installations.&lt;/li&gt;
&lt;li&gt;A periodic task to clean up old log files would fail and send error messages to the local root account.&lt;/li&gt;
&lt;li&gt;The recovery console would prompt for a root password, even if the root account was locked.&lt;/li&gt;
&lt;li&gt;When a GitHub Enterprise Server license contained non-ASCII characters, a &lt;code&gt;GET&lt;/code&gt; request to the Management Console API &lt;code&gt;/setup/api/settings&lt;/code&gt; endpoint would result in an Internal Server Error.&lt;/li&gt;
&lt;li&gt;When using the GraphQL&#39;s API for filtering issues assigned to a non-existent user, the message received would not be descriptive enough.&lt;/li&gt;
&lt;li&gt;A CODEOWNERS file with a leading UTF-8 Byte Order Mark would cause all codeowner rules to be ignored.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;When an external identity provider controlled user&#39;s site administrator status, users could not be demoted via the command line utility.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.17&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.17 will be deprecated as of May 23, 2020&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Thu, 23 Apr 2020 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.23</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.23</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.5</title>
					<description></description>
					<pubDate>Tue, 07 Apr 2020 16:00:40 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.11</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The hotpatch mechanism did not properly handle the case where extracted patch contents were no longer present on the filesystem.&lt;/li&gt;
&lt;li&gt;A maximum Git object size of 100MB option could not be selected for a repository when the global enterprise account had a Git object size option other than 100MB set.&lt;/li&gt;
&lt;li&gt;Results from the the Issues and Pull Requests API could have inconsistent behaviour when ordering by the &lt;code&gt;updated_at&lt;/code&gt; field.&lt;/li&gt;
&lt;li&gt;The SecurityVulnerability &lt;code&gt;package&lt;/code&gt; field could not be queried via the GraphQL API.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When pushing to a gist, an exception could be triggered during the post-receive hook.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 07 Apr 2020 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.16</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The hotpatch mechanism did not properly handle the case where extracted patch contents were no longer present on the filesystem.&lt;/li&gt;
&lt;li&gt;A maximum Git object size of 100MB option could not be selected for a repository when the global enterprise account had a Git object size option other than 100MB set.&lt;/li&gt;
&lt;li&gt;Results from the the Issues and Pull Requests API could have inconsistent behaviour when ordering by the &lt;code&gt;updated_at&lt;/code&gt; field.&lt;/li&gt;
&lt;li&gt;The SecurityVulnerability &lt;code&gt;package&lt;/code&gt; field could not be queried via the GraphQL API.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 07 Apr 2020 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.22</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The hotpatch mechanism did not properly handle the case where extracted patch contents were no longer present on the filesystem.&lt;/li&gt;
&lt;li&gt;A maximum Git object size of 100MB option could not be selected for a repository when the global enterprise account had a Git object size option other than 100MB set.&lt;/li&gt;
&lt;li&gt;Results from the the Issues and Pull Requests API could have inconsistent behaviour when ordering by the &lt;code&gt;updated_at&lt;/code&gt; field.&lt;/li&gt;
&lt;li&gt;The SecurityVulnerability &lt;code&gt;package&lt;/code&gt; field could not be queried via the GraphQL API.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.17&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.17 will be deprecated as of May 23, 2020&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 07 Apr 2020 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.4</title>
					<description></description>
					<pubDate>Wed, 25 Mar 2020 16:00:40 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.10</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;SAML Authentication requests and Metadata were not strictly encoded, causing some Identity Providers to not correctly process Service Provider initiated Authentication requests.&lt;/li&gt;
&lt;li&gt;When using GitHub Connect, the GHES license sync process sent information that was not required.&lt;/li&gt;
&lt;li&gt;When pushing to a Gist, an exception could be triggered during the post-receive hook.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When pushing to a gist, an exception could be triggered during the post-receive hook.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 25 Mar 2020 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.15</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;SAML Authentication requests and Metadata were not strictly encoded, causing some Identity Providers to not correctly process Service Provider initiated Authentication requests.&lt;/li&gt;
&lt;li&gt;When using GitHub Connect, the GHES license sync process sent information that was not required.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-migrator&lt;/code&gt; exports did not contain milestone users, which could break import operations.&lt;/li&gt;
&lt;li&gt;When viewing file changes in comparison views, long file paths were truncated in a way that emphasised the directory components, rather than the filename.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 25 Mar 2020 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.21</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;SAML Authentication requests and Metadata were not strictly encoded, causing some Identity Providers to not correctly process Service Provider initiated Authentication requests.&lt;/li&gt;
&lt;li&gt;When using GitHub Connect, the GHES license sync process sent information that was not required.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-migrator&lt;/code&gt; exports did not contain milestone users, which could break import operations.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.17&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.17 will be deprecated as of May 23, 2020&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 25 Mar 2020 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.3</title>
					<description></description>
					<pubDate>Thu, 12 Mar 2020 13:00:40 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.2</title>
					<description></description>
					<pubDate>Tue, 10 Mar 2020 16:00:40 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.9</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In some cases the forwarded log entries, mainly for audit.log were getting truncated.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-license-check&lt;/code&gt; command-line utility returned an &amp;quot;Invalid license file&amp;quot; error for some valid licenses, causing configuration changes to fail.&lt;/li&gt;
&lt;li&gt;Alambic exception logs were not forwarded by syslog.&lt;/li&gt;
&lt;li&gt;The &lt;a href=&quot;https://developer.github.com/v3/activity/events/types/#orgblockevent&quot;&gt;&lt;code&gt;org_block event&lt;/code&gt;&lt;/a&gt; is not unavailable but was appearing for GitHub Apps on GitHub Enterprise Server.&lt;/li&gt;
&lt;li&gt;GraphQL query responses sometimes returned unmatched node identifiers for &lt;code&gt;ProtectedBranch&lt;/code&gt; objects.&lt;/li&gt;
&lt;li&gt;The GitHub App credential used by GitHub Connect failed to refresh immediately after expiry.&lt;/li&gt;
&lt;li&gt;Leaving a comment in reply to a pull request comment was intermittently creating a pending pull request review.&lt;/li&gt;
&lt;li&gt;Using ghe-migrator or exporting from GitHub.com, an export would silently fail to export non-image attachments.&lt;/li&gt;
&lt;li&gt;Pre-receive hook returned 500 error on web UI when UTF-8 characters were encountered.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;ghe-license-usage &lt;/code&gt; command-line utility includes a new &lt;code&gt;--unencrypted&lt;/code&gt; option to provide visibility into the exported license usage file.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When pushing to a gist, an exception could be triggered during the post-receive hook.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 10 Mar 2020 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.14</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In some cases the forwarded log entries, mainly for audit.log were getting truncated.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-license-check&lt;/code&gt; command-line utility returned an &amp;quot;Invalid license file&amp;quot; error for some valid licenses, causing configuration changes to fail.&lt;/li&gt;
&lt;li&gt;Alambic exception logs were not forwarded by syslog.&lt;/li&gt;
&lt;li&gt;The &lt;a href=&quot;https://developer.github.com/v3/activity/events/types/#orgblockevent&quot;&gt;&lt;code&gt;org_block event&lt;/code&gt;&lt;/a&gt; is not unavailable but was appearing for GitHub Apps on GitHub Enterprise Server.&lt;/li&gt;
&lt;li&gt;GraphQL query responses sometimes returned unmatched node identifiers for &lt;code&gt;ProtectedBranch&lt;/code&gt; objects.&lt;/li&gt;
&lt;li&gt;The GitHub App credential used by GitHub Connect failed to refresh immediately after expiry.&lt;/li&gt;
&lt;li&gt;Leaving a comment in reply to a pull request comment was intermittently creating a pending pull request review.&lt;/li&gt;
&lt;li&gt;Using ghe-migrator or exporting from GitHub.com, an export would silently fail to export non-image attachments.&lt;/li&gt;
&lt;li&gt;Pre-receive hook returned 500 error on web UI when UTF-8 characters were encountered.&lt;/li&gt;
&lt;li&gt;Signing out on Chrome was taking 30+ seconds when using a non-incognito browser.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;ghe-license-usage &lt;/code&gt; command-line utility includes a new &lt;code&gt;--unencrypted&lt;/code&gt; option to provide visibility into the exported license usage file.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 10 Mar 2020 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.20</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In some cases the forwarded log entries, mainly for audit.log were getting truncated.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-license-check&lt;/code&gt; command-line utility returned an &amp;quot;Invalid license file&amp;quot; error for some valid licenses, causing configuration changes to fail.&lt;/li&gt;
&lt;li&gt;Alambic exception logs were not forwarded by syslog.&lt;/li&gt;
&lt;li&gt;The &lt;a href=&quot;https://developer.github.com/v3/activity/events/types/#orgblockevent&quot;&gt;&lt;code&gt;org_block event&lt;/code&gt;&lt;/a&gt; is not unavailable but was appearing for GitHub Apps on GitHub Enterprise Server.&lt;/li&gt;
&lt;li&gt;GraphQL query responses sometimes returned unmatched node identifiers for &lt;code&gt;ProtectedBranch&lt;/code&gt; objects.&lt;/li&gt;
&lt;li&gt;The GitHub App credential used by GitHub Connect failed to refresh immediately after expiry.&lt;/li&gt;
&lt;li&gt;Using ghe-migrator or exporting from GitHub.com, an export would silently fail to export non-image attachments.&lt;/li&gt;
&lt;li&gt;Pre-receive hook returned 500 error on web UI when UTF-8 characters were encountered.&lt;/li&gt;
&lt;li&gt;Signing out on Chrome was taking 30+ seconds when using a non-incognito browser.&lt;/li&gt;
&lt;li&gt;Leaving a comment in reply to a pull request comment was intermittently creating a pending pull request review.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;ghe-license-usage &lt;/code&gt; command-line utility includes a new &lt;code&gt;--unencrypted&lt;/code&gt; option to provide visibility into the exported license usage file.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 10 Mar 2020 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.1</title>
					<description></description>
					<pubDate>Thu, 27 Feb 2020 16:00:40 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.8</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Restore from backups would fail with an &lt;code&gt;Invalid RDB version number&lt;/code&gt; error.&lt;/li&gt;
&lt;li&gt;Upgrading an HA replica would stall indefinitely waiting for MySQL to start.&lt;/li&gt;
&lt;li&gt;Importing teams from external sources failed when there were spaces in the team name.&lt;/li&gt;
&lt;li&gt;PR review comments with unexpected values for &amp;quot;position&amp;quot; or &amp;quot;original_position&amp;quot; caused imports to fail.&lt;/li&gt;
&lt;li&gt;Project hovercards were not properly displayed.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When pushing to a gist, an exception could be triggered during the post-receive hook.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Thu, 27 Feb 2020 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.13</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Upgrading an HA replica would stall indefinitely waiting for MySQL to start.&lt;/li&gt;
&lt;li&gt;Importing teams from external sources failed when there were spaces in the team name.&lt;/li&gt;
&lt;li&gt;PR review comments with unexpected values for &amp;quot;position&amp;quot; or &amp;quot;original_position&amp;quot; caused imports to fail.&lt;/li&gt;
&lt;li&gt;Project hovercards were not properly displayed.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Thu, 27 Feb 2020 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.19</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Thu, 27 Feb 2020 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.20.0</title>
					<description></description>
					<pubDate>Tue, 11 Feb 2020 16:00:40 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.20.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.20.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.7</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Dependency Graph for Python repositories failed to update.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;GITHUB_REPO_PUBLIC&lt;/code&gt; environment variable passed to pre-receive hooks could be empty.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Background queues were re-prioritized to increase performance in large environments.&lt;/li&gt;
&lt;li&gt;Improved formatting of the example output of blocked Subversion access on the Admin Center repository Subversion management page.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When pushing to a gist, an exception could be triggered during the post-receive hook.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 11 Feb 2020 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.12</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Dependency Graph for Python repositories failed to update.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;GITHUB_REPO_PUBLIC&lt;/code&gt; environment variable passed to pre-receive hooks could be empty.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Improved formatting of the example output of blocked Subversion access on the Admin Center repository Subversion management page.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 11 Feb 2020 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.18</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Dependency Graph for Python repositories failed to update.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;GITHUB_REPO_PUBLIC&lt;/code&gt; environment variable passed to pre-receive hooks could be empty.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Improved formatting of the example output of blocked Subversion access on the Admin Center repository Subversion management page.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 11 Feb 2020 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.6</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Obtaining a Lets Encrypt via Enterprise Manage would fail to install the certificate.&lt;/li&gt;
&lt;li&gt;Support bundle generation wasn&#39;t possible when consul was unavailable.&lt;/li&gt;
&lt;li&gt;Service startup wouldn&#39;t wait for MySQL database to accept connections.&lt;/li&gt;
&lt;li&gt;GitHub Apps acting on behalf of a user could not list a repositories forks via the REST API.&lt;/li&gt;
&lt;li&gt;GitHub Connect code search presented the user with an error instead of search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When pushing to a gist, an exception could be triggered during the post-receive hook.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 28 Jan 2020 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.11</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Obtaining a Lets Encrypt via Enterprise Manage would fail to install the certificate.&lt;/li&gt;
&lt;li&gt;Support bundle generation wasn&#39;t possible when consul was unavailable.&lt;/li&gt;
&lt;li&gt;Service startup wouldn&#39;t wait for MySQL database to accept connections.&lt;/li&gt;
&lt;li&gt;GitHub Connect code search presented the user with an error instead of search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 28 Jan 2020 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.17</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Obtaining a Lets Encrypt via Enterprise Manage would fail to install the certificate.&lt;/li&gt;
&lt;li&gt;Support bundle generation wasn&#39;t possible when consul was unavailable.&lt;/li&gt;
&lt;li&gt;Service startup wouldn&#39;t wait for MySQL database to accept connections.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 28 Jan 2020 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.5</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Git has been updated to address &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1348&quot;&gt;CVE-2019-1348&lt;/a&gt;, &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1349&quot;&gt;CVE-2019-1349&lt;/a&gt;, &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1350&quot;&gt;CVE-2019-1350&lt;/a&gt;, &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1351&quot;&gt;CVE-2019-1351&lt;/a&gt;, &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1352&quot;&gt;CVE-2019-1352&lt;/a&gt;, &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1353&quot;&gt;CVE-2019-1353&lt;/a&gt;, &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1354&quot;&gt;CVE-2019-1354&lt;/a&gt;, and &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19604&quot;&gt;CVE-2019-19604&lt;/a&gt;.  These vulnerabilities could not be triggered on the GitHub Enteprise Server instance itself, but new restrictions prevent malicious repositories from being pushed to the server instance, protecting clients which have not yet been patched.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The root disk utilization graph in the Management Console was missing on AWS Nitro instance types.&lt;/li&gt;
&lt;li&gt;The Alambic storage service could hit a file descriptor limit that could cause the kernel to hang and other services to log errors.&lt;/li&gt;
&lt;li&gt;Importing of teams with nested teams with security visibility could fail. Nested teams will now be imported as top-level teams if they are imported as children of a team with secret visibility.&lt;/li&gt;
&lt;li&gt;When a repository is locked users could still directly visit pull request URLs and modify the reviewers.&lt;/li&gt;
&lt;li&gt;A team created via the API V3 would not automatically add its creator as a maintainer, which caused it to be inaccessible to that person.&lt;/li&gt;
&lt;li&gt;A GitHub App with the proper set of permissions was not able to create teams with LDAP.&lt;/li&gt;
&lt;li&gt;The DNS resolution for GitHub Connect could timeout.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When pushing to a gist, an exception could be triggered during the post-receive hook.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 15 Jan 2020 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.10</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Git has been updated to address &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1348&quot;&gt;CVE-2019-1348&lt;/a&gt;, &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1349&quot;&gt;CVE-2019-1349&lt;/a&gt;, &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1350&quot;&gt;CVE-2019-1350&lt;/a&gt;, &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1351&quot;&gt;CVE-2019-1351&lt;/a&gt;, &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1352&quot;&gt;CVE-2019-1352&lt;/a&gt;, &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1353&quot;&gt;CVE-2019-1353&lt;/a&gt;, &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1354&quot;&gt;CVE-2019-1354&lt;/a&gt;, and &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19604&quot;&gt;CVE-2019-19604&lt;/a&gt;.  These vulnerabilities could not be triggered on the GitHub Enteprise Server instance itself, but new restrictions prevent malicious repositories from being pushed to the server instance, protecting clients which have not yet been patched.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The root disk utilization graph in the Management Console was missing on AWS Nitro instance types.&lt;/li&gt;
&lt;li&gt;The Alambic storage service could hit a file descriptor limit that could cause the kernel to hang and other services to log errors.&lt;/li&gt;
&lt;li&gt;Importing of teams with nested teams with security visibility could fail. Nested teams will now be imported as top-level teams if they are imported as children of a team with secret visibility.&lt;/li&gt;
&lt;li&gt;When a repository is locked users could still directly visit pull request URLs and modify the reviewers.&lt;/li&gt;
&lt;li&gt;A team created via the API V3 would not automatically add its creator as a maintainer, which caused it to be inaccessible to that person.&lt;/li&gt;
&lt;li&gt;A GitHub App with the proper set of permissions was not able to create teams with LDAP.&lt;/li&gt;
&lt;li&gt;The DNS resolution for GitHub Connect could timeout.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 15 Jan 2020 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.16</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Git has been updated to address &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1348&quot;&gt;CVE-2019-1348&lt;/a&gt;, &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1349&quot;&gt;CVE-2019-1349&lt;/a&gt;, &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1350&quot;&gt;CVE-2019-1350&lt;/a&gt;, &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1351&quot;&gt;CVE-2019-1351&lt;/a&gt;, &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1352&quot;&gt;CVE-2019-1352&lt;/a&gt;, &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1353&quot;&gt;CVE-2019-1353&lt;/a&gt;, &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1354&quot;&gt;CVE-2019-1354&lt;/a&gt;, and &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19604&quot;&gt;CVE-2019-19604&lt;/a&gt;.  These vulnerabilities could not be triggered on the GitHub Enteprise Server instance itself, but new restrictions prevent malicious repositories from being pushed to the server instance, protecting clients which have not yet been patched.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The root disk utilization graph in the Management Console was missing on AWS Nitro instance types.&lt;/li&gt;
&lt;li&gt;The Alambic storage service could hit a file descriptor limit that could cause the kernel to hang and other services to log errors.&lt;/li&gt;
&lt;li&gt;Importing of teams with nested teams with security visibility could fail. Nested teams will now be imported as top-level teams if they are imported as children of a team with secret visibility.&lt;/li&gt;
&lt;li&gt;When a repository is locked users could still directly visit pull request URLs and modify the reviewers.&lt;/li&gt;
&lt;li&gt;A team created via the API V3 would not automatically add its creator as a maintainer, which caused it to be inaccessible to that person.&lt;/li&gt;
&lt;li&gt;A GitHub App with the proper set of permissions was not able to create teams with LDAP.&lt;/li&gt;
&lt;li&gt;The DNS resolution for GitHub Connect could timeout.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 15 Jan 2020 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.25</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Git has been updated to address &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1348&quot;&gt;CVE-2019-1348&lt;/a&gt;, &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1349&quot;&gt;CVE-2019-1349&lt;/a&gt;, &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1350&quot;&gt;CVE-2019-1350&lt;/a&gt;, &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1351&quot;&gt;CVE-2019-1351&lt;/a&gt;, &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1352&quot;&gt;CVE-2019-1352&lt;/a&gt;, &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1353&quot;&gt;CVE-2019-1353&lt;/a&gt;, &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1354&quot;&gt;CVE-2019-1354&lt;/a&gt;, and &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-19604&quot;&gt;CVE-2019-19604&lt;/a&gt;.  These vulnerabilities could not be triggered on the GitHub Enteprise Server instance itself, but new restrictions prevent malicious repositories from being pushed to the server instance, protecting clients which have not yet been patched.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Alambic storage service could hit a file descriptor limit that could cause the kernel to hang and other services to log errors.&lt;/li&gt;
&lt;li&gt;Importing of teams with nested teams with security visibility could fail. Nested teams will now be imported as top-level teams if they are imported as children of a team with secret visibility.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.16&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.16 will be deprecated as of January 22, 2020&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 15 Jan 2020 16:00:36 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.25</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.25</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.4</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM:&lt;/strong&gt; An attacker could push a malicious GitHub Pages branch with overlapping submodule names, possibly leading to remote code execution within the GitHub Pages build container. To exploit this vulnerability, an attacker would need permission to create a branch within a repository on the GitHub Enterprise Server instance. &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1387&quot;&gt;CVE-2019-1387&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Unknown locales were generating errors when running commands in the administrative shell.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-config-check&lt;/code&gt; was returning validation errors for &lt;code&gt;github-ssl.acme.ca-conf&lt;/code&gt; and &lt;code&gt;syslog.cert&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The Let&#39;s Encrypt certificate registration feature consistently failed following an update to the external API.&lt;/li&gt;
&lt;li&gt;Upgrades could fail due to a missing SQL table.&lt;/li&gt;
&lt;li&gt;Commit objects could be lost in some cases if an update of a replica failed and then a repair operation was ran.&lt;/li&gt;
&lt;li&gt;Commit messages containing links were not clickable or properly rendered in blame view.&lt;/li&gt;
&lt;li&gt;When importing review comments that were created using old versions of GHES, some comments would fail to import due to corrupt diffs.&lt;/li&gt;
&lt;li&gt;Audit log did not include some entries when changing protected branches settings.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Increase autolink reference limit to 50.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When pushing to a gist, an exception could be triggered during the post-receive hook.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 17 Dec 2019 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.9</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM:&lt;/strong&gt; An attacker could push a malicious GitHub Pages branch with overlapping submodule names, possibly leading to remote code execution within the GitHub Pages build container. To exploit this vulnerability, an attacker would need permission to create a branch within a repository on the GitHub Enterprise Server instance. &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1387&quot;&gt;CVE-2019-1387&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Unknown locales were generating errors when running commands in the administrative shell.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-config-check&lt;/code&gt; was returning validation errors for &lt;code&gt;github-ssl.acme.ca-conf&lt;/code&gt; and &lt;code&gt;syslog.cert&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The Let&#39;s Encrypt certificate registration feature consistently failed following an update to the external API.&lt;/li&gt;
&lt;li&gt;Upgrades could fail due to a missing SQL table.&lt;/li&gt;
&lt;li&gt;Commit objects could be lost in some cases if an update of a replica failed and then a repair operation was ran.&lt;/li&gt;
&lt;li&gt;Commit messages containing links were not clickable or properly rendered in blame view.&lt;/li&gt;
&lt;li&gt;When importing review comments that were created using old versions of GHES, some comments would fail to import due to corrupt diffs.&lt;/li&gt;
&lt;li&gt;Audit log did not include some entries when changing protected branches settings.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 17 Dec 2019 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.15</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM:&lt;/strong&gt; An attacker could push a malicious GitHub Pages branch with overlapping submodule names, possibly leading to remote code execution within the GitHub Pages build container. To exploit this vulnerability, an attacker would need permission to create a branch within a repository on the GitHub Enterprise Server instance. &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1387&quot;&gt;CVE-2019-1387&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Unknown locales were generating errors when running commands in the administrative shell.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-config-check&lt;/code&gt; was returning validation errors for &lt;code&gt;github-ssl.acme.ca-conf&lt;/code&gt; and &lt;code&gt;syslog.cert&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The Let&#39;s Encrypt certificate registration feature consistently failed following an update to the external API.&lt;/li&gt;
&lt;li&gt;Upgrades could fail due to a missing SQL table.&lt;/li&gt;
&lt;li&gt;Commit objects could be lost in some cases if an update of a replica failed and then a repair operation was ran.&lt;/li&gt;
&lt;li&gt;A GraphQL query to retrieve the additions and deletions for a changed binary file returned a 500 error.&lt;/li&gt;
&lt;li&gt;Audit log did not include some entries when changing protected branches settings.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 17 Dec 2019 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.24</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM:&lt;/strong&gt; An attacker could push a malicious GitHub Pages branch with overlapping submodule names, possibly leading to remote code execution within the GitHub Pages build container. To exploit this vulnerability, an attacker would need permission to create a branch within a repository on the GitHub Enterprise Server instance. &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1387&quot;&gt;CVE-2019-1387&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-config-check&lt;/code&gt; was returning validation errors for &lt;code&gt;github-ssl.acme.ca-conf&lt;/code&gt; and &lt;code&gt;syslog.cert&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The Let&#39;s Encrypt certificate registration feature consistently failed following an update to the external API.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.16&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.16 will be deprecated as of January 22, 2020&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 17 Dec 2019 16:00:36 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.24</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.24</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.3</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Graphs for some metrics in the Management Console &#39;Monitor&#39; page were displaying data in the opposite ordering than expected.&lt;/li&gt;
&lt;li&gt;Site Admin users could encounter timeouts when attempting to impersonate accounts that were members of a large number of Organizations.&lt;/li&gt;
&lt;li&gt;Backups of GitHub Enterprise Server clusters could intermittently fail due to duplicated Gist repository references.&lt;/li&gt;
&lt;li&gt;Transient, non-fatal errors returned from external LDAP servers during team synchronization operations could cause the incorrect removal of team members.&lt;/li&gt;
&lt;li&gt;GitHub Apps were unable to modify GitHub Team memberships via the API.&lt;/li&gt;
&lt;li&gt;GrahpQL queries that referenced Organizations could run slowly and occasionally time out on a GitHub Enterprise Server instance that contained a large number of Organizations.&lt;/li&gt;
&lt;li&gt;Inviting users to a team could time out if the invitees weren&#39;t already members of that team&#39;s Organization.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Background job queues have been re-ordered to reduce the chances of user-visible jobs being delayed on very busy instances.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;The &lt;em&gt;Let&#39;s Encrypt&lt;/em&gt; certificate registration feature consistently fails following an update to the external API.&lt;/li&gt;
&lt;li&gt;When pushing to a gist, an exception could be triggered during the post-receive hook.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 03 Dec 2019 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.8</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Graphs for some metrics in the Management Console &#39;Monitor&#39; page were displaying data in the opposite ordering than expected.&lt;/li&gt;
&lt;li&gt;Site Admin users could encounter timeouts when attempting to impersonate accounts that were members of a large number of Organizations.&lt;/li&gt;
&lt;li&gt;Backups of GitHub Enterprise Server clusters could intermittently fail due to duplicated Gist repository references.&lt;/li&gt;
&lt;li&gt;Transient, non-fatal errors returned from external LDAP servers during team synchronization operations could cause the incorrect removal of team members.&lt;/li&gt;
&lt;li&gt;GrahpQL queries that referenced Organizations could run slowly and occasionally time out on a GitHub Enterprise Server instance that contained a large number of Organizations.&lt;/li&gt;
&lt;li&gt;Inviting users to a team could time out if the invitees weren&#39;t already members of that team&#39;s Organization.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Background job queues have been re-ordered to reduce the chances of user-visible jobs being delayed on very busy instances.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;The &lt;em&gt;Let&#39;s Encrypt&lt;/em&gt; certificate registration feature consistently fails following an update to the external API.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 03 Dec 2019 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.14</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Graphs for some metrics in the Management Console &#39;Monitor&#39; page were displaying data in the opposite ordering than expected.&lt;/li&gt;
&lt;li&gt;Backups of GitHub Enterprise Server clusters could intermittently fail due to duplicated Gist repository references.&lt;/li&gt;
&lt;li&gt;Transient, non-fatal errors returned from external LDAP servers during team synchronization operations could cause the incorrect removal of team members.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Background job queues have been re-ordered to reduce the chances of user-visible jobs being delayed on very busy instances.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable.&lt;/li&gt;
&lt;li&gt;The &lt;em&gt;Let&#39;s Encrypt&lt;/em&gt; certificate registration feature consistently fails following an update to the external API.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 03 Dec 2019 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.23</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Backups of GitHub Enterprise Server clusters could intermittently fail due to duplicated Gist repository references.&lt;/li&gt;
&lt;li&gt;Transient, non-fatal errors returned from external LDAP servers during team synchronization operations could cause the incorrect removal of team members.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.16&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.16 will be deprecated as of January 22, 2020&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;li&gt;The &lt;em&gt;Let&#39;s Encrypt&lt;/em&gt; certificate registration feature consistently fails following an update to the external API.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 03 Dec 2019 16:00:36 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.23</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.23</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.2</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH:&lt;/strong&gt; The legacy avatar upgrade functionality was vulnerable to a Server-Side Request Forgery (SSRF) vulnerability when fetching image content from third-party avatar services. This could allow an attacker to make GET requests to internal services reachable from the GitHub Enterprise deployment.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Storage objects were incorrectly deleted from non-voting replicas, potentially leading to data loss on replica promotion.&lt;/li&gt;
&lt;li&gt;Unsubscribe email notification language was inconsistent with the language used in the web interface.&lt;/li&gt;
&lt;li&gt;Team membership information could be destroyed during an upgrade from GHES 2.17.&lt;/li&gt;
&lt;li&gt;The related issues feature was incorrectly included in the release.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;The &lt;em&gt;Let&#39;s Encrypt&lt;/em&gt; certificate registration feature consistently fails following an update to the external API.&lt;/li&gt;
&lt;li&gt;When pushing to a gist, an exception could be triggered during the post-receive hook.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 20 Nov 2019 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.7</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH:&lt;/strong&gt; The legacy avatar upgrade functionality was vulnerable to a Server-Side Request Forgery (SSRF) vulnerability when fetching image content from third-party avatar services. This could allow an attacker to make GET requests to internal services reachable from the GitHub Enterprise deployment.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW:&lt;/strong&gt; The &lt;code&gt;script-src: &#39;unsafe-inline&#39;&lt;/code&gt; CSP header was applied to all paths for Enterprise Manager.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Promoting a replica in an active HA environment could fail to properly apply configuration changes and remove a pre-flight check holding page.&lt;/li&gt;
&lt;li&gt;A race condition could occur when a replica node was rebooted, preventing the internal VPN from starting correctly.&lt;/li&gt;
&lt;li&gt;MySQL replication lag could rise significantly on high traffic instances during times of peak user activity.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Google Accounts Daemon and &lt;code&gt;google_set_hostname&lt;/code&gt; DHCP hook are now disabled on Google Cloud Platform images.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise Server is now available in the eu-north-1 AWS region.&lt;/li&gt;
&lt;li&gt;MySQL database seeding progress is reported during replication setup and recorded in the configuration log.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When using Let&#39;s Encrypt with a new installation, an error can occur when creating a new Let&#39;s Encrypt account.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 20 Nov 2019 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.13</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH:&lt;/strong&gt; The legacy avatar upgrade functionality was vulnerable to a Server-Side Request Forgery (SSRF) vulnerability when fetching image content from third-party avatar services. This could allow an attacker to make GET requests to internal services reachable from the GitHub Enterprise deployment.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW:&lt;/strong&gt; The &lt;code&gt;script-src: &#39;unsafe-inline&#39;&lt;/code&gt; CSP header was applied to all paths for Enterprise Manager.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Promoting a replica in an active HA environment could fail to properly apply configuration changes and remove a pre-flight check holding page.&lt;/li&gt;
&lt;li&gt;In certain cluster configurations, background jobs are unable to communicate with local storage services.&lt;/li&gt;
&lt;li&gt;MySQL replication lag could rise significantly on high traffic instances during times of peak user activity.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Google Accounts Daemon and &lt;code&gt;google_set_hostname&lt;/code&gt; DHCP hook are now disabled on Google Cloud Platform images.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise Server is now available in the eu-north-1 AWS region.&lt;/li&gt;
&lt;li&gt;MySQL database seeding progress is reported during replication setup and recorded in the configuration log.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable.&lt;/li&gt;
&lt;li&gt;When using Let&#39;s Encrypt with a new installation, an error can occur when creating a new Let&#39;s Encrypt account.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 20 Nov 2019 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.22</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH:&lt;/strong&gt; The legacy avatar upgrade functionality was vulnerable to a Server-Side Request Forgery (SSRF) vulnerability when fetching image content from third-party avatar services. This could allow an attacker to make GET requests to internal services reachable from the GitHub Enterprise deployment.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW:&lt;/strong&gt; The &lt;code&gt;script-src: &#39;unsafe-inline&#39;&lt;/code&gt; CSP header was applied to all paths for Enterprise Manager.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Promoting a replica in an active HA environment could fail to properly apply configuration changes and remove a pre-flight check holding page.&lt;/li&gt;
&lt;li&gt;In certain cluster configurations, background jobs are unable to communicate with local storage services.&lt;/li&gt;
&lt;li&gt;MySQL replication lag could rise significantly on high traffic instances during times of peak user activity.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise Server is now available in the eu-north-1 AWS region.&lt;/li&gt;
&lt;li&gt;MySQL database seeding progress is reported during replication setup and recorded in the configuration log.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;li&gt;When using Let&#39;s Encrypt with a new installation, an error can occur when creating a new Let&#39;s Encrypt account.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 20 Nov 2019 16:00:36 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.1</title>
					<description>&lt;p&gt;&lt;strong&gt;Due to a database migration error, we have disabled access to the 2.19.1 images. This error will be resolved in the next patch release.&lt;/strong&gt;&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW:&lt;/strong&gt; The &lt;code&gt;script-src: &#39;unsafe-inline&#39;&lt;/code&gt; CSP header was applied to all paths for Enterprise Manager.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Promoting a replica in an active HA environment could fail to properly apply configuration changes and remove a pre-flight check holding page.&lt;/li&gt;
&lt;li&gt;In certain cluster configurations, background jobs are unable to communicate with local storage services.&lt;/li&gt;
&lt;li&gt;Upgrading from 2.17 to 2.19 could fail with a database migration error.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Google Accounts Daemon and &lt;code&gt;google_set_hostname&lt;/code&gt; DHCP hook are now disabled on Google Cloud Platform images.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise Server is now available in the eu-north-1 AWS region.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;The &lt;em&gt;Let&#39;s Encrypt&lt;/em&gt; certificate registration feature consistently fails following an update to the external API.&lt;/li&gt;
&lt;li&gt;When pushing to a gist, an exception could be triggered during the post-receive hook.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Fri, 15 Nov 2019 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.19.0</title>
					<description>&lt;p&gt;&lt;strong&gt;Due to a database migration error, we have disabled access to the 2.19.0 images. This error will be resolved in the next patch release.&lt;/strong&gt;&lt;/p&gt;
&lt;h2&gt;Features&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Organization and repository administrators can assign the &lt;code&gt;triage&lt;/code&gt; and &lt;code&gt;maintain&lt;/code&gt; roles to users and teams.&lt;/li&gt;
&lt;li&gt;When an issue is referenced with a &lt;a href=&quot;https://docs.github.com/en/articles/closing-issues-using-keywords&quot;&gt;closing keyword&lt;/a&gt; in a pull request description, the referenced issue will now surface the relevant pull request information in its header.&lt;/li&gt;
&lt;li&gt;The dependency graph supports &lt;code&gt;.vcxproj&lt;/code&gt; and &lt;code&gt;.fsproj&lt;/code&gt; files that list NuGet dependencies in their PackageReference section.&lt;/li&gt;
&lt;li&gt;The WebAuthn standard is supported for authentication.&lt;/li&gt;
&lt;li&gt;Users can change the project board columns of issues directly from the issue sidebar.&lt;/li&gt;
&lt;li&gt;GitHub Pages supports adding a remote theme using Jekyll.&lt;/li&gt;
&lt;li&gt;Administrators can utilize the Audit Log GraphQL API.&lt;/li&gt;
&lt;li&gt;The dependency graph supports &lt;a href=&quot;https://docs.npmjs.com/misc/scope&quot;&gt;scoped npm packages&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Repositories can be set to delete the head branch of a pull request once it has merged into the base branch.&lt;/li&gt;
&lt;li&gt;Enterprise accounts can be managed using the &lt;a href=&quot;https://developer.github.com/v4/guides/managing-enterprise-accounts&quot;&gt;GraphQL API&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Enterprise accounts can issue their members SSH certificates to access repositories over Git.&lt;/li&gt;
&lt;li&gt;Administrators can enable &lt;a href=&quot;https://docs.github.com/en/github/writing-on-github/autolinked-references-and-urls&quot;&gt;autolink references&lt;/a&gt; on repositories. (updated 2019-11-13)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Team maintainers could not add child teams to their teams if &amp;quot;Allow members to create teams&amp;quot; was disabled.&lt;/li&gt;
&lt;li&gt;Pull requests authors with read permissions could not re-request reviews.&lt;/li&gt;
&lt;li&gt;A label could be shown as removed from a pull request that it was never added to.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The web notification retention policy has been increased to 5 months for all notification types.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-repl-status&lt;/code&gt; command shows more granular status information for consul replication.&lt;/li&gt;
&lt;li&gt;Audit log data is now stored in Elasticsearch instead of MySQL.&lt;/li&gt;
&lt;li&gt;Users will only be able to see the Secret teams they are part of in the list of teams.&lt;/li&gt;
&lt;li&gt;Users will be listed as owners of the organizations they own when logged in.&lt;/li&gt;
&lt;li&gt;Pull requests are shown under Recent Activity when they&#39;ve recently been reviewed.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Backups and Disaster Recovery&lt;/h2&gt;
&lt;p&gt;GitHub Enterprise Server 2.19 requires at least &lt;a href=&quot;https://github.com/github/backup-utils&quot;&gt;GitHub Enterprise Backup Utilities&lt;/a&gt; 2.19.0 for &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/backups-and-disaster-recovery/&quot;&gt;Backups and Disaster Recovery&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Upcoming Deprecation of GitHub Enterprise Server 2.16&lt;/h2&gt;
&lt;p&gt;GitHub Enterprise Server 2.16 will be deprecated as of January 22, 2020. That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Upcoming Deprecation of Adding New SSH-DSS Keys&lt;/h2&gt;
&lt;p&gt;The addition of new SSH-DSS keys will be removed in GitHub Enterprise Server 2.20.0.&lt;/p&gt;
&lt;h2&gt;Upcoming Deprecation of the Legacy Gravatar Service&lt;/h2&gt;
&lt;p&gt;Support for using an external service for Avatars was deprecated in GitHub Enterprise Server 2.1.0. At the time, functionality was implemented to copy avatars from the external service to the GitHub Enterprise Server and the configuration options remained in Enterprise Manage for instances configured with an external service prior to the deprecation. This functionality and configuration will be removed from GitHub Enterprise Server 2.20.0.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;The &lt;em&gt;Let&#39;s Encrypt&lt;/em&gt; certificate registration feature consistently fails following an update to the external API.&lt;/li&gt;
&lt;li&gt;When pushing to a gist, an exception could be triggered during the post-receive hook.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 12 Nov 2019 16:00:39 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.19.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.19.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.6</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM:&lt;/strong&gt; The repository import functionality was vulnerable to a Server Side Request Forgery (SSRF) issue when importing TFS repositories.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The storage objects were incorrectly deleted from non-voting replicas.&lt;/li&gt;
&lt;li&gt;In some cases systemd would fail to start services after a reboot.&lt;/li&gt;
&lt;li&gt;Submitting the form to request to change a team&#39;s parent team with an empty value caused an error.&lt;/li&gt;
&lt;li&gt;The GitHub App installation page returned a timeout error for some users and Apps.&lt;/li&gt;
&lt;li&gt;Unsubscribe email notification language was inconsistent with the language used in the web interface.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 05 Nov 2019 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.12</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM:&lt;/strong&gt; The repository import functionality was vulnerable to a Server Side Request Forgery (SSRF) issue when importing TFS repositories.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The storage objects were incorrectly deleted from non-voting replicas.&lt;/li&gt;
&lt;li&gt;In some cases systemd would fail to start services after a reboot.&lt;/li&gt;
&lt;li&gt;Submitting the form to request to change a team&#39;s parent team with an empty value caused an error.&lt;/li&gt;
&lt;li&gt;Unsubscribe email notification language was inconsistent with the language used in the web interface.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 05 Nov 2019 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.21</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM:&lt;/strong&gt; The repository import functionality was vulnerable to a Server Side Request Forgery (SSRF) issue when importing TFS repositories.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The storage objects were incorrectly deleted from non-voting replicas.&lt;/li&gt;
&lt;li&gt;In some cases systemd would fail to start services after a reboot.&lt;/li&gt;
&lt;li&gt;Submitting the form to request to change a team&#39;s parent team with an empty value caused an error.&lt;/li&gt;
&lt;li&gt;Unsubscribe email notification language was inconsistent with the language used in the web interface.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 05 Nov 2019 16:00:36 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.5</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH:&lt;/strong&gt; The repository import functionality was vulnerable to a command injection issue when importing Mercurial repositories.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In a clustering environment, trying to add files to a repository using the web interface or pushing commits from the command line interface could fail.&lt;/li&gt;
&lt;li&gt;A 500 Internal Server Error could occur when creating a new organization.&lt;/li&gt;
&lt;li&gt;GitHub Apps were unable to modify GitHub Team memberships via the API.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 23 Oct 2019 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.11</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH:&lt;/strong&gt; The repository import functionality was vulnerable to a command injection issue when importing Mercurial repositories.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A 500 Internal Server Error could occur when creating a new organization.&lt;/li&gt;
&lt;li&gt;GitHub Apps were unable to modify GitHub Team memberships via the API.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 23 Oct 2019 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.20</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH:&lt;/strong&gt; The repository import functionality was vulnerable to a command injection issue when importing Mercurial repositories.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A 500 Internal Server Error could occur when creating a new organization.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 23 Oct 2019 16:00:36 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.4</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Git pushes could take a long time when pushing to a fork of a repository with a lot of forks.&lt;/li&gt;
&lt;li&gt;Webhooks could not be created or updated to point to &lt;code&gt;.consul&lt;/code&gt; domains.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 08 Oct 2019 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.10</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Webhooks could not be created or updated to point to &lt;code&gt;.consul&lt;/code&gt; domains.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 08 Oct 2019 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.19</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Webhooks could not be created or updated to point to &lt;code&gt;.consul&lt;/code&gt; domains.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 08 Oct 2019 16:00:36 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.24</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.15&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.15 will be deprecated as of October 16, 2019&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 08 Oct 2019 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.24</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.24</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.3</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Missing /etc/aliases.db file caused the deferred mail queue to fill with internal alert messages.&lt;/li&gt;
&lt;li&gt;The text toolbar and the subheading were overlapping on the global enterprise account Messages pages.&lt;/li&gt;
&lt;li&gt;It was possible for the two-factor authentication requirement on the global enterprise account to remain enabled after switching to an authentication mode that does not support built-in two-factor authentication (such as SAML).&lt;/li&gt;
&lt;li&gt;In large repos the protected branch settings page was loading slowly and triggering a timeout error.&lt;/li&gt;
&lt;li&gt;Attempting to unarchive a repository would fail due to schema mismatch.&lt;/li&gt;
&lt;li&gt;Viewing blobs in a repository was slow and could cause timeout errors under certain network conditions.&lt;/li&gt;
&lt;li&gt;Forking a private repository into an organization was erroneously blocked by an error that mentioned upgrading your plan.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Added support for r5.8xlarge and r5.16xlarge EC2 instance types&lt;/li&gt;
&lt;li&gt;The number of pull requests that can be created from the same head SHA1 is limited to 100 by default.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 25 Sep 2019 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.9</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;It was possible for the two-factor authentication requirement on the global enterprise account to remain enabled after switching to an authentication mode that does not support built-in two-factor authentication (such as SAML).&lt;/li&gt;
&lt;li&gt;In large repos the protected branch settings page was loading slowly and triggering a timeout error.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The number of pull requests that can be created from the same head SHA1 is limited to 100 by default.&lt;/li&gt;
&lt;li&gt;Added support for r5.8xlarge and r5.16xlarge EC2 instance types&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 25 Sep 2019 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.18</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;It was possible for the two-factor authentication requirement on the global enterprise account to remain enabled after switching to an authentication mode that does not support built-in two-factor authentication (such as SAML).&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The number of pull requests that can be created from the same head SHA1 is limited to 100 by default.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 25 Sep 2019 16:00:36 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.23</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The number of pull requests that can be created from the same head SHA1 is limited to 100 by default.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.15&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.15 will be deprecated as of October 16, 2019&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 25 Sep 2019 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.23</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.23</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.2</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Live updates for pull requests and issues would fail due to an incorrect list of allowed origin domains.&lt;/li&gt;
&lt;li&gt;A Git operation could fail to connect to the server with a SIGABRT error in certain cases.&lt;/li&gt;
&lt;li&gt;WireGuard private keys were missing in some cases, causing a failure to connect.&lt;/li&gt;
&lt;li&gt;Restarting replication after an upgrade using &lt;code&gt;ghe-repl-start&lt;/code&gt; could fail to detect an existing configuration run and break the replication between HA nodes.&lt;/li&gt;
&lt;li&gt;Promotion of an HA replica would cause a memory leak in some cases.&lt;/li&gt;
&lt;li&gt;Site administrators could have two-factor authentication disabled via the Site Admin dashboard when two-factor authentication was enabled on the global enterprise account.&lt;/li&gt;
&lt;li&gt;A background job that doesn&#39;t apply to GitHub Enterprise Server was enqueued but never processed.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 10 Sep 2019 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.8</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Site administrators could have two-factor authentication disabled via the Site Admin dashboard when two-factor authentication was enabled on the global enterprise account.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 10 Sep 2019 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.17</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 10 Sep 2019 16:00:36 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.22</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.15&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.15 will be deprecated as of October 16, 2019&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 10 Sep 2019 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.1</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On appliances that send a lot of notifications, GitHub Enterprise opened too many connections to the configured email server which delayed delivery in certain cases.&lt;/li&gt;
&lt;li&gt;When a SAML Session expired before a form was submitted, users of Chrome would not be redirected to the SAML authentication workflow.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Adjusted the amount of logging for the Alive service to reduce noise.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Issue, pull request, and project pages may not automatically update with changes from other users. (updated 2019-08-30)&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 27 Aug 2019 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.7</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On appliances that send a lot of notifications, GitHub Enterprise opened too many connections to the configured email server which delayed delivery in certain cases.&lt;/li&gt;
&lt;li&gt;GPG key warning used to appear during fresh installs.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 27 Aug 2019 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.16</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On appliances that send a lot of notifications, GitHub Enterprise opened too many connections to the configured email server which delayed delivery in certain cases.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 27 Aug 2019 16:00:36 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.21</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On appliances that send a lot of notifications, GitHub Enterprise opened too many connections to the configured email server which delayed delivery in certain cases.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.15&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.15 will be deprecated as of October 16, 2019&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 27 Aug 2019 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.18.0</title>
					<description>&lt;h2&gt;Features&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://github.blog/2019-06-25-assign-issues-to-issue-commenters/&quot;&gt;Issues can be assigned to read-only contributors that have commented on the issue&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.blog/changelog/2019-05-30-milestones-in-project-cards/&quot;&gt;Milestones are now visible on project boards&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.blog/changelog/2019-06-12-auto-watching-updates/&quot;&gt;User-owned repositories are automatically watched for updates upon creation&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.blog/changelog/2019-05-08-gist-notifications/&quot;&gt;Users can receive notifications for conversations occurring on Gists&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.blog/changelog/2019-05-09-custom-thread-subscriptions/&quot;&gt;Users can limit the types of notifications they receive for any issue and pull request to be specific to &lt;code&gt;merge&lt;/code&gt;, &lt;code&gt;reopened&lt;/code&gt; and/or &lt;code&gt;closed&lt;/code&gt; events&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/en/articles/transferring-an-issue-to-another-repository&quot;&gt;Users can transfer issues from one repository to another that they have write access to&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.blog/2019-07-02-yarn-support-for-security-alerts/&quot;&gt;Security alerts are supported for repositories using Yarn for dependency management&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.blog/2019-06-06-generate-new-repositories-with-repository-templates/&quot;&gt;Repository admins can make an existing repository a template&lt;/a&gt; so users can generate new repositories with the same directory structure and files.&lt;/li&gt;
&lt;li&gt;Organization owners can &lt;a href=&quot;https://docs.github.com/en/articles/managing-the-display-of-member-names-in-your-organization&quot;&gt;choose to display their member&#39;s profile names&lt;/a&gt; in comments on private repositories.&lt;/li&gt;
&lt;li&gt;The audit log can now be &lt;a href=&quot;https://docs.github.com/en/enterprise/2.18/user/articles/reviewing-the-audit-log-for-your-organization#exporting-the-audit-log&quot;&gt;exported in JSON or CSV format&lt;/a&gt; and queried using the &lt;a href=&quot;https://docs.github.com/en/enterprise/2.18/user/articles/reviewing-the-audit-log-for-your-organization#using-the-audit-log-api&quot;&gt;Audit log API&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Cards can be converted to issues on user owned projects.&lt;/li&gt;
&lt;li&gt;Users have the option to toggle annotations in the diff view.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: An attacker could inject potentially malicious options into Git sub-commands when executed on the server. This could allow an attacker to truncate existing files on the server or execute other unintended functionality of affected Git sub-commands. To exploit this vulnerability, an attacker would need permission to create a branch within a repository on the GitHub Enterprise Server instance. This vulnerability was reported through the GitHub Security Bug Bounty program.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: GitHub App permissions could be incorrectly set by the user.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise Server was incorrectly using &lt;code&gt;support@example.com&lt;/code&gt; as the sender of notification emails if a URL was used for the support link instead of an email address.&lt;/li&gt;
&lt;li&gt;GitHub app managers were able to access and manage applications for the organization after being removed from it.&lt;/li&gt;
&lt;li&gt;Lines in gists were not selectable.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;WireGuard replaces OpenVPN as the technology used to encrypt communication between nodes in High Availability configurations.&lt;/li&gt;
&lt;li&gt;Webhook payloads include the milestone object when milestones are added or removed.&lt;/li&gt;
&lt;li&gt;Links to all the pull requests associated with a security alert are viewable on the security alerts page.&lt;/li&gt;
&lt;li&gt;Users are able to update their branch with the base branch when a pull request is in draft status.&lt;/li&gt;
&lt;li&gt;Files marked as reviewed will be marked as unreviewed for all users that have previously reviewed the file after a new commit has been made.&lt;/li&gt;
&lt;li&gt;Reduced memory utilization on GitHub Enterprise Server instances.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;longpoll&lt;/code&gt; service has been replaced with &lt;code&gt;alive&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/en/enterprise/admin/installation/upgrading-github-enterprise-server#upgrading-an-appliance-that-has-replica-instances-using-an-upgrade-package&quot;&gt;Replication must be stopped during a feature upgrade&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Backups and Disaster Recovery&lt;/h2&gt;
&lt;p&gt;GitHub Enterprise Server 2.18 requires at least &lt;a href=&quot;https://github.com/github/backup-utils&quot;&gt;GitHub Enterprise Backup Utilities&lt;/a&gt; 2.18.0 for &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/backups-and-disaster-recovery/&quot;&gt;Backups and Disaster Recovery&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.15&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.15 will be deprecated as of October 16, 2019.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules are not maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent Subversion checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Issue, pull request, and project pages may not automatically update with changes from other users. (updated 2019-08-30)&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;li&gt;Security alerts are not reported when pushing to a repository on the command line. (updated 2020-06-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 20 Aug 2019 16:00:38 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.18.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.18.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.6</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: An attacker could inject potentially malicious options into Git sub-commands when executed on the server. This could allow an attacker to truncate existing files on the server or execute other unintended functionality of affected Git sub-commands. To exploit this vulnerability, an attacker would need permission to create a branch within a repository on the GitHub Enterprise Server instance. This vulnerability was reported through the GitHub Security Bug Bounty program.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: GitHub App permissions could be incorrectly set by the user.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The database wouldn&#39;t automatically reconnect, which caused dependency graphs not to show on repositories.&lt;/li&gt;
&lt;li&gt;When creating an organization, name availability check wouldn&#39;t correctly display its URL.&lt;/li&gt;
&lt;li&gt;Using ghe-migrator or exporting from GitHub.com, an export would silently fail to export issue comments when a repository was archived.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise Server was incorrectly using &lt;code&gt;support@example.com&lt;/code&gt; as the sender of notification emails in certain circumstances.&lt;/li&gt;
&lt;li&gt;GitHub app managers were able to access and manage applications for the organization after being removed from it.&lt;/li&gt;
&lt;li&gt;Comparing OAuth Access Tokens returned 404 Not Found error.&lt;/li&gt;
&lt;li&gt;Deleting a repository and its projects could delete other owned or accessible projects.&lt;/li&gt;
&lt;li&gt;When enabling a feature for GitHub Connect resulted in an error, users were not properly notified.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Reduced memory utilization on GitHub Enterprise Server instances.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 13 Aug 2019 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.15</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: An attacker could inject potentially malicious options into Git sub-commands when executed on the server. This could allow an attacker to truncate existing files on the server or execute other unintended functionality of affected Git sub-commands. To exploit this vulnerability, an attacker would need permission to create a branch within a repository on the GitHub Enterprise Server instance. This vulnerability was reported through the GitHub Security Bug Bounty program.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: GitHub App permissions could be incorrectly set by the user.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Using ghe-migrator or exporting from GitHub.com, an export would silently fail to export issue comments when a repository was archived.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise Server was incorrectly using &lt;code&gt;support@example.com&lt;/code&gt; as the sender of notification emails in certain circumstances.&lt;/li&gt;
&lt;li&gt;Comparing OAuth Access Tokens returned 404 Not Found error.&lt;/li&gt;
&lt;li&gt;Deleting a repository and its projects could delete other owned or accessible projects.&lt;/li&gt;
&lt;li&gt;When enabling a feature for GitHub Connect resulted in an error, users were not properly notified.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Reduced memory utilization on GitHub Enterprise Server instances.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 13 Aug 2019 16:00:36 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.20</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: An attacker could inject potentially malicious options into Git sub-commands when executed on the server. This could allow an attacker to truncate existing files on the server or execute other unintended functionality of affected Git sub-commands. To exploit this vulnerability, an attacker would need permission to create a branch within a repository on the GitHub Enterprise Server instance. This vulnerability was reported through the GitHub Security Bug Bounty program.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: GitHub App permissions could be incorrectly set by the user.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise Server was incorrectly using &lt;code&gt;support@example.com&lt;/code&gt; as the sender of notification emails in certain circumstances.&lt;/li&gt;
&lt;li&gt;Comparing OAuth Access Tokens returned 404 Not Found error.&lt;/li&gt;
&lt;li&gt;Deleting a repository and its projects could delete other owned or accessible projects.&lt;/li&gt;
&lt;li&gt;When enabling a feature for GitHub Connect resulted in an error, users were not properly notified.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Reduced memory utilization on GitHub Enterprise Server instances.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 13 Aug 2019 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.5</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Identical node identifiers on high availability replica nodes could prevent configuring or updating high availability replication.&lt;/li&gt;
&lt;li&gt;Consul did not automatically recover when a node&#39;s identity changed unexpectedly.&lt;/li&gt;
&lt;li&gt;An incorrect free memory total was calculated when determining the available memory required to install a hotpatch.&lt;/li&gt;
&lt;li&gt;Hypervisor type and root volumes were incorrectly detected on AWS Nitro instance types, preventing non-hotpatch upgrades.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable.&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 23 Jul 2019 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.14</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Identical node identifiers on high availability replica nodes could prevent configuring or updating high availability replication.&lt;/li&gt;
&lt;li&gt;Consul did not automatically recover when a node&#39;s identity changed unexpectedly.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 23 Jul 2019 16:00:36 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.19</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Identical node identifiers on high availability replica nodes could prevent configuring or updating high availability replication.&lt;/li&gt;
&lt;li&gt;Consul did not automatically recover when a node&#39;s identity changed unexpectedly.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 23 Jul 2019 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.4</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Resque workers may not have been cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;li&gt;Viewing the profile of a user with a username similar to a common HTML error page, for example &lt;code&gt;404-html&lt;/code&gt;, would display the error page and not the user&#39;s profile.&lt;/li&gt;
&lt;li&gt;Reattaching a forked repository to its parent after changing the visibility would fail for the second and subsequent forks.&lt;/li&gt;
&lt;li&gt;The global enterprise account members page did not list all members of the installation.&lt;/li&gt;
&lt;li&gt;Creating a new repository could fail with a 404 error if the user is an owner of a large number of organizations.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Hypervisor type and root volumes are incorrectly detected on AWS Nitro instance types, preventing non-hotpatch upgrades. (updated: 2019-07-09)&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable. (updated: 2019-07-19)&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 02 Jul 2019 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.13</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Viewing the profile of a user with a username similar to a common HTML error page, for example &lt;code&gt;404-html&lt;/code&gt;, would display the error page and not the user&#39;s profile.&lt;/li&gt;
&lt;li&gt;Reattaching a forked repository to its parent after changing the visibility would fail for the second and subsequent forks.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 02 Jul 2019 16:00:36 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.18</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Viewing the profile of a user with a username similar to a common HTML error page, for example &lt;code&gt;404-html&lt;/code&gt;, would display the error page and not the user&#39;s profile.&lt;/li&gt;
&lt;li&gt;Reattaching a forked repository to its parent after changing the visibility would fail for the second and subsequent forks.&lt;/li&gt;
&lt;li&gt;LFS pushes could fail if a repository admin was suspended.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 02 Jul 2019 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.25</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Viewing the profile of a user with a username similar to a common HTML error page, for example &lt;code&gt;404-html&lt;/code&gt;, would display the error page and not the user&#39;s profile.&lt;/li&gt;
&lt;li&gt;Reattaching a forked repository to its parent after changing the visibility would fail for the second and subsequent forks.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.14&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.14 will be deprecated as of July 12, 2019&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 02 Jul 2019 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.25</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.25</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.3</title>
					<description>&lt;h2&gt;OAuth app authorization bypass&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; vulnerability was identified that allows an attacker to authorize an OAuth application on the account of a targeted user without the approval of the targeted user. This would allow an attacker to execute actions on behalf of the targeted user via the authorized OAuth application. The attacker would need to be able to create an OAuth application on the affected GitHub Enterprise Server instance to perform this attack. Additionally, to execute the attack, the targeted user would need to visit an attacker controlled website.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.14.0 - 2.14.23&lt;/li&gt;
&lt;li&gt;2.15.0 - 2.15.16&lt;/li&gt;
&lt;li&gt;2.16.0 - 2.16.11&lt;/li&gt;
&lt;li&gt;2.17.0 - 2.17.2&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We &lt;strong&gt;strongly&lt;/strong&gt; recommend upgrading your GitHub Enterprise Server appliance to the latest patch release in your series, GitHub Enterprise Server 2.14.24, 2.15.17, 2.16.12, 2.17.3, or greater immediately. If you have any questions, please contact GitHub support at &lt;a href=&quot;https://enterprise.github.com/support&quot;&gt;https://enterprise.github.com/support&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This vulnerability was reported through the &lt;a href=&quot;https://bounty.github.com/&quot;&gt;GitHub Security Bug Bounty&lt;/a&gt; program.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: A malicious OAuth application could be authorized on a targeted user&#39;s account without requiring user approval, allowing an attacker to execute actions on behalf of the user.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;li&gt;Hypervisor type and root volumes are incorrectly detected on AWS Nitro instance types, preventing non-hotpatch upgrades. (updated: 2019-07-09)&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable. (updated: 2019-07-19)&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 26 Jun 2019 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.12</title>
					<description>&lt;h2&gt;OAuth app authorization bypass&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; vulnerability was identified that allows an attacker to authorize an OAuth application on the account of a targeted user without the approval of the targeted user. This would allow an attacker to execute actions on behalf of the targeted user via the authorized OAuth application. The attacker would need to be able to create an OAuth application on the affected GitHub Enterprise Server instance to perform this attack. Additionally, to execute the attack, the targeted user would need to visit an attacker controlled website.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.14.0 - 2.14.23&lt;/li&gt;
&lt;li&gt;2.15.0 - 2.15.16&lt;/li&gt;
&lt;li&gt;2.16.0 - 2.16.11&lt;/li&gt;
&lt;li&gt;2.17.0 - 2.17.2&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We &lt;strong&gt;strongly&lt;/strong&gt; recommend upgrading your GitHub Enterprise Server appliance to the latest patch release in your series, GitHub Enterprise Server 2.14.24, 2.15.17, 2.16.12, 2.17.3, or greater immediately. If you have any questions, please contact GitHub support at &lt;a href=&quot;https://enterprise.github.com/support&quot;&gt;https://enterprise.github.com/support&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This vulnerability was reported through the &lt;a href=&quot;https://bounty.github.com/&quot;&gt;GitHub Security Bug Bounty&lt;/a&gt; program.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: A malicious OAuth application could be authorized on a targeted user&#39;s account without requiring user approval, allowing an attacker to execute actions on behalf of the user.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 26 Jun 2019 16:00:36 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.17</title>
					<description>&lt;h2&gt;OAuth app authorization bypass&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; vulnerability was identified that allows an attacker to authorize an OAuth application on the account of a targeted user without the approval of the targeted user. This would allow an attacker to execute actions on behalf of the targeted user via the authorized OAuth application. The attacker would need to be able to create an OAuth application on the affected GitHub Enterprise Server instance to perform this attack. Additionally, to execute the attack, the targeted user would need to visit an attacker controlled website.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.14.0 - 2.14.23&lt;/li&gt;
&lt;li&gt;2.15.0 - 2.15.16&lt;/li&gt;
&lt;li&gt;2.16.0 - 2.16.11&lt;/li&gt;
&lt;li&gt;2.17.0 - 2.17.2&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We &lt;strong&gt;strongly&lt;/strong&gt; recommend upgrading your GitHub Enterprise Server appliance to the latest patch release in your series, GitHub Enterprise Server 2.14.24, 2.15.17, 2.16.12, 2.17.3, or greater immediately. If you have any questions, please contact GitHub support at &lt;a href=&quot;https://enterprise.github.com/support&quot;&gt;https://enterprise.github.com/support&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This vulnerability was reported through the &lt;a href=&quot;https://bounty.github.com/&quot;&gt;GitHub Security Bug Bounty&lt;/a&gt; program.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: A malicious OAuth application could be authorized on a targeted user&#39;s account without requiring user approval, allowing an attacker to execute actions on behalf of the user.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 26 Jun 2019 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.24</title>
					<description>&lt;h2&gt;OAuth app authorization bypass&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; vulnerability was identified that allows an attacker to authorize an OAuth application on the account of a targeted user without the approval of the targeted user. This would allow an attacker to execute actions on behalf of the targeted user via the authorized OAuth application. The attacker would need to be able to create an OAuth application on the affected GitHub Enterprise Server instance to perform this attack. Additionally, to execute the attack, the targeted user would need to visit an attacker controlled website.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.14.0 - 2.14.23&lt;/li&gt;
&lt;li&gt;2.15.0 - 2.15.16&lt;/li&gt;
&lt;li&gt;2.16.0 - 2.16.11&lt;/li&gt;
&lt;li&gt;2.17.0 - 2.17.2&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;We &lt;strong&gt;strongly&lt;/strong&gt; recommend upgrading your GitHub Enterprise Server appliance to the latest patch release in your series, GitHub Enterprise Server 2.14.24, 2.15.17, 2.16.12, 2.17.3, or greater immediately. If you have any questions, please contact GitHub support at &lt;a href=&quot;https://enterprise.github.com/support&quot;&gt;https://enterprise.github.com/support&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;This vulnerability was reported through the &lt;a href=&quot;https://bounty.github.com/&quot;&gt;GitHub Security Bug Bounty&lt;/a&gt; program.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: A malicious OAuth application could be authorized on a targeted user&#39;s account without requiring user approval, allowing an attacker to execute actions on behalf of the user.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 26 Jun 2019 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.24</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.24</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.2</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: An attacker with direct network access to the server could send a specially crafted sequence of network packets that could cause a kernel panic or slow down the system causing a Denial of Service (DoS). For more information, see the associated CVEs: &lt;a href=&quot;https://security-tracker.debian.org/tracker/CVE-2019-11477&quot;&gt;CVE-2019-11477&lt;/a&gt;, &lt;a href=&quot;https://security-tracker.debian.org/tracker/CVE-2019-11478&quot;&gt;CVE-2019-11478&lt;/a&gt;, &lt;a href=&quot;https://security-tracker.debian.org/tracker/CVE-2019-11479&quot;&gt;CVE-2019-11479&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Internal API data values exceeded internal buffer sizes and caused access from the Git command-line to fail unconditionally for some users or deploy keys.&lt;/li&gt;
&lt;li&gt;In single node appliances, the &lt;code&gt;ghe-export-audit-logs&lt;/code&gt; command did not correctly detect the instance type in some cases, causing backups to fail.&lt;/li&gt;
&lt;li&gt;Adding a new node to a currently or previously configured high availability replication primary node that has been upgraded to GitHub Enterprise Server 2.17 could fail due to a missing &lt;code&gt;/etc/openvpn/easy-rsa/openssl.cnf&lt;/code&gt; file.&lt;/li&gt;
&lt;li&gt;Pre-seeding the initial replica appliance in a HA configuration would result in the failure of the existing primary appliance.&lt;/li&gt;
&lt;li&gt;The GitHub Connect &amp;quot;Learn more&amp;quot; link beside the message &amp;quot;You can now connect to an enterprise account&amp;quot; pointed to a nonexistent help article.&lt;/li&gt;
&lt;li&gt;The &amp;quot;Learn why&amp;quot; link beside the message &amp;quot;Custom sign-in messages are disabled when SAML authentication is enabled&amp;quot; pointed to a nonexistent help article.&lt;/li&gt;
&lt;li&gt;The GraphQL API would only return 300 objects instead of the documented 3000.&lt;/li&gt;
&lt;li&gt;In the GraphQL API, the &lt;code&gt;suggestedReviewers&lt;/code&gt; field returned an error when queried in combination with some other fields (e.g., &lt;code&gt;additions&lt;/code&gt; or &lt;code&gt;deletions&lt;/code&gt;).&lt;/li&gt;
&lt;li&gt;Displayed an invalid prompt when editing &lt;code&gt;FUNDING.yml&lt;/code&gt;, which would then also fail to preview changes correctly.&lt;/li&gt;
&lt;li&gt;The Collaboration &amp;quot;Funding model links&amp;quot; section would appear within the UI.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks that printed non UTF-8 characters would fail with an &amp;quot;incompatible character encodings&amp;quot; error message.&lt;/li&gt;
&lt;li&gt;When attempting to search for private repositories on GitHub.com via GitHub Connect, a 500 Internal Server Error occurred.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise Server incorrectly enforced a version of Backup Utilities that was the same or newer than the precise patch version of GitHub Enterprise Server.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise is now available in the AWS GovCloud (US-East) region.&lt;/li&gt;
&lt;li&gt;When pushing a very large number of Git LFS objects to a repository, the returning &amp;quot;Git LFS Integrity Check&amp;quot; warning message was confusing, leading users to think something went wrong.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;li&gt;Hypervisor type and root volumes are incorrectly detected on AWS Nitro instance types, preventing non-hotpatch upgrades. (updated: 2019-07-09)&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable. (updated: 2019-07-19)&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 19 Jun 2019 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.11</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: An attacker with direct network access to the server could send a specially crafted sequence of network packets that could cause a kernel panic or slow down the system causing a Denial of Service (DoS). For more information, see the associated CVEs: &lt;a href=&quot;https://security-tracker.debian.org/tracker/CVE-2019-11477&quot;&gt;CVE-2019-11477&lt;/a&gt;, &lt;a href=&quot;https://security-tracker.debian.org/tracker/CVE-2019-11478&quot;&gt;CVE-2019-11478&lt;/a&gt;, &lt;a href=&quot;https://security-tracker.debian.org/tracker/CVE-2019-11479&quot;&gt;CVE-2019-11479&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Internal API data values exceeded internal buffer sizes and caused access from the Git command-line to fail unconditionally for some users or deploy keys.&lt;/li&gt;
&lt;li&gt;Pre-seeding the initial replica appliance in a HA configuration would result in the failure of the existing primary appliance.&lt;/li&gt;
&lt;li&gt;The &amp;quot;Learn why&amp;quot; link beside the message &amp;quot;Custom sign-in messages are disabled when SAML authentication is enabled&amp;quot; pointed to a nonexistent help article.&lt;/li&gt;
&lt;li&gt;In the GraphQL API, the &lt;code&gt;suggestedReviewers&lt;/code&gt; field returned an error when queried in combination with some other fields (e.g., &lt;code&gt;additions&lt;/code&gt; or &lt;code&gt;deletions&lt;/code&gt;).&lt;/li&gt;
&lt;li&gt;Pre-receive hooks that printed non UTF-8 characters would fail with an &amp;quot;incompatible character encodings&amp;quot; error message.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise Server incorrectly enforced a version of Backup Utilities that was the same or newer than the precise patch version of GitHub Enterprise Server.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;When pushing a very large number of Git LFS objects to a repository, the returning &amp;quot;Git LFS Integrity Check&amp;quot; warning message was confusing, leading users to think something went wrong.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 19 Jun 2019 16:00:36 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.16</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: An attacker with direct network access to the server could send a specially crafted sequence of network packets that could cause a kernel panic or slow down the system causing a Denial of Service (DoS). For more information, see the associated CVEs: &lt;a href=&quot;https://security-tracker.debian.org/tracker/CVE-2019-11477&quot;&gt;CVE-2019-11477&lt;/a&gt;, &lt;a href=&quot;https://security-tracker.debian.org/tracker/CVE-2019-11478&quot;&gt;CVE-2019-11478&lt;/a&gt;, &lt;a href=&quot;https://security-tracker.debian.org/tracker/CVE-2019-11479&quot;&gt;CVE-2019-11479&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Internal API data values exceeded internal buffer sizes and caused access from the Git command-line to fail unconditionally for some users or deploy keys.&lt;/li&gt;
&lt;li&gt;Pre-seeding the initial replica appliance in a HA configuration would result in the failure of the existing primary appliance.&lt;/li&gt;
&lt;li&gt;The &amp;quot;Learn why&amp;quot; link beside the message &amp;quot;Custom sign-in messages are disabled when SAML authentication is enabled&amp;quot; pointed to a nonexistent help article.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise incorrectly enforced a version of Backup Utilities that was the same or newer than the precise patch version of GitHub Enterprise.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;When pushing a very large number of Git LFS objects to a repository, the returning &amp;quot;Git LFS Integrity Check&amp;quot; warning message was confusing, leading users to think something went wrong.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 19 Jun 2019 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.23</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: An attacker with direct network access to the server could send a specially crafted sequence of network packets that could cause a kernel panic or slow down the system causing a Denial of Service (DoS). For more information, see the associated CVEs: &lt;a href=&quot;https://security-tracker.debian.org/tracker/CVE-2019-11477&quot;&gt;CVE-2019-11477&lt;/a&gt;, &lt;a href=&quot;https://security-tracker.debian.org/tracker/CVE-2019-11478&quot;&gt;CVE-2019-11478&lt;/a&gt;, &lt;a href=&quot;https://security-tracker.debian.org/tracker/CVE-2019-11479&quot;&gt;CVE-2019-11479&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise incorrectly enforced a version of Backup Utilities that was the same or newer than the precise patch version of GitHub Enterprise.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 19 Jun 2019 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.23</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.23</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.1</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Using &lt;code&gt;ghe-migrator&lt;/code&gt; or exporting from GitHub.com, an export would silently fail to export pull request review comments when a repository was archived.&lt;/li&gt;
&lt;li&gt;Rename conflicts were not detected while importing from some 3rd party systems using &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The GitHub Blog URL was incorrect.&lt;/li&gt;
&lt;li&gt;GitHub app permissions were not properly displayed during app creation.&lt;/li&gt;
&lt;li&gt;The global enterprise account listed suspended outside collaborators.&lt;/li&gt;
&lt;li&gt;Recently promoted site admins could be suspended by another site admin without revoking site admin privilege first.&lt;/li&gt;
&lt;li&gt;A partially completed GitHub Connect permissions request would be requested on a subsequent unrelated permission request.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Adjusted the memcached graph to include the memory &amp;quot;used&amp;quot; in addition to the memory &amp;quot;free&amp;quot;.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;client_id&lt;/code&gt; and &lt;code&gt;client_secret&lt;/code&gt; were added to the JSON payload when creating a GitHub App via manifest.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;li&gt;Adding a new node to a currently or previously configured high availability replication primary node that has been upgraded to GitHub Enterprise Server 2.17 may fail due to a missing &lt;code&gt;/etc/openvpn/easy-rsa/openssl.cnf&lt;/code&gt; file. (updated: 2019-06-19)&lt;/li&gt;
&lt;li&gt;GitHub Enterprise Server incorrectly enforces a version of Backup Utilities that is the same or newer than the precise patch version of GitHub Enterprise Server. (updated 2019-06-25)&lt;/li&gt;
&lt;li&gt;Hypervisor type and root volumes are incorrectly detected on AWS Nitro instance types, preventing non-hotpatch upgrades. (updated: 2019-07-09)&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable. (updated: 2019-07-19)&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 04 Jun 2019 00:00:01 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.10</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Using &lt;code&gt;ghe-migrator&lt;/code&gt; or exporting from GitHub.com, an export would silently fail to export pull request review comments when a repository was archived.&lt;/li&gt;
&lt;li&gt;Rename conflicts were not detected while importing from some 3rd party systems using &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Adjusted the memcached graph to include the memory &amp;quot;used&amp;quot; in addition to the memory &amp;quot;free&amp;quot;.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;client_id&lt;/code&gt; and &lt;code&gt;client_secret&lt;/code&gt; were added to the JSON payload when creating a GitHub App via manifest.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise Server incorrectly enforces a version of Backup Utilities that is the same or newer than the precise patch version of GitHub Enterprise Server. (updated 2019-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 04 Jun 2019 00:00:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.15</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Using &lt;code&gt;ghe-migrator&lt;/code&gt; or exporting from GitHub.com, an export would silently fail to export pull request review comments when a repository was archived.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Adjusted the memcached graph to include the memory &amp;quot;used&amp;quot; in addition to the memory &amp;quot;free&amp;quot;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise incorrectly enforces a version of Backup Utilities that is the same or newer than the precise patch version of GitHub Enterprise. (updated 2019-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 04 Jun 2019 00:00:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.22</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise incorrectly enforces a version of Backup Utilities that is the same or newer than the precise patch version of GitHub Enterprise. (updated 2019-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 04 Jun 2019 00:00:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.17.0</title>
					<description>&lt;h2&gt;Features&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Users can create draft pull requests.&lt;/li&gt;
&lt;li&gt;Pull request reviewers can expand and contract the diff view.&lt;/li&gt;
&lt;li&gt;Code authors can commit a batch of suggested changes as a single commit.&lt;/li&gt;
&lt;li&gt;Security alerts are available to customers utilizing GitHub Connect.&lt;/li&gt;
&lt;li&gt;Organization owners can view and export a list of users that have access to a repository.&lt;/li&gt;
&lt;li&gt;Users can create and manage their own project boards.&lt;/li&gt;
&lt;li&gt;Users can set a status on their profile.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise Server supports more AWS EC2 instance types with the AWS Nitro System.&lt;/li&gt;
&lt;li&gt;Organization owners can revoke personal access token via the API.&lt;/li&gt;
&lt;li&gt;Users can view a list of all the repository releases that are being watched.&lt;/li&gt;
&lt;li&gt;Organization owners can restrict members&#39; ability to create teams.&lt;/li&gt;
&lt;li&gt;Users can view all of their subscriptions to issues and pull requests.&lt;/li&gt;
&lt;li&gt;Audit log data is now stored in MySQL instead of Elasticsearch.&lt;/li&gt;
&lt;li&gt;Users can exclude labels from search in an issue or pull request list filter.&lt;/li&gt;
&lt;li&gt;Organization owners can grant users the ability to manage either individual GitHub Apps or all GitHub Apps in an organization.&lt;/li&gt;
&lt;li&gt;Users can mark previously viewed notifications as unread.&lt;/li&gt;
&lt;li&gt;License usage can be uploaded to GitHub Enterprise Cloud for customers utilizing GitHub Connect.&lt;/li&gt;
&lt;li&gt;Users can view information about the author of an issue or pull request by hovering over their username in sticky conversation headers.&lt;/li&gt;
&lt;li&gt;Users can reset their profile picture to the default &lt;a href=&quot;https://github.blog/2013-08-14-identicons/&quot;&gt;identicon&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;Organization admins can restrict email notifications for activity within their organization to one or more verified domains.&lt;/del&gt; (update: 2019-10-04)&lt;/li&gt;
&lt;li&gt;Pull request review summary comments now support reactions, edit history, quote replies, and copying URLs.&lt;/li&gt;
&lt;li&gt;Users can pin gists to their profile.&lt;/li&gt;
&lt;li&gt;Organization admins can enable the dependency graph for their organization if utilizing GitHub Connect.&lt;/li&gt;
&lt;li&gt;Users can re-request a code review to notify requested reviewers that changes have been made to a pull request.&lt;/li&gt;
&lt;li&gt;Users can select a different repository when opening a new issue from a comment.&lt;/li&gt;
&lt;li&gt;Users can copy comment permalinks on mobile.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise Server admins can enable Transport Layer Security (TLS) version 1.3.&lt;/li&gt;
&lt;li&gt;Users can close or open an issue or pull request from the projects side pane.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: An endpoint in the GitHub API would disclose sensitive user information in its error response. The disclosed information included authentication tokens that could be used to authenticate as unauthorized users. An authenticated user on the instance would be required to access to the affected API.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: External collaborators received security vulnerability alerts after write access to a repository was revoked.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Assigned issues in another users private repository could appear in an issues search.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;/var/log/github/exceptions.log&lt;/code&gt; file could include a large number of &lt;code&gt;QueryWarningLogger::QueryWarning&lt;/code&gt; errors.&lt;/li&gt;
&lt;li&gt;Organizations imported with &lt;code&gt;ghe-migrator&lt;/code&gt; were not added to the global enterprise account.&lt;/li&gt;
&lt;li&gt;The diff context for diffs that included submodules would sometimes load incorrect content.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&#39;Business Account&#39; has been renamed to &#39;Enterprise Account&#39;.&lt;/li&gt;
&lt;li&gt;The user/organization dashboard is now full-width and responsive.&lt;/li&gt;
&lt;li&gt;When a user opens a new issue from a comment, the new issue will include the full original comment text in its body.&lt;/li&gt;
&lt;li&gt;Users can close the detail pane for a project board by pressing the &lt;code&gt;esc&lt;/code&gt; key.&lt;/li&gt;
&lt;li&gt;Organization names can now include spaces.&lt;/li&gt;
&lt;li&gt;The blob editor page is now responsive.&lt;/li&gt;
&lt;li&gt;The maximum number of files in API diffs is 3000.&lt;/li&gt;
&lt;li&gt;Organization admins can view the Two-Factor Authentication (2FA) status of organization members via the API.&lt;/li&gt;
&lt;li&gt;Deleted repositories can be restored in bulk.&lt;/li&gt;
&lt;li&gt;Users must have at least one verified email to create a gist.&lt;/li&gt;
&lt;li&gt;If contribution guidelines have been added to a repository, they are shown in the sidebar when a user opens their first issue in that repository.&lt;/li&gt;
&lt;li&gt;Organization administrators can invite members of other organizations in the same business when there are no remaining seats.&lt;/li&gt;
&lt;li&gt;The live page updates keep-alive has been reduced to 30 seconds to better accommodate load balancer related timeouts.&lt;/li&gt;
&lt;li&gt;The minimum recommended hardware requirements for GitHub Enterprise Server have been updated.  (updated 2019-05-30)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Backups and Disaster Recovery&lt;/h2&gt;
&lt;p&gt;GitHub Enterprise Server 2.17 requires at least &lt;a href=&quot;https://github.com/github/backup-utils&quot;&gt;GitHub Enterprise Backup Utilities&lt;/a&gt; 2.17.0 for &lt;a href=&quot;https://docs.github.com/enterprise/2.17/admin/guides/installation/backups-and-disaster-recovery/&quot;&gt;Backups and Disaster Recovery&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.14&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.14 will be deprecated as of July 12, 2019.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.17/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Deprecation of GitHub Services&lt;/h2&gt;
&lt;p&gt;Starting with GitHub Enterprise Server 2.17.0, support for GitHub Services is now deprecated and administrators will not be able to install or configure new GitHub Services. Existing GitHub Services from a previous version of GitHub Enterprise Server will continue to function but GitHub Enterprise Server will not be providing any security or bug fixes to the GitHub Services functionality. At this time, there will be no changes to the existing functionality, but a warning banner is displayed with the &lt;a href=&quot;https://developer.github.com/changes/2018-04-25-github-services-deprecation/&quot;&gt;deprecation announcement blog post&lt;/a&gt;. Administrators can see which repositories are using GitHub Services with &lt;code&gt;ghe-legacy-github-services-report&lt;/code&gt;.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Subversion (SVN) checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;li&gt;Adding a new node to a currently or previously configured high availability replication primary node that has been upgraded to GitHub Enterprise Server 2.17 may fail due to a missing &lt;code&gt;/etc/openvpn/easy-rsa/openssl.cnf&lt;/code&gt; file. (updated: 2019-06-19)&lt;/li&gt;
&lt;li&gt;Hypervisor type and root volumes are incorrectly detected on AWS Nitro instance types, preventing non-hotpatch upgrades. (updated: 2019-07-09)&lt;/li&gt;
&lt;li&gt;Lines in gists are not selectable. (updated: 2019-07-19)&lt;/li&gt;
&lt;li&gt;When &amp;quot;Users can search GitHub.com&amp;quot; is enabled with GitHub Connect, issues in private and internal repositories are not included in GitHub.com search results.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The ability for Organization admins to restrict email notifications for activity within their organization is not included in GitHub Enterprise Server 2.17.0.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Thu, 23 May 2019 16:00:37 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.17.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.17.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.9</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: An endpoint in the GitHub API would disclose sensitive user information in its error response. The disclosed information included authentication tokens that could be used to authenticate as unauthorized users. An authenticated user on the instance would be required to access to the affected API.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;/var/log/github/exceptions.log&lt;/code&gt; file could include a large number of &lt;code&gt;QueryWarningLogger::QueryWarning&lt;/code&gt; errors.&lt;/li&gt;
&lt;li&gt;Organizations imported with &lt;code&gt;ghe-migrator&lt;/code&gt; were not added to the global enterprise account.&lt;/li&gt;
&lt;li&gt;The diff context for diffs that included submodules would sometimes load incorrect content.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 21 May 2019 16:00:36 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.14</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: An endpoint in the GitHub API would disclose sensitive user information in its error response. The disclosed information included authentication tokens that could be used to authenticate as unauthorized users. An authenticated user on the instance would be required to access to the affected API.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 21 May 2019 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.21</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: An endpoint in the GitHub API would disclose sensitive user information in its error response. The disclosed information included authentication tokens that could be used to authenticate as unauthorized users. An authenticated user on the instance would be required to access to the affected API.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 21 May 2019 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.8</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In certain cases, when a user would try to authorize their account through the &lt;a href=&quot;https://developer.github.com/apps/building-oauth-apps/authorizing-oauth-apps/#web-application-flow&quot;&gt;OAuth web application flow&lt;/a&gt;, not all of the requested scopes would appear on the authorization page.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;When using the quote reply feature &lt;code&gt;~strikethrough~&lt;/code&gt; text was not preserved and suggested changes were duplicated.&lt;/li&gt;
&lt;li&gt;Using &lt;code&gt;ghe-migrator&lt;/code&gt;, an import would fail if an attachment file was missing from the export archive.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.  (updated 2019-05-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 07 May 2019 16:00:36 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.13</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In certain cases, when a user would try to authorize their account through the &lt;a href=&quot;https://developer.github.com/apps/building-oauth-apps/authorizing-oauth-apps/#web-application-flow&quot;&gt;OAuth web application flow&lt;/a&gt;, not all of the requested scopes would appear on the authorization page.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;When using the quote reply feature &lt;code&gt;~strikethrough~&lt;/code&gt; text was not preserved and suggested changes were duplicated.&lt;/li&gt;
&lt;li&gt;Using &lt;code&gt;ghe-migrator&lt;/code&gt;, an import would fail if an attachment file was missing from the export archive.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.  (updated 2019-05-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 07 May 2019 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.20</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In certain cases, when a user would try to authorize their account through the &lt;a href=&quot;https://developer.github.com/apps/building-oauth-apps/authorizing-oauth-apps/#web-application-flow&quot;&gt;OAuth web application flow&lt;/a&gt;, not all of the requested scopes would appear on the authorization page.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 07 May 2019 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.7</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Consul logged errors when the dependency graph service was not enabled.&lt;/li&gt;
&lt;li&gt;GitHub Connect did not go through the proxy if the protocol/scheme wasn&#39;t part of the proxy URL configured in the management console.&lt;/li&gt;
&lt;li&gt;GitHub App manifests were not being created on instances with private mode enabled.&lt;/li&gt;
&lt;li&gt;GitHub Connect disconnection messages did not always reflect the enabled features.&lt;/li&gt;
&lt;li&gt;When viewing a diff, the indentation between the diff text and the expanded diff context was not aligned.&lt;/li&gt;
&lt;li&gt;Password change emails were incorrectly being sent for accounts created on initial LDAP login&lt;/li&gt;
&lt;li&gt;When importing from other platforms using ghe-migrator conflicts for teams were not detected.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.  (updated 2019-05-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 23 Apr 2019 16:00:36 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.12</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Connect disconnection messages did not always reflect the enabled features.&lt;/li&gt;
&lt;li&gt;Password change emails were incorrectly being sent for accounts created on initial LDAP login&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.  (updated 2019-05-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 23 Apr 2019 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.19</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 23 Apr 2019 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.6</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Release assets uploaded via the &lt;a href=&quot;https://developer.github.com/v3/repos/releases/#upload-a-release-asset&quot;&gt;Releases API&lt;/a&gt; would fail if the asset is larger than 1GB.&lt;/li&gt;
&lt;li&gt;The package validation performed when upgrading would print the result of an internal check.&lt;/li&gt;
&lt;li&gt;The maximum number of allowed connections to the internal HAProxy load balancer could be reached on very large instances leading to a large backlog of resqued jobs.&lt;/li&gt;
&lt;li&gt;DNS resolution of appliance hostnames in a HA configuration could timeout or return an incorrect IP address.&lt;/li&gt;
&lt;li&gt;Some pull requests and issues were purged completely when restoring the repository right after deleting it.&lt;/li&gt;
&lt;li&gt;When creating a new repository, default repository visibility input could have the wrong value selected.&lt;/li&gt;
&lt;li&gt;Links to the security alerts help documentation were incorrect.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Running &lt;code&gt;ghe-repl-promote&lt;/code&gt; will now prompt for confirmation. To promote a replica without confirmation, use the &lt;code&gt;-y&lt;/code&gt; flag:  &lt;code&gt;ghe-repl-promote -y&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.  (updated 2019-05-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 09 Apr 2019 16:00:36 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.11</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Release assets uploaded via the &lt;a href=&quot;https://developer.github.com/v3/repos/releases/#upload-a-release-asset&quot;&gt;Releases API&lt;/a&gt; would fail if the asset is larger than 1GB.&lt;/li&gt;
&lt;li&gt;The maximum number of allowed connections to the internal HAProxy load balancer could be reached on very large instances leading to a large backlog of resqued jobs.&lt;/li&gt;
&lt;li&gt;The package validation performed when upgrading would print the result of an internal check.&lt;/li&gt;
&lt;li&gt;DNS resolution of appliance hostnames in a HA configuration could timeout or return an incorrect IP address.&lt;/li&gt;
&lt;li&gt;Some pull requests and issues were purged completely when restoring the repository right after deleting it.&lt;/li&gt;
&lt;li&gt;Links to the security alerts help documentation were incorrect.&lt;/li&gt;
&lt;li&gt;When creating a new repository, default repository visibility input could have the wrong value selected.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Running &lt;code&gt;ghe-repl-promote&lt;/code&gt; will now prompt for confirmation. To promote a replica without confirmation, use the &lt;code&gt;-y&lt;/code&gt; flag:  &lt;code&gt;ghe-repl-promote -y&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.  (updated 2019-05-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 09 Apr 2019 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.18</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Release assets uploaded via the &lt;a href=&quot;https://developer.github.com/v3/repos/releases/#upload-a-release-asset&quot;&gt;Releases API&lt;/a&gt; would fail if the asset is larger than 1GB.&lt;/li&gt;
&lt;li&gt;The package validation performed when upgrading would print the result of an internal check.&lt;/li&gt;
&lt;li&gt;The maximum number of allowed connections to the internal HAProxy load balancer could be reached on very large instances leading to a large backlog of resqued jobs.&lt;/li&gt;
&lt;li&gt;DNS resolution of appliance hostnames in a HA configuration could timeout or return an incorrect IP address.&lt;/li&gt;
&lt;li&gt;Some pull requests and issues were purged completely when restoring the repository right after deleting it.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Running &lt;code&gt;ghe-repl-promote&lt;/code&gt; will now prompt for confirmation. To promote a replica without confirmation, use the &lt;code&gt;-y&lt;/code&gt; flag:  &lt;code&gt;ghe-repl-promote -y&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 09 Apr 2019 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.5</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Certain high throughput conditions caused MySQL to consume a large amount of CPU time.&lt;/li&gt;
&lt;li&gt;Certain scenarios resulted in a sign out message being displayed incorrectly.&lt;/li&gt;
&lt;li&gt;Inefficient connection handling for an internal service created unnecessary log entries and in extreme cases could lead to a service outage.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.  (updated 2019-05-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 26 Mar 2019 16:00:36 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.10</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Certain scenarios resulted in a sign out message being displayed incorrectly.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.  (updated 2019-05-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 26 Mar 2019 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.17</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Certain scenarios resulted in a sign out message being displayed incorrectly.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 26 Mar 2019 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.13.23</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Certain scenarios resulted in a sign out message being displayed incorrectly.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments are missing from an import with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise Server 2.13&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.13 will be deprecated as of March 27, 2019.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.16/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 26 Mar 2019 16:00:33 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.13.23</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.13.23</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.4</title>
					<description>&lt;h2&gt;Arbitrary file content disclosure vulnerability in GitHub Enterprise Server&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified in Rails that allows an attacker to send a specially crafted request that could allow arbitrary files to be read and the file content to be disclosed.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.13.0 - 2.13.21&lt;/li&gt;
&lt;li&gt;2.14.0 - 2.14.15&lt;/li&gt;
&lt;li&gt;2.15.0 - 2.15.8&lt;/li&gt;
&lt;li&gt;2.16.0 - 2.16.3&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;All older, no longer supported versions are also affected.&lt;/p&gt;
&lt;p&gt;We strongly urge upgrading your GitHub Enterprise Server appliance to the latest patch release in your series, GitHub Enterprise Server 2.13.22, 2.14.16, 2.15.9, 2.16.4, or greater immediately. If you have any questions, please contact GitHub support at &lt;a href=&quot;https://enterprise.github.com/support&quot;&gt;https://enterprise.github.com/support&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: A specially crafted request could allow arbitrary files to be read and the file content to be disclosed. For more information see the associated Rails CVE: &lt;a href=&quot;https://groups.google.com/forum/#!topic/rubyonrails-security/pFRKI96Sm8Q&quot;&gt;CVE-2019-5418&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: High CPU usage could be triggered by a specially crafted request resulting in Denial of Service (DoS). For more information see the associated Rails CVE: &lt;a href=&quot;https://groups.google.com/forum/#!topic/rubyonrails-security/GN7w9fFAQeI&quot;&gt;CVE-2019-5419&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repository pushes could fail to register in a cluster environment when a node was marked as offline.&lt;/li&gt;
&lt;li&gt;Appliance upgrades could time out when updating significantly large databases.&lt;/li&gt;
&lt;li&gt;In rare circumstances, a race condition could lead to repository data loss if an automated background maintenance job was triggered during a configuration update.&lt;/li&gt;
&lt;li&gt;Files couldn&#39;t be deleted via the web editor.&lt;/li&gt;
&lt;li&gt;LFS operations using a deploy key could fail with a HTTP 401 or 403 status if the deploy key creator was removed from the organization. (updated 2019-06-25)&lt;/li&gt;
&lt;li&gt;With private mode disabled, the &amp;quot;Explore&amp;quot; menu shown when signed out included a &amp;quot;Collections&amp;quot; link.&lt;/li&gt;
&lt;li&gt;A race condition during git operations sometimes caused the default branch to be assigned incorrectly.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.  (updated 2019-05-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 13 Mar 2019 16:00:36 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.9</title>
					<description>&lt;h2&gt;Arbitrary file content disclosure vulnerability in GitHub Enterprise Server&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified in Rails that allows an attacker to send a specially crafted request that could allow arbitrary files to be read and the file content to be disclosed.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.13.0 - 2.13.21&lt;/li&gt;
&lt;li&gt;2.14.0 - 2.14.15&lt;/li&gt;
&lt;li&gt;2.15.0 - 2.15.8&lt;/li&gt;
&lt;li&gt;2.16.0 - 2.16.3&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;All older, no longer supported versions are also affected.&lt;/p&gt;
&lt;p&gt;We strongly urge upgrading your GitHub Enterprise Server appliance to the latest patch release in your series, GitHub Enterprise Server 2.13.22, 2.14.16, 2.15.9, 2.16.4, or greater immediately. If you have any questions, please contact GitHub support at &lt;a href=&quot;https://enterprise.github.com/support&quot;&gt;https://enterprise.github.com/support&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: A specially crafted request could allow arbitrary files to be read and the file content to be disclosed. For more information see the associated Rails CVE: &lt;a href=&quot;https://groups.google.com/forum/#!topic/rubyonrails-security/pFRKI96Sm8Q&quot;&gt;CVE-2019-5418&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: High CPU usage could be triggered by a specially crafted request resulting in Denial of Service (DoS). For more information see the associated Rails CVE: &lt;a href=&quot;https://groups.google.com/forum/#!topic/rubyonrails-security/GN7w9fFAQeI&quot;&gt;CVE-2019-5419&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Appliance upgrades could time out when updating significantly large databases.&lt;/li&gt;
&lt;li&gt;In rare circumstances, a race condition could lead to repository data loss if an automated background maintenance job was triggered during a configuration update.&lt;/li&gt;
&lt;li&gt;A pull request with a status check that was created by a deleted GitHub App would fail to load and showed a 500 error.&lt;/li&gt;
&lt;li&gt;A race condition during git operations sometimes caused the default branch to be assigned incorrectly.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.  (updated 2019-05-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 13 Mar 2019 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.16</title>
					<description>&lt;h2&gt;Arbitrary file content disclosure vulnerability in GitHub Enterprise Server&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified in Rails that allows an attacker to send a specially crafted request that could allow arbitrary files to be read and the file content to be disclosed.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.13.0 - 2.13.21&lt;/li&gt;
&lt;li&gt;2.14.0 - 2.14.15&lt;/li&gt;
&lt;li&gt;2.15.0 - 2.15.8&lt;/li&gt;
&lt;li&gt;2.16.0 - 2.16.3&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;All older, no longer supported versions are also affected.&lt;/p&gt;
&lt;p&gt;We strongly urge upgrading your GitHub Enterprise Server appliance to the latest patch release in your series, GitHub Enterprise Server 2.13.22, 2.14.16, 2.15.9, 2.16.4, or greater immediately. If you have any questions, please contact GitHub support at &lt;a href=&quot;https://enterprise.github.com/support&quot;&gt;https://enterprise.github.com/support&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: A specially crafted request could allow arbitrary files to be read and the file content to be disclosed. For more information see the associated Rails CVE: &lt;a href=&quot;https://groups.google.com/forum/#!topic/rubyonrails-security/pFRKI96Sm8Q&quot;&gt;CVE-2019-5418&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: High CPU usage could be triggered by a specially crafted request resulting in Denial of Service (DoS). For more information see the associated Rails CVE: &lt;a href=&quot;https://groups.google.com/forum/#!topic/rubyonrails-security/GN7w9fFAQeI&quot;&gt;CVE-2019-5419&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In rare circumstances, a race condition could lead to repository data loss if an automated background maintenance job was triggered during a configuration update.&lt;/li&gt;
&lt;li&gt;A pull request with a status check that was created by a deleted GitHub App would fail to load and showed a 500 error.&lt;/li&gt;
&lt;li&gt;A race condition during git operations sometimes caused the default branch to be assigned incorrectly.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 13 Mar 2019 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.13.22</title>
					<description>&lt;h2&gt;Arbitrary file content disclosure vulnerability in GitHub Enterprise Server&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified in Rails that allows an attacker to send a specially crafted request that could allow arbitrary files to be read and the file content to be disclosed.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.13.0 - 2.13.21&lt;/li&gt;
&lt;li&gt;2.14.0 - 2.14.15&lt;/li&gt;
&lt;li&gt;2.15.0 - 2.15.8&lt;/li&gt;
&lt;li&gt;2.16.0 - 2.16.3&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;All older, no longer supported versions are also affected.&lt;/p&gt;
&lt;p&gt;We strongly urge upgrading your GitHub Enterprise Server appliance to the latest patch release in your series, GitHub Enterprise Server 2.13.22, 2.14.16, 2.15.9, 2.16.4, or greater immediately. If you have any questions, please contact GitHub support at &lt;a href=&quot;https://enterprise.github.com/support&quot;&gt;https://enterprise.github.com/support&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: A specially crafted request could allow arbitrary files to be read and the file content to be disclosed. For more information see the associated Rails CVE: &lt;a href=&quot;https://groups.google.com/forum/#!topic/rubyonrails-security/pFRKI96Sm8Q&quot;&gt;CVE-2019-5418&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: High CPU usage could be triggered by a specially crafted request resulting in Denial of Service (DoS). For more information see the associated Rails CVE: &lt;a href=&quot;https://groups.google.com/forum/#!topic/rubyonrails-security/GN7w9fFAQeI&quot;&gt;CVE-2019-5419&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In rare circumstances, a race condition could lead to repository data loss if an automated background maintenance job was triggered during a configuration update.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments are missing from an import with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 13 Mar 2019 16:00:33 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.13.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.13.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.3</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &amp;quot;Ignore whitespace changes&amp;quot; option was not honoured with progressively loaded diffs.&lt;/li&gt;
&lt;li&gt;The custom sign out message was displayed on the sign in page in certain situations.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.  (updated 2019-05-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 26 Feb 2019 16:00:36 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.8</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.  (updated 2019-05-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 26 Feb 2019 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.15</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 26 Feb 2019 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.13.21</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments are missing from an import with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 26 Feb 2019 16:00:33 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.13.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.13.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.2</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Uploads of some image types could fail when using Git LFS 2.5.0 or newer.&lt;/li&gt;
&lt;li&gt;Entries for the &lt;code&gt;babeld.log&lt;/code&gt;, &lt;code&gt;gitauth.log&lt;/code&gt;, &lt;code&gt;production.log&lt;/code&gt;, &lt;code&gt;resqued.log&lt;/code&gt; and &lt;code&gt;unicorn.log&lt;/code&gt; log files were truncated when forwarded to a central log server.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.github.com/changes/2018-09-25-stricter-validation-coming-soon-in-the-rest-api/&quot;&gt;Stricter REST API validation&lt;/a&gt; was prematurely enabled. As a result, API requests that previously succeeded may have been rejected with a &lt;code&gt;422 Unprocessable Entity&lt;/code&gt; response.&lt;/li&gt;
&lt;li&gt;Viewing the global business profile page for organizations with a lot of users could timeout.&lt;/li&gt;
&lt;li&gt;Restoring a backup containing a very large number of deleted repositories could fail with the error &amp;quot;Resource temporarily unavailable&amp;quot;.&lt;/li&gt;
&lt;li&gt;Repositories owned by organizations could not be deleted by organization owners if the &lt;em&gt;Repository deletion and transfer&lt;/em&gt; business setting was set to &lt;em&gt;Disabled&lt;/em&gt;.&lt;/li&gt;
&lt;li&gt;Repository pages with a lot of tags and branches could take a very long time to load.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.  (updated 2019-05-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 13 Feb 2019 16:00:36 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.7</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Uploads of some image types could fail when using Git LFS 2.5.0 or newer.&lt;/li&gt;
&lt;li&gt;The Consul service could fail to start when attaching storage devices configured on other instances.&lt;/li&gt;
&lt;li&gt;Entries for the &lt;code&gt;babeld.log&lt;/code&gt;, &lt;code&gt;gitauth.log&lt;/code&gt;, &lt;code&gt;production.log&lt;/code&gt;, &lt;code&gt;resqued.log&lt;/code&gt; and &lt;code&gt;unicorn.log&lt;/code&gt; log files were truncated when forwarded to a central log server.&lt;/li&gt;
&lt;li&gt;Viewing the global business profile page for organizations with a lot of users could timeout.&lt;/li&gt;
&lt;li&gt;Restoring a backup containing a very large number of deleted repositories could fail with the error &amp;quot;Resource temporarily unavailable&amp;quot;.&lt;/li&gt;
&lt;li&gt;Repositories owned by organizations could not be deleted by organization owners if the &lt;em&gt;Repository deletion and transfer&lt;/em&gt; business setting was set to &lt;em&gt;Disabled&lt;/em&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.  (updated 2019-05-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 13 Feb 2019 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.14</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Uploads of some image types could fail when using Git LFS 2.5.0 or newer.&lt;/li&gt;
&lt;li&gt;Entries for the &lt;code&gt;babeld.log&lt;/code&gt;, &lt;code&gt;gitauth.log&lt;/code&gt;, &lt;code&gt;production.log&lt;/code&gt;, &lt;code&gt;resqued.log&lt;/code&gt; and &lt;code&gt;unicorn.log&lt;/code&gt; log files were truncated when forwarded to a central log server.&lt;/li&gt;
&lt;li&gt;Restoring a backup containing a very large number of deleted repositories could fail with the error &amp;quot;Resource temporarily unavailable&amp;quot;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 13 Feb 2019 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.13.20</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Entries for the &lt;code&gt;babeld.log&lt;/code&gt;, &lt;code&gt;gitauth.log&lt;/code&gt;, &lt;code&gt;production.log&lt;/code&gt;, &lt;code&gt;resqued.log&lt;/code&gt; and &lt;code&gt;unicorn.log&lt;/code&gt; log files were truncated when forwarded to a central log server.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments are missing from an import with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 13 Feb 2019 16:00:33 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.13.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.13.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.1</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM:&lt;/strong&gt; A race condition allowed a malicious GitHub App integrator to gain escalated user privileges by quickly updating their App&#39;s permissions during the OAuth flow.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Webhooks continued to be delivered via a proxy server after removing the proxy configuration.&lt;/li&gt;
&lt;li&gt;Background jobs for the &lt;a href=&quot;https://developer.github.com/changes/2018-12-10-content-attachments-api/&quot;&gt;Content Attachments API&lt;/a&gt; used by GitHub Apps were not processed and as a result context information was not shown.&lt;/li&gt;
&lt;li&gt;Successful delivery logs for Webhooks sent through a proxy server were reported as a delivery error if the proxy server inserted additional headers.&lt;/li&gt;
&lt;li&gt;The migrations that are run while upgrading to GitHub Enterprise Server 2.16.0 could report &amp;quot;Column cache_version_number cannot be null&amp;quot; errors being logged to &lt;code&gt;/var/log/github/exceptions.log&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Site admins can no longer create GitHup Apps and OAuth apps that start with the reserved words &lt;code&gt;github&lt;/code&gt; or &lt;code&gt;gist&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.github.com/changes/2018-09-25-stricter-validation-coming-soon-in-the-rest-api/&quot;&gt;Stricter REST API validation&lt;/a&gt; has been prematurely enabled. As a result, API requests that previously succeeded may be rejected with a &lt;code&gt;422 Unprocessable Entity&lt;/code&gt; response. (updated 2019-02-01)&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.  (updated 2019-05-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 29 Jan 2019 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.6</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Webhooks continued to be delivered via a proxy server after removing the proxy configuration.&lt;/li&gt;
&lt;li&gt;Successful delivery logs for Webhooks sent through a proxy server were reported as a delivery error if the proxy server inserted additional headers.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.  (updated 2019-05-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 29 Jan 2019 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.13</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Webhooks continued to be delivered via a proxy server after removing the proxy configuration.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 29 Jan 2019 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.13.19</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Webhooks continued to be delivered via a proxy server after removing the proxy configuration.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments are missing from an import with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 29 Jan 2019 16:00:33 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.13.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.13.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.16.0</title>
					<description>&lt;h2&gt;Features&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Deployments API includes new states. &lt;del&gt;Deployments API integrates with GitHub Flow.&lt;/del&gt; (updated: 2019-04-02)&lt;/li&gt;
&lt;li&gt;Integrator links can be expanded with relevant details in the context of GitHub comments via API.&lt;/li&gt;
&lt;li&gt;Only pull request authors or users with write access to repository can resolve conversations.&lt;/li&gt;
&lt;li&gt;Repository administrator can delete issues.&lt;/li&gt;
&lt;li&gt;Users can subscribe to only receive repository notifications for releases.&lt;/li&gt;
&lt;li&gt;Organization administrators can control whether users can create public, private, or no repositories.&lt;/li&gt;
&lt;li&gt;A timeline event is shown when users force push to a branch.&lt;/li&gt;
&lt;li&gt;Users can filter Pull Request by file type or hide deleted files.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;Repository administrators can transfer an issue to another repository where the administrator also has repository administration privileges.&lt;/del&gt; (updated: 2019-04-08)&lt;/li&gt;
&lt;li&gt;‘Allow members to invite external collaborators’ setting added to Organization Settings page.&lt;/li&gt;
&lt;li&gt;Pull request reviews automatically update the merge button.&lt;/li&gt;
&lt;li&gt;2-up image diffs will now also display file size alongside the width and height data.&lt;/li&gt;
&lt;li&gt;When hovering over the status of a commit in a pull request&#39;s timeline, the full details for that status is displayed in a popover.&lt;/li&gt;
&lt;li&gt;When searching from a user profile page users have the option to search by &amp;quot;this user&amp;quot;.&lt;/li&gt;
&lt;li&gt;Users can pre-fill values in the new Release form fields using URL query parameters.&lt;/li&gt;
&lt;li&gt;Filtering files in a pull request by file type.&lt;/li&gt;
&lt;li&gt;Bookmark any notification to move it into a prioritized list called Saved for Later.&lt;/li&gt;
&lt;li&gt;When writing a comment with -1 or +1, GitHub suggests leaving a reaction.&lt;/li&gt;
&lt;li&gt;Maintainers can add more template automation in the form of a default title, labels, and assignees.&lt;/li&gt;
&lt;li&gt;When a user clicks the &amp;quot;Fork&amp;quot; button on a repository that has been already forked, the user&#39;s existing forks are listed.&lt;/li&gt;
&lt;li&gt;Create and upload file to empty repos.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The native browser tooltip overlaid the GitHub custom tooltip when a commit message contained &lt;code&gt;Closes #issue&lt;/code&gt; text.&lt;/li&gt;
&lt;li&gt;The repository selection radio button and dropdown selection could be hidden when installing a GitHub App.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Recent changes to a project board will be highlighted since a user&#39;s last visit.&lt;/li&gt;
&lt;li&gt;When viewing recent activity on a personal dashboard, timestamps will include a deep link to the most recent comment.&lt;/li&gt;
&lt;li&gt;The owner dropdown is highlighted first on the &amp;quot;Create a new repository&amp;quot; page.&lt;/li&gt;
&lt;li&gt;The keyboard shortcuts help dialog modal has been redesigned.&lt;/li&gt;
&lt;li&gt;Comments are only outdated when the line the comment is related to changes.&lt;/li&gt;
&lt;li&gt;New installs of Enterprise Server will use GitHub&#39;s NTP server pool by default and the upgrade package will change old default servers to the new NTP pool.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Backups and Disaster Recovery&lt;/h2&gt;
&lt;p&gt;GitHub Enterprise Server 2.16 requires at least &lt;a href=&quot;https://github.com/github/backup-utils&quot;&gt;GitHub Enterprise Backup Utilities&lt;/a&gt; 2.16.0 for &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/backups-and-disaster-recovery/&quot;&gt;Backups and Disaster Recovery&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise Server 2.13&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise Server 2.13 will be deprecated as of March 27, 2019.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.16/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise Server&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Services&lt;/h2&gt;
&lt;p&gt;Starting with GitHub Enterprise Server 2.17.0, support for GitHub Services will be deprecated and administrators will not be able to install or configure new GitHub Services. Existing GitHub Services from a previous version of GitHub Enterprise Server will continue to function but GitHub Enterprise Server will not be providing any security or bug fixes to the GitHub Services functionality. At this time, there will be no changes to the existing functionality, but a warning banner will be displayed with the &lt;a href=&quot;https://developer.github.com/changes/2018-04-25-github-services-deprecation/&quot;&gt;deprecation announcement blog post&lt;/a&gt;. Administrators can see which repositories are using GitHub Services with &lt;code&gt;ghe-legacy-github-services-report&lt;/code&gt;.&lt;/p&gt;
&lt;h2&gt;Deprecation of Internet 11 Support&lt;/h2&gt;
&lt;p&gt;Starting with GitHub Enterprise Server 2.16.0, Internet Explorer 11 is no longer a supported browser. See a current list of supported browsers &lt;a href=&quot;https://docs.github.com/en/enterprise/user/articles/supported-browsers&quot;&gt;on this page&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise Server without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.github.com/changes/2018-09-25-stricter-validation-coming-soon-in-the-rest-api/&quot;&gt;Stricter REST API validation&lt;/a&gt; has been prematurely enabled. As a result, API requests that previously succeeded may be rejected with a &lt;code&gt;422 Unprocessable Entity&lt;/code&gt; response. (updated 2019-02-01)&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.  (updated 2019-05-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The ability for repository administrators to transfer an issue to another repository is not included in GitHub Enterprise Server 2.16.0.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 22 Jan 2019 16:00:36 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.16.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.16.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.5</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repositories migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; we not automatically re-indexed so weren&#39;t returned in the search results until manually re-indexed.&lt;/li&gt;
&lt;li&gt;The GitHub 2FA user interface was not disabled if an external authentication provider is configured.&lt;/li&gt;
&lt;li&gt;LFS objects were not reassociated with repositories when the repositories were unarchived.&lt;/li&gt;
&lt;li&gt;Adding a repository to an organisation team via &lt;a href=&quot;https://developer.github.com/enterprise/2.15/v3/teams/#add-or-update-team-repository&quot;&gt;Add or Update team repository&lt;/a&gt; as a GitHub app, would fail with error &amp;quot;You must have administrative rights on this repository&amp;quot;.&lt;/li&gt;
&lt;li&gt;Users could encounter a 500 Internal Server Error when viewing a pull request on a repository imported with &lt;code&gt;ghe-migrator&lt;/code&gt; that contains references to another pull request the user does not have access to.&lt;/li&gt;
&lt;li&gt;Creating or modifying &lt;a href=&quot;https://docs.github.com/articles/creating-issue-templates-for-your-repository/&quot;&gt;Issue Templates&lt;/a&gt; on a repository with pre-receive hooks that rejected pushes would fail with a 500 Internal Server error.&lt;/li&gt;
&lt;li&gt;Listing all repositories of a team, via the user interface or API, that contained one or more disabled repositories would fail with a 500 Internal Server Error.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Searching GitHub.com through GitHub Connect now works with all search prefixes accepted when searching directly in GitHub.com (e.g.: &lt;code&gt;repo:&lt;/code&gt;, &lt;code&gt;org:&lt;/code&gt;, etc.).&lt;/li&gt;
&lt;li&gt;Wikis for forked repositories now have the &amp;quot;Restrict access to collaborators&amp;quot; setting enabled by default.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments can be misplaced when the pull request has large diffs.  (updated 2019-01-21)&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.  (updated 2019-05-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 15 Jan 2019 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.12</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repositories migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; we not automatically re-indexed so weren&#39;t returned in the search results until manually re-indexed.&lt;/li&gt;
&lt;li&gt;Users could encounter a 500 Internal Server Error when viewing a pull request on a repository imported with &lt;code&gt;ghe-migrator&lt;/code&gt; that contains references to another pull request the user does not have access to.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Wikis for forked repositories now have the &amp;quot;Restrict access to collaborators&amp;quot; setting enabled by default.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments can be misplaced when the pull request has large diffs.  (updated 2019-01-21)&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 15 Jan 2019 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.13.18</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repositories migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; we not automatically re-indexed so weren&#39;t returned in the search results until manually re-indexed.&lt;/li&gt;
&lt;li&gt;Users could encounter a 500 Internal Server Error when viewing a pull request on a repository imported with &lt;code&gt;ghe-migrator&lt;/code&gt; that contains references to another pull request the user does not have access to.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Wikis for forked repositories now have the &amp;quot;Restrict access to collaborators&amp;quot; setting enabled by default.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments are missing from an import with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 15 Jan 2019 16:00:33 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.13.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.13.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.4</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;An Elasticsearch node ID collision could happen when adding a high availability replica that has been part of a high availability replication environment before or has been restored from a backup.&lt;/li&gt;
&lt;li&gt;A &amp;quot;Hook is now disabled&amp;quot; notice was shown instead of &amp;quot;Hook is now enabled&amp;quot; when &lt;em&gt;enabling&lt;/em&gt; a pre-receive hook on either an organization or repository.&lt;/li&gt;
&lt;li&gt;Some settings available on the &lt;code&gt;/business&lt;/code&gt; page were inaccessible when the company name in the license file is comprised of multi byte strings.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;404 Not Found&lt;/code&gt; errors were shown in the browser console for some script requests when using the code editor.&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; failed when the creator of a card on the board no longer exists on the source instance.&lt;/li&gt;
&lt;li&gt;Migrating a repository with &lt;code&gt;ghe-migrator&lt;/code&gt; could lead to an incorrect mapping between links to pull requests and the correct pull requests.&lt;/li&gt;
&lt;li&gt;Listing the GUIDs of migrations that are in progress with the &lt;code&gt;ghe-migrator list&lt;/code&gt; command failed with a  &lt;code&gt;&amp;quot;undefined method &#39;uniq&#39; &lt;/code&gt; error.&lt;/li&gt;
&lt;li&gt;Viewing pull requests with &lt;a href=&quot;https://developer.github.com/v3/repos/deployments/#create-a-deployment&quot;&gt;deployments&lt;/a&gt; imported with &lt;code&gt;ghe-migrator&lt;/code&gt; would fail with a 500 Internal Server Error.&lt;/li&gt;
&lt;li&gt;Invalid search qualifiers for a particular search type were treated as part of the search query and not ignored in GitHub.com searches.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments can be misplaced when the pull request has large diffs.  (updated 2019-01-21)&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.  (updated 2019-05-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 11 Dec 2018 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.11</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;An Elasticsearch node ID collision could happen when adding a high availability replica that has been part of a high availability replication environment before or has been restored from a backup.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;404 Not Found&lt;/code&gt; errors were shown in the browser console for some script requests when using the code editor.&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; failed when the creator of a card on the board no longer exists on the source instance.&lt;/li&gt;
&lt;li&gt;Migrating a repository with &lt;code&gt;ghe-migrator&lt;/code&gt; could lead to an incorrect mapping between links to pull requests and the correct pull requests.&lt;/li&gt;
&lt;li&gt;Viewing pull requests with &lt;a href=&quot;https://developer.github.com/v3/repos/deployments/#create-a-deployment&quot;&gt;deployments&lt;/a&gt; imported with &lt;code&gt;ghe-migrator&lt;/code&gt; would fail with a 500 Internal Server Error.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments can be misplaced when the pull request has large diffs.  (updated 2019-01-21)&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 11 Dec 2018 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.13.17</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;404 Not Found&lt;/code&gt; errors were shown in the browser console for some script requests when using the code editor.&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; failed when the creator of a card on the board no longer exists on the source instance.&lt;/li&gt;
&lt;li&gt;Migrating a repository with &lt;code&gt;ghe-migrator&lt;/code&gt; could lead to an incorrect mapping between links to pull requests and the correct pull requests.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments are missing from an import with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 11 Dec 2018 16:00:33 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.13.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.13.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.25</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.12&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.12 will be deprecated as of December 12, 2018.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.15/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 11 Dec 2018 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.25</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.25</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.3</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-16471&quot;&gt;CVE-2018-16471&lt;/a&gt; was addressed by updating Rack.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A stale temporary file could prevent an object managed by the Alambic service, which handles binary data such as avatars and image attachments, from syncing to HA or cluster replica nodes.&lt;/li&gt;
&lt;li&gt;Attempting to save settings in the Management Console incorrectly raised a validation error when an already saved TLS certificate or private key contains bag attributes.&lt;/li&gt;
&lt;li&gt;Custom DNS resolver settings were reverted during appliance hotpatch upgrades.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;/var/log/error&lt;/code&gt; was not automatically rotated with logrotate and could sometimes use too much disk space.&lt;/li&gt;
&lt;li&gt;Submitting a comment after clicking the &amp;quot;Start a new conversation&amp;quot; button on a pull request diff raised an error under some circumstances.&lt;/li&gt;
&lt;li&gt;There was a layout issue with a notice shown to new organization members on the dashboard.&lt;/li&gt;
&lt;li&gt;Git authentication errors suggested the SSH protocol to the user even if it was &lt;a href=&quot;https://docs.github.com/enterprise/2.15/admin/guides/installation/disabling-git-ssh-access-on-github-enterprise/&quot;&gt;disabled&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;The GitHub App installation settings page always showed the viewer as the one that had installed the App.&lt;/li&gt;
&lt;li&gt;Complicated rebases within very busy repositories could cause replicas to get out of sync, sometimes leading to transient push errors.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;POST /repos/:owner/:repo/pulls&lt;/code&gt; REST API endpoint could return a 502 Bad Gateway response due to using suboptimal query indexes.&lt;/li&gt;
&lt;li&gt;The repository permissions settings for newly created organizations could get stuck in an &amp;quot;Update in progress&amp;quot; state.&lt;/li&gt;
&lt;li&gt;Pre-receive hook failures were not communicated to the end user when attempting to merge a pull request.&lt;/li&gt;
&lt;li&gt;The &amp;quot;Unsupported Browser&amp;quot; notice was not correctly shown when an unsupported browser was being used.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Listing the GUIDs of migrations that are in progress with the &lt;code&gt;ghe-migrator list&lt;/code&gt; command throws an error and fails.&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.&lt;/li&gt;
&lt;li&gt;Some settings available on the &lt;code&gt;/business&lt;/code&gt; page are inaccessible when the company name in the license file is comprised of multi byte strings.&lt;/li&gt;
&lt;li&gt;Pull request review comments can be misplaced when the pull request has large diffs.  (updated 2019-01-21)&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.  (updated 2019-05-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 27 Nov 2018 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.10</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-16471&quot;&gt;CVE-2018-16471&lt;/a&gt; was addressed by updating Rack.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A stale temporary file could prevent an object managed by the Alambic service, which handles binary data such as avatars and image attachments, from syncing to HA or cluster replica nodes.&lt;/li&gt;
&lt;li&gt;Attempting to save settings in the Management Console incorrectly raised a validation error when an already saved TLS certificate or private key contains bag attributes.&lt;/li&gt;
&lt;li&gt;Custom DNS resolver settings were reverted during appliance hotpatch upgrades.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;/var/log/error&lt;/code&gt; was not automatically rotated with logrotate and could sometimes use too much disk space.&lt;/li&gt;
&lt;li&gt;A slow memory leak would result in performance degradation over time.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;POST /repos/:owner/:repo/pulls&lt;/code&gt; REST API endpoint could return a 502 Bad Gateway response due to using suboptimal query indexes.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.&lt;/li&gt;
&lt;li&gt;Pull request review comments can be misplaced when the pull request has large diffs.  (updated 2019-01-21)&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 27 Nov 2018 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.13.16</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-16471&quot;&gt;CVE-2018-16471&lt;/a&gt; was addressed by updating Rack.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A stale temporary file could prevent an object managed by the Alambic service, which handles binary data such as avatars and image attachments, from syncing to HA or cluster replica nodes.&lt;/li&gt;
&lt;li&gt;Attempting to save settings in the Management Console incorrectly raised a validation error when an already saved TLS certificate or private key contains bag attributes.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;/var/log/error&lt;/code&gt; was not automatically rotated with logrotate and could sometimes use too much disk space.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments are missing from an import with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 27 Nov 2018 16:00:33 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.13.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.13.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.24</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-16471&quot;&gt;CVE-2018-16471&lt;/a&gt; was addressed by updating Rack.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A stale temporary file could prevent an object managed by the Alambic service, which handles binary data such as avatars and image attachments, from syncing to HA or cluster replica nodes.&lt;/li&gt;
&lt;li&gt;Attempting to save settings in the Management Console incorrectly raised a validation error when an already saved TLS certificate or private key contains bag attributes.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;/var/log/error&lt;/code&gt; was not automatically rotated with logrotate and could sometimes use too much disk space.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;Git LFS, release and issue assets, user profile images, webhooks, or Subversion access may be unavailable if an appliance is restarted after applying the 2.12.5 or greater hotpatch—if this occurs, please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us&quot;&gt;Enterprise Support&lt;/a&gt; for assistance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.12&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.12 will be deprecated as of December 12, 2018.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.15/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 27 Nov 2018 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.24</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.24</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.2</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Rack packages have been updated to address cross-site scripting (XSS) and Denial of Service (DoS) vulnerabilities &lt;a href=&quot;https://groups.google.com/forum/#!topic/ruby-security-ann/Dz4sRl-ktKk&quot;&gt;CVE-2018-16470&lt;/a&gt; and &lt;a href=&quot;https://groups.google.com/forum/#!topic/ruby-security-ann/NAalCee8n6o&quot;&gt;CVE-2018-16471&lt;/a&gt; respectively.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Checking the replication status on a replica during a reboot of the primary could prevent replication for Git pre-receive hooks.&lt;/li&gt;
&lt;li&gt;When a business had enforced a two-factor authentication policy, business admins were able to be added when they didn&#39;t have two-factor authentication enabled.&lt;/li&gt;
&lt;li&gt;Text between a pair of double underscores, such as &lt;code&gt;__init__&lt;/code&gt;, was removed in code blocks in MediaWiki-formatted pages.&lt;/li&gt;
&lt;li&gt;The &amp;quot;Start a new conversation&amp;quot; button on a pull request diff did not work for threads targeting the context of a change rather than an addition or deletion.&lt;/li&gt;
&lt;li&gt;When creating a new organization, the preview of the resulting organization URL was reset on validation.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;BackfillEnterpriseBusinessAdminsAndOrganizationsTransition&lt;/code&gt; data transition could fail while running migrations.&lt;/li&gt;
&lt;li&gt;Under some circumstances, attempting to create a new organization would result in a &lt;code&gt;422 Unprocessable Entity&lt;/code&gt; error.&lt;/li&gt;
&lt;li&gt;Pre-receive hook target enforcement options did not properly reflect their persisted values.&lt;/li&gt;
&lt;li&gt;Issue and pull request pages could fail to load if they were referred to by a project the viewer of the issue does not have access to.&lt;/li&gt;
&lt;li&gt;A user&#39;s roles in an organization were represented inconsistently at &lt;code&gt;/stafftools/users/:user/organization_memberships&lt;/code&gt; in comparison to user-facing pages.&lt;/li&gt;
&lt;li&gt;When an invalid &lt;code&gt;admin&lt;/code&gt; value was provided to the REST API endpoint to &lt;a href=&quot;https://developer.github.com/enterprise/2.15/v3/enterprise-admin/orgs/#create-an-organization&quot;&gt;create an organization&lt;/a&gt;, an organization without any owners was created rather than a meaningful error message being returned.&lt;/li&gt;
&lt;li&gt;After signing in, users were sometimes shown the contents of the &lt;code&gt;manifest.json&lt;/code&gt; file instead of being redirected to the correct location in the user interface.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Some settings available on the &lt;code&gt;/business&lt;/code&gt; page are inaccessible when the company name in the license file is comprised of multi byte strings.&lt;/li&gt;
&lt;li&gt;Listing the GUIDs of migrations that are in progress with the &lt;code&gt;ghe-migrator list&lt;/code&gt; command throws an error and fails.  (updated 2018-11-21)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;li&gt;Pull request review comments can be misplaced when the pull request has large diffs.  (updated 2019-01-21)&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.  (updated 2019-05-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The issue that some settings available on the &lt;code&gt;/business&lt;/code&gt; page are inaccessible when the company name in the license file is comprised of multi byte strings was incorrectly included in the bug fixes section instead of the known issues section. (updated 2019-01-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 13 Nov 2018 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.9</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Checking the replication status on a replica during a reboot of the primary could prevent replication for Git pre-receive hooks.&lt;/li&gt;
&lt;li&gt;Text between a pair of double underscores, such as &lt;code&gt;__init__&lt;/code&gt;, was removed in code blocks in MediaWiki-formatted pages.&lt;/li&gt;
&lt;li&gt;After signing in, users were sometimes shown the contents of the &lt;code&gt;manifest.json&lt;/code&gt; file instead of being redirected to the correct location in the user interface.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;li&gt;Upgrading to a later version in this series may overwrite custom DNS entries in &lt;code&gt;/etc/resolvconf/resolv.conf.d/head&lt;/code&gt; (updated 2018-12-19)&lt;/li&gt;
&lt;li&gt;Pull request review comments can be misplaced when the pull request has large diffs.  (updated 2019-01-21)&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 13 Nov 2018 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.13.15</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Checking the replication status on a replica during a reboot of the primary could prevent replication for Git pre-receive hooks.&lt;/li&gt;
&lt;li&gt;Text between a pair of double underscores, such as &lt;code&gt;__init__&lt;/code&gt;, was removed in code blocks in MediaWiki-formatted pages.&lt;/li&gt;
&lt;li&gt;After signing in, users were sometimes shown the contents of the &lt;code&gt;manifest.json&lt;/code&gt; file instead of being redirected to the correct location in the user interface.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments are missing from an import with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 13 Nov 2018 16:00:33 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.13.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.13.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.23</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Checking the replication status on a replica during a reboot of the primary could prevent replication for Git pre-receive hooks.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;Git LFS, release and issue assets, user profile images, webhooks, or Subversion access may be unavailable if an appliance is restarted after applying the 2.12.5 or greater hotpatch—if this occurs, please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us&quot;&gt;Enterprise Support&lt;/a&gt; for assistance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.12&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.12 will be deprecated as of December 12, 2018.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.15/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 13 Nov 2018 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.23</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.23</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.1</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The version string presented when using Git over SSH was misleading, causing security scanners to incorrectly report GitHub as vulnerable.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Installing a hotpatch when replication is not setup displayed a harmless error message: &lt;code&gt;grep: /etc/github/repl-state: No such file or directory&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The addition of new GitHub Services was deprecated too early.&lt;/li&gt;
&lt;li&gt;The App request/response Grafana section did not report any metrics.&lt;/li&gt;
&lt;li&gt;The page shown to a user when an abuse detection mechanism is triggered contained links only relevant to GitHub.com.&lt;/li&gt;
&lt;li&gt;Rate limiting was enforced when adding members to organizations.&lt;/li&gt;
&lt;li&gt;Changing a team member&#39;s role would not complete after prompting for authentication.&lt;/li&gt;
&lt;li&gt;Using ghe-migrator to import a repository including a protected branch which has null in the creator entry failed.&lt;/li&gt;
&lt;li&gt;Organizations created using the REST API were not listed on the global business profile page.&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Connect settings pages now show the connected GitHub.com organization or user.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;The App request/response Grafana section is not reporting any metrics.&lt;/li&gt;
&lt;li&gt;Creating a new organization may cause a &lt;code&gt;422 Unprocessable Entity&lt;/code&gt; error.  (updated 2018-11-03)&lt;/li&gt;
&lt;li&gt;Some settings available on the &lt;code&gt;/business&lt;/code&gt; page are inaccessible when the company name in the license file is comprised of multi byte strings.  (updated 2018-11-7)&lt;/li&gt;
&lt;li&gt;Listing the GUIDs of migrations that are in progress with the &lt;code&gt;ghe-migrator list&lt;/code&gt; command throws an error and fails.  (updated 2018-11-21)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;li&gt;Pull request review comments can be misplaced when the pull request has large diffs.  (updated 2019-01-21)&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.  (updated 2019-05-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 30 Oct 2018 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.8</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The version string presented when using Git over SSH was misleading, causing security scanners to incorrectly report GitHub as vulnerable.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;All non-root connections to the cloud provider metadata IP address (169.254.169.254) were blocked, preventing Google Cloud load balancer health checks from working correctly.&lt;/li&gt;
&lt;li&gt;Installing a hotpatch when replication is not setup displayed a harmless error message: &lt;code&gt;grep: /etc/github/repl-state: No such file or directory&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Rate limiting was enforced when adding members to organizations.&lt;/li&gt;
&lt;li&gt;Using ghe-migrator to import a repository including a protected branch which has null in the creator entry failed.&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;li&gt;Upgrading to a later version in this series may overwrite custom DNS entries in &lt;code&gt;/etc/resolvconf/resolv.conf.d/head&lt;/code&gt; (updated 2018-12-19)&lt;/li&gt;
&lt;li&gt;Pull request review comments can be misplaced when the pull request has large diffs.  (updated 2019-01-21)&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 30 Oct 2018 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.13.14</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The version string presented when using Git over SSH was misleading, causing security scanners to incorrectly report GitHub as vulnerable.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;All non-root connections to the cloud provider metadata IP address (169.254.169.254) were blocked, preventing Google Cloud load balancer health checks from working correctly.&lt;/li&gt;
&lt;li&gt;Installing a hotpatch when replication is not setup displayed a harmless error message: &lt;code&gt;grep: /etc/github/repl-state: No such file or directory&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Rate limiting was enforced when adding members to organizations.&lt;/li&gt;
&lt;li&gt;Using ghe-migrator to import a repository including a protected branch which has null in the creator entry failed.&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments are missing from an import with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 30 Oct 2018 16:00:33 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.13.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.13.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.22</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The version string presented when using Git over SSH was misleading, causing security scanners to incorrectly report GitHub as vulnerable.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;All non-root connections to the cloud provider metadata IP address (169.254.169.254) were blocked, preventing Google Cloud load balancer health checks from working correctly.&lt;/li&gt;
&lt;li&gt;Installing a hotpatch when replication is not setup displayed a harmless error message: &lt;code&gt;grep: /etc/github/repl-state: No such file or directory&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Rate limiting was enforced when adding members to organizations.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;Git LFS, release and issue assets, user profile images, webhooks, or Subversion access may be unavailable if an appliance is restarted after applying the 2.12.5 or greater hotpatch—if this occurs, please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us&quot;&gt;Enterprise Support&lt;/a&gt; for assistance.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 30 Oct 2018 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.15.0</title>
					<description>&lt;h2&gt;Features&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Business administrators can enable, disable, or no-policy repository creation, deletion, visibility change, forking, and permissions to all repositories and organizations.&lt;/li&gt;
&lt;li&gt;Automatically protect branches with regex patterns.&lt;/li&gt;
&lt;li&gt;Link repositories for your organization-owned projects to make searching faster and more relevant.&lt;/li&gt;
&lt;li&gt;Show the issue and pull request details from a project board.&lt;/li&gt;
&lt;li&gt;Resolve conversations in a pull request review.&lt;/li&gt;
&lt;li&gt;Sign commits using X.509 certificates and S/MIME signatures.&lt;/li&gt;
&lt;li&gt;Quote replies or copy permalinks in issue and pull request conversations.&lt;/li&gt;
&lt;li&gt;Hide off topic, outdated, or resolved comments in issue and pull request conversations.&lt;/li&gt;
&lt;li&gt;Pushes will be rejected if a Git LFS object hasn&#39;t been uploaded properly.&lt;/li&gt;
&lt;li&gt;Pull request URL is included in the output of a &lt;code&gt;git push&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Opt-in to the activity overview dashboard to view work across all your organizations and repositories.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;Clustering environments support an &lt;code&gt;elasticsearch-server&lt;/code&gt; in a separate datacenter.&lt;/del&gt; (updated 2018-10-29)&lt;/li&gt;
&lt;li&gt;Wiki, search, and releases pages have been updated to be responsive.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;+&lt;/code&gt; and &lt;code&gt;-&lt;/code&gt; diff markers are no longer copied to your clipboard when copying content from a diff.&lt;/li&gt;
&lt;li&gt;Remove files directly from a pull request.&lt;/li&gt;
&lt;li&gt;Permalinked comments will be highlighted for easier discovery.&lt;/li&gt;
&lt;li&gt;Use a keyboard shortcut (e.g., &lt;code&gt;⌘ shift enter&lt;/code&gt;) to leave a pull request review comment.&lt;/li&gt;
&lt;li&gt;Collapse all diffs by using the &lt;code&gt;alt&lt;/code&gt; shortcut and clicking the inverted caret icon in any file header.&lt;/li&gt;
&lt;li&gt;Edit a repository&#39;s &lt;code&gt;README.md&lt;/code&gt; directly from the repository&#39;s root page.&lt;/li&gt;
&lt;li&gt;After pushing the changes, quickly create a pull request from the pull requests or code tab.&lt;/li&gt;
&lt;li&gt;Add members directly from the team discussion page using the &lt;strong&gt;+&lt;/strong&gt; button.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: LDAP users could authenticate as another user because GitHub Enterprise was incorrectly encoding whitespaces from the relative distinguished name (RDN).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: The issues API could disclose private organization membership status. The organization membership information now requires the &lt;code&gt;repo&lt;/code&gt; or &lt;code&gt;read:org&lt;/code&gt; scope.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;git&lt;/code&gt; package has been updated to detect malicious Git submodules that could be used to exploit &lt;a href=&quot;https://blog.github.com/2018-10-05-git-submodule-vulnerability/&quot;&gt;CVE-2018-17456&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The access control list (ACL) of configuration files transferred to replica nodes could be lost when configuring High Availability replication.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-config-apply&lt;/code&gt; contained innocuous and misleading error messages about &lt;code&gt;WARNING: Setting ES auto_expand_replicas failed&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The Grafana monitor dashboard truncated background jobs in the graph&#39;s legend.&lt;/li&gt;
&lt;li&gt;Scheduling maintenance mode could cause a &lt;code&gt;500 Internal Sever Error&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Pull request review requests weren&#39;t satisfied if a member of a subteam completed the review.&lt;/li&gt;
&lt;li&gt;Healthcheck requests from the provider (i.e., AWS, Azure, or GCP) were blocked.&lt;/li&gt;
&lt;li&gt;Users could get stuck choosing where to fork and be shown an indefinite spinning icon.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;osqueryi&lt;/code&gt; utility has been added to the GitHub Enterprise environment.&lt;/li&gt;
&lt;li&gt;The diff lines are omitted for file deletions.&lt;/li&gt;
&lt;li&gt;Collapsed review threads are requested and loaded when uncollapsing the view.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;agilezen&lt;/code&gt;, &lt;code&gt;boxcar&lt;/code&gt;, &lt;code&gt;codeportingcsharp2java&lt;/code&gt;, &lt;code&gt;coffeedocinfo&lt;/code&gt;, &lt;code&gt;coop&lt;/code&gt;, &lt;code&gt;cube&lt;/code&gt;, &lt;code&gt;distiller&lt;/code&gt;, &lt;code&gt;hall&lt;/code&gt;, &lt;code&gt;honbu&lt;/code&gt;, &lt;code&gt;loggly&lt;/code&gt;, &lt;code&gt;masterbranch&lt;/code&gt;, &lt;code&gt;nma&lt;/code&gt;, &lt;code&gt;notifymyandroid&lt;/code&gt;, &lt;code&gt;pushalot&lt;/code&gt;, &lt;code&gt;swiggle&lt;/code&gt;, &lt;code&gt;stormpath&lt;/code&gt;, &lt;code&gt;trajector&lt;/code&gt;, &lt;code&gt;visualops&lt;/code&gt;, and &lt;code&gt;yammer&lt;/code&gt; GitHub services have been deprecated.&lt;/li&gt;
&lt;li&gt;New &lt;a href=&quot;https://developer.github.com/enterprise/2.15/v3/&quot;&gt;REST API&lt;/a&gt; resources have been added.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.github.com/enterprise/2.15/v4/&quot;&gt;GraphQL API&lt;/a&gt; schema has been updated.&lt;/li&gt;
&lt;li&gt;New &lt;a href=&quot;https://developer.github.com/enterprise/2.15/webhooks/&quot;&gt;webhook events&lt;/a&gt; have been added.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.github.com/enterprise/2.15/apps/&quot;&gt;GitHub Apps&lt;/a&gt; has been updated to access more API resources and GraphQL queries.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise is now available in Azure Government. (updated 2018-10-18)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Backups and Disaster Recovery&lt;/h2&gt;
&lt;p&gt;GitHub Enterprise 2.15 requires at least &lt;a href=&quot;https://github.com/github/backup-utils&quot;&gt;GitHub Enterprise Backup Utilities&lt;/a&gt; 2.15.0 for &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/backups-and-disaster-recovery/&quot;&gt;Backups and Disaster Recovery&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.12&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.12 will be deprecated as of December 12, 2018.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.15/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Services&lt;/h2&gt;
&lt;p&gt;Starting with GitHub Enterprise 2.17.0, support for GitHub Services will be deprecated and administrators will not be able to install or configure new GitHub Services. Existing GitHub Services from a previous version of GitHub Enterprise will continue to function but GitHub Enterprise will not be providing any security or bug fixes to the GitHub Services functionality. At this time, there will be no changes to the existing functionality, but a warning banner will be displayed with the &lt;a href=&quot;https://developer.github.com/changes/2018-04-25-github-services-deprecation/&quot;&gt;deprecation announcement blog post&lt;/a&gt;. Administrators can see which repositories are using GitHub Services with &lt;code&gt;ghe-legacy-github-services-report&lt;/code&gt;.&lt;/p&gt;
&lt;h2&gt;&lt;del&gt;Deprecation of Internet Explorer 11 support&lt;/del&gt; Upcoming deprecation of Internet Explorer 11 support&lt;/h2&gt;
&lt;p&gt;&lt;del&gt;Support for Internet Explorer 11 has been deprecated as of GitHub Enterprise 2.15.0.&lt;/del&gt; Internet Explorer is still supported in GitHub Enterprise 2.15.0. Support for Internet Explorer 11 will be deprecated in the next feature release, 2.16.0. (updated 2018-11-22)&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;The App request/response Grafana section is not reporting any metrics.&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.  (updated 2018-10-31)&lt;/li&gt;
&lt;li&gt;Creating a new organization may cause a &lt;code&gt;422 Unprocessable Entity&lt;/code&gt; error.  (updated 2018-11-03)&lt;/li&gt;
&lt;li&gt;Some settings available on the &lt;code&gt;/business&lt;/code&gt; page are inaccessible when the company name in the license file is comprised of multi byte strings.  (updated 2018-11-7)&lt;/li&gt;
&lt;li&gt;Listing the GUIDs of migrations that are in progress with the &lt;code&gt;ghe-migrator list&lt;/code&gt; command throws an error and fails.  (updated 2018-11-21)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;li&gt;Pull request review comments can be misplaced when the pull request has large diffs.  (updated 2019-01-21)&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;li&gt;Resque workers may not be cleaned up following a configuration run leading to a growing number of stale workers which in turn could lead to high memory consumption.  (updated 2019-05-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;elasticsearch-server&lt;/code&gt; was added as part of preliminary work needed for Elasticsearch indices replication under cluster disaster recovery.  This update does not affect any instance of GitHub Enterprise at this time. (updated 2018-10-29)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 16 Oct 2018 16:00:35 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.15.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.15.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.7</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;git&lt;/code&gt; package has been updated to detect malicious Git submodules that could be used to exploit &lt;a href=&quot;https://blog.github.com/2018-10-05-git-submodule-vulnerability/&quot;&gt;CVE-2018-17456&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The access control list (ACL) of configuration files transferred to replica nodes could be lost when configuring High Availability replication.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-config-apply&lt;/code&gt; contained innocuous and misleading error messages about &lt;code&gt;WARNING: Setting ES auto_expand_replicas failed&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The Grafana monitor dashboard truncated background jobs in the graph&#39;s legend.&lt;/li&gt;
&lt;li&gt;Scheduling maintenance mode could cause a &lt;code&gt;500 Internal Sever Error&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Pull request review requests weren&#39;t satisfied if a member of a subteam completed the review.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;osqueryi&lt;/code&gt; utility has been added to the GitHub Enterprise environment.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise is now available in Azure Government. (updated 2018-10-18)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.  (updated 2018-10-31)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;li&gt;Upgrading to a later version in this series may overwrite custom DNS entries in &lt;code&gt;/etc/resolvconf/resolv.conf.d/head&lt;/code&gt; (updated 2018-12-19)&lt;/li&gt;
&lt;li&gt;Pull request review comments can be misplaced when the pull request has large diffs.  (updated 2019-01-21)&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 09 Oct 2018 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.13.13</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;git&lt;/code&gt; package has been updated to detect malicious Git submodules that could be used to exploit &lt;a href=&quot;https://blog.github.com/2018-10-05-git-submodule-vulnerability/&quot;&gt;CVE-2018-17456&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The access control list (ACL) of configuration files transferred to replica nodes could be lost when configuring High Availability replication.&lt;/li&gt;
&lt;li&gt;The Grafana monitor dashboard truncated background jobs in the graph&#39;s legend.&lt;/li&gt;
&lt;li&gt;Organization migrations could fail to be exported if a pull request review comment could not be encoded properly.&lt;/li&gt;
&lt;li&gt;Pull request review requests weren&#39;t satisfied if a member of a subteam completed the review.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;osqueryi&lt;/code&gt; utility has been added to the GitHub Enterprise environment.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise is now available in Azure Government. (updated 2018-10-18)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments are missing from an import with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.  (updated 2018-10-31)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 09 Oct 2018 16:00:33 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.13.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.13.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.21</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;git&lt;/code&gt; package has been updated to detect malicious Git submodules that could be used to exploit &lt;a href=&quot;https://blog.github.com/2018-10-05-git-submodule-vulnerability/&quot;&gt;CVE-2018-17456&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The access control list (ACL) of configuration files transferred to replica nodes could be lost when configuring High Availability replication.&lt;/li&gt;
&lt;li&gt;Pull request review requests weren&#39;t satisfied if a member of a subteam completed the review.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;osqueryi&lt;/code&gt; utility has been added to the GitHub Enterprise environment.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise is now available in Azure Government. (updated 2018-10-18)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;Git LFS, release and issue assets, user profile images, webhooks, or Subversion access may be unavailable if an appliance is restarted after applying the 2.12.5 or greater hotpatch—if this occurs, please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us&quot;&gt;Enterprise Support&lt;/a&gt; for assistance.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 09 Oct 2018 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.6</title>
					<description>&lt;!-- raw HTML omitted --&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: A file path traversal vulnerability in the &lt;code&gt;jekyll-remote-theme&lt;/code&gt; gem of GitHub Pages could allow users to display the content of local files.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-repl-setup&lt;/code&gt; allowed re-adding the same node as a replica.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise API responses would not be compressed when requested with &lt;code&gt;gzip&lt;/code&gt; encoding.&lt;/li&gt;
&lt;li&gt;Webhooks could fail to be delivered if the compressed payload was greater than 1 MB.&lt;/li&gt;
&lt;li&gt;Upgrades could fail with &lt;code&gt;Connection timed out&lt;/code&gt; if the hookshot service was unable to run migrations due to a firewall update that ran out of order.&lt;/li&gt;
&lt;li&gt;Repository replication records may be created inconsistently, resulting in unreported replication failures. This type of replication failure is now reported in &lt;code&gt;ghe-repl-status&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Replication could fail due to stale or duplicate entries to the primary in a replica&#39;s &lt;code&gt;/etc/hosts&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Messages sent from the email service hook failed when the upstream SMTP server didn’t accept the &lt;code&gt;plain&lt;/code&gt; authentication method.&lt;/li&gt;
&lt;li&gt;Using Safari, administrators were unable to schedule a future hotpatch upgrade from the Management Console due to an incompatible date parse.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-config-check&lt;/code&gt; would hang if run without any arguments.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;hookshot&lt;/code&gt; logs weren&#39;t purged properly in Elasticsearch and could consume large amounts of disk space.&lt;/li&gt;
&lt;li&gt;Migrations with &lt;code&gt;ghe-migrator&lt;/code&gt; could fail to complete trying to add the same label to an issue.&lt;/li&gt;
&lt;li&gt;The pull request page could fail to load with a &lt;code&gt;500 Internal Server Error&lt;/code&gt; if a reviewer is no longer a member of the GitHub Enterprise environment.&lt;/li&gt;
&lt;li&gt;Users were unable to view the diff of comment edits, delete comment edit history items, dismiss the comment edit history onboarding, and reload on comment edits for gist comments.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise clustering has been updated to purge older than one hour MySQL binary logs prior to a &lt;code&gt;ghe-restore&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.  (updated 2018-10-31)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;li&gt;Upgrading to a later version in this series may overwrite custom DNS entries in &lt;code&gt;/etc/resolvconf/resolv.conf.d/head&lt;/code&gt; (updated 2018-12-19)&lt;/li&gt;
&lt;li&gt;Pull request review comments can be misplaced when the pull request has large diffs.  (updated 2019-01-21)&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 25 Sep 2018 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.13.12</title>
					<description>&lt;!-- raw HTML omitted --&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: A file path traversal vulnerability in the &lt;code&gt;jekyll-remote-theme&lt;/code&gt; gem of GitHub Pages could allow users to display the content of local files.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise API responses would not be compressed when requested with &lt;code&gt;gzip&lt;/code&gt; encoding.&lt;/li&gt;
&lt;li&gt;Webhooks could fail to be delivered if the compressed payload was greater than 1 MB.&lt;/li&gt;
&lt;li&gt;Upgrades could fail with &lt;code&gt;Connection timed out&lt;/code&gt; if the hookshot service was unable to run migrations due to a firewall update that ran out of order.&lt;/li&gt;
&lt;li&gt;Repository replication records may be created inconsistently, resulting in unreported replication failures. This type of replication failure is now reported in &lt;code&gt;ghe-repl-status&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-repl-setup&lt;/code&gt; allowed re-adding the same node as a replica.&lt;/li&gt;
&lt;li&gt;Using Safari, administrators were unable to schedule a future hotpatch upgrade from the Management Console due to an incompatible date parse.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-config-check&lt;/code&gt; would hang if run without any arguments.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;hookshot&lt;/code&gt; logs weren&#39;t purged properly in Elasticsearch and could consume large amounts of disk space.&lt;/li&gt;
&lt;li&gt;Migrations with &lt;code&gt;ghe-migrator&lt;/code&gt; could fail to complete trying to add the same label to an issue.&lt;/li&gt;
&lt;li&gt;The pull request page could fail to load with a &lt;code&gt;500 Internal Server Error&lt;/code&gt; if a reviewer is no longer a member of the GitHub Enterprise environment.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments are missing from an import with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.  (updated 2018-10-31)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 25 Sep 2018 16:00:33 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.13.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.13.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.20</title>
					<description>&lt;!-- raw HTML omitted --&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: A file path traversal vulnerability in the &lt;code&gt;jekyll-remote-theme&lt;/code&gt; gem of GitHub Pages could allow users to display the content of local files.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise API responses would not be compressed when requested with &lt;code&gt;gzip&lt;/code&gt; encoding.&lt;/li&gt;
&lt;li&gt;Webhooks could fail to be delivered if the compressed payload was greater than 1 MB.&lt;/li&gt;
&lt;li&gt;Upgrades could fail with &lt;code&gt;Connection timed out&lt;/code&gt; if the hookshot service was unable to run migrations due to a firewall update that ran out of order.&lt;/li&gt;
&lt;li&gt;Repository replication records may be created inconsistently, resulting in unreported replication failures. This type of replication failure is now reported in &lt;code&gt;ghe-repl-status&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-repl-setup&lt;/code&gt; allowed re-adding the same node as a replica.&lt;/li&gt;
&lt;li&gt;Using Safari, administrators were unable to schedule a future hotpatch upgrade from the Management Console due to an incompatible date parse.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-config-check&lt;/code&gt; would hang if run without any arguments.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;hookshot&lt;/code&gt; logs weren&#39;t purged properly in Elasticsearch and could consume large amounts of disk space.&lt;/li&gt;
&lt;li&gt;Migrations with &lt;code&gt;ghe-migrator&lt;/code&gt; could fail to complete trying to add the same label to an issue.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;Git LFS, release and issue assets, user profile images, webhooks, or Subversion access may be unavailable if an appliance is restarted after applying the 2.12.5 or greater hotpatch—if this occurs, please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us&quot;&gt;Enterprise Support&lt;/a&gt; for assistance.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 25 Sep 2018 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.5</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: A malicious user could execute a &#39;tab-nabbing&#39; attack by exploiting &lt;code&gt;window.opener&lt;/code&gt; when linking from GitHub Enterprise hosted Markdown content.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Promoting a replica could take an excessive amount of time in a multi-replica environment.&lt;/li&gt;
&lt;li&gt;Incorrect legends were displayed in the LDAP Management Console graphs.&lt;/li&gt;
&lt;li&gt;Network interface statistics were not collected or displayed due to a recent kernel upgrade.&lt;/li&gt;
&lt;li&gt;When executed in verbose mode, &lt;code&gt;ghe-repl-status&lt;/code&gt; will set its exit code to &lt;code&gt;0&lt;/code&gt; even when replication issues are present.&lt;/li&gt;
&lt;li&gt;The order of nameservers defined in &lt;code&gt;/etc/resolve.conf&lt;/code&gt; was not respected when performing lookups.&lt;/li&gt;
&lt;li&gt;When a web proxy is configured, uploads of files, diagnostics, or support bundles will silently fail.&lt;/li&gt;
&lt;li&gt;Self-signed TLS certificates would fail to generate on Azure instances.&lt;/li&gt;
&lt;li&gt;Local connections were not properly closed and resulted in a memory leak.&lt;/li&gt;
&lt;li&gt;Tags created through a release contained incomplete reflog data&lt;/li&gt;
&lt;li&gt;Organizations could be incorrectly suspended via the Suspend User REST API.&lt;/li&gt;
&lt;li&gt;Email visibility could be incorrectly toggled via the REST API.&lt;/li&gt;
&lt;li&gt;Fixes an issue where rate limits on raw and archive endpoints were left enabled even when configured to be disabled.&lt;/li&gt;
&lt;li&gt;Users can no longer accidentally upload their private PGP keys.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Optimise Elasticsearch backup process by preferring local copies of indices.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.11&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.11 will be deprecated as of September 13, 2018.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.14/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.  (updated 2018-10-31)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;li&gt;Upgrading to a later version in this series may overwrite custom DNS entries in &lt;code&gt;/etc/resolvconf/resolv.conf.d/head&lt;/code&gt; (updated 2018-12-19)&lt;/li&gt;
&lt;li&gt;Pull request review comments can be misplaced when the pull request has large diffs.  (updated 2019-01-21)&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 11 Sep 2018 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.13.11</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: A malicious user could execute a &#39;tab-nabbing&#39; attack by exploiting &lt;code&gt;window.opener&lt;/code&gt; when linking from GitHub Enterprise hosted Markdown content.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Promoting a replica could take an excessive amount of time in a multi-replica environment.&lt;/li&gt;
&lt;li&gt;Incorrect legends were displayed in the LDAP Management Console graphs.&lt;/li&gt;
&lt;li&gt;Self-signed TLS certificates would fail to generate on Azure instances.&lt;/li&gt;
&lt;li&gt;Tags created through a release contained incomplete reflog data&lt;/li&gt;
&lt;li&gt;Organizations could be incorrectly suspended via the Suspend User REST API.&lt;/li&gt;
&lt;li&gt;Email visibility could be incorrectly toggled via the REST API.&lt;/li&gt;
&lt;li&gt;Fixes an issue where rate limits on raw and archive endpoints were left enabled even when configured to be disabled.&lt;/li&gt;
&lt;li&gt;Users can no longer accidentally upload their private PGP keys.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Optimise Elasticsearch backup process by preferring local copies of indices.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments are missing from an import with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.  (updated 2018-10-31)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 11 Sep 2018 16:00:33 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.13.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.13.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.19</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: A malicious user could execute a &#39;tab-nabbing&#39; attack by exploiting &lt;code&gt;window.opener&lt;/code&gt; when linking from GitHub Enterprise hosted Markdown content.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Promoting a replica could take an excessive amount of time in a multi-replica environment.&lt;/li&gt;
&lt;li&gt;Self-signed TLS certificates would fail to generate on Azure instances.&lt;/li&gt;
&lt;li&gt;Tags created through a release contained incomplete reflog data&lt;/li&gt;
&lt;li&gt;Organizations could be incorrectly suspended via the Suspend User REST API.&lt;/li&gt;
&lt;li&gt;Email visibility could be incorrectly toggled via the REST API.&lt;/li&gt;
&lt;li&gt;Fixes an issue where rate limits on raw and archive endpoints were left enabled even when configured to be disabled.&lt;/li&gt;
&lt;li&gt;Users can no longer accidentally upload revoked PGP keys.&lt;/li&gt;
&lt;li&gt;Users can no longer accidentally upload their private PGP keys.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Optimise Elasticsearch backup process by preferring local copies of indices.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;Git LFS, release and issue assets, user profile images, webhooks, or Subversion access may be unavailable if an appliance is restarted after applying the 2.12.5 or greater hotpatch—if this occurs, please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us&quot;&gt;Enterprise Support&lt;/a&gt; for assistance.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 11 Sep 2018 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.25</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: A malicious user could execute a &#39;tab-nabbing&#39; attack by exploiting &lt;code&gt;window.opener&lt;/code&gt; when linking from GitHub Enterprise hosted Markdown content.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Promoting a replica could take an excessive amount of time in a multi-replica environment.&lt;/li&gt;
&lt;li&gt;Self-signed TLS certificates would fail to generate on Azure instances.&lt;/li&gt;
&lt;li&gt;Tags created through a release contained incomplete reflog data&lt;/li&gt;
&lt;li&gt;Organizations could be incorrectly suspended via the Suspend User REST API.&lt;/li&gt;
&lt;li&gt;Email visibility could be incorrectly toggled via the REST API.&lt;/li&gt;
&lt;li&gt;Fixes an issue where rate limits on raw and archive endpoints were left enabled even when configured to be disabled.&lt;/li&gt;
&lt;li&gt;Users can no longer accidentally upload revoked PGP keys.&lt;/li&gt;
&lt;li&gt;Users can no longer accidentally upload their private PGP keys.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Optimise Elasticsearch backup process by preferring local copies of indices.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.11&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.11 will be deprecated as of September 13, 2018.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 11 Sep 2018 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.25</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.25</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.4</title>
					<description>&lt;h2&gt;A file path traversal vulnerability in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker with repository write access to create Pages sites that can display the content of system files. This could used to further escalate the vulnerability to execute arbitrary commands on the GitHub Enterprise appliance.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.12.0 - 2.12.17&lt;/li&gt;
&lt;li&gt;2.13.0 - 2.13.9&lt;/li&gt;
&lt;li&gt;2.14.0 - 2.14.3&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;GitHub Enterprise 2.11 is not vulnerable.&lt;/p&gt;
&lt;p&gt;We &lt;strong&gt;strongly&lt;/strong&gt; recommend upgrading your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.12.18, 2.13.10, 2.14.4, or greater.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: A file path traversal vulnerability in GitHub Pages could allow users to display the content of local files.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Access may have been inadvertently granted to internal IP addresses of GitHub Enterprise. The fix removed any access grants via an IP address.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: A malicious user could execute a &#39;tab-nabbing&#39; attack by exploiting &lt;code&gt;window.opener&lt;/code&gt; when linking from GitHub Enterprise hosted Markdown content.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Corrupted Consul configuration data could prevent appliance configuration changes from completing successfully.&lt;/li&gt;
&lt;li&gt;Deleting an SNMPv3 user via &lt;code&gt;ghe-snmpv3-remove-user&lt;/code&gt; did not remove all account data, preventing administrators from updating the password for the SNMPv3 user.&lt;/li&gt;
&lt;li&gt;Terminating the &lt;code&gt;ghe-set-password&lt;/code&gt; command could result in unexpected shell behavior.&lt;/li&gt;
&lt;li&gt;Messages sent from the email service hook failed due to a recent security update.&lt;/li&gt;
&lt;li&gt;Viewing a GitHub App page could result in an error if the parent organization contained repositories which were user-administered.&lt;/li&gt;
&lt;li&gt;Adding a new integration failed if the license seat limit was reached.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.11&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.11 will be deprecated as of September 13, 2018.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.14/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.  (updated 2018-10-31)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;li&gt;Pull request review comments can be misplaced when the pull request has large diffs.  (updated 2019-01-21)&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 28 Aug 2018 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.13.10</title>
					<description>&lt;h2&gt;A file path traversal vulnerability in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker with repository write access to create Pages sites that can display the content of system files. This could used to further escalate the vulnerability to execute arbitrary commands on the GitHub Enterprise appliance.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.12.0 - 2.12.17&lt;/li&gt;
&lt;li&gt;2.13.0 - 2.13.9&lt;/li&gt;
&lt;li&gt;2.14.0 - 2.14.3&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;GitHub Enterprise 2.11 is not vulnerable.&lt;/p&gt;
&lt;p&gt;We &lt;strong&gt;strongly&lt;/strong&gt; recommend upgrading your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.12.18, 2.13.10, 2.14.4, or greater.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: A file path traversal vulnerability in GitHub Pages could allow users to display the content of local files.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Access may have been inadvertently granted to internal IP addresses of GitHub Enterprise. The fix removed any access grants via an IP address.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: A malicious user could execute a &#39;tab-nabbing&#39; attack by exploiting &lt;code&gt;window.opener&lt;/code&gt; when linking from GitHub Enterprise hosted Markdown content.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Corrupted Consul configuration data could prevent appliance configuration changes from completing successfully.&lt;/li&gt;
&lt;li&gt;Deleting an SNMPv3 user via &lt;code&gt;ghe-snmpv3-remove-user&lt;/code&gt; did not remove all account data, preventing administrators from updating the password for the SNMPv3 user.&lt;/li&gt;
&lt;li&gt;Terminating the &lt;code&gt;ghe-set-password&lt;/code&gt; command could result in unexpected shell behavior.&lt;/li&gt;
&lt;li&gt;Messages sent from the email service hook failed due to a recent security update.&lt;/li&gt;
&lt;li&gt;Adding a new integration failed if the license seat limit was reached.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments are missing from an import with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.  (updated 2018-10-31)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 28 Aug 2018 16:00:33 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.13.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.13.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.18</title>
					<description>&lt;h2&gt;A file path traversal vulnerability in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker with repository write access to create Pages sites that can display the content of system files. This could used to further escalate the vulnerability to execute arbitrary commands on the GitHub Enterprise appliance.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.12.0 - 2.12.17&lt;/li&gt;
&lt;li&gt;2.13.0 - 2.13.9&lt;/li&gt;
&lt;li&gt;2.14.0 - 2.14.3&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;GitHub Enterprise 2.11 is not vulnerable.&lt;/p&gt;
&lt;p&gt;We &lt;strong&gt;strongly&lt;/strong&gt; recommend upgrading your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.12.18, 2.13.10, 2.14.4, or greater.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: A file path traversal vulnerability in GitHub Pages could allow users to display the content of local files.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Access may have been inadvertently granted to internal IP addresses of GitHub Enterprise. The fix removed any access grants via an IP address.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: A malicious user could execute a &#39;tab-nabbing&#39; attack by exploiting &lt;code&gt;window.opener&lt;/code&gt; when linking from GitHub Enterprise hosted Markdown content.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Deleting an SNMPv3 user via &lt;code&gt;ghe-snmpv3-remove-user&lt;/code&gt; did not remove all account data, preventing administrators from updating the password for the SNMPv3 user.&lt;/li&gt;
&lt;li&gt;Terminating the &lt;code&gt;ghe-set-password&lt;/code&gt; command could result in unexpected shell behavior.&lt;/li&gt;
&lt;li&gt;Messages sent from the email service hook failed due to a recent security update.&lt;/li&gt;
&lt;li&gt;Adding a new integration failed if the license seat limit was reached.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Admins can see which repositories are using GitHub Services with &lt;code&gt;ghe-legacy-github-services-report&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;Git LFS, release and issue assets, user profile images, webhooks, or Subversion access may be unavailable if an appliance is restarted after applying the 2.12.5 or greater hotpatch—if this occurs, please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us&quot;&gt;Enterprise Support&lt;/a&gt; for assistance.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 28 Aug 2018 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.24</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Access may have been inadvertently granted to internal IP addresses of GitHub Enterprise. The fix removed any access grants via an IP address.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: A malicious user could execute a &#39;tab-nabbing&#39; attack by exploiting &lt;code&gt;window.opener&lt;/code&gt; when linking from GitHub Enterprise hosted Markdown content.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Deleting an SNMPv3 user via &lt;code&gt;ghe-snmpv3-remove-user&lt;/code&gt; did not remove all account data, preventing administrators from updating the password for the SNMPv3 user.&lt;/li&gt;
&lt;li&gt;Terminating the &lt;code&gt;ghe-set-password&lt;/code&gt; command could result in unexpected shell behavior.&lt;/li&gt;
&lt;li&gt;Adding a new integration failed if the license seat limit was reached.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Admins can see which repositories are using GitHub Services with &lt;code&gt;ghe-legacy-github-services-report&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.11&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.11 will be deprecated as of September 13, 2018.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 28 Aug 2018 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.24</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.24</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.3</title>
					<description>&lt;h2&gt;Remote code execution with server side request forgery in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker with repository admin or owner privileges to execute arbitrary commands on the appliance.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.11.0 - 2.11.23&lt;/li&gt;
&lt;li&gt;2.12.0 - 2.12.16&lt;/li&gt;
&lt;li&gt;2.13.0 - 2.13.8&lt;/li&gt;
&lt;li&gt;2.14.0 - 2.14.2&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata: A file path traversal vulnerability in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;GitHub Enterprise 2.14.3, 2.13.9, and 2.12.17 were not patched properly and are still vulnerable to the file path traversal vulnerability. GitHub Enterprise 2.14.4, 2.13.10, and 2.12.18 will ship next week to address this vulnerability. As a manual workaround, you can &lt;a href=&quot;https://docs.github.com/enterprise/2.14/admin/guides/installation/configuring-github-pages-on-your-appliance/#disabling-github-pages-on-your-github-enterprise-instance&quot;&gt;disable Pages&lt;/a&gt; on the GitHub Enterprise environment. (updated 2018-08-23)&lt;/p&gt;
&lt;p&gt;&lt;em&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker with repository write access to create Pages sites that can display the content of system files. This could used to further escalate the vulnerability to execute arbitrary commands on the GitHub Enterprise appliance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;The affected supported versions are:&lt;/em&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;2.12.0 - &lt;del&gt;2.12.16&lt;/del&gt; 2.12.17&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2.13.0 - &lt;del&gt;2.13.8&lt;/del&gt; 2.13.9&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2.14.0 - &lt;del&gt;2.14.2&lt;/del&gt; 2.14.3&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;GitHub Enterprise 2.11 is not vulnerable.&lt;/em&gt;&lt;/p&gt;
&lt;h2&gt;Next steps&lt;/h2&gt;
&lt;p&gt;We &lt;strong&gt;strongly&lt;/strong&gt; recommend upgrading your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.12.17, 2.13.9 or 2.14.3.&lt;/p&gt;
&lt;p&gt;Due to a change in the implementation on GitHub Enterprise 2.12 and later, it is not possible to apply the same fix to GitHub Enterprise 2.11 for the remote code execution vulnerability. We &lt;strong&gt;strongly&lt;/strong&gt; recommend upgrading GitHub Enterprise 2.11 to 2.12 or newer.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: An attacker with repository admin or owner privileges could execute arbitrary commands on the appliance.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: A file path traversal vulnerability in GitHub Pages could allow users to display the content of local files.&lt;/del&gt; (updated 2018-08-23)&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-repl-status&lt;/code&gt;, used to query the status of a high availability status, failed with a &lt;code&gt;parse error: Invalid numeric literal at line 1, column 3&lt;/code&gt; error.&lt;/li&gt;
&lt;li&gt;Harmless &#39;Cannot add dependency job for unit cloud-config.service, ignoring&#39; messages we reported to syslog when booting non-cloud based appliances.&lt;/li&gt;
&lt;li&gt;Signing in with SAML authentication on a newly-deployed GitHub Enterprise appliance could fail with a &lt;code&gt;500 Internal Server Error&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;MySQL procedures executed when MySQL starts could fail if tables don&#39;t exist yet. This could prevent MySQL replication from starting in cluster and high availability environments.&lt;/li&gt;
&lt;li&gt;Hotpatching on Azure would fail due to a package conflict between &lt;code&gt;waagent&lt;/code&gt; and &lt;code&gt;walinuxagent&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The public pages for GitHub Apps responded with a 500 Internal Server Error on some installations that use SAML or CAS for authentication.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-org-admin-promote&lt;/code&gt; command-line utility would fail when attempting to promote a user without two-factor-authentication enabled as an admin of an org where two-factor authentication is required.&lt;/li&gt;
&lt;li&gt;New repository maintenance jobs would attempt to start whilst another maintenance job was still running on very large repositories.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Restoring cluster backups could fail if inconsistent repository data is stored in the backup. These cases are now logged and the restore allowed to continue when using &lt;a href=&quot;https://github.com/github/backup-utils&quot;&gt;backup-utils&lt;/a&gt; v2.14.2.&lt;/li&gt;
&lt;li&gt;Feature upgrades in environments with a large number of labels would take longer than needed.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.11&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.11 will be deprecated as of September 13, 2018.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.14/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.  (updated 2018-10-31)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;li&gt;Pull request review comments can be misplaced when the pull request has large diffs.  (updated 2019-01-21)&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise 2.14.3 was not patched properly and is still vulnerable to the file path traversal vulnerability. (updated 2018-08-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 21 Aug 2018 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.13.9</title>
					<description>&lt;h2&gt;Remote code execution with server side request forgery in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker with repository admin or owner privileges to execute arbitrary commands on the appliance.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.11.0 - 2.11.23&lt;/li&gt;
&lt;li&gt;2.12.0 - 2.12.16&lt;/li&gt;
&lt;li&gt;2.13.0 - 2.13.8&lt;/li&gt;
&lt;li&gt;2.14.0 - 2.14.2&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata: A file path traversal vulnerability in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;GitHub Enterprise 2.14.3, 2.13.9, and 2.12.17 were not patched properly and are still vulnerable to the file path traversal vulnerability. GitHub Enterprise 2.14.4, 2.13.10, and 2.12.18 will ship next week to address this vulnerability. As a manual workaround, you can &lt;a href=&quot;https://docs.github.com/enterprise/2.14/admin/guides/installation/configuring-github-pages-on-your-appliance/#disabling-github-pages-on-your-github-enterprise-instance&quot;&gt;disable Pages&lt;/a&gt; on the GitHub Enterprise environment. (updated 2018-08-23)&lt;/p&gt;
&lt;p&gt;&lt;em&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker with repository write access to create Pages sites that can display the content of system files. This could used to further escalate the vulnerability to execute arbitrary commands on the GitHub Enterprise appliance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;The affected supported versions are:&lt;/em&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;2.12.0 - &lt;del&gt;2.12.16&lt;/del&gt; 2.12.17&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2.13.0 - &lt;del&gt;2.13.8&lt;/del&gt; 2.13.9&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2.14.0 - &lt;del&gt;2.14.2&lt;/del&gt; 2.14.3&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;GitHub Enterprise 2.11 is not vulnerable.&lt;/em&gt;&lt;/p&gt;
&lt;h2&gt;Next steps&lt;/h2&gt;
&lt;p&gt;We &lt;strong&gt;strongly&lt;/strong&gt; recommend upgrading your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.12.17, 2.13.9 or 2.14.3.&lt;/p&gt;
&lt;p&gt;Due to a change in the implementation on GitHub Enterprise 2.12 and later, it is not possible to apply the same fix to GitHub Enterprise 2.11 for the remote code execution vulnerability. We &lt;strong&gt;strongly&lt;/strong&gt; recommend upgrading GitHub Enterprise 2.11 to 2.12 or newer.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: An attacker with repository admin or owner privileges could execute arbitrary commands on the appliance.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: A file path traversal vulnerability in GitHub Pages could allow users to display the content of local files.&lt;/del&gt; (updated 2018-08-23)&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Harmless &#39;Cannot add dependency job for unit cloud-config.service, ignoring&#39; messages we reported to syslog when booting non-cloud based appliances.&lt;/li&gt;
&lt;li&gt;MySQL procedures executed when MySQL starts could fail if tables don&#39;t exist yet. This could prevent MySQL replication from starting in cluster and high availability environments.&lt;/li&gt;
&lt;li&gt;Hotpatching on Azure would fail due to a package conflict between &lt;code&gt;waagent&lt;/code&gt; and &lt;code&gt;walinuxagent&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The public pages for GitHub Apps responded with a 500 Internal Server Error on some installations that use SAML or CAS for authentication.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-org-admin-promote&lt;/code&gt; command-line utility would fail when attempting to promote a user without two-factor-authentication enabled as an admin of an org where two-factor authentication is required.&lt;/li&gt;
&lt;li&gt;New repository maintenance jobs would attempt to start whilst another maintenance job was still running on very large repositories.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Restoring cluster backups could fail if inconsistent repository data is stored in the backup. These cases are now logged and the restore allowed to continue when using &lt;a href=&quot;https://github.com/github/backup-utils&quot;&gt;backup-utils&lt;/a&gt; v2.14.2.&lt;/li&gt;
&lt;li&gt;Feature upgrades in environments with a large number of labels would take longer than needed.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;User-Agent&lt;/code&gt; has been added to &lt;code&gt;Access-Control-Allow-Headers&lt;/code&gt; to support API clients which follow the &lt;a href=&quot;https://fetch.spec.whatwg.org/&quot;&gt;Fetch&lt;/a&gt; specification.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments are missing from an import with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.  (updated 2018-10-31)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise 2.13.9 was not patched properly and is still vulnerable to the file path traversal vulnerability. (updated 2018-08-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 21 Aug 2018 16:00:33 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.13.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.13.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.17</title>
					<description>&lt;h2&gt;Remote code execution with server side request forgery in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker with repository admin or owner privileges to execute arbitrary commands on the appliance.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.11.0 - 2.11.23&lt;/li&gt;
&lt;li&gt;2.12.0 - 2.12.16&lt;/li&gt;
&lt;li&gt;2.13.0 - 2.13.8&lt;/li&gt;
&lt;li&gt;2.14.0 - 2.14.2&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata: A file path traversal vulnerability in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;GitHub Enterprise 2.14.3, 2.13.9, and 2.12.17 were not patched properly and are still vulnerable to the file path traversal vulnerability. GitHub Enterprise 2.14.4, 2.13.10, and 2.12.18 will ship next week to address this vulnerability. As a manual workaround, you can &lt;a href=&quot;https://docs.github.com/enterprise/2.14/admin/guides/installation/configuring-github-pages-on-your-appliance/#disabling-github-pages-on-your-github-enterprise-instance&quot;&gt;disable Pages&lt;/a&gt; on the GitHub Enterprise environment. (updated 2018-08-23)&lt;/p&gt;
&lt;p&gt;&lt;em&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker with repository write access to create Pages sites that can display the content of system files. This could used to further escalate the vulnerability to execute arbitrary commands on the GitHub Enterprise appliance.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;The affected supported versions are:&lt;/em&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;2.12.0 - &lt;del&gt;2.12.16&lt;/del&gt; 2.12.17&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2.13.0 - &lt;del&gt;2.13.8&lt;/del&gt; 2.13.9&lt;/em&gt;&lt;/li&gt;
&lt;li&gt;&lt;em&gt;2.14.0 - &lt;del&gt;2.14.2&lt;/del&gt; 2.14.3&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;em&gt;GitHub Enterprise 2.11 is not vulnerable.&lt;/em&gt;&lt;/p&gt;
&lt;h2&gt;Next steps&lt;/h2&gt;
&lt;p&gt;We &lt;strong&gt;strongly&lt;/strong&gt; recommend upgrading your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.12.17, 2.13.9 or 2.14.3.&lt;/p&gt;
&lt;p&gt;Due to a change in the implementation on GitHub Enterprise 2.12 and later, it is not possible to apply the same fix to GitHub Enterprise 2.11 for the remote code execution vulnerability. We &lt;strong&gt;strongly&lt;/strong&gt; recommend upgrading GitHub Enterprise 2.11 to 2.12 or newer.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: An attacker with repository admin or owner privileges could execute arbitrary commands on the appliance.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: A file path traversal vulnerability in GitHub Pages could allow users to display the content of local files.&lt;/del&gt; (updated 2018-08-23)&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Harmless &#39;Cannot add dependency job for unit cloud-config.service, ignoring&#39; messages we reported to syslog when booting non-cloud based appliances.&lt;/li&gt;
&lt;li&gt;MySQL procedures executed when MySQL starts could fail if tables don&#39;t exist yet. This could prevent MySQL replication from starting in cluster and high availability environments.&lt;/li&gt;
&lt;li&gt;Hotpatching on Azure would fail due to a package conflict between &lt;code&gt;waagent&lt;/code&gt; and &lt;code&gt;walinuxagent&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The public pages for GitHub Apps responded with a 500 Internal Server Error on some installations that use SAML or CAS for authentication.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-org-admin-promote&lt;/code&gt; command-line utility would fail when attempting to promote a user without two-factor-authentication enabled as an admin of an org where two-factor authentication is required.&lt;/li&gt;
&lt;li&gt;New repository maintenance jobs would attempt to start whilst another maintenance job was still running on very large repositories.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;User-Agent&lt;/code&gt; has been added to &lt;code&gt;Access-Control-Allow-Headers&lt;/code&gt; to support API clients which follow the &lt;a href=&quot;https://fetch.spec.whatwg.org/&quot;&gt;Fetch&lt;/a&gt; specification.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;Git LFS, release and issue assets, user profile images, webhooks, or Subversion access may be unavailable if an appliance is restarted after applying the 2.12.5 or greater hotpatch—if this occurs, please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us&quot;&gt;Enterprise Support&lt;/a&gt; for assistance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise 2.12.17 was not patched properly and is still vulnerable to the file path traversal vulnerability. (updated 2018-08-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 21 Aug 2018 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.23</title>
					<description>&lt;h2&gt;Remote code execution with server side request forgery in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker with repository admin or owner privileges to execute arbitrary commands on the appliance.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.11.0 - 2.11.23&lt;/li&gt;
&lt;li&gt;2.12.0 - 2.12.16&lt;/li&gt;
&lt;li&gt;2.13.0 - 2.13.8&lt;/li&gt;
&lt;li&gt;2.14.0 - 2.14.2&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Next steps&lt;/h2&gt;
&lt;p&gt;Due to a change in the implementation on GitHub Enterprise 2.12 and later, it is not possible to apply the same fix to GitHub Enterprise 2.11. We &lt;strong&gt;strongly&lt;/strong&gt; recommend upgrading GitHub Enterprise 2.11 to 2.12 or newer.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Harmless &#39;Cannot add dependency job for unit cloud-config.service, ignoring&#39; messages we reported to syslog when booting non-cloud based appliances.&lt;/li&gt;
&lt;li&gt;MySQL procedures executed when MySQL starts could fail if tables don&#39;t exist yet. This could prevent MySQL replication from starting in cluster and high availability environments.&lt;/li&gt;
&lt;li&gt;Hotpatching on Azure would fail due to a package conflict between &lt;code&gt;waagent&lt;/code&gt; and &lt;code&gt;walinuxagent&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The public pages for GitHub Apps responded with a 500 Internal Server Error on some installations that use SAML or CAS for authentication.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-org-admin-promote&lt;/code&gt; command-line utility would fail when attempting to promote a user without two-factor-authentication enabled as an admin of an org where two-factor authentication is required.&lt;/li&gt;
&lt;li&gt;New repository maintenance jobs would attempt to start whilst another maintenance job was still running on very large repositories.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;User-Agent&lt;/code&gt; has been added to &lt;code&gt;Access-Control-Allow-Headers&lt;/code&gt; to support API clients which follow the &lt;a href=&quot;https://fetch.spec.whatwg.org/&quot;&gt;Fetch&lt;/a&gt; specification.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.11&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.11 will be deprecated as of September 13, 2018.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 21 Aug 2018 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.23</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.23</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.2</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Running &lt;code&gt;ghe-support-upload&lt;/code&gt; or &lt;code&gt;ghe-cluster-support-upload&lt;/code&gt; with &lt;code&gt;sudo&lt;/code&gt; would set restrictive permissions on a temporary directory preventing subsequent execution of these commands by the admin user.&lt;/li&gt;
&lt;li&gt;The webhook Elasticsearch index replica count was not adjusted when upgrading the appliance leading to Elasticsearch attempting to over or under replicate the index.&lt;/li&gt;
&lt;li&gt;In high availability environments, Consul would attempt to communicate with the other node using the public IP address in addition to the VPN IP address. These are correctly blocked but result in a flood of errors in the system log.&lt;/li&gt;
&lt;li&gt;The compare page could fail to load if a user of a fork of the repository has been deleted.&lt;/li&gt;
&lt;li&gt;Redundant routes were created for archived gists when restoring to a cluster environment. This prevented archived gists from being unarchived.&lt;/li&gt;
&lt;li&gt;Searching for GitHub.com wiki results could fail with a &lt;code&gt;406 Not Acceptable&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Searching for GitHub.com code results could fail with a &lt;code&gt;500 Internal Server Error&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;connect&lt;/code&gt; timeout has been increased to allow up to four retries during a cluster restore.&lt;/li&gt;
&lt;li&gt;Repositories which failed periodic maintenance needed manual intervention. GitHub Enterprise now retries maintenance for failed repositories once per week.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.  (updated 2018-10-31)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;li&gt;Pull request review comments can be misplaced when the pull request has large diffs.  (updated 2019-01-21)&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 07 Aug 2018 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.13.8</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In high availability environments, Consul would attempt to communicate with the other node using the public IP address in addition to the VPN IP address. These are correctly blocked but result in a flood of errors in the system log.&lt;/li&gt;
&lt;li&gt;The compare page could fail to load if a user of a fork of the repository has been deleted.&lt;/li&gt;
&lt;li&gt;Redundant routes were created for archived gists when restoring to a cluster environment. This prevented archived gists from being unarchived.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;connect&lt;/code&gt; timeout has been increased to allow up to four retries during a cluster restore.&lt;/li&gt;
&lt;li&gt;Repositories which failed periodic maintenance needed manual intervention. GitHub Enterprise now retries maintenance for failed repositories once per week.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments are missing from an import with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.  (updated 2018-10-31)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 07 Aug 2018 16:00:33 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.13.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.13.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.16</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The compare page could fail to load if a user of a fork of the repository has been deleted.&lt;/li&gt;
&lt;li&gt;Redundant routes were created for archived gists when restoring to a cluster environment. This prevented archived gists from being unarchived.&lt;/li&gt;
&lt;li&gt;When a commit comment is left on a file with non-ascii characters in the path, the pull request page could return 503.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;connect&lt;/code&gt; timeout has been increased to allow up to four retries during a cluster restore.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;Git LFS, release and issue assets, user profile images, webhooks, or Subversion access may be unavailable if an appliance is restarted after applying the 2.12.5 or greater hotpatch—if this occurs, please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us&quot;&gt;Enterprise Support&lt;/a&gt; for assistance.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 07 Aug 2018 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.22</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Redundant routes were created for archived gists when restoring to a cluster environment. This prevented archived gists from being unarchived.&lt;/li&gt;
&lt;li&gt;When a commit comment is left on a file with non-ascii characters in the path, the pull request page could return 503.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;connect&lt;/code&gt; timeout has been increased to allow up to four retries during a cluster restore.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.11&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.11 will be deprecated as of September 13, 2018.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 07 Aug 2018 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.1</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The high availability replication status as reported by &lt;code&gt;ghe-repl-status&lt;/code&gt; reported a harmless error, &lt;code&gt;parse error: Invalid numeric literal at line 1, column 3&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Attempting to rename a repository and only changing character casing resulted in an error.&lt;/li&gt;
&lt;li&gt;Pages was not replicated properly when tearing down and re-attaching a former replica.&lt;/li&gt;
&lt;li&gt;The &amp;quot;Files Changed&amp;quot; view failed to display all changes when the difference contained a type change and the difference was too large.&lt;/li&gt;
&lt;li&gt;The &amp;quot;Learn more&amp;quot; reference when configuring a &amp;quot;GitHub.com connection&amp;quot; used an incorrect help.github.com guide.&lt;/li&gt;
&lt;li&gt;Built-in users would not have a password reset button available for administrators when external authentication was used with allowing built-in accounts.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Apps have been updated with access to the &lt;a href=&quot;https://developer.github.com/enterprise/2.14/v3/orgs/pre_receive_hooks/&quot;&gt;Organization Pre-receive Hooks &lt;/a&gt; endpoints.&lt;/li&gt;
&lt;li&gt;GitHub Apps have been updated with access to the &lt;a href=&quot;https://developer.github.com/enterprise/2.14/v3/repos/pre_receive_hooks/&quot;&gt;Repository Pre-receive Hooks &lt;/a&gt; endpoints.&lt;/li&gt;
&lt;li&gt;GitHub Apps have been updated to allow archiving repositories.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Services&lt;/h2&gt;
&lt;p&gt;Starting with GitHub Enterprise 2.17.0, support for GitHub Services will be deprecated and administrators will not be able to install or configure new GitHub Services. Existing GitHub Services from a previous version of GitHub Enterprise will continue to function but GitHub Enterprise will not be providing any security or bug fixes to the GitHub Services functionality. At this time, there will be no changes to the existing functionality, but a warning banner will be displayed with the &lt;a href=&quot;https://developer.github.com/changes/2018-04-25-github-services-deprecation/&quot;&gt;deprecation announcement blog post&lt;/a&gt;. Administrators can see which repositories are using GitHub Services with &lt;code&gt;ghe-legacy-github-services-report&lt;/code&gt;.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.  (updated 2018-10-31)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;li&gt;Pull request review comments can be misplaced when the pull request has large diffs.  (updated 2019-01-21)&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 24 Jul 2018 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.13.7</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The review requirement of a protected branch did not take into consideration a a review created by a GitHub App.&lt;/li&gt;
&lt;li&gt;Pages was not replicated properly when tearing down and re-attaching a former replica.&lt;/li&gt;
&lt;li&gt;The &amp;quot;Files Changed&amp;quot; view failed to display all changes when the difference contained a type change and the difference was too large.&lt;/li&gt;
&lt;li&gt;Built-in users would not have a password reset button available for administrators when external authentication was used with allowing built-in accounts.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Apps have been updated to allow archiving repositories.&lt;/li&gt;
&lt;li&gt;GitHub Apps have been updated to allow reviewing pull requests.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments are missing from an import with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.  (updated 2018-10-31)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 24 Jul 2018 16:00:33 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.13.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.13.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.15</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &amp;quot;Files Changed&amp;quot; view failed to display all changes when the difference contained a type change and the difference was too large.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Apps have been updated to allow archiving repositories.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;GitHub Enterprise clustering can not be configured without https.&lt;/del&gt;&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;Git LFS, release and issue assets, user profile images, webhooks, or Subversion access may be unavailable if an appliance is restarted after applying the 2.12.5 or greater hotpatch—if this occurs, please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us&quot;&gt;Enterprise Support&lt;/a&gt; for assistance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;HTTPS is now a requirement of GitHub Enterprise clustering. (updated 2018-08-13)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 24 Jul 2018 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.21</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &amp;quot;Files Changed&amp;quot; view failed to display all changes when the difference contained a type change and the difference was too large.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;GitHub Enterprise clustering can not be configured without https.&lt;/del&gt;&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Failing to delete associated metadata when deleting a search index was resolved in 2.11.12. (updated 2018-08-06)&lt;/li&gt;
&lt;li&gt;HTTPS is now a requirement of GitHub Enterprise clustering. (updated 2018-08-13)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 24 Jul 2018 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.14.0</title>
					<description>&lt;h2&gt;Features&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.14/admin/guides/user-management/configuring-visibility-for-organization-membership&quot;&gt;Configure visibility for organization membership&lt;/a&gt; to allow or disallow users in your instance to see all members of their organizations.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.14/admin/guides/user-management/managing-dormant-users/&quot;&gt;Extend user dormancy threshold&lt;/a&gt; from one month up to 90 days.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.14/admin/guides/user-management/allowing-admins-to-enable-anonymous-git-read-access-to-public-repositories&quot;&gt;Allow administrators to enable anonymous Git read access to public repositories&lt;/a&gt; when your instance is in private mode.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.14/admin/guides/enterprise-support/submitting-a-ticket#submitting-a-ticket-using-the-github-enterprise-management-console&quot;&gt;Contact GitHub Enterprise Support using the Management Console&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.14/admin/articles/command-line-utilities#ghe-support-upload&quot;&gt;Provide data to GitHub Enterprise Support using command-line utilities&lt;/a&gt; and &lt;a href=&quot;https://docs.github.com/enterprise/2.14/admin/guides/enterprise-support/providing-data-to-github-enterprise-support/&quot;&gt;improve diagnostic files&lt;/a&gt; for providing data to GitHub Enterprise Support.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.14/user/articles/project-board-permissions-for-an-organization&quot;&gt;Set granular permissions&lt;/a&gt; for project boards owned by organizations.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.14/user/articles/about-project-boards#templates-for-project-boards&quot;&gt;Triage and prioritize bugs using an automated project board template&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.14/user/articles/reopening-a-closed-project-board&quot;&gt;Reopen a closed project board&lt;/a&gt; and optionally resync automation.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.14/user/articles/enabling-required-reviews-for-pull-requests&quot;&gt;Require multiple approving reviews&lt;/a&gt; for pull requests against a protected branch.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.14/user/articles/requesting-to-add-or-change-a-parent-team/&quot;&gt;Request to add or change a parent team&lt;/a&gt; for a team in an organization.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.14/user/articles/about-issue-and-pull-request-templates#issue-templates&quot;&gt;Use multiple issue templates in your repository&lt;/a&gt; with the issue template builder.&lt;/li&gt;
&lt;li&gt;Keep track of issues, pull requests, repositories, and organizations using improved &lt;a href=&quot;https://docs.github.com/enterprise/2.14/user/articles/about-your-personal-dashboard&quot;&gt;personal&lt;/a&gt; and &lt;a href=&quot;https://docs.github.com/enterprise/2.14/user/articles/about-your-organization-dashboard&quot;&gt;organization&lt;/a&gt; dashboards.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.14/user/articles/tracking-changes-in-a-comment&quot;&gt;See a comment&#39;s edit history&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.14/user/articles/reviewing-the-audit-log-for-your-organization#the-integration_installation_request-category&quot;&gt;Request that an organization owner install an integration&lt;/a&gt;, and approve or deny requests.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.14/user/articles/about-searching-on-github&quot;&gt;Search globally across your instance or scope your search to a particular organization or repository&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.14/user/articles/about-comparing-branches-in-pull-requests&quot;&gt;Ignore whitespace changes&lt;/a&gt; in a pull request.&lt;/li&gt;
&lt;li&gt;Use keyboard shortcuts to &lt;a href=&quot;https://docs.github.com/enterprise/2.14/user/articles/using-keyboard-shortcuts/#comments&quot;&gt;autofill a saved reply&lt;/a&gt;, &lt;a href=&quot;https://docs.github.com/enterprise/2.14/user/articles/using-keyboard-shortcuts#site-wide-shortcuts&quot;&gt;view user hovercards&lt;/a&gt;, and &lt;a href=&quot;https://docs.github.com/enterprise/2.14/user/articles/using-keyboard-shortcuts#site-wide-shortcuts&quot;&gt;focus the search bar&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Allow administrators to override the suggested protocol for cloning.&lt;/li&gt;
&lt;li&gt;View alerts when the configured TLS certificate will expire in the next 30 days.&lt;/li&gt;
&lt;li&gt;Communicate richer feedback to check runs against code changes with the new Checks API.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: A GitHub App could download a repository archive that it was not authorized to access during installation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Command-line injection could be triggered by uploading a specially-crafted pre-receive hook environment.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM:&lt;/strong&gt; Environment variables passed to pre-receive hook scripts were not properly escaped.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: It was possible to start a shell from the network configuration settings screen available on a virtual console.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Filtering of parameters in log files was changed from a blacklist of fields to a whitelist. This ensures that less values are logged and in the future no values are accidentally logged.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: The body of API requests containing sensitive data was written to log files on the appliance. The request body is now only logged for debugging purposes and sensitive data is scrubbed before being logged.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Parallel uploads of the same Git LFS object could fail but reported as successful.&lt;/li&gt;
&lt;li&gt;Jupyter notebooks added to a Gist would fail to render on appliances with subdomain isolation disabled.&lt;/li&gt;
&lt;li&gt;Including the port in the &lt;code&gt;Host&lt;/code&gt; header when requesting a Pages site would return a 404 error.&lt;/li&gt;
&lt;li&gt;A pull request created via the API could be assigned an ID of &lt;code&gt;0&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The LDAP users page at &lt;code&gt;/stafftools/users/ldap&lt;/code&gt; had layout and accessibility issues.&lt;/li&gt;
&lt;li&gt;The Fork button was enabled for repositories in cases where a repository could not be forked anywhere.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.14/admin/guides/installation/migrating-elasticsearch-indices-to-github-enterprise-2-14-or-later&quot;&gt;Upgrade to Elasticsearch 5.6&lt;/a&gt;. An upgrade to GitHub Enterprise 2.14 requires a manual migration while the &lt;a href=&quot;https://docs.github.com/enterprise/2.14/admin/guides/installation/migrating-elasticsearch-indices-to-github-enterprise-2-14-or-later#preparing-a-github-enterprise-212-or-213-appliance&quot;&gt;appliance is running GitHub Enterprise 2.12 or 2.13&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Following users is rate limited to 35 users per minute or 300 users per hour.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;/var/log/github/audit.log&lt;/code&gt; has been updated to output audit events only when there has been a change.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;babeld.log&lt;/code&gt; has been updated to include the &lt;code&gt;X-Forwarded-For&lt;/code&gt; and &lt;code&gt;ts&lt;/code&gt; (timestamp) metadata.&lt;/li&gt;
&lt;li&gt;Renaming an existing user is enabled for SAML configured appliances.&lt;/li&gt;
&lt;li&gt;New &lt;a href=&quot;https://developer.github.com/enterprise/2.14/v3/&quot;&gt;REST API&lt;/a&gt; resources have been added.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.github.com/enterprise/2.14/v4/&quot;&gt;GraphQL API&lt;/a&gt; schema has been updated.&lt;/li&gt;
&lt;li&gt;New &lt;a href=&quot;https://developer.github.com/enterprise/2.14/webhooks/&quot;&gt;webhook events&lt;/a&gt; have been added.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Backups and Disaster Recovery&lt;/h2&gt;
&lt;p&gt;GitHub Enterprise 2.14 requires at least &lt;a href=&quot;https://github.com/github/backup-utils&quot;&gt;GitHub Enterprise Backup Utilities&lt;/a&gt; 2.14.0 for &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/backups-and-disaster-recovery/&quot;&gt;Backups and Disaster Recovery&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Services&lt;/h2&gt;
&lt;p&gt;Starting with GitHub Enterprise 2.17.0, support for GitHub Services will be deprecated and administrators will not be able to install or configure new GitHub Services. Existing GitHub Services from a previous version of GitHub Enterprise will continue to function but GitHub Enterprise will not be providing any security or bug fixes to the GitHub Services functionality. At this time, there will be no changes to the existing functionality, but a warning banner will be displayed with the &lt;a href=&quot;https://developer.github.com/changes/2018-04-25-github-services-deprecation/&quot;&gt;deprecation announcement blog post&lt;/a&gt;. Administrators can see which repositories are using GitHub Services with &lt;code&gt;ghe-legacy-github-services-report&lt;/code&gt;. (updated 2017-07-24)&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of Internet Explorer 11 support&lt;/h2&gt;
&lt;p&gt;Support for Internet Explorer 11 will be deprecated on September 13, 2018.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;The high availability replication status as reported by &lt;code&gt;ghe-repl-status&lt;/code&gt; could report a harmless error, &lt;code&gt;parse error: Invalid numeric literal at line 1, column 3&lt;/code&gt;.  (updated 2018-07-17)&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.  (updated 2018-10-31)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;li&gt;Pull request review comments can be misplaced when the pull request has large diffs.  (updated 2019-01-21)&lt;/li&gt;
&lt;li&gt;Issues cannot be closed if they contain a permalink to a blob in the same repository where the file path is longer than 255 characters.  (updated 2019-03-07)&lt;/li&gt;
&lt;li&gt;Some pull requests and issues are purged completely when restoring the repository right after deleting it.  (updated 2019-03-19)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Thu, 12 Jul 2018 16:00:34 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.14.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.14.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.13.6</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Environment variables passed to pre-receive hook scripts were not properly escaped.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: It was possible to start a shell from the network configuration settings screen available on a virtual console.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Filtering of parameters in log files was changed from a blacklist of fields to a whitelist. This ensures that less values are logged and in the future no values are accidentally logged.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: The body of API requests containing sensitive data was written to log files on the appliance. The request body is now only logged for debugging purposes and sensitive data is scrubbed before being logged.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Parallel uploads of the same Git LFS object could fail but still be reported as successful.&lt;/li&gt;
&lt;li&gt;A hotpatch could be applied to the appliance whilst a configuration run was in progress. This could lead to inconsistencies and unexpected behaviour.&lt;/li&gt;
&lt;li&gt;Jupyter notebooks added to a Gist would fail to render on appliances with subdomain isolation disabled.&lt;/li&gt;
&lt;li&gt;A pull request created via the API could be assigned an ID of &lt;code&gt;0&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The &lt;em&gt;LDAP users&lt;/em&gt; page at &lt;code&gt;/stafftools/users/ldap&lt;/code&gt; had layout and accessibility issues.&lt;/li&gt;
&lt;li&gt;The &lt;em&gt;Fork&lt;/em&gt; button was enabled for repositories in cases where a repository could not be forked anywhere.&lt;/li&gt;
&lt;li&gt;Including the port in the &lt;code&gt;Host&lt;/code&gt; header when requesting a Pages site would return a 404 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Pull request review comments are missing from an import with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.  (updated 2018-10-31)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 10 Jul 2018 16:00:33 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.13.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.13.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.14</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Environment variables passed to pre-receive hook scripts were not properly escaped.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: It was possible to start a shell from the network configuration settings screen available on a virtual console.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Filtering of parameters in log files was changed from a blacklist of fields to a whitelist. This ensures that less values are logged and in the future no values are accidentally logged.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: The body of API requests containing sensitive data was written to log files on the appliance. The request body is now only logged for debugging purposes and sensitive data is scrubbed before being logged.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Parallel uploads of the same Git LFS object could fail but still be reported as successful.&lt;/li&gt;
&lt;li&gt;A hotpatch could be applied to the appliance whilst a configuration run was in progress. This could lead to inconsistencies and unexpected behaviour.&lt;/li&gt;
&lt;li&gt;The &lt;em&gt;LDAP users&lt;/em&gt; page at &lt;code&gt;/stafftools/users/ldap&lt;/code&gt; had layout and accessibility issues.&lt;/li&gt;
&lt;li&gt;The &lt;em&gt;Fork&lt;/em&gt; button was enabled for repositories in cases where a repository could not be forked anywhere.&lt;/li&gt;
&lt;li&gt;Including the port in the &lt;code&gt;Host&lt;/code&gt; header when requesting a Pages site would return a 404 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;GitHub Enterprise clustering can not be configured without https.&lt;/del&gt;&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;Git LFS, release and issue assets, user profile images, webhooks, or Subversion access may be unavailable if an appliance is restarted after applying the 2.12.5 or greater hotpatch—if this occurs, please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us&quot;&gt;Enterprise Support&lt;/a&gt; for assistance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;HTTPS is now a requirement of GitHub Enterprise clustering. (updated 2018-08-13)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 10 Jul 2018 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.20</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Environment variables passed to pre-receive hook scripts were not properly escaped.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: It was possible to start a shell from the network configuration settings screen available on a virtual console.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Filtering of parameters in log files was changed from a blacklist of fields to a whitelist. This ensures that less values are logged and in the future no values are accidentally logged.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: The body of API requests containing sensitive data was written to log files on the appliance. The request body is now only logged for debugging purposes and sensitive data is scrubbed before being logged.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Parallel uploads of the same Git LFS object could fail but still be reported as successful.&lt;/li&gt;
&lt;li&gt;A hotpatch could be applied to the appliance whilst a configuration run was in progress. This could lead to inconsistencies and unexpected behaviour.&lt;/li&gt;
&lt;li&gt;The &lt;em&gt;LDAP users&lt;/em&gt; page at &lt;code&gt;/stafftools/users/ldap&lt;/code&gt; had layout and accessibility issues.&lt;/li&gt;
&lt;li&gt;The &lt;em&gt;Fork&lt;/em&gt; button was enabled for repositories in cases where a repository could not be forked anywhere.&lt;/li&gt;
&lt;li&gt;Including the port in the &lt;code&gt;Host&lt;/code&gt; header when requesting a Pages site would return a 404 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;GitHub Enterprise clustering can not be configured without https.&lt;/del&gt;&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Failing to delete associated metadata when deleting a search index was resolved in 2.11.12. (updated 2018-08-06)&lt;/li&gt;
&lt;li&gt;HTTPS is now a requirement of GitHub Enterprise clustering. (updated 2018-08-13)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 10 Jul 2018 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.13.5</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Pre-receive hooks would fail if the pre-receive environment lacked a &lt;code&gt;/etc&lt;/code&gt; directory.&lt;/li&gt;
&lt;li&gt;Active git processes were not displayed on the Management Console&#39;s maintenance page&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Pull request review comments are missing from an import with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.  (updated 2018-10-31)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 19 Jun 2018 16:00:33 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.13.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.13.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.13</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Pre-receive hooks would fail if the pre-receive environment lacked a &lt;code&gt;/etc&lt;/code&gt; directory.&lt;/li&gt;
&lt;li&gt;Active git processes were not displayed on the Management Console&#39;s maintenance page&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;Git LFS, release and issue assets, user profile images, webhooks, or Subversion access may be unavailable if an appliance is restarted after applying the 2.12.5 or greater hotpatch—if this occurs, please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us&quot;&gt;Enterprise Support&lt;/a&gt; for assistance.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 19 Jun 2018 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.19</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Pre-receive hooks would fail if the pre-receive environment lacked a &lt;code&gt;/etc&lt;/code&gt; directory.&lt;/li&gt;
&lt;li&gt;Active git processes were not displayed on the Management Console&#39;s maintenance page&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 19 Jun 2018 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.13.4</title>
					<description>&lt;h2&gt;Git client vulnerabilities&lt;/h2&gt;
&lt;p&gt;A number of critical Git security vulnerabilities were recently announced that affect all versions of the official Git client.&lt;/p&gt;
&lt;p&gt;We strongly recommend that you ensure that all users &lt;a href=&quot;https://git-scm.com/downloads&quot;&gt;update their Git clients&lt;/a&gt;, in addition to upgrading to this GitHub Enterprise release.&lt;/p&gt;
&lt;p&gt;More details on these vulnerabilities can be found in the &lt;a href=&quot;https://lkml.org/lkml/2018/5/29/889&quot;&gt;official announcement&lt;/a&gt;, and the associated CVEs, &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11233&quot;&gt;CVE-2018-11233&lt;/a&gt; and &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11235&quot;&gt;CVE-2018-11235&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; There was a remote code execution vulnerability that leveraged &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11235&quot;&gt;CVE-2018-11235&lt;/a&gt; during the Pages build process. The Git package has been updated to address the vulnerability in the Pages build process. This fix is also available in GitHub Enterprise &lt;a href=&quot;https://enterprise.github.com/releases/2.13.2/notes&quot;&gt;2.13.2&lt;/a&gt; and &lt;a href=&quot;https://enterprise.github.com/releases/2.13.3/notes&quot;&gt;2.13.3&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;GitHub will block pushing malicious Git submodules that could be used to exploit Git clients vulnerable to &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11235&quot;&gt;CVE-2018-11235&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;User passwords could end up being logged in plain text in the audit log.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Elasticsearch metrics in the management console metrics dashboards have been fixed.&lt;/li&gt;
&lt;li&gt;Importing a Subversion repository that was created with an older version of Subversion would fail in specific scenarios.&lt;/li&gt;
&lt;li&gt;The GitHub Services deprecation warning contained a broken link to the deprecation announcement blog post.&lt;/li&gt;
&lt;li&gt;Increased performance of pull request reviewer selection box.&lt;/li&gt;
&lt;li&gt;Performance of issues and pull requests has been improved by ensuring data is properly cached.&lt;/li&gt;
&lt;li&gt;Enable marking one search index as primary when there are multiple primary Elasticsearch indexes listed.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Pull request review comments are missing from an import with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.  (updated 2018-10-31)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 05 Jun 2018 16:00:33 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.13.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.13.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.12</title>
					<description>&lt;h2&gt;Git client vulnerabilities&lt;/h2&gt;
&lt;p&gt;A number of critical Git security vulnerabilities were recently announced that affect all versions of the official Git client.&lt;/p&gt;
&lt;p&gt;We strongly recommend that you ensure that all users &lt;a href=&quot;https://git-scm.com/downloads&quot;&gt;update their Git clients&lt;/a&gt;, in addition to upgrading to this GitHub Enterprise release.&lt;/p&gt;
&lt;p&gt;More details on these vulnerabilities can be found in the &lt;a href=&quot;https://lkml.org/lkml/2018/5/29/889&quot;&gt;official announcement&lt;/a&gt;, and the associated CVEs, &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11233&quot;&gt;CVE-2018-11233&lt;/a&gt; and &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11235&quot;&gt;CVE-2018-11235&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; There was a remote code execution vulnerability that leveraged &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11235&quot;&gt;CVE-2018-11235&lt;/a&gt; during the Pages build process. The Git package has been updated to address the vulnerability in the Pages build process. This fix is also available in GitHub Enterprise &lt;a href=&quot;https://enterprise.github.com/releases/2.12.10/notes&quot;&gt;2.12.10&lt;/a&gt; and &lt;a href=&quot;https://enterprise.github.com/releases/2.12.11/notes&quot;&gt;2.12.11&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;GitHub will block pushing malicious Git submodules that could be used to exploit Git clients vulnerable to &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11235&quot;&gt;CVE-2018-11235&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Elasticsearch metrics in the management console metrics dashboards have been fixed.&lt;/li&gt;
&lt;li&gt;Enable marking one search index as primary when there are multiple primary Elasticsearch indexes listed.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;Git LFS, release and issue assets, user profile images, webhooks, or Subversion access may be unavailable if an appliance is restarted after applying the 2.12.5 or greater hotpatch—if this occurs, please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us&quot;&gt;Enterprise Support&lt;/a&gt; for assistance.&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 05 Jun 2018 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.18</title>
					<description>&lt;h2&gt;Git client vulnerabilities&lt;/h2&gt;
&lt;p&gt;A number of critical Git security vulnerabilities were recently announced that affect all versions of the official Git client.&lt;/p&gt;
&lt;p&gt;We strongly recommend that you ensure that all users &lt;a href=&quot;https://git-scm.com/downloads&quot;&gt;update their Git clients&lt;/a&gt;, in addition to upgrading to this GitHub Enterprise release.&lt;/p&gt;
&lt;p&gt;More details on these vulnerabilities can be found in the &lt;a href=&quot;https://lkml.org/lkml/2018/5/29/889&quot;&gt;official announcement&lt;/a&gt;, and the associated CVEs, &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11233&quot;&gt;CVE-2018-11233&lt;/a&gt; and &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11235&quot;&gt;CVE-2018-11235&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; There was a remote code execution vulnerability that leveraged &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11235&quot;&gt;CVE-2018-11235&lt;/a&gt; during the Pages build process. The Git package has been updated to address the vulnerability in the Pages build process. This fix is also available in GitHub Enterprise &lt;a href=&quot;https://enterprise.github.com/releases/2.11.16/notes&quot;&gt;2.11.16&lt;/a&gt; and &lt;a href=&quot;https://enterprise.github.com/releases/2.11.17/notes&quot;&gt;2.11.17&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;GitHub will block pushing malicious Git submodules that could be used to exploit Git clients vulnerable to &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11235&quot;&gt;CVE-2018-11235&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Elasticsearch metrics in the management console metrics dashboards have been fixed.&lt;/li&gt;
&lt;li&gt;Enable marking one search index as primary when there are multiple primary Elasticsearch indexes listed.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 05 Jun 2018 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.24</title>
					<description>&lt;h2&gt;Git client vulnerabilities&lt;/h2&gt;
&lt;p&gt;A number of critical Git security vulnerabilities were recently announced that affect all versions of the official Git client.&lt;/p&gt;
&lt;p&gt;We strongly recommend that you ensure that all users &lt;a href=&quot;https://git-scm.com/downloads&quot;&gt;update their Git clients&lt;/a&gt;, in addition to upgrading to this GitHub Enterprise release.&lt;/p&gt;
&lt;p&gt;More details on these vulnerabilities can be found in the &lt;a href=&quot;https://lkml.org/lkml/2018/5/29/889&quot;&gt;official announcement&lt;/a&gt;, and the associated CVEs, &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11233&quot;&gt;CVE-2018-11233&lt;/a&gt; and &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11235&quot;&gt;CVE-2018-11235&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; There was a remote code execution vulnerability that leveraged &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11235&quot;&gt;CVE-2018-11235&lt;/a&gt; during the Pages build process. The Git package has been updated to address the vulnerability in the Pages build process. This fix is also available in GitHub Enterprise &lt;a href=&quot;https://enterprise.github.com/releases/2.10.22/notes&quot;&gt;2.10.22&lt;/a&gt; and &lt;a href=&quot;https://enterprise.github.com/releases/2.10.23/notes&quot;&gt;2.10.23&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;GitHub will block pushing malicious Git submodules that could be used to exploit Git clients vulnerable to &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11235&quot;&gt;CVE-2018-11235&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Enable marking one search index as primary when there are multiple primary Elasticsearch indexes listed.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise 2.10&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.10 is now deprecated as of June 5, 2018.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 05 Jun 2018 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.24</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.24</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.13.3</title>
					<description>&lt;h2&gt;Git client vulnerabilities&lt;/h2&gt;
&lt;p&gt;A number of critical Git security vulnerabilities were recently announced that affect all versions of the official Git client.&lt;/p&gt;
&lt;p&gt;We strongly recommend that you ensure that all users &lt;a href=&quot;https://git-scm.com/downloads&quot;&gt;update their Git clients&lt;/a&gt;, in addition to upgrading to this GitHub Enterprise release.&lt;/p&gt;
&lt;p&gt;More details on these vulnerabilities can be found in the &lt;a href=&quot;https://lkml.org/lkml/2018/5/29/889&quot;&gt;official announcement&lt;/a&gt;, and the associated CVEs, &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11233&quot;&gt;CVE-2018-11233&lt;/a&gt; and &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11235&quot;&gt;CVE-2018-11235&lt;/a&gt;. (updated 2018-05-30)&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; There was a remote code execution vulnerability that leveraged &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11235&quot;&gt;CVE-2018-11235&lt;/a&gt; during the Pages build process. The Git package has been updated to address the vulnerability in the Pages build process. This fix is also available in &lt;a href=&quot;https://enterprise.github.com/releases/2.13.2/notes&quot;&gt;GitHub Enterprise 2.13.2&lt;/a&gt;. (updated 2018-05-30)&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Management Console contained broken links to help documentation.&lt;/li&gt;
&lt;li&gt;Maintenance mode could be unset while a configuration run was in progress.&lt;/li&gt;
&lt;li&gt;Viewing a team discussion showed a &amp;quot;You can&#39;t perform that action at this time&amp;quot; error at the top of the page.&lt;/li&gt;
&lt;li&gt;A background job that purges deleted storage objects could cause backups to fail if run whilst a backup was in progress.&lt;/li&gt;
&lt;li&gt;Restoring a backup to an unconfigured GitHub Enterprise appliance could fail to restore Pages data with a &amp;quot;could not find 3 online voting fileservers&amp;quot; error.&lt;/li&gt;
&lt;li&gt;Updating branch protections from the API ignored the restricted teams parameter.&lt;/li&gt;
&lt;li&gt;Exporting a repository didn&#39;t include project boards.&lt;/li&gt;
&lt;li&gt;Performing bulk actions, like labelling, on pull requests would silently fail if issues were disabled.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Add a notice for the upcoming &lt;a href=&quot;https://developer.github.com/changes/2018-04-25-github-services-deprecation/&quot;&gt;GitHub services deprecation&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Admins can see which repositories are using GitHub Services with &lt;code&gt;ghe-legacy-github-services-report&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Improve Git rate limit configuration to prevent over-limiting of Git operations.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Pull request review comments are missing from an import with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.  (updated 2018-10-31)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 22 May 2018 16:00:33 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.13.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.13.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.11</title>
					<description>&lt;h2&gt;Git client vulnerabilities&lt;/h2&gt;
&lt;p&gt;A number of critical Git security vulnerabilities were recently announced that affect all versions of the official Git client.&lt;/p&gt;
&lt;p&gt;We strongly recommend that you ensure that all users &lt;a href=&quot;https://git-scm.com/downloads&quot;&gt;update their Git clients&lt;/a&gt;, in addition to upgrading to this GitHub Enterprise release.&lt;/p&gt;
&lt;p&gt;More details on these vulnerabilities can be found in the &lt;a href=&quot;https://lkml.org/lkml/2018/5/29/889&quot;&gt;official announcement&lt;/a&gt;, and the associated CVEs, &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11233&quot;&gt;CVE-2018-11233&lt;/a&gt; and &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11235&quot;&gt;CVE-2018-11235&lt;/a&gt;. (updated 2018-05-30)&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; There was a remote code execution vulnerability that leveraged &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11235&quot;&gt;CVE-2018-11235&lt;/a&gt; during the Pages build process. The Git package has been updated to address the vulnerability in the Pages build process. This fix is also available in &lt;a href=&quot;https://enterprise.github.com/releases/2.12.10/notes&quot;&gt;GitHub Enterprise 2.12.10&lt;/a&gt;. (updated 2018-05-30)&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Maintenance mode could be unset while a configuration run was in progress.&lt;/li&gt;
&lt;li&gt;A background job that purges deleted storage objects could cause backups to fail if run whilst a backup was in progress.&lt;/li&gt;
&lt;li&gt;Restoring a backup to an unconfigured GitHub Enterprise appliance could fail to restore Pages data with a &amp;quot;could not find 3 online voting fileservers&amp;quot; error.&lt;/li&gt;
&lt;li&gt;Updating branch protections from the API ignored the restricted teams parameter.&lt;/li&gt;
&lt;li&gt;Viewing a pull request reviewed by a member of a team that has been deleted could fail with a &amp;quot;500 Internal Server Error&amp;quot;.&lt;/li&gt;
&lt;li&gt;Exporting a repository didn&#39;t include project boards.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;Git LFS, release and issue assets, user profile images, webhooks, or Subversion access may be unavailable if an appliance is restarted after applying the 2.12.5 or greater hotpatch—if this occurs, please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us&quot;&gt;Enterprise Support&lt;/a&gt; for assistance.&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 22 May 2018 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.17</title>
					<description>&lt;h2&gt;Git client vulnerabilities&lt;/h2&gt;
&lt;p&gt;A number of critical Git security vulnerabilities were recently announced that affect all versions of the official Git client.&lt;/p&gt;
&lt;p&gt;We strongly recommend that you ensure that all users &lt;a href=&quot;https://git-scm.com/downloads&quot;&gt;update their Git clients&lt;/a&gt;, in addition to upgrading to this GitHub Enterprise release.&lt;/p&gt;
&lt;p&gt;More details on these vulnerabilities can be found in the &lt;a href=&quot;https://lkml.org/lkml/2018/5/29/889&quot;&gt;official announcement&lt;/a&gt;, and the associated CVEs, &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11233&quot;&gt;CVE-2018-11233&lt;/a&gt; and &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11235&quot;&gt;CVE-2018-11235&lt;/a&gt;. (updated 2018-05-30)&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; There was a remote code execution vulnerability that leveraged &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11235&quot;&gt;CVE-2018-11235&lt;/a&gt; during the Pages build process. The Git package has been updated to address the vulnerability in the Pages build process. This fix is also available in &lt;a href=&quot;https://enterprise.github.com/releases/2.11.16/notes&quot;&gt;GitHub Enterprise 2.11.16&lt;/a&gt;. (updated 2018-05-30)&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Maintenance mode could be unset while a configuration run was in progress.&lt;/li&gt;
&lt;li&gt;A background job that purges deleted storage objects could cause backups to fail if run whilst a backup was in progress.&lt;/li&gt;
&lt;li&gt;Restoring a backup to an unconfigured GitHub Enterprise appliance could fail to restore Pages data with a &amp;quot;could not find 3 online voting fileservers&amp;quot; error.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 22 May 2018 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.23</title>
					<description>&lt;h2&gt;Git client vulnerabilities&lt;/h2&gt;
&lt;p&gt;A number of critical Git security vulnerabilities were recently announced that affect all versions of the official Git client.&lt;/p&gt;
&lt;p&gt;We strongly recommend that you ensure that all users &lt;a href=&quot;https://git-scm.com/downloads&quot;&gt;update their Git clients&lt;/a&gt;, in addition to upgrading to this GitHub Enterprise release.&lt;/p&gt;
&lt;p&gt;More details on these vulnerabilities can be found in the &lt;a href=&quot;https://lkml.org/lkml/2018/5/29/889&quot;&gt;official announcement&lt;/a&gt;, and the associated CVEs, &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11233&quot;&gt;CVE-2018-11233&lt;/a&gt; and &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11235&quot;&gt;CVE-2018-11235&lt;/a&gt;. (updated 2018-05-30)&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; There was a remote code execution vulnerability that leveraged &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11235&quot;&gt;CVE-2018-11235&lt;/a&gt; during the Pages build process. The Git package has been updated to address the vulnerability in the Pages build process. This fix is also available in &lt;a href=&quot;https://enterprise.github.com/releases/2.10.22/notes&quot;&gt;GitHub Enterprise 2.10.22&lt;/a&gt;. (updated 2018-05-30)&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Maintenance mode could be unset while a configuration run was in progress.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 22 May 2018 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.23</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.23</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.13.2</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; There was a remote code execution vulnerability that leveraged &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11235&quot;&gt;CVE-2018-11235&lt;/a&gt; during the Pages build process. The Git package has been updated to address the vulnerability in the Pages build process. (updated 2018-05-30)&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;GitHub App user-to-server tokens generated for site-admins can access the internal GraphQL schema.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;When booted into recovery mode, using &lt;code&gt;ghe-set-password&lt;/code&gt; to reset the Management Console password would fail unless the &lt;code&gt;haproxy-internal-proxy&lt;/code&gt; service was manually started.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;collectd.log&lt;/code&gt; contained superfluous Elasticsearch plugin warnings.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-migrator&lt;/code&gt; failed to import a GitHub.com migration archive when a pull request&#39;s requested reviewer was not a member of the organization.&lt;/li&gt;
&lt;li&gt;Commits pushed to a closed pull request were not included when fetching the pull request&#39;s tracking branch.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Our unified Git proxy, babeld, now uses the BoringSSL cryptographic library to avoid lock contention issues in Git over SSH connections, which may have been encountered on large and busy appliances.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Pull request review comments are missing from an import with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;We incorrectly show a warning message, &amp;quot;You can&#39;t perform this action at this time&amp;quot;, on team discussion pages. The message can be safely ignored.&lt;/li&gt;
&lt;li&gt;On a repository that&#39;s been locked for migration using &lt;code&gt;ghe-migrator&lt;/code&gt;, project boards are not exported.&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.  (updated 2018-10-31)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 08 May 2018 16:00:33 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.13.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.13.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.10</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; There was a remote code execution vulnerability that leveraged &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11235&quot;&gt;CVE-2018-11235&lt;/a&gt; during the Pages build process. The Git package has been updated to address the vulnerability in the Pages build process. (updated 2018-05-30)&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;When booted into recovery mode, using &lt;code&gt;ghe-set-password&lt;/code&gt; to reset the Management Console password would fail unless the &lt;code&gt;haproxy-internal-proxy&lt;/code&gt; service was manually started.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;collectd.log&lt;/code&gt; contained superfluous Elasticsearch plugin warnings.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-migrator&lt;/code&gt; failed to import a GitHub.com migration archive when a pull request&#39;s requested reviewer was not a member of the organization.&lt;/li&gt;
&lt;li&gt;Commits pushed to a closed pull request were not included when fetching the pull request&#39;s tracking branch.&lt;/li&gt;
&lt;li&gt;API returned an incorrect response code when adding organization team members to a repository.&lt;/li&gt;
&lt;li&gt;The repository collaborator API ignored the &lt;code&gt;permission&lt;/code&gt; parameter and always invited users with &lt;code&gt;push&lt;/code&gt; permissions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Our unified Git proxy, babeld, now uses the BoringSSL cryptographic library to avoid lock contention issues in Git over SSH connections, which may have been encountered on large and busy appliances.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;Git LFS, release and issue assets, user profile images, webhooks, or Subversion access may be unavailable if an appliance is restarted after applying the 2.12.5 or greater hotpatch—if this occurs, please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us&quot;&gt;Enterprise Support&lt;/a&gt; for assistance.&lt;/li&gt;
&lt;li&gt;On a repository that&#39;s been locked for migration using &lt;code&gt;ghe-migrator&lt;/code&gt;, project boards are not exported.&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 08 May 2018 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.16</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; There was a remote code execution vulnerability that leveraged &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11235&quot;&gt;CVE-2018-11235&lt;/a&gt; during the Pages build process. The Git package has been updated to address the vulnerability in the Pages build process. (updated 2018-05-30)&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;collectd.log&lt;/code&gt; contained superfluous Elasticsearch plugin warnings.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-migrator&lt;/code&gt; failed to import a GitHub.com migration archive when a pull request&#39;s requested reviewer was not a member of the organization.&lt;/li&gt;
&lt;li&gt;Commits pushed to a closed pull request were not included when fetching the pull request&#39;s tracking branch.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 08 May 2018 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.22</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; There was a remote code execution vulnerability that leveraged &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2018-11235&quot;&gt;CVE-2018-11235&lt;/a&gt; during the Pages build process. The Git package has been updated to address the vulnerability in the Pages build process. (updated 2018-05-30)&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 08 May 2018 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.13.1</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;LOW: Changed how certain types of exceptions are handled to prevent sensitive user data from being written to log files.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Resetting the self signed certificate, either manually or as a result of a hostname or IP change, would fail.&lt;/li&gt;
&lt;li&gt;Monitoring graphs in the management console can be unavailable when a metrics node is down in a cluster configuration.&lt;/li&gt;
&lt;li&gt;Updates the support of automatically-managed TLS certificates from Let&#39;s Encrypt to request a single-domain certificate when Subdomain Isolation is disabled, and a multi-domain (SAN) certificate when Subdomain Isolation is enabled.  A GitHub Enterprise installation will no longer require a wildcard DNS record to use this feature when Subdomain Isolation is disabled.&lt;/li&gt;
&lt;li&gt;Corrects calculation of hour and day of month for the crontab entry supporting renewals of automatically-managed ACME (Let&#39;s Encrypt) TLS certificates.&lt;/li&gt;
&lt;li&gt;Users may be unable to sign in to GitHub Enterprise via a private GitHub Pages site if subdomain isolation is enabled.&lt;/li&gt;
&lt;li&gt;After upgrading to 2.13.0, users could lose access to their LDAP mapped teams when LDAP sync was enabled.&lt;/li&gt;
&lt;li&gt;The dashboard graphs at &lt;code&gt;/dashboards/overview&lt;/code&gt; were empty.&lt;/li&gt;
&lt;li&gt;Generated identicons for GitHub Apps and OAuth Apps responded with a &lt;code&gt;404 Not Found&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;LDAP sync could suspend user accounts &lt;a href=&quot;https://docs.github.com/enterprise/2.13/admin/guides/user-management/allowing-built-in-authentication-for-users-outside-your-identity-provider/&quot;&gt;created with built-in authentication&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Pages builds failed when TLS is disabled.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Proportional Set Size (PSS) metric has been added to &lt;code&gt;ghe-diagnostics&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Disabled redundant UDP listener in memcached.&lt;/li&gt;
&lt;li&gt;Updated ESX image guest identifier to other26xLinux64Guest, which allows provisioning 65-128 virtual CPU cores on VMWare.&lt;/li&gt;
&lt;li&gt;The footer has been updated to display current version of GitHub Enterprise.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Pull request review comments are missing from an import with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;We incorrectly show a warning message, &amp;quot;You can&#39;t perform this action at this time&amp;quot;, on team discussion pages. The message can be safely ignored. (updated 2018-04-11)&lt;/li&gt;
&lt;li&gt;On a repository that&#39;s been locked for migration using &lt;code&gt;ghe-migrator&lt;/code&gt;, project boards are not exported. (updated 2018-05-07)&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.  (updated 2018-10-31)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 10 Apr 2018 16:00:33 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.13.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.13.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.9</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;LOW: Changed how certain types of exceptions are handled to prevent sensitive user data from being written to log files.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Resetting the self signed certificate, either manually or as a result of a hostname or IP change, would fail.&lt;/li&gt;
&lt;li&gt;Duplicate object identifier (OID) entries were returned for the mounted partitions.&lt;/li&gt;
&lt;li&gt;Updates the support of automatically-managed TLS certificates from Let&#39;s Encrypt to request a single-domain certificate when Subdomain Isolation is disabled, and a multi-domain (SAN) certificate when Subdomain Isolation is enabled.  A GitHub Enterprise installation will no longer require a wildcard DNS record to use this feature when Subdomain Isolation is disabled.&lt;/li&gt;
&lt;li&gt;Corrects calculation of hour and day of month for the crontab entry supporting renewals of automatically-managed ACME (Let&#39;s Encrypt) TLS certificates.&lt;/li&gt;
&lt;li&gt;Users may be unable to sign in to GitHub Enterprise via a private GitHub Pages site if subdomain isolation is enabled.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-migrator&lt;/code&gt; failed when the user was not a member of the organization at the time of export.&lt;/li&gt;
&lt;li&gt;Pages builds failed when TLS is disabled.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Disabled redundant UDP listener in memcached.&lt;/li&gt;
&lt;li&gt;The appliance&#39;s UUID has been added to the replication overview page.&lt;/li&gt;
&lt;li&gt;Updated ESX image guest identifier to other26xLinux64Guest, which allows provisioning 65-128 virtual CPU cores on VMWare.&lt;/li&gt;
&lt;li&gt;The footer has been updated to display current version of GitHub Enterprise.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;Git LFS, release and issue assets, user profile images, webhooks, or Subversion access may be unavailable if an appliance is restarted after applying the 2.12.5 or greater hotpatch—if this occurs, please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us&quot;&gt;Enterprise Support&lt;/a&gt; for assistance.&lt;/li&gt;
&lt;li&gt;On a repository that&#39;s been locked for migration using &lt;code&gt;ghe-migrator&lt;/code&gt;, project boards are not exported. (updated 2018-05-07)&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 10 Apr 2018 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.15</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;LOW: Changed how certain types of exceptions are handled to prevent sensitive user data from being written to log files.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Duplicate object identifier (OID) entries were returned for the mounted partitions.&lt;/li&gt;
&lt;li&gt;Users may be unable to sign in to GitHub Enterprise via a private GitHub Pages site if subdomain isolation is enabled.&lt;/li&gt;
&lt;li&gt;Reviewers of a pull request were not correctly mapped when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-migrator&lt;/code&gt; failed when the user was not a member of the organization at the time of export.&lt;/li&gt;
&lt;li&gt;Pages builds failed when TLS is disabled.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Disabled redundant UDP listener in memcached.&lt;/li&gt;
&lt;li&gt;The appliance&#39;s UUID has been added to the replication overview page.&lt;/li&gt;
&lt;li&gt;Updated ESX image guest identifier to other26xLinux64Guest, which allows provisioning 65-128 virtual CPU cores on VMWare.&lt;/li&gt;
&lt;li&gt;The footer has been updated to display current version of GitHub Enterprise.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 10 Apr 2018 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.21</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;LOW: Changed how certain types of exceptions are handled to prevent sensitive user data from being written to log files.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Duplicate object identifier (OID) entries were returned for the mounted partitions.&lt;/li&gt;
&lt;li&gt;Users may be unable to sign in to GitHub Enterprise via a private GitHub Pages site if subdomain isolation is enabled.&lt;/li&gt;
&lt;li&gt;Reviewers of a pull request were not correctly mapped when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Pages builds failed when TLS is disabled.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Disabled redundant UDP listener in memcached.&lt;/li&gt;
&lt;li&gt;Updated ESX image guest identifier to other26xLinux64Guest, which allows provisioning 65-128 virtual CPU cores on VMWare.&lt;/li&gt;
&lt;li&gt;The footer has been updated to display current version of GitHub Enterprise.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 10 Apr 2018 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.13.0</title>
					<description>&lt;h2&gt;Features&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.13/user/articles/about-team-discussions/&quot;&gt;Use team discussions&lt;/a&gt; as a static space to have conversations that span across projects or repositories.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.13/user/articles/creating-a-commit-with-multiple-authors/&quot;&gt;Attribute a commit to multiple authors&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.13/admin/guides/user-management/allowing-built-in-authentication-for-users-outside-your-identity-provider/&quot;&gt;Allow built-in authentication&lt;/a&gt; for users who aren&#39;t authenticated by your identity provider.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.13/admin/guides/developer-workflow/creating-a-pre-receive-hook-script/&quot;&gt;Use &lt;code&gt;git --push_option&lt;/code&gt;&lt;/a&gt; to transmit strings based to the server on to their pre-receive hooks.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.13/admin/guides/migrations/exporting-the-github-enterprise-source-repositories&quot;&gt;Export multiple repositories at once&lt;/a&gt; using the &lt;code&gt;-i&lt;/code&gt; flag with the &lt;code&gt;ghe-migrator&lt;/code&gt; command-line utilty.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.13/admin/guides/user-management/configuring-email-for-notifications/&quot;&gt;Choose to discard emails&lt;/a&gt; addressed to the no-reply email address.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.13/admin/guides/clustering/upgrading-a-cluster&quot;&gt;Upgrade a GitHub Enterprise clustering environment&lt;/a&gt; using a hotpatch.&lt;/li&gt;
&lt;li&gt;Track the health of your appliance using Grafana.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.github.com/enterprise/2.13/apps/&quot;&gt;Create&lt;/a&gt; and &lt;a href=&quot;https://docs.github.com/enterprise/2.13/user/articles/reviewing-your-organization-s-installed-integrations/&quot;&gt;manage&lt;/a&gt; GitHub Apps.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.13/user/articles/about-required-commit-signing/&quot;&gt;Require commit signing&lt;/a&gt; in a repository so that local commits can&#39;t be pushed to the branch if they aren&#39;t signed with a verified GPG key.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.13/user/articles/locking-conversations/&quot;&gt;Specify a publicly visible reason&lt;/a&gt; for locking a conversation.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.13/user/articles/about-project-boards/&quot;&gt;Create templates&lt;/a&gt; to quickly set up project boards.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.13/user/articles/tracking-progress-on-your-project-board/&quot;&gt;Track progress&lt;/a&gt; on project boards.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.13/user/articles/about-project-boards/&quot;&gt;Create a reference card&lt;/a&gt; for another project board.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.13/user/articles/searching-topics&quot;&gt;Search for a topic&lt;/a&gt; and view the repositories using that topic.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.13/user/articles/editing-a-label/&quot;&gt;Add label descriptions&lt;/a&gt;, search labels, add emoji in label names, and preview a label when creating or editing it.&lt;/li&gt;
&lt;li&gt;View a merge direction indicator for the base and compare branches.&lt;/li&gt;
&lt;li&gt;Upload a team avatar.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.13/user/articles/finding-changed-methods-and-functions-in-a-pull-request/&quot;&gt;PHP methods and functions within pull requests&lt;/a&gt; now appear in the table of contents.&lt;/li&gt;
&lt;li&gt;View pending collaborators from &lt;code&gt;/stafftools&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Lock an issue thread from &lt;code&gt;/stafftools&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Support Go&#39;s remote import path when private mode is configured.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;The &lt;a href=&quot;https://githubengineering.com/crypto-removal-notice/&quot;&gt;&lt;code&gt;diffie-hellman-group1-sha1&lt;/code&gt; and &lt;code&gt;diffie-hellman-group14-sha1&lt;/code&gt; algorithms have been deprecated and disallowed for &lt;code&gt;git&lt;/code&gt; SSH connections&lt;/a&gt;. (updated 2018-04-17)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;After a review request has been removed, users could be missing from the pull request reviwer&#39;s list.&lt;/li&gt;
&lt;li&gt;The OAuth authorization page did not list the requested organization access for outside collaborators.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;milestone:*&lt;/code&gt;, &lt;code&gt;milestone:any&lt;/code&gt;, and &lt;code&gt;milestone:none&lt;/code&gt; search queries were not returning the correct issue or pull requests.&lt;/li&gt;
&lt;li&gt;From &lt;code&gt;/stafftools&lt;/code&gt;, administrators could incorrectly delete user accounts when they were the sole owner of a repository.&lt;/li&gt;
&lt;li&gt;API search results with an out of bound page query returned an inaccurate &lt;code&gt;prev&lt;/code&gt; reference.&lt;/li&gt;
&lt;li&gt;Organization projects were redundantly imported creating duplicate projects.&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.github.com/enterprise/2.13/v3/enterprise-admin/&quot;&gt;Enterprise Administration API resources&lt;/a&gt; require the &lt;code&gt;site_admin&lt;/code&gt; scope when authenticating with an access token.&lt;/li&gt;
&lt;li&gt;An e-mail notification will be sent to users after an addition or removal of an e-mail address.&lt;/li&gt;
&lt;li&gt;An e-mail notification will be sent to users during a two-factor authentication lockout.&lt;/li&gt;
&lt;li&gt;An e-mail notification will be sent to users when a two-factor recovery code is used.&lt;/li&gt;
&lt;li&gt;The original project creator will retain administrative access when transferring owner from &lt;code&gt;/stafftools&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Emojis are supported on label names.&lt;/li&gt;
&lt;li&gt;Label names are required to be 50 characters or fewer. Existing labels will be unchanged but must adhere to the character limit to be updated.&lt;/li&gt;
&lt;li&gt;Saved replies character limit has been increased to 100 from 50.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.13/admin/articles/command-line-utilities/#ghe-org-admin-promote&quot;&gt;&lt;code&gt;ghe-org-admin-promote&lt;/code&gt;&lt;/a&gt; requires an &lt;code&gt;-a&lt;/code&gt; flag to give admin privileges to all site administrators in all organizations.&lt;/li&gt;
&lt;li&gt;New &lt;a href=&quot;https://developer.github.com/enterprise/2.13/v3/&quot;&gt;REST API&lt;/a&gt; resources have been added.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.github.com/enterprise/2.13/v4/&quot;&gt;GraphQL API&lt;/a&gt; schema has been updated.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Backups and Disaster Recovery&lt;/h2&gt;
&lt;p&gt;GitHub Enterprise 2.13 requires at least &lt;a href=&quot;https://github.com/github/backup-utils&quot;&gt;GitHub Enterprise Backup Utilities&lt;/a&gt; 2.13.0 for &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/backups-and-disaster-recovery/&quot;&gt;Backups and Disaster Recovery&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Starting with Backup Utilities 2.13.0, version support is inline with that of the &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/about-upgrade-requirements/&quot;&gt;GitHub Enterprise upgrade requirements&lt;/a&gt; and as such, support is limited to three versions of GitHub Enterprise: the version that corresponds with the version of Backup Utilities, and the two releases prior to it.&lt;/p&gt;
&lt;p&gt;For example, Backup Utilities 2.13.0 can be used to backup and restore all patch releases from 2.11.0 to the latest patch release of GitHub Enterprise 2.13. Backup utilities 2.14.0 will be released when GitHub Enterprise 2.14.0 is released and will then be used to backup all releases of GitHub Enterprise from 2.12.0 to the latest patch release of GitHub Enterprise 2.14.&lt;/p&gt;
&lt;p&gt;Backup Utilities 2.11.4 and earlier offer support for GitHub Enterprise 2.10 and earlier releases.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of Internet Explorer 11 support&lt;/h2&gt;
&lt;p&gt;Support for Internet Explorer 11 will be deprecated on September 13, 2018. There will be no changes in site functionality, but a warning banner will be displayed to Internet Explorer 11 users.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of VMware ESX 5.5 support&lt;/h2&gt;
&lt;p&gt;Support for &lt;a href=&quot;https://www.vmware.com/content/dam/digitalmarketing/vmware/en/pdf/support/product-lifecycle-matrix.pdf&quot;&gt;VMware ESX 5.5 will be deprecated on September 19, 2018&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.10&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.10 will be deprecated as of June 5, 2018.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.13/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Pull request review comments are missing from an import with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;After upgrading to 2.13.0, users can lose access to their LDAP mapped teams when LDAP sync is enabled. Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us&quot;&gt;Enterprise Support&lt;/a&gt; to manually workaround this issue. (updated 2018-03-28)&lt;/li&gt;
&lt;li&gt;Pages builds fail when TLS is disabled. (updated 2018-04-03)&lt;/li&gt;
&lt;li&gt;We incorrectly show a warning message, &amp;quot;You can&#39;t perform this action at this time&amp;quot;, on team discussion pages. The message can be safely ignored. (updated 2018-04-11)&lt;/li&gt;
&lt;li&gt;On a repository that&#39;s been locked for migration using &lt;code&gt;ghe-migrator&lt;/code&gt;, project boards are not exported. (updated 2018-05-07)&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;li&gt;The import of protected branches with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of the protected branch no longer exists on the source instance.  (updated 2018-10-31)&lt;/li&gt;
&lt;li&gt;The import of project boards with &lt;code&gt;ghe-migrator&lt;/code&gt; fails when the creator of a card on the board no longer exists on the source instance.  (updated 2018-11-21)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 27 Mar 2018 16:00:33 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.13.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.13.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.8</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;LOW: It was identified internally that the existence of private repositories could be determined due to the differing error messages of some REST API endpoints. These error messages have been updated to be consistent regardless of a user’s authorization to the repository. No information except for the existence of a private repository would have been exposed due to this issue.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Upgrades to later feature releases were blocked if the new patch release number is lower than the current one.&lt;/li&gt;
&lt;li&gt;Wiki footer options were not shown for read-only users.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;Git LFS, release and issue assets, user profile images, webhooks, or Subversion access may be unavailable if an appliance is restarted after applying the 2.12.5 or greater hotpatch—if this occurs, please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us&quot;&gt;Enterprise Support&lt;/a&gt; for assistance.&lt;/li&gt;
&lt;li&gt;Pages builds fail when TLS is disabled. (updated 2018-04-03)&lt;/li&gt;
&lt;li&gt;On a repository that&#39;s been locked for migration using &lt;code&gt;ghe-migrator&lt;/code&gt;, project boards are not exported. (updated 2018-05-07)&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 20 Mar 2018 17:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.14</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;LOW: It was identified internally that the existence of private repositories could be determined due to the differing error messages of some REST API endpoints. These error messages have been updated to be consistent regardless of a user’s authorization to the repository. No information except for the existence of a private repository would have been exposed due to this issue.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Upgrades to later feature releases were blocked if the new patch release number is lower than the current one.&lt;/li&gt;
&lt;li&gt;Wiki footer options were not shown for read-only users.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.&lt;/li&gt;
&lt;li&gt;Pages builds fail when TLS is disabled. (updated 2018-04-03)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 20 Mar 2018 17:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.20</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;LOW: It was identified internally that the existence of private repositories could be determined due to the differing error messages of some REST API endpoints. These error messages have been updated to be consistent regardless of a user’s authorization to the repository. No information except for the existence of a private repository would have been exposed due to this issue.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Upgrades to later feature releases were blocked if the new patch release number is lower than the current one.&lt;/li&gt;
&lt;li&gt;Wiki footer options were not shown for read-only users.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Pages builds fail when TLS is disabled. (updated 2018-04-03)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 20 Mar 2018 17:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.7</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;An appliance could not be successfully deployed on Google Cloud Platform without allocating a public IP address.&lt;/li&gt;
&lt;li&gt;Snapshots taken using the Backup Utilities from a GitHub Enterprise cluster will connect to the MySQL master node to allow transfer of SQL data via a unix domain socket instead of TCP.&lt;/li&gt;
&lt;li&gt;When creating a custom pre-receive hook environment, the operation would fail if the specified URL requested redirection.&lt;/li&gt;
&lt;li&gt;Upgrades with a package from an earlier release were not prevented.&lt;/li&gt;
&lt;li&gt;Some services would fail to restart after applying a hotpatch.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;documentation_url&lt;/code&gt; field in some GraphQL API v4 responses referred to the REST API v3 documentation rather than the GraphQL API v4 documentation.&lt;/li&gt;
&lt;li&gt;Adding members via the new organization page did not display added users.&lt;/li&gt;
&lt;li&gt;Archived gists were not restored in cluster environments.&lt;/li&gt;
&lt;li&gt;The &lt;a href=&quot;https://developer.github.com/enterprise/v3/repos/contents/#get-contents&quot;&gt;Get repository contents&lt;/a&gt; API endpoint incorrectly returned a &lt;code&gt;403 Forbidden&lt;/code&gt; response for some Git LFS-tracked files.&lt;/li&gt;
&lt;li&gt;Milestones retrieved using the REST API were not sorted as documented by default.&lt;/li&gt;
&lt;li&gt;&amp;quot;You signed out in another tab or window. Reload to refresh your session&amp;quot; message was being shown to some Firefox users.&lt;/li&gt;
&lt;li&gt;Pull Request would not merge if it touches file(s) the author owns requiring reviews from code owners.&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Entries recorded in the resqued.log file weren&#39;t included when forwarding logs to an external server. Customers monitoring the github_resque tag will need to switch to github_resqued instead.&lt;/li&gt;
&lt;li&gt;Added the ability to add multiple repositories to an export at once using a text file that lists the repository URLs.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;Git LFS, release and issue assets, user profile images, webhooks, or Subversion access may be unavailable if an appliance is restarted after applying the 2.12.5 or greater hotpatch—if this occurs, please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us&quot;&gt;Enterprise Support&lt;/a&gt; for assistance. (updated 2018-03-19)&lt;/li&gt;
&lt;li&gt;Pages builds fail when TLS is disabled. (updated 2018-04-03)&lt;/li&gt;
&lt;li&gt;On a repository that&#39;s been locked for migration using &lt;code&gt;ghe-migrator&lt;/code&gt;, project boards are not exported. (updated 2018-05-07)&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 13 Mar 2018 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.13</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;An appliance could not be successfully deployed on Google Cloud Platform without allocating a public IP address.&lt;/li&gt;
&lt;li&gt;When creating a custom pre-receive hook environment, the operation would fail if the specified URL requested redirection.&lt;/li&gt;
&lt;li&gt;Upgrades with a package from an earlier release were not prevented.&lt;/li&gt;
&lt;li&gt;Some services would fail to restart after applying a hotpatch.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;documentation_url&lt;/code&gt; field in some GraphQL API v4 responses referred to the REST API v3 documentation rather than the GraphQL API v4 documentation.&lt;/li&gt;
&lt;li&gt;Archived gists were not restored in cluster environments.&lt;/li&gt;
&lt;li&gt;The &lt;a href=&quot;https://developer.github.com/enterprise/v3/repos/contents/#get-contents&quot;&gt;Get repository contents&lt;/a&gt; API endpoint incorrectly returned a &lt;code&gt;403 Forbidden&lt;/code&gt; response for some Git LFS-tracked files.&lt;/li&gt;
&lt;li&gt;Milestones retrieved using the REST API were not sorted as documented by default.&lt;/li&gt;
&lt;li&gt;&amp;quot;You signed out in another tab or window. Reload to refresh your session&amp;quot; message was being shown to some Firefox users.&lt;/li&gt;
&lt;li&gt;Pull Request would not merge if it touches file(s) the author owns requiring reviews from code owners.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Entries recorded in the resqued.log file weren&#39;t included when forwarding logs to an external server. Customers monitoring the github_resque tag will need to switch to github_resqued instead.&lt;/li&gt;
&lt;li&gt;Added the ability to add multiple repositories to an export at once using a text file that lists the repository URLs.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.  (updated 2018-02-14)&lt;/li&gt;
&lt;li&gt;Pages builds fail when TLS is disabled. (updated 2018-04-03)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 13 Mar 2018 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.19</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;An appliance could not be successfully deployed on Google Cloud Platform without allocating a public IP address.&lt;/li&gt;
&lt;li&gt;When creating a custom pre-receive hook environment, the operation would fail if the specified URL requested redirection.&lt;/li&gt;
&lt;li&gt;Upgrades with a package from an earlier release were not prevented.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;documentation_url&lt;/code&gt; field in some GraphQL API v4 responses referred to the REST API v3 documentation rather than the GraphQL API v4 documentation.&lt;/li&gt;
&lt;li&gt;The &lt;a href=&quot;https://developer.github.com/enterprise/v3/repos/contents/#get-contents&quot;&gt;Get repository contents&lt;/a&gt; API endpoint incorrectly returned a &lt;code&gt;403 Forbidden&lt;/code&gt; response for some Git LFS-tracked files.&lt;/li&gt;
&lt;li&gt;Milestones retrieved using the REST API were not sorted as documented by default.&lt;/li&gt;
&lt;li&gt;&amp;quot;You signed out in another tab or window. Reload to refresh your session&amp;quot; message was being shown to some Firefox users.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Added the ability to add multiple repositories to an export at once using a text file that lists the repository URLs.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Pages builds fail when TLS is disabled. (updated 2018-04-03)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 13 Mar 2018 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.6</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;LOW: Tokens were contained in extended support bundles when they were used in GET requests as a URL parameter.&lt;/li&gt;
&lt;li&gt;Packages were updated to their latest patch versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;RRD files used to store metrics that are no longer collected were never deleted, wasting space on the root file system.&lt;/li&gt;
&lt;li&gt;Webhook delivery could fail in a clustering environment when one of the web-server nodes was unavailable and not explicitly marked as offline.&lt;/li&gt;
&lt;li&gt;SVG files referenced using a relative path in a README were not shown.&lt;/li&gt;
&lt;li&gt;Trial CloudFormation template updated to use current version of AWS instances. As part of this update, this trial template will no longer work within the EC2 Classic network type.&lt;/li&gt;
&lt;li&gt;Failed to upgrade a replica to the same version on a newly partitioned root disk.&lt;/li&gt;
&lt;li&gt;Deleting a search index didn&#39;t delete all associated metadata, which were then incorrectly reused if a new search index was created. This caused search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong.&lt;/li&gt;
&lt;li&gt;LFS objects could fail to be cloned after a successful upload.&lt;/li&gt;
&lt;li&gt;GitHub Apps silently fail to be created when the name contains an underscore.&lt;/li&gt;
&lt;li&gt;Trying to delete an App&#39;s avatar in &lt;code&gt;settings/apps/[app-name]&lt;/code&gt; caused an error and didn&#39;t delete the avatar.&lt;/li&gt;
&lt;li&gt;Installations failed to be removed while transferring repository ownership.&lt;/li&gt;
&lt;li&gt;Collaborators added through the API were incorrectly sent invitations.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-repl-status&lt;/code&gt; could show an inaccurate count when Alambic replication was behind.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;Git LFS, release and issue assets, user profile images, webhooks, or Subversion access may be unavailable if an appliance is restarted after applying the 2.12.5 or greater hotpatch—if this occurs, please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us&quot;&gt;Enterprise Support&lt;/a&gt; for assistance. (updated 2018-03-19)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;li&gt;On a repository that&#39;s been locked for migration using &lt;code&gt;ghe-migrator&lt;/code&gt;, project boards are not exported. (updated 2018-05-07)&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 27 Feb 2018 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.12</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;LOW: Tokens were contained in extended support bundles when they were used in GET requests as a URL parameter.&lt;/li&gt;
&lt;li&gt;Packages were updated to their latest patch versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;RRD files used to store metrics that are no longer collected were never deleted, wasting space on the root file system.&lt;/li&gt;
&lt;li&gt;Failed to upgrade a replica to the same version on a newly partitioned root disk.&lt;/li&gt;
&lt;li&gt;Deleting a search index didn&#39;t delete all associated metadata, which were then incorrectly reused if a new search index was created. This caused search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong.&lt;/li&gt;
&lt;li&gt;LFS objects could fail to be cloned after a successful upload.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-repl-status&lt;/code&gt; could show an inaccurate count when Alambic replication was behind.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.  (updated 2018-02-14)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 27 Feb 2018 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.18</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;LOW: Tokens were contained in extended support bundles when they were used in GET requests as a URL parameter.&lt;/li&gt;
&lt;li&gt;Packages were updated to their latest patch versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;RRD files used to store metrics that are no longer collected were never deleted, wasting space on the root file system.&lt;/li&gt;
&lt;li&gt;Failed to upgrade a replica to the same version on a newly partitioned root disk.&lt;/li&gt;
&lt;li&gt;Deleting a search index didn&#39;t delete all associated metadata, which were then incorrectly reused if a new search index was created. This caused search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong.&lt;/li&gt;
&lt;li&gt;LFS objects could fail to be cloned after a successful upload.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-repl-status&lt;/code&gt; could show an inaccurate count when Alambic replication was behind.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 27 Feb 2018 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.9.23</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;LOW: Tokens were contained in extended support bundles when they were used in GET requests as a URL parameter.&lt;/li&gt;
&lt;li&gt;Packages were updated to their latest patch versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.9&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.9 will be deprecated as of March 1, 2018.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.12/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Failed to upgrade a replica to the same version on a newly partitioned root disk.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 27 Feb 2018 16:00:29 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.9.23</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.9.23</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.5</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The directory hierarchy was not retained when uploading a directory of files to a repository using &lt;a href=&quot;https://docs.github.com/articles/adding-a-file-to-a-repository/&quot;&gt;drag &amp;amp; drop&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;MySQL backups could fail with &lt;code&gt;mysqldump: Error 2013: Lost connection to MySQL server during query when dumping table&lt;/code&gt; error.&lt;/li&gt;
&lt;li&gt;An incorrect merge commit SHA could be returned for pull requests merged through the API.&lt;/li&gt;
&lt;li&gt;Multiple attempts may have been required to resolve a merge conflict using the &lt;a href=&quot;https://github.com/blog/2293-resolve-simple-merge-conflicts-on-github&quot;&gt;conflict resolution web interface&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;The incomplete preview &lt;a href=&quot;https://developer.github.com/v3/repos/community/&quot;&gt;Community Profile API&lt;/a&gt; endpoint was enabled on GitHub Enterprise.&lt;/li&gt;
&lt;li&gt;Pull request reviewers were not migrated when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The pull request assignee event was duplicated on repositories migrated using &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The pull request review request had users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Granting push permissions on a protected branch to a child team could fail with a &lt;code&gt;500 internal server&lt;/code&gt; error when submitting the form.&lt;/li&gt;
&lt;li&gt;Archived repositories could not be forked via the REST API.&lt;/li&gt;
&lt;li&gt;Querying the status of storage objects using in high availability and cluster environments has been optimized for improved performance.&lt;/li&gt;
&lt;li&gt;Git references, such as tags or branch names, with a high number of transitions from letter to numbers and back again, could result in a background worker crashing causing some webhooks not to fire.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service could consume large amounts of CPU time even when not processing requests.  (updated 2018-02-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise is now available in the Paris AWS region.&lt;/li&gt;
&lt;li&gt;Support bundles are more efficiently sanitized during generation.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;GitHub Apps silently fail to be created when the name contains an underscore.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong.&lt;/li&gt;
&lt;li&gt;Git LFS, release and issue assets, user profile images, webhooks, or Subversion access may be unavailable if an appliance is restarted after applying the 2.12.5 or greater hotpatch—if this occurs, please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us&quot;&gt;Enterprise Support&lt;/a&gt; for assistance. (updated 2018-03-19)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;li&gt;On a repository that&#39;s been locked for migration using &lt;code&gt;ghe-migrator&lt;/code&gt;, project boards are not exported. (updated 2018-05-07)&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 13 Feb 2018 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.11</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The directory hierarchy was not retained when uploading a directory of files to a repository using &lt;a href=&quot;https://docs.github.com/articles/adding-a-file-to-a-repository/&quot;&gt;drag &amp;amp; drop&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;An incorrect merge commit SHA could be returned for pull requests merged through the API.&lt;/li&gt;
&lt;li&gt;Multiple attempts may have been required to resolve a merge conflict using the &lt;a href=&quot;https://github.com/blog/2293-resolve-simple-merge-conflicts-on-github&quot;&gt;conflict resolution web interface&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;The incomplete preview &lt;a href=&quot;https://developer.github.com/v3/repos/community/&quot;&gt;Community Profile API&lt;/a&gt; endpoint was enabled on GitHub Enterprise.&lt;/li&gt;
&lt;li&gt;Pull request reviewers were not migrated when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The pull request assignee event was duplicated on repositories migrated using &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The pull request review request had users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Granting push permissions on a protected branch to a child team could fail with a &lt;code&gt;500 internal server&lt;/code&gt; error when submitting the form.&lt;/li&gt;
&lt;li&gt;Querying the status of storage objects using in high availability and cluster environments has been optimized for improved performance.&lt;/li&gt;
&lt;li&gt;Git references, such as tags or branch names, with a high number of transitions from letter to numbers and back again, could result in a background worker crashing causing some webhooks not to fire.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service could consume large amounts of CPU time even when not processing requests.  (updated 2018-02-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise is now available in the Paris AWS region.&lt;/li&gt;
&lt;li&gt;Support bundles are more efficiently sanitized during generation.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong.&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 13 Feb 2018 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.17</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The directory hierarchy was not retained when uploading a directory of files to a repository using &lt;a href=&quot;https://docs.github.com/articles/adding-a-file-to-a-repository/&quot;&gt;drag &amp;amp; drop&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Querying the status of storage objects using in high availability and cluster environments has been optimized for improved performance.&lt;/li&gt;
&lt;li&gt;Pull request reviewers were not migrated when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The pull request assignee event was duplicated on repositories migrated using &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The pull request review request had users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Git references, such as tags or branch names, with a high number of transitions from letter to numbers and back again, could result in a background worker crashing causing some webhooks not to fire.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise is now available in the Paris AWS region.&lt;/li&gt;
&lt;li&gt;Support bundles are more efficiently sanitized during generation.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 13 Feb 2018 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.9.22</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The directory hierarchy was not retained when uploading a directory of files to a repository using &lt;a href=&quot;https://docs.github.com/articles/adding-a-file-to-a-repository/&quot;&gt;drag &amp;amp; drop&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Git references, such as tags or branch names, with a high number of transitions from letter to numbers and back again, could result in a background worker crashing causing some webhooks not to fire.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise is now available in the Paris AWS region.&lt;/li&gt;
&lt;li&gt;Support bundles are more efficiently sanitized during generation.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 13 Feb 2018 16:00:29 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.9.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.9.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.4</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The hostname documentation link in the Management Console linked to an invalid location.&lt;/li&gt;
&lt;li&gt;Large Git LFS objects and release downloads were temporarily buffered to the root disk. This could lead to disk space contention.&lt;/li&gt;
&lt;li&gt;The create team API endpoint returned a 500 error if LDAP Sync is enabled and the team already exists.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;hookshot-unicorn&lt;/code&gt; service could fail to start if there was a large backlog of webhook jobs.&lt;/li&gt;
&lt;li&gt;Tearing down replication did not remove the database seed data used when configuring high availability replication.&lt;/li&gt;
&lt;li&gt;The license expiry notification was shown if the appliance was restarted after the current has license expired.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;elasticsearch-upgrade&lt;/code&gt; service was not stopped during the upgrade process when upgrading via a hotpatch. This could lead to unnecessary logging to the root disk.&lt;/li&gt;
&lt;li&gt;Applying a hotpatch that required a reboot did not warn that a reboot is required.&lt;/li&gt;
&lt;li&gt;Postfix attempted to negotiate NTLM authentication if the relay host offered it.&lt;/li&gt;
&lt;li&gt;Toggling each of the Branch Protection settings would produce inconsistent audit log events.&lt;/li&gt;
&lt;li&gt;Toggling the &#39;Require review from Code Owners&#39; Branch Protection setting did not generate an audit log event.&lt;/li&gt;
&lt;li&gt;Background job logging to &lt;code&gt;/var/log/github/production.log&lt;/code&gt; could consume large amounts of disk space. The fast growth of this log file could cause the root disk to fill up.&lt;/li&gt;
&lt;li&gt;Comparing branches with unicode characters in their names could fail with a &#39;500 Internal Server Error&#39;.&lt;/li&gt;
&lt;li&gt;Large API requests could trigger excessive logging in the exceptions log. (updated 2018-01-31)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-diagnostics&lt;/code&gt; can now upload directly to GitHub using the &lt;code&gt;-u&lt;/code&gt; or &lt;code&gt;-t [ticket reference]&lt;/code&gt; options.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;GitHub Apps silently fail to be created when the name contains an underscore.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.  (updated 2018-02-14)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;li&gt;On a repository that&#39;s been locked for migration using &lt;code&gt;ghe-migrator&lt;/code&gt;, project boards are not exported. (updated 2018-05-07)&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 30 Jan 2018 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.10</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The hostname documentation link in the Management Console linked to an invalid location.&lt;/li&gt;
&lt;li&gt;Large Git LFS objects and release downloads were temporarily buffered to the root disk. This could lead to disk space contention.&lt;/li&gt;
&lt;li&gt;The create team API endpoint returned a 500 error if LDAP Sync is enabled and the team already exists.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;hookshot-unicorn&lt;/code&gt; service could fail to start if there was a large backlog of webhook jobs.&lt;/li&gt;
&lt;li&gt;Tearing down replication did not remove the database seed data used when configuring high availability replication.&lt;/li&gt;
&lt;li&gt;The license expiry notification was shown if the appliance was restarted after the current has license expired.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;elasticsearch-upgrade&lt;/code&gt; service was not stopped during the upgrade process when upgrading via a hotpatch. This could lead to unnecessary logging to the root disk.&lt;/li&gt;
&lt;li&gt;Applying a hotpatch that required a reboot did not warn that a reboot is required.&lt;/li&gt;
&lt;li&gt;Postfix attempted to negotiate NTLM authentication if the relay host offered it.&lt;/li&gt;
&lt;li&gt;Toggling each of the Branch Protection settings would produce inconsistent audit log events.&lt;/li&gt;
&lt;li&gt;Toggling the &#39;Require review from Code Owners&#39; Branch Protection setting did not generate an audit log event.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-diagnostics&lt;/code&gt; can now upload directly to GitHub using the &lt;code&gt;-u&lt;/code&gt; or &lt;code&gt;-t [ticket reference]&lt;/code&gt; options.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.  (updated 2018-02-14)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 30 Jan 2018 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.16</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The hostname documentation link in the Management Console linked to an invalid location.&lt;/li&gt;
&lt;li&gt;Large Git LFS objects and release downloads were temporarily buffered to the root disk. This could lead to disk space contention.&lt;/li&gt;
&lt;li&gt;The create team API endpoint returned a 500 error if LDAP Sync is enabled and the team already exists.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;hookshot-unicorn&lt;/code&gt; service could fail to start if there was a large backlog of webhook jobs.&lt;/li&gt;
&lt;li&gt;Tearing down replication did not remove the database seed data used when configuring high availability replication.&lt;/li&gt;
&lt;li&gt;The license expiry notification was shown if the appliance was restarted after the current has license expired.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-diagnostics&lt;/code&gt; can now upload directly to GitHub using the &lt;code&gt;-u&lt;/code&gt; or &lt;code&gt;-t [ticket reference]&lt;/code&gt; options.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 30 Jan 2018 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.9.21</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The hostname documentation link in the Management Console linked to an invalid location.&lt;/li&gt;
&lt;li&gt;Large Git LFS objects and release downloads were temporarily buffered to the root disk. This could lead to disk space contention.&lt;/li&gt;
&lt;li&gt;The create team API endpoint returned a 500 error if LDAP Sync is enabled and the team already exists.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;hookshot-unicorn&lt;/code&gt; service could fail to start if there was a large backlog of webhook jobs.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-diagnostics&lt;/code&gt; can now upload directly to GitHub using the &lt;code&gt;-u&lt;/code&gt; or &lt;code&gt;-t [ticket reference]&lt;/code&gt; options.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 30 Jan 2018 16:00:29 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.9.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.9.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.3</title>
					<description>&lt;h2&gt;Meltdown&lt;/h2&gt;
&lt;p&gt;This release addresses the &lt;a href=&quot;https://meltdownattack.com/&quot;&gt;Meltdown&lt;/a&gt; (CVE-2017-5754) attack. This has been fixed in the &lt;code&gt;3.16.51-3+deb8u1&lt;/code&gt; release from Debian. Please note that this patch does not address the &lt;a href=&quot;https://spectreattack.com/&quot;&gt;Spectre&lt;/a&gt; (CVE-2017-5753 and CVE-2017-5715) vulnerability. A fix is not available for the Spectre vulnerability yet.&lt;/p&gt;
&lt;p&gt;Internally conducted benchmarks indicate the performance impact is limited to a 2-5% increase in CPU usage on most platforms. The impact can vary depending on your usage and platform though. If you see a significant performance difference, don&#39;t hesitate to reach out to &lt;a href=&quot;https://enterprise.github.com/support&quot;&gt;Enterprise Support&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Note on Hotpatching&lt;/h2&gt;
&lt;p&gt;The hotpatch contains an upgrade to the kernel and requires a reboot. The Meltdown attack is not fixed until a reboot is performed.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: Kernel is updated to 3.16.51-3+deb8u1 which implements Kernel Page Table Isolation (KPTI) to address Meltdown.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-dbconsole&lt;/code&gt;, in a cluster environment, did not work on nodes without a database role.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-repl-status&lt;/code&gt; command-line utility incorrectly showed &lt;code&gt;TypeError: no implicit conversion of Symbol into Integer&lt;/code&gt; when there are repositories or gists with bad replica counts.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-dpages check-replicas&lt;/code&gt; command could show an error with widely dispersed geo replicas.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;GitHub Apps silently fail to be created when the name contains an underscore.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong.&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists.&lt;/li&gt;
&lt;li&gt;Background job logging to &lt;code&gt;/var/log/github/production.log&lt;/code&gt; may consume large amounts of disk space. The fast growth of this log file could cause the root disk to fill up.&lt;/li&gt;
&lt;li&gt;Large API requests may trigger excessive logging in the exceptions log. (updated 2018-01-31)&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.  (updated 2018-02-14)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;li&gt;On a repository that&#39;s been locked for migration using &lt;code&gt;ghe-migrator&lt;/code&gt;, project boards are not exported. (updated 2018-05-07)&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 16 Jan 2018 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.9</title>
					<description>&lt;h2&gt;Meltdown&lt;/h2&gt;
&lt;p&gt;This release addresses the &lt;a href=&quot;https://meltdownattack.com/&quot;&gt;Meltdown&lt;/a&gt; (CVE-2017-5754) attack. This has been fixed in the &lt;code&gt;3.16.51-3+deb8u1&lt;/code&gt; release from Debian. Please note that this patch does not address the &lt;a href=&quot;https://spectreattack.com/&quot;&gt;Spectre&lt;/a&gt; (CVE-2017-5753 and CVE-2017-5715) vulnerability. A fix is not available for the Spectre vulnerability yet.&lt;/p&gt;
&lt;p&gt;Internally conducted benchmarks indicate the performance impact is limited to a 2-5% increase in CPU usage on most platforms. The impact can vary depending on your usage and platform though. If you see a significant performance difference, don&#39;t hesitate to reach out to &lt;a href=&quot;https://enterprise.github.com/support&quot;&gt;Enterprise Support&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Note on Hotpatching&lt;/h2&gt;
&lt;p&gt;The hotpatch contains an upgrade to the kernel and requires a reboot. The Meltdown attack is not fixed until a reboot is performed.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: Kernel is updated to 3.16.51-3+deb8u1 which implements Kernel Page Table Isolation (KPTI) to address Meltdown.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;ghe-dpages check-replicas&lt;/code&gt; command could show an error incorrectly with widely dispersed geo replicas.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong.&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.  (updated 2018-02-14)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 16 Jan 2018 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.15</title>
					<description>&lt;h2&gt;Meltdown&lt;/h2&gt;
&lt;p&gt;This release addresses the &lt;a href=&quot;https://meltdownattack.com/&quot;&gt;Meltdown&lt;/a&gt; (CVE-2017-5754) attack. This has been fixed in the &lt;code&gt;3.16.51-3+deb8u1&lt;/code&gt; release from Debian. Please note that this patch does not address the &lt;a href=&quot;https://spectreattack.com/&quot;&gt;Spectre&lt;/a&gt; (CVE-2017-5753 and CVE-2017-5715) vulnerability. A fix is not available for the Spectre vulnerability yet.&lt;/p&gt;
&lt;p&gt;Internally conducted benchmarks indicate the performance impact is limited to a 2-5% increase in CPU usage on most platforms. The impact can vary depending on your usage and platform though. If you see a significant performance difference, don&#39;t hesitate to reach out to &lt;a href=&quot;https://enterprise.github.com/support&quot;&gt;Enterprise Support&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Note on Hotpatching&lt;/h2&gt;
&lt;p&gt;The hotpatch contains an upgrade to the kernel and requires a reboot. The Meltdown attack is not fixed until a reboot is performed.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: Kernel is updated to 3.16.51-3+deb8u1 which implements Kernel Page Table Isolation (KPTI) to address Meltdown.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists.&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 16 Jan 2018 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.9.20</title>
					<description>&lt;h2&gt;Meltdown&lt;/h2&gt;
&lt;p&gt;This release addresses the &lt;a href=&quot;https://meltdownattack.com/&quot;&gt;Meltdown&lt;/a&gt; (CVE-2017-5754) attack. This has been fixed in the &lt;code&gt;3.16.51-3+deb8u1&lt;/code&gt; release from Debian. Please note that this patch does not address the &lt;a href=&quot;https://spectreattack.com/&quot;&gt;Spectre&lt;/a&gt; (CVE-2017-5753 and CVE-2017-5715) vulnerability. A fix is not available for the Spectre vulnerability yet.&lt;/p&gt;
&lt;p&gt;Internally conducted benchmarks indicate the performance impact is limited to a 2-5% increase in CPU usage on most platforms. The impact can vary depending on your usage and platform though. If you see a significant performance difference, don&#39;t hesitate to reach out to &lt;a href=&quot;https://enterprise.github.com/support&quot;&gt;Enterprise Support&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Note on Hotpatching&lt;/h2&gt;
&lt;p&gt;The hotpatch contains an upgrade to the kernel and requires a reboot. The Meltdown attack is not fixed until a reboot is performed.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: Kernel is updated to 3.16.51-3+deb8u1 which implements Kernel Page Table Isolation (KPTI) to address Meltdown.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 16 Jan 2018 16:00:29 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.9.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.9.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.2</title>
					<description>&lt;h2&gt;Meltdown &amp;amp; Spectre&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://meltdownattack.com/&quot;&gt;Meltdown&lt;/a&gt; (CVE-2017-5754) and &lt;a href=&quot;https://spectreattack.com/&quot;&gt;Spectre&lt;/a&gt; (CVE-2017-5753 and CVE-2017-5715) exploit critical vulnerabilities in modern processors. These hardware vulnerabilities allow programs to extract data which is currently processed on the same machine. This also can affect GitHub Enterprise.&lt;/p&gt;
&lt;p&gt;The risk to GitHub Enterprise depends on the environment that it runs in. There are two main vectors of attack that need to be considered.&lt;/p&gt;
&lt;h3&gt;Virtualization platform&lt;/h3&gt;
&lt;p&gt;Given that GitHub Enterprise runs on various virtualization platforms, it&#39;s essential to update the virtualization platform where possible to mitigate any of these issues. The existing patches and fixes almost all focus on solving Meltdown. Meltdown is more straightforward to fix and most providers focus on this first.&lt;/p&gt;
&lt;p&gt;Spectre is more complicated to exploit and also more complicated to fix. KVM for example is not vulnerable to Meltdown but is vulnerable, with a proof of concept, to Spectre which was tested by Google in the project originally (see &lt;a href=&quot;https://googleprojectzero.blogspot.nl/2018/01/reading-privileged-memory-with-side.html&quot;&gt;https://googleprojectzero.blogspot.nl/2018/01/reading-privileged-memory-with-side.html&lt;/a&gt;). Specifically under &amp;quot;Reading host memory from a KVM guest&amp;quot;. This Spectre exploit tested against a specific kernel version, but nothing implies it&#39;s impossible to adapt for other kernel versions and or other virtualization platforms.&lt;/p&gt;
&lt;p&gt;The following Cloud and virtualization platforms have released announcements and/or fixes.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;On AWS we use HVM for virtualization. According to Amazon, HVM is not vulnerable to Meltdown. Also see &lt;a href=&quot;https://aws.amazon.com/security/security-bulletins/AWS-2018-013/&quot;&gt;https://aws.amazon.com/security/security-bulletins/AWS-2018-013/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Xen VMs using PV virtualization are vulnerable. We recommend switching to HVM virtualization as HVM is not vulnerable to Meltdown. Also see &lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-254.html&quot;&gt;https://xenbits.xen.org/xsa/advisory-254.html&lt;/a&gt; under &amp;quot;Mitigation&amp;quot;.&lt;/li&gt;
&lt;li&gt;Google Cloud is not vulnerable to Meltdown as VMs there are isolated and cross VM attacks are not possible.&lt;br /&gt;
See their &lt;a href=&quot;https://support.google.com/faqs/answer/7622138#gce&quot;&gt;FAQ&lt;/a&gt; and the Google Cloud &lt;a href=&quot;https://cloud.google.com/compute/docs/security-bulletins&quot;&gt;Security Bulletins page&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Microsoft Azure is updating/rebooting infrastructure where necessary to mitigate potential hypervisor level issues. See &lt;a href=&quot;https://azure.microsoft.com/en-us/blog/securing-azure-customers-from-cpu-vulnerability/&quot;&gt;https://azure.microsoft.com/en-us/blog/securing-azure-customers-from-cpu-vulnerability/&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;VMWare has released patches to address this at the hypervisor level: &lt;a href=&quot;https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html&quot;&gt;https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html&lt;/a&gt; &amp;amp; &lt;a href=&quot;https://lists.vmware.com/pipermail/security-announce/2018/000397.html&quot;&gt;https://lists.vmware.com/pipermail/security-announce/2018/000397.html&lt;/a&gt;. We strongly encourage customers install those patches.&lt;/li&gt;
&lt;li&gt;Intel has also announced &lt;a href=&quot;https://newsroom.intel.com/news-releases/intel-issues-updates-protect-systems-security-exploits/&quot;&gt;they will be releasing updates for their processors&lt;/a&gt;. If the host platform you run GitHub Enterprise on has these patches available in the future, we also strongly recommend installing those.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Inside GitHub Enterprise&lt;/h3&gt;
&lt;p&gt;The vulnerability can also be exploited if there is code under the control of an attacker running on the same system. GitHub Enterprise has very limited support for custom code in the form of pre-receive hooks. Pre-receive hooks are limited such that administrators are the only ones who can set them up and their runtime execution is limited to 5 seconds. Both these aspects greatly limit the risk of data exposure through pre-receive hooks. As a general rule, administrators should ensure that only known and trusted pre-receive hooks are enabled on their appliance.&lt;/p&gt;
&lt;p&gt;GitHub Enterprise is based on Debian Jessie. A fix for Meltdown is not yet available for Debian Jessie, as can be seen in the &lt;a href=&quot;https://security-tracker.debian.org/tracker/CVE-2017-5754&quot;&gt;Debian CVE tracker for Meltdown&lt;/a&gt;. The new kernel version will be included in a future release of GitHub Enterprise and can potentially come with a performance regression. Accordingly, we recommend testing that release before putting it into production.&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;The primary risk for GitHub Enterprise installations is cross-guest or host &amp;lt;-&amp;gt; guest data leakage on the virtualization platform. This may be mitigated by the support cloud hosting providers, or by the suppliers of virtualization software. There is very limited risk of externally supplied software running within the appliance obtaining data from other processes, mitigated by administrators only enabling pre-receive hooks that are reviewed and trusted.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Pre-receive hooks could access internal cloud platform metadata. The metadata resources have been restricted to the &lt;code&gt;root&lt;/code&gt; user.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Changing the parent of a nested team can result in the nested team not receiving updated inherited permissions.&lt;/li&gt;
&lt;li&gt;Changes to legal hold state of a repository did not trigger an audit log event.&lt;/li&gt;
&lt;li&gt;After changing HTTP proxy configuration in the Management Console, webhooks did not use the settings unless &lt;code&gt;hookshot-resqued&lt;/code&gt; was restarted manually.&lt;/li&gt;
&lt;li&gt;NUMA enabled appliances could crash with a kernel panic. This was a &lt;a href=&quot;https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=883938&quot;&gt;known issue with linux-image-3.16.51-2&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;GitHub Apps referenced an invalid profile in the notifications and comment views.&lt;/li&gt;
&lt;li&gt;The pre-receive hook &lt;code&gt;$GITHUB_PULL_REQUEST_AUTHOR_LOGIN&lt;/code&gt; environment variable was empty when pull requests were merged via the API.&lt;/li&gt;
&lt;li&gt;Permission update notifications for GitHub Apps were not sent to organization administrators.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise support ticket creation via e-mail (&lt;code&gt;enterprise@github.com&lt;/code&gt;) has been disabled. Please contact GitHub Enterprise Support using the &lt;a href=&quot;https://docs.github.com/enterprise/2.12/admin/guides/enterprise-support/submitting-a-ticket/&quot;&gt;Submitting a ticket&lt;/a&gt; article.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;GitHub Apps silently fail to be created when the name contains an underscore.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong.&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-repl-status&lt;/code&gt; command-line utility incorrectly shows &lt;code&gt;TypeError: no implicit conversion of Symbol into Integer&lt;/code&gt; when there are repositories or gists with bad replica counts. (updated 2018-01-10)&lt;/li&gt;
&lt;li&gt;Reviewers and the &amp;quot;Review requested&amp;quot; status disappear on pull requests migrated with &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-01-12)&lt;/li&gt;
&lt;li&gt;Background job logging to &lt;code&gt;/var/log/github/production.log&lt;/code&gt; may consume large amounts of disk space. The fast growth of this log file could cause the root disk to fill up. (updated 2018-01-16)&lt;/li&gt;
&lt;li&gt;Large API requests may trigger excessive logging in the exceptions log. (updated 2018-01-31)&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.  (updated 2018-02-14)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;li&gt;On a repository that&#39;s been locked for migration using &lt;code&gt;ghe-migrator&lt;/code&gt;, project boards are not exported. (updated 2018-05-07)&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 09 Jan 2018 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.8</title>
					<description>&lt;h2&gt;Meltdown &amp;amp; Spectre&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://meltdownattack.com/&quot;&gt;Meltdown&lt;/a&gt; (CVE-2017-5754) and &lt;a href=&quot;https://spectreattack.com/&quot;&gt;Spectre&lt;/a&gt; (CVE-2017-5753 and CVE-2017-5715) exploit critical vulnerabilities in modern processors. These hardware vulnerabilities allow programs to extract data which is currently processed on the same machine. This also can affect GitHub Enterprise.&lt;/p&gt;
&lt;p&gt;The risk to GitHub Enterprise depends on the environment that it runs in. There are two main vectors of attack that need to be considered.&lt;/p&gt;
&lt;h3&gt;Virtualization platform&lt;/h3&gt;
&lt;p&gt;Given that GitHub Enterprise runs on various virtualization platforms, it&#39;s essential to update the virtualization platform where possible to mitigate any of these issues. The existing patches and fixes almost all focus on solving Meltdown. Meltdown is more straightforward to fix and most providers focus on this first.&lt;/p&gt;
&lt;p&gt;Spectre is more complicated to exploit and also more complicated to fix. KVM for example is not vulnerable to Meltdown but is vulnerable, with a proof of concept, to Spectre which was tested by Google in the project originally (see &lt;a href=&quot;https://googleprojectzero.blogspot.nl/2018/01/reading-privileged-memory-with-side.html&quot;&gt;https://googleprojectzero.blogspot.nl/2018/01/reading-privileged-memory-with-side.html&lt;/a&gt;). Specifically under &amp;quot;Reading host memory from a KVM guest&amp;quot;. This Spectre exploit tested against a specific kernel version, but nothing implies it&#39;s impossible to adapt for other kernel versions and or other virtualization platforms.&lt;/p&gt;
&lt;p&gt;The following Cloud and virtualization platforms have released announcements and/or fixes.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;On AWS we use HVM for virtualization. According to Amazon, HVM is not vulnerable to Meltdown. Also see &lt;a href=&quot;https://aws.amazon.com/security/security-bulletins/AWS-2018-013/&quot;&gt;https://aws.amazon.com/security/security-bulletins/AWS-2018-013/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Xen VMs using PV virtualization are vulnerable. We recommend switching to HVM virtualization as HVM is not vulnerable to Meltdown. Also see &lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-254.html&quot;&gt;https://xenbits.xen.org/xsa/advisory-254.html&lt;/a&gt; under &amp;quot;Mitigation&amp;quot;.&lt;/li&gt;
&lt;li&gt;Google Cloud is not vulnerable to Meltdown as VMs there are isolated and cross VM attacks are not possible.&lt;br /&gt;
See their &lt;a href=&quot;https://support.google.com/faqs/answer/7622138#gce&quot;&gt;FAQ&lt;/a&gt; and the Google Cloud &lt;a href=&quot;https://cloud.google.com/compute/docs/security-bulletins&quot;&gt;Security Bulletins page&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Microsoft Azure is updating/rebooting infrastructure where necessary to mitigate potential hypervisor level issues. See &lt;a href=&quot;https://azure.microsoft.com/en-us/blog/securing-azure-customers-from-cpu-vulnerability/&quot;&gt;https://azure.microsoft.com/en-us/blog/securing-azure-customers-from-cpu-vulnerability/&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;VMWare has released patches to address this at the hypervisor level: &lt;a href=&quot;https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html&quot;&gt;https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html&lt;/a&gt; &amp;amp; &lt;a href=&quot;https://lists.vmware.com/pipermail/security-announce/2018/000397.html&quot;&gt;https://lists.vmware.com/pipermail/security-announce/2018/000397.html&lt;/a&gt;. We strongly encourage customers install those patches.&lt;/li&gt;
&lt;li&gt;Intel has also announced &lt;a href=&quot;https://newsroom.intel.com/news-releases/intel-issues-updates-protect-systems-security-exploits/&quot;&gt;they will be releasing updates for their processors&lt;/a&gt;. If the host platform you run GitHub Enterprise on has these patches available in the future, we also strongly recommend installing those.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Inside GitHub Enterprise&lt;/h3&gt;
&lt;p&gt;The vulnerability can also be exploited if there is code under the control of an attacker running on the same system. GitHub Enterprise has very limited support for custom code in the form of pre-receive hooks. Pre-receive hooks are limited such that administrators are the only ones who can set them up and their runtime execution is limited to 5 seconds. Both these aspects greatly limit the risk of data exposure through pre-receive hooks. As a general rule, administrators should ensure that only known and trusted pre-receive hooks are enabled on their appliance.&lt;/p&gt;
&lt;p&gt;GitHub Enterprise is based on Debian Jessie. A fix for Meltdown is not yet available for Debian Jessie, as can be seen in the &lt;a href=&quot;https://security-tracker.debian.org/tracker/CVE-2017-5754&quot;&gt;Debian CVE tracker for Meltdown&lt;/a&gt;. The new kernel version will be included in a future release of GitHub Enterprise and can potentially come with a performance regression. Accordingly, we recommend testing that release before putting it into production.&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;The primary risk for GitHub Enterprise installations is cross-guest or host &amp;lt;-&amp;gt; guest data leakage on the virtualization platform. This may be mitigated by the support cloud hosting providers, or by the suppliers of virtualization software. There is very limited risk of externally supplied software running within the appliance obtaining data from other processes, mitigated by administrators only enabling pre-receive hooks that are reviewed and trusted.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Pre-receive hooks could access internal cloud platform metadata. The metadata resources have been restricted to the &lt;code&gt;root&lt;/code&gt; user.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Changing the parent of a nested team can result in the nested team not receiving updated inherited permissions.&lt;/li&gt;
&lt;li&gt;After changing HTTP proxy configuration in the Management Console, webhooks did not use the settings unless &lt;code&gt;hookshot-resqued&lt;/code&gt; was restarted manually.&lt;/li&gt;
&lt;li&gt;NUMA enabled appliances could crash with a kernel panic. This was a &lt;a href=&quot;https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=883938&quot;&gt;known issue with linux-image-3.16.51-2&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;The pre-receive hook &lt;code&gt;$GITHUB_PULL_REQUEST_AUTHOR_LOGIN&lt;/code&gt; environment variable was empty when pull requests were merged via the API.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise support ticket creation via e-mail (&lt;code&gt;enterprise@github.com&lt;/code&gt;) has been disabled. Please contact GitHub Enterprise Support using the &lt;a href=&quot;https://docs.github.com/enterprise/2.11/admin/guides/enterprise-support/submitting-a-ticket/&quot;&gt;Submitting a ticket&lt;/a&gt; article.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order.&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong.&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.  (updated 2018-02-14)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 09 Jan 2018 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.14</title>
					<description>&lt;h2&gt;Meltdown &amp;amp; Spectre&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://meltdownattack.com/&quot;&gt;Meltdown&lt;/a&gt; (CVE-2017-5754) and &lt;a href=&quot;https://spectreattack.com/&quot;&gt;Spectre&lt;/a&gt; (CVE-2017-5753 and CVE-2017-5715) exploit critical vulnerabilities in modern processors. These hardware vulnerabilities allow programs to extract data which is currently processed on the same machine. This also can affect GitHub Enterprise.&lt;/p&gt;
&lt;p&gt;The risk to GitHub Enterprise depends on the environment that it runs in. There are two main vectors of attack that need to be considered.&lt;/p&gt;
&lt;h3&gt;Virtualization platform&lt;/h3&gt;
&lt;p&gt;Given that GitHub Enterprise runs on various virtualization platforms, it&#39;s essential to update the virtualization platform where possible to mitigate any of these issues. The existing patches and fixes almost all focus on solving Meltdown. Meltdown is more straightforward to fix and most providers focus on this first.&lt;/p&gt;
&lt;p&gt;Spectre is more complicated to exploit and also more complicated to fix. KVM for example is not vulnerable to Meltdown but is vulnerable, with a proof of concept, to Spectre which was tested by Google in the project originally (see &lt;a href=&quot;https://googleprojectzero.blogspot.nl/2018/01/reading-privileged-memory-with-side.html&quot;&gt;https://googleprojectzero.blogspot.nl/2018/01/reading-privileged-memory-with-side.html&lt;/a&gt;). Specifically under &amp;quot;Reading host memory from a KVM guest&amp;quot;. This Spectre exploit tested against a specific kernel version, but nothing implies it&#39;s impossible to adapt for other kernel versions and or other virtualization platforms.&lt;/p&gt;
&lt;p&gt;The following Cloud and virtualization platforms have released announcements and/or fixes.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;On AWS we use HVM for virtualization. According to Amazon, HVM is not vulnerable to Meltdown. Also see &lt;a href=&quot;https://aws.amazon.com/security/security-bulletins/AWS-2018-013/&quot;&gt;https://aws.amazon.com/security/security-bulletins/AWS-2018-013/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Xen VMs using PV virtualization are vulnerable. We recommend switching to HVM virtualization as HVM is not vulnerable to Meltdown. Also see &lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-254.html&quot;&gt;https://xenbits.xen.org/xsa/advisory-254.html&lt;/a&gt; under &amp;quot;Mitigation&amp;quot;.&lt;/li&gt;
&lt;li&gt;Google Cloud is not vulnerable to Meltdown as VMs there are isolated and cross VM attacks are not possible.&lt;br /&gt;
See their &lt;a href=&quot;https://support.google.com/faqs/answer/7622138#gce&quot;&gt;FAQ&lt;/a&gt; and the Google Cloud &lt;a href=&quot;https://cloud.google.com/compute/docs/security-bulletins&quot;&gt;Security Bulletins page&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Microsoft Azure is updating/rebooting infrastructure where necessary to mitigate potential hypervisor level issues. See &lt;a href=&quot;https://azure.microsoft.com/en-us/blog/securing-azure-customers-from-cpu-vulnerability/&quot;&gt;https://azure.microsoft.com/en-us/blog/securing-azure-customers-from-cpu-vulnerability/&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;VMWare has released patches to address this at the hypervisor level: &lt;a href=&quot;https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html&quot;&gt;https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html&lt;/a&gt; &amp;amp; &lt;a href=&quot;https://lists.vmware.com/pipermail/security-announce/2018/000397.html&quot;&gt;https://lists.vmware.com/pipermail/security-announce/2018/000397.html&lt;/a&gt;. We strongly encourage customers install those patches.&lt;/li&gt;
&lt;li&gt;Intel has also announced &lt;a href=&quot;https://newsroom.intel.com/news-releases/intel-issues-updates-protect-systems-security-exploits/&quot;&gt;they will be releasing updates for their processors&lt;/a&gt;. If the host platform you run GitHub Enterprise on has these patches available in the future, we also strongly recommend installing those.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Inside GitHub Enterprise&lt;/h3&gt;
&lt;p&gt;The vulnerability can also be exploited if there is code under the control of an attacker running on the same system. GitHub Enterprise has very limited support for custom code in the form of pre-receive hooks. Pre-receive hooks are limited such that administrators are the only ones who can set them up and their runtime execution is limited to 5 seconds. Both these aspects greatly limit the risk of data exposure through pre-receive hooks. As a general rule, administrators should ensure that only known and trusted pre-receive hooks are enabled on their appliance.&lt;/p&gt;
&lt;p&gt;GitHub Enterprise is based on Debian Jessie. A fix for Meltdown is not yet available for Debian Jessie, as can be seen in the &lt;a href=&quot;https://security-tracker.debian.org/tracker/CVE-2017-5754&quot;&gt;Debian CVE tracker for Meltdown&lt;/a&gt;. The new kernel version will be included in a future release of GitHub Enterprise and can potentially come with a performance regression. Accordingly, we recommend testing that release before putting it into production.&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;The primary risk for GitHub Enterprise installations is cross-guest or host &amp;lt;-&amp;gt; guest data leakage on the virtualization platform. This may be mitigated by the support cloud hosting providers, or by the suppliers of virtualization software. There is very limited risk of externally supplied software running within the appliance obtaining data from other processes, mitigated by administrators only enabling pre-receive hooks that are reviewed and trusted.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Pre-receive hooks could access internal cloud platform metadata. The metadata resources have been restricted to the &lt;code&gt;root&lt;/code&gt; user.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;NUMA enabled appliances could crash with a kernel panic. This was a &lt;a href=&quot;https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=883938&quot;&gt;known issue with linux-image-3.16.51-2&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;The pre-receive hook &lt;code&gt;$GITHUB_PULL_REQUEST_AUTHOR_LOGIN&lt;/code&gt; environment variable was empty when pull requests were merged via the API.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise support ticket creation via e-mail (&lt;code&gt;enterprise@github.com&lt;/code&gt;) has been disabled. Please contact GitHub Enterprise Support using the &lt;a href=&quot;https://docs.github.com/enterprise/2.10/admin/guides/enterprise-support/submitting-a-ticket/&quot;&gt;Submitting a ticket&lt;/a&gt; article.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists.&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 09 Jan 2018 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.9.19</title>
					<description>&lt;h2&gt;Meltdown &amp;amp; Spectre&lt;/h2&gt;
&lt;p&gt;&lt;a href=&quot;https://meltdownattack.com/&quot;&gt;Meltdown&lt;/a&gt; (CVE-2017-5754) and &lt;a href=&quot;https://spectreattack.com/&quot;&gt;Spectre&lt;/a&gt; (CVE-2017-5753 and CVE-2017-5715) exploit critical vulnerabilities in modern processors. These hardware vulnerabilities allow programs to extract data which is currently processed on the same machine. This also can affect GitHub Enterprise.&lt;/p&gt;
&lt;p&gt;The risk to GitHub Enterprise depends on the environment that it runs in. There are two main vectors of attack that need to be considered.&lt;/p&gt;
&lt;h3&gt;Virtualization platform&lt;/h3&gt;
&lt;p&gt;Given that GitHub Enterprise runs on various virtualization platforms, it&#39;s essential to update the virtualization platform where possible to mitigate any of these issues. The existing patches and fixes almost all focus on solving Meltdown. Meltdown is more straightforward to fix and most providers focus on this first.&lt;/p&gt;
&lt;p&gt;Spectre is more complicated to exploit and also more complicated to fix. KVM for example is not vulnerable to Meltdown but is vulnerable, with a proof of concept, to Spectre which was tested by Google in the project originally (see &lt;a href=&quot;https://googleprojectzero.blogspot.nl/2018/01/reading-privileged-memory-with-side.html&quot;&gt;https://googleprojectzero.blogspot.nl/2018/01/reading-privileged-memory-with-side.html&lt;/a&gt;). Specifically under &amp;quot;Reading host memory from a KVM guest&amp;quot;. This Spectre exploit tested against a specific kernel version, but nothing implies it&#39;s impossible to adapt for other kernel versions and or other virtualization platforms.&lt;/p&gt;
&lt;p&gt;The following Cloud and virtualization platforms have released announcements and/or fixes.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;On AWS we use HVM for virtualization. According to Amazon, HVM is not vulnerable to Meltdown. Also see &lt;a href=&quot;https://aws.amazon.com/security/security-bulletins/AWS-2018-013/&quot;&gt;https://aws.amazon.com/security/security-bulletins/AWS-2018-013/&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Xen VMs using PV virtualization are vulnerable. We recommend switching to HVM virtualization as HVM is not vulnerable to Meltdown. Also see &lt;a href=&quot;https://xenbits.xen.org/xsa/advisory-254.html&quot;&gt;https://xenbits.xen.org/xsa/advisory-254.html&lt;/a&gt; under &amp;quot;Mitigation&amp;quot;.&lt;/li&gt;
&lt;li&gt;Google Cloud is not vulnerable to Meltdown as VMs there are isolated and cross VM attacks are not possible.&lt;br /&gt;
See their &lt;a href=&quot;https://support.google.com/faqs/answer/7622138#gce&quot;&gt;FAQ&lt;/a&gt; and the Google Cloud &lt;a href=&quot;https://cloud.google.com/compute/docs/security-bulletins&quot;&gt;Security Bulletins page&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Microsoft Azure is updating/rebooting infrastructure where necessary to mitigate potential hypervisor level issues. See &lt;a href=&quot;https://azure.microsoft.com/en-us/blog/securing-azure-customers-from-cpu-vulnerability/&quot;&gt;https://azure.microsoft.com/en-us/blog/securing-azure-customers-from-cpu-vulnerability/&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;VMWare has released patches to address this at the hypervisor level: &lt;a href=&quot;https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html&quot;&gt;https://www.vmware.com/us/security/advisories/VMSA-2018-0002.html&lt;/a&gt; &amp;amp; &lt;a href=&quot;https://lists.vmware.com/pipermail/security-announce/2018/000397.html&quot;&gt;https://lists.vmware.com/pipermail/security-announce/2018/000397.html&lt;/a&gt;. We strongly encourage customers install those patches.&lt;/li&gt;
&lt;li&gt;Intel has also announced &lt;a href=&quot;https://newsroom.intel.com/news-releases/intel-issues-updates-protect-systems-security-exploits/&quot;&gt;they will be releasing updates for their processors&lt;/a&gt;. If the host platform you run GitHub Enterprise on has these patches available in the future, we also strongly recommend installing those.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Inside GitHub Enterprise&lt;/h3&gt;
&lt;p&gt;The vulnerability can also be exploited if there is code under the control of an attacker running on the same system. GitHub Enterprise has very limited support for custom code in the form of pre-receive hooks. Pre-receive hooks are limited such that administrators are the only ones who can set them up and their runtime execution is limited to 5 seconds. Both these aspects greatly limit the risk of data exposure through pre-receive hooks. As a general rule, administrators should ensure that only known and trusted pre-receive hooks are enabled on their appliance.&lt;/p&gt;
&lt;p&gt;GitHub Enterprise is based on Debian Jessie. A fix for Meltdown is not yet available for Debian Jessie, as can be seen in the &lt;a href=&quot;https://security-tracker.debian.org/tracker/CVE-2017-5754&quot;&gt;Debian CVE tracker for Meltdown&lt;/a&gt;. The new kernel version will be included in a future release of GitHub Enterprise and can potentially come with a performance regression. Accordingly, we recommend testing that release before putting it into production.&lt;/p&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;The primary risk for GitHub Enterprise installations is cross-guest or host &amp;lt;-&amp;gt; guest data leakage on the virtualization platform. This may be mitigated by the support cloud hosting providers, or by the suppliers of virtualization software. There is very limited risk of externally supplied software running within the appliance obtaining data from other processes, mitigated by administrators only enabling pre-receive hooks that are reviewed and trusted.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Pre-receive hooks could access internal cloud platform metadata. The metadata resources have been restricted to the &lt;code&gt;root&lt;/code&gt; user.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;NUMA enabled appliances could crash with a kernel panic. This was a &lt;a href=&quot;https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=883938&quot;&gt;known issue with linux-image-3.16.51-2&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;The pre-receive hook &lt;code&gt;$GITHUB_PULL_REQUEST_AUTHOR_LOGIN&lt;/code&gt; environment variable was empty when pull requests were merged via the API.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise support ticket creation via e-mail (&lt;code&gt;enterprise@github.com&lt;/code&gt;) has been disabled. Please contact GitHub Enterprise Support using the &lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/guides/enterprise-support/submitting-a-ticket/&quot;&gt;Submitting a ticket&lt;/a&gt; article.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 09 Jan 2018 16:00:29 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.9.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.9.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.1</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard.&lt;/li&gt;
&lt;li&gt;Authentication graphs in the management console were incorrectly empty and &lt;code&gt;auth.result.*&lt;/code&gt; metrics weren&#39;t forwarded to external collectd servers.&lt;/li&gt;
&lt;li&gt;Orphaned &lt;code&gt;resqued&lt;/code&gt; processes accumulated and caused out-of-memory (OOM) issues.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;CODEOWNERS&lt;/code&gt; failed with CRLF line endings.&lt;/li&gt;
&lt;li&gt;Nested teams could not be migrated with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Pre-receive hook&#39;s &lt;code&gt;enforcement&lt;/code&gt; could not be updated with the API.&lt;/li&gt;
&lt;li&gt;GitHub Apps incorrectly linked to a &amp;quot;Report abuse&amp;quot; reference.&lt;/li&gt;
&lt;li&gt;Repository changes and creation could timeout when an organization contains many teams and members.&lt;/li&gt;
&lt;li&gt;When restoring a deleted repository via the site admin dashboard, an error message could be shown even though the restore worked.&lt;/li&gt;
&lt;li&gt;The compare view could display the incorrect additions or deletions status.&lt;/li&gt;
&lt;li&gt;Updates to a pull request through the API could incorrectly modify &lt;code&gt;manitainer_can_modify&lt;/code&gt; to &lt;code&gt;false&lt;/code&gt; when the field was not a part of the request.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;/var/log/github/production.log&lt;/code&gt; has been updated to include more metadata for &lt;code&gt;resque.performed&lt;/code&gt; and &lt;code&gt;resque.queued&lt;/code&gt; events.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Changing the parent of a nested team can result in the nested team not receiving updated inherited permissions.&lt;/li&gt;
&lt;li&gt;GitHub Apps silently fail to be created when the name contains an underscore.&lt;/li&gt;
&lt;li&gt;Changes to legal hold state of a repository does not trigger an audit log event.&lt;/li&gt;
&lt;li&gt;After changing HTTP proxy configuration in the Management Console, webhooks do not use the settings unless &lt;code&gt;hookshot-resqued&lt;/code&gt; is restarted manually via SSH by running: &lt;code&gt;sudo systemctl restart hookshot-resqued&lt;/code&gt;. (updated 2017-12-20)&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order. (updated 2017-12-27)&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2017-12-27)&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong. (updated 2017-12-27)&lt;/li&gt;
&lt;li&gt;NUMA enabled appliances can crash with a kernel panic. This is a &lt;a href=&quot;https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=883938&quot;&gt;known issue with &lt;code&gt;linux-image-3.16.51-2&lt;/code&gt;&lt;/a&gt; and the workaround is to add the &lt;code&gt;numa=off&lt;/code&gt; parameter to the kernel command line in &lt;code&gt;/boot/grub/grub.cfg&lt;/code&gt;. Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have questions. (updated 2017-12-28)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-repl-status&lt;/code&gt; command-line utility incorrectly shows &lt;code&gt;TypeError: no implicit conversion of Symbol into Integer&lt;/code&gt; when there are repositories or gists with bad replica counts. (updated 2018-01-10)&lt;/li&gt;
&lt;li&gt;Reviewers and the &amp;quot;Review requested&amp;quot; status disappear on pull requests migrated with &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-01-12)&lt;/li&gt;
&lt;li&gt;Background job logging to &lt;code&gt;/var/log/github/production.log&lt;/code&gt; may consume large amounts of disk space. The fast growth of this log file could cause the root disk to fill up. (updated 2018-01-16)&lt;/li&gt;
&lt;li&gt;Large API requests may trigger excessive logging in the exceptions log. (updated 2018-01-31)&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.  (updated 2018-02-14)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;li&gt;On a repository that&#39;s been locked for migration using &lt;code&gt;ghe-migrator&lt;/code&gt;, project boards are not exported. (updated 2018-05-07)&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 19 Dec 2017 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.7</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The followers and following count incorrectly considered suspended accounts.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard.&lt;/li&gt;
&lt;li&gt;Orphaned &lt;code&gt;resqued&lt;/code&gt; processes accumulated and caused out-of-memory (OOM) issues.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;CODEOWNERS&lt;/code&gt; failed with CRLF line endings.&lt;/li&gt;
&lt;li&gt;Nested teams could not be migrated with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Pre-receive hook&#39;s &lt;code&gt;enforcement&lt;/code&gt; could not be updated with the API.&lt;/li&gt;
&lt;li&gt;Repository changes and creation could timeout when an organization contains many teams and members.&lt;/li&gt;
&lt;li&gt;When restoring a deleted repository via the site admin dashboard, an error message could be shown even though the restore worked.&lt;/li&gt;
&lt;li&gt;The compare view could display the incorrect additions or deletions status.&lt;/li&gt;
&lt;li&gt;Updates to a pull request through the API could incorrectly modify &lt;code&gt;manitainer_can_modify&lt;/code&gt; to &lt;code&gt;false&lt;/code&gt; when the field was not a part of the request.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Changing the parent of a nested team can result in the nested team not receiving updated inherited permissions.&lt;/li&gt;
&lt;li&gt;After changing HTTP proxy configuration in the Management Console, webhooks do not use the settings unless &lt;code&gt;hookshot-resqued&lt;/code&gt; is restarted manually via SSH by running: &lt;code&gt;sudo systemctl restart hookshot-resqued&lt;/code&gt;. (updated 2017-12-20)&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order. (updated 2017-12-20)&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2017-12-20)&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong. (updated 2017-12-20)&lt;/li&gt;
&lt;li&gt;NUMA enabled appliances can crash with a kernel panic. This is a &lt;a href=&quot;https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=883938&quot;&gt;known issue with &lt;code&gt;linux-image-3.16.51-2&lt;/code&gt;&lt;/a&gt; and the workaround is to add the &lt;code&gt;numa=off&lt;/code&gt; parameter to the kernel command line in &lt;code&gt;/boot/grub/grub.cfg&lt;/code&gt;. Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have questions. (updated 2017-12-28)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.  (updated 2018-02-14)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 19 Dec 2017 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.13</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The followers and following count incorrectly considered suspended accounts.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard.&lt;/li&gt;
&lt;li&gt;Pre-receive hook&#39;s &lt;code&gt;enforcement&lt;/code&gt; could not be updated with the API.&lt;/li&gt;
&lt;li&gt;When restoring a deleted repository via the site admin dashboard, an error message could be shown even though the restore worked.&lt;/li&gt;
&lt;li&gt;Updates to a pull request through the API could incorrectly modify &lt;code&gt;manitainer_can_modify&lt;/code&gt; to &lt;code&gt;false&lt;/code&gt; when the field was not a part of the request.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;NUMA enabled appliances can crash with a kernel panic. This is a &lt;a href=&quot;https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=883938&quot;&gt;known issue with &lt;code&gt;linux-image-3.16.51-2&lt;/code&gt;&lt;/a&gt; and the workaround is to add the &lt;code&gt;numa=off&lt;/code&gt; parameter to the kernel command line in &lt;code&gt;/boot/grub/grub.cfg&lt;/code&gt;. Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have questions. (updated 2017-12-28)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 19 Dec 2017 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.9.18</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The followers and following count incorrectly considered suspended accounts.&lt;/li&gt;
&lt;li&gt;Pre-receive hook&#39;s &lt;code&gt;enforcement&lt;/code&gt; could not be updated with the API.&lt;/li&gt;
&lt;li&gt;Updates to a pull request through the API could incorrectly modify &lt;code&gt;manitainer_can_modify&lt;/code&gt; to &lt;code&gt;false&lt;/code&gt; when the field was not a part of the request.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;NUMA enabled appliances can crash with a kernel panic. This is a &lt;a href=&quot;https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=883938&quot;&gt;known issue with &lt;code&gt;linux-image-3.16.51-2&lt;/code&gt;&lt;/a&gt; and the workaround is to add the &lt;code&gt;numa=off&lt;/code&gt; parameter to the kernel command line in &lt;code&gt;/boot/grub/grub.cfg&lt;/code&gt;. Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have questions. (updated 2017-12-28)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 19 Dec 2017 16:00:29 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.9.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.9.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.12.0</title>
					<description>&lt;h2&gt;Features&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.12/admin/articles/archiving-and-unarchiving-repositories/&quot;&gt;Archive repositories&lt;/a&gt; to indicate when a project is no longer actively maintained.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.12/admin/guides/installation/about-tls/#about-lets-encrypt-support&quot;&gt;Install and renew TLS certificates from Let&#39;s Encrypt®&lt;/a&gt; on your appliance without any required manual maintenance.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.12/admin/guides/installation/system-overview/#open-source-dependencies-for-github-enterprise&quot;&gt;View the modules, libraries, projects, and corresponding licenses&lt;/a&gt; that are used by a GitHub Enterprise appliance.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.12/admin/guides/installation/upgrading-github-enterprise/#installing-a-hotpatch-using-the-management-console&quot;&gt;Install a hotpatch using the management console&lt;/a&gt; or schedule an installation to upgrade your GitHub Enterprise appliance to the latest patch release.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.12/user/articles/file-attachments-on-issues-and-pull-requests/&quot;&gt;Attach &lt;code&gt;.log&lt;/code&gt; files&lt;/a&gt; to issues and pull requests.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.12/user/articles/about-automation-for-project-boards/&quot;&gt;Configure automation for project board columns&lt;/a&gt; to keep cards in sync with associated issues and pull requests.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.12/user/articles/requesting-to-add-a-child-team/&quot;&gt;Request to nest&lt;/a&gt; an existing team under your team in your organization’s hierarchy.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.12/user/articles/licensing-a-repository#searching-github-by-license-type&quot;&gt;Search repositories&lt;/a&gt; by license type.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.12/admin/guides/user-management/about-global-webhooks&quot;&gt;Create global web hooks&lt;/a&gt; to monitor, respond to, or enforce rules for user and organization management on your appliance.&lt;/li&gt;
&lt;li&gt;View a comment&#39;s edit history.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.12/admin/guides/user-management/placing-a-legal-hold-on-a-user-or-organization&quot;&gt;Place a legal hold on a user or organization&lt;/a&gt; to ensure that repositories they own cannot be permanently removed.&lt;/li&gt;
&lt;li&gt;Faster MySQL and Redis failover for high availability and clustering environment.&lt;/li&gt;
&lt;li&gt;View a user&#39;s public GPG key by visiting the &lt;code&gt;/login.gpg&lt;/code&gt; endpoint.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.github.com/enterprise/2.12/apps/&quot;&gt;GitHub Apps&lt;/a&gt; is available as an early access technical preview.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;Users could accept an organization invitation incorrectly sent to an unverified email address.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;ghe-es-search-repair&lt;/code&gt; script refused to run in a single instance environment.&lt;/li&gt;
&lt;li&gt;The OpenVPN log was not created if it did not already exist.&lt;/li&gt;
&lt;li&gt;The audit log rotation schedule was unintentionally set to weekly instead of daily.&lt;/li&gt;
&lt;li&gt;Archived repositories were not restored correctly in cluster environments.&lt;/li&gt;
&lt;li&gt;The Management Console was not correctly reloaded after a hotpatch is applied.&lt;/li&gt;
&lt;li&gt;Chrome attempted to automatically fill the SMTP and SNMP password fields with the password for the management console.&lt;/li&gt;
&lt;li&gt;Migration archives excluded users who created a protected branch and were subsequently removed from the organization.&lt;/li&gt;
&lt;li&gt;Git repair jobs repeatedly tried to access unavailable objects, causing high CPU usage.&lt;/li&gt;
&lt;li&gt;Searching for users or email addresses in the site admin tools did not return results for incomplete and fuzzy matches.&lt;/li&gt;
&lt;li&gt;The merge button got stuck in the &amp;quot;Checking for ability to merge&amp;quot; state.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-cluster-status&lt;/code&gt; returned invalid JSON when nodes were unavailable.&lt;/li&gt;
&lt;li&gt;Projects were incorrectly editable when the repositories was locked for migration.&lt;/li&gt;
&lt;li&gt;Users were unable to add collaborators to a personal project when the actor followed a large number of users.&lt;/li&gt;
&lt;li&gt;Pages failed to publish when the publishing source was configured as a path to a submodule.&lt;/li&gt;
&lt;li&gt;The followers and following count incorrectly considered suspended accounts.&lt;/li&gt;
&lt;li&gt;The squash and merge option was not resizing the text area to the height of the commit message.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;To restrict actions on raw content, including preventing popups, preventing the execution of plugins and scripts, and enforcing a same-origin policy, our content security policy (CSP) header for raw URLs now includes the &lt;a href=&quot;https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/sandbox&quot;&gt;sandbox attribute&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;babeld.log&lt;/code&gt; includes an &lt;code&gt;api_time&lt;/code&gt; key for internal timings on verifying authentication.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;codeload.log&lt;/code&gt; include a &lt;code&gt;api_ms&lt;/code&gt; attribute for internal timings.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;gitauth.log&lt;/code&gt; has been updated to add the &lt;code&gt;commit-refs&lt;/code&gt;, &lt;code&gt;verification-tokens&lt;/code&gt;, &lt;code&gt;pre-2fa&lt;/code&gt;, and &lt;code&gt;git-lfs-authenticate&lt;/code&gt; actions and include the &lt;code&gt;request_ip&lt;/code&gt; and &lt;code&gt;path_info&lt;/code&gt; metadata.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;GitHubMetadata&lt;/code&gt; GraphQL API object has been added.&lt;/li&gt;
&lt;li&gt;The meta RESTAPI endpoint has been updated to include &lt;code&gt;installed_version&lt;/code&gt; for the GitHub Enterprise version.&lt;/li&gt;
&lt;li&gt;Webhooks payloads have been updated to include two headers, &lt;code&gt;X-GitHub-Enterprise-Version&lt;/code&gt; and &lt;code&gt;X-GitHub-Enterprise-Host&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The git signing API is no longer behind a preview header.&lt;/li&gt;
&lt;li&gt;Outside collaborators will be counted in the team member count view in the site admin dashboard.&lt;/li&gt;
&lt;li&gt;The number of cards awaiting triage has been added to the project section of the site admin dashboard.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.12/admin/articles/command-line-utilities#ghe-nwo&quot;&gt;&lt;code&gt;ghe-nwo&lt;/code&gt;&lt;/a&gt; command-line utility can identify the repository owner from a repository id.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.12/admin/articles/command-line-utilities#ghe-version&quot;&gt;&lt;code&gt;ghe-version&lt;/code&gt;&lt;/a&gt; command-line utility returns the current GitHub Enterprise version number.&lt;/li&gt;
&lt;li&gt;Topic descriptions will render GitHub Flavored Markdown.&lt;/li&gt;
&lt;li&gt;Project notes character limit has been increased to 1024 from from 250.&lt;/li&gt;
&lt;li&gt;Project, webhook APIs &lt;code&gt;created_at&lt;/code&gt; and &lt;code&gt;updated_at&lt;/code&gt; fields have been updated to use a consistent and standard &lt;code&gt;YYYY-MM-DDTHH:MM:SSZ&lt;/code&gt; ISO 8601 format.&lt;/li&gt;
&lt;li&gt;GPG verification for commits are parallelized for faster performance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Backups and Disaster Recovery&lt;/h2&gt;
&lt;p&gt;GitHub Enterprise 2.12 requires at least &lt;a href=&quot;https://github.com/github/backup-utils&quot;&gt;GitHub Enterprise Backup Utilities&lt;/a&gt; 2.11.2 for &lt;a href=&quot;https://docs.github.com/enterprise/2.12/admin/guides/installation/backups-and-disaster-recovery/&quot;&gt;Backups and Disaster Recovery&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of Internet Explorer 11 support&lt;/h2&gt;
&lt;p&gt;Support for Internet Explorer 11 will be deprecated on September 13, 2018. There will be no changes in site functionality, but a warning banner will be displayed to Internet Explorer 11 users.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of VMware ESX 5.5 support&lt;/h2&gt;
&lt;p&gt;Support for &lt;a href=&quot;https://www.vmware.com/content/dam/digitalmarketing/vmware/en/pdf/support/product-lifecycle-matrix.pdf&quot;&gt;VMware ESX 5.5 will be deprecated on September 19, 2018&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.9&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.9 will be deprecated as of March 1, 2018.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.12/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;svn checkout may timeout while the repository data cache is being built. In most cases, subsequent svn checkout attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Changing the parent of a nested team can result in the nested team not receiving updated inherited permissions.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-12-19)&lt;/li&gt;
&lt;li&gt;GitHub Apps silently fail to be created when the name contains an underscore.&lt;/li&gt;
&lt;li&gt;Authentication graph is incorrectly empty because &lt;code&gt;auth.result.*&lt;/code&gt; metrics are missing and not forwarded to external collectd servers.&lt;/li&gt;
&lt;li&gt;Changes to legal hold state of a repository does not trigger an audit log event.&lt;/li&gt;
&lt;li&gt;After changing HTTP proxy configuration in the Management Console, webhooks do not use the settings unless &lt;code&gt;hookshot-resqued&lt;/code&gt; is restarted manually via SSH by running: &lt;code&gt;sudo systemctl restart hookshot-resqued&lt;/code&gt;. (updated 2017-12-19)&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order. (updated 2017-12-27)&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2017-12-27)&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong. (updated 2017-12-27)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-repl-status&lt;/code&gt; command-line utility incorrectly shows &lt;code&gt;TypeError: no implicit conversion of Symbol into Integer&lt;/code&gt; when there are repositories or gists with bad replica counts. (updated 2018-01-10)&lt;/li&gt;
&lt;li&gt;Reviewers and the &amp;quot;Review requested&amp;quot; status disappear on pull requests migrated with &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-01-12)&lt;/li&gt;
&lt;li&gt;Large API requests may trigger excessive logging in the exceptions log. (updated 2018-01-31)&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.  (updated 2018-02-14)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;li&gt;On a repository that&#39;s been locked for migration using &lt;code&gt;ghe-migrator&lt;/code&gt;, project boards are not exported. (updated 2018-05-07)&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 12 Dec 2017 16:00:32 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.12.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.12.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.6</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;Users could accept an organization invitation incorrectly sent to an unverified email address.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;ghe-es-search-repair&lt;/code&gt; script refused to run in a single instance environment.&lt;/li&gt;
&lt;li&gt;The OpenVPN log was not created if it did not already exist.&lt;/li&gt;
&lt;li&gt;The audit log rotation schedule was unintentionally set to weekly instead of daily.&lt;/li&gt;
&lt;li&gt;Archived repositories were not restored correctly in cluster environments.&lt;/li&gt;
&lt;li&gt;The management application was not correctly reloaded after a hotpatch is applied.&lt;/li&gt;
&lt;li&gt;Chrome attempted to automatically fill the SMTP and SNMP password fields with the password for the management console.&lt;/li&gt;
&lt;li&gt;Migration archives excluded users who created a protected branch and were subsequently removed from the organization.&lt;/li&gt;
&lt;li&gt;Git repair jobs repeatedly tried to access unavailable objects, causing high CPU usage.&lt;/li&gt;
&lt;li&gt;Searching for users or email addresses in the stafftools did not return results for incomplete and fuzzy matches.&lt;/li&gt;
&lt;li&gt;The merge button could get stuck in the &amp;quot;Checking for ability to merge&amp;quot; state.&lt;/li&gt;
&lt;li&gt;Rebuilding a search index—including during an upgrade to this version—could cause many exceptions to be logged to &lt;code&gt;/var/log/github/exceptions.log&lt;/code&gt;. The fast growth of this log file could cause the root disk to fill up. (updated 2017-12-20)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;To restrict actions on raw content, including preventing popups, preventing the execution of plugins and scripts, and enforcing a same-origin policy, our content security policy (CSP) header for raw URLs now includes the &lt;a href=&quot;https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/sandbox&quot;&gt;sandbox attribute&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Changing the parent of a nested team can result in the nested team not receiving updated inherited permissions.&lt;/li&gt;
&lt;li&gt;After changing HTTP proxy configuration in the Management Console, webhooks do not use the settings unless &lt;code&gt;hookshot-resqued&lt;/code&gt; is restarted manually via SSH by running: &lt;code&gt;sudo systemctl restart hookshot-resqued&lt;/code&gt;. (updated 2017-12-19)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-12-19)&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order. (updated 2017-12-20)&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2017-12-20)&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong. (updated 2017-12-20)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.  (updated 2018-02-14)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 05 Dec 2017 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.12</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;Users could accept an organization invitation incorrectly sent to an unverified email address.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Chrome attempted to automatically fill the SMTP and SNMP password fields with the password for the management console.&lt;/li&gt;
&lt;li&gt;Git repair jobs repeatedly tried to access unavailable objects, causing high CPU usage.&lt;/li&gt;
&lt;li&gt;Suspended users were suggested as pull request reviewers.&lt;/li&gt;
&lt;li&gt;Migration archives excluded users who created a protected branch and were subsequently removed from the organization.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;To restrict actions on raw content, including preventing popups, preventing the execution of plugins and scripts, and enforcing a same-origin policy, our content security policy (CSP) header for raw URLs now includes the &lt;a href=&quot;https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/sandbox&quot;&gt;sandbox attribute&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-12-19)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 05 Dec 2017 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.9.17</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;Users could accept an organization invitation incorrectly sent to an unverified email address.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Chrome attempted to automatically fill the SMTP and SNMP password fields with the password for the management console.&lt;/li&gt;
&lt;li&gt;Git repair jobs repeatedly tried to access unavailable objects, causing high CPU usage.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;To restrict actions on raw content, including preventing popups, preventing the execution of plugins and scripts, and enforcing a same-origin policy, our content security policy (CSP) header for raw URLs now includes the &lt;a href=&quot;https://developer.mozilla.org/en-US/docs/Web/HTTP/Headers/Content-Security-Policy/sandbox&quot;&gt;sandbox attribute&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 05 Dec 2017 16:00:29 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.9.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.9.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.5</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A configuration run could fail in high availability environments if Redis isn&#39;t ready.&lt;/li&gt;
&lt;li&gt;The open-vm-tools package, included in ESXi VM images, has been updated to 2.10.1.5 to address stability issues when performing snapshots.&lt;/li&gt;
&lt;li&gt;The audit log migration process could leave old indices in place which would prevent upgrading to 2.11.&lt;/li&gt;
&lt;li&gt;LDAP team sync could cause a noticeable increase in CPU usage when synchronizing large teams.&lt;/li&gt;
&lt;li&gt;Pull request comments were not exported with &lt;code&gt;ghe-migrator&lt;/code&gt; if the repository is locked.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GraphQL authenticated requests rate limit has been increased from 200 to 5,000.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Changing the parent of a nested team can result in the nested team not receiving updated inherited permissions.&lt;/li&gt;
&lt;li&gt;After changing HTTP proxy configuration in the Management Console, webhooks do not use the settings unless &lt;code&gt;hookshot-resqued&lt;/code&gt; is restarted manually via SSH by running: &lt;code&gt;sudo systemctl restart hookshot-resqued&lt;/code&gt;. (updated 2017-12-19)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-12-19)&lt;/li&gt;
&lt;li&gt;The merge button could get stuck in the &amp;quot;Checking for ability to merge&amp;quot; state. (updated 2017-12-20)&lt;/li&gt;
&lt;li&gt;Rebuilding a search index—including during an upgrade to this version—could cause many exceptions to be logged to &lt;code&gt;/var/log/github/exceptions.log&lt;/code&gt;. The fast growth of this log file could cause the root disk to fill up. (updated 2017-12-20)&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order. (updated 2017-12-20)&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2017-12-20)&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong. (updated 2017-12-20)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.  (updated 2018-02-14)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 21 Nov 2017 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.11</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The audit log migration process could leave old indices in place which would prevent upgrading to 2.11.&lt;/li&gt;
&lt;li&gt;LDAP team sync could cause a noticeable increase in CPU usage when synchronizing large teams.&lt;/li&gt;
&lt;li&gt;Pull request comments were not exported with ghe-migratior if the repository is locked.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-12-19)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 21 Nov 2017 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.9.16</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The audit log migration process could leave old indices in place which would prevent upgrading to 2.11.&lt;/li&gt;
&lt;li&gt;LDAP team sync could cause a noticeable increase in CPU usage when synchronizing large teams.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 21 Nov 2017 16:00:29 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.9.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.9.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.4</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: The TLS cipher list did not include ciphers that offer forward secrecy for legacy browsers.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Management Console password could not be reset using &lt;code&gt;ghe-set-password&lt;/code&gt; when the appliance is in recovery mode.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-diagnostics&lt;/code&gt; could output &lt;code&gt;Connection refused&lt;/code&gt; line items when Redis, Memcached, or Elasticsearch services aren&#39;t running.&lt;/li&gt;
&lt;li&gt;A pre-receive hook audit log search returned no results.&lt;/li&gt;
&lt;li&gt;SSH metrics were missing from the Management Console authentication graphs.&lt;/li&gt;
&lt;li&gt;Background job errors could cause Redis to consume large amounts of memory.&lt;/li&gt;
&lt;li&gt;The mobile view of the pull request dashboard displayed &amp;quot;No issues to show&amp;quot; instead of &amp;quot;No pull requests to show&amp;quot;.&lt;/li&gt;
&lt;li&gt;The site admin cache indicator always displayed the memcached service as being active.&lt;/li&gt;
&lt;li&gt;For a user or organization named &lt;code&gt;apps&lt;/code&gt;, the profile page at &lt;code&gt;/apps&lt;/code&gt; showed an integrations landing page and repository pages at &lt;code&gt;/apps/&amp;lt;repository&amp;gt;&lt;/code&gt; resulting in a &lt;code&gt;404 Not Found&lt;/code&gt; response due to a conflict with an internal URL. (updated 2017-11-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Changing the parent of a nested team can result in the nested team not receiving updated inherited permissions.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;After changing HTTP proxy configuration in the Management Console, webhooks do not use the settings unless &lt;code&gt;hookshot-resqued&lt;/code&gt; is restarted manually via SSH by running: &lt;code&gt;sudo systemctl restart hookshot-resqued&lt;/code&gt;. (updated 2017-12-19)&lt;/li&gt;
&lt;li&gt;The merge button could get stuck in the &amp;quot;Checking for ability to merge&amp;quot; state. (updated 2017-12-20)&lt;/li&gt;
&lt;li&gt;Rebuilding a search index—including during an upgrade to this version—could cause many exceptions to be logged to &lt;code&gt;/var/log/github/exceptions.log&lt;/code&gt;. The fast growth of this log file could cause the root disk to fill up. (updated 2017-12-20)&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order. (updated 2017-12-20)&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2017-12-20)&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong. (updated 2017-12-20)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.  (updated 2018-02-14)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 07 Nov 2017 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.10</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: The TLS cipher list did not include ciphers that offer forward secrecy for legacy browsers.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-repl-status-pages&lt;/code&gt; showed a critical status if run while a sync is in progress.&lt;/li&gt;
&lt;li&gt;The Management Console password could not be reset using &lt;code&gt;ghe-set-password&lt;/code&gt; when the appliance is in recovery mode.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-diagnostics&lt;/code&gt; could output &lt;code&gt;Connection refused&lt;/code&gt; line items when Redis, Memcached, or Elasticsearch services aren&#39;t running.&lt;/li&gt;
&lt;li&gt;Background job errors could cause Redis to consume large amounts of memory.&lt;/li&gt;
&lt;li&gt;Viewing a pull request could fail with a &lt;code&gt;500 Internal Server Error&lt;/code&gt; if it contained a review request from a deleted user.&lt;/li&gt;
&lt;li&gt;The mobile view of the pull request dashboard displayed &amp;quot;No issues to show&amp;quot; instead of &amp;quot;No pull requests to show&amp;quot;.&lt;/li&gt;
&lt;li&gt;The site admin cache indicator always displayed the memcached service as being active.&lt;/li&gt;
&lt;li&gt;Fetching a list of reviews from the API could have returned an empty page.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 07 Nov 2017 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.9.15</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: The TLS cipher list did not include ciphers that offer forward secrecy for legacy browsers.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-repl-status-pages&lt;/code&gt; showed a critical status if run while a sync is in progress.&lt;/li&gt;
&lt;li&gt;The Management Console password could not be reset using &lt;code&gt;ghe-set-password&lt;/code&gt; when the appliance is in recovery mode.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-diagnostics&lt;/code&gt; could output &lt;code&gt;Connection refused&lt;/code&gt; line items when Redis, Memcached, or Elasticsearch services aren&#39;t running.&lt;/li&gt;
&lt;li&gt;Background job errors could cause Redis to consume large amounts of memory.&lt;/li&gt;
&lt;li&gt;The mobile view of the pull request dashboard displayed &amp;quot;No issues to show&amp;quot; instead of &amp;quot;No pull requests to show&amp;quot;.&lt;/li&gt;
&lt;li&gt;The site admin cache indicator always displayed the memcached service as being active.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 07 Nov 2017 16:00:29 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.9.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.9.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.8.23</title>
					<description>&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.8&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.8 will be deprecated as of November 9, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: The TLS cipher list did not include ciphers that offer forward secrecy for legacy browsers.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-repl-status-pages&lt;/code&gt; showed a critical status if run while a sync is in progress.&lt;/li&gt;
&lt;li&gt;The Management Console password could not be reset using &lt;code&gt;ghe-set-password&lt;/code&gt; when the appliance is in recovery mode.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-diagnostics&lt;/code&gt; could output &lt;code&gt;Connection refused&lt;/code&gt; line items when Redis, Memcached, or Elasticsearch services aren&#39;t running.&lt;/li&gt;
&lt;li&gt;Background job errors could cause Redis to consume large amounts of memory.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 07 Nov 2017 16:00:28 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.8.23</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.8.23</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.3</title>
					<description>&lt;h2&gt;GitHub Enterprise includes protection from vulnerable, weak SSH keys (CVE-2017-15361)&lt;/h2&gt;
&lt;p&gt;In response to &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2017-15361&quot;&gt;CVE-2017-15361&lt;/a&gt;, certain SSH authentication RSA keys that were generated by some Yubikey 4 devices are vulnerable to private key factorization. Such keys are considered cryptographically weak and therefore in need of replacement. To help users avoid vulnerable keys, GitHub Enterprise has added capabilities to detect and reject them from being configured for user authentication. GitHub Enterprise now includes an administration utility, &lt;a href=&quot;https://docs.github.com/enterprise/2.11/admin/articles/command-line-utilities/#ghe-ssh-weak-fingerprints&quot;&gt;&lt;code&gt;ghe-ssh-weak-fingerprints&lt;/code&gt;&lt;/a&gt;, to enable admins to list any affected keys and, optionally, perform a bulk revocation.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.8.0 - 2.8.21&lt;/li&gt;
&lt;li&gt;2.9.0 - 2.9.13&lt;/li&gt;
&lt;li&gt;2.10.0 - 2.10.8&lt;/li&gt;
&lt;li&gt;2.11.0 - 2.11.2&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This vulnerability was found and reported internally and we have no evidence that it has been exploited in the wild.&lt;br /&gt;
We strongly recommend upgrading your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.8.22, 2.9.14, 2.10.9, or 2.11.3.&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have questions.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On Firefox browsers, the first page of some PDF files was blank when rendered.&lt;/li&gt;
&lt;li&gt;Hotpatching failed to retain maintenance mode after a hotpatch was applied.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;babeld&lt;/code&gt; service required a manual restart after a hotpatch was applied.&lt;/li&gt;
&lt;li&gt;SMTP port was still accepting TLSv1 even after disabling the TLSv1 protocol via the Management Console.&lt;/li&gt;
&lt;li&gt;With private mode enabled, using &lt;code&gt;git lfs locks&lt;/code&gt; to show the current locks on files tracked by Git LFS showed a user ID instead of a username.&lt;/li&gt;
&lt;li&gt;Activities were not shown on the dashboard for users without any repositories.&lt;/li&gt;
&lt;li&gt;Suspending all dormant users failed due to a serialization bug.&lt;/li&gt;
&lt;li&gt;Password reset emails included an inaccurate description of when the password reset link would expire.&lt;/li&gt;
&lt;li&gt;Migrating specific repositories with &lt;code&gt;ghe-migrator&lt;/code&gt; failed if an organization level Project referred to a repository that wasn&#39;t exported.&lt;/li&gt;
&lt;li&gt;Querying the Teams API endpoint could result in a 500 HTTP error if LDAP authentication was enabled.&lt;/li&gt;
&lt;li&gt;A &amp;quot;Select a user below to manage roles&amp;quot; team maintainers tip was shown for LDAP-mapped teams.&lt;/li&gt;
&lt;li&gt;Attempting to reset the password of a suspended user did not redirect the user to the suspended page.&lt;/li&gt;
&lt;li&gt;Restoring a deleted repository from the site admin dashboard did not correctly restore its wiki. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;Checking high availability replication status could incorrectly report &amp;quot;CRITICAL: git-hooks replication is behind the primary by 3600s&amp;quot;.&lt;/li&gt;
&lt;li&gt;The &amp;quot;Clear page cache&amp;quot; link in the site admin modal failed if the current page&#39;s URL included query string parameters.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks could succeed or fail incorrectly because the &lt;code&gt;$GITHUB_VIA&lt;/code&gt; environment variable contained a truncated value.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;For a user or organization named &lt;code&gt;apps&lt;/code&gt;, the profile page at &lt;code&gt;/apps&lt;/code&gt; shows an integrations landing page and repository pages at &lt;code&gt;/apps/&amp;lt;repository&amp;gt;&lt;/code&gt; result in a &lt;code&gt;404 Not Found&lt;/code&gt; response due to a conflict with an internal URL. (updated 2017-11-08)&lt;/li&gt;
&lt;li&gt;Changing the parent of a nested team can result in the nested team not receiving updated inherited permissions. (updated 2017-10-27)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;After changing HTTP proxy configuration in the Management Console, webhooks do not use the settings unless &lt;code&gt;hookshot-resqued&lt;/code&gt; is restarted manually via SSH by running: &lt;code&gt;sudo systemctl restart hookshot-resqued&lt;/code&gt;. (updated 2017-12-19)&lt;/li&gt;
&lt;li&gt;The merge button could get stuck in the &amp;quot;Checking for ability to merge&amp;quot; state. (updated 2017-12-20)&lt;/li&gt;
&lt;li&gt;Rebuilding a search index—including during an upgrade to this version—could cause many exceptions to be logged to &lt;code&gt;/var/log/github/exceptions.log&lt;/code&gt;. The fast growth of this log file could cause the root disk to fill up. (updated 2017-12-20)&lt;/li&gt;
&lt;li&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order. (updated 2017-12-20)&lt;/li&gt;
&lt;li&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2017-12-20)&lt;/li&gt;
&lt;li&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong. (updated 2017-12-20)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.  (updated 2018-02-14)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;li&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Note on Hotpatching&lt;/h2&gt;
&lt;p&gt;The hotpatch contains an upgrade to the kernel and related packages and requires a reboot. The reboot can be performed at a later time after applying the hotpatch.&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 25 Oct 2017 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.9</title>
					<description>&lt;h2&gt;GitHub Enterprise includes protection from vulnerable, weak SSH keys (CVE-2017-15361)&lt;/h2&gt;
&lt;p&gt;In response to &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2017-15361&quot;&gt;CVE-2017-15361&lt;/a&gt;, certain SSH authentication RSA keys that were generated by some Yubikey 4 devices are vulnerable to private key factorization. Such keys are considered cryptographically weak and therefore in need of replacement. To help users avoid vulnerable keys, GitHub Enterprise has added capabilities to detect and reject them from being configured for user authentication. GitHub Enterprise now includes an administration utility, &lt;a href=&quot;https://docs.github.com/enterprise/2.10/admin/articles/command-line-utilities/#ghe-ssh-weak-fingerprints&quot;&gt;&lt;code&gt;ghe-ssh-weak-fingerprints&lt;/code&gt;&lt;/a&gt;, to enable admins to list any affected keys and, optionally, perform a bulk revocation.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.8.0 - 2.8.21&lt;/li&gt;
&lt;li&gt;2.9.0 - 2.9.13&lt;/li&gt;
&lt;li&gt;2.10.0 - 2.10.8&lt;/li&gt;
&lt;li&gt;2.11.0 - 2.11.2&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This vulnerability was found and reported internally and we have no evidence that it has been exploited in the wild.&lt;br /&gt;
We strongly recommend upgrading your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.8.22, 2.9.14, 2.10.9, or 2.11.3.&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have questions.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On Firefox browsers, the first page of some PDF files was blank when rendered.&lt;/li&gt;
&lt;li&gt;With private mode enabled, using &lt;code&gt;git lfs locks&lt;/code&gt; to show the current locks on files tracked by Git LFS showed a user ID instead of a username.&lt;/li&gt;
&lt;li&gt;Checking high availability replication status could incorrectly report &amp;quot;CRITICAL: git-hooks replication is behind the primary by 3600s&amp;quot;.&lt;/li&gt;
&lt;li&gt;SMTP port was still accepting TLSv1 even after disabling the TLSv1 protocol via the Management Console.&lt;/li&gt;
&lt;li&gt;Migrating specific repositories with &lt;code&gt;ghe-migrator&lt;/code&gt; failed if an organization level Project referred to a repository that wasn&#39;t exported.&lt;/li&gt;
&lt;li&gt;Password reset emails included an inaccurate description of when the password reset link would expire.&lt;/li&gt;
&lt;li&gt;The &amp;quot;Clear page cache&amp;quot; link in the site admin modal failed if the current page&#39;s URL included query string parameters.&lt;/li&gt;
&lt;li&gt;Restoring a deleted repository from the site admin dashboard did not correctly restore its wiki. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 25 Oct 2017 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.9.14</title>
					<description>&lt;h2&gt;GitHub Enterprise includes protection from vulnerable, weak SSH keys (CVE-2017-15361)&lt;/h2&gt;
&lt;p&gt;In response to &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2017-15361&quot;&gt;CVE-2017-15361&lt;/a&gt;, certain SSH authentication RSA keys that were generated by some Yubikey 4 devices are vulnerable to private key factorization. Such keys are considered cryptographically weak and therefore in need of replacement. To help users avoid vulnerable keys, GitHub Enterprise has added capabilities to detect and reject them from being configured for user authentication. GitHub Enterprise now includes an administration utility, &lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/articles/command-line-utilities/#ghe-ssh-weak-fingerprints&quot;&gt;&lt;code&gt;ghe-ssh-weak-fingerprints&lt;/code&gt;&lt;/a&gt;, to enable admins to list any affected keys and, optionally, perform a bulk revocation.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.8.0 - 2.8.21&lt;/li&gt;
&lt;li&gt;2.9.0 - 2.9.13&lt;/li&gt;
&lt;li&gt;2.10.0 - 2.10.8&lt;/li&gt;
&lt;li&gt;2.11.0 - 2.11.2&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This vulnerability was found and reported internally and we have no evidence that it has been exploited in the wild.&lt;br /&gt;
We strongly recommend upgrading your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.8.22, 2.9.14, 2.10.9, or 2.11.3.&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have questions.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On Firefox browsers, the first page of some PDF files was blank when rendered.&lt;/li&gt;
&lt;li&gt;Checking high availability replication status could incorrectly report &amp;quot;CRITICAL: git-hooks replication is behind the primary by 3600s&amp;quot;.&lt;/li&gt;
&lt;li&gt;Password reset emails included an inaccurate description of when the password reset link would expire.&lt;/li&gt;
&lt;li&gt;The &amp;quot;Clear page cache&amp;quot; link in the site admin modal failed if the current page&#39;s URL included query string parameters.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 25 Oct 2017 16:00:29 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.9.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.9.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.8.22</title>
					<description>&lt;h2&gt;GitHub Enterprise includes protection from vulnerable, weak SSH keys (CVE-2017-15361)&lt;/h2&gt;
&lt;p&gt;In response to &lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2017-15361&quot;&gt;CVE-2017-15361&lt;/a&gt;, certain SSH authentication RSA keys that were generated by some Yubikey 4 devices are vulnerable to private key factorization. Such keys are considered cryptographically weak and therefore in need of replacement. To help users avoid vulnerable keys, GitHub Enterprise has added capabilities to detect and reject them from being configured for user authentication. GitHub Enterprise now includes an administration utility, &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/articles/command-line-utilities/#ghe-ssh-weak-fingerprints&quot;&gt;&lt;code&gt;ghe-ssh-weak-fingerprints&lt;/code&gt;&lt;/a&gt;, to enable admins to list any affected keys and, optionally, perform a bulk revocation.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.8.0 - 2.8.21&lt;/li&gt;
&lt;li&gt;2.9.0 - 2.9.13&lt;/li&gt;
&lt;li&gt;2.10.0 - 2.10.8&lt;/li&gt;
&lt;li&gt;2.11.0 - 2.11.2&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This vulnerability was found and reported internally and we have no evidence that it has been exploited in the wild.&lt;br /&gt;
We strongly recommend upgrading your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.8.22, 2.9.14, 2.10.9, or 2.11.3.&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have questions.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.8&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.8 will be deprecated as of November 9, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On Firefox browsers, the first page of some PDF files was blank when rendered.&lt;/li&gt;
&lt;li&gt;Checking high availability replication status could incorrectly report &amp;quot;CRITICAL: git-hooks replication is behind the primary by 3600s&amp;quot;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 25 Oct 2017 16:00:28 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.8.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.8.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.2</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Memory budgets computed for services were under-allocated leading to severe performance issues.&lt;/li&gt;
&lt;li&gt;LFS operations could fail with a slow LDAP server. The internal API timeout for LFS operations has been increased.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Fixes from 2.11.1 that was withdrawn due to a memory budget computation bug&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Elasticsearch could exceed recommended heap size. The memory budget is capped at a maximum of 32 GB.&lt;/li&gt;
&lt;li&gt;Upgrading a high availability environment from a 2.10 release to 2.11.0 failed with a &lt;code&gt;Failed drop elasticsearch scan file&lt;/code&gt; error.&lt;/li&gt;
&lt;li&gt;The default authenticated homepage would be blank for users that don&#39;t own or have direct collaboration permissions to any repositories.&lt;/li&gt;
&lt;li&gt;The repository owner was not displayed when configuring a pre-receive hook.&lt;/li&gt;
&lt;li&gt;Querying the Teams API with an invalid ID failed with a &#39;500 Internal Server Error&#39;.&lt;/li&gt;
&lt;li&gt;Outside collaborators were not added to a repository if mapped to a suspended user during the migration of a repository using &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded with through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;GitHub Enterprise clustering can not be configured without https.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Hotpatch upgrades 2.11.2 could fail reloading the babeld service. If the upgrade fails, run the following command from the affected appliance(s):&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo systemctl restart babeld
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;For a user or organization named &lt;code&gt;apps&lt;/code&gt;, the profile page at &lt;code&gt;/apps&lt;/code&gt; shows an integrations landing page and repository pages at &lt;code&gt;/apps/&amp;lt;repository&amp;gt;&lt;/code&gt; result in a &lt;code&gt;404 Not Found&lt;/code&gt; response due to a conflict with an internal URL. (updated 2017-10-24)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Changing the parent of a nested team can result in the nested team not receiving updated inherited permissions. (updated 2017-10-27)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;After changing HTTP proxy configuration in the Management Console, webhooks do not use the settings unless &lt;code&gt;hookshot-resqued&lt;/code&gt; is restarted manually via SSH by running: &lt;code&gt;sudo systemctl restart hookshot-resqued&lt;/code&gt;. (updated 2017-12-19)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The merge button could get stuck in the &amp;quot;Checking for ability to merge&amp;quot; state. (updated 2017-12-20)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Rebuilding a search index—including during an upgrade to this version—could cause many exceptions to be logged to &lt;code&gt;/var/log/github/exceptions.log&lt;/code&gt;. The fast growth of this log file could cause the root disk to fill up. (updated 2017-12-20)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order. (updated 2017-12-20)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2017-12-20)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong. (updated 2017-12-20)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.  (updated 2018-02-14)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Fri, 22 Sep 2017 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.8</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Memory budgets computed for services were under-allocated leading to severe performance issues.&lt;/li&gt;
&lt;li&gt;LFS operations could fail with a slow LDAP server. The internal API timeout for LFS operations has been increased.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Fixes from 2.10.7 that was withdrawn due to a memory budget computation bug&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Elasticsearch could exceed recommended heap size. The memory budget is capped at a maximum of 32 GB.&lt;/li&gt;
&lt;li&gt;The repository owner was not displayed when configuring a pre-receive hook.&lt;/li&gt;
&lt;li&gt;Querying the Teams API with an invalid ID failed with a &#39;500 Internal Server Error&#39;.&lt;/li&gt;
&lt;li&gt;Outside collaborators were not added to a repository if mapped to a suspended user during the migration of a repository using &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded with through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Fri, 22 Sep 2017 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.9.13</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Memory budgets computed for services were under-allocated leading to severe performance issues.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Fixes from 2.9.12 that was withdrawn due to a memory budget computation bug&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Elasticsearch could exceed recommended heap size. The memory budget is capped at a maximum of 32 GB.&lt;/li&gt;
&lt;li&gt;Querying the Teams API with an invalid ID failed with a &#39;500 Internal Server Error&#39;.&lt;/li&gt;
&lt;li&gt;Outside collaborators were not added to a repository if mapped to a suspended user during the migration of a repository using &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded with through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Fri, 22 Sep 2017 16:00:29 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.9.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.9.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.8.21</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Memory budgets computed for services were under-allocated leading to severe performance issues.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Fixes from 2.8.20 that was withdrawn due to a memory budget computation bug&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Elasticsearch could exceed recommended heap size. The memory budget is capped at a maximum of 32 GB.&lt;/li&gt;
&lt;li&gt;Querying the Teams API with an invalid ID failed with a &#39;500 Internal Server Error&#39;.&lt;/li&gt;
&lt;li&gt;Outside collaborators were not added to a repository if mapped to a suspended user during the migration of a repository using &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded with through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Fri, 22 Sep 2017 16:00:28 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.8.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.8.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.1</title>
					<description>&lt;h2&gt;Notice&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;The 2.11.1 patch release has been withdrawn due to the introduction of a major bug which caused memory budgets for services to be under-allocated. If you have already upgraded your appliance to GitHub Enterprise 2.11.1, please &lt;a href=&quot;https://enterprise.github.com/support&quot;&gt;contact support&lt;/a&gt; for assistance. (updated 2017-09-21)&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: A PDF with looping xref tables caused the PDF renderer to consume high amounts of CPU or hang a user&#39;s browser. This vulnerability was also patched in 2.11.0.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Elasticsearch could exceed recommended heap size. The memory budget is capped at a maximum of 32 GB.&lt;/li&gt;
&lt;li&gt;Upgrading a high availability environment from a 2.10 release to 2.11.0 failed with a &lt;code&gt;Failed drop elasticsearch scan file&lt;/code&gt; error.&lt;/li&gt;
&lt;li&gt;Users had a missing dashboard (i.e. default authenticated homepage) if they didn&#39;t own or have direct collaboration permissions to any repositories.&lt;/li&gt;
&lt;li&gt;The repository owner was not displayed when configuring a pre-receive hook.&lt;/li&gt;
&lt;li&gt;Querying the Teams API with an invalid ID failed with a &#39;500 Internal Server Error&#39;.&lt;/li&gt;
&lt;li&gt;Outside collaborators were not added to a repository if mapped to a suspended user during the migration of a repository using &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded with through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;GitHub Enterprise clustering can not be configured without https.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Hotpatch upgrades from 2.11.0 to 2.11.1 and configuration updates could fail reloading the babeld service. If the upgrade or configuration update fails, run the following command from the affected appliance(s): (updated 2017-09-21)&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo systemctl restart babeld
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;For a user or organization named &lt;code&gt;apps&lt;/code&gt;, the profile page at &lt;code&gt;/apps&lt;/code&gt; shows an integrations landing page and repository pages at &lt;code&gt;/apps/&amp;lt;repository&amp;gt;&lt;/code&gt; result in a &lt;code&gt;404 Not Found&lt;/code&gt; response due to a conflict with an internal URL. (updated 2017-10-24)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Changing the parent of a nested team can result in the nested team not receiving updated inherited permissions. (updated 2017-10-27)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;After changing HTTP proxy configuration in the Management Console, webhooks do not use the settings unless &lt;code&gt;hookshot-resqued&lt;/code&gt; is restarted manually via SSH by running: &lt;code&gt;sudo systemctl restart hookshot-resqued&lt;/code&gt;. (updated 2017-12-19)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The merge button could get stuck in the &amp;quot;Checking for ability to merge&amp;quot; state. (updated 2017-12-20)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Rebuilding a search index—including during an upgrade to this version—could cause many exceptions to be logged to &lt;code&gt;/var/log/github/exceptions.log&lt;/code&gt;. The fast growth of this log file could cause the root disk to fill up. (updated 2017-12-20)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order. (updated 2017-12-20)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2017-12-20)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong. (updated 2017-12-20)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.  (updated 2018-02-14)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 19 Sep 2017 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.7</title>
					<description>&lt;h2&gt;Notice&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;The 2.10.7 patch release has been withdrawn due to the introduction of a major bug which caused memory budgets for services to be under-allocated. If you have already upgraded your appliance to GitHub Enterprise 2.10.7, please &lt;a href=&quot;https://enterprise.github.com/support&quot;&gt;contact support&lt;/a&gt; for assistance. (updated 2017-09-21)&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: A PDF with looping xref tables caused the PDF renderer to consume high amounts of CPU or hang a user&#39;s browser.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Elasticsearch could exceed recommended heap size. The memory budget is capped at a maximum of 32 GB.&lt;/li&gt;
&lt;li&gt;The repository owner was not displayed when configuring a pre-receive hook.&lt;/li&gt;
&lt;li&gt;Querying the Teams API with an invalid ID failed with a &#39;500 Internal Server Error&#39;.&lt;/li&gt;
&lt;li&gt;Outside collaborators were not added to a repository if mapped to a suspended user during the migration of a repository using &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded with through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 19 Sep 2017 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.9.12</title>
					<description>&lt;h2&gt;Notice&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;The 2.9.12 patch release has been withdrawn due to the introduction of a major bug which caused memory budgets for services to be under-allocated. If you have already upgraded your appliance to GitHub Enterprise 2.9.12, please &lt;a href=&quot;https://enterprise.github.com/support&quot;&gt;contact support&lt;/a&gt; for assistance. (updated 2017-09-21)&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: A PDF with looping xref tables caused the PDF renderer to consume high amounts of CPU or hang a user&#39;s browser.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Elasticsearch could exceed recommended heap size. The memory budget is capped at a maximum of 32 GB.&lt;/li&gt;
&lt;li&gt;Querying the Teams API with an invalid ID failed with a &#39;500 Internal Server Error&#39;.&lt;/li&gt;
&lt;li&gt;Outside collaborators were not added to a repository if mapped to a suspended user during the migration of a repository using &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded with through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 19 Sep 2017 16:00:29 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.9.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.9.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.8.20</title>
					<description>&lt;h2&gt;Notice&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;The 2.8.20 patch release has been withdrawn due to the introduction of a major bug which caused memory budgets for services to be under-allocated. If you have already upgraded your appliance to GitHub Enterprise 2.8.20, please &lt;a href=&quot;https://enterprise.github.com/support&quot;&gt;contact support&lt;/a&gt; for assistance. (updated 2017-09-21)&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: A PDF with looping xref tables caused the PDF renderer to consume high amounts of CPU or hang a user&#39;s browser.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Elasticsearch could exceed recommended heap size. The memory budget is capped at a maximum of 32 GB.&lt;/li&gt;
&lt;li&gt;Querying the Teams API with an invalid ID failed with a &#39;500 Internal Server Error&#39;.&lt;/li&gt;
&lt;li&gt;Outside collaborators were not added to a repository if mapped to a suspended user during the migration of a repository using &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded with through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 19 Sep 2017 16:00:28 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.8.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.8.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.11.0</title>
					<description>&lt;h2&gt;Features&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Upgrade to Elasticsearch 2.4, which &lt;a href=&quot;https://docs.github.com/enterprise/2.11/admin/guides/installation/migrating-audit-logs-to-github-enterprise-2-11/&quot;&gt;impacts GitHub Enterprise upgrades&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Experience reduced downtime when you’re upgrading patch releases with &lt;a href=&quot;https://docs.github.com/enterprise/2.11/admin/guides/installation/upgrading-github-enterprise#upgrading-a-single-appliance-using-a-hotpatch/&quot;&gt;hotpatching&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Configure &lt;a href=&quot;https://docs.github.com/enterprise/2.11/admin/guides/installation/configuring-rate-limits#enabling-git-rate-limits/&quot;&gt;Git rate limiting with Governor&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Experience performance improvements in high-availability environments for geographically-distributed teams with &lt;a href=&quot;https://docs.github.com/enterprise/2.11/admin/guides/installation/about-geo-replication/&quot;&gt;geo-replication&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Enable &lt;a href=&quot;https://docs.github.com/enterprise/2.11/admin/articles/monitoring-using-snmp/&quot;&gt;SNMP v3 for extra security&lt;/a&gt;, including authentication and encryption using the user-based security model (USM).&lt;/li&gt;
&lt;li&gt;Increase the root partition size using an &lt;a href=&quot;https://docs.github.com/enterprise/2.11/admin/guides/installation/increasing-storage-capacity#increasing-the-root-partition-size-using-an-existing-appliance/&quot;&gt;existing appliance&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Limit the &lt;a href=&quot;https://docs.github.com/enterprise/2.11/admin/guides/user-management/using-ldap/&quot;&gt;creation of LDAP group mappings&lt;/a&gt; to organization or site administrators.&lt;/li&gt;
&lt;li&gt;Enable &lt;a href=&quot;https://docs.github.com/enterprise/2.11/admin/guides/user-management/using-ldap#enabling-ldap-certificate-verification/&quot;&gt;LDAP certificate verification&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Configure a replica appliance with a &lt;a href=&quot;https://docs.github.com/enterprise/2.11/admin/guides/installation/creating-a-high-availability-replica/&quot;&gt;new workflow&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Restrict the ability to &lt;a href=&quot;https://docs.github.com/enterprise/2.11/admin/guides/user-management/preventing-users-from-changing-a-repository-s-visibility/&quot;&gt;change repository visibility&lt;/a&gt; to organization owners.&lt;/li&gt;
&lt;li&gt;Display and delete image attachments from issues and pull requests using administrator tools.&lt;/li&gt;
&lt;li&gt;Create &lt;a href=&quot;https://docs.github.com/enterprise/2.11/user/articles/about-teams/#nested-teams&quot;&gt;multiple levels of nested teams&lt;/a&gt; within an organization to reflect your company or group’s hierarchy structure.&lt;/li&gt;
&lt;li&gt;Ask a specific team in your organization to &lt;a href=&quot;https://docs.github.com/enterprise/2.11/user/articles/requesting-a-pull-request-review/&quot;&gt;review a pull request&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Specify a &lt;a href=&quot;https://docs.github.com/enterprise/2.11/user/articles/about-codeowners/&quot;&gt;code owner&lt;/a&gt; for your project&#39;s code who will be automatically added as a reviewer for code they own.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.11/user/articles/opening-an-issue-from-code/&quot;&gt;Open issues directly from code&lt;/a&gt; within a file or pull request.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.11/user/articles/creating-a-permanent-link-to-a-code-snippet/&quot;&gt;Create a permanent link&lt;/a&gt; to a code snippet.&lt;/li&gt;
&lt;li&gt;Store important files for your project, like &lt;code&gt;README&lt;/code&gt; and &lt;code&gt;CONTRIBUTING&lt;/code&gt; files, in a &lt;a href=&quot;https://docs.github.com/enterprise/2.11/user/articles/about-readmes&quot;&gt;repository&#39;s &lt;code&gt;docs&lt;/code&gt; folder&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Create a &lt;a href=&quot;https://docs.github.com/enterprise/2.11/user/articles/adding-support-resources-to-your-project/&quot;&gt;&lt;code&gt;SUPPORT&lt;/code&gt; file&lt;/a&gt; for your project.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.11/user/articles/about-duplicate-issues-and-pull-requests/&quot;&gt;Mark and unmark&lt;/a&gt; issues and pull requests as duplicates.&lt;/li&gt;
&lt;li&gt;Use a saved reply to &lt;a href=&quot;https://docs.github.com/enterprise/2.11/user/articles/about-saved-replies&quot;&gt;mark an issue as a duplicate&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Navigate pull requests, including Python pull requests, using a &lt;a href=&quot;https://docs.github.com/enterprise/2.11/user/articles/finding-changed-methods-and-functions-in-a-pull-request/&quot;&gt;summary list of changed methods and functions&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Use &lt;a href=&quot;https://docs.github.com/enterprise/2.11/user/articles/generating-a-new-gpg-key/&quot;&gt;ED25519 keys&lt;/a&gt; for GPG.&lt;/li&gt;
&lt;li&gt;Use emojis and @mentions in your organization description.&lt;/li&gt;
&lt;li&gt;Clone your repository in Xcode.&lt;/li&gt;
&lt;li&gt;Use improved project board features, like advanced card filtering and task list summaries on cards.&lt;/li&gt;
&lt;li&gt;Search, show, and delete image attachments from &lt;code&gt;/stafftools&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to their latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: A PDF with looping xref tables caused the PDF renderer to consume high amounts of CPU or hang a user&#39;s browser. (updated 2017-09-19)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Commit contributions for a repository were not rebuilt when the &lt;code&gt;gh-pages&lt;/code&gt; branch is deleted.&lt;/li&gt;
&lt;li&gt;In a clustering environment, &lt;code&gt;ghe-cluster-config-node-init&lt;/code&gt; could fail silently.&lt;/li&gt;
&lt;li&gt;Adding a project note containing emoji would fail with a &#39;500 Internal Server Error&#39;.&lt;/li&gt;
&lt;li&gt;The Branch Merging API stripped lines starting with &lt;code&gt;#&lt;/code&gt; from commit messages.&lt;/li&gt;
&lt;li&gt;The user suggestion functionality could timeout when adding members to a very large team.&lt;/li&gt;
&lt;li&gt;Adding files with a blank content type, e.g. &lt;code&gt;.zip&lt;/code&gt;, &lt;code&gt;.docx&lt;/code&gt;, to conversations in issues and pull requests would fail.&lt;/li&gt;
&lt;li&gt;An empty Projects board was shown when Elasticsearch was unavailable or rebuilding indices after an upgrade.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The MIME types used by GitHub Pages match those used by the rest of the appliance.&lt;/li&gt;
&lt;li&gt;Syslog identifiers for various services have been made more explicit to make it easier to identify the service.&lt;/li&gt;
&lt;li&gt;The maximum number of multiplexed session for administrative SSH session has been increased to 100. This improves backup restores for clustering environments.&lt;/li&gt;
&lt;li&gt;NTLM has been removed from the SMTP configuration as an authentication protocol option. This was not working and is insecure.&lt;/li&gt;
&lt;li&gt;Releases are sorted first by date and then semantic version instead of lexicographically.&lt;/li&gt;
&lt;li&gt;Support for legacy high availability replication has been removed in 2.11. The default replication mechanism changed in 2.9 and this is now the only option in 2.11. This change has no impact unless legacy high availability replication was explicitly configured.&lt;/li&gt;
&lt;li&gt;OpenVPN, used in high availability and clustering environments, has been upgraded to 2.4 with support for ECDHE. This removes the need to generate DH parameters and speeds up initial OpenVPN setup.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks now run as an unprivileged dedicated user. This could impact running hooks if hooks write temporary data outside &lt;code&gt;/tmp&lt;/code&gt;. Running pre-receive hooks as an unprivileged dedicated user improves security by limiting access to the rest of the system from pre-receive hooks.&lt;/li&gt;
&lt;li&gt;GitHub Pages now uses Jekyll 3.5.1.&lt;/li&gt;
&lt;li&gt;GitHub Pages now uses &lt;a href=&quot;http://commonmark.org/&quot;&gt;Commonmark&lt;/a&gt; for Markdown rendering.&lt;/li&gt;
&lt;li&gt;Using &lt;a href=&quot;mailto:enterprise@github.com&quot;&gt;enterprise@github.com&lt;/a&gt; as the support address is no longer supported. Customers who have this email address configured need to change it to a valid internal support address or URL.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;samplicator&lt;/code&gt;, the utility that sends statistics to the metrics servers in cluster environments, now runs as an unprivileged dedicated user.&lt;/li&gt;
&lt;li&gt;The commit button text is now shown as &amp;quot;Commit merge&amp;quot; in the conflict editor to better communicate what is happening.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Backups and Disaster Recovery&lt;/h2&gt;
&lt;p&gt;GitHub Enterprise 2.11 requires at least &lt;a href=&quot;https://github.com/github/backup-utils&quot;&gt;GitHub Enterprise Backup Utilities&lt;/a&gt; 2.11.0 for &lt;a href=&quot;https://docs.github.com/enterprise/2.11/admin/guides/installation/backups-and-disaster-recovery/&quot;&gt;Backups and Disaster Recovery&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of Internet Explorer 11 support&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Support for Internet Explorer 11 will be deprecated on September 13, 2018.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of VMware ESX 5.5 support&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Support for VMware ESX 5.5 will be deprecated on September 13, 2018.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.8&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.8 will be deprecated as of November 9, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.11/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;GitHub Enterprise clustering can not be configured without https.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Upgrading a high availability environment from a 2.10 release to 2.11.0 could fail with the following error: (updated 2017-09-14)&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;```bash
$ ghe-upgrade ./github-enterprise-ami-2.11.0.pkg
*** verifying upgrade package signature...
725MiB 0:00:05 [ 141MiB/s] [===========================&amp;gt;] 100%
gpg: Signature made Tue 12 Sep 2017 05:03:10 AM UTC using RSA key ID 0D65D57A
gpg: Good signature from &amp;quot;GitHub Enterprise (Upgrade Package Key) &amp;lt;enterprise@github.com&amp;gt;&amp;quot;
*** applying update...
Scanning for incompatible Elasticsearch mappings...
waiting for ssh for [ghe-host-replica] to be available
ssh command returned 255
Failed drop elasticsearch scan file
```
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;If you encounter this error, run the following command from your primary or replica appliance before running &lt;code&gt;ghe-upgrade&lt;/code&gt; again:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;```bash
$ ghe-cluster-each -- sudo touch /data/user/common/es-scan-complete
```
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Users may have a missing dashboard (i.e. default authenticated homepage) if they don&#39;t own or have direct collaboration permissions to any repositories. If users are encountering this error, they can work around this issue by &lt;a href=&quot;https://docs.github.com/enterprise/2.11/user/articles/create-a-repo/&quot;&gt;creating a personal repository&lt;/a&gt;. (updated 2017-09-14)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;For a user or organization named &lt;code&gt;apps&lt;/code&gt;, the profile page at &lt;code&gt;/apps&lt;/code&gt; shows an integrations landing page and repository pages at &lt;code&gt;/apps/&amp;lt;repository&amp;gt;&lt;/code&gt; result in a &lt;code&gt;404 Not Found&lt;/code&gt; response due to a conflict with an internal URL. (updated 2017-10-24)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Changing the parent of a nested team can result in the nested team not receiving updated inherited permissions. (updated 2017-10-27)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;After changing HTTP proxy configuration in the Management Console, webhooks do not use the settings unless &lt;code&gt;hookshot-resqued&lt;/code&gt; is restarted manually via SSH by running: &lt;code&gt;sudo systemctl restart hookshot-resqued&lt;/code&gt;. (updated 2017-12-19)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The merge button could get stuck in the &amp;quot;Checking for ability to merge&amp;quot; state. (updated 2017-12-20)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Rebuilding a search index—including during an upgrade to this version—could cause many exceptions to be logged to &lt;code&gt;/var/log/github/exceptions.log&lt;/code&gt;. The fast growth of this log file could cause the root disk to fill up. (updated 2017-12-20)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Pull request review comments migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; are displayed in the wrong order. (updated 2017-12-20)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The pull request review request has users reversed, after migration with &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2017-12-20)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The comment count in the &amp;quot;Conversation&amp;quot; tab of a pull request migrated with &lt;code&gt;ghe-migrator&lt;/code&gt; can be wrong. (updated 2017-12-20)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The &lt;code&gt;gpgverify&lt;/code&gt; service may consume large amounts of CPU time even when not processing requests.  (updated 2018-02-14)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Nameid-format matching on SAML response is too strict when value is &amp;quot;unspecified&amp;quot;, which can cause an error with the &amp;quot;Another user already owns the account.&amp;quot; message if the IdP changes &lt;code&gt;NameID&lt;/code&gt;. (updated 2018-06-25)&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 13 Sep 2017 16:00:31 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.11.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.11.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.6</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: GitHub Services webhooks could be configured to use non-HTTP protocols.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repository read priority was incorrect after promoting a high availability replica and then re-introducing the original primary node as a replica. This can have a significant performance impact.&lt;/li&gt;
&lt;li&gt;Repository read performance could be severely impacted on very large instances under moderate load.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;admin:pre_receive_hook&lt;/code&gt; scope wasn&#39;t displayed when authorizing an Oauth application requesting this particular scope.&lt;/li&gt;
&lt;li&gt;Cloning or pushing repositories with Git LFS assets could fail with a &#39;500 Internal Server Error&#39;.&lt;/li&gt;
&lt;li&gt;Labels with encoded characters didn&#39;t link correctly with an issue or pull request timeline.&lt;/li&gt;
&lt;li&gt;Manual wiki repository repairs and scheduled repair jobs would fail.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;SSH keys added to a user via LDAP sync are automatically verified.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 05 Sep 2017 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.9.11</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: GitHub Services webhooks could be configured to use non-HTTP protocols.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repository read priority was incorrect after promoting a high availability replica and then re-introducing the original primary node as a replica. This can have a significant performance impact.&lt;/li&gt;
&lt;li&gt;Repository read performance could be severely impacted on very large instances under moderate load.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;admin:pre_receive_hook&lt;/code&gt; scope wasn&#39;t displayed when authorizing an Oauth application requesting this particular scope.&lt;/li&gt;
&lt;li&gt;Cloning or pushing repositories with Git LFS assets could fail with a &#39;500 Internal Server Error&#39;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;SSH keys added to a user via LDAP sync are automatically verified.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 05 Sep 2017 16:00:29 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.9.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.9.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.8.19</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: GitHub Services webhooks could be configured to use non-HTTP protocols.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;admin:pre_receive_hook&lt;/code&gt; scope wasn&#39;t displayed when authorizing an Oauth application requesting this particular scope.&lt;/li&gt;
&lt;li&gt;Cloning or pushing repositories with Git LFS assets could fail with a &#39;500 Internal Server Error&#39;.&lt;/li&gt;
&lt;li&gt;The Alambic service, which serves avatars, release downloads, and image attachments, could crash and not recover.&lt;/li&gt;
&lt;li&gt;Visiting a user&#39;s profile page whilst signed out failed with a &#39;500 Internal Server Error&#39;.&lt;/li&gt;
&lt;li&gt;Memcached could fail to start if another process claimed its port first.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;SSH keys added to a user via LDAP sync are automatically verified.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.8&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.8 will be deprecated as of November 9, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 05 Sep 2017 16:00:28 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.8.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.8.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.5</title>
					<description>&lt;h2&gt;Security fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;MySQL replication could fail to start if an old seed file was found.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-update-check --help&lt;/code&gt; would fail if &lt;code&gt;ghe-update-check&lt;/code&gt; was already running.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;longpoll&lt;/code&gt; service connections, which provide live updates to Issues and Pull Requests pages, could flood the instance leading to TCP connection exhaustion and excessive logging.&lt;/li&gt;
&lt;li&gt;Forking a repository on a promoted high availability replica node could take a very long time.&lt;/li&gt;
&lt;li&gt;Suspended users were suggested as potential reviewers.&lt;/li&gt;
&lt;li&gt;The SAML record dumping and updating utility, &lt;code&gt;ghe-saml-mapping-csv&lt;/code&gt;, was not exposed to the admin user.&lt;/li&gt;
&lt;li&gt;The @-mentions suggester didn&#39;t work in IE11.&lt;/li&gt;
&lt;li&gt;Ordered lists rendered incorrectly in custom messages on the sign in page.&lt;/li&gt;
&lt;li&gt;Using &lt;code&gt;ghe-migrator&lt;/code&gt;, protected branch settings were always migrating with push restrictions enabled.&lt;/li&gt;
&lt;li&gt;When two-factor authentication is required, LDAP team synchronization could fail if a member hasn&#39;t configured 2FA for their account.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The verbosity of logging for the &lt;code&gt;longpoll&lt;/code&gt; service, which provides live updates to Issues and Pull Requests pages, has been lowered.&lt;/li&gt;
&lt;li&gt;The conflict editor can be disabled for cross-repository pull requests.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 22 Aug 2017 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.9.10</title>
					<description>&lt;h2&gt;Security fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-update-check --help&lt;/code&gt; would fail if &lt;code&gt;ghe-update-check&lt;/code&gt; was already running.&lt;/li&gt;
&lt;li&gt;The @-mentions suggester didn&#39;t work in IE11.&lt;/li&gt;
&lt;li&gt;Ordered lists rendered incorrectly in custom messages on the sign in page.&lt;/li&gt;
&lt;li&gt;The SAML record dumping and updating utility, &lt;code&gt;ghe-saml-mapping-csv&lt;/code&gt;, was not exposed to the admin user.&lt;/li&gt;
&lt;li&gt;When two-factor authentication is required, LDAP team synchronization could fail if a member hasn&#39;t configured 2FA for their account.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The verbosity of logging for the &lt;code&gt;longpoll&lt;/code&gt; service, which provides live updates to Issues and Pull Requests pages, has been lowered.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 22 Aug 2017 16:00:29 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.9.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.9.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.8.18</title>
					<description>&lt;h2&gt;Security fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-update-check --help&lt;/code&gt; would fail if &lt;code&gt;ghe-update-check&lt;/code&gt; was already running.&lt;/li&gt;
&lt;li&gt;Ordered lists rendered incorrectly in custom messages on the sign in page.&lt;/li&gt;
&lt;li&gt;When two-factor authentication is required, LDAP team synchronization could fail if a member hasn&#39;t configured 2FA for their account.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The verbosity of logging for the &lt;code&gt;longpoll&lt;/code&gt; service, which provides live updates to Issues and Pull Requests pages, has been lowered.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 22 Aug 2017 16:00:28 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.8.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.8.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.4</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: Pages and Git have been updated to handle maliciously constructed &lt;code&gt;ssh://&lt;/code&gt; URLs during &lt;a href=&quot;https://docs.github.com/articles/using-submodules-with-pages/&quot;&gt;submodule cloning&lt;/a&gt;. This mitigates the vulnerability detailed in &lt;a href=&quot;https://public-inbox.org/git/xmqqh8xf482j.fsf@gitster.mtv.corp.google.com&quot;&gt;CVE-2017-100117&lt;/a&gt; which could have allowed an authenticated attacker to run arbitrary commands on a GitHub Enterprise environment through Pages builds. (updated 2017-08-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ping latency for High Availability replicas could be misreported in Enterprise Manage.&lt;/li&gt;
&lt;li&gt;Creating a support bundle failed with a “File exists” error if HAProxy logs have been rotated.&lt;/li&gt;
&lt;li&gt;Duplicate unicorn-worker related statistics were gathered by Collectd.&lt;/li&gt;
&lt;li&gt;ghe-repl-stop did not forcibly stop replication when the primary was offline.&lt;/li&gt;
&lt;li&gt;gpgverify could fail to start after an improper shutdown.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks with spaces in their paths failed to run.&lt;/li&gt;
&lt;li&gt;Links to diffs in the first 50 lines of a file did not properly expand context.&lt;/li&gt;
&lt;li&gt;Calling the update-pre-receive-hook-enforcement API could result in an application error.&lt;/li&gt;
&lt;li&gt;Deleted repositories were not purged after three months.&lt;/li&gt;
&lt;li&gt;Webhook requests ignored local search domains when resolving hosts, which could result in &amp;quot;Couldn&#39;t resolve host name&amp;quot; errors.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Added command-line tool to help map SAML records; ghe-saml-mapping-csv.&lt;/li&gt;
&lt;li&gt;Repository maintenance time and status is now shown on the repository network page in the Site Admin dashboard.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Using &lt;code&gt;ghe-migrator&lt;/code&gt;, protected branch settings are always migrating with push restrictions enabled. (updated 2017-08-01)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 01 Aug 2017 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.9.9</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: Pages and Git have been updated to handle maliciously constructed &lt;code&gt;ssh://&lt;/code&gt; URLs during &lt;a href=&quot;https://docs.github.com/articles/using-submodules-with-pages/&quot;&gt;submodule cloning&lt;/a&gt;. This mitigates the vulnerability detailed in &lt;a href=&quot;https://public-inbox.org/git/xmqqh8xf482j.fsf@gitster.mtv.corp.google.com&quot;&gt;CVE-2017-100117&lt;/a&gt; which could have allowed an authenticated attacker to run arbitrary commands on a GitHub Enterprise environment through Pages builds. (updated 2017-08-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;ghe-repl-stop did not forcibly stop replication when the primary was offline.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks with spaces in their paths failed to run.&lt;/li&gt;
&lt;li&gt;Calling the update-pre-receive-hook-enforcement API could result in an application error.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Added command-line tool to help map SAML records; ghe-saml-mapping-csv.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 01 Aug 2017 16:00:29 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.9.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.9.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.8.17</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: Pages and Git have been updated to handle maliciously constructed &lt;code&gt;ssh://&lt;/code&gt; URLs during &lt;a href=&quot;https://docs.github.com/articles/using-submodules-with-pages/&quot;&gt;submodule cloning&lt;/a&gt;. This mitigates the vulnerability detailed in &lt;a href=&quot;https://public-inbox.org/git/xmqqh8xf482j.fsf@gitster.mtv.corp.google.com&quot;&gt;CVE-2017-100117&lt;/a&gt; which could have allowed an authenticated attacker to run arbitrary commands on a GitHub Enterprise environment through Pages builds. (updated 2017-08-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Pre-receive hooks with spaces in their paths failed to run.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 01 Aug 2017 16:00:28 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.8.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.8.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.7.21</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: Pages and Git have been updated to handle maliciously constructed &lt;code&gt;ssh://&lt;/code&gt; URLs during &lt;a href=&quot;https://docs.github.com/articles/using-submodules-with-pages/&quot;&gt;submodule cloning&lt;/a&gt;. This mitigates the vulnerability detailed in &lt;a href=&quot;https://public-inbox.org/git/xmqqh8xf482j.fsf@gitster.mtv.corp.google.com&quot;&gt;CVE-2017-100117&lt;/a&gt; which could have allowed an authenticated attacker to run arbitrary commands on a GitHub Enterprise environment through Pages builds. (updated 2017-08-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Pre-receive hooks with spaces in their paths failed to run.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise 2.7&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.7 is now deprecated as of August 3, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Additional white spacing can sometimes be seen above the Admin center header.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 01 Aug 2017 16:00:27 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.7.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.7.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.3</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to their latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW:&lt;/strong&gt; OAuth application access tokens and personal access tokens weren&#39;t sanitized from support bundles.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The authentication graphs in the management console could be inaccurate and not display a legend due to incorrectly grouped and ordered keys.&lt;/li&gt;
&lt;li&gt;Authentication and application request/response graphs in the management console could fail to render when high availability replication was configured. The bug did not affect forwarding metrics to an external collectd server.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;/setup/replication&lt;/code&gt; in the management console returned a &#39;500 Internal Server Error&#39; when replication was configured.&lt;/li&gt;
&lt;li&gt;collectd metric paths could be truncated, which caused multiple write attempts to the same file for different metrics.&lt;/li&gt;
&lt;li&gt;Password reset emails incorrectly displayed reset links were valid for 24 hours when they are only valid for three hours.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks were incorrectly triggered on internal reference updates.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks could not be updated after moving to a new GitHub Enterprise instance, for example after failing over to a replica.&lt;/li&gt;
&lt;li&gt;Fetches or pushes that transferred more than 2 GB of data were incorrectly recorded as much larger in the logs for the Git proxy service, &lt;code&gt;babeld&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Users could receive a temporary &amp;quot;bad pack header&amp;quot; error when fetching a very large repository if the repository was being repacked at the same time.&lt;/li&gt;
&lt;li&gt;Suspended users could be assigned to issues.&lt;/li&gt;
&lt;li&gt;Users could delete organizations that contained repositories even if they were not permitted to delete repositories.&lt;/li&gt;
&lt;li&gt;Webhooks could send outdated data after editing an issue comment or changing the base branch of a pull request.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;Webhook requests incorrectly ignored local search domains when resolving hosts, which could result in &amp;quot;Couldn&#39;t resolve host name&amp;quot; errors.&lt;/del&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;When authenticating via SAML the NameID will be recorded instead of the custom username attribute value when a custom username attribute is defined.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-support-bundle&lt;/code&gt; command now honors the &lt;code&gt;http_proxy&lt;/code&gt; environment variable.&lt;/li&gt;
&lt;li&gt;The value of the &lt;code&gt;X-Forwarded-For&lt;/code&gt; header will now be recorded in the HAproxy log.&lt;/li&gt;
&lt;li&gt;The maximum number of HTTPS and websocket connections has been increased.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Background jobs are added to the &amp;quot;toggle_hidden_user_in_notifications&amp;quot; queue, but these jobs aren&#39;t processed on GitHub Enterprise. The entries are harmless but will show in &lt;code&gt;ghe-resque-info&lt;/code&gt; output and in management console graphs. (updated 2017-07-13)&lt;/li&gt;
&lt;li&gt;Webhook requests incorrectly ignore local search domains when resolving hosts, which can result in &amp;quot;Couldn&#39;t resolve host name&amp;quot; errors. (updated 2017-07-14)&lt;/li&gt;
&lt;li&gt;Creating a support bundle fails with a “File exists” error if HAProxy logs have been rotated. (updated 2017-07-24)&lt;/li&gt;
&lt;li&gt;Using &lt;code&gt;ghe-migrator&lt;/code&gt;, protected branch settings are always migrating with push restrictions enabled. (updated 2017-08-01)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We didn&#39;t include the fix for webhook requests incorrectly ignoring local search domains when resolving hosts in this release.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 12 Jul 2017 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.9.8</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to their latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW:&lt;/strong&gt; OAuth application access tokens and personal access tokens weren&#39;t sanitized from support bundles.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The authentication graphs in the management console could be inaccurate and not display a legend due to incorrectly grouped and ordered keys.&lt;/li&gt;
&lt;li&gt;collectd metric paths could be truncated, which caused multiple write attempts to the same file for different metrics.&lt;/li&gt;
&lt;li&gt;Password reset emails incorrectly displayed reset links were valid for 24 hours when they are only valid for three hours.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks were incorrectly triggered on internal reference updates.&lt;/li&gt;
&lt;li&gt;Fetches or pushes that transferred more than 2 GB of data were incorrectly recorded as much larger in the logs for the Git proxy service, &lt;code&gt;babeld&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Suspended users could be assigned to issues.&lt;/li&gt;
&lt;li&gt;Updates to pre-receive hooks would not work when a replica was promoted to primary.&lt;/li&gt;
&lt;li&gt;Fetches on very large repositories could fail when a repack was running concurrently.&lt;/li&gt;
&lt;li&gt;Webhooks could send outdated data when a comment on an issue was edited or when the base branch of a pull request was changed.&lt;/li&gt;
&lt;li&gt;Milestones and labels could not be applied while creating an issue.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;When authenticating via SAML the NameID will be recorded instead of the custom username attribute value when a custom username attribute is defined.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-support-bundle&lt;/code&gt; command now honors the &lt;code&gt;http_proxy&lt;/code&gt; environment variable.&lt;/li&gt;
&lt;li&gt;The value of the &lt;code&gt;X-Forwarded-For&lt;/code&gt; header will now be recorded in the HAproxy log.&lt;/li&gt;
&lt;li&gt;The maximum number of HTTPS and websocket connections has been increased.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Creating a support bundle fails with a “File exists” error if HAproxy logs have been rotated. (updated 2017-07-24)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 12 Jul 2017 16:00:29 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.9.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.9.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.8.16</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to their latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW:&lt;/strong&gt; OAuth application access tokens and personal access tokens weren&#39;t sanitized from support bundles.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The authentication graphs in the management console could be inaccurate and not display a legend due to incorrectly grouped and ordered keys.&lt;/li&gt;
&lt;li&gt;collectd metric paths could be truncated, which caused multiple write attempts to the same file for different metrics.&lt;/li&gt;
&lt;li&gt;Password reset emails incorrectly displayed reset links were valid for 24 hours when they are only valid for three hours.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks were incorrectly triggered on internal reference updates.&lt;/li&gt;
&lt;li&gt;Fetches or pushes that transferred more than 2 GB of data were incorrectly recorded as much larger in the logs for the Git proxy service, &lt;code&gt;babeld&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Users could receive a temporary &amp;quot;bad pack header&amp;quot; error when fetching a very large repository if the repository was being repacked at the same time.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;ghe-support-bundle&lt;/code&gt; command now honors the &lt;code&gt;http_proxy&lt;/code&gt; environment variable.&lt;/li&gt;
&lt;li&gt;The value of the &lt;code&gt;X-Forwarded-For&lt;/code&gt; header will now be recorded in the HAproxy log.&lt;/li&gt;
&lt;li&gt;The maximum number of HTTPS and websocket connections has been increased.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Creating a support bundle fails with a “File exists” error if HAproxy logs have been rotated. (updated 2017-07-24)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 12 Jul 2017 16:00:28 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.8.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.8.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.7.20</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to their latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW:&lt;/strong&gt; OAuth application access tokens and personal access tokens weren&#39;t sanitized from support bundles.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;collectd metric paths could be truncated, which caused multiple write attempts to the same file for different metrics.&lt;/li&gt;
&lt;li&gt;Password reset emails incorrectly displayed reset links were valid for 24 hours when they are only valid for three hours.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks could not be updated after moving to a new GitHub Enterprise instance, for example after failing over to a replica.&lt;/li&gt;
&lt;li&gt;Fetches or pushes that transferred more than 2 GB of data were incorrectly recorded as much larger in the logs for the Git proxy service, &lt;code&gt;babeld&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Users could receive a temporary &amp;quot;bad pack header&amp;quot; error when fetching a very large repository if the repository was being repacked at the same time.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;ghe-support-bundle&lt;/code&gt; command now honors the &lt;code&gt;http_proxy&lt;/code&gt; environment variable.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Additional white spacing can sometimes be seen above the Admin center header.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Creating a support bundle fails with a “File exists” error if HAproxy logs have been rotated. (updated 2017-07-24)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 12 Jul 2017 16:00:27 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.7.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.7.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.2</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to their latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Tokens were contained in support bundles when they were used in GET requests as a URL parameter.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;LDAP team sync failed when a duplicate fork was being restored.&lt;/li&gt;
&lt;li&gt;Users in large organizations and teams were unable to filter assignees and reviewers for issues and pull requests.&lt;/li&gt;
&lt;li&gt;Users in large organizations and teams were unable to @-mention users and teams in issue and pull request comments.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;/setup/replication&lt;/code&gt; in the Management console returned a &#39;500 Internal Server Error&#39; when replication was not running.&lt;/li&gt;
&lt;li&gt;In a clustering environment, collectd statistics weren&#39;t reported for the workers that handle RPC calls for Git.&lt;/li&gt;
&lt;li&gt;In a clustering environment, preflight checks failed when running &lt;code&gt;ghe-cluster-config-apply&lt;/code&gt; against an unresponsive HTTP proxy.&lt;/li&gt;
&lt;li&gt;In a clustering environment, a new node could silently fail to be added after &lt;code&gt;ghe-cluster-config-init&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;memcached&lt;/code&gt; collectd stats have been added.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;/setup/replication&lt;/code&gt; in the Management console returns a &#39;500 Internal Server Error&#39; when replication is configured. (updated 2017-06-27)&lt;/li&gt;
&lt;li&gt;Webhook requests incorrectly ignore local search domains when resolving hosts, which can result in &amp;quot;Couldn&#39;t resolve host name&amp;quot; errors. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;Background jobs are added to the &amp;quot;toggle_hidden_user_in_notifications&amp;quot; queue, but these jobs aren&#39;t processed on GitHub Enterprise. The entries are harmless but will show in &lt;code&gt;ghe-resque-info&lt;/code&gt; output and in management console graphs. (updated 2017-07-13)&lt;/li&gt;
&lt;li&gt;Using &lt;code&gt;ghe-migrator&lt;/code&gt;, protected branch settings are always migrating with push restrictions enabled. (updated 2017-08-01)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 20 Jun 2017 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.9.7</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to their latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Tokens were contained in support bundles when they were used in GET requests as a URL parameter.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a &lt;code&gt;404&lt;/code&gt; page with an appliance configured to use public mode and SAML, the &amp;quot;Sign in&amp;quot; button was illegible.&lt;/li&gt;
&lt;li&gt;Webhook &lt;code&gt;edited&lt;/code&gt; events could have incorrect &lt;code&gt;body&lt;/code&gt; values.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;contributions_backfill&lt;/code&gt; background jobs were enqueued on every additional push to a repository, even if it contained no commits from users of the appliance.&lt;/li&gt;
&lt;li&gt;LDAP team sync failed when a duplicate fork was being restored.&lt;/li&gt;
&lt;li&gt;Users in large organizations and teams were unable to filter assignees and reviewers for issues and pull requests.&lt;/li&gt;
&lt;li&gt;Users in large organizations and teams were unable to @-mention users and teams in issue and pull request comments.&lt;/li&gt;
&lt;li&gt;In a clustering environment, collectd statistics weren&#39;t reported for the workers that handle RPC calls for Git.&lt;/li&gt;
&lt;li&gt;In a clustering environment, preflight checks failed when running &lt;code&gt;ghe-cluster-config-apply&lt;/code&gt; against an unresponsive HTTP proxy.&lt;/li&gt;
&lt;li&gt;In a clustering environment, a new node could silently fail to be added after &lt;code&gt;ghe-cluster-config-init&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;memcached&lt;/code&gt; collectd stats have been added.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;It is not possible to select and apply labels or milestones when creating new issues. (updated 2017-07-04)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 20 Jun 2017 16:00:29 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.9.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.9.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.8.15</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to their latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Tokens were contained in support bundles when they were used in GET requests as a URL parameter.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a &lt;code&gt;404&lt;/code&gt; page with an appliance configured to use public mode and SAML, the &amp;quot;Sign in&amp;quot; button was illegible.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;contributions_backfill&lt;/code&gt; background jobs were enqueued on every additional push to a repository, even if it contained no commits from users of the appliance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 20 Jun 2017 16:00:28 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.8.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.8.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.7.19</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to their latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Tokens were contained in support bundles when they were used in GET requests as a URL parameter.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On a &lt;code&gt;404&lt;/code&gt; page with an appliance configured to use public mode and SAML, the &amp;quot;Sign in&amp;quot; button was illegible.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;contributions_backfill&lt;/code&gt; background jobs were enqueued on every additional push to a repository, even if it contained no commits from users of the appliance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Additional white spacing can sometimes be seen above the Admin center header.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 20 Jun 2017 16:00:27 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.7.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.7.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.1</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;p&gt;Packages have been updated to their latest security versions.&lt;/p&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;On an appliance configured to use LDAP with SSL or StartTLS, users could have failed to authenticate from the web interface or Git client with a 500 error. The failure occurred when the LDAP host uses a certificate that isn&#39;t signed by a trusted certificate authority (CA) or is invalid.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;github&lt;/code&gt;, &lt;code&gt;hookshot&lt;/code&gt;, &lt;code&gt;slumlord&lt;/code&gt;, and &lt;code&gt;render&lt;/code&gt; service logs weren&#39;t rotated which may cause the root disk to fill up.&lt;/li&gt;
&lt;li&gt;On a &lt;code&gt;404&lt;/code&gt; page with an appliance configured to use public mode and SAML, the &amp;quot;Sign in&amp;quot; button was illegible.&lt;/li&gt;
&lt;li&gt;Visiting &lt;code&gt;/explore&lt;/code&gt; could have been slow due to querying each repositories language.&lt;/li&gt;
&lt;li&gt;Requesting reviewers could have been slow when there are many users in the appliance.&lt;/li&gt;
&lt;li&gt;Webhook &lt;code&gt;edited&lt;/code&gt; events could have incorrect &lt;code&gt;body&lt;/code&gt; values.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;contributions_backfill&lt;/code&gt; background jobs were enqueued on every additional push to a repository, even if it contained no commits from users of the appliance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Webhook requests incorrectly ignore local search domains when resolving hosts, which can result in &amp;quot;Couldn&#39;t resolve host name&amp;quot; errors. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;Background jobs are added to the &amp;quot;toggle_hidden_user_in_notifications&amp;quot; queue, but these jobs aren&#39;t processed on GitHub Enterprise. The entries are harmless but will show in &lt;code&gt;ghe-resque-info&lt;/code&gt; output and in management console graphs. (updated 2017-07-13)&lt;/li&gt;
&lt;li&gt;Using &lt;code&gt;ghe-migrator&lt;/code&gt;, protected branch settings are always migrating with push restrictions enabled. (updated 2017-08-01)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 13 Jun 2017 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.10.0</title>
					<description>&lt;h2&gt;Features&lt;/h2&gt;
&lt;p&gt;With the new features added in GitHub Enterprise 2.10.0, you can:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Create your own tools with &lt;a href=&quot;https://developer.github.com/enterprise/2.10/v4/guides/intro-to-graphql/&quot;&gt;GitHub GraphQL API&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.10/user/articles/filtering-pull-requests-by-review-status/&quot;&gt;Filter pull requests by review status&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Use &lt;a href=&quot;https://docs.github.com/enterprise/2.10/user/articles/tracing-changes-in-a-file/&quot;&gt;improved blame&lt;/a&gt; when viewing the revision history of a file.&lt;/li&gt;
&lt;li&gt;Use &lt;a href=&quot;https://docs.github.com/enterprise/2.10/user/articles/about-topics/&quot;&gt;topics&lt;/a&gt; to explore repositories, find projects, and discover new solutions.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.10/user/articles/about-project-boards/&quot;&gt;View activity in your project board&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.10/user/articles/requesting-a-pull-request-review/&quot;&gt;Request a pull request review&lt;/a&gt; from suggested reviewers.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.10/user/articles/enabling-required-reviews-for-pull-requests/&quot;&gt;Restrict who can dismiss pull request reviews&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Search commits by the &lt;a href=&quot;https://docs.github.com/enterprise/2.10/user/articles/searching-commits/&quot;&gt;tree qualifier&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;View the audit log entry when an &lt;a href=&quot;https://docs.github.com/enterprise/2.10/user/articles/reviewing-the-audit-log-for-your-organization/&quot;&gt;avatar is changed&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.10/user/articles/closing-a-project/&quot;&gt;Close project boards&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Add &lt;a href=&quot;https://docs.github.com/enterprise/2.10/user/articles/adding-issues-and-pull-requests-to-a-project-board/&quot;&gt;issues and pull requests to a project board from the sidebar&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.10/user/articles/disabling-project-boards-in-your-organization/&quot;&gt;Disable project boards in your organization&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.10/user/articles/enabling-required-reviews-for-pull-requests/&quot;&gt;Dismiss stale pull request reviews&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Restrict &lt;a href=&quot;https://docs.github.com/enterprise/2.10/admin/guides/user-management/preventing-users-from-deleting-organization-repositories/&quot;&gt;repository deletion&lt;/a&gt; to site administrators or the organization owners.&lt;/li&gt;
&lt;li&gt;Disable &lt;a href=&quot;https://docs.github.com/enterprise/2.10/admin/guides/installation/configuring-tls&quot;&gt;insecure TLS protocols&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.10/admin/guides/installation/configuring-rate-limits&quot;&gt;Configure rate limits&lt;/a&gt; for the API and protect the instance from abusive behavior.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.10/admin/guides/migrations/exporting-the-github-enterprise-source-repositories&quot;&gt;Use the &lt;code&gt;ghe-migrator&lt;/code&gt; tool&lt;/a&gt; to migrate pull request reviews, pull request review comments, protected branches, project boards, multiple assignees, and repository deploy keys.&lt;/li&gt;
&lt;li&gt;Review which &lt;a href=&quot;https://docs.github.com/enterprise/2.10/admin/articles/site-admin-dashboard/#organization-reports&quot;&gt;organizations have two-factor authentication enabled&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/2328-git-lfs-2-0-0-released&quot;&gt;Use Git LFS 2.0.0&lt;/a&gt; client features like &lt;a href=&quot;https://github.com/git-lfs/git-lfs/wiki/File-Locking&quot;&gt;File Locking&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Identify whether a user is a first-time contributor in the issue or pull request comment.&lt;/li&gt;
&lt;li&gt;Mark a notification as read with keyboard shortcut &lt;code&gt;I&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The edited by badge includes the actor when updated by a different author.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Early Access Program&lt;/h2&gt;
&lt;p&gt;Be a part of the Early Access Program:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Request access to &lt;a href=&quot;https://enterprise.github.com/early_access/new?type=hotpatching&quot;&gt;hotpatching&lt;/a&gt; for reduced downtime when you’re upgrading patch releases.&lt;/li&gt;
&lt;li&gt;If your team is geographically-distributed, request access to &lt;a href=&quot;https://enterprise.github.com/early_access/new?type=georeplication&quot;&gt;geo-replication&lt;/a&gt; for better performance in high availability environments.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to their latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Users could fail to fork a repository if a conflicting fork was restored.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.github.com/enterprise/2.10/v3/repos/collaborators/#add-user-as-a-collaborator&quot;&gt;Adding a user as a collaborator&lt;/a&gt; via the API incorrectly sent an invitation without adding the user.&lt;/li&gt;
&lt;li&gt;Users associated with a large number of repositories were unable to view their organization pages.&lt;/li&gt;
&lt;li&gt;Image wiki tag failed to render images.&lt;/li&gt;
&lt;li&gt;Migrations failed when the branch name contained an invalid unicode character.&lt;/li&gt;
&lt;li&gt;Unauthenticated users visiting a public repository&#39;s fork were incorrectly redirected to a &lt;code&gt;404 Not Found&lt;/code&gt; page instead of the login page.&lt;/li&gt;
&lt;li&gt;After the parent repository has been deleted, the Git LFS objects from the forks were inaccessible.&lt;/li&gt;
&lt;li&gt;Deleting a repository containing files in LFS could cause the &#39;File storage&#39; within the Site Admin to show a temporary 500 error.&lt;/li&gt;
&lt;li&gt;After a user or organization renaming, search results incorrectly displayed the previous name.&lt;/li&gt;
&lt;li&gt;The hypervisor console welcome screen may have incorrectly displayed &lt;code&gt;sed: couldn&#39;t flush stdout: Broken pipe&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Repository and Gist synchronization could stall after restarting high availability replication.&lt;/li&gt;
&lt;li&gt;Archived repositories were not restorable from &lt;code&gt;/stafftools&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;/status&lt;/code&gt; endpoint on a high availability replica incorrectly returned &lt;code&gt;200 OK&lt;/code&gt; instead of &lt;code&gt;503 Service Unavailable&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Issues and pull requests were inaccessible if a high availability replica was rebooted before it was promoted.&lt;/li&gt;
&lt;li&gt;Graphs in the Management Console displayed the sum instead of an average value. As a result, graphs had incorrectly displayed an increasing metric over time.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks may have failed with &lt;code&gt;mount: can&#39;t find ...&lt;/code&gt; error messages.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-upgrade.log&lt;/code&gt; contained harmless &lt;code&gt;/proc/... No such file or directory&lt;/code&gt; messages.&lt;/li&gt;
&lt;li&gt;Gists were not rendering Jupyter notebook files. (updated 2017-06-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The default root partition has increased to 200GB.&lt;/li&gt;
&lt;li&gt;New &lt;a href=&quot;https://developer.github.com/enterprise/2.10/v3/&quot;&gt;REST API&lt;/a&gt; resources have been added.&lt;/li&gt;
&lt;li&gt;New &lt;a href=&quot;https://developer.github.com/enterprise/2.10/webhooks/&quot;&gt;webhook events&lt;/a&gt; have been added.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-*&lt;/code&gt; scripts require an &lt;code&gt;Enter&lt;/code&gt; keydown after the &lt;code&gt;[y/N]&lt;/code&gt; prompt.&lt;/li&gt;
&lt;li&gt;GPG keys with duplicate subkeys will be added using the most recent subkey.&lt;/li&gt;
&lt;li&gt;Replication will not always start after upgrading a replica, but will instead assume the pre-upgrade state (stopped or started) in order to prevent issues with multiple replicas starting concurrently when using the &lt;a href=&quot;https://enterprise.github.com/early_access/new?type=georeplication&quot;&gt;Early access program for geo distributed replicas&lt;/a&gt;. We recommend that you stop replication with &lt;code&gt;ghe-repl-stop&lt;/code&gt; and start replication with &lt;code&gt;ghe-repl-start&lt;/code&gt; after the replica upgrade is complete.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering environments require an additional TCP port to be opened for &lt;a href=&quot;https://docs.github.com/enterprise/2.10/admin/guides/clustering/network-configuration/#cluster-communication-ports&quot;&gt;LFS communication&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;GitHub Flavored Markdown, which is now compliant with &lt;a href=&quot;http://commonmark.org/&quot;&gt;CommonMark&lt;/a&gt;, is used to render repository markdown (e.g. &lt;code&gt;.md&lt;/code&gt;) files. (updated 2017-06-11)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.7&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.7 will be deprecated as of August 3, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.10/admin/guides/installation/upgrading-github-enterprise/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;On an appliance configured to use LDAP with SSL or StartTLS, users could fail to authenticate from the web interface or Git client with a 500 error. The failure occurs when the LDAP host uses a certificate that isn&#39;t signed by a trusted certificate authority (CA) or is invalid. (updated 2017-06-05)&lt;/li&gt;
&lt;li&gt;&lt;code&gt;github&lt;/code&gt;, &lt;code&gt;hookshot&lt;/code&gt;, &lt;code&gt;slumlord&lt;/code&gt;, and &lt;code&gt;render&lt;/code&gt; service logs aren&#39;t rotated which may cause the root disk to fill up. (updated 2017-06-08) .&lt;/li&gt;
&lt;li&gt;Webhook requests incorrectly ignore local search domains when resolving hosts, which can result in &amp;quot;Couldn&#39;t resolve host name&amp;quot; errors. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;Background jobs are added to the &amp;quot;toggle_hidden_user_in_notifications&amp;quot; queue, but these jobs aren&#39;t processed on GitHub Enterprise. The entries are harmless but will show in &lt;code&gt;ghe-resque-info&lt;/code&gt; output and in management console graphs. (updated 2017-07-13)&lt;/li&gt;
&lt;li&gt;Using &lt;code&gt;ghe-migrator&lt;/code&gt;, protected branch settings are always migrating with push restrictions enabled. (updated 2017-08-01)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;li&gt;Pull request reviewer usernames were not updated if a reviewer was mapped to a different username when migrating repositories using &lt;code&gt;ghe-migrator&lt;/code&gt;. (updated 2018-04-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Mon, 05 Jun 2017 16:00:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.10.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.10.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.9.6</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;After the parent repository has been deleted, the Git LFS objects from the forks were inaccessible.&lt;/li&gt;
&lt;li&gt;Deleting a repository containing files in LFS could cause the &#39;File storage&#39; within the Site Admin to show a temporary 500 error.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.github.com/enterprise/2.9/v3/repos/collaborators/#add-user-as-a-collaborator&quot;&gt;Adding a user as a collaborator&lt;/a&gt; via the API incorrectly sent an invitation without adding the user.&lt;/li&gt;
&lt;li&gt;After a user or organization renaming, search results incorrectly displayed the previous name.&lt;/li&gt;
&lt;li&gt;The hypervisor console welcome screen may have incorrectly displayed &lt;code&gt;sed: couldn&#39;t flush stdout: Broken pipe&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Repository and Gist synchronization could stall after restarting high availability replication.&lt;/li&gt;
&lt;li&gt;Archived repositories were not restorable from &lt;code&gt;/stafftools&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;/status&lt;/code&gt; endpoint on a high availability replica incorrectly returned &lt;code&gt;200 OK&lt;/code&gt; instead of &lt;code&gt;503 Service Unavailable&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Issues and pull requests were inaccessible if a high availability replica was rebooted before it was promoted.&lt;/li&gt;
&lt;li&gt;Graphs in the Management Console displayed the sum instead of an average value. As a result, graphs had incorrectly displayed an increasing metric over time.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks may have failed with &lt;code&gt;mount: can&#39;t find ...&lt;/code&gt; error messages.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-upgrade.log&lt;/code&gt; contained harmless &lt;code&gt;/proc/... No such file or directory&lt;/code&gt; messages.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Flavored Markdown, which is now compliant with &lt;a href=&quot;http://commonmark.org/&quot;&gt;CommonMark&lt;/a&gt;, is used to render repository markdown (e.g. &lt;code&gt;.md&lt;/code&gt;) files. (updated 2017-06-11)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 30 May 2017 16:00:29 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.9.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.9.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.8.14</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;After the parent repository has been deleted, the Git LFS objects from the forks were inaccessible.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.github.com/enterprise/2.8/v3/repos/collaborators/#add-user-as-a-collaborator&quot;&gt;Adding a user as a collaborator&lt;/a&gt; via the API incorrectly sent an invitation without adding the user.&lt;/li&gt;
&lt;li&gt;Deleting a repository containing files in LFS could cause the &#39;File storage&#39; within the Site Admin to show a temporary 500 error.&lt;/li&gt;
&lt;li&gt;The hypervisor console welcome screen may have incorrectly displayed &lt;code&gt;sed: couldn&#39;t flush stdout: Broken pipe&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Graphs in the Management Console displayed the sum instead of an average value. As a result, graphs had incorrectly displayed an increasing metric over time.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks may have failed with &lt;code&gt;mount: can&#39;t find ...&lt;/code&gt; error messages.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-upgrade.log&lt;/code&gt; contained harmless &lt;code&gt;/proc/... No such file or directory&lt;/code&gt; messages.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 30 May 2017 16:00:28 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.8.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.8.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.7.18</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;After the parent repository has been deleted, the Git LFS objects from the forks were inaccessible.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.github.com/enterprise/2.7/v3/repos/collaborators/#add-user-as-a-collaborator&quot;&gt;Adding a user as a collaborator&lt;/a&gt; via the API incorrectly sent an invitation without adding the user.&lt;/li&gt;
&lt;li&gt;Graphs in the Management Console displayed the sum instead of an average value. As a result, graphs had incorrectly displayed an increasing metric over time.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-upgrade.log&lt;/code&gt; contained harmless &lt;code&gt;/proc/... No such file or directory&lt;/code&gt; messages.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Additional white spacing can sometimes be seen above the Admin center header.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 30 May 2017 16:00:27 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.7.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.7.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.9.5</title>
					<description>&lt;h2&gt;Note about Git LFS v2.1.1&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; security fix for the Git LFS client was released on 19 May. The remote code execution vulnerability can be exploited if:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;a repository contains a &lt;code&gt;.lfsconfig&lt;/code&gt; with:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;  ...
    url = ssh://-oProxyCommand=command
  ...
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;a user clones the malicious repository with a vulnerable Git LFS client&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This vulnerability exists in the Git LFS client and &lt;strong&gt;not&lt;/strong&gt; GitHub Enterprise. However, we strongly encourage all users of GitHub Enterprise to upgrade their Git LFS client to v2.1.1 (or greater) from &lt;a href=&quot;https://git-lfs.github.com/&quot;&gt;https://git-lfs.github.com/&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have any questions.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; GitHub Enterprise supports broadcasting messages directly on the application with &lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/articles/command-line-utilities/#ghe-announce&quot;&gt;&lt;code&gt;ghe-announce&lt;/code&gt;&lt;/a&gt; and &lt;em&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/guides/user-management/creating-a-custom-sign-in-message/&quot;&gt;Creating a custom sign in message&lt;/a&gt;&lt;/em&gt;.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;This release and previous releases of GitHub Enterprise are not affected by the Git shell vulnerability announced 10 May 2017 (CVE-2017-8386).&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Memcached could fail to start if another process claimed its port first.&lt;/li&gt;
&lt;li&gt;A high availability replica could fail to connect to the primary after upgrading.&lt;/li&gt;
&lt;li&gt;When LDAP Sync is enabled, only organization owners could search the LDAP directory for groups when creating a new team.&lt;/li&gt;
&lt;li&gt;With SAML authentication configured, and the IdP set to assert administrator status, the user promotion/demotion button on a user&#39;s Site Admin page was shown as disabled but was still clickable and useable.&lt;/li&gt;
&lt;li&gt;In a clustering environment, &lt;code&gt;ghe-cluster-status&lt;/code&gt; would use the configured proxy when querying each node.&lt;/li&gt;
&lt;li&gt;In a clustering environment, restoring a backup to a cluster not meeting the minimum recommended number of &lt;code&gt;pages-server&lt;/code&gt; and &lt;code&gt;storage-server&lt;/code&gt; nodes would fail.&lt;/li&gt;
&lt;li&gt;Pagination of a webhook&#39;s &#39;Recent Deliveries&#39; was not enabled, limiting access to the last ten deliveries.&lt;/li&gt;
&lt;li&gt;High availability replication on 2.9.0-2.9.4 would not synchronize all Git data if the replica node has been offline for more than 90 minutes. Those failed synchronizations may not be reported by &lt;code&gt;ghe-repl-status&lt;/code&gt;. We strongly recommend upgrading to 2.9.5 or later before promoting a replica. (updated 2017-05-16)&lt;/li&gt;
&lt;li&gt;A high availability replica could report a warning that alambic replication is behind the primary because deleting objects such as release assets or avatars did not remove their corresponding database entries. (updated 2017-05-25)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The GitHub Enterprise version is shown on the hypervisor welcome console.&lt;/li&gt;
&lt;li&gt;The SAML authentication logs no longer contain debug information by default. Debugging information can be enabled in the Admin Center.&lt;/li&gt;
&lt;li&gt;Organizations are sorted alphabetically when selecting repository owner when creating a new repository.&lt;/li&gt;
&lt;li&gt;In a clustering environment, a failure to retrieve a support bundle from a node is reported as an error. It was reported as a warning.&lt;/li&gt;
&lt;li&gt;GitHub Flavored Markdown, which is now compliant with &lt;a href=&quot;http://commonmark.org/&quot;&gt;CommonMark&lt;/a&gt;, is used to render repository markdown (e.g. &lt;code&gt;.md&lt;/code&gt;) files. (updated 2017-06-11)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Deleting a repository containing files in LFS can cause the &#39;File storage&#39; within the Site Admin to show a temporary 500 error.&lt;/li&gt;
&lt;li&gt;Graphs in the Management Console are displaying the sum instead of an average value. As a result, graphs may incorrectly show an increasing metric over time. (updated 2017-05-17)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 16 May 2017 16:00:29 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.9.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.9.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.8.13</title>
					<description>&lt;h2&gt;Note about Git LFS v2.1.1&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; security fix for the Git LFS client was released on 19 May. The remote code execution vulnerability can be exploited if:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;a repository contains a &lt;code&gt;.lfsconfig&lt;/code&gt; with:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;  ...
    url = ssh://-oProxyCommand=command
  ...
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;a user clones the malicious repository with a vulnerable Git LFS client&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This vulnerability exists in the Git LFS client and &lt;strong&gt;not&lt;/strong&gt; GitHub Enterprise. However, we strongly encourage all users of GitHub Enterprise to upgrade their Git LFS client to v2.1.1 (or greater) from &lt;a href=&quot;https://git-lfs.github.com/&quot;&gt;https://git-lfs.github.com/&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have any questions.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; GitHub Enterprise supports broadcasting messages directly on the application with &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/articles/command-line-utilities/#ghe-announce&quot;&gt;&lt;code&gt;ghe-announce&lt;/code&gt;&lt;/a&gt; and &lt;em&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/user-management/creating-a-custom-sign-in-message/&quot;&gt;Creating a custom sign in message&lt;/a&gt;&lt;/em&gt;.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;This release and previous releases of GitHub Enterprise are not affected by the Git shell vulnerability announced 10 May 2017 (CVE-2017-8386).&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;When LDAP Sync is enabled, only organization owners could search the LDAP directory for groups when creating a new team.&lt;/li&gt;
&lt;li&gt;Deleting a repository containing files in LFS could cause the &#39;File storage&#39; within the Site Admin to show a temporary 500 error.&lt;/li&gt;
&lt;li&gt;In a clustering environment, &lt;code&gt;ghe-cluster-status&lt;/code&gt; would use the configured proxy when querying each node.&lt;/li&gt;
&lt;li&gt;In a clustering environment, restoring a backup to a cluster not meeting the minimum recommended number of &lt;code&gt;pages-server&lt;/code&gt; and &lt;code&gt;storage-server&lt;/code&gt; nodes would fail.&lt;/li&gt;
&lt;li&gt;Pagination of a webhook&#39;s &#39;Recent Deliveries&#39; was not enabled, limiting access to the last ten deliveries.&lt;/li&gt;
&lt;li&gt;In clustering and high availability environments, the disk usage percentage and tooltip in the admin bar were incorrect.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The GitHub Enterprise version is shown on the hypervisor welcome console.&lt;/li&gt;
&lt;li&gt;The SAML authentication logs no longer contain debug information by default. Debugging information can be enabled in the Admin Center.&lt;/li&gt;
&lt;li&gt;In a clustering environment, a failure to retrieve a support bundle from a node is reported as an error. It was reported as a warning.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 16 May 2017 16:00:28 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.8.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.8.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.7.17</title>
					<description>&lt;h2&gt;Note about Git LFS v2.1.1&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; security fix for the Git LFS client was released on 19 May. The remote code execution vulnerability can be exploited if:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;a repository contains a &lt;code&gt;.lfsconfig&lt;/code&gt; with:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;  ...
    url = ssh://-oProxyCommand=command
  ...
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;a user clones the malicious repository with a vulnerable Git LFS client&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This vulnerability exists in the Git LFS client and &lt;strong&gt;not&lt;/strong&gt; GitHub Enterprise. However, we strongly encourage all users of GitHub Enterprise to upgrade their Git LFS client to v2.1.1 (or greater) from &lt;a href=&quot;https://git-lfs.github.com/&quot;&gt;https://git-lfs.github.com/&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have any questions.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; GitHub Enterprise supports broadcasting messages directly on the application with &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/articles/command-line-utilities/#ghe-announce&quot;&gt;&lt;code&gt;ghe-announce&lt;/code&gt;&lt;/a&gt; and &lt;em&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/user-management/creating-a-custom-sign-in-message/&quot;&gt;Creating a custom sign in message&lt;/a&gt;&lt;/em&gt;.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;This release and previous releases of GitHub Enterprise are not affected by the Git shell vulnerability announced 10 May 2017 (CVE-2017-8386).&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In a clustering environment, restoring a backup to a cluster not meeting the minimum recommended number of &lt;code&gt;pages-server&lt;/code&gt; and &lt;code&gt;storage-server&lt;/code&gt; nodes would fail.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The SAML authentication logs no longer contain debug information by default. Debugging information can be enabled in the Admin Center.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Additional white spacing can sometimes be seen above the Admin center header.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 16 May 2017 16:00:27 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.7.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.7.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.9.4</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: When using 2FA, the recovery codes could be brute forced on browsers that do not implement the &lt;code&gt;X-Content-Type-Options&lt;/code&gt; HTTP header correctly.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Service hooks were blocked from accessing the API endpoint of the local instance.&lt;/li&gt;
&lt;li&gt;Processes could be leaked if Collectd exited unexpectedly.&lt;/li&gt;
&lt;li&gt;Job queues could not be paused if the workers serviced multiple queues.&lt;/li&gt;
&lt;li&gt;Site administrators could experience a &#39;500 Internal Server Error&#39; after viewing the history for a file path containing Japanese characters.&lt;/li&gt;
&lt;li&gt;Fetching a list of pull request reviews via the API could fail with &#39;422 Unprocessable Entity&#39; or &#39;500 Internal Server Error&#39; errors.&lt;/li&gt;
&lt;li&gt;Git LFS files were not rendered when private mode is disabled.&lt;/li&gt;
&lt;li&gt;In cluster mode, restoring backups could hang indefinitely.&lt;/li&gt;
&lt;li&gt;Custom sysctl settings were not taking effect when saving the settings.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Support bundles are now built and stored in &lt;code&gt;/data/user/tmp&lt;/code&gt; to preserve free space on the root filesystem.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;/status&lt;/code&gt; endpoint can be queried over HTTP.&lt;/li&gt;
&lt;li&gt;GitHub Flavored Markdown, which is now compliant with &lt;a href=&quot;http://commonmark.org/&quot;&gt;CommonMark&lt;/a&gt;, is used to render repository markdown (e.g. &lt;code&gt;.md&lt;/code&gt;) files. (updated 2017-06-11)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise 2.6&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.6 is now deprecated as of April 26, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;Graphs in the Management Console are displaying the sum instead of an average value. As a result, graphs may incorrectly show an increasing metric over time. (updated 2017-05-17)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 02 May 2017 16:00:29 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.9.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.9.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.8.12</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: When using 2FA, the recovery codes could be brute forced on browsers that do not implement the &lt;code&gt;X-Content-Type-Options&lt;/code&gt; HTTP header correctly.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Service hooks were blocked from accessing the API endpoint of the local instance.&lt;/li&gt;
&lt;li&gt;Processes could be leaked if Collectd exited unexpectedly.&lt;/li&gt;
&lt;li&gt;Custom sysctl settings were not taking effect when saving the settings.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Support bundles are now built and stored in &lt;code&gt;/data/user/tmp&lt;/code&gt; to preserve free space on the root filesystem.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise 2.6&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.6 is now deprecated as of April 26, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 02 May 2017 16:00:28 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.8.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.8.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.7.16</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: When using 2FA, the recovery codes could be brute forced on browsers that do not implement the &lt;code&gt;X-Content-Type-Options&lt;/code&gt; HTTP header correctly.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Service hooks were blocked from accessing the API endpoint of the local instance.&lt;/li&gt;
&lt;li&gt;Processes could be leaked if Collectd exited unexpectedly.&lt;/li&gt;
&lt;li&gt;Custom sysctl settings were not taking effect when saving the settings.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Support bundles are now built and stored in &lt;code&gt;/data/user/tmp&lt;/code&gt; to preserve free space on the root filesystem.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise 2.6&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.6 is now deprecated as of April 26, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Additional white spacing can sometimes be seen above the Admin center header.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 02 May 2017 16:00:27 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.7.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.7.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.9.3</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Local privileged MySQL credentials and Alambic HMAC/API keys were exposed in log files included in the support bundle.&lt;/li&gt;
&lt;li&gt;None of the currently supported releases of GitHub Enterprise are affected by the Linux kernel UDP remote code execution vulnerability issued 4 April 2017 (&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2016-10229&quot;&gt;CVE-2016-10229&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;An issue or pull request comment containing the string &amp;quot;User-Agent: GitHub-Hookshot&amp;quot; incorrectly triggered a firewall rule that caused an internal server error on several pages, including the author&#39;s profile page.&lt;/li&gt;
&lt;li&gt;Collectd statistics were collected for the temporary pre-receive hook environment mount points.&lt;/li&gt;
&lt;li&gt;Users could be added to a team if they don&#39;t satisfy the Organization&#39;s 2FA requirements.&lt;/li&gt;
&lt;li&gt;Very large release or Git LFS assets failed to replicate due to a timeout in a high availability environment.&lt;/li&gt;
&lt;li&gt;In a clustering environment, several services failed to start following a reboot.&lt;/li&gt;
&lt;li&gt;In a clustering environment, configuring multiple nodes in parallel could lead to nodes overwriting each other&#39;s MySQL seed data.&lt;/li&gt;
&lt;li&gt;In clustering and high availability environments, the disk usage percentage and tooltip in the admin bar were incorrect.&lt;/li&gt;
&lt;li&gt;Attempts to authenticate via LDAP, would result in /var/log/github/auth.log log entries with &lt;code&gt;via token&lt;/code&gt; repeated many times.&lt;/li&gt;
&lt;li&gt;A suggested branch name of &amp;quot;null&amp;quot; was displayed when using IE11 or Microsoft Edge browsers.&lt;/li&gt;
&lt;li&gt;Users were referred to the GitHub.com status page when a repository was offline.&lt;/li&gt;
&lt;li&gt;Pushes to a repository in a high availability environment could fail with &lt;code&gt;! [remote rejected] master -&amp;gt; master (missing necessary objects)&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;New repositories created whilst a high availability replica was stopped were not created on disk and were marked offline.&lt;/li&gt;
&lt;li&gt;The Management Console did not become accessible after promoting a high availability replica.&lt;/li&gt;
&lt;li&gt;Saving custom messages containing UTF-8 characters in the Admin Center failed with a 500 error.&lt;/li&gt;
&lt;li&gt;HTTP clone URLs which include the username did not cause Git to prompt for credentials when password authentication is disabled.&lt;/li&gt;
&lt;li&gt;During maintenance mode for a high availability environment, the &lt;code&gt;/setup/maintenance&lt;/code&gt; page did not list active processes.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;/status&lt;/code&gt; endpoint on a high availability replica incorrectly returned &lt;code&gt;200 OK&lt;/code&gt; instead of &lt;code&gt;503 Service Unavailable&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;jq&lt;/code&gt; utility has been added to the default pre-receive hook environment.&lt;/li&gt;
&lt;li&gt;More colors are used in the monitoring graphs in a high availability environment, making them more legible.&lt;/li&gt;
&lt;li&gt;Pinned Organization repositories can now only be modified by Organization owners.&lt;/li&gt;
&lt;li&gt;Backups of cluster environments with a large number of archived repositories has been optimized for improved performance.&lt;/li&gt;
&lt;li&gt;GitHub Flavored Markdown, which is now compliant with &lt;a href=&quot;http://commonmark.org/&quot;&gt;CommonMark&lt;/a&gt;, is used to render repository markdown (e.g. &lt;code&gt;.md&lt;/code&gt;) files. (updated 2017-06-11)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.6&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.6 will be deprecated as of April 26, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Site administrators can experience a &lt;code&gt;500 Internal Server Error&lt;/code&gt; after viewing the history for a file path containing Japanese characters.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 18 Apr 2017 16:00:29 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.9.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.9.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.8.11</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Local privileged MySQL credentials and Alambic HMAC/API keys were exposed in log files included in the support bundle.&lt;/li&gt;
&lt;li&gt;None of the currently supported releases of GitHub Enterprise are affected by the Linux kernel UDP remote code execution vulnerability issued 4 April 2017 (&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2016-10229&quot;&gt;CVE-2016-10229&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;An issue or pull request comment containing the string &amp;quot;User-Agent: GitHub-Hookshot&amp;quot; incorrectly triggered a firewall rule that caused an internal server error on several pages, including the author&#39;s profile page.&lt;/li&gt;
&lt;li&gt;Collectd statistics were collected for the temporary pre-receive hook environment mount points.&lt;/li&gt;
&lt;li&gt;Users could be added to a team if they don&#39;t satisfy the Organization&#39;s 2FA requirements.&lt;/li&gt;
&lt;li&gt;Very large release or Git LFS assets failed to replicate due to a timeout in a high availability environment.&lt;/li&gt;
&lt;li&gt;In a clustering environment, several services failed to start following a reboot.&lt;/li&gt;
&lt;li&gt;In a clustering environment, configuring multiple nodes in parallel could lead to nodes overwriting each other&#39;s MySQL seed data.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;jq&lt;/code&gt; utility has been added to the default pre-receive hook environment.&lt;/li&gt;
&lt;li&gt;More colors are used in the monitoring graphs in a high availability environment, making them more legible.&lt;/li&gt;
&lt;li&gt;Backups of cluster environments with a large number of archived repositories has been optimized for improved performance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.6&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.6 will be deprecated as of April 26, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 18 Apr 2017 16:00:28 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.8.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.8.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.7.15</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Local privileged MySQL credentials and Alambic HMAC/API keys were exposed in log files included in the support bundle.&lt;/li&gt;
&lt;li&gt;None of the currently supported releases of GitHub Enterprise are affected by the Linux kernel UDP remote code execution vulnerability issued 4 April 2017 (&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2016-10229&quot;&gt;CVE-2016-10229&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;An issue or pull request comment containing the string &#39;User-Agent: GitHub-Hookshot&#39; incorrectly triggered a firewall rule that caused an internal server error on several pages, including the author&#39;s profile page.&lt;/li&gt;
&lt;li&gt;Collectd statistics were collected for the temporary pre-receive hook environment mount points.&lt;/li&gt;
&lt;li&gt;Users could be added to a team if they don&#39;t satisfy the Organization&#39;s 2FA requirements.&lt;/li&gt;
&lt;li&gt;Very large release or Git LFS assets failed to replicate due to a timeout in a high availability environment.&lt;/li&gt;
&lt;li&gt;In a clustering environment, several services failed to start following a reboot.&lt;/li&gt;
&lt;li&gt;In a clustering environment, configuring multiple nodes in parallel could lead to nodes overwriting each other&#39;s MySQL seed data.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;jq&lt;/code&gt; utility has been added to the default pre-receive hook environment.&lt;/li&gt;
&lt;li&gt;More colors are used in the monitoring graphs in a high availability environment, making them more legible.&lt;/li&gt;
&lt;li&gt;Backups of cluster environments with a large number of archived repositories has been optimized for improved performance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.6&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.6 will be deprecated as of April 26, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Additional white spacing can sometimes be seen above the Admin center header.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 18 Apr 2017 16:00:27 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.7.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.7.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.6.20</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Local privileged MySQL credentials and Alambic HMAC/API keys were exposed in log files included in the support bundle.&lt;/li&gt;
&lt;li&gt;None of the currently supported releases of GitHub Enterprise are affected by the Linux kernel UDP remote code execution vulnerability issued 4 April 2017 (&lt;a href=&quot;https://nvd.nist.gov/vuln/detail/CVE-2016-10229&quot;&gt;CVE-2016-10229&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;An issue or pull request comment containing the string &amp;quot;User-Agent: GitHub-Hookshot&amp;quot; incorrectly triggered a firewall rule that caused an internal server error on several pages, including the author&#39;s profile page.&lt;/li&gt;
&lt;li&gt;Collectd statistics were collected for the temporary pre-receive hook environment mount points.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;More colors are used in the monitoring graphs in a high availability environment, making them more legible.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise 2.6&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.6 is now deprecated as of April 26, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring a protected branch archived whilst running 2.3, will not restore all the settings correctly. This does not affect new instances or protected branches archived on later releases.&lt;/li&gt;
&lt;li&gt;Editing custom messages in the Admin Center doesn&#39;t provide emoji suggestions.&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin Center.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/articles/viewing-push-logs/&quot;&gt;Repository push logs&lt;/a&gt; don&#39;t record whether a push was forced.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Uploading PNG images with &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;through the web interface&lt;/a&gt; can fail with the error &#39;Something went really wrong, and we can&#39;t process that file.&#39;&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 18 Apr 2017 16:00:26 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.6.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.6.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.9.2</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: Improper sanitization of user markup content, while not allowing full XSS, could have been abused to leak sensitive data or perform actions as the user viewing the content.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: A file path traversal vulnerability in the Management Console API could allow authenticated users to download content of local files ending with &lt;code&gt;.txt&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Improper sanitization of input allowed splitting of a response header value over multiple lines. No headers could be injected because the actual header name was included on each line.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Detect and reject any Git content that shows evidence of being part of a &lt;a href=&quot;https://github.com/blog/2338-sha-1-collision-detection-on-github-com&quot;&gt;SHA-1 collision attack&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The webhook delivery log was missing timing metrics.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;/trending&lt;/code&gt; page could incorrectly display a &lt;code&gt;Sign up for free&lt;/code&gt; button.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/articles/command-line-utilities/#ghe-check-disk-usage&quot;&gt;&lt;code&gt;ghe-check-disk-usage&lt;/code&gt;&lt;/a&gt; incorrectly defaulted to a &lt;code&gt;--verbose&lt;/code&gt; run.&lt;/li&gt;
&lt;li&gt;When &lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/guides/migrations/&quot;&gt;migrating from GitHub.com or another GitHub Enterprise appliance&lt;/a&gt;, an &lt;code&gt;@&lt;/code&gt; could cause comments to be truncated.&lt;/li&gt;
&lt;li&gt;Status checks on a pull request weren&#39;t properly run after using the &lt;code&gt;Update branch&lt;/code&gt; button, so the &lt;code&gt;Merge pull request&lt;/code&gt; button was inaccessible.&lt;/li&gt;
&lt;li&gt;Processes responsible for Git repository replication could cause a high availability replica appliance to run out of memory and kill a dependent service.&lt;/li&gt;
&lt;li&gt;After an upgrade, the Management Console of a high availability replica appliance could indefinitely show the &lt;code&gt;Starting...&lt;/code&gt; page.&lt;/li&gt;
&lt;li&gt;The total number of organizations was incorrect because the count included trusted OAuth applications.&lt;/li&gt;
&lt;li&gt;Exceptions were logged to &lt;code&gt;/var/log/github/exceptions.log&lt;/code&gt; when a reaction was added a comment.&lt;/li&gt;
&lt;li&gt;It wasn&#39;t possible to give LDAP mapped access to a repository when transferring a repository to an organization.&lt;/li&gt;
&lt;li&gt;Administrators couldn&#39;t restore deleted LFS objects.&lt;/li&gt;
&lt;li&gt;When a SAML user whose normalized username matches an organization&#39;s name tried to authenticate, the organization&#39;s attributes such as profile email could be incorrecty altered.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;org_repos&lt;/code&gt; count in &lt;a href=&quot;https://developer.github.com/enterprise/2.9/v3/enterprise/admin_stats/#get-statistics&quot;&gt;&lt;code&gt;/enterprise/stats&lt;/code&gt;&lt;/a&gt; incorrectly counted private user-owned forks.&lt;/li&gt;
&lt;li&gt;It was possible to queue more jobs to repair a search index through the site admin than could be processed in a reasonable time, causing low priority jobs to become backlogged.&lt;/li&gt;
&lt;li&gt;A configuration run could revert an SSL certificate to an automatically generated self-signed certificate.&lt;/li&gt;
&lt;li&gt;Graphs in the Management Console monitoring page were incorrectly sorted.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/articles/site-admin-dashboard/#reports&quot;&gt;Site admin reports&lt;/a&gt; are now accessible with a &lt;code&gt;site_admin&lt;/code&gt; scoped OAuth token.&lt;/li&gt;
&lt;li&gt;GitHub Flavored Markdown, which is now compliant with &lt;a href=&quot;http://commonmark.org/&quot;&gt;CommonMark&lt;/a&gt;, is used to render repository markdown (e.g. &lt;code&gt;.md&lt;/code&gt;) files. (updated 2017-06-11)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.6&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.6 will be deprecated as of April 26, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;/status&lt;/code&gt; endpoint on a high availability replica incorrectly returns &lt;code&gt;200 OK&lt;/code&gt; instead of &lt;code&gt;503 Service Unavailable&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Site administrators can experience a &lt;code&gt;500 Internal Server Error&lt;/code&gt; after viewing the history for a file path containing Japanese characters. (updated 2017-03-30)&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not. (updated 2017-03-30)&lt;/li&gt;
&lt;li&gt;During maintenance mode for a high availability environment, the &lt;code&gt;/setup/maintenance&lt;/code&gt; does not list active processes. (updated 2017-03-30)&lt;/li&gt;
&lt;li&gt;An issue or pull request comment containing the string &amp;quot;User-Agent: GitHub-Hookshot&amp;quot; incorrectly triggers a firewall rule and causes an internal server error on several pages, including the author&#39;s profile page. (updated 2017-03-30)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 29 Mar 2017 16:00:29 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.9.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.9.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.8.10</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: Improper sanitization of user markup content, while not allowing full XSS, could have been abused to leak sensitive data or perform actions as the user viewing the content.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Detect and reject any Git content that shows evidence of being part of a &lt;a href=&quot;https://github.com/blog/2338-sha-1-collision-detection-on-github-com&quot;&gt;SHA-1 collision attack&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The webhook delivery log was missing timing metrics.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;/trending&lt;/code&gt; page could incorrectly display a &lt;code&gt;Sign up for free&lt;/code&gt; button.&lt;/li&gt;
&lt;li&gt;The total number of organizations was incorrect because the count included trusted OAuth applications.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/articles/command-line-utilities/#ghe-check-disk-usage&quot;&gt;&lt;code&gt;ghe-check-disk-usage&lt;/code&gt;&lt;/a&gt; incorrectly defaulted to a &lt;code&gt;--verbose&lt;/code&gt; run.&lt;/li&gt;
&lt;li&gt;When &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/migrations/&quot;&gt;migrating from GitHub.com or another GitHub Enterprise appliance&lt;/a&gt;, an &lt;code&gt;@&lt;/code&gt; could cause comments to be truncated.&lt;/li&gt;
&lt;li&gt;Administrators couldn&#39;t restore deleted LFS objects.&lt;/li&gt;
&lt;li&gt;Pull request review comment webhooks could fail to send.&lt;/li&gt;
&lt;li&gt;When a SAML user whose normalized username matches an organization&#39;s name tried to authenticate, the organization&#39;s attributes such as profile email could be incorrecty altered.&lt;/li&gt;
&lt;li&gt;A configuration run could revert an SSL certificate to an automatically generated self-signed certificate.&lt;/li&gt;
&lt;li&gt;Graphs in the Management Console monitoring page were incorrectly sorted.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.6&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.6 will be deprecated as of April 26, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not. (updated 2017-03-30)&lt;/li&gt;
&lt;li&gt;An issue or pull request comment containing the string &amp;quot;User-Agent: GitHub-Hookshot&amp;quot; incorrectly triggers a firewall rule and causes an internal server error on several pages, including the author&#39;s profile page. (updated 2017-04-05)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 29 Mar 2017 16:00:28 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.8.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.8.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.7.14</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Detect and reject any Git content that shows evidence of being part of a &lt;a href=&quot;https://github.com/blog/2338-sha-1-collision-detection-on-github-com&quot;&gt;SHA-1 collision attack&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;/trending&lt;/code&gt; page could incorrectly display a &lt;code&gt;Sign up for free&lt;/code&gt; button.&lt;/li&gt;
&lt;li&gt;The total number of organizations was incorrect because the count included trusted OAuth applications.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/articles/command-line-utilities/#ghe-check-disk-usage&quot;&gt;&lt;code&gt;ghe-check-disk-usage&lt;/code&gt;&lt;/a&gt; incorrectly defaulted to a &lt;code&gt;--verbose&lt;/code&gt; run.&lt;/li&gt;
&lt;li&gt;Administrators couldn&#39;t restore deleted LFS objects.&lt;/li&gt;
&lt;li&gt;A configuration run could revert an SSL certificate to an automatically generated self-signed certificate.&lt;/li&gt;
&lt;li&gt;Graphs in the Management Console monitoring page were incorrectly sorted.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.6&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.6 will be deprecated as of April 26, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Additional white spacing can sometimes be seen above the Admin center header.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not. (updated 2017-03-30)&lt;/li&gt;
&lt;li&gt;An issue or pull request comment containing the string &amp;quot;User-Agent: GitHub-Hookshot&amp;quot; incorrectly triggers a firewall rule and causes an internal server error on several pages, including the author&#39;s profile page. (updated 2017-03-30)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 29 Mar 2017 16:00:27 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.7.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.7.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.6.19</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Detect and reject any Git content that shows evidence of being part of a &lt;a href=&quot;https://github.com/blog/2338-sha-1-collision-detection-on-github-com&quot;&gt;SHA-1 collision attack&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;/trending&lt;/code&gt; page could incorrectly display a &lt;code&gt;Sign up for free&lt;/code&gt; button.&lt;/li&gt;
&lt;li&gt;The total number of organizations was incorrect because the count included trusted OAuth applications.&lt;/li&gt;
&lt;li&gt;Administrators couldn&#39;t restore deleted LFS objects.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.6&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.6 will be deprecated as of April 26, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring a protected branch archived whilst running 2.3, will not restore all the settings correctly. This does not affect new instances or protected branches archived on later releases.&lt;/li&gt;
&lt;li&gt;Editing custom messages in the Admin Center doesn&#39;t provide emoji suggestions.&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin Center.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/articles/viewing-push-logs/&quot;&gt;Repository push logs&lt;/a&gt; don&#39;t record whether a push was forced.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Uploading PNG images with &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;through the web interface&lt;/a&gt; can fail with the error &#39;Something went really wrong, and we can&#39;t process that file.&#39;&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which are then incorrectly reused if a new search index is created. This causes search index repair jobs to be reported as finished in the site admin when they were not. (updated 2017-03-30)&lt;/li&gt;
&lt;li&gt;An issue or pull request comment containing the string &amp;quot;User-Agent: GitHub-Hookshot&amp;quot; incorrectly triggers a firewall rule and causes an internal server error on several pages, including the author&#39;s profile page. (updated 2017-03-30)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 29 Mar 2017 16:00:26 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.6.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.6.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.9.1</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: New, invited users received their initial passwords in clear text via e-mail. A password reset link, valid for 24 hours, is sent to the user instead.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Incorrect support bundle and diagnostics instructions were displayed for high availability environments.&lt;/li&gt;
&lt;li&gt;The secondary NTP server was not allowed to be blank.&lt;/li&gt;
&lt;li&gt;A search index that was not marked as the primary index, for example when a new index was being built after an upgrade, could be incorrectly deleted.&lt;/li&gt;
&lt;li&gt;OAuth application authorization failed when the path contained more than one query parameter.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image would fail when deployed via vCenter Server 6.0 or 6.5.&lt;/li&gt;
&lt;li&gt;Starting high availability replication would fail if the appliance was previously configured as a replica.&lt;/li&gt;
&lt;li&gt;Git replication maintenance jobs failed to complete if there were unhealthy repositories prior to upgrading to 2.9.&lt;/li&gt;
&lt;li&gt;An unused &lt;code&gt;locations&lt;/code&gt; search index was incorrectly listed in the site admin indexing page.&lt;/li&gt;
&lt;li&gt;Site administrators may have experienced &lt;code&gt;500 Internal Server Error&lt;/code&gt; if the license was approaching expiration or was close to the seat limit.&lt;/li&gt;
&lt;li&gt;Accessing a GitHub Pages site would cause &lt;code&gt;500 Internal Server Error&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;It was not possible to enable or disable maintenance mode through the Management Console.&lt;/li&gt;
&lt;li&gt;Issues or pull requests with renamed labels were not properly indexed for filtering.&lt;/li&gt;
&lt;li&gt;On Google Compute Engine, it was possible to use an ephemeral scratch disk as repository storage.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A clustering environment requires at least 2 &lt;code&gt;metrics-server&lt;/code&gt;s.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise 2.5&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.5 is now deprecated as of March 14, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this release. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.6&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.6 will be deprecated as of April 26, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Graphs in the Management Console monitoring page are incorrectly sorted.&lt;/li&gt;
&lt;li&gt;It&#39;s possible to queue more jobs to repair a search index through the site admin than can be processed in a reasonable time, causing low priority jobs to become backlogged.&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which is then incorrectly reused if a new search index is created. This can cause search index repair jobs to be reported as finished in the site admin when they&#39;re not.&lt;/li&gt;
&lt;li&gt;A configuration run can incorrectly revert an SSL certificate to an automatically generated self-signed certificate.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;/status&lt;/code&gt; endpoint on a high availability replica incorrectly returns &lt;code&gt;200 OK&lt;/code&gt; instead of &lt;code&gt;503 Service Unavailable&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Site administrators can experience a &lt;code&gt;500 Internal Server Error&lt;/code&gt; after viewing the history for a file path containing Japanese characters. (updated 2017-03-30)&lt;/li&gt;
&lt;li&gt;An issue or pull request comment containing the string &amp;quot;User-Agent: GitHub-Hookshot&amp;quot; incorrectly triggers a firewall rule and causes an internal server error on several pages, including the author&#39;s profile page. (updated 2017-03-30)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 14 Mar 2017 16:00:29 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.9.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.9.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.8.9</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: New, invited users received their initial passwords in clear text via e-mail. A password reset link, valid for 24 hours, is sent to the user instead.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The secondary NTP server was not allowed to be blank.&lt;/li&gt;
&lt;li&gt;A search index that was not marked as the primary index, for example when a new index was being built after an upgrade, could be incorrectly deleted.&lt;/li&gt;
&lt;li&gt;OAuth application authorization failed when the path contained more than one query parameter.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image would fail when deployed via vCenter Server 6.0 or 6.5.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A clustering environment requires at least 2 &lt;code&gt;metrics-server&lt;/code&gt;s.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise 2.5&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.5 is now deprecated as of March 14, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this release. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.6&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.6 will be deprecated as of April 26, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Graphs in the Management Console monitoring page are incorrectly sorted.&lt;/li&gt;
&lt;li&gt;An issue or pull request comment containing the string &amp;quot;User-Agent: GitHub-Hookshot&amp;quot; incorrectly triggers a firewall rule and causes an internal server error on several pages, including the author&#39;s profile page. (updated 2017-03-30)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 14 Mar 2017 16:00:28 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.8.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.8.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.7.13</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: New, invited users received their initial passwords in clear text via e-mail. A password reset link, valid for 24 hours, is sent to the user instead.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A search index that was not marked as the primary index, for example when a new index was being built after an upgrade, could be incorrectly deleted.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image would fail when deployed via vCenter Server 6.0 or 6.5.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise 2.5&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.5 is now deprecated as of March 14, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this release. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.6&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.6 will be deprecated as of April 26, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Additional white spacing can sometimes be seen above the Admin center header.&lt;/li&gt;
&lt;li&gt;Graphs in the Management Console monitoring page are incorrectly sorted.&lt;/li&gt;
&lt;li&gt;An issue or pull request comment containing the string &amp;quot;User-Agent: GitHub-Hookshot&amp;quot; incorrectly triggers a firewall rule and causes an internal server error on several pages, including the author&#39;s profile page. (updated 2017-03-30)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 14 Mar 2017 16:00:27 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.7.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.7.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.6.18</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: New, invited users received their initial passwords in clear text via e-mail. A password reset link, valid for 24 hours, is sent to the user instead.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The initial import of the VMware OVA image would fail when deployed via vCenter Server 6.0 or 6.5.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise 2.5&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.5 is now deprecated as of March 14, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this release. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.6&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.6 will be deprecated as of April 26, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring a protected branch archived whilst running 2.3, will not restore all the settings correctly. This does not affect new instances or protected branches archived on later releases.&lt;/li&gt;
&lt;li&gt;Editing custom messages in the Admin Center doesn&#39;t provide emoji suggestions.&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin Center.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/articles/viewing-push-logs/&quot;&gt;Repository push logs&lt;/a&gt; don&#39;t record whether a push was forced.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Uploading PNG images with &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;through the web interface&lt;/a&gt; can fail with the error &#39;Something went really wrong, and we can&#39;t process that file.&#39;&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;An issue or pull request comment containing the string &amp;quot;User-Agent: GitHub-Hookshot&amp;quot; incorrectly triggers a firewall rule and causes an internal server error on several pages, including the author&#39;s profile page. (updated 2017-03-30)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 14 Mar 2017 16:00:26 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.6.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.6.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.5.23</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: New, invited users received their initial passwords in clear text via e-mail. A password reset link, valid for 24 hours, is sent to the user instead.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The initial import of the VMware OVA image would fail when deployed via vCenter Server 6.0 or 6.5.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise 2.5&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.5 is now deprecated as of March 14, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this release. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.6&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.6 will be deprecated as of April 26, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;An issue or pull request comment containing the string &amp;quot;User-Agent: GitHub-Hookshot&amp;quot; incorrectly triggers a firewall rule and causes an internal server error on several pages, including the author&#39;s profile page. (updated 2017-03-30)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 14 Mar 2017 16:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.5.23</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.5.23</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.9.0</title>
					<description>&lt;h2&gt;Features&lt;/h2&gt;
&lt;p&gt;With the new features added in GitHub Enterprise 2.9.0, you can:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/guides/user-management/using-saml/#saml-attributes&quot;&gt;Configure the SAML username attribute name&lt;/a&gt; to match your organizational standard or what your identity provider uses.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/guides/user-management/using-ldap/&quot;&gt;Disable password-based authentication&lt;/a&gt; for Git operations when using LDAP authentication.&lt;/li&gt;
&lt;li&gt;Use &lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/guides/installation/using-github-enterprise-with-a-load-balancer/&quot;&gt;load balancers for a single appliance of GitHub Enterprise and in front of a High Availability environment&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Use &lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/articles/log-forwarding/&quot;&gt;TLS encrypted communication for secure log forwarding&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Deploy GitHub Enterprise on &lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/guides/installation/installing-github-enterprise-on-google-cloud-platform&quot;&gt;Google Compute Engine&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Require users to &lt;a href=&quot;https://docs.github.com/enterprise/2.9/user/articles/downloading-your-two-factor-authentication-recovery-codes/&quot;&gt;download recovery codes&lt;/a&gt; before they can complete the 2FA setup process.&lt;/li&gt;
&lt;li&gt;Manage one or more users at a time with &lt;a href=&quot;https://docs.github.com/enterprise/2.9/user/articles/maintaining-teams/&quot;&gt;bulk management&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.9/user/articles/removing-an-outside-collaborator-from-an-organization-repository/&quot;&gt;Remove one or more outside collaborator&#39;s access&lt;/a&gt; to a single repository or to all organization owned repositories at one time.&lt;/li&gt;
&lt;li&gt;Locate users by their GPG key from &lt;code&gt;/stafftools&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Purge LFS objects in a repository from &lt;code&gt;/stafftools&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.9/user/articles/searching-commits/&quot;&gt;Search commits&lt;/a&gt; by fields such as message, author, and date.
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;&lt;strong&gt;Note:&lt;/strong&gt; Due to indexing commits, this feature may require adding more space to the data partition (depending on the number of commits and the length of each message).&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.9/user/articles/limits-for-viewing-content-and-diffs-in-a-repository/#diff-limits&quot;&gt;View diffs&lt;/a&gt; beyond the previous 300 file maximum.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.9/user/articles/resolving-a-merge-conflict-on-github/&quot;&gt;Resolve merge conflicts&lt;/a&gt; from your pull requests.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.9/user/articles/requesting-a-pull-request-review/&quot;&gt;Request a pull request review&lt;/a&gt; from a specific person.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.9/user/articles/dismissing-a-pull-request-review/&quot;&gt;Dismiss a review&lt;/a&gt; from a pull request.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/guides/user-management/creating-teams/#creating-teams-with-ldap-sync-enabled&quot;&gt;Preserve your forks&lt;/a&gt; even if you are removed from a team using LDAP sync.&lt;/li&gt;
&lt;li&gt;Identify whether a user is a contributor, owner, or member from badges in the issue or pull request comment.&lt;/li&gt;
&lt;li&gt;Allow organizations to pin repositories.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.9/user/articles/creating-a-project/#creating-an-organization-wide-project&quot;&gt;Create an organization-wide project&lt;/a&gt; to manage issues and pull requests from any repository that belongs to an organization.&lt;/li&gt;
&lt;li&gt;Resume downloads of Git LFS objects, releases, and uploads with supported HTTP(S) clients.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Directory names containing spaces failed to be created from the web interface.&lt;/li&gt;
&lt;li&gt;Directional hotkeys weren&#39;t functional on the commit activity graph.&lt;/li&gt;
&lt;li&gt;Searching repositories from the organization page was inconsistent with the results from the global search.&lt;/li&gt;
&lt;li&gt;Commits were incorrectly referenced to the parent repository in the timeline after restoring a fork.&lt;/li&gt;
&lt;li&gt;Validly signed commits were displayed as invalid if the client added metadata to the &lt;code&gt;gpg&lt;/code&gt; signature.&lt;/li&gt;
&lt;li&gt;Attempting to convert a user to an organization failed with an internal server error.&lt;/li&gt;
&lt;li&gt;Git LFS objects could take up to an hour to replicate in a High Availability configuration.&lt;/li&gt;
&lt;li&gt;In a clustering environment, reindexing failed when a pull request routes to an offline repository.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; could incorrectly fail with a 429 HTTP error code.&lt;/li&gt;
&lt;li&gt;Copy to clipboard buttons failed for Internet Explorer 11 users.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks failed to output UTF-8 characters.&lt;/li&gt;
&lt;li&gt;Migrations failed to preserve a label with a &lt;code&gt;/&lt;/code&gt; character.&lt;/li&gt;
&lt;li&gt;A previously configured replica appliance excessively logged errors during High Availability initialization.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks could fail with &lt;code&gt;Device or resource busy&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;LDAP synchronization incorrectly removed users after a server-side LDAP timeout.&lt;/li&gt;
&lt;li&gt;An &lt;code&gt;Encoding::Compatibility&lt;/code&gt; error occurred when viewing a webhook from &lt;code&gt;/stafftools&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The Management Console &lt;strong&gt;Add new SSH key field&lt;/strong&gt; incorrectly allowed an SSH fingerprint instead of the contents of the key.&lt;/li&gt;
&lt;li&gt;A former primary appliance failed to create or update pre-receive hook environments.&lt;/li&gt;
&lt;li&gt;In a clustering environment, services were incorrectly started after reboot.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks checking internal or temporary Git references failed.&lt;/li&gt;
&lt;li&gt;In a clustering environment, releases, uploads, avatars, and LFS files could fail to be accessible after a &lt;code&gt;storage-server&lt;/code&gt; is removed.&lt;/li&gt;
&lt;li&gt;In a clustering environment, &lt;code&gt;storage-server&lt;/code&gt; repair jobs took a long time when a new &lt;code&gt;storage-server&lt;/code&gt; is added.&lt;/li&gt;
&lt;li&gt;In a clustering environment, the &lt;code&gt;enterprise-manage&lt;/code&gt; and &lt;code&gt;resolvconf&lt;/code&gt; service were incorrectly stopped after &lt;code&gt;ghe-cluster-config-apply&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;An updated SAML &lt;strong&gt;Verification certificate&lt;/strong&gt; did not take effect until the &lt;code&gt;github-unicorn&lt;/code&gt; service was restarted.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Reactivate suspended users configuration has changed to reflect the current configured state.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;&amp;lt;Destination&amp;gt;&lt;/code&gt; element is no longer optional in the SAML response.&lt;/li&gt;
&lt;li&gt;The default Amazon Web Services EC2 root partition has increased to 80 GB.&lt;/li&gt;
&lt;li&gt;GitHub Flavored Markdown, which is used to render issue and pull request comments, is now compliant with &lt;a href=&quot;http://commonmark.org/&quot;&gt;CommonMark&lt;/a&gt;.
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;&lt;strong&gt;Note:&lt;/strong&gt; Rendering for repository files has not changed.&lt;/em&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;New &lt;a href=&quot;https://developer.github.com/enterprise/2.9/webhooks/&quot;&gt;webhook events&lt;/a&gt; have been added.&lt;/li&gt;
&lt;li&gt;New &lt;a href=&quot;https://developer.github.com/enterprise/2.9/v3/&quot;&gt;API resources&lt;/a&gt; have been added.&lt;/li&gt;
&lt;li&gt;High Availability Git replication has been updated to use &lt;a href=&quot;https://githubengineering.com/building-resilience-in-spokes/&quot;&gt;Spokes&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;A ten second timeout is enforced for all LDAP authentication requests. In the event of a timeout, the user is notified, and the timeout is recorded to the log files and reflected on the LDAP Authentication Management Console monitoring graph.&lt;/li&gt;
&lt;li&gt;Outdated diffs and review comments are now hidden by default when viewing a Pull Request. (updated 2017-05-17)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Backups and Disaster Recovery&lt;/h2&gt;
&lt;p&gt;GitHub Enterprise 2.9 requires at least &lt;a href=&quot;https://github.com/github/backup-utils&quot;&gt;GitHub Enterprise Backup Utilities&lt;/a&gt; 2.9.0 for &lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/guides/installation/backups-and-disaster-recovery/&quot;&gt;Backups and Disaster Recovery&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise 2.4&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.4 is now deprecated as of February 9, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this release. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.5&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.5 will be deprecated as of March 14, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Graphs in the Management Console monitoring page are incorrectly sorted.&lt;/li&gt;
&lt;li&gt;Site administrators may experience &lt;code&gt;500 Internal Server Error&lt;/code&gt; if the license is approaching expiration or is close to the seat limit. (updated 2017-03-08)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host.&lt;/li&gt;
&lt;li&gt;On Google Compute Engine, it&#39;s possible to use an ephemeral scratch disk as repository storage (updated 2017-03-10)&lt;/li&gt;
&lt;li&gt;A search index that&#39;s not marked as the primary index, for example when a new index is being built after an upgrade, can be incorrectly deleted. (updated 2017-03-10)&lt;/li&gt;
&lt;li&gt;It&#39;s possible to queue more jobs to repair a search index through the site admin than can be processed in a reasonable time, causing low priority jobs to become backlogged. (updated 2017-03-10)&lt;/li&gt;
&lt;li&gt;Deleting a search index doesn&#39;t delete all associated metadata, which is then incorrectly reused if a new search index is created. This can cause search index repair jobs to be reported as finished in the site admin when they&#39;re not. (updated 2017-03-10)&lt;/li&gt;
&lt;li&gt;An unused &lt;code&gt;locations&lt;/code&gt; search index is incorrectly listed in the site admin indexing page. (updated 2017-03-10)&lt;/li&gt;
&lt;li&gt;It&#39;s not possible to enable or disable maintenance mode through the Management Console. Maintenance mode can still be enabled and disabled using the &lt;a href=&quot;https://docs.github.com/enterprise/2.9/admin/articles/command-line-utilities/#ghe-maintenance&quot;&gt;&lt;code&gt;ghe-maintenance&lt;/code&gt; command line utility&lt;/a&gt;. (updated 2017-03-10)&lt;/li&gt;
&lt;li&gt;Accessing a GitHub Pages site could cause &lt;code&gt;500 Internal Server Error&lt;/code&gt;. (updated 2017-03-10)&lt;/li&gt;
&lt;li&gt;A configuration run can incorrectly revert an SSL certificate to an automatically generated self-signed certificate. (updated 2017-03-10)&lt;/li&gt;
&lt;li&gt;Starting high availability replication can fail if the appliance was previously configured as a replica. (updated 2017-03-10)&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;/status&lt;/code&gt; endpoint on a high availability replica incorrectly returns &lt;code&gt;200 OK&lt;/code&gt; instead of &lt;code&gt;503 Service Unavailable&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Site administrators can experience a &lt;code&gt;500 Internal Server Error&lt;/code&gt; after viewing the history for a file path containing Japanese characters. (updated 2017-03-30)&lt;/li&gt;
&lt;li&gt;An issue or pull request comment containing the string &amp;quot;User-Agent: GitHub-Hookshot&amp;quot; incorrectly triggers a firewall rule and causes an internal server error on several pages, including the author&#39;s profile page. (updated 2017-03-30)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;li&gt;The create team API endpoint returns a 500 error if LDAP Sync is enabled and the team already exists. (updated 2018-01-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 01 Mar 2017 16:00:29 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.9.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.9.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.8.8</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: An internal upload policies API disclosed which users had push access to a repository.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: An internal administrative API was vulnerable to cross-site request forgery (CSRF).&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Attempting to convert a user to an organization failed with an internal server error.&lt;/li&gt;
&lt;li&gt;Git LFS objects could take up to an hour to replicate in a High Availability configuration.&lt;/li&gt;
&lt;li&gt;In a clustering environment, reindexing failed when a pull request routes to an offline repository.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; could incorrectly fail with a 429 HTTP error code.&lt;/li&gt;
&lt;li&gt;Copy to clipboard buttons failed for Internet Explorer 11 users.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks failed to output UTF-8 characters.&lt;/li&gt;
&lt;li&gt;Migrations failed to preserve a label with a &lt;code&gt;/&lt;/code&gt; character.&lt;/li&gt;
&lt;li&gt;A previously configured replica appliance excessively logged errors during High Availability initialization.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks could fail with &lt;code&gt;Device or resource busy&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;LDAP synchronization incorrectly removed users after a server-side LDAP timeout.&lt;/li&gt;
&lt;li&gt;An &lt;code&gt;Encoding::Compatibility&lt;/code&gt; error occurred when viewing a webhook from &lt;code&gt;/stafftools&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The Management Console &lt;strong&gt;Add new SSH key field&lt;/strong&gt; incorrectly allowed an SSH fingerprint instead of the contents of the key.&lt;/li&gt;
&lt;li&gt;A former primary appliance failed to create or update pre-receive hook environments.&lt;/li&gt;
&lt;li&gt;In a clustering environment, services were incorrectly started after reboot.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks checking internal or temporary Git references failed.&lt;/li&gt;
&lt;li&gt;In a clustering environment, releases, uploads, avatars, and LFS files could fail to be accessible after a &lt;code&gt;storage-server&lt;/code&gt; is removed.&lt;/li&gt;
&lt;li&gt;In a clustering environment, &lt;code&gt;storage-server&lt;/code&gt; repair jobs took a long time when a new &lt;code&gt;storage-server&lt;/code&gt; is added.&lt;/li&gt;
&lt;li&gt;In a clustering environment, the &lt;code&gt;enterprise-manage&lt;/code&gt; and &lt;code&gt;resolvconf&lt;/code&gt; service were incorrectly stopped after &lt;code&gt;ghe-cluster-config-apply&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;An updated SAML &lt;strong&gt;Verification certificate&lt;/strong&gt; did not take effect until the &lt;code&gt;github-unicorn&lt;/code&gt; service was restarted.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Reactivate suspended users configuration has changed to reflect the current configured state.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;&amp;lt;Destination&amp;gt;&lt;/code&gt; element is no longer optional in the SAML response.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise 2.4&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.4 is now deprecated as of February 9, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this release. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.5&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.5 will be deprecated as of March 14, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Graphs in the Management Console monitoring page are incorrectly sorted.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host.&lt;/li&gt;
&lt;li&gt;An issue or pull request comment containing the string &amp;quot;User-Agent: GitHub-Hookshot&amp;quot; incorrectly triggers a firewall rule and causes an internal server error on several pages, including the author&#39;s profile page. (updated 2017-03-30)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 01 Mar 2017 16:00:28 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.8.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.8.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.7.12</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: An internal upload policies API disclosed which users had push access to a repository.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: An internal administrative API was vulnerable to cross-site request forgery (CSRF).&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Git LFS objects could take up to an hour to replicate in a High Availability configuration.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks failed to output UTF-8 characters.&lt;/li&gt;
&lt;li&gt;Migrations failed to preserve a label with a &lt;code&gt;/&lt;/code&gt; character.&lt;/li&gt;
&lt;li&gt;A previously configured replica appliance excessively logged errors during High Availability initialization.&lt;/li&gt;
&lt;li&gt;The Management Console &lt;strong&gt;Add new SSH key field&lt;/strong&gt; incorrectly allowed an SSH fingerprint instead of the contents of the key.&lt;/li&gt;
&lt;li&gt;A former primary appliance failed to create or update pre-receive hook environments.&lt;/li&gt;
&lt;li&gt;An updated SAML &lt;strong&gt;Verification certificate&lt;/strong&gt; did not take effect until the &lt;code&gt;github-unicorn&lt;/code&gt; service was restarted.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Reactivate suspended users configuration has changed to reflect the current configured state.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;&amp;lt;Destination&amp;gt;&lt;/code&gt; element is no longer optional in the SAML response.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise 2.4&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.4 is now deprecated as of February 9, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this release. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.5&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.5 will be deprecated as of March 14, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Additional white spacing can sometimes be seen above the Admin center header.&lt;/li&gt;
&lt;li&gt;Graphs in the Management Console monitoring page are incorrectly sorted.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host.&lt;/li&gt;
&lt;li&gt;An issue or pull request comment containing the string &amp;quot;User-Agent: GitHub-Hookshot&amp;quot; incorrectly triggers a firewall rule and causes an internal server error on several pages, including the author&#39;s profile page. (updated 2017-03-30)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 01 Mar 2017 16:00:27 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.7.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.7.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.6.17</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: An internal upload policies API disclosed which users had push access to a repository.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: An internal administrative API was vulnerable to cross-site request forgery (CSRF).&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Git LFS objects could take up to an hour to replicate in a High Availability configuration.&lt;/li&gt;
&lt;li&gt;Migrations failed to preserve a label with a &lt;code&gt;/&lt;/code&gt; character.&lt;/li&gt;
&lt;li&gt;The Management Console &lt;strong&gt;Add new SSH key field&lt;/strong&gt; incorrectly allowed an SSH fingerprint instead of the contents of the key.&lt;/li&gt;
&lt;li&gt;A former primary appliance failed to create or update pre-receive hook environments.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;&amp;lt;Destination&amp;gt;&lt;/code&gt; element is no longer optional in the SAML response.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise 2.4&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.4 is now deprecated as of February 9, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this release. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.5&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.5 will be deprecated as of March 14, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring a protected branch archived whilst running 2.3, will not restore all the settings correctly. This does not affect new instances or protected branches archived on later releases.&lt;/li&gt;
&lt;li&gt;Editing custom messages in the Admin Center doesn&#39;t provide emoji suggestions.&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin Center.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/articles/viewing-push-logs/&quot;&gt;Repository push logs&lt;/a&gt; don&#39;t record whether a push was forced.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Uploading PNG images with &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;through the web interface&lt;/a&gt; can fail with the error &#39;Something went really wrong, and we can&#39;t process that file.&#39;&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host.&lt;/li&gt;
&lt;li&gt;An issue or pull request comment containing the string &amp;quot;User-Agent: GitHub-Hookshot&amp;quot; incorrectly triggers a firewall rule and causes an internal server error on several pages, including the author&#39;s profile page. (updated 2017-03-30)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 01 Mar 2017 16:00:26 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.6.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.6.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.5.22</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: An internal upload policies API disclosed which users had push access to a repository.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Git LFS objects could take up to an hour to replicate in a High Availability configuration.&lt;/li&gt;
&lt;li&gt;Migrations failed to preserve a label with a &lt;code&gt;/&lt;/code&gt; character.&lt;/li&gt;
&lt;li&gt;The Management Console &lt;strong&gt;Add new SSH key field&lt;/strong&gt; incorrectly allowed an SSH fingerprint instead of the contents of the key.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;&amp;lt;Destination&amp;gt;&lt;/code&gt; element is no longer optional in the SAML response.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise 2.4&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.4 is now deprecated as of February 9, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this release. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.5&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.5 will be deprecated as of March 14, 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host.&lt;/li&gt;
&lt;li&gt;An issue or pull request comment containing the string &amp;quot;User-Agent: GitHub-Hookshot&amp;quot; incorrectly triggers a firewall rule and causes an internal server error on several pages, including the author&#39;s profile page. (updated 2017-03-30)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 01 Mar 2017 16:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.5.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.5.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.8.7</title>
					<description>&lt;h2&gt;SAML authentication bypass with XML signature wrapping in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker to bypass SAML authentication. The vulnerability is applicable if the attacker has access to a validly signed SAML assertion or response against the &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/user-management/using-saml/#configuring-saml-settings&quot;&gt;configured &lt;strong&gt;Verification certificate&lt;/strong&gt;&lt;/a&gt;. When applicable, an attacker can sign in as any user, including administrators.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.8.0 - 2.8.6&lt;/li&gt;
&lt;li&gt;2.7.0 - 2.7.10&lt;/li&gt;
&lt;li&gt;2.6.0 - 2.6.15&lt;/li&gt;
&lt;li&gt;2.5.0 - 2.5.20&lt;/li&gt;
&lt;li&gt;2.4.0 - 2.4.22&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This is a different vulnerability than the one addressed in GitHub Enterprise 2.8.6, 2.7.10, 2.6.15, and 2.5.20.&lt;/p&gt;
&lt;h2&gt;Remote code execution with server side request forgery in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker to execute arbitrary commands on the GitHub Enterprise appliance. The vulnerability is applicable if the attacker has access to &lt;a href=&quot;https://docs.github.com/enterprise/2.8/user/articles/about-webhooks/&quot;&gt;configure a repository&#39;s Webhooks&lt;/a&gt; - owner or admin privileges to a repository.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.8.0 - 2.8.6&lt;/li&gt;
&lt;li&gt;2.7.0 - 2.7.10&lt;/li&gt;
&lt;li&gt;2.6.0 - 2.6.15&lt;/li&gt;
&lt;li&gt;2.5.0 - 2.5.20&lt;/li&gt;
&lt;li&gt;2.4.0 - 2.4.22&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Remote code execution in GitHub Enterprise &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/installation/web-based-management-console/&quot;&gt;Management Console&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker to execute arbitrary commands on the GitHub Enterprise appliance. This vulnerability exists in the &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/installation/web-based-management-console/&quot;&gt;Management Console&lt;/a&gt; which is accessible from port 8080 and 8443. This is only applicable to GitHub Enterprise 2.8.0 - 2.8.6.&lt;/p&gt;
&lt;h2&gt;Next steps&lt;/h2&gt;
&lt;p&gt;We &lt;strong&gt;strongly&lt;/strong&gt; recommend &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrading&lt;/a&gt; your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.8.7, 2.7.11, 2.6.16, 2.5.21, or 2.4.23.&lt;/p&gt;
&lt;p&gt;Additionally, if SAML authentication is configured in your appliance, all existing SAML user sessions should be destroyed:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Put your GitHub Enterprise environment in &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/installation/maintenance-mode/&quot;&gt;Maintenance Mode&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your primary GitHub Enterprise appliance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Destroy the existing SAML sessions.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ echo SAML::Session.destroy_all | ghe-console -y
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Upgrade to the latest patch release in your series, GitHub Enterprise 2.8.7, 2.7.11, 2.6.16, 2.5.21, or 2.4.23.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If possible, we also recommend restricting &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/installation/web-based-management-console/&quot;&gt;Management Console&lt;/a&gt; access to your site administrators.&lt;/p&gt;
&lt;p&gt;These vulnerabilities were reported through the &lt;a href=&quot;https://bounty.github.com/&quot;&gt;GitHub Security Bug Bounty&lt;/a&gt; program and we have no evidence that they have been exploited in the wild. To learn more about the Bug Bounty program for GitHub Enterprise, visit &lt;a href=&quot;https://bounty.github.com/targets/github-enterprise.html&quot;&gt;https://bounty.github.com/targets/github-enterprise.html&lt;/a&gt; and our recent blog post about the inclusion of GitHub Enterprise, &lt;strong&gt;&lt;a href=&quot;https://github.com/blog/2302-bug-bounty-anniversary-promotion-bigger-bounties-in-january-and-february&quot;&gt;Bug Bounty anniversary promotion: bigger bounties in January and February&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have any questions.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: An attacker could bypass SAML authentication via XML signature wrapping and log in as any other user.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: There was a remote code execution vulnerability via server side request forgery.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: There was a remote code execution vulnerability through the Management Console.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: With &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/user-management/using-built-in-authentication/&quot;&gt;built-in authentication&lt;/a&gt;, suspended users could log in.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;For Internet Explorer 11 users, the Write and Preview tabs in the comment window were switched.&lt;/li&gt;
&lt;li&gt;In a clustering environment, services would not automatically start after reboot.&lt;/li&gt;
&lt;li&gt;In a clustering environment, &lt;code&gt;ghe-migrator&lt;/code&gt; failed to import when running on node with the &lt;code&gt;git-server&lt;/code&gt; role.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;/stafftools&lt;/code&gt; notification could incorrectly link to a deleted user&#39;s page.&lt;/li&gt;
&lt;li&gt;The OAuth application logo was incorrectly displayed when private mode was enabled.&lt;/li&gt;
&lt;li&gt;Collaborators with access via the default organization permissions were not listed in &lt;a href=&quot;https://developer.github.com/enterprise/2.8/v3/repos/collaborators/#list-collaborators&quot;&gt;&lt;code&gt;/repos/:owner/:repo/collaborators&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;LDAP Sync Totals graph was incorrectly counting runs instead of users and teams synced.&lt;/li&gt;
&lt;li&gt;@mentions would not work for single character organization or team names.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.5&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.5 will be deprecated as of March 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Attempting to convert a user to an organization fails with an internal server error.&lt;/li&gt;
&lt;li&gt;Graphs in the Management Console monitoring page are incorrectly sorted.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;An issue or pull request comment containing the string &amp;quot;User-Agent: GitHub-Hookshot&amp;quot; incorrectly triggers a firewall rule and causes an internal server error on several pages, including the author&#39;s profile page. (updated 2017-03-30)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 31 Jan 2017 16:00:28 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.8.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.8.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.7.11</title>
					<description>&lt;h2&gt;SAML authentication bypass with XML signature wrapping in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker to bypass SAML authentication. The vulnerability is applicable if the attacker has access to a validly signed SAML assertion or response against the &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/user-management/using-saml/#configuring-saml-settings&quot;&gt;configured &lt;strong&gt;Verification certificate&lt;/strong&gt;&lt;/a&gt;. When applicable, an attacker can sign in as any user, including administrators.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.8.0 - 2.8.6&lt;/li&gt;
&lt;li&gt;2.7.0 - 2.7.10&lt;/li&gt;
&lt;li&gt;2.6.0 - 2.6.15&lt;/li&gt;
&lt;li&gt;2.5.0 - 2.5.20&lt;/li&gt;
&lt;li&gt;2.4.0 - 2.4.22&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This is a different vulnerability than the one addressed in GitHub Enterprise 2.8.6, 2.7.10, 2.6.15, and 2.5.20.&lt;/p&gt;
&lt;h2&gt;Remote code execution with server side request forgery in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker to execute arbitrary commands on the GitHub Enterprise appliance. The vulnerability is applicable if the attacker has access to &lt;a href=&quot;https://docs.github.com/enterprise/2.7/user/articles/about-webhooks/&quot;&gt;configure a repository&#39;s Webhooks&lt;/a&gt; - owner or admin privileges to a repository.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.8.0 - 2.8.6&lt;/li&gt;
&lt;li&gt;2.7.0 - 2.7.10&lt;/li&gt;
&lt;li&gt;2.6.0 - 2.6.15&lt;/li&gt;
&lt;li&gt;2.5.0 - 2.5.20&lt;/li&gt;
&lt;li&gt;2.4.0 - 2.4.22&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Next steps&lt;/h2&gt;
&lt;p&gt;We &lt;strong&gt;strongly&lt;/strong&gt; recommend &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrading&lt;/a&gt; your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.8.7, 2.7.11, 2.6.16, 2.5.21, or 2.4.23.&lt;/p&gt;
&lt;p&gt;Additionally, if SAML authentication is configured in your appliance, all existing SAML user sessions should be destroyed:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Put your GitHub Enterprise environment in &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/maintenance-mode/&quot;&gt;Maintenance Mode&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your primary GitHub Enterprise appliance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Destroy the existing SAML sessions.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ echo SAML::Session.destroy_all | ghe-console -y
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Upgrade to the latest patch release in your series, GitHub Enterprise 2.8.7, 2.7.11, 2.6.16, 2.5.21, or 2.4.23.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If possible, we also recommend restricting &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/web-based-management-console/&quot;&gt;Management Console&lt;/a&gt; access to your site administrators.&lt;/p&gt;
&lt;p&gt;These vulnerabilities were reported through the &lt;a href=&quot;https://bounty.github.com/&quot;&gt;GitHub Security Bug Bounty&lt;/a&gt; program and we have no evidence that they have been exploited in the wild. To learn more about the Bug Bounty program for GitHub Enterprise, visit &lt;a href=&quot;https://bounty.github.com/targets/github-enterprise.html&quot;&gt;https://bounty.github.com/targets/github-enterprise.html&lt;/a&gt; and our recent blog post about the inclusion of GitHub Enterprise, &lt;strong&gt;&lt;a href=&quot;https://github.com/blog/2302-bug-bounty-anniversary-promotion-bigger-bounties-in-january-and-february&quot;&gt;Bug Bounty anniversary promotion: bigger bounties in January and February&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have any questions.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: An attacker could bypass SAML authentication via XML signature wrapping and log in as any other user.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: There was a remote code execution vulnerability via server side request forgery.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: With &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/user-management/using-built-in-authentication/&quot;&gt;built-in authentication&lt;/a&gt;, suspended users could log in.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In a clustering environment, services would not automatically start after reboot.&lt;br /&gt;
Thanks!&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.5&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.5 will be deprecated as of March 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Additional white spacing can sometimes be seen above the Admin center header.&lt;/li&gt;
&lt;li&gt;Graphs in the Management Console monitoring page are incorrectly sorted.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;An issue or pull request comment containing the string &amp;quot;User-Agent: GitHub-Hookshot&amp;quot; incorrectly triggers a firewall rule and causes an internal server error on several pages, including the author&#39;s profile page. (updated 2017-03-30)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 31 Jan 2017 16:00:27 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.7.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.7.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.6.16</title>
					<description>&lt;h2&gt;SAML authentication bypass with XML signature wrapping in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker to bypass SAML authentication. The vulnerability is applicable if the attacker has access to a validly signed SAML assertion or response against the &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/user-management/using-saml/#configuring-saml-settings&quot;&gt;configured &lt;strong&gt;Verification certificate&lt;/strong&gt;&lt;/a&gt;. When applicable, an attacker can sign in as any user, including administrators.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.8.0 - 2.8.6&lt;/li&gt;
&lt;li&gt;2.7.0 - 2.7.10&lt;/li&gt;
&lt;li&gt;2.6.0 - 2.6.15&lt;/li&gt;
&lt;li&gt;2.5.0 - 2.5.20&lt;/li&gt;
&lt;li&gt;2.4.0 - 2.4.22&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This is a different vulnerability than the one addressed in GitHub Enterprise 2.8.6, 2.7.10, 2.6.15, and 2.5.20.&lt;/p&gt;
&lt;h2&gt;Remote code execution with server side request forgery in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker to execute arbitrary commands on the GitHub Enterprise appliance. The vulnerability is applicable if the attacker has access to &lt;a href=&quot;https://docs.github.com/enterprise/2.6/user/articles/about-webhooks/&quot;&gt;configure a repository&#39;s Webhooks&lt;/a&gt; - owner or admin privileges to a repository.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.8.0 - 2.8.6&lt;/li&gt;
&lt;li&gt;2.7.0 - 2.7.10&lt;/li&gt;
&lt;li&gt;2.6.0 - 2.6.15&lt;/li&gt;
&lt;li&gt;2.5.0 - 2.5.20&lt;/li&gt;
&lt;li&gt;2.4.0 - 2.4.22&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Next steps&lt;/h2&gt;
&lt;p&gt;We &lt;strong&gt;strongly&lt;/strong&gt; recommend &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrading&lt;/a&gt; your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.8.7, 2.7.11, 2.6.16, 2.5.21, or 2.4.23.&lt;/p&gt;
&lt;p&gt;Additionally, if SAML authentication is configured in your appliance, all existing SAML user sessions should be destroyed:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Put your GitHub Enterprise environment in &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/maintenance-mode/&quot;&gt;Maintenance Mode&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your primary GitHub Enterprise appliance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Destroy the existing SAML sessions.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ echo SAML::Session.destroy_all | ghe-console -y
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Upgrade to the latest patch release in your series, GitHub Enterprise 2.8.7, 2.7.11, 2.6.16, 2.5.21, or 2.4.23.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If possible, we also recommend restricting &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/web-based-management-console/&quot;&gt;Management Console&lt;/a&gt; access to your site administrators.&lt;/p&gt;
&lt;p&gt;These vulnerabilities were reported through the &lt;a href=&quot;https://bounty.github.com/&quot;&gt;GitHub Security Bug Bounty&lt;/a&gt; program and we have no evidence that they have been exploited in the wild. To learn more about the Bug Bounty program for GitHub Enterprise, visit &lt;a href=&quot;https://bounty.github.com/targets/github-enterprise.html&quot;&gt;https://bounty.github.com/targets/github-enterprise.html&lt;/a&gt; and our recent blog post about the inclusion of GitHub Enterprise, &lt;strong&gt;&lt;a href=&quot;https://github.com/blog/2302-bug-bounty-anniversary-promotion-bigger-bounties-in-january-and-february&quot;&gt;Bug Bounty anniversary promotion: bigger bounties in January and February&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have any questions.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: An attacker could bypass SAML authentication via XML signature wrapping and log in as any other user.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: There was a remote code execution vulnerability via server side request forgery.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: With &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/user-management/using-built-in-authentication/&quot;&gt;built-in authentication&lt;/a&gt;, suspended users could log in.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring a protected branch archived whilst running 2.3, will not restore all the settings correctly. This does not affect new instances or protected branches archived on later releases.&lt;/li&gt;
&lt;li&gt;Editing custom messages in the Admin Center doesn&#39;t provide emoji suggestions.&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin Center.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/articles/viewing-push-logs/&quot;&gt;Repository push logs&lt;/a&gt; don&#39;t record whether a push was forced.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Uploading PNG images with &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;through the web interface&lt;/a&gt; can fail with the error &#39;Something went really wrong, and we can&#39;t process that file.&#39;&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;An issue or pull request comment containing the string &amp;quot;User-Agent: GitHub-Hookshot&amp;quot; incorrectly triggers a firewall rule and causes an internal server error on several pages, including the author&#39;s profile page. (updated 2017-03-30)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 31 Jan 2017 16:00:26 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.6.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.6.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.5.21</title>
					<description>&lt;h2&gt;SAML authentication bypass with XML signature wrapping in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker to bypass SAML authentication. The vulnerability is applicable if the attacker has access to a validly signed SAML assertion or response against the &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/user-management/using-saml/#configuring-saml-settings&quot;&gt;configured &lt;strong&gt;Verification certificate&lt;/strong&gt;&lt;/a&gt;. When applicable, an attacker can sign in as any user, including administrators.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.8.0 - 2.8.6&lt;/li&gt;
&lt;li&gt;2.7.0 - 2.7.10&lt;/li&gt;
&lt;li&gt;2.6.0 - 2.6.15&lt;/li&gt;
&lt;li&gt;2.5.0 - 2.5.20&lt;/li&gt;
&lt;li&gt;2.4.0 - 2.4.22&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This is a different vulnerability than the one addressed in GitHub Enterprise 2.8.6, 2.7.10, 2.6.15, and 2.5.20.&lt;/p&gt;
&lt;h2&gt;Remote code execution with server side request forgery in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker to execute arbitrary commands on the GitHub Enterprise appliance. The vulnerability is applicable if the attacker has access to &lt;a href=&quot;https://docs.github.com/enterprise/2.5/user/articles/about-webhooks/&quot;&gt;configure a repository&#39;s Webhooks&lt;/a&gt; - owner or admin privileges to a repository.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.8.0 - 2.8.6&lt;/li&gt;
&lt;li&gt;2.7.0 - 2.7.10&lt;/li&gt;
&lt;li&gt;2.6.0 - 2.6.15&lt;/li&gt;
&lt;li&gt;2.5.0 - 2.5.20&lt;/li&gt;
&lt;li&gt;2.4.0 - 2.4.22&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Next steps&lt;/h2&gt;
&lt;p&gt;We &lt;strong&gt;strongly&lt;/strong&gt; recommend &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrading&lt;/a&gt; your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.8.7, 2.7.11, 2.6.16, 2.5.21, or 2.4.23.&lt;/p&gt;
&lt;p&gt;Additionally, if SAML authentication is configured in your appliance, all existing SAML user sessions should be destroyed:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Put your GitHub Enterprise environment in &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/maintenance-mode/&quot;&gt;Maintenance Mode&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your primary GitHub Enterprise appliance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Destroy the existing SAML sessions.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ echo SAML::Session.destroy_all | ghe-console-github
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Upgrade to the latest patch release in your series, GitHub Enterprise 2.8.7, 2.7.11, 2.6.16, 2.5.21, or 2.4.23.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If possible, we also recommend restricting &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/web-based-management-console/&quot;&gt;Management Console&lt;/a&gt; access to your site administrators.&lt;/p&gt;
&lt;p&gt;These vulnerabilities were reported through the &lt;a href=&quot;https://bounty.github.com/&quot;&gt;GitHub Security Bug Bounty&lt;/a&gt; program and we have no evidence that they have been exploited in the wild. To learn more about the Bug Bounty program for GitHub Enterprise, visit &lt;a href=&quot;https://bounty.github.com/targets/github-enterprise.html&quot;&gt;https://bounty.github.com/targets/github-enterprise.html&lt;/a&gt; and our recent blog post about the inclusion of GitHub Enterprise, &lt;strong&gt;&lt;a href=&quot;https://github.com/blog/2302-bug-bounty-anniversary-promotion-bigger-bounties-in-january-and-february&quot;&gt;Bug Bounty anniversary promotion: bigger bounties in January and February&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have any questions.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: An attacker could bypass SAML authentication via XML signature wrapping and log in as any other user.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: There was a remote code execution vulnerability via server side request forgery.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: With &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/user-management/using-built-in-authentication/&quot;&gt;built-in authentication&lt;/a&gt;, suspended users could log in.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;An issue or pull request comment containing the string &amp;quot;User-Agent: GitHub-Hookshot&amp;quot; incorrectly triggers a firewall rule and causes an internal server error on several pages, including the author&#39;s profile page. (updated 2017-03-30)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 31 Jan 2017 16:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.5.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.5.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.4.23</title>
					<description>&lt;h2&gt;SAML authentication bypass with XML signature wrapping in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker to bypass SAML authentication. The vulnerability is applicable if the attacker has access to a validly signed SAML assertion or response against the &lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/user-management/using-saml/#configuring-saml-settings&quot;&gt;configured &lt;strong&gt;Verification certificate&lt;/strong&gt;&lt;/a&gt;. When applicable, an attacker can sign in as any user, including administrators.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.8.0 - 2.8.6&lt;/li&gt;
&lt;li&gt;2.7.0 - 2.7.10&lt;/li&gt;
&lt;li&gt;2.6.0 - 2.6.15&lt;/li&gt;
&lt;li&gt;2.5.0 - 2.5.20&lt;/li&gt;
&lt;li&gt;2.4.0 - 2.4.22&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;&lt;strong&gt;Note:&lt;/strong&gt; This is a different vulnerability than the one addressed in GitHub Enterprise 2.8.6, 2.7.10, 2.6.15, and 2.5.20.&lt;/p&gt;
&lt;h2&gt;Remote code execution with server side request forgery in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker to execute arbitrary commands on the GitHub Enterprise appliance. The vulnerability is applicable if the attacker has access to &lt;a href=&quot;https://docs.github.com/enterprise/2.4/user/articles/about-webhooks/&quot;&gt;configure a repository&#39;s Webhooks&lt;/a&gt; - owner or admin privileges to a repository.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.8.0 - 2.8.6&lt;/li&gt;
&lt;li&gt;2.7.0 - 2.7.10&lt;/li&gt;
&lt;li&gt;2.6.0 - 2.6.15&lt;/li&gt;
&lt;li&gt;2.5.0 - 2.5.20&lt;/li&gt;
&lt;li&gt;2.4.0 - 2.4.22&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Next steps&lt;/h2&gt;
&lt;p&gt;We &lt;strong&gt;strongly&lt;/strong&gt; recommend &lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrading&lt;/a&gt; your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.8.7, 2.7.11, 2.6.16, 2.5.21, or 2.4.23.&lt;/p&gt;
&lt;p&gt;Additionally, if SAML authentication is configured in your appliance, all existing SAML user sessions should be destroyed:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Put your GitHub Enterprise environment in &lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/installation/maintenance-mode/&quot;&gt;Maintenance Mode&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your primary GitHub Enterprise appliance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Destroy the existing SAML sessions.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ echo SAML::Session.destroy_all | ghe-console-github
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Upgrade to the latest patch release in your series, GitHub Enterprise 2.8.7, 2.7.11, 2.6.16, 2.5.21, or 2.4.23.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If possible, we also recommend restricting &lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/installation/web-based-management-console/&quot;&gt;Management Console&lt;/a&gt; access to your site administrators.&lt;/p&gt;
&lt;p&gt;These vulnerabilities were reported through the &lt;a href=&quot;https://bounty.github.com/&quot;&gt;GitHub Security Bug Bounty&lt;/a&gt; program and we have no evidence that they have been exploited in the wild. To learn more about the Bug Bounty program for GitHub Enterprise, visit &lt;a href=&quot;https://bounty.github.com/targets/github-enterprise.html&quot;&gt;https://bounty.github.com/targets/github-enterprise.html&lt;/a&gt; and our recent blog post about the inclusion of GitHub Enterprise, &lt;strong&gt;&lt;a href=&quot;https://github.com/blog/2302-bug-bounty-anniversary-promotion-bigger-bounties-in-january-and-february&quot;&gt;Bug Bounty anniversary promotion: bigger bounties in January and February&lt;/a&gt;&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have any questions.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: An attacker could bypass SAML authentication via XML signature wrapping and log in as any other user.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: There was a remote code execution vulnerability via server side request forgery.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: With &lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/user-management/using-built-in-authentication/&quot;&gt;built-in authentication&lt;/a&gt;, suspended users could log in.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.4&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.4 will be deprecated as of February 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;An issue or pull request comment containing the string &amp;quot;User-Agent: GitHub-Hookshot&amp;quot; incorrectly triggers a firewall rule and causes an internal server error on several pages, including the author&#39;s profile page. (updated 2017-03-30)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 31 Jan 2017 16:00:24 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.4.23</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.4.23</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.8.6</title>
					<description>&lt;h2&gt;SAML authentication bypass in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker to bypass SAML authentication by creating a fake response. This could allow the attacker to sign in as any user, including administrators.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.8.0 - 2.8.5&lt;/li&gt;
&lt;li&gt;2.7.0 - 2.7.9&lt;/li&gt;
&lt;li&gt;2.6.0 - 2.6.14&lt;/li&gt;
&lt;li&gt;2.5.0 - 2.5.19&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you are using SAML as your authentication method, we &lt;strong&gt;strongly&lt;/strong&gt; recommend &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrading&lt;/a&gt; your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.8.6, 2.7.10, 2.6.15, or 2.5.20.&lt;/p&gt;
&lt;p&gt;Additionally, all existing user sessions should be destroyed:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Put your GitHub Enterprise environment in &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/installation/maintenance-mode/&quot;&gt;Maintenance Mode&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your primary GitHub Enterprise appliance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Destroy the existing SAML sessions.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ echo SAML::Session.destroy_all | ghe-console -y
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Upgrade to the latest patch release in your series, GitHub Enterprise 2.8.6, 2.7.10, 2.6.15, or 2.5.20.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;This vulnerability was reported through the &lt;a href=&quot;https://bounty.github.com/&quot;&gt;GitHub Security Bug Bounty&lt;/a&gt; program and we have no evidence that it has been exploited in the wild.&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have any questions.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: An attacker could bypass SAML authentication and log in as any other user.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Files uploaded to a repository through the web interface were saved in the wrong location if the target directory contained multi-byte characters.&lt;/li&gt;
&lt;li&gt;For teams synchronized to the same LDAP group, group members were inefficiently cached, leading to slower Team Synchronization job runs.&lt;/li&gt;
&lt;li&gt;When configured with more than one group, there was an extra comma in the list of restricted LDAP groups in the site admin user search page.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;babeld&lt;/code&gt;, &lt;code&gt;codeload&lt;/code&gt;, and &lt;code&gt;ruby&lt;/code&gt; processes could crash.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We now only save a single core file per process, so multiple crashes of the same process use less disk space.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Attempting to convert a user to an organization fails with an internal server error.&lt;/li&gt;
&lt;li&gt;Graphs in the Management Console monitoring page are incorrectly sorted. (updated 2017-01-18)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Thu, 12 Jan 2017 16:00:28 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.8.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.8.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.7.10</title>
					<description>&lt;h2&gt;SAML authentication bypass in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker to bypass SAML authentication by creating a fake response. This could allow the attacker to sign in as any user, including administrators.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.8.0 - 2.8.5&lt;/li&gt;
&lt;li&gt;2.7.0 - 2.7.9&lt;/li&gt;
&lt;li&gt;2.6.0 - 2.6.14&lt;/li&gt;
&lt;li&gt;2.5.0 - 2.5.19&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you are using SAML as your authentication method, we &lt;strong&gt;strongly&lt;/strong&gt; recommend &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrading&lt;/a&gt; your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.8.6, 2.7.10, 2.6.15, or 2.5.20.&lt;/p&gt;
&lt;p&gt;Additionally, all existing user sessions should be destroyed:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Put your GitHub Enterprise environment in &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/maintenance-mode/&quot;&gt;Maintenance Mode&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your primary GitHub Enterprise appliance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Destroy the existing SAML sessions.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ echo SAML::Session.destroy_all | ghe-console -y
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Upgrade to the latest patch release in your series, GitHub Enterprise 2.8.6, 2.7.10, 2.6.15, or 2.5.20.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;This vulnerability was reported through the &lt;a href=&quot;https://bounty.github.com/&quot;&gt;GitHub Security Bug Bounty&lt;/a&gt; program and we have no evidence that it has been exploited in the wild.&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have any questions.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: Users could bypass SAML authentication and log in as any other user&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Additional white spacing can sometimes be seen above the Admin center header.&lt;/li&gt;
&lt;li&gt;Graphs in the Management Console monitoring page are incorrectly sorted. (updated 2017-01-18)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Thu, 12 Jan 2017 16:00:27 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.7.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.7.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.6.15</title>
					<description>&lt;h2&gt;SAML authentication bypass in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker to bypass SAML authentication by creating a fake response. This could allow the attacker to sign in as any user, including administrators.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.8.0 - 2.8.5&lt;/li&gt;
&lt;li&gt;2.7.0 - 2.7.9&lt;/li&gt;
&lt;li&gt;2.6.0 - 2.6.14&lt;/li&gt;
&lt;li&gt;2.5.0 - 2.5.19&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you are using SAML as your authentication method, we &lt;strong&gt;strongly&lt;/strong&gt; recommend &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrading&lt;/a&gt; your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.8.6, 2.7.10, 2.6.15, or 2.5.20.&lt;/p&gt;
&lt;p&gt;Additionally, all existing user sessions should be destroyed:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Put your GitHub Enterprise environment in &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/maintenance-mode/&quot;&gt;Maintenance Mode&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your primary GitHub Enterprise appliance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Destroy the existing SAML sessions.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ echo SAML::Session.destroy_all | ghe-console -y
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Upgrade to the latest patch release in your series, GitHub Enterprise 2.8.6, 2.7.10, 2.6.15, or 2.5.20.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;This vulnerability was reported through the &lt;a href=&quot;https://bounty.github.com/&quot;&gt;GitHub Security Bug Bounty&lt;/a&gt; program and we have no evidence that it has been exploited in the wild.&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have any questions.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: Users could bypass SAML authentication and log in as any other user&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring a protected branch archived whilst running 2.3, will not restore all the settings correctly. This does not affect new instances or protected branches archived on later releases.&lt;/li&gt;
&lt;li&gt;Editing custom messages in the Admin Center doesn&#39;t provide emoji suggestions.&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin Center.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/articles/viewing-push-logs/&quot;&gt;Repository push logs&lt;/a&gt; don&#39;t record whether a push was forced.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Uploading PNG images with &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;through the web interface&lt;/a&gt; can fail with the error &#39;Something went really wrong, and we can&#39;t process that file.&#39;&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Thu, 12 Jan 2017 16:00:26 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.6.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.6.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.5.20</title>
					<description>&lt;h2&gt;SAML authentication bypass in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified that allows an attacker to bypass SAML authentication by creating a fake response. This could allow the attacker to sign in as any user, including administrators.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.8.0 - 2.8.5&lt;/li&gt;
&lt;li&gt;2.7.0 - 2.7.9&lt;/li&gt;
&lt;li&gt;2.6.0 - 2.6.14&lt;/li&gt;
&lt;li&gt;2.5.0 - 2.5.19&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you are using SAML as your authentication method, we &lt;strong&gt;strongly&lt;/strong&gt; recommend &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrading&lt;/a&gt; your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.8.6, 2.7.10, 2.6.15, or 2.5.20.&lt;/p&gt;
&lt;p&gt;Additionally, all existing user sessions should be destroyed:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;Put your GitHub Enterprise environment in &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/maintenance-mode/&quot;&gt;Maintenance Mode&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your primary GitHub Enterprise appliance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Destroy the existing SAML sessions.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ echo SAML::Session.destroy_all | ghe-console-github
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Upgrade to the latest patch release in your series, GitHub Enterprise 2.8.6, 2.7.10, 2.6.15, or 2.5.20.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;This vulnerability was reported through the &lt;a href=&quot;https://bounty.github.com/&quot;&gt;GitHub Security Bug Bounty&lt;/a&gt; program and we have no evidence that it has been exploited in the wild.&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have any questions.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: Users could bypass SAML authentication and log in as any other user&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-migrator&lt;/code&gt; now scrubs access tokens from the logs.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Thu, 12 Jan 2017 16:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.5.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.5.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.8.5</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: Fix SQL injection in &lt;a href=&quot;https://developer.github.com/enterprise/2.8/v3/enterprise/pre_receive_hooks/&quot;&gt;pre-receive hook APIs&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Downloading a support bundle through the Management Console failed if a support bundle was created since the last reboot.&lt;/li&gt;
&lt;li&gt;Japanese characters in PDF files were not rendered.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks were blocked and not timeout properly.&lt;/li&gt;
&lt;li&gt;Alambic crashed resizing user avatars.&lt;/li&gt;
&lt;li&gt;Pending review comments were not included in the count on the pull request index page.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-migrator&lt;/code&gt; now scrubs access tokens from the logs.&lt;/li&gt;
&lt;li&gt;Added cron job to compress core files.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Attempting to convert a user to an organization fails with an internal server error.&lt;/li&gt;
&lt;li&gt;Graphs in the Management Console monitoring page are incorrectly sorted. (updated 2017-01-18)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 04 Jan 2017 16:00:28 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.8.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.8.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.7.9</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: Fix SQL injection in pre-receive hook APIs.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Alambic crashed resizing user avatars.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-migrator&lt;/code&gt; now scrubs access tokens from the logs.&lt;/li&gt;
&lt;li&gt;Added cron job to compress core files.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Additional white spacing can sometimes be seen above the Admin center header.&lt;/li&gt;
&lt;li&gt;Graphs in the Management Console monitoring page are incorrectly sorted. (updated 2017-01-18)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 04 Jan 2017 16:00:27 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.7.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.7.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.6.14</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Alambic crashed resizing user avatars.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-migrator&lt;/code&gt; now scrubs access tokens from the logs.&lt;/li&gt;
&lt;li&gt;Added cron job to compress core files.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring a protected branch archived whilst running 2.3, will not restore all the settings correctly. This does not affect new instances or protected branches archived on later releases.&lt;/li&gt;
&lt;li&gt;Editing custom messages in the Admin Center doesn&#39;t provide emoji suggestions.&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin Center.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/articles/viewing-push-logs/&quot;&gt;Repository push logs&lt;/a&gt; don&#39;t record whether a push was forced.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Uploading PNG images with &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;through the web interface&lt;/a&gt; can fail with the error &#39;Something went really wrong, and we can&#39;t process that file.&#39;&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 04 Jan 2017 16:00:26 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.6.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.6.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.5.19</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Added cron job to compress core files.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 04 Jan 2017 16:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.5.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.5.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.4.22</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.4&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.4 will be deprecated as of February 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 04 Jan 2017 16:00:24 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.4.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.4.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.8.4</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Submodules with names ending in a digit weren&#39;t correctly linked in repository directory listings.&lt;/li&gt;
&lt;li&gt;User profile pages loaded slowly when the user was a member of many organizations. We now limit the number of organization avatars displayed to the first 25 with the most members.&lt;/li&gt;
&lt;li&gt;The sign up button was displayed on Gist pages for unauthenticated users when running GitHub Enterprise in public mode with sign ups disabled.&lt;/li&gt;
&lt;li&gt;Access to a repository granted to teams during a transfer to an organization didn&#39;t take effect.&lt;/li&gt;
&lt;li&gt;Viewing the site admin page for Projects with names that included non-ASCII characters failed with a 500 server error.&lt;/li&gt;
&lt;li&gt;The initial boot of an instance could hang on networks not using DHCP.&lt;/li&gt;
&lt;li&gt;Upgrading an instance could fail due to stale temporary files.&lt;/li&gt;
&lt;li&gt;Upgrading an instance without any Gists could fail.&lt;/li&gt;
&lt;li&gt;Maintenance mode was not enabled when scheduling in advance.&lt;/li&gt;
&lt;li&gt;A race condition could cause saving settings in the Management Console to fail with internal server error.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise is now available in the EU West (London) and Canada (Central) AWS regions.&lt;/li&gt;
&lt;li&gt;The network information displayed on the hypervisor console clearly highlights the unset network settings.&lt;/li&gt;
&lt;li&gt;Admin Center can be used to configure automatic reactivation of suspended users when they successfully sign in.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Attempting to convert a user to an organization fails with an internal server error.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 21 Dec 2016 16:00:28 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.8.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.8.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.7.8</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Pushing an update could cause the &lt;code&gt;babeld&lt;/code&gt; service to segment fault under certain circumstances.&lt;/li&gt;
&lt;li&gt;The deletion of branches and tags rejected by a &lt;code&gt;pre-receive&lt;/code&gt; hook would have failed with the error &amp;quot;Something went wrong with the request. Please try again.&amp;quot;&lt;/li&gt;
&lt;li&gt;Attempts were prematurely made to gather &lt;code&gt;redis&lt;/code&gt; performance statistics. This resulted in excessive logging to the collectd log files.&lt;/li&gt;
&lt;li&gt;Appliance settings saved using the &lt;a href=&quot;https://developer.github.com/enterprise/2.8/v3/enterprise/management_console/#retrieve-settings&quot;&gt;&lt;code&gt;/setup/api/settings&lt;/code&gt;&lt;/a&gt; API endpoint failed to apply when applying at the same time as &lt;a href=&quot;https://developer.github.com/enterprise/2.8/v3/enterprise/management_console/#upload-a-license-for-the-first-time&quot;&gt;uploading the license for the first time&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Access to a repository granted to teams during a transfer to an organization didn&#39;t take effect.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise is now available in the EU West (London) and Canada (Central) AWS regions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Additional white spacing can sometimes be seen above the Admin center header.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 21 Dec 2016 16:00:27 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.7.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.7.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.6.13</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Pushing an update could cause the &lt;code&gt;babeld&lt;/code&gt; service to segment fault under certain circumstances.&lt;/li&gt;
&lt;li&gt;The deletion of branches and tags rejected by a &lt;code&gt;pre-receive&lt;/code&gt; hook would have failed with the error &amp;quot;Something went wrong with the request. Please try again.&amp;quot;&lt;/li&gt;
&lt;li&gt;Appliance settings saved using the &lt;a href=&quot;https://developer.github.com/enterprise/2.8/v3/enterprise/management_console/#retrieve-settings&quot;&gt;&lt;code&gt;/setup/api/settings&lt;/code&gt;&lt;/a&gt; API endpoint failed to apply when applying at the same time as &lt;a href=&quot;https://developer.github.com/enterprise/2.8/v3/enterprise/management_console/#upload-a-license-for-the-first-time&quot;&gt;uploading the license for the first time&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise is now available in the EU West (London) and Canada (Central) AWS regions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring a protected branch archived whilst running 2.3, will not restore all the settings correctly. This does not affect new instances or protected branches archived on later releases.&lt;/li&gt;
&lt;li&gt;Editing custom messages in the Admin Center doesn&#39;t provide emoji suggestions.&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin Center.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/articles/viewing-push-logs/&quot;&gt;Repository push logs&lt;/a&gt; don&#39;t record whether a push was forced.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Uploading PNG images with &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;through the web interface&lt;/a&gt; can fail with the error &#39;Something went really wrong, and we can&#39;t process that file.&#39;&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 21 Dec 2016 16:00:26 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.6.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.6.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.5.18</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Appliance settings saved using the &lt;a href=&quot;https://developer.github.com/enterprise/2.8/v3/enterprise/management_console/#retrieve-settings&quot;&gt;&lt;code&gt;/setup/api/settings&lt;/code&gt;&lt;/a&gt; API endpoint failed to apply when applying at the same time as &lt;a href=&quot;https://developer.github.com/enterprise/2.8/v3/enterprise/management_console/#upload-a-license-for-the-first-time&quot;&gt;uploading the license for the first time&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise is now available in the EU West (London) and Canada (Central) AWS regions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 21 Dec 2016 16:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.5.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.5.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.4.21</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Appliance settings saved using the &lt;a href=&quot;https://developer.github.com/enterprise/2.8/v3/enterprise/management_console/#retrieve-settings&quot;&gt;&lt;code&gt;/setup/api/settings&lt;/code&gt;&lt;/a&gt; API endpoint failed to apply when applying at the same time as &lt;a href=&quot;https://developer.github.com/enterprise/2.8/v3/enterprise/management_console/#upload-a-license-for-the-first-time&quot;&gt;uploading the license for the first time&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise is now available in the EU West (London) and Canada (Central) AWS regions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 21 Dec 2016 16:00:24 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.4.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.4.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.8.3</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The background job to sync assets to the high availability replica appliance could fail.&lt;/li&gt;
&lt;li&gt;Pushing an update could cause the &lt;code&gt;babeld&lt;/code&gt; service to segment fault under certain circumstances.&lt;/li&gt;
&lt;li&gt;The &lt;a href=&quot;https://developer.github.com/enterprise/2.8/v3/activity/events/types/#pullrequestreviewevent&quot;&gt;PullRequestReviewEvent&lt;/a&gt; webhook events were not triggered.&lt;/li&gt;
&lt;li&gt;The deletion of branches and tags rejected by a &lt;code&gt;pre-receive&lt;/code&gt; hook would have failed with the error &amp;quot;Something went wrong with the request. Please try again.&amp;quot;&lt;/li&gt;
&lt;li&gt;Organization and repository e-mails incorrectly contained links to &lt;a href=&quot;https://github.com&quot;&gt;https://github.com&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Pushes to a promoted high availability replica failed.&lt;/li&gt;
&lt;li&gt;Attempts were prematurely made to gather &lt;code&gt;redis&lt;/code&gt; performance statistics. This resulted in excessive logging to the collectd log files.&lt;/li&gt;
&lt;li&gt;The QR code used to configure two-factor authentication failed to generate on appliances with long hostnames and usernames.&lt;/li&gt;
&lt;li&gt;Appliance settings saved using the &lt;a href=&quot;https://developer.github.com/enterprise/2.8/v3/enterprise/management_console/#retrieve-settings&quot;&gt;&lt;code&gt;/setup/api/settings&lt;/code&gt;&lt;/a&gt; API endpoint failed to apply when applying at the same time as &lt;a href=&quot;https://developer.github.com/enterprise/2.8/v3/enterprise/management_console/#upload-a-license-for-the-first-time&quot;&gt;uploading the license for the first time&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Elasticsearch logs are now forwarded when &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/articles/log-forwarding/&quot;&gt;log forwarding&lt;/a&gt; is enabled.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise 2.5 - 2.7 inadvertently ignored the SSH username for &lt;code&gt;git&lt;/code&gt; operations with the SSH protocol. In GitHub Enterprise 2.8, the remote URL for SSH only works for the &lt;code&gt;git&lt;/code&gt; user. (updated 2016-12-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Attempting to convert a user to an organization fails with an internal server error.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 29 Nov 2016 16:00:28 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.8.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.8.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.8.2</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Unable to view webhook delivery logs when the delivery GUID collided.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;404 Not Found&lt;/code&gt; page incorrectly referred to status.github.com.&lt;/li&gt;
&lt;li&gt;LDAP authentication failures were missing from &lt;code&gt;audit.log&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;upload-pack&lt;/code&gt; events were missing from &lt;code&gt;audit.log&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Users were unable to update their primary e-mail address after their password was reset.&lt;/li&gt;
&lt;li&gt;An internal server error occurred in the Management Console when a corrupt license was uploaded.&lt;/li&gt;
&lt;li&gt;In a clustering environment, &lt;code&gt;ghe-cluster-config-apply&lt;/code&gt; could restart services when the application configuration has not changed.&lt;/li&gt;
&lt;li&gt;Merge button was disabled for protected branches when &lt;code&gt;memcached&lt;/code&gt; was stopped.&lt;/li&gt;
&lt;li&gt;Unable to set the &lt;code&gt;site_admin&lt;/code&gt; scope for personal access tokens.&lt;/li&gt;
&lt;li&gt;Disallow administrators from renaming system accounts.&lt;/li&gt;
&lt;li&gt;Users were unable to update their primary e-mail address after migrating data with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;LFS push failed with a 0-byte file.&lt;/li&gt;
&lt;li&gt;Management Console was not redirecting to the previously navigated page after authentication.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The two-factor authentication organization affiliation was added to users&#39; &lt;code&gt;/stafftools&lt;/code&gt; page.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise 2.5 - 2.7 inadvertently ignored the SSH username for &lt;code&gt;git&lt;/code&gt; operations with the SSH protocol. In GitHub Enterprise 2.8, the remote URL for SSH only works for the &lt;code&gt;git&lt;/code&gt; user. (updated 2016-12-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Backups and Disaster Recovery&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise 2.8.2 requires &lt;code&gt;backup-utils-2.8.2&lt;/code&gt; or greater.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Attempting to convert a user to an organization fails with an internal server error. (updated 2016-11-22)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;WARNING:&lt;/strong&gt; Pushes to a promoted high availability replica will fail. (updated 2016-11-23)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 22 Nov 2016 16:00:28 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.8.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.8.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.7.7</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Unable to view webhook delivery logs when the delivery GUID collided.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;upload-pack&lt;/code&gt; events were missing from &lt;code&gt;audit.log&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;In a clustering environment, &lt;code&gt;ghe-cluster-config-apply&lt;/code&gt; could restart services when the application configuration has not changed.&lt;/li&gt;
&lt;li&gt;LFS push failed with a 0-byte file.&lt;/li&gt;
&lt;li&gt;Merge button was disabled for protected branches when &lt;code&gt;memcached&lt;/code&gt; was stopped.&lt;/li&gt;
&lt;li&gt;Disallow administrators from renaming system accounts.&lt;/li&gt;
&lt;li&gt;Users were unable to update their primary e-mail address after migrating data with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Management Console was not redirecting to the previously navigated page after authentication.&lt;/li&gt;
&lt;li&gt;Unable to change an organization owned repository&#39;s visibility from public to private if the repository had collaborators.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-update-check&lt;/code&gt; utility returned an incorrect message, &lt;code&gt;you must first upgrade to&lt;/code&gt;, when it was not necessary.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;memcached&lt;/code&gt; would remain stopped after a crash (e.g. via OOM kill).&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Additional white spacing can sometimes be seen above the Admin center header.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 22 Nov 2016 16:00:27 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.7.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.7.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.6.12</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;LFS push failed with a 0-byte file.&lt;/li&gt;
&lt;li&gt;In a clustering environment, LFS file uploads failed due to an internal HTTP timeout.&lt;/li&gt;
&lt;li&gt;Merge button was disabled for protected branches when &lt;code&gt;memcached&lt;/code&gt; was stopped.&lt;/li&gt;
&lt;li&gt;Disallow administrators from renaming system accounts.&lt;/li&gt;
&lt;li&gt;Users were unable to update their primary e-mail address after migrating data with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-update-check&lt;/code&gt; utility returned an incorrect message, &lt;code&gt;you must first upgrade to&lt;/code&gt;, when it was not necessary.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring a protected branch archived whilst running 2.3, will not restore all the settings correctly. This does not affect new instances or protected branches archived on later releases.&lt;/li&gt;
&lt;li&gt;Editing custom messages in the Admin Center doesn&#39;t provide emoji suggestions.&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin Center.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/articles/viewing-push-logs/&quot;&gt;Repository push logs&lt;/a&gt; don&#39;t record whether a push was forced.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Uploading PNG images with &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;through the web interface&lt;/a&gt; can fail with the error &#39;Something went really wrong, and we can&#39;t process that file.&#39;&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 22 Nov 2016 16:00:26 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.6.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.6.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.5.17</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Merge button was disabled for protected branches when &lt;code&gt;memcached&lt;/code&gt; was stopped.&lt;/li&gt;
&lt;li&gt;Disallow administrators from renaming system accounts.&lt;/li&gt;
&lt;li&gt;Users were unable to update their primary e-mail address after migrating data with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 22 Nov 2016 16:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.5.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.5.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.4.20</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Merge button was disabled for protected branches when &lt;code&gt;memcached&lt;/code&gt; was stopped.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 22 Nov 2016 16:00:24 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.4.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.4.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.8.1</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Pushing to a branch in a fork that is the head of a pull request closed the pull request.&lt;/li&gt;
&lt;li&gt;Unable to change an organization owned repository&#39;s visibility from public to private if the repository had collaborators.&lt;/li&gt;
&lt;li&gt;Upgrading or installing GitHub Enterprise 2.8.0 failed if your license file contained a non-ASCII character.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise 2.5 - 2.7 inadvertently ignored the SSH username for &lt;code&gt;git&lt;/code&gt; operations with the SSH protocol. In GitHub Enterprise 2.8, the remote URL for SSH only works for the &lt;code&gt;git&lt;/code&gt; user. (updated 2016-12-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.github.com/changes/2016-10-27-changes-to-projects-api/&quot;&gt;Changes announced&lt;/a&gt; to the Projects API during its Early Access period are not included in the 2.8 feature release series. (updated 2016-11-18)&lt;/li&gt;
&lt;li&gt;&lt;code&gt;User.failed_login&lt;/code&gt; events aren&#39;t recorded in the audit log when using LDAP authentication. (updated 2016-11-18)&lt;/li&gt;
&lt;li&gt;Attempting to convert a user to an organization fails with an internal server error. (updated 2016-11-22)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;WARNING:&lt;/strong&gt; Pushes to a promoted high availability replica will fail. (updated 2016-11-23)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Thu, 10 Nov 2016 16:00:28 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.8.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.8.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.8.0</title>
					<description>&lt;h2&gt;Features&lt;/h2&gt;
&lt;p&gt;With the new features added in GitHub Enterprise 2.8.0, you can:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Prioritize issues and pull requests within a milestone by &lt;a href=&quot;https://docs.github.com/enterprise/2.8/user/articles/about-milestones/#prioritizing-issues-and-pull-requests-in-milestones&quot;&gt;dragging and dropping them&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Invite anyone to become a member of your organization &lt;a href=&quot;https://docs.github.com/enterprise/2.8/user/articles/adding-people-to-your-organization&quot;&gt;by email&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Use the sidebar to &lt;a href=&quot;https://docs.github.com/enterprise/2.8/user/articles/searching-wikis/&quot;&gt;search wikis&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.8/user/articles/changing-the-base-branch-of-a-pull-request/&quot;&gt;Edit the base branch&lt;/a&gt; after opening a pull request.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.8/user/articles/committing-changes-to-a-pull-request-branch-created-from-a-fork/&quot;&gt;Edit pull requests&lt;/a&gt; created from a fork.&lt;/li&gt;
&lt;li&gt;Use your profile to &lt;a href=&quot;https://docs.github.com/enterprise/2.8/user/articles/viewing-contributions-on-your-profile/#contribution-activity&quot;&gt;view special events&lt;/a&gt; in your GitHub usage history.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.8/user/articles/tracking-the-progress-of-your-work-with-projects/&quot;&gt;Create a Project&lt;/a&gt; to track and prioritize issues, pull requests, and notes to match your workflow.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.8/user/articles/reviewing-changes-in-pull-requests/&quot;&gt;Review the proposed changes&lt;/a&gt; in a pull request.&lt;/li&gt;
&lt;li&gt;As an organization owner, &lt;a href=&quot;https://docs.github.com/enterprise/2.8/user/articles/requiring-two-factor-authentication-in-your-organization/&quot;&gt;require two-factor authentication&lt;/a&gt; to add a layer of security for your organization members, and  outside collaborators.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/user-management/configuring-email-for-notifications/&quot;&gt;Configure a website URL&lt;/a&gt; for all support links on the appliance.&lt;/li&gt;
&lt;li&gt;Use the command-line utility to grant site admins organization admin privileges to &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/articles/command-line-utilities/#ghe-org-admin-promote&quot;&gt;specific organizations&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/articles/command-line-utilities/#git-import&quot;&gt;Import a repository&lt;/a&gt; from an external source repository.&lt;/li&gt;
&lt;li&gt;Add Jupyter notebook files to a repository and &lt;a href=&quot;https://docs.github.com/enterprise/2.8/user/articles/working-with-jupyter-notebook-files-on-github/&quot;&gt;have them render&lt;/a&gt; as static HTML files on GitHub Enterprise.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/installation/configuring-the-default-visibility-of-new-repositories-on-your-appliance/&quot;&gt;Set the default repository visibility&lt;/a&gt; to private or public for all new repositories on the appliance.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.8/user/articles/configuring-a-publishing-source-for-github-pages/&quot;&gt;Select a publishing source&lt;/a&gt; for GitHub Pages and host project documentation alongside your code.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.8/user/articles/adding-a-jekyll-theme-to-your-github-pages-site/&quot;&gt;Add a Jekyll theme&lt;/a&gt; to your GitHub Pages site to install a different site design.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/installation/system-resource-monitoring-and-alerting/&quot;&gt;Monitor&lt;/a&gt; authentication traffic on GitHub Enterprise.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.8/user/articles/reinstating-a-former-member-of-your-organization/&quot;&gt;Reinstate a former member&lt;/a&gt; of an organization and restore their settings.&lt;/li&gt;
&lt;li&gt;Add a &lt;code&gt;LICENSE&lt;/code&gt; file to your project and &lt;a href=&quot;https://docs.github.com/enterprise/2.8/user/articles/adding-a-license-to-a-repository#detecting-a-license&quot;&gt;have it displayed&lt;/a&gt; at the top of the repository page.&lt;/li&gt;
&lt;li&gt;In a clustering environment, the Git Fileserver health dashboard was added to the Site Admin dashboard.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Additional white spacing could sometimes be seen above the Admin center header.&lt;/li&gt;
&lt;li&gt;A site administrator could configure SSL with invalid certificates (e.g. invalid issuer, incomplete chain).&lt;/li&gt;
&lt;li&gt;The &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/articles/command-line-utilities/#ghe-update-check&quot;&gt;&lt;code&gt;ghe-update-check&lt;/code&gt;&lt;/a&gt; utility returned an incorrect message, &lt;code&gt;you must first upgrade to&lt;/code&gt;, when it was not necessary.&lt;/li&gt;
&lt;li&gt;Replication failed after replica promotion because the OpenVPN service was not properly managed.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;memcached&lt;/code&gt; would remain stopped after a crash (e.g. via OOM kill).&lt;/li&gt;
&lt;li&gt;A user could be assigned twice to an Issue.&lt;/li&gt;
&lt;li&gt;When creating a file from the web interface, a backspace incorrectly deleted characters from the directory&#39;s path.,&lt;/li&gt;
&lt;li&gt;When forking a private repository in an organization, repository owners were unable to configure a user to bypass branch restrictions.&lt;/li&gt;
&lt;li&gt;In a gist, users were unable to select lines starting with a number.&lt;/li&gt;
&lt;li&gt;In a wiki diff, users were unable to expand lines from a wiki diff.&lt;/li&gt;
&lt;li&gt;A punctuation could disappear after prettifying an issue or pull request reference.&lt;/li&gt;
&lt;li&gt;Fixed an incorrect description suggesting Member webhook events did not trigger for non-organization repositories.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Reject assets (e.g. avatar, issue attachments) if the file type does not match the extension or &lt;code&gt;Content-Type&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/articles/command-line-utilities/#ghe-console&quot;&gt;&lt;code&gt;ghe-console&lt;/code&gt;&lt;/a&gt; and &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/articles/command-line-utilities/#ghe-dbconsole&quot;&gt;&lt;code&gt;ghe-dbconsole&lt;/code&gt;&lt;/a&gt; utility has been updated with an interactive disclaimer.&lt;/li&gt;
&lt;li&gt;The Management Console, &lt;code&gt;memcached&lt;/code&gt;, &lt;code&gt;snmpd&lt;/code&gt;, &lt;code&gt;graphite-web&lt;/code&gt; services run as an unprivileged user.&lt;/li&gt;
&lt;li&gt;The &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/articles/command-line-utilities/#ghe-config&quot;&gt;&lt;code&gt;ghe-config&lt;/code&gt;&lt;/a&gt; does not require &lt;code&gt;sudo&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.github.com/changes/2016-10-11-pull-request-review-webhooks/&quot;&gt;Pull request review comment webhook events&lt;/a&gt; were added.&lt;/li&gt;
&lt;li&gt;Adobe Flash is no longer required for clipboard operations.&lt;/li&gt;
&lt;li&gt;The Site Admin interface has been updated.&lt;/li&gt;
&lt;li&gt;Preview the new &lt;a href=&quot;https://developer.github.com/changes/2016-09-14-projects-api/&quot;&gt;Projects&lt;/a&gt; API.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.github.com/changes/2016-08-23-change-base/&quot;&gt;Change the base branch&lt;/a&gt; using the updated Pull Request API.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.github.com/changes/2016-08-09-breaking-change-removed-sensitive-fields-from-organization-api-responses-for-owner/&quot;&gt;Removed sensitive fields from Organization API for non-owners&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise 2.5 - 2.7 inadvertently ignored the SSH username for &lt;code&gt;git&lt;/code&gt; operations with the SSH protocol. In GitHub Enterprise 2.8, the remote URL for SSH only works for the &lt;code&gt;git&lt;/code&gt; user. (updated 2016-12-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Backups and Disaster Recovery&lt;/h2&gt;
&lt;p&gt;GitHub Enterprise 2.8 requires at least &lt;a href=&quot;https://github.com/github/backup-utils&quot;&gt;GitHub Enterprise Backup Utilities&lt;/a&gt; 2.8.0 for &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/installation/backups-and-disaster-recovery/&quot;&gt;Backups and Disaster Recovery&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise 2.3&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.3 was deprecated as of November 1, 2016.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this release. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.4&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.4 will be deprecated as of February 2017.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.8/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.github.com/changes/2016-10-27-changes-to-projects-api/&quot;&gt;Changes announced&lt;/a&gt; to the Projects API during its Early Access period are not included in the 2.8 feature release series. (updated 2016-11-18)&lt;/li&gt;
&lt;li&gt;&lt;code&gt;User.failed_login&lt;/code&gt; events aren&#39;t recorded in the audit log when using LDAP authentication. (updated 2016-11-18)&lt;/li&gt;
&lt;li&gt;Attempting to convert a user to an organization fails with an internal server error. (updated 2016-11-22)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;WARNING:&lt;/strong&gt; Upgrading or installing GitHub Enterprise 2.8.0 will fail if your license file contains a non-ASCII character. (updated 2016-11-09)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;WARNING:&lt;/strong&gt; Pushing to a branch in a fork that is the head of a pull request closes the pull request. (updated 2016-11-10)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;WARNING:&lt;/strong&gt; Pushes to a promoted high availability replica will fail. (updated 2016-11-23)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;li&gt;After changing the visibility of a repository, wiki search results have a conflicting number of displayed search results. Administrators can reindex the wiki through the site admin dashboard. (updated 2017-11-09)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 09 Nov 2016 16:00:28 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.8.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.8.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.7.6</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In a clustering environment, LFS file uploads failed due to an internal HTTP timeout.&lt;/li&gt;
&lt;li&gt;In a clustering environment, uploading avatars would fail if a proxy was configured.&lt;/li&gt;
&lt;li&gt;In a clustering environment, a clustering node made unnecessary internal API calls through the load balancer.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise is now available in the US East (Ohio) AWS region.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Additional white spacing can sometimes be seen above the Admin center header.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 01 Nov 2016 16:00:27 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.7.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.7.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.6.11</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In a clustering environment, a clustering node made unnecessary internal API calls through the load balancer.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise is now available in the US East (Ohio) AWS region.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring a protected branch archived whilst running 2.3, will not restore all the settings correctly. This does not affect new instances or protected branches archived on later releases.&lt;/li&gt;
&lt;li&gt;Editing custom messages in the Admin Center doesn&#39;t provide emoji suggestions.&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin Center.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/articles/viewing-push-logs/&quot;&gt;Repository push logs&lt;/a&gt; don&#39;t record whether a push was forced.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Uploading PNG images with &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;through the web interface&lt;/a&gt; can fail with the error &#39;Something went really wrong, and we can&#39;t process that file.&#39;&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 01 Nov 2016 16:00:26 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.6.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.6.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.5.16</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise is now available in the US East (Ohio) AWS region.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-11-15)&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We didn&#39;t include the fix for the issue that migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-11-15)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 01 Nov 2016 16:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.5.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.5.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.4.19</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise is now available in the US East (Ohio) AWS region.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 01 Nov 2016 16:00:24 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.4.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.4.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.3.23</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise is now available in the US East (Ohio) AWS region.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Email can&#39;t be sent over TLS when SSL is disabled.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise 2.3&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.3 is now deprecated.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this release. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 01 Nov 2016 16:00:23 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.3.23</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.3.23</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.7.5</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Background jobs were deleted and lost when stopping replication. This happens when failing over to a high availability replica and during a cluster configuration run.&lt;/li&gt;
&lt;li&gt;Webhook delivery logs were not accessible and logged when a proxy was configured.&lt;/li&gt;
&lt;li&gt;It was possible to change the parent repository to itself.&lt;/li&gt;
&lt;li&gt;SVN checkout failed if a repository has symlinks.&lt;/li&gt;
&lt;li&gt;Running &lt;code&gt;git symbolic-ref&lt;/code&gt; would hang when resolving references with broken symlinks.&lt;/li&gt;
&lt;li&gt;LDAP Sync suspended users that were already suspended, causing unnecessary audit log entries.&lt;/li&gt;
&lt;li&gt;Changing the default branch of a repository was not synchronized to a high availability replica, so the wrong branch was set as default after fail over.&lt;/li&gt;
&lt;li&gt;Webhook delivery logs were not pruned causing unnecessary storage usage.&lt;/li&gt;
&lt;li&gt;Webhook delivery logs may not be accessible and logged if the first webhook event for the day was a push event.&lt;/li&gt;
&lt;li&gt;Custom messaging for suspended users was not displayed to suspended SAML users.&lt;/li&gt;
&lt;li&gt;LDAP Sync removed and re-added users or teams when their distinguished name contained upper case characters.&lt;/li&gt;
&lt;li&gt;Forking a repository could fail if the maintenance job for the repository&#39;s network ran at the same time.&lt;/li&gt;
&lt;li&gt;After restarting a crashed process, writing data to the management console monitoring graphs may not have immediately restarted.&lt;/li&gt;
&lt;li&gt;An error was thrown when trying to access audit logs containing authentication attempts using two-factor authentication.&lt;/li&gt;
&lt;li&gt;In a clustering environment, the web application service could fail to start after cluster configuration run.&lt;/li&gt;
&lt;li&gt;Upgrade to 2.7.4 failed on &lt;code&gt;Running Migration&lt;/code&gt; if there were multiple OAuth applications named &lt;code&gt;GitHub Desktop&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Additional white spacing can sometimes be seen above the Admin center header.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 18 Oct 2016 16:00:27 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.7.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.7.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.6.10</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In a clustering environment, the web application service could fail to start after cluster configuration run.&lt;/li&gt;
&lt;li&gt;Background jobs were deleted and lost when stopping replication. This happens when failing over to a high availability replica and during a cluster configuration run.&lt;/li&gt;
&lt;li&gt;Forking a repository could fail if the maintenance job for the repository&#39;s network ran at the same time.&lt;/li&gt;
&lt;li&gt;Running &lt;code&gt;git symbolic-ref&lt;/code&gt; would hang when resolving references with broken symlinks.&lt;/li&gt;
&lt;li&gt;LDAP Sync suspended users that were already suspended users, causing unnecessary audit log entries.&lt;/li&gt;
&lt;li&gt;Changing the default branch of a repository was not synchronized to a high availability replica, so the wrong branch was set as default after fail over.&lt;/li&gt;
&lt;li&gt;LDAP Sync removed and re-added users or teams when their distinguished name contained upper case characters.&lt;/li&gt;
&lt;li&gt;After restarting a crashed process, writing data to the management console monitoring graphs may not have immediately restarted.&lt;/li&gt;
&lt;li&gt;An error was thrown when trying to access audit logs containing authentication attempts using two-factor authentication.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring a protected branch archived whilst running 2.3, will not restore all the settings correctly. This does not affect new instances or protected branches archived on later releases.&lt;/li&gt;
&lt;li&gt;Editing custom messages in the Admin Center doesn&#39;t provide emoji suggestions.&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin Center.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/articles/viewing-push-logs/&quot;&gt;Repository push logs&lt;/a&gt; don&#39;t record whether a push was forced.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Uploading PNG images with &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;through the web interface&lt;/a&gt; can fail with the error &#39;Something went really wrong, and we can&#39;t process that file.&#39;&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 18 Oct 2016 16:00:26 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.6.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.6.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.5.15</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Changing the default branch of a repository was not synchronized to a high availability replica, so the wrong branch was set as default after fail over.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-11-15)&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We didn&#39;t include the fix for the issue that migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-11-15)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 18 Oct 2016 16:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.5.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.5.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.4.18</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Changing the default branch of a repository was not synchronized to a high availability replica, so the wrong branch was set as default after fail over.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 18 Oct 2016 16:00:24 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.4.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.4.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.3.22</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Changing the default branch of a repository was not synchronized to a high availability replica, so the wrong branch was set as default after fail over.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Email can&#39;t be sent over TLS when SSL is disabled.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 18 Oct 2016 16:00:23 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.3.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.3.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.7.4</title>
					<description>&lt;h2&gt;Pre-generated SSH Host Keys in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified for all 2.x versions of GitHub Enterprise. The GitHub Enterprise images contain pre-generated SSH host keys that were not regenerated upon installation for all supported platforms:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Hyper-V (VHD)&lt;/li&gt;
&lt;li&gt;OpenStack KVM (QCOW2)&lt;/li&gt;
&lt;li&gt;VMware ESXi/vSphere (OVA)&lt;/li&gt;
&lt;li&gt;Xen (VHD)&lt;/li&gt;
&lt;li&gt;Amazon Web Services (See the &lt;strong&gt;&lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; in GitHub Enterprise&lt;/strong&gt; section below)&lt;/li&gt;
&lt;li&gt;Microsoft Azure&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This means an attacker with the capability to perform a &lt;a href=&quot;https://en.wikipedia.org/wiki/Man-in-the-middle_attack&quot;&gt;man-in-the-middle attack&lt;/a&gt; on SSH traffic can intercept and modify network traffic to the GitHub Enterprise appliance.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.7.0 - 2.7.3&lt;/li&gt;
&lt;li&gt;2.6.0 - 2.6.8&lt;/li&gt;
&lt;li&gt;2.5.0 - 2.5.13&lt;/li&gt;
&lt;li&gt;2.4.0 - 2.4.16&lt;/li&gt;
&lt;li&gt;2.3.0 - 2.3.20&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This vulnerability was found and reported internally and we have no evidence that it has been exploited in the wild.&lt;/p&gt;
&lt;p&gt;We &lt;strong&gt;strongly&lt;/strong&gt; recommend &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrading&lt;/a&gt; your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, or 2.3.21. In addition, with &lt;a href=&quot;https://github.com/github/backup-utils/releases/tag/v2.7.1&quot;&gt;backup-utils-2.7.1&lt;/a&gt;, &lt;code&gt;ghe-backup&lt;/code&gt; and &lt;code&gt;ghe-restore&lt;/code&gt; will check for any leaked SSH host keys in the snapshot(s).&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have questions.&lt;/p&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;h3&gt;Verification and Mitigation on GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater&lt;/h3&gt;
&lt;p&gt;If you&#39;ve upgraded to the latest patch release, GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater,&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your primary GitHub Enterprise appliance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Check for leaked SSH host keys using the &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/articles/command-line-utilities/#ghe-ssh-check-host-keys&quot;&gt;&lt;code&gt;ghe-ssh-check-host-keys&lt;/code&gt;&lt;/a&gt; utility.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-ssh-check-host-keys
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The utility should output either:&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;One or more of your SSH host keys were found in the blacklist.
Please reset your host keys using ghe-ssh-roll-host-keys.
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;The SSH host keys were not found in the SSH host key blacklist.
No additional steps are needed/recommended at this time.
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;If one or more SSH host keys were found in the blacklist, continue to the next step. Otherwise, your GitHub Enterprise environment is not vulnerable.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Put your GitHub Enterprise environment in &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/maintenance-mode/&quot;&gt;Maintenance Mode&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Rotate all SSH host keys using the &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/articles/command-line-utilities/#ghe-ssh-roll-host-keys&quot;&gt;&lt;code&gt;ghe-ssh-roll-host-keys&lt;/code&gt;&lt;/a&gt; utility.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo ghe-ssh-roll-host-keys
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The utility should output:&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ SSH host keys have successfully been rolled.
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If you&#39;ve upgraded to GitHub Enterprise 2.7.4, 2.6.9, or greater, and you are using the &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/high-availability-configuration/&quot;&gt;High Availability Configuration&lt;/a&gt;, there are no additional steps to take on your replica appliance.&lt;/p&gt;
&lt;p&gt;If you&#39;ve upgraded to GitHub Enterprise 2.5.14, 2.4.17, 2.3.21, or greater, and you are using the &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/high-availability-configuration/&quot;&gt;High Availability Configuration&lt;/a&gt;,&lt;/p&gt;
&lt;ol start=&quot;6&quot;&gt;
&lt;li&gt;
&lt;p&gt;After completing steps 1-5, stop replication on the replica appliance.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-stop
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Synchronize the SSH host keys from the primary appliance.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-setup
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Resume replication on the replica appliance.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-start
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If you&#39;ve upgraded to GitHub Enterprise 2.7.4, 2.6.9, 2.5.14 or greater, and you are using &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/clustering/&quot;&gt;Clustering&lt;/a&gt;,&lt;/p&gt;
&lt;ol start=&quot;6&quot;&gt;
&lt;li&gt;
&lt;p&gt;After completing steps 1-5, apply the changes to all cluster nodes.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-cluster-config-apply
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;h3&gt;Verification and Mitigation if Immediate Upgrade is not Possible&lt;/h3&gt;
&lt;p&gt;If you&#39;re unable to upgrade immediately to the latest patch release, GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater,&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your primary GitHub Enterprise appliance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Download the list of leaked SSH host keys and verify its content using any of the provided hashes.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ curl -O https://enterprise.github.com/security/2016-09-20/ghe-ssh-leaked-host-keys-list.txt
$ sha256sum ghe-ssh-leaked-host-keys-list.txt
3bb29658784a4059a41f1a77cffba9586baab179ba07b795f80e12a9f10c5665  ghe-ssh-leaked-host-keys-list.txt
$ sha1sum ghe-ssh-leaked-host-keys-list.txt
5db799da044da9aae0bcfc523d22e7ce0fe72550  ghe-ssh-leaked-host-keys-list.txt
$ md5sum ghe-ssh-leaked-host-keys-list.txt
de75bcb0bf1d13e15620952c0af8da41  ghe-ssh-leaked-host-keys-list.txt
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Print the fingerprint of your GitHub Enterprise appliance&#39;s SSH host keys.&lt;br /&gt;
&lt;strong&gt;Note:&lt;/strong&gt; The &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; may exist on your GitHub Enterprise appliance but is only used in 2.7.4 or greater.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ssh-keygen -lf /etc/ssh/ssh_host_dsa_key.pub
1024 b2:69:82:2f:25:48:bb:fc:62:c7:9a:de:41:42:13:55 /etc/ssh/ssh_host_dsa_key.pub (DSA)
$ ssh-keygen -lf /etc/ssh/ssh_host_ecdsa_key.pub
256 c0:cb:fd:07:33:e9:62:14:6b:fb:d5:26:54:f3:c5:0d /etc/ssh/ssh_host_ecdsa_key.pub (ECDSA)
$ ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pub
256 d6:92:21:4b:04:3b:22:f5:ee:85:0a:63:bf:b3:fe:9b /etc/ssh/ssh_host_ed25519_key.pub (ED25519)
$ ssh-keygen -lf /etc/ssh/ssh_host_rsa_key.pub
2048 0f:ee:8d:02:2d:e1:76:f3:eb:f5:af:cb:38:9a:1c:33 /etc/ssh/ssh_host_rsa_key.pub (RSA)
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Check for leaked SSH host keys by comparing against the downloaded list of leaked SSH host keys.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;If one or more SSH host keys were found in the blacklist, continue to the next step. Otherwise, your GitHub Enterprise environment is not vulnerable.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Put your GitHub Enterprise environment in &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/maintenance-mode/&quot;&gt;Maintenance Mode&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Remove all SSH host keys.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo rm -f /etc/ssh/ssh_host_*
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Regenerate the SSH host keys.&lt;br /&gt;
&lt;strong&gt;Note:&lt;/strong&gt; The &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; may exist on your GitHub Enterprise appliance but is only used and regenerated for in 2.7.4 or greater.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo ssh-keygen -t ed25519 -N &amp;quot;&amp;quot; -f /etc/ssh/ssh_host_ed25519_key
$ sudo dpkg-reconfigure openssh-server
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Apply the changes to the &lt;code&gt;ssh&lt;/code&gt; and &lt;code&gt;babeld&lt;/code&gt; service.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo cp /etc/ssh/ssh_host_{rsa,dsa,ecdsa,ed25519}_key{,.pub} /data/user/common/
$ sudo chown babeld:babeld /data/user/common/ssh_host_{rsa,dsa,ecdsa,ed25519}_key{,.pub}
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If you&#39;re unable to upgrade immediately to GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater, and you are using the &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/high-availability-configuration/&quot;&gt;High Availability Configuration&lt;/a&gt;,&lt;/p&gt;
&lt;ol start=&quot;10&quot;&gt;
&lt;li&gt;After completing steps 1-9, stop replication on the replica appliance.&lt;/li&gt;
&lt;/ol&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-stop
&lt;/code&gt;&lt;/pre&gt;
&lt;ol start=&quot;11&quot;&gt;
&lt;li&gt;Synchronize the SSH host keys from the primary appliance.&lt;/li&gt;
&lt;/ol&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-setup
&lt;/code&gt;&lt;/pre&gt;
&lt;ol start=&quot;12&quot;&gt;
&lt;li&gt;Resume replication on the replica appliance.&lt;/li&gt;
&lt;/ol&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-start
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;If you&#39;re unable to upgrade immediately to GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, or greater, and you are using &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/clustering/&quot;&gt;Clustering&lt;/a&gt;,&lt;/p&gt;
&lt;ol start=&quot;10&quot;&gt;
&lt;li&gt;After completing steps 1-9, apply the changes to all cluster nodes.&lt;/li&gt;
&lt;/ol&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-cluster-config-apply
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;h3&gt;Post SSH Host Key Rotation&lt;/h3&gt;
&lt;p&gt;After rotating the SSH host keys, your GitHub Enterprise environment can exit &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/maintenance-mode/&quot;&gt;Maintenance Mode&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Your end-users will receive an error message when attempting to use the &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;Administrative Shell (SSH)&lt;/a&gt; or the SSH protocol for Git activity. The rotation does not affect users using the HTTPS protocol for Git activity.&lt;/p&gt;
&lt;p&gt;For example, the following is an output from the command-line,&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@    WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!     @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
Someone could be eavesdropping on you right now (man-in-the-middle attack)!
It is also possible that a host key has just been changed.
The fingerprint for the ECDSA key sent by the remote host is
SHA256:seFT9eIOmAZWbfcO9yU1sXiEYIqcrdi0qttbtmNm0Io.
Please contact your system administrator.
Add correct host key in /Users/monalisa/.ssh/known_hosts to get rid of this message.
Offending ECDSA key in /Users/monalisa/.ssh/known_hosts:42
ECDSA host key for [github.example.com]:122 has changed and you have requested strict checking.
Host key verification failed.
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;After updating the &lt;code&gt;known_hosts&lt;/code&gt;, end-users will be prompted to accept a new fingerprint.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ssh -p 122 admin@github.example.com
The authenticity of host &#39;[github.example.com]:122 ([169.254.1.1]:122)&#39; can&#39;t be established.
ECDSA key fingerprint is SHA256:seFT9eIOmAZWbfcO9yU1sXiEYIqcrdi0qttbtmNm0Io.
Are you sure you want to continue connecting (yes/no)?
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;We strongly recommend publishing your GitHub Enterprise appliance&#39;s SSH host key fingerprints in a location that is accessible to all your end-users. For example, for GitHub.com, we publish the SSH fingerprints at &lt;a href=&quot;https://docs.github.com/articles/what-are-github-s-ssh-key-fingerprints/&quot;&gt;https://docs.github.com/articles/what-are-github-s-ssh-key-fingerprints/&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you&#39;d like to to give end-users notice before rotating the SSH host keys, follow the instructions in the &lt;strong&gt;Verification and Mitigation if Immediate Upgrade is not Possible&lt;/strong&gt; skipping step 7 and replacing step 8 with,&lt;/p&gt;
&lt;ol start=&quot;8&quot;&gt;
&lt;li&gt;
&lt;p&gt;Regenerate the SSH host keys.&lt;br /&gt;
&lt;strong&gt;Note:&lt;/strong&gt; The &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; may exist on your GitHub Enterprise appliance but is only used and regenerated for in 2.7.4 or greater.&lt;/p&gt;
&lt;p&gt;i. Pre-generate new SSH host keys to a temporary directory.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ssh-keygen -t dsa -N &amp;quot;&amp;quot; -f /var/tmp/ssh_host_dsa_key
$ ssh-keygen -t rsa -N &amp;quot;&amp;quot; -f /var/tmp/ssh_host_rsa_key
$ ssh-keygen -t ecdsa -N &amp;quot;&amp;quot; -f /var/tmp/ssh_host_ecdsa_key
$ ssh-keygen -t ed25519 -N &amp;quot;&amp;quot; -f /var/tmp/ssh_host_ed25519_key
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;ii. Print the fingerprint of your GitHub Enterprise appliance&#39;s SSH host keys for tentative rotation.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ssh-keygen -lf /var/tmp/ssh_host_dsa_key.pub
 1024 b2:69:82:2f:25:48:bb:fc:62:c7:9a:de:41:42:13:55 /var/tmp/ssh_host_dsa_key.pub (DSA)
$ ssh-keygen -lf /var/tmp/ssh_host_ecdsa_key.pub
 256 c0:cb:fd:07:33:e9:62:14:6b:fb:d5:26:54:f3:c5:0d /var/tmp/ssh_host_ecdsa_key.pub (ECDSA)
$ ssh-keygen -lf /var/tmp/ssh_host_ed25519_key.pub
 256 d6:92:21:4b:04:3b:22:f5:ee:85:0a:63:bf:b3:fe:9b /var/tmp/ssh_host_ed25519_key.pub (ED25519)
$ ssh-keygen -lf /var/tmp/ssh_host_rsa_key.pub
248 0f:ee:8d:02:2d:e1:76:f3:eb:f5:af:cb:38:9a:1c:33 /var/tmp/ssh_host_rsa_key.pub (RSA)
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;iii. Once you are ready to migrate to the new, rotated SSH host keys, move the host keys from the temporary directory and apply the changes to the &lt;code&gt;ssh&lt;/code&gt; service.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo mv /var/tmp/ssh_host_{rsa,dsa,ecdsa,ed25519}_key{,.pub} /etc/ssh
$ sudo service ssh restart
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;iv. Continue with steps 9 in the &lt;strong&gt;Verification and Mitigation if Immediate Upgrade is not Possible&lt;/strong&gt; section.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;&lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; in GitHub Enterprise&lt;/h3&gt;
&lt;p&gt;The 2.x versions of GitHub Enterprise on all supported platforms:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Hyper-V (VHD)&lt;/li&gt;
&lt;li&gt;OpenStack KVM (QCOW2)&lt;/li&gt;
&lt;li&gt;VMware ESXi/vSphere (OVA)&lt;/li&gt;
&lt;li&gt;Xen (VHD)&lt;/li&gt;
&lt;li&gt;Amazon Web Services&lt;/li&gt;
&lt;li&gt;Microsoft Azure&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;contain a pre-generated &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt;. However, only GitHub Enterprise 2.7.4 or greater use the &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt;. This can be verified by checking your GitHub Enterprise appliance&#39;s &lt;code&gt;/etc/ssh/sshd_config&lt;/code&gt;, which added &lt;code&gt;HostKey /etc/ssh/ssh_host_ed25519_key&lt;/code&gt; in 2.7.4 or greater.&lt;/p&gt;
&lt;p&gt;The &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; may exist on your GitHub Enterprise appliance but is only used in 2.7.4 or greater.&lt;/p&gt;
&lt;p&gt;If you&#39;ve upgraded your appliance to 2.7.4 or greater on any of the supported platforms including Amazon Web Services, please follow the instructions in the &lt;strong&gt;Verification and Mitigation on GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater&lt;/strong&gt; section.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; Pre-generated SSH host keys were not regenerated when installing appliances from GitHub Enterprise 2.x images.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;When rejected from a pre-receive hook, API merge requests incorrectly returned &lt;code&gt;Internal Server Error&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Webhooks failed to deliver when the external server could only be resolved by the configured proxy server.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;snmpd&lt;/code&gt; service did not automatically start on replica instances.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-system-info&lt;/code&gt; command line utility was not available to run because the utility was missing from the &lt;code&gt;$PATH&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;In a clustering environment, the &lt;code&gt;redis-server&lt;/code&gt; role may not have dedicated memory allocated to the &lt;code&gt;redis&lt;/code&gt; service.&lt;/li&gt;
&lt;li&gt;In a clustering environment, storage assets that were not replicated or marked for deletion were not properly maintained.&lt;/li&gt;
&lt;li&gt;Users were unable to add or remove deploy keys when LDAP sync is enabled.&lt;/li&gt;
&lt;li&gt;In a clustering environment, the &lt;code&gt;ghe-cluster-config-check&lt;/code&gt; command line utility terminated early from unsuccessful cURL checks.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks using the &lt;code&gt;git-grep&lt;/code&gt; command may have failed using the default hook environment due to missing libraries.&lt;/li&gt;
&lt;li&gt;The initial push of a repository with many Git refs could time out.&lt;/li&gt;
&lt;li&gt;The root API endpoint incorrectly returned &lt;code&gt;Not Found&lt;/code&gt; when the trailing slash was omitted.&lt;/li&gt;
&lt;li&gt;Repository maintenance could time out for large repositories, so the timeout was increased to 120 minutes.&lt;/li&gt;
&lt;li&gt;Upgrades could incorrectly output &lt;code&gt;upgrade failed!&lt;/code&gt; after a successful upgrade.&lt;/li&gt;
&lt;li&gt;After upgrading, the site admin page on replica instances could incorrectly show &lt;code&gt;Verifying ElasticSearch indexes&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Elasticsearch logs could grow very large due to incorrect HTTP and HTTPS connection management.&lt;/li&gt;
&lt;li&gt;SSH forced commands containing &lt;code&gt;${},&lt;/code&gt; were not configurable from the Management Console.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-ssl-ca-certificate-install&lt;/code&gt; command line utility did not accept a piped certificate as input.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise is now available in the Asia Pacific (Mumbai) AWS region.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Additional white spacing can sometimes be seen above the Admin center header.&lt;/li&gt;
&lt;li&gt;Upgrade to 2.7.4 will fail on &lt;code&gt;Running Migration&lt;/code&gt; if there are multiple OAuth applications named &lt;code&gt;GitHub Desktop&lt;/code&gt;. (updated 2016-09-22)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;strong&gt;Pre-generated SSH Host Keys in GitHub Enterprise&lt;/strong&gt; vulnerability disclosure added the &lt;strong&gt;&lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; in GitHub Enterprise&lt;/strong&gt; for GitHub Enterprise 2.7.4 or greater appliances on the Amazon Web Services platform. (updated 2016-09-22)&lt;/li&gt;
&lt;li&gt;Editing custom messages in the Admin center doesn&#39;t provide emoji suggestions was resolved in 2.7.0. (updated 2016-09-21)&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin center was resolved in 2.7.0. (updated 2016-09-21)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 20 Sep 2016 10:30:46 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.7.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.7.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.6.9</title>
					<description>&lt;h2&gt;Pre-generated SSH Host Keys in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified for all 2.x versions of GitHub Enterprise. The GitHub Enterprise images contain pre-generated SSH host keys that were not regenerated upon installation for all supported platforms:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Hyper-V (VHD)&lt;/li&gt;
&lt;li&gt;OpenStack KVM (QCOW2)&lt;/li&gt;
&lt;li&gt;VMware ESXi/vSphere (OVA)&lt;/li&gt;
&lt;li&gt;Xen (VHD)&lt;/li&gt;
&lt;li&gt;Amazon Web Services (See the &lt;strong&gt;&lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; in GitHub Enterprise&lt;/strong&gt; section below)&lt;/li&gt;
&lt;li&gt;Microsoft Azure&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This means an attacker with the capability to perform a &lt;a href=&quot;https://en.wikipedia.org/wiki/Man-in-the-middle_attack&quot;&gt;man-in-the-middle attack&lt;/a&gt; on SSH traffic can intercept and modify network traffic to the GitHub Enterprise appliance.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.7.0 - 2.7.3&lt;/li&gt;
&lt;li&gt;2.6.0 - 2.6.8&lt;/li&gt;
&lt;li&gt;2.5.0 - 2.5.13&lt;/li&gt;
&lt;li&gt;2.4.0 - 2.4.16&lt;/li&gt;
&lt;li&gt;2.3.0 - 2.3.20&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This vulnerability was found and reported internally and we have no evidence that it has been exploited in the wild.&lt;/p&gt;
&lt;p&gt;We &lt;strong&gt;strongly&lt;/strong&gt; recommend &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrading&lt;/a&gt; your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, or 2.3.21. In addition, with &lt;a href=&quot;https://github.com/github/backup-utils/releases/tag/v2.7.1&quot;&gt;backup-utils-2.7.1&lt;/a&gt;, &lt;code&gt;ghe-backup&lt;/code&gt; and &lt;code&gt;ghe-restore&lt;/code&gt; will check for any leaked SSH host keys in the snapshot(s).&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have questions.&lt;/p&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;h3&gt;Verification and Mitigation on GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater&lt;/h3&gt;
&lt;p&gt;If you&#39;ve upgraded to the latest patch release, GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater,&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your primary GitHub Enterprise appliance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Check for leaked SSH host keys using the &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/articles/command-line-utilities/#ghe-ssh-check-host-keys&quot;&gt;&lt;code&gt;ghe-ssh-check-host-keys&lt;/code&gt;&lt;/a&gt; utility.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-ssh-check-host-keys
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The utility should output either:&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;One or more of your SSH host keys were found in the blacklist.
Please reset your host keys using ghe-ssh-roll-host-keys.
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;The SSH host keys were not found in the SSH host key blacklist.
No additional steps are needed/recommended at this time.
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;If one or more SSH host keys were found in the blacklist, continue to the next step. Otherwise, your GitHub Enterprise environment is not vulnerable.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Put your GitHub Enterprise environment in &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/maintenance-mode/&quot;&gt;Maintenance Mode&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Rotate all SSH host keys using the &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/articles/command-line-utilities/#ghe-ssh-roll-host-keys&quot;&gt;&lt;code&gt;ghe-ssh-roll-host-keys&lt;/code&gt;&lt;/a&gt; utility.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo ghe-ssh-roll-host-keys
$ sudo ssh-keygen -t ed25519 -N &amp;quot;&amp;quot; -f /etc/ssh/ssh_host_ed25519_key
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The utility should output:&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ SSH host keys have successfully been rolled.
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If you&#39;ve upgraded to GitHub Enterprise 2.7.4, 2.6.9, or greater, and you are using the &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/high-availability-configuration/&quot;&gt;High Availability Configuration&lt;/a&gt;, there are no additional steps to take on your replica appliance.&lt;/p&gt;
&lt;p&gt;If you&#39;ve upgraded to GitHub Enterprise 2.5.14, 2.4.17, 2.3.21, or greater, and you are using the &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/high-availability-configuration/&quot;&gt;High Availability Configuration&lt;/a&gt;,&lt;/p&gt;
&lt;ol start=&quot;6&quot;&gt;
&lt;li&gt;
&lt;p&gt;After completing steps 1-5, stop replication on the replica appliance.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-stop
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Synchronize the SSH host keys from the primary appliance.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-setup
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Resume replication on the replica appliance.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-start
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If you&#39;ve upgraded to GitHub Enterprise 2.7.4, 2.6.9, 2.5.14 or greater, and you are using &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/clustering/&quot;&gt;Clustering&lt;/a&gt;,&lt;/p&gt;
&lt;ol start=&quot;6&quot;&gt;
&lt;li&gt;
&lt;p&gt;After completing steps 1-5, apply the changes to all cluster nodes.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-cluster-config-apply
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;h3&gt;Verification and Mitigation if Immediate Upgrade is not Possible&lt;/h3&gt;
&lt;p&gt;If you&#39;re unable to upgrade immediately to the latest patch release, GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater,&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your primary GitHub Enterprise appliance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Download the list of leaked SSH host keys and verify its content using any of the provided hashes.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ curl -O https://enterprise.github.com/security/2016-09-20/ghe-ssh-leaked-host-keys-list.txt
$ sha256sum ghe-ssh-leaked-host-keys-list.txt
3bb29658784a4059a41f1a77cffba9586baab179ba07b795f80e12a9f10c5665  ghe-ssh-leaked-host-keys-list.txt
$ sha1sum ghe-ssh-leaked-host-keys-list.txt
5db799da044da9aae0bcfc523d22e7ce0fe72550  ghe-ssh-leaked-host-keys-list.txt
$ md5sum ghe-ssh-leaked-host-keys-list.txt
de75bcb0bf1d13e15620952c0af8da41  ghe-ssh-leaked-host-keys-list.txt
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Print the fingerprint of your GitHub Enterprise appliance&#39;s SSH host keys.&lt;br /&gt;
&lt;strong&gt;Note:&lt;/strong&gt; The &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; may exist on your GitHub Enterprise appliance but is only used in 2.7.4 or greater.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ssh-keygen -lf /etc/ssh/ssh_host_dsa_key.pub
1024 b2:69:82:2f:25:48:bb:fc:62:c7:9a:de:41:42:13:55 /etc/ssh/ssh_host_dsa_key.pub (DSA)
$ ssh-keygen -lf /etc/ssh/ssh_host_ecdsa_key.pub
256 c0:cb:fd:07:33:e9:62:14:6b:fb:d5:26:54:f3:c5:0d /etc/ssh/ssh_host_ecdsa_key.pub (ECDSA)
$ ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pub
256 d6:92:21:4b:04:3b:22:f5:ee:85:0a:63:bf:b3:fe:9b /etc/ssh/ssh_host_ed25519_key.pub (ED25519)
$ ssh-keygen -lf /etc/ssh/ssh_host_rsa_key.pub
2048 0f:ee:8d:02:2d:e1:76:f3:eb:f5:af:cb:38:9a:1c:33 /etc/ssh/ssh_host_rsa_key.pub (RSA)
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Check for leaked SSH host keys by comparing against the downloaded list of leaked SSH host keys.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;If one or more SSH host keys were found in the blacklist, continue to the next step. Otherwise, your GitHub Enterprise environment is not vulnerable.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Put your GitHub Enterprise environment in &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/maintenance-mode/&quot;&gt;Maintenance Mode&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Remove all SSH host keys.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo rm -f /etc/ssh/ssh_host_*
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Regenerate the SSH host keys.&lt;br /&gt;
&lt;strong&gt;Note:&lt;/strong&gt; The &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; may exist on your GitHub Enterprise appliance but is only used and regenerated for in 2.7.4 or greater.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo ssh-keygen -t ed25519 -N &amp;quot;&amp;quot; -f /etc/ssh/ssh_host_ed25519_key
$ sudo dpkg-reconfigure openssh-server
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Apply the changes to the &lt;code&gt;ssh&lt;/code&gt; and &lt;code&gt;babeld&lt;/code&gt; service.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo cp /etc/ssh/ssh_host_{rsa,dsa,ecdsa,ed25519}_key{,.pub} /data/user/common/
$ sudo chown babeld:babeld /data/user/common/ssh_host_{rsa,dsa,ecdsa,ed25519}_key{,.pub}
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If you&#39;re unable to upgrade immediately to GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater, and you are using the &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/high-availability-configuration/&quot;&gt;High Availability Configuration&lt;/a&gt;,&lt;/p&gt;
&lt;ol start=&quot;10&quot;&gt;
&lt;li&gt;After completing steps 1-9, stop replication on the replica appliance.&lt;/li&gt;
&lt;/ol&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-stop
&lt;/code&gt;&lt;/pre&gt;
&lt;ol start=&quot;11&quot;&gt;
&lt;li&gt;Synchronize the SSH host keys from the primary appliance.&lt;/li&gt;
&lt;/ol&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-setup
&lt;/code&gt;&lt;/pre&gt;
&lt;ol start=&quot;12&quot;&gt;
&lt;li&gt;Resume replication on the replica appliance.&lt;/li&gt;
&lt;/ol&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-start
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;If you&#39;re unable to upgrade immediately to GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, or greater, and you are using &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/clustering/&quot;&gt;Clustering&lt;/a&gt;,&lt;/p&gt;
&lt;ol start=&quot;10&quot;&gt;
&lt;li&gt;After completing steps 1-9, apply the changes to all cluster nodes.&lt;/li&gt;
&lt;/ol&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-cluster-config-apply
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;h3&gt;Post SSH Host Key Rotation&lt;/h3&gt;
&lt;p&gt;After rotating the SSH host keys, your GitHub Enterprise environment can exit &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/maintenance-mode/&quot;&gt;Maintenance Mode&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Your end-users will receive an error message when attempting to use the &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;Administrative Shell (SSH)&lt;/a&gt; or the SSH protocol for Git activity. The rotation does not affect users using the HTTPS protocol for Git activity.&lt;/p&gt;
&lt;p&gt;For example, the following is an output from the command-line,&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@    WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!     @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
Someone could be eavesdropping on you right now (man-in-the-middle attack)!
It is also possible that a host key has just been changed.
The fingerprint for the ECDSA key sent by the remote host is
SHA256:seFT9eIOmAZWbfcO9yU1sXiEYIqcrdi0qttbtmNm0Io.
Please contact your system administrator.
Add correct host key in /Users/monalisa/.ssh/known_hosts to get rid of this message.
Offending ECDSA key in /Users/monalisa/.ssh/known_hosts:42
ECDSA host key for [github.example.com]:122 has changed and you have requested strict checking.
Host key verification failed.
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;After updating the &lt;code&gt;known_hosts&lt;/code&gt;, end-users will be prompted to accept a new fingerprint.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ssh -p 122 admin@github.example.com
The authenticity of host &#39;[github.example.com]:122 ([169.254.1.1]:122)&#39; can&#39;t be established.
ECDSA key fingerprint is SHA256:seFT9eIOmAZWbfcO9yU1sXiEYIqcrdi0qttbtmNm0Io.
Are you sure you want to continue connecting (yes/no)?
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;We strongly recommend publishing your GitHub Enterprise appliance&#39;s SSH host key fingerprints in a location that is accessible to all your end-users. For example, for GitHub.com, we publish the SSH fingerprints at &lt;a href=&quot;https://docs.github.com/articles/what-are-github-s-ssh-key-fingerprints/&quot;&gt;https://docs.github.com/articles/what-are-github-s-ssh-key-fingerprints/&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you&#39;d like to to give end-users notice before rotating the SSH host keys, follow the instructions in the &lt;strong&gt;Verification and Mitigation if Immediate Upgrade is not Possible&lt;/strong&gt; skipping step 7 and replacing step 8 with,&lt;/p&gt;
&lt;ol start=&quot;8&quot;&gt;
&lt;li&gt;
&lt;p&gt;Regenerate the SSH host keys.&lt;br /&gt;
&lt;strong&gt;Note:&lt;/strong&gt; The &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; may exist on your GitHub Enterprise appliance but is only used and regenerated for in 2.7.4 or greater.&lt;/p&gt;
&lt;p&gt;i. Pre-generate new SSH host keys to a temporary directory.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ssh-keygen -t dsa -N &amp;quot;&amp;quot; -f /var/tmp/ssh_host_dsa_key
$ ssh-keygen -t rsa -N &amp;quot;&amp;quot; -f /var/tmp/ssh_host_rsa_key
$ ssh-keygen -t ecdsa -N &amp;quot;&amp;quot; -f /var/tmp/ssh_host_ecdsa_key
$ ssh-keygen -t ed25519 -N &amp;quot;&amp;quot; -f /var/tmp/ssh_host_ed25519_key
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;ii. Print the fingerprint of your GitHub Enterprise appliance&#39;s SSH host keys for tentative rotation.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ssh-keygen -lf /var/tmp/ssh_host_dsa_key.pub
 1024 b2:69:82:2f:25:48:bb:fc:62:c7:9a:de:41:42:13:55 /var/tmp/ssh_host_dsa_key.pub (DSA)
$ ssh-keygen -lf /var/tmp/ssh_host_ecdsa_key.pub
 256 c0:cb:fd:07:33:e9:62:14:6b:fb:d5:26:54:f3:c5:0d /var/tmp/ssh_host_ecdsa_key.pub (ECDSA)
$ ssh-keygen -lf /var/tmp/ssh_host_ed25519_key.pub
 256 d6:92:21:4b:04:3b:22:f5:ee:85:0a:63:bf:b3:fe:9b /var/tmp/ssh_host_ed25519_key.pub (ED25519)
$ ssh-keygen -lf /var/tmp/ssh_host_rsa_key.pub
248 0f:ee:8d:02:2d:e1:76:f3:eb:f5:af:cb:38:9a:1c:33 /var/tmp/ssh_host_rsa_key.pub (RSA)
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;iii. Once you are ready to migrate to the new, rotated SSH host keys, move the host keys from the temporary directory and apply the changes to the &lt;code&gt;ssh&lt;/code&gt; service.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo mv /var/tmp/ssh_host_{rsa,dsa,ecdsa,ed25519}_key{,.pub} /etc/ssh
$ sudo service ssh restart
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;iv. Continue with steps 9 in the &lt;strong&gt;Verification and Mitigation if Immediate Upgrade is not Possible&lt;/strong&gt; section.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;&lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; in GitHub Enterprise&lt;/h3&gt;
&lt;p&gt;The 2.x versions of GitHub Enterprise on all supported platforms:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Hyper-V (VHD)&lt;/li&gt;
&lt;li&gt;OpenStack KVM (QCOW2)&lt;/li&gt;
&lt;li&gt;VMware ESXi/vSphere (OVA)&lt;/li&gt;
&lt;li&gt;Xen (VHD)&lt;/li&gt;
&lt;li&gt;Amazon Web Services&lt;/li&gt;
&lt;li&gt;Microsoft Azure&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;contained a pre-generated &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt;. However, only GitHub Enterprise 2.7.4 or greater use the &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt;. This can be verified by checking your GitHub Enterprise appliance&#39;s &lt;code&gt;/etc/ssh/sshd_config&lt;/code&gt;, which added &lt;code&gt;HostKey /etc/ssh/ssh_host_ed25519_key&lt;/code&gt; in 2.7.4 or greater.&lt;/p&gt;
&lt;p&gt;The &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; may exist on your GitHub Enterprise appliance but is only used in 2.7.4 or greater.&lt;/p&gt;
&lt;p&gt;If you&#39;ve upgraded your appliance to 2.7.4 or greater on any of the supported platforms including Amazon Web Services, please follow the instructions in the &lt;strong&gt;Verification and Mitigation on GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater&lt;/strong&gt; section.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; Pre-generated SSH host keys were not regenerated when installing appliances from GitHub Enterprise 2.x images.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;When rejected from a pre-receive hook, API merge requests incorrectly returned &lt;code&gt;Internal Server Error&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Webhooks failed to deliver when the external server could only be resolved by the configured proxy server.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-system-info&lt;/code&gt; command line utility was not available to run because the utility was missing from the &lt;code&gt;$PATH&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;In a clustering environment, storage assets that were not replicated or marked for deletion were not properly maintained.&lt;/li&gt;
&lt;li&gt;Users were unable to add or remove deploy keys when LDAP sync is enabled.&lt;/li&gt;
&lt;li&gt;In a clustering environment, the &lt;code&gt;ghe-cluster-config-check&lt;/code&gt; command line utility terminated early from unsuccessful cURL checks.&lt;/li&gt;
&lt;li&gt;The root API endpoint incorrectly returned &lt;code&gt;Not Found&lt;/code&gt; when the trailing slash was omitted.&lt;/li&gt;
&lt;li&gt;The initial push of a repository with many Git refs could time out.&lt;/li&gt;
&lt;li&gt;Elasticsearch logs could grow very large due to incorrect HTTP and HTTPS connection management.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-ssl-ca-certificate-install&lt;/code&gt; command line utility did not accept a piped certificate as input.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise is now available in the Asia Pacific (Mumbai) AWS region.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring a protected branch archived whilst running 2.3, will not restore all the settings correctly. This does not affect new instances or protected branches archived on later releases.&lt;/li&gt;
&lt;li&gt;Editing custom messages in the Admin Center doesn&#39;t provide emoji suggestions.&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin Center.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/articles/viewing-push-logs/&quot;&gt;Repository push logs&lt;/a&gt; don&#39;t record whether a push was forced.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Uploading PNG images with &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;through the web interface&lt;/a&gt; can fail with the error &#39;Something went really wrong, and we can&#39;t process that file.&#39;&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;strong&gt;Pre-generated SSH Host Keys in GitHub Enterprise&lt;/strong&gt; vulnerability disclosure added the &lt;strong&gt;&lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; in GitHub Enterprise&lt;/strong&gt; for GitHub Enterprise 2.7.4 or greater appliances on the Amazon Web Services platform. (updated 2016-09-22)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 20 Sep 2016 10:30:45 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.6.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.6.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.5.14</title>
					<description>&lt;h2&gt;Pre-generated SSH Host Keys in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified for all 2.x versions of GitHub Enterprise. The GitHub Enterprise images contain pre-generated SSH host keys that were not regenerated upon installation for all supported platforms:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Hyper-V (VHD)&lt;/li&gt;
&lt;li&gt;OpenStack KVM (QCOW2)&lt;/li&gt;
&lt;li&gt;VMware ESXi/vSphere (OVA)&lt;/li&gt;
&lt;li&gt;Xen (VHD)&lt;/li&gt;
&lt;li&gt;Amazon Web Services (See the &lt;strong&gt;&lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; in GitHub Enterprise&lt;/strong&gt; section below)&lt;/li&gt;
&lt;li&gt;Microsoft Azure&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This means an attacker with the capability to perform a &lt;a href=&quot;https://en.wikipedia.org/wiki/Man-in-the-middle_attack&quot;&gt;man-in-the-middle attack&lt;/a&gt; on SSH traffic can intercept and modify network traffic to the GitHub Enterprise appliance.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.7.0 - 2.7.3&lt;/li&gt;
&lt;li&gt;2.6.0 - 2.6.8&lt;/li&gt;
&lt;li&gt;2.5.0 - 2.5.13&lt;/li&gt;
&lt;li&gt;2.4.0 - 2.4.16&lt;/li&gt;
&lt;li&gt;2.3.0 - 2.3.20&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This vulnerability was found and reported internally and we have no evidence that it has been exploited in the wild.&lt;/p&gt;
&lt;p&gt;We &lt;strong&gt;strongly&lt;/strong&gt; recommend &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrading&lt;/a&gt; your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, or 2.3.21. In addition, with &lt;a href=&quot;https://github.com/github/backup-utils/releases/tag/v2.7.1&quot;&gt;backup-utils-2.7.1&lt;/a&gt;, &lt;code&gt;ghe-backup&lt;/code&gt; and &lt;code&gt;ghe-restore&lt;/code&gt; will check for any leaked SSH host keys in the snapshot(s).&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have questions.&lt;/p&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;h3&gt;Verification and Mitigation on GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater&lt;/h3&gt;
&lt;p&gt;If you&#39;ve upgraded to the latest patch release, GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater,&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your primary GitHub Enterprise appliance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Check for leaked SSH host keys using the &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/articles/command-line-utilities/#ghe-ssh-check-host-keys&quot;&gt;&lt;code&gt;ghe-ssh-check-host-keys&lt;/code&gt;&lt;/a&gt; utility.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-ssh-check-host-keys
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The utility should output either:&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;One or more of your SSH host keys were found in the blacklist.
Please reset your host keys using ghe-ssh-roll-host-keys.
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;The SSH host keys were not found in the SSH host key blacklist.
No additional steps are needed/recommended at this time.
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;If one or more SSH host keys were found in the blacklist, continue to the next step. Otherwise, your GitHub Enterprise environment is not vulnerable.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Put your GitHub Enterprise environment in &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/maintenance-mode/&quot;&gt;Maintenance Mode&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Rotate all SSH host keys using the &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/articles/command-line-utilities/#ghe-ssh-roll-host-keys&quot;&gt;&lt;code&gt;ghe-ssh-roll-host-keys&lt;/code&gt;&lt;/a&gt; utility.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo ghe-ssh-roll-host-keys
$ sudo ssh-keygen -t ed25519 -N &amp;quot;&amp;quot; -f /etc/ssh/ssh_host_ed25519_key
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The utility should output:&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ SSH host keys have successfully been rolled.
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If you&#39;ve upgraded to GitHub Enterprise 2.7.4, 2.6.9, or greater, and you are using the &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/high-availability-configuration/&quot;&gt;High Availability Configuration&lt;/a&gt;, there are no additional steps to take on your replica appliance.&lt;/p&gt;
&lt;p&gt;If you&#39;ve upgraded to GitHub Enterprise 2.5.14, 2.4.17, 2.3.21, or greater, and you are using the &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/high-availability-configuration/&quot;&gt;High Availability Configuration&lt;/a&gt;,&lt;/p&gt;
&lt;ol start=&quot;6&quot;&gt;
&lt;li&gt;
&lt;p&gt;After completing steps 1-5, stop replication on the replica appliance.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-stop
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Synchronize the SSH host keys from the primary appliance.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-setup
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Resume replication on the replica appliance.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-start
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If you&#39;ve upgraded to GitHub Enterprise 2.7.4, 2.6.9, 2.5.14 or greater, and you are using &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/clustering/&quot;&gt;Clustering&lt;/a&gt;,&lt;/p&gt;
&lt;ol start=&quot;6&quot;&gt;
&lt;li&gt;
&lt;p&gt;After completing steps 1-5, apply the changes to all cluster nodes.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-cluster-config-apply
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;h3&gt;Verification and Mitigation if Immediate Upgrade is not Possible&lt;/h3&gt;
&lt;p&gt;If you&#39;re unable to upgrade immediately to the latest patch release, GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater,&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your primary GitHub Enterprise appliance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Download the list of leaked SSH host keys and verify its content using any of the provided hashes.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ curl -O https://enterprise.github.com/security/2016-09-20/ghe-ssh-leaked-host-keys-list.txt
$ sha256sum ghe-ssh-leaked-host-keys-list.txt
3bb29658784a4059a41f1a77cffba9586baab179ba07b795f80e12a9f10c5665  ghe-ssh-leaked-host-keys-list.txt
$ sha1sum ghe-ssh-leaked-host-keys-list.txt
5db799da044da9aae0bcfc523d22e7ce0fe72550  ghe-ssh-leaked-host-keys-list.txt
$ md5sum ghe-ssh-leaked-host-keys-list.txt
de75bcb0bf1d13e15620952c0af8da41  ghe-ssh-leaked-host-keys-list.txt
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Print the fingerprint of your GitHub Enterprise appliance&#39;s SSH host keys.&lt;br /&gt;
&lt;strong&gt;Note:&lt;/strong&gt; The &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; may exist on your GitHub Enterprise appliance but is only used in 2.7.4 or greater.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ssh-keygen -lf /etc/ssh/ssh_host_dsa_key.pub
1024 b2:69:82:2f:25:48:bb:fc:62:c7:9a:de:41:42:13:55 /etc/ssh/ssh_host_dsa_key.pub (DSA)
$ ssh-keygen -lf /etc/ssh/ssh_host_ecdsa_key.pub
256 c0:cb:fd:07:33:e9:62:14:6b:fb:d5:26:54:f3:c5:0d /etc/ssh/ssh_host_ecdsa_key.pub (ECDSA)
$ ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pub
256 d6:92:21:4b:04:3b:22:f5:ee:85:0a:63:bf:b3:fe:9b /etc/ssh/ssh_host_ed25519_key.pub (ED25519)
$ ssh-keygen -lf /etc/ssh/ssh_host_rsa_key.pub
2048 0f:ee:8d:02:2d:e1:76:f3:eb:f5:af:cb:38:9a:1c:33 /etc/ssh/ssh_host_rsa_key.pub (RSA)
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Check for leaked SSH host keys by comparing against the downloaded list of leaked SSH host keys.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;If one or more SSH host keys were found in the blacklist, continue to the next step. Otherwise, your GitHub Enterprise environment is not vulnerable.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Put your GitHub Enterprise environment in &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/maintenance-mode/&quot;&gt;Maintenance Mode&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Remove all SSH host keys.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo rm -f /etc/ssh/ssh_host_*
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Regenerate the SSH host keys.&lt;br /&gt;
&lt;strong&gt;Note:&lt;/strong&gt; The &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; may exist on your GitHub Enterprise appliance but is only used and regenerated for in 2.7.4 or greater.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo ssh-keygen -t ed25519 -N &amp;quot;&amp;quot; -f /etc/ssh/ssh_host_ed25519_key
$ sudo dpkg-reconfigure openssh-server
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Apply the changes to the &lt;code&gt;ssh&lt;/code&gt; and &lt;code&gt;babeld&lt;/code&gt; service.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo cp /etc/ssh/ssh_host_{rsa,dsa,ecdsa,ed25519}_key{,.pub} /data/user/common/
$ sudo chown babeld:babeld /data/user/common/ssh_host_{rsa,dsa,ecdsa,ed25519}_key{,.pub}
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If you&#39;re unable to upgrade immediately to GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater, and you are using the &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/high-availability-configuration/&quot;&gt;High Availability Configuration&lt;/a&gt;,&lt;/p&gt;
&lt;ol start=&quot;10&quot;&gt;
&lt;li&gt;After completing steps 1-9, stop replication on the replica appliance.&lt;/li&gt;
&lt;/ol&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-stop
&lt;/code&gt;&lt;/pre&gt;
&lt;ol start=&quot;11&quot;&gt;
&lt;li&gt;Synchronize the SSH host keys from the primary appliance.&lt;/li&gt;
&lt;/ol&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-setup
&lt;/code&gt;&lt;/pre&gt;
&lt;ol start=&quot;12&quot;&gt;
&lt;li&gt;Resume replication on the replica appliance.&lt;/li&gt;
&lt;/ol&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-start
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;If you&#39;re unable to upgrade immediately to GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, or greater, and you are using &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/clustering/&quot;&gt;Clustering&lt;/a&gt;,&lt;/p&gt;
&lt;ol start=&quot;10&quot;&gt;
&lt;li&gt;After completing steps 1-9, apply the changes to all cluster nodes.&lt;/li&gt;
&lt;/ol&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-cluster-config-apply
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;h3&gt;Post SSH Host Key Rotation&lt;/h3&gt;
&lt;p&gt;After rotating the SSH host keys, your GitHub Enterprise environment can exit &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/maintenance-mode/&quot;&gt;Maintenance Mode&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Your end-users will receive an error message when attempting to use the &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;Administrative Shell (SSH)&lt;/a&gt; or the SSH protocol for Git activity. The rotation does not affect users using the HTTPS protocol for Git activity.&lt;/p&gt;
&lt;p&gt;For example, the following is an output from the command-line,&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@    WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!     @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
Someone could be eavesdropping on you right now (man-in-the-middle attack)!
It is also possible that a host key has just been changed.
The fingerprint for the ECDSA key sent by the remote host is
SHA256:seFT9eIOmAZWbfcO9yU1sXiEYIqcrdi0qttbtmNm0Io.
Please contact your system administrator.
Add correct host key in /Users/monalisa/.ssh/known_hosts to get rid of this message.
Offending ECDSA key in /Users/monalisa/.ssh/known_hosts:42
ECDSA host key for [github.example.com]:122 has changed and you have requested strict checking.
Host key verification failed.
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;After updating the &lt;code&gt;known_hosts&lt;/code&gt;, end-users will be prompted to accept a new fingerprint.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ssh -p 122 admin@github.example.com
The authenticity of host &#39;[github.example.com]:122 ([169.254.1.1]:122)&#39; can&#39;t be established.
ECDSA key fingerprint is SHA256:seFT9eIOmAZWbfcO9yU1sXiEYIqcrdi0qttbtmNm0Io.
Are you sure you want to continue connecting (yes/no)?
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;We strongly recommend publishing your GitHub Enterprise appliance&#39;s SSH host key fingerprints in a location that is accessible to all your end-users. For example, for GitHub.com, we publish the SSH fingerprints at &lt;a href=&quot;https://docs.github.com/articles/what-are-github-s-ssh-key-fingerprints/&quot;&gt;https://docs.github.com/articles/what-are-github-s-ssh-key-fingerprints/&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you&#39;d like to to give end-users notice before rotating the SSH host keys, follow the instructions in the &lt;strong&gt;Verification and Mitigation if Immediate Upgrade is not Possible&lt;/strong&gt; skipping step 7 and replacing step 8 with,&lt;/p&gt;
&lt;ol start=&quot;8&quot;&gt;
&lt;li&gt;
&lt;p&gt;Regenerate the SSH host keys.&lt;br /&gt;
&lt;strong&gt;Note:&lt;/strong&gt; The &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; may exist on your GitHub Enterprise appliance but is only used and regenerated for in 2.7.4 or greater.&lt;/p&gt;
&lt;p&gt;i. Pre-generate new SSH host keys to a temporary directory.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ssh-keygen -t dsa -N &amp;quot;&amp;quot; -f /var/tmp/ssh_host_dsa_key
$ ssh-keygen -t rsa -N &amp;quot;&amp;quot; -f /var/tmp/ssh_host_rsa_key
$ ssh-keygen -t ecdsa -N &amp;quot;&amp;quot; -f /var/tmp/ssh_host_ecdsa_key
$ ssh-keygen -t ed25519 -N &amp;quot;&amp;quot; -f /var/tmp/ssh_host_ed25519_key
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;ii. Print the fingerprint of your GitHub Enterprise appliance&#39;s SSH host keys for tentative rotation.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ssh-keygen -lf /var/tmp/ssh_host_dsa_key.pub
 1024 b2:69:82:2f:25:48:bb:fc:62:c7:9a:de:41:42:13:55 /var/tmp/ssh_host_dsa_key.pub (DSA)
$ ssh-keygen -lf /var/tmp/ssh_host_ecdsa_key.pub
 256 c0:cb:fd:07:33:e9:62:14:6b:fb:d5:26:54:f3:c5:0d /var/tmp/ssh_host_ecdsa_key.pub (ECDSA)
$ ssh-keygen -lf /var/tmp/ssh_host_ed25519_key.pub
 256 d6:92:21:4b:04:3b:22:f5:ee:85:0a:63:bf:b3:fe:9b /var/tmp/ssh_host_ed25519_key.pub (ED25519)
$ ssh-keygen -lf /var/tmp/ssh_host_rsa_key.pub
248 0f:ee:8d:02:2d:e1:76:f3:eb:f5:af:cb:38:9a:1c:33 /var/tmp/ssh_host_rsa_key.pub (RSA)
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;iii. Once you are ready to migrate to the new, rotated SSH host keys, move the host keys from the temporary directory and apply the changes to the &lt;code&gt;ssh&lt;/code&gt; service.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo mv /var/tmp/ssh_host_{rsa,dsa,ecdsa,ed25519}_key{,.pub} /etc/ssh
$ sudo service ssh restart
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;iv. Continue with steps 9 in the &lt;strong&gt;Verification and Mitigation if Immediate Upgrade is not Possible&lt;/strong&gt; section.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;&lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; in GitHub Enterprise&lt;/h3&gt;
&lt;p&gt;The 2.x versions of GitHub Enterprise on all supported platforms:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Hyper-V (VHD)&lt;/li&gt;
&lt;li&gt;OpenStack KVM (QCOW2)&lt;/li&gt;
&lt;li&gt;VMware ESXi/vSphere (OVA)&lt;/li&gt;
&lt;li&gt;Xen (VHD)&lt;/li&gt;
&lt;li&gt;Amazon Web Services&lt;/li&gt;
&lt;li&gt;Microsoft Azure&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;contain a pre-generated &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt;. However, only GitHub Enterprise 2.7.4 or greater use the &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt;. This can be verified by checking your GitHub Enterprise appliance&#39;s &lt;code&gt;/etc/ssh/sshd_config&lt;/code&gt;, which added &lt;code&gt;HostKey /etc/ssh/ssh_host_ed25519_key&lt;/code&gt; in 2.7.4 or greater.&lt;/p&gt;
&lt;p&gt;The &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; may exist on your GitHub Enterprise appliance but is only used in 2.7.4 or greater.&lt;/p&gt;
&lt;p&gt;If you&#39;ve upgraded your appliance to 2.7.4 or greater on any of the supported platforms including Amazon Web Services, please follow the instructions in the &lt;strong&gt;Verification and Mitigation on GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater&lt;/strong&gt; section.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; Pre-generated SSH host keys were not regenerated when installing appliances from GitHub Enterprise 2.x images.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In a clustering environment, storage assets that were not replicated or marked for deletion were not properly maintained.&lt;/li&gt;
&lt;li&gt;Users were unable to add or remove deploy keys when LDAP sync is enabled.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise is now available in the Asia Pacific (Mumbai) AWS region.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-11-15)&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;strong&gt;Pre-generated SSH Host Keys in GitHub Enterprise&lt;/strong&gt; vulnerability disclosure added the &lt;strong&gt;&lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; in GitHub Enterprise&lt;/strong&gt; for GitHub Enterprise 2.7.4 or greater appliances on the Amazon Web Services platform. (updated 2016-09-22)&lt;/li&gt;
&lt;li&gt;We didn&#39;t include the fix for the issue that migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-11-15)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 20 Sep 2016 10:30:44 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.5.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.5.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.4.17</title>
					<description>&lt;h2&gt;Pre-generated SSH Host Keys in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified for all 2.x versions of GitHub Enterprise. The GitHub Enterprise images contain pre-generated SSH host keys that were not regenerated upon installation for all supported platforms:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Hyper-V (VHD)&lt;/li&gt;
&lt;li&gt;OpenStack KVM (QCOW2)&lt;/li&gt;
&lt;li&gt;VMware ESXi/vSphere (OVA)&lt;/li&gt;
&lt;li&gt;Xen (VHD)&lt;/li&gt;
&lt;li&gt;Amazon Web Services (See the &lt;strong&gt;&lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; in GitHub Enterprise&lt;/strong&gt; section below)&lt;/li&gt;
&lt;li&gt;Microsoft Azure&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This means an attacker with the capability to perform a &lt;a href=&quot;https://en.wikipedia.org/wiki/Man-in-the-middle_attack&quot;&gt;man-in-the-middle attack&lt;/a&gt; on SSH traffic can intercept and modify network traffic to the GitHub Enterprise appliance.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.7.0 - 2.7.3&lt;/li&gt;
&lt;li&gt;2.6.0 - 2.6.8&lt;/li&gt;
&lt;li&gt;2.5.0 - 2.5.13&lt;/li&gt;
&lt;li&gt;2.4.0 - 2.4.16&lt;/li&gt;
&lt;li&gt;2.3.0 - 2.3.20&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This vulnerability was found and reported internally and we have no evidence that it has been exploited in the wild.&lt;/p&gt;
&lt;p&gt;We &lt;strong&gt;strongly&lt;/strong&gt; recommend &lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrading&lt;/a&gt; your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, or 2.3.21. In addition, with &lt;a href=&quot;https://github.com/github/backup-utils/releases/tag/v2.7.1&quot;&gt;backup-utils-2.7.1&lt;/a&gt;, &lt;code&gt;ghe-backup&lt;/code&gt; and &lt;code&gt;ghe-restore&lt;/code&gt; will check for any leaked SSH host keys in the snapshot(s).&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have questions.&lt;/p&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;h3&gt;Verification and Mitigation on GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater&lt;/h3&gt;
&lt;p&gt;If you&#39;ve upgraded to the latest patch release, GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater,&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your primary GitHub Enterprise appliance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Check for leaked SSH host keys using the &lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/articles/command-line-utilities/#ghe-ssh-check-host-keys&quot;&gt;&lt;code&gt;ghe-ssh-check-host-keys&lt;/code&gt;&lt;/a&gt; utility.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-ssh-check-host-keys
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The utility should output either:&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;One or more of your SSH host keys were found in the blacklist.
Please reset your host keys using ghe-ssh-roll-host-keys.
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;The SSH host keys were not found in the SSH host key blacklist.
No additional steps are needed/recommended at this time.
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;If one or more SSH host keys were found in the blacklist, continue to the next step. Otherwise, your GitHub Enterprise environment is not vulnerable.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Put your GitHub Enterprise environment in &lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/installation/maintenance-mode/&quot;&gt;Maintenance Mode&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Rotate all SSH host keys using the &lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/articles/command-line-utilities/#ghe-ssh-roll-host-keys&quot;&gt;&lt;code&gt;ghe-ssh-roll-host-keys&lt;/code&gt;&lt;/a&gt; utility.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo ghe-ssh-roll-host-keys
$ sudo ssh-keygen -t ed25519 -N &amp;quot;&amp;quot; -f /etc/ssh/ssh_host_ed25519_key
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The utility should output:&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ SSH host keys have successfully been rolled.
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If you&#39;ve upgraded to GitHub Enterprise 2.7.4, 2.6.9, or greater, and you are using the &lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/installation/high-availability-configuration/&quot;&gt;High Availability Configuration&lt;/a&gt;, there are no additional steps to take on your replica appliance.&lt;/p&gt;
&lt;p&gt;If you&#39;ve upgraded to GitHub Enterprise 2.5.14, 2.4.17, 2.3.21, or greater, and you are using the &lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/installation/high-availability-configuration/&quot;&gt;High Availability Configuration&lt;/a&gt;,&lt;/p&gt;
&lt;ol start=&quot;6&quot;&gt;
&lt;li&gt;
&lt;p&gt;After completing steps 1-5, stop replication on the replica appliance.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-stop
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Synchronize the SSH host keys from the primary appliance.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-setup
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Resume replication on the replica appliance.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-start
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;h3&gt;Verification and Mitigation if Immediate Upgrade is not Possible&lt;/h3&gt;
&lt;p&gt;If you&#39;re unable to upgrade immediately to the latest patch release, GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater,&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your primary GitHub Enterprise appliance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Download the list of leaked SSH host keys and verify its content using any of the provided hashes.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ curl -O https://enterprise.github.com/security/2016-09-20/ghe-ssh-leaked-host-keys-list.txt
$ sha256sum ghe-ssh-leaked-host-keys-list.txt
3bb29658784a4059a41f1a77cffba9586baab179ba07b795f80e12a9f10c5665  ghe-ssh-leaked-host-keys-list.txt
$ sha1sum ghe-ssh-leaked-host-keys-list.txt
5db799da044da9aae0bcfc523d22e7ce0fe72550  ghe-ssh-leaked-host-keys-list.txt
$ md5sum ghe-ssh-leaked-host-keys-list.txt
de75bcb0bf1d13e15620952c0af8da41  ghe-ssh-leaked-host-keys-list.txt
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Print the fingerprint of your GitHub Enterprise appliance&#39;s SSH host keys.&lt;br /&gt;
&lt;strong&gt;Note:&lt;/strong&gt; The &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; may exist on your GitHub Enterprise appliance but is only used in 2.7.4 or greater.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ssh-keygen -lf /etc/ssh/ssh_host_dsa_key.pub
1024 b2:69:82:2f:25:48:bb:fc:62:c7:9a:de:41:42:13:55 /etc/ssh/ssh_host_dsa_key.pub (DSA)
$ ssh-keygen -lf /etc/ssh/ssh_host_ecdsa_key.pub
256 c0:cb:fd:07:33:e9:62:14:6b:fb:d5:26:54:f3:c5:0d /etc/ssh/ssh_host_ecdsa_key.pub (ECDSA)
$ ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pub
256 d6:92:21:4b:04:3b:22:f5:ee:85:0a:63:bf:b3:fe:9b /etc/ssh/ssh_host_ed25519_key.pub (ED25519)
$ ssh-keygen -lf /etc/ssh/ssh_host_rsa_key.pub
2048 0f:ee:8d:02:2d:e1:76:f3:eb:f5:af:cb:38:9a:1c:33 /etc/ssh/ssh_host_rsa_key.pub (RSA)
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Check for leaked SSH host keys by comparing against the downloaded list of leaked SSH host keys.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;If one or more SSH host keys were found in the blacklist, continue to the next step. Otherwise, your GitHub Enterprise environment is not vulnerable.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Put your GitHub Enterprise environment in &lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/installation/maintenance-mode/&quot;&gt;Maintenance Mode&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Remove all SSH host keys.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo rm -f /etc/ssh/ssh_host_*
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Regenerate the SSH host keys.&lt;br /&gt;
&lt;strong&gt;Note:&lt;/strong&gt; The &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; may exist on your GitHub Enterprise appliance but is only used and regenerated for in 2.7.4 or greater.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo ssh-keygen -t ed25519 -N &amp;quot;&amp;quot; -f /etc/ssh/ssh_host_ed25519_key
$ sudo dpkg-reconfigure openssh-server
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Apply the changes to the &lt;code&gt;ssh&lt;/code&gt; and &lt;code&gt;babeld&lt;/code&gt; service.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo cp /etc/ssh/ssh_host_{rsa,dsa,ecdsa,ed25519}_key{,.pub} /data/user/common/
$ sudo chown babeld:babeld /data/user/common/ssh_host_{rsa,dsa,ecdsa,ed25519}_key{,.pub}
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If you&#39;re unable to upgrade immediately to GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater, and you are using the &lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/installation/high-availability-configuration/&quot;&gt;High Availability Configuration&lt;/a&gt;,&lt;/p&gt;
&lt;ol start=&quot;10&quot;&gt;
&lt;li&gt;After completing steps 1-9, stop replication on the replica appliance.&lt;/li&gt;
&lt;/ol&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-stop
&lt;/code&gt;&lt;/pre&gt;
&lt;ol start=&quot;11&quot;&gt;
&lt;li&gt;Synchronize the SSH host keys from the primary appliance.&lt;/li&gt;
&lt;/ol&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-setup
&lt;/code&gt;&lt;/pre&gt;
&lt;ol start=&quot;12&quot;&gt;
&lt;li&gt;Resume replication on the replica appliance.&lt;/li&gt;
&lt;/ol&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-start
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;h3&gt;Post SSH Host Key Rotation&lt;/h3&gt;
&lt;p&gt;After rotating the SSH host keys, your GitHub Enterprise environment can exit &lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/installation/maintenance-mode/&quot;&gt;Maintenance Mode&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Your end-users will receive an error message when attempting to use the &lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;Administrative Shell (SSH)&lt;/a&gt; or the SSH protocol for Git activity. The rotation does not affect users using the HTTPS protocol for Git activity.&lt;/p&gt;
&lt;p&gt;For example, the following is an output from the command-line,&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@    WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!     @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
Someone could be eavesdropping on you right now (man-in-the-middle attack)!
It is also possible that a host key has just been changed.
The fingerprint for the ECDSA key sent by the remote host is
SHA256:seFT9eIOmAZWbfcO9yU1sXiEYIqcrdi0qttbtmNm0Io.
Please contact your system administrator.
Add correct host key in /Users/monalisa/.ssh/known_hosts to get rid of this message.
Offending ECDSA key in /Users/monalisa/.ssh/known_hosts:42
ECDSA host key for [github.example.com]:122 has changed and you have requested strict checking.
Host key verification failed.
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;After updating the &lt;code&gt;known_hosts&lt;/code&gt;, end-users will be prompted to accept a new fingerprint.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ssh -p 122 admin@github.example.com
The authenticity of host &#39;[github.example.com]:122 ([169.254.1.1]:122)&#39; can&#39;t be established.
ECDSA key fingerprint is SHA256:seFT9eIOmAZWbfcO9yU1sXiEYIqcrdi0qttbtmNm0Io.
Are you sure you want to continue connecting (yes/no)?
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;We strongly recommend publishing your GitHub Enterprise appliance&#39;s SSH host key fingerprints in a location that is accessible to all your end-users. For example, for GitHub.com, we publish the SSH fingerprints at &lt;a href=&quot;https://docs.github.com/articles/what-are-github-s-ssh-key-fingerprints/&quot;&gt;https://docs.github.com/articles/what-are-github-s-ssh-key-fingerprints/&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you&#39;d like to to give end-users notice before rotating the SSH host keys, follow the instructions in the &lt;strong&gt;Verification and Mitigation if Immediate Upgrade is not Possible&lt;/strong&gt; skipping step 7 and replacing step 8 with,&lt;/p&gt;
&lt;ol start=&quot;8&quot;&gt;
&lt;li&gt;
&lt;p&gt;Regenerate the SSH host keys.&lt;br /&gt;
&lt;strong&gt;Note:&lt;/strong&gt; The &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; may exist on your GitHub Enterprise appliance but is only used and regenerated for in 2.7.4 or greater.&lt;/p&gt;
&lt;p&gt;i. Pre-generate new SSH host keys to a temporary directory.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ssh-keygen -t dsa -N &amp;quot;&amp;quot; -f /var/tmp/ssh_host_dsa_key
$ ssh-keygen -t rsa -N &amp;quot;&amp;quot; -f /var/tmp/ssh_host_rsa_key
$ ssh-keygen -t ecdsa -N &amp;quot;&amp;quot; -f /var/tmp/ssh_host_ecdsa_key
$ ssh-keygen -t ed25519 -N &amp;quot;&amp;quot; -f /var/tmp/ssh_host_ed25519_key
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;ii. Print the fingerprint of your GitHub Enterprise appliance&#39;s SSH host keys for tentative rotation.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ssh-keygen -lf /var/tmp/ssh_host_dsa_key.pub 1024 b2:69:82:2f:25:48:bb:fc:62:c7:9a:de:41:42:13:55 /var/tmp/ssh_host_dsa_key.pub (DSA)
$ ssh-keygen -lf /var/tmp/ssh_host_ecdsa_key.pub
 256 c0:cb:fd:07:33:e9:62:14:6b:fb:d5:26:54:f3:c5:0d /var/tmp/ssh_host_ecdsa_key.pub (ECDSA)
$ ssh-keygen -lf /var/tmp/ssh_host_ed25519_key.pub
 256 d6:92:21:4b:04:3b:22:f5:ee:85:0a:63:bf:b3:fe:9b /var/tmp/ssh_host_ed25519_key.pub (ED25519)
$ ssh-keygen -lf /var/tmp/ssh_host_rsa_key.pub
248 0f:ee:8d:02:2d:e1:76:f3:eb:f5:af:cb:38:9a:1c:33 /var/tmp/ssh_host_rsa_key.pub (RSA)
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;iii. Once you are ready to migrate to the new, rotated SSH host keys, move the host keys from the temporary directory and apply the changes to the &lt;code&gt;ssh&lt;/code&gt; service.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo mv /var/tmp/ssh_host_{rsa,dsa,ecdsa,ed25519}_key{,.pub} /etc/ssh
$ sudo service ssh restart
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;iv. Continue with steps 9 in the &lt;strong&gt;Verification and Mitigation if Immediate Upgrade is not Possible&lt;/strong&gt; section.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;&lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; in GitHub Enterprise&lt;/h3&gt;
&lt;p&gt;The 2.x versions of GitHub Enterprise on all supported platforms:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Hyper-V (VHD)&lt;/li&gt;
&lt;li&gt;OpenStack KVM (QCOW2)&lt;/li&gt;
&lt;li&gt;VMware ESXi/vSphere (OVA)&lt;/li&gt;
&lt;li&gt;Xen (VHD)&lt;/li&gt;
&lt;li&gt;Amazon Web Services&lt;/li&gt;
&lt;li&gt;Microsoft Azure&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;contain a pre-generated &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt;. However, only GitHub Enterprise 2.7.4 or greater use the &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt;. This can be verified by checking your GitHub Enterprise appliance&#39;s &lt;code&gt;/etc/ssh/sshd_config&lt;/code&gt;, which added &lt;code&gt;HostKey /etc/ssh/ssh_host_ed25519_key&lt;/code&gt; in 2.7.4 or greater.&lt;/p&gt;
&lt;p&gt;The &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; may exist on your GitHub Enterprise appliance but is only used in 2.7.4 or greater.&lt;/p&gt;
&lt;p&gt;If you&#39;ve upgraded your appliance to 2.7.4 or greater on any of the supported platforms including Amazon Web Services, please follow the instructions in the &lt;strong&gt;Verification and Mitigation on GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater&lt;/strong&gt; section.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; Pre-generated SSH host keys were not regenerated when installing appliances from GitHub Enterprise 2.x images.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Users were unable to add or remove deploy keys when LDAP sync is enabled.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise is now available in the Asia Pacific (Mumbai) AWS region.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;strong&gt;Pre-generated SSH Host Keys in GitHub Enterprise&lt;/strong&gt; vulnerability disclosure added the &lt;strong&gt;&lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; in GitHub Enterprise&lt;/strong&gt; for GitHub Enterprise 2.7.4 or greater appliances on the Amazon Web Services platform. (updated 2016-09-22)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 20 Sep 2016 10:30:43 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.4.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.4.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.3.21</title>
					<description>&lt;h2&gt;Pre-generated SSH Host Keys in GitHub Enterprise&lt;/h2&gt;
&lt;p&gt;A &lt;strong&gt;CRITICAL&lt;/strong&gt; issue was identified for all 2.x versions of GitHub Enterprise. The GitHub Enterprise images contain pre-generated SSH host keys that were not regenerated upon installation for all supported platforms:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Hyper-V (VHD)&lt;/li&gt;
&lt;li&gt;OpenStack KVM (QCOW2)&lt;/li&gt;
&lt;li&gt;VMware ESXi/vSphere (OVA)&lt;/li&gt;
&lt;li&gt;Xen (VHD)&lt;/li&gt;
&lt;li&gt;Amazon Web Services (See the &lt;strong&gt;&lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; in GitHub Enterprise&lt;/strong&gt; section below)&lt;/li&gt;
&lt;li&gt;Microsoft Azure&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This means an attacker with the capability to perform a &lt;a href=&quot;https://en.wikipedia.org/wiki/Man-in-the-middle_attack&quot;&gt;man-in-the-middle attack&lt;/a&gt; on SSH traffic can intercept and modify network traffic to the GitHub Enterprise appliance.&lt;/p&gt;
&lt;p&gt;The affected supported versions are:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;2.7.0 - 2.7.3&lt;/li&gt;
&lt;li&gt;2.6.0 - 2.6.8&lt;/li&gt;
&lt;li&gt;2.5.0 - 2.5.13&lt;/li&gt;
&lt;li&gt;2.4.0 - 2.4.16&lt;/li&gt;
&lt;li&gt;2.3.0 - 2.3.20&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;This vulnerability was found and reported internally and we have no evidence that it has been exploited in the wild.&lt;/p&gt;
&lt;p&gt;We &lt;strong&gt;strongly&lt;/strong&gt; recommend &lt;a href=&quot;https://docs.github.com/enterprise/2.3/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrading&lt;/a&gt; your GitHub Enterprise appliance to the latest patch release in your series, GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, or 2.3.21. In addition, with &lt;a href=&quot;https://github.com/github/backup-utils/releases/tag/v2.7.1&quot;&gt;backup-utils-2.7.1&lt;/a&gt;, &lt;code&gt;ghe-backup&lt;/code&gt; and &lt;code&gt;ghe-restore&lt;/code&gt; will check for any leaked SSH host keys in the snapshot(s).&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have questions.&lt;/p&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;h3&gt;Verification and Mitigation on GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater&lt;/h3&gt;
&lt;p&gt;If you&#39;ve upgraded to the latest patch release, GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater,&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.3/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your primary GitHub Enterprise appliance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Check for leaked SSH host keys using the &lt;a href=&quot;https://docs.github.com/enterprise/2.3/admin/articles/command-line-utilities/#ghe-ssh-check-host-keys&quot;&gt;&lt;code&gt;ghe-ssh-check-host-keys&lt;/code&gt;&lt;/a&gt; utility.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-ssh-check-host-keys
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The utility should output either:&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;One or more of your SSH host keys were found in the blacklist.
Please reset your host keys using ghe-ssh-roll-host-keys.
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;The SSH host keys were not found in the SSH host key blacklist.
No additional steps are needed/recommended at this time.
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;If one or more SSH host keys were found in the blacklist, continue to the next step. Otherwise, your GitHub Enterprise environment is not vulnerable.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Put your GitHub Enterprise environment in &lt;a href=&quot;https://docs.github.com/enterprise/2.3/admin/guides/installation/maintenance-mode/&quot;&gt;Maintenance Mode&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Rotate all SSH host keys using the &lt;a href=&quot;https://docs.github.com/enterprise/2.3/admin/articles/command-line-utilities/#ghe-ssh-roll-host-keys&quot;&gt;&lt;code&gt;ghe-ssh-roll-host-keys&lt;/code&gt;&lt;/a&gt; utility.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo ghe-ssh-roll-host-keys
$ sudo ssh-keygen -t ed25519 -N &amp;quot;&amp;quot; -f /etc/ssh/ssh_host_ed25519_key
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The utility should output:&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ SSH host keys have successfully been rolled.
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If you&#39;ve upgraded to GitHub Enterprise 2.7.4, 2.6.9, or greater, and you are using the &lt;a href=&quot;https://docs.github.com/enterprise/2.3/admin/guides/installation/high-availability-configuration/&quot;&gt;High Availability Configuration&lt;/a&gt;, there are no additional steps to take on your replica appliance.&lt;/p&gt;
&lt;p&gt;If you&#39;ve upgraded to GitHub Enterprise 2.5.14, 2.4.17, 2.3.21, or greater, and you are using the &lt;a href=&quot;https://docs.github.com/enterprise/2.3/admin/guides/installation/high-availability-configuration/&quot;&gt;High Availability Configuration&lt;/a&gt;,&lt;/p&gt;
&lt;ol start=&quot;6&quot;&gt;
&lt;li&gt;
&lt;p&gt;After completing steps 1-5, stop replication on the replica appliance.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-stop
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Synchronize the SSH host keys from the primary appliance.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-setup
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Resume replication on the replica appliance.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-start
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;h3&gt;Verification and Mitigation if Immediate Upgrade is not Possible&lt;/h3&gt;
&lt;p&gt;If you&#39;re unable to upgrade immediately to the latest patch release, GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater,&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.3/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your primary GitHub Enterprise appliance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Download the list of leaked SSH host keys and verify its content using any of the provided hashes.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ curl -O https://enterprise.github.com/security/2016-09-20/ghe-ssh-leaked-host-keys-list.txt
$ sha256sum ghe-ssh-leaked-host-keys-list.txt
3bb29658784a4059a41f1a77cffba9586baab179ba07b795f80e12a9f10c5665  ghe-ssh-leaked-host-keys-list.txt
$ sha1sum ghe-ssh-leaked-host-keys-list.txt
5db799da044da9aae0bcfc523d22e7ce0fe72550  ghe-ssh-leaked-host-keys-list.txt
$ md5sum ghe-ssh-leaked-host-keys-list.txt
de75bcb0bf1d13e15620952c0af8da41  ghe-ssh-leaked-host-keys-list.txt
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Print the fingerprint of your GitHub Enterprise appliance&#39;s SSH host keys.&lt;br /&gt;
&lt;strong&gt;Note:&lt;/strong&gt; The &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; may exist on your GitHub Enterprise appliance but is only used in 2.7.4 or greater.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ssh-keygen -lf /etc/ssh/ssh_host_dsa_key.pub
1024 b2:69:82:2f:25:48:bb:fc:62:c7:9a:de:41:42:13:55 /etc/ssh/ssh_host_dsa_key.pub (DSA)
$ ssh-keygen -lf /etc/ssh/ssh_host_ecdsa_key.pub
256 c0:cb:fd:07:33:e9:62:14:6b:fb:d5:26:54:f3:c5:0d /etc/ssh/ssh_host_ecdsa_key.pub (ECDSA)
$ ssh-keygen -lf /etc/ssh/ssh_host_ed25519_key.pub
256 d6:92:21:4b:04:3b:22:f5:ee:85:0a:63:bf:b3:fe:9b /etc/ssh/ssh_host_ed25519_key.pub (ED25519)
$ ssh-keygen -lf /etc/ssh/ssh_host_rsa_key.pub
2048 0f:ee:8d:02:2d:e1:76:f3:eb:f5:af:cb:38:9a:1c:33 /etc/ssh/ssh_host_rsa_key.pub (RSA)
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Check for leaked SSH host keys by comparing against the downloaded list of leaked SSH host keys.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;If one or more SSH host keys were found in the blacklist, continue to the next step. Otherwise, your GitHub Enterprise environment is not vulnerable.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Put your GitHub Enterprise environment in &lt;a href=&quot;https://docs.github.com/enterprise/2.3/admin/guides/installation/maintenance-mode/&quot;&gt;Maintenance Mode&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Remove all SSH host keys.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo rm -f /etc/ssh/ssh_host_*
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Regenerate the SSH host keys.&lt;br /&gt;
&lt;strong&gt;Note:&lt;/strong&gt; The &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; may exist on your GitHub Enterprise appliance but is only used and regenerated for in 2.7.4 or greater.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo ssh-keygen -t ed25519 -N &amp;quot;&amp;quot; -f /etc/ssh/ssh_host_ed25519_key
$ sudo dpkg-reconfigure openssh-server
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Apply the changes to the &lt;code&gt;ssh&lt;/code&gt; and &lt;code&gt;babeld&lt;/code&gt; service.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo cp /etc/ssh/ssh_host_{rsa,dsa,ecdsa,ed25519}_key{,.pub} /data/user/common/
$ sudo chown babeld:babeld /data/user/common/ssh_host_{rsa,dsa,ecdsa,ed25519}_key{,.pub}
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;If you&#39;re unable to upgrade immediately to GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater, and you are using the &lt;a href=&quot;https://docs.github.com/enterprise/2.3/admin/guides/installation/high-availability-configuration/&quot;&gt;High Availability Configuration&lt;/a&gt;,&lt;/p&gt;
&lt;ol start=&quot;10&quot;&gt;
&lt;li&gt;After completing steps 1-9, stop replication on the replica appliance.&lt;/li&gt;
&lt;/ol&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-stop
&lt;/code&gt;&lt;/pre&gt;
&lt;ol start=&quot;11&quot;&gt;
&lt;li&gt;Synchronize the SSH host keys from the primary appliance.&lt;/li&gt;
&lt;/ol&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-setup
&lt;/code&gt;&lt;/pre&gt;
&lt;ol start=&quot;12&quot;&gt;
&lt;li&gt;Resume replication on the replica appliance.&lt;/li&gt;
&lt;/ol&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ghe-repl-start
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;--&lt;/p&gt;
&lt;h3&gt;Post SSH Host Key Rotation&lt;/h3&gt;
&lt;p&gt;After rotating the SSH host keys, your GitHub Enterprise environment can exit &lt;a href=&quot;https://docs.github.com/enterprise/2.3/admin/guides/installation/maintenance-mode/&quot;&gt;Maintenance Mode&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Your end-users will receive an error message when attempting to use the &lt;a href=&quot;https://docs.github.com/enterprise/2.3/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;Administrative Shell (SSH)&lt;/a&gt; or the SSH protocol for Git activity. The rotation does not affect users using the HTTPS protocol for Git activity.&lt;/p&gt;
&lt;p&gt;For example, the following is an output from the command-line,&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
@    WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED!     @
@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
Someone could be eavesdropping on you right now (man-in-the-middle attack)!
It is also possible that a host key has just been changed.
The fingerprint for the ECDSA key sent by the remote host is
SHA256:seFT9eIOmAZWbfcO9yU1sXiEYIqcrdi0qttbtmNm0Io.
Please contact your system administrator.
Add correct host key in /Users/monalisa/.ssh/known_hosts to get rid of this message.
Offending ECDSA key in /Users/monalisa/.ssh/known_hosts:42
ECDSA host key for [github.example.com]:122 has changed and you have requested strict checking.
Host key verification failed.
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;After updating the &lt;code&gt;known_hosts&lt;/code&gt;, end-users will be prompted to accept a new fingerprint.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ssh -p 122 admin@github.example.com
The authenticity of host &#39;[github.example.com]:122 ([169.254.1.1]:122)&#39; can&#39;t be established.
ECDSA key fingerprint is SHA256:seFT9eIOmAZWbfcO9yU1sXiEYIqcrdi0qttbtmNm0Io.
Are you sure you want to continue connecting (yes/no)?
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;We strongly recommend publishing your GitHub Enterprise appliance&#39;s SSH host key fingerprints in a location that is accessible to all your end-users. For example, for GitHub.com, we publish the SSH fingerprints at &lt;a href=&quot;https://docs.github.com/articles/what-are-github-s-ssh-key-fingerprints/&quot;&gt;https://docs.github.com/articles/what-are-github-s-ssh-key-fingerprints/&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you&#39;d like to to give end-users notice before rotating the SSH host keys, follow the instructions in the &lt;strong&gt;Verification and Mitigation if Immediate Upgrade is not Possible&lt;/strong&gt; skipping step 7 and replacing step 8 with,&lt;/p&gt;
&lt;ol start=&quot;8&quot;&gt;
&lt;li&gt;
&lt;p&gt;Regenerate the SSH host keys.&lt;br /&gt;
&lt;strong&gt;Note:&lt;/strong&gt; The &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; may exist on your GitHub Enterprise appliance but is only used and regenerated for in 2.7.4 or greater.&lt;/p&gt;
&lt;p&gt;i. Pre-generate new SSH host keys to a temporary directory.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ssh-keygen -t dsa -N &amp;quot;&amp;quot; -f /var/tmp/ssh_host_dsa_key
$ ssh-keygen -t rsa -N &amp;quot;&amp;quot; -f /var/tmp/ssh_host_rsa_key
$ ssh-keygen -t ecdsa -N &amp;quot;&amp;quot; -f /var/tmp/ssh_host_ecdsa_key
$ ssh-keygen -t ed25519 -N &amp;quot;&amp;quot; -f /var/tmp/ssh_host_ed25519_key
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;ii. Print the fingerprint of your GitHub Enterprise appliance&#39;s SSH host keys for tentative rotation.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ ssh-keygen -lf /var/tmp/ssh_host_dsa_key.pub
 1024 b2:69:82:2f:25:48:bb:fc:62:c7:9a:de:41:42:13:55 /var/tmp/ssh_host_dsa_key.pub (DSA)
$ ssh-keygen -lf /var/tmp/ssh_host_ecdsa_key.pub
 256 c0:cb:fd:07:33:e9:62:14:6b:fb:d5:26:54:f3:c5:0d /var/tmp/ssh_host_ecdsa_key.pub (ECDSA)
$ ssh-keygen -lf /var/tmp/ssh_host_ed25519_key.pub
 256 d6:92:21:4b:04:3b:22:f5:ee:85:0a:63:bf:b3:fe:9b /var/tmp/ssh_host_ed25519_key.pub (ED25519)
$ ssh-keygen -lf /var/tmp/ssh_host_rsa_key.pub
248 0f:ee:8d:02:2d:e1:76:f3:eb:f5:af:cb:38:9a:1c:33 /var/tmp/ssh_host_rsa_key.pub (RSA)
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;iii. Once you are ready to migrate to the new, rotated SSH host keys, move the host keys from the temporary directory and apply the changes to the &lt;code&gt;ssh&lt;/code&gt; service.&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo mv /var/tmp/ssh_host_{rsa,dsa,ecdsa,ed25519}_key{,.pub} /etc/ssh
$ sudo service ssh restart
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;iv. Continue with steps 9 in the &lt;strong&gt;Verification and Mitigation if Immediate Upgrade is not Possible&lt;/strong&gt; section.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;h3&gt;&lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; in GitHub Enterprise&lt;/h3&gt;
&lt;p&gt;The 2.x versions of GitHub Enterprise on all supported platforms:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Hyper-V (VHD)&lt;/li&gt;
&lt;li&gt;OpenStack KVM (QCOW2)&lt;/li&gt;
&lt;li&gt;VMware ESXi/vSphere (OVA)&lt;/li&gt;
&lt;li&gt;Xen (VHD)&lt;/li&gt;
&lt;li&gt;Amazon Web Services&lt;/li&gt;
&lt;li&gt;Microsoft Azure&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;contain a pre-generated &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt;. However, only GitHub Enterprise 2.7.4 or greater use the &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt;. This can be verified by checking your GitHub Enterprise appliance&#39;s &lt;code&gt;/etc/ssh/sshd_config&lt;/code&gt;, which added &lt;code&gt;HostKey /etc/ssh/ssh_host_ed25519_key&lt;/code&gt; in 2.7.4 or greater.&lt;/p&gt;
&lt;p&gt;The &lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; may exist on your GitHub Enterprise appliance but is only used in 2.7.4 or greater.&lt;/p&gt;
&lt;p&gt;If you&#39;ve upgraded your appliance to 2.7.4 or greater on any of the supported platforms including Amazon Web Services, please follow the instructions in the &lt;strong&gt;Verification and Mitigation on GitHub Enterprise 2.7.4, 2.6.9, 2.5.14, 2.4.17, 2.3.21, or greater&lt;/strong&gt; section.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; Pre-generated SSH host keys were not regenerated when installing appliances from GitHub Enterprise 2.x images.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Users were unable to add or remove deploy keys when LDAP sync is enabled.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;GitHub Enterprise is now available in the Asia Pacific (Mumbai) AWS region.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Email can&#39;t be sent over TLS when SSL is disabled.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;strong&gt;Pre-generated SSH Host Keys in GitHub Enterprise&lt;/strong&gt; vulnerability disclosure added the &lt;strong&gt;&lt;code&gt;ssh_host_ed25519_key&lt;/code&gt; in GitHub Enterprise&lt;/strong&gt; for GitHub Enterprise 2.7.4 or greater appliances on the Amazon Web Services platform. (updated 2016-09-22)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 20 Sep 2016 10:30:42 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.3.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.3.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.7.3</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In a clustering environment, Gists were not being replicated to new nodes.&lt;/li&gt;
&lt;li&gt;In a clustering environment, Git pushes could time out while waiting for the server to replicate data.&lt;/li&gt;
&lt;li&gt;LFS files with spaces in the file path were not rendered properly.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;git-lfs pull&lt;/code&gt; could cause high MySQL CPU usage.&lt;/li&gt;
&lt;li&gt;Unsuspending users did not check for available license seats.&lt;/li&gt;
&lt;li&gt;Gist IDs could incorrectly collide when MySQL restarted.&lt;/li&gt;
&lt;li&gt;The Git proxy service, &lt;code&gt;babeld&lt;/code&gt;, did not scale the number of workers when memory was added.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks failed when using an environment with incorrect &lt;code&gt;/tmp&lt;/code&gt; permissions.&lt;/li&gt;
&lt;li&gt;Issue assignees assigned in GitHub Enterprise 2.6 or earlier weren&#39;t visible.&lt;/li&gt;
&lt;li&gt;Dynamic worker optimizations could exhaust the maximum number of allowed MySQL connections. MySQL&#39;s &lt;code&gt;max_connections&lt;/code&gt; was increased to 2000.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Additional white spacing can sometimes be seen above the Admin center header.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Editing custom messages in the Admin center doesn&#39;t provide emoji suggestions was resolved in 2.7.0. (updated 2016-09-21)&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin center was resolved in 2.7.0. (updated 2016-09-21)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 30 Aug 2016 16:00:27 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.7.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.7.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.6.8</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In a clustering environment, Git pushes could time out while waiting for the server to replicate data.&lt;/li&gt;
&lt;li&gt;In a clustering environment, Gist were not being replicated to new nodes.&lt;/li&gt;
&lt;li&gt;LFS files with spaces in the file path were not rendered properly.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;git-lfs pull&lt;/code&gt; could cause high MySQL CPU usage.&lt;/li&gt;
&lt;li&gt;Unsuspending users did not check for available license seats.&lt;/li&gt;
&lt;li&gt;Purging an archived repository could fail.&lt;/li&gt;
&lt;li&gt;Gist IDs could incorrectly collide when MySQL restarted.&lt;/li&gt;
&lt;li&gt;The Git proxy service, &lt;code&gt;babeld&lt;/code&gt;, did not scale the number of workers when memory was added.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks failed when using an environment with incorrect &lt;code&gt;/tmp&lt;/code&gt; permissions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring a protected branch archived whilst running 2.3, will not restore all the settings correctly. This does not affect new instances or protected branches archived on later releases.&lt;/li&gt;
&lt;li&gt;Editing custom messages in the Admin Center doesn&#39;t provide emoji suggestions.&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin Center.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/articles/viewing-push-logs/&quot;&gt;Repository push logs&lt;/a&gt; don&#39;t record whether a push was forced.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Uploading PNG images with &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;through the web interface&lt;/a&gt; can fail with the error &#39;Something went really wrong, and we can&#39;t process that file.&#39;&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 30 Aug 2016 16:00:26 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.6.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.6.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.5.13</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In a clustering environment, Gists were not being replicated to new nodes.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;git-lfs pull&lt;/code&gt; could cause high MySQL CPU usage.&lt;/li&gt;
&lt;li&gt;Gist IDs could incorrectly collide when MySQL restarted.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-11-15)&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We didn&#39;t include the fix for the issue that migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-11-15)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 30 Aug 2016 16:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.5.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.5.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.4.16</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Gist IDs could incorrectly collide when MySQL restarted.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 30 Aug 2016 16:00:24 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.4.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.4.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.3.20</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Gist IDs could incorrectly collide when MySQL restarted.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Email can&#39;t be sent over TLS when SSL is disabled.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 30 Aug 2016 16:00:23 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.3.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.3.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.7.2</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: Fixed a buffer overflow vulnerability in a network accessible service. Exploitation could result in remote code execution or denial of service. This vulnerability was identified internally and currently no known exploits exist.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: Worked around Microsoft Internet Explorer bug causing redirects to the incorrect hostname during OAuth negotiation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Users were able to delete SSH and/or GPG keys when LDAP sync is enabled.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;An appliance would enter maintenance mode earlier than expected if scheduled more than a week in advance.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-diagnostics&lt;/code&gt; printed a benign &lt;code&gt;unrecognised disk label&lt;/code&gt; error message.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks using the &lt;code&gt;curl&lt;/code&gt; and/or &lt;code&gt;gpg&lt;/code&gt; command may have failed using the &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/developer-workflow/creating-a-pre-receive-hook-environment/&quot;&gt;default hook environment&lt;/a&gt; due to missing libraries.&lt;/li&gt;
&lt;li&gt;Git pushes were denied if the pre-receive hook timed out on repositories with a non-enforced exit-status.&lt;/li&gt;
&lt;li&gt;Public Pages could not be configured when Private Mode is enabled.&lt;/li&gt;
&lt;li&gt;The &lt;a href=&quot;https://developer.github.com/changes/2016-07-06-github-pages-preiew-api/&quot;&gt;Pages preview API&lt;/a&gt; showed incorrect values for &lt;code&gt;html_url&lt;/code&gt; and erroneously used &lt;code&gt;cname&lt;/code&gt; when subdomain isolation is enabled.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;sudo&lt;/code&gt; and commands that call &lt;code&gt;sudo&lt;/code&gt;, like the &lt;code&gt;ghe-repl-*&lt;/code&gt; commands, would print a harmless &lt;code&gt;sudo: unable to resolve host&lt;/code&gt; message when run on AWS-hosted high availability replicas.&lt;/li&gt;
&lt;li&gt;Avatars may have failed to render in a clustering environment.&lt;/li&gt;
&lt;li&gt;Large file uploads may have timed out in a clustering environment.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;git&lt;/code&gt; operations may have blocked indefinitely if the data volume had less than 10% free disk space.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Additional white spacing can sometimes be seen above the Admin center header.&lt;/li&gt;
&lt;li&gt;Issue assignees assigned in GitHub Enterprise 2.6 or earlier aren&#39;t visible. (updated 2016-08-27)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Editing custom messages in the Admin center doesn&#39;t provide emoji suggestions was resolved in 2.7.0. (updated 2016-09-21)&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin center was resolved in 2.7.0. (updated 2016-09-21)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 16 Aug 2016 16:00:27 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.7.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.7.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.6.7</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: Worked around Microsoft Internet Explorer bug causing redirects to the incorrect hostname during OAuth negotiation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Users were able to delete SSH and/or GPG keys when LDAP sync is enabled.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;An appliance would enter maintenance mode earlier than expected if scheduled more than a week in advance.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks using the &lt;code&gt;curl&lt;/code&gt; and/or &lt;code&gt;gpg&lt;/code&gt; command may have failed using the &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/developer-workflow/creating-a-pre-receive-hook-environment/&quot;&gt;default hook environment&lt;/a&gt; due to missing libraries.&lt;/li&gt;
&lt;li&gt;Git pushes were denied if the pre-receive hook timed out on repositories with a non-enforced exit-status.&lt;/li&gt;
&lt;li&gt;Avatars may have failed to render in a clustering environment.&lt;/li&gt;
&lt;li&gt;Large file uploads may have timed out in a clustering environment.&lt;/li&gt;
&lt;li&gt;Unable to delete, transfer, or change the visibility of a repository from incorrect input validation.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring a protected branch archived whilst running 2.3, will not restore all the settings correctly. This does not affect new instances or protected branches archived on later releases.&lt;/li&gt;
&lt;li&gt;Editing custom messages in the Admin Center doesn&#39;t provide emoji suggestions.&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin Center.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/articles/viewing-push-logs/&quot;&gt;Repository push logs&lt;/a&gt; don&#39;t record whether a push was forced.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Uploading PNG images with &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;through the web interface&lt;/a&gt; can fail with the error &#39;Something went really wrong, and we can&#39;t process that file.&#39;&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 16 Aug 2016 16:00:26 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.6.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.6.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.5.12</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: Worked around Microsoft Internet Explorer bug causing redirects to the incorrect hostname during OAuth negotiation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Users were able to delete SSH and/or GPG keys when LDAP sync is enabled.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;An appliance would enter maintenance mode earlier than expected if scheduled more than a week in advance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-11-15)&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We didn&#39;t include the fix for the issue that migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-11-15)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 16 Aug 2016 16:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.5.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.5.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.4.15</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: Worked around Microsoft Internet Explorer bug causing redirects to the incorrect hostname during OAuth negotiation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Users were able to delete SSH and/or GPG keys when LDAP sync is enabled.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;An appliance would enter maintenance mode earlier than expected if scheduled more than a week in advance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 16 Aug 2016 16:00:24 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.4.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.4.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.3.19</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: Worked around Microsoft Internet Explorer bug causing redirects to the incorrect hostname during OAuth negotiation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Users were able to delete SSH and/or GPG keys when LDAP sync is enabled.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;An appliance would enter maintenance mode earlier than expected if scheduled more than a week in advance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Email can&#39;t be sent over TLS when SSL is disabled.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 16 Aug 2016 16:00:23 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.3.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.3.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.7.1</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Pre-receive hooks using the &lt;code&gt;awk&lt;/code&gt; command in the &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/developer-workflow/creating-a-pre-receive-hook-environment/&quot;&gt;default hook environment&lt;/a&gt; would fail with a &lt;em&gt;cannot open shared object file&lt;/em&gt; message.&lt;/li&gt;
&lt;li&gt;The network information displayed on the hypervisor console didn&#39;t display correctly if the instance did not have an IP address.&lt;/li&gt;
&lt;li&gt;Updated &lt;code&gt;glibc&lt;/code&gt; to fix an assertion error during DNS lookups which occured in very specific network setups. See &lt;a href=&quot;https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=825699&quot;&gt;https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=825699&lt;/a&gt; for more details.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;task_list_instrumentation&lt;/code&gt; queue in the output from &lt;code&gt;ghe-resque-info&lt;/code&gt; would show harmless unprocessed jobs. These are now being correctly processed.&lt;/li&gt;
&lt;li&gt;When LDAP sync is enabled for SSH and/or GPG keys, users were still able to add new keys via the web UI.&lt;/li&gt;
&lt;li&gt;New and upgraded AWS-hosted instances would default to using &lt;code&gt;8.8.8.8&lt;/code&gt; for the DNS server. This could cause issues if that DNS server is not reachable.&lt;/li&gt;
&lt;li&gt;Language breakdown for an empty repository would fail with a HTTP 500 error.&lt;/li&gt;
&lt;li&gt;Administrators could not view a user&#39;s GPG keys via the Site Admin dashboard.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Additional white spacing can sometimes be seen above the Admin center header.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;git&lt;/code&gt; operations may block indefinitely if the data volume has less than 10% free disk space. (updated 2016-08-16)&lt;/li&gt;
&lt;li&gt;Issue assignees assigned in GitHub Enterprise 2.6 or earlier aren&#39;t visible. (updated 2016-08-27)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Backups and Disaster Recovery&lt;/h2&gt;
&lt;p&gt;GitHub Enterprise 2.7 requires at least &lt;a href=&quot;https://github.com/github/backup-utils&quot;&gt;GitHub Enterprise Backup Utilities&lt;/a&gt; 2.7.0 for &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/backups-and-disaster-recovery/&quot;&gt;Backups and Disaster Recovery&lt;/a&gt;. (updated 2016-08-15)&lt;/p&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Editing custom messages in the Admin center doesn&#39;t provide emoji suggestions was resolved in 2.7.0. (updated 2016-09-21)&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin center was resolved in 2.7.0. (updated 2016-09-21)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 09 Aug 2016 16:00:27 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.7.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.7.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.7.0</title>
					<description>&lt;h2&gt;Features&lt;/h2&gt;
&lt;p&gt;With the new features added in GitHub Enterprise 2.7.0, you can:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Sign commits and tags using verified &lt;a href=&quot;https://docs.github.com/enterprise/2.7/user/categories/gpg/&quot;&gt;GPG keys&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Keep track of comment edits with edit badges, a label indicating a post was edited.&lt;/li&gt;
&lt;li&gt;Add up to 10 people to an issue or pull request with &lt;a href=&quot;https://docs.github.com/enterprise/2.7/user/articles/assigning-issues-and-pull-requests-to-other-github-users&quot;&gt;multiple assignees&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Move checklist items around by &lt;a href=&quot;https://docs.github.com/enterprise/2.7/user/articles/basic-writing-and-formatting-syntax#task-lists&quot;&gt;dragging and dropping them&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Display up to five public repositories in the &lt;a href=&quot;https://docs.github.com/enterprise/2.7/user/articles/pinning-repositories-to-your-profile&quot;&gt;&amp;quot;Pinned repositories&amp;quot; section on your profile&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.github.com/enterprise/2.7/v3/pulls/#merge-a-pull-request-merge-button&quot;&gt;Squash a pull request&lt;/a&gt; in the Pull Request Merge API during the preview period.&lt;/li&gt;
&lt;li&gt;Use the &lt;a href=&quot;https://developer.github.com/enterprise/2.7/v3/reactions/&quot;&gt;endpoints for Reactions&lt;/a&gt; to react and unreact via the API.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.github.com/enterprise/2.7/v3/issues/#lock-an-issue&quot;&gt;Lock an issue&#39;s conversation&lt;/a&gt; via the API.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/2203-email-updates-about-your-own-activity&quot;&gt;Receive email notifications&lt;/a&gt; about your GitHub activity.&lt;/li&gt;
&lt;li&gt;Use the branches API to &lt;a href=&quot;https://developer.github.com/enterprise/2.7/v3/repos/branches/#add-user-restrictions-of-protected-branch&quot;&gt;specify which members and teams can push to a protected branch&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.7/user/articles/publicizing-or-hiding-your-private-contributions-on-your-profile&quot;&gt;Publicize or hide&lt;/a&gt; your private contributions on your profile.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.7/user/articles/adding-a-bio-to-your-profile&quot;&gt;Add a bio&lt;/a&gt; to your profile to share information about yourself with other GitHub users.&lt;/li&gt;
&lt;li&gt;Integrate Pre-receive hooks into your workflow using the &lt;a href=&quot;https://developer.github.com/enterprise/2.7/v3/enterprise/pre_receive_environments&quot;&gt;Pre-receive environments&lt;/a&gt; and &lt;a href=&quot;https://developer.github.com/enterprise/2.7/v3/enterprise/pre_receive_hooks&quot;&gt;Pre-receive hooks&lt;/a&gt; API.&lt;/li&gt;
&lt;li&gt;Use more &lt;a href=&quot;https://developer.github.com/changes/2016-04-18-new-webhook-actions-are-live/&quot;&gt;webhook event actions&lt;/a&gt; to notify when changes are made to issues and pull requests and if a repository&#39;s public visibility changes.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: In current (less than 2.7) versions of GitHub Enterprise, a SAML or CAS authenticated user may log in as another user if they have full control of the login value registered with the external authentication provider. While this issue only affects specific installations, we have released this as a CRITICAL issue given its impact when external authentication configurations allow user control of registered logins.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: The permissions on &lt;code&gt;rbenv&lt;/code&gt;, used by many components of GitHub Enterprise, have been tightened.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Webhook responses that were not encoded as UTF-8 would not be viewable in the delivery log.&lt;/li&gt;
&lt;li&gt;Organizations could be suspended using the &lt;code&gt;ghe-user-suspend&lt;/code&gt; command.&lt;/li&gt;
&lt;li&gt;Transparent avatars were rendered with an opaque white background.&lt;/li&gt;
&lt;li&gt;Clicking the rocket icon led to the current repository administration page instead of the intended Site admin page.&lt;/li&gt;
&lt;li&gt;The first part of the fully qualified hostname was used in the system logs instead of the normalized hostname.&lt;/li&gt;
&lt;li&gt;Uploading PNG images with drag and drop could fail with the error &#39;Something went really wrong, and we can&#39;t process that file.&#39;.&lt;/li&gt;
&lt;li&gt;The mobile view of a repository didn&#39;t show the total number of commits.&lt;/li&gt;
&lt;li&gt;Repository push logs didn&#39;t record whether a push was forced.&lt;/li&gt;
&lt;li&gt;Avatars may not have been displayed on preview.&lt;/li&gt;
&lt;li&gt;Console text was difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The &amp;quot;Revert&amp;quot; button was missing when a pull request was squash merged. (updated 2016-09-21)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Upgrading of Elasticsearch indices is now a background process. Searching will continue to operate normally during this time.&lt;/li&gt;
&lt;li&gt;The speed of some SVN to Git operations has been improved.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-webhook-logs&lt;/code&gt; command line utility, a command-line viewer for webhook logs has been introduced.&lt;/li&gt;
&lt;li&gt;Unsubscribe links now require authentication. The logged in user must match the user the link was originally sent to in order for the unsubscribe to occur.&lt;/li&gt;
&lt;li&gt;RequestDenied SAML responses are better handled and a descriptive message is returned to the user.&lt;/li&gt;
&lt;li&gt;Webhooks can now be migrated along with repository and user data using &lt;code&gt;gh-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/2172-github-pages-now-runs-jekyll-3-1&quot;&gt;GitHub Pages uses Jekyll 3.1&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Backups and Disaster Recovery&lt;/h2&gt;
&lt;p&gt;GitHub Enterprise 2.7 requires at least &lt;a href=&quot;https://github.com/github/backup-utils&quot;&gt;GitHub Enterprise Backup Utilities&lt;/a&gt; 2.7.0 for &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/backups-and-disaster-recovery/&quot;&gt;Backups and Disaster Recovery&lt;/a&gt;. (updated 2016-08-15)&lt;/p&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise 2.2&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.2 is now deprecated.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this release. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.3&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.3 will be deprecated as of October 2016.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of Markdown engines&lt;/h2&gt;
&lt;p&gt;GitHub Pages on GitHub Enterprise 2.8 and later will &lt;a href=&quot;https://github.com/blog/2136-a-look-behind-our-decision-to-standardize-on-a-single-markdown-engine-for-github-pages&quot;&gt;only support kramdown&lt;/a&gt;, Jekyll&#39;s default Markdown engine. If you are currently using Rdiscount or Redcarpet we&#39;ve enabled kramdown&#39;s GitHub-flavored Markdown support by default, meaning kramdown should have all the features of the two deprecated Markdown engines, so the transition should be as simple as updating the Markdown setting to &lt;code&gt;kramdown&lt;/code&gt; in your site&#39;s configuration (or removing it entirely).&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Administrators cannot view a user&#39;s GPG keys via the Site Admin dashboard.&lt;/li&gt;
&lt;li&gt;Additional white spacing can sometimes be seen above the Admin center header.&lt;/li&gt;
&lt;li&gt;When LDAP sync is enabled for SSH and/or GPG keys, users are still able to add new keys via the web UI.&lt;/li&gt;
&lt;li&gt;New and upgraded AWS-hosted instances will default to using &lt;code&gt;8.8.8.8&lt;/code&gt; for the DNS server. This can cause issues if that DNS server is not reachable. Run: &lt;code&gt;sudo rm /etc/resolv.conf &amp;amp;&amp;amp; sudo ln -s /etc/resolvconf/run/resolv.conf /etc/resolv.conf&lt;/code&gt; and then reboot to workaround this issue. (updated 2016-08-04)&lt;/li&gt;
&lt;li&gt;Pre-receive hooks using the &lt;code&gt;awk&lt;/code&gt; command in the &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/developer-workflow/creating-a-pre-receive-hook-environment/&quot;&gt;default hook environment&lt;/a&gt; will fail with a &lt;em&gt;cannot open shared object file&lt;/em&gt; message. (updated 2016-08-08)&lt;/li&gt;
&lt;li&gt;&lt;code&gt;git&lt;/code&gt; operations may block indefinitely if the data volume has less than 10% free disk space. (updated 2016-08-16)&lt;/li&gt;
&lt;li&gt;Issue assignees assigned in GitHub Enterprise 2.6 or earlier aren&#39;t visible. (updated 2016-08-27)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;collectd metric paths can be truncated, which causes multiple write attempts to the same file for different metrics. (updated 2017-07-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Editing custom messages in the Admin center doesn&#39;t provide emoji suggestions was resolved in 2.7.0. (updated 2016-09-21)&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin center was resolved in 2.7.0. (updated 2016-09-21)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 03 Aug 2016 16:00:27 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.7.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.7.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.6.6</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; In versions 2.6.0 through 2.6.5 of GitHub Enterprise, a CAS authenticated user may log in as another user if they have full control of the login value registered with the external authentication provider. While this issue only affects specific installations, we have released this as a CRITICAL issue given its impact when external authentication configurations allow user control of registered logins.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; The permissions on &lt;code&gt;rbenv&lt;/code&gt;, used by many components of GitHub Enterprise, have been tightened.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Built Pages sites on a cluster node became inaccessible if the database master role was migrated to the node.&lt;/li&gt;
&lt;li&gt;The schema for requests to and responses from the LFS API has been relaxed to allow additional properties. This will allow the API to be extended in the future.&lt;/li&gt;
&lt;li&gt;Organizations could be suspended using the &lt;code&gt;ghe-user-suspend&lt;/code&gt; command.&lt;/li&gt;
&lt;li&gt;Adding a new node to a cluster would fail if another node was unavailable.&lt;/li&gt;
&lt;li&gt;Updates to user avatars may not have been visible for up to five minutes on clustered installations.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring a protected branch archived whilst running 2.3, will not restore all the settings correctly. This does not affect new instances or protected branches archived on later releases.&lt;/li&gt;
&lt;li&gt;Editing custom messages in the Admin Center doesn&#39;t provide emoji suggestions.&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin Center.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/articles/viewing-push-logs/&quot;&gt;Repository push logs&lt;/a&gt; don&#39;t record whether a push was forced.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Uploading PNG images with &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;through the web interface&lt;/a&gt; can fail with the error &#39;Something went really wrong, and we can&#39;t process that file.&#39;&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https.&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 03 Aug 2016 16:00:26 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.6.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.6.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.5.11</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; The permissions on &lt;code&gt;rbenv&lt;/code&gt;, used by many components of GitHub Enterprise, have been tightened.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The schema for requests to and responses from the LFS API has been relaxed to allow additional properties. This will allow the API to be extended in the future.&lt;/li&gt;
&lt;li&gt;Organizations could be suspended using the &lt;code&gt;ghe-user-suspend&lt;/code&gt; command.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-11-15)&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM.&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We didn&#39;t include the fix for the issue that migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-11-15)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 03 Aug 2016 16:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.5.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.5.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.4.14</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; The permissions on &lt;code&gt;rbenv&lt;/code&gt;, used by many components of GitHub Enterprise, have been tightened.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The schema for requests to and responses from the LFS API has been relaxed to allow additional properties. This will allow the API to be extended in the future.&lt;/li&gt;
&lt;li&gt;Organizations could be suspended using the &lt;code&gt;ghe-user-suspend&lt;/code&gt; command.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 03 Aug 2016 16:00:24 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.4.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.4.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.3.18</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; The permissions on &lt;code&gt;rbenv&lt;/code&gt;, used by many components of GitHub Enterprise, have been tightened.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Organizations could be suspended using the &lt;code&gt;ghe-user-suspend&lt;/code&gt; command.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Email can&#39;t be sent over TLS when SSL is disabled.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 03 Aug 2016 16:00:23 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.3.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.3.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.24</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; The permissions on &lt;code&gt;rbenv&lt;/code&gt;, used by many components of GitHub Enterprise, have been tightened.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise 2.2&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.2 is now deprecated.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this release. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.7/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Organization invitation emails are sent from the configured support email address rather than the no-reply address.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 03 Aug 2016 16:00:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.2.24</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.24</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.6.5</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; Due to the way that email addresses with Unicode in the &#39;local part&#39; are handled, it was possible to generate a password reset token for an email address and have it delivered to a separate email address with Unicode homoglyphs that normalized to the original email address.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; Admin users could still access user reports after being suspended.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; did not include issue file attachments, which could cause imports to another server to fail.&lt;/li&gt;
&lt;li&gt;SAML reauthentication could fail if the SAML identity provider returned large headers in the authentication response.&lt;/li&gt;
&lt;li&gt;LDAP sync could fail on suspended users if restricted groups are not configured.&lt;/li&gt;
&lt;li&gt;Pushing Git LFS objects to a fork of a repository the user only has read access to would fail.&lt;/li&gt;
&lt;li&gt;PSD files stored in LFS failed to render.&lt;/li&gt;
&lt;li&gt;The settings would fail to be copied to the high availability replica if NTP has not been configured.&lt;/li&gt;
&lt;li&gt;SSH keys added or removed via the management console after high availability replication has started could fail to be copied to the replica.&lt;/li&gt;
&lt;li&gt;Hostnames that contain hyphens could not be used in the proxy exclusion list in the management console settings.&lt;/li&gt;
&lt;li&gt;Alambic services would not run on job-server cluster nodes.&lt;/li&gt;
&lt;li&gt;ElasticSearch on cluster nodes could enter a split-brain state in the event of a network partition or failure.&lt;/li&gt;
&lt;li&gt;Pre-receive hook environment variables were not all set on repository initialization. This could lead to pre-receive hooks running incorrectly on the first commit that takes place when creating a repository via a web browser. (updated 2016-07-13)&lt;/li&gt;
&lt;li&gt;Downloading identical user or repository reports in quick succession could lead to a build up in duplicate jobs that could affect the performance of the appliance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h1&gt;Changes&lt;/h1&gt;
&lt;ul&gt;
&lt;li&gt;The automatic update check will only download the latest release that the appliance can upgrade directly to.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring a protected branch archived whilst running 2.3, will not restore all the settings correctly. This does not affect new instances or protected branches archived on later releases.&lt;/li&gt;
&lt;li&gt;Editing custom messages in the Admin Center doesn&#39;t provide emoji suggestions.&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin Center.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/articles/viewing-push-logs/&quot;&gt;Repository push logs&lt;/a&gt; don&#39;t record whether a push was forced.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Uploading PNG images with &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;through the web interface&lt;/a&gt; can fail with the error &#39;Something went really wrong, and we can&#39;t process that file.&#39;&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https. (updated 2016-08-01)&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM. (updated 2016-08-03)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 12 Jul 2016 17:00:06 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.6.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.6.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.5.10</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; Due to the way that email addresses with Unicode in the &#39;local part&#39; are handled, it was possible to generate a password reset token for an email address and have it delivered to a separate email address with Unicode homoglyphs that normalized to the original email address.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; Admin users could still access user reports after being suspended.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;LDAP sync failed on suspended users if restricted groups are not configured.&lt;/li&gt;
&lt;li&gt;Pushing Git LFS objects to a fork of a repository the user only has read access to would fail.&lt;/li&gt;
&lt;li&gt;PSD files stored in LFS failed to render.&lt;/li&gt;
&lt;li&gt;Alambic services would not run on job-server cluster nodes.&lt;/li&gt;
&lt;li&gt;Downloading identical user or repository reports in quick succession could lead to a build up in duplicate jobs that could affect the performance of the appliance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-11-15)&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM. (updated 2016-08-03)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We didn&#39;t include the fix for the issue that migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-11-15)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 12 Jul 2016 17:00:05 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.5.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.5.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.4.13</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; Due to the way that email addresses with Unicode in the &#39;local part&#39; are handled, it was possible to generate a password reset token for an email address and have it delivered to a separate email address with Unicode homoglyphs that normalized to the original email address.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; Admin users could still access user reports after being suspended.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;LDAP sync failed on suspended users if restricted groups are not configured.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 12 Jul 2016 17:00:04 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.4.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.4.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.3.17</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; Due to the way that email addresses with Unicode in the &#39;local part&#39; are handled, it was possible to generate a password reset token for an email address and have it delivered to a separate email address with Unicode homoglyphs that normalized to the original email address.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; Admin users could still access user reports after being suspended.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Email can&#39;t be sent over TLS when SSL is disabled.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 12 Jul 2016 17:00:03 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.3.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.3.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.23</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; Due to the way that email addresses with Unicode in the &#39;local part&#39; are handled, it was possible to generate a password reset token for an email address and have it delivered to a separate email address with Unicode homoglyphs that normalized to the original email address.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; Admin users could still access user reports after being suspended.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Organization invitation emails are sent from the configured support email address rather than the no-reply address.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 12 Jul 2016 17:00:02 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.2.23</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.23</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.6.4</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The proxy configuration was not picked up by the update check initiated from the the management console.&lt;/li&gt;
&lt;li&gt;The merge pull request button could remain disabled for an extended period of time following a force-push on a repository with protected branches and required statuses enabled.&lt;/li&gt;
&lt;li&gt;It was not possible to ignore whitespace in diffs by appending &lt;code&gt;?w=1&lt;/code&gt; to the URL.&lt;/li&gt;
&lt;li&gt;Authenticating using SAML could fail if the authentication process took too long, for example when a user is performing two-factor authentication with the SAML server.&lt;/li&gt;
&lt;li&gt;Importing or restoring a Redis database using &lt;code&gt;ghe-import-redis&lt;/code&gt; or setting up a cluster, could fail if reading in the data takes longer than 30 seconds to complete.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/user/articles/adding-a-file-to-a-repository/&quot;&gt;Repository file uploads&lt;/a&gt; would fail if SSL is not enabled on the appliance.&lt;/li&gt;
&lt;li&gt;Redownloading and extracting an existing pre-receive hook environment could fail due to incorrect file permissions.&lt;/li&gt;
&lt;li&gt;Migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; did not include issue file attachments, which could cause imports to another server to fail.&lt;/li&gt;
&lt;li&gt;Custom environments for pre-receive hooks failed to install correctly on a cluster.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Prompt-less upgrades can now be performed by passing the &lt;code&gt;-y&lt;/code&gt; argument to &lt;code&gt;ghe-upgrade&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Restoring repositories from backups of cluster nodes has been sped up.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring a protected branch archived whilst running 2.3, will not restore all the settings correctly. This does not affect new instances or protected branches archived on later releases.&lt;/li&gt;
&lt;li&gt;Editing custom messages in the Admin Center doesn&#39;t provide emoji suggestions.&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin Center.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/articles/viewing-push-logs/&quot;&gt;Repository push logs&lt;/a&gt; don&#39;t record whether a push was forced.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https. (updated 2016-08-01)&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM. (updated 2016-08-03)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 21 Jun 2016 14:30:26 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.6.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.6.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.5.9</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Authenticating using SAML could fail if the authentication process took too long, for example when a user is performing two-factor authentication with the SAML server.&lt;/li&gt;
&lt;li&gt;Importing or restoring a Redis database using &lt;code&gt;ghe-import-redis&lt;/code&gt; or setting up a cluster, could fail if reading in the data takes longer than 30 seconds to complete.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail.&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM. (updated 2016-08-03)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 21 Jun 2016 14:30:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.5.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.5.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.4.12</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Authenticating using SAML could fail if the authentication process took too long, for example when a user is performing two-factor authentication with the SAML server.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 21 Jun 2016 14:30:24 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.4.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.4.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.3.16</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Authenticating using SAML could fail if the authentication process took too long, for example when a user is performing two-factor authentication with the SAML server.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Email can&#39;t be sent over TLS when SSL is disabled.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 21 Jun 2016 14:30:23 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.3.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.3.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.22</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Organization invitation emails are sent from the configured support email address rather than the no-reply address.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 21 Jun 2016 14:30:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.2.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.6.3</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Redis database was not properly cleared when restoring with the backup utilities more than once to GitHub Enterprise Cluster configuration. This could cause the Redis database to become very large, slowing down restores.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;$GITHUB_REPO_PUBLIC&lt;/code&gt; variable wasn&#39;t available to pre-receive hook scripts when edits were made via the web UI.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-migrator&lt;/code&gt; failed to import users without an email address, which could cause the whole import to fail.&lt;/li&gt;
&lt;li&gt;Deleting Git LFS files from the site admin dashboard failed with a 500 error.&lt;/li&gt;
&lt;li&gt;Uploading a support bundle with a ticket reference using &lt;code&gt;ghe-cluster-support-bundle -t [ticket reference]&lt;/code&gt; failed on a GitHub Enterprise Cluster.&lt;/li&gt;
&lt;li&gt;Increasing the size of the data volume using &lt;code&gt;ghe-storage-extend&lt;/code&gt; could fail.&lt;/li&gt;
&lt;li&gt;OAuth application callback hostnames were limited to no longer than 63 characters, which caused some OAuth applications to stop working.&lt;/li&gt;
&lt;li&gt;A missing Git repository on a high availability replica could block Git replication.&lt;/li&gt;
&lt;li&gt;Pre-receive hooks in the default environment failed after upgrading.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Pre-receive hook scripts in the default environment now execute as Bash if no shebang program is specified.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring a protected branch archived whilst running 2.3, will not restore all the settings correctly. This does not affect new instances or protected branches archived on later releases.&lt;/li&gt;
&lt;li&gt;Editing custom messages in the Admin Center doesn&#39;t provide emoji suggestions.&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin Center.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/articles/viewing-push-logs/&quot;&gt;Repository push logs&lt;/a&gt; don&#39;t record whether a push was forced.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository.&lt;/li&gt;
&lt;li&gt;Migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-06-09)&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https. (updated 2016-08-01)&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM. (updated 2016-08-03)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 31 May 2016 16:00:26 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.6.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.6.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.5.8</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Redis database was not properly cleared when restoring with the backup utilities more than once to GitHub Enterprise in a Cluster configuration. This could waste disk space and cause restores to be slow.&lt;/li&gt;
&lt;li&gt;Deleting Git LFS files from the site admin dashboard failed with a 500 error.&lt;/li&gt;
&lt;li&gt;Uploading a support bundle with a ticket reference using &lt;code&gt;ghe-cluster-support-bundle -t [ticket reference]&lt;/code&gt; failed on a GitHub Enterprise Cluster.&lt;/li&gt;
&lt;li&gt;OAuth application callback hostnames were limited to no longer than 63 characters, which caused some OAuth applications to stop working.&lt;/li&gt;
&lt;li&gt;A missing Git repository on a high availability replica could block Git replication.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed.&lt;/li&gt;
&lt;li&gt;Migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-06-09)&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM. (updated 2016-08-03)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 31 May 2016 16:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.5.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.5.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.4.11</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;OAuth application callback hostnames were limited to no longer than 63 characters, which caused some OAuth applications to stop working.&lt;/li&gt;
&lt;li&gt;A missing Git repository on a high availability replica could block Git replication.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 31 May 2016 16:00:24 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.4.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.4.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.3.15</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;OAuth application callback hostnames were limited to no longer than 63 characters, which caused some OAuth applications to stop working.&lt;/li&gt;
&lt;li&gt;A missing Git repository on a high availability replica could block Git replication.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Email can&#39;t be sent over TLS when SSL is disabled.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 31 May 2016 16:00:23 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.3.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.3.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.21</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;OAuth application callback hostnames were limited to no longer than 63 characters, which caused some OAuth applications to stop working.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Organization invitation emails are sent from the configured support email address rather than the no-reply address.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 31 May 2016 16:00:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.2.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.6.2</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; Release assets from a public repository could be accessed by unauthenticated users in private mode. (updated 2016-05-27)&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The custom messages Markdown editor in the Admin Center included buttons for non-applicable functionality.&lt;/li&gt;
&lt;li&gt;Custom messages within the Admin Center were not disabled when SAML authentication was used, even though they had no effect since the SAML server is responsible for displaying the relevant messages to users.&lt;/li&gt;
&lt;li&gt;CAS logout failed when the CAS server URL includes a path.&lt;/li&gt;
&lt;li&gt;Using a deploy key to fetch Git LFS assets prompted for password authentication.&lt;/li&gt;
&lt;li&gt;The &amp;quot;explore&amp;quot; and &amp;quot;trending&amp;quot; pages included a &amp;quot;Sign in&amp;quot; button when you&#39;re already signed in.&lt;/li&gt;
&lt;li&gt;We didn&#39;t display errors when updating a pre-receive hook failed.&lt;/li&gt;
&lt;li&gt;Admins couldn&#39;t manage Gist comments in the site admin.&lt;/li&gt;
&lt;li&gt;The pre-receive hook permissions text described the wrong scope.&lt;/li&gt;
&lt;li&gt;The GitHub Enterprise version wasn&#39;t displayed when hovering over the Octocat icon in the footer.&lt;/li&gt;
&lt;li&gt;Background jobs in the &lt;code&gt;languages&lt;/code&gt; queue weren&#39;t run. This caused repository language statistics to be inaccurate.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring a protected branch archived whilst running 2.3, will not restore all the settings correctly. This does not affect new instances or protected branches archived on later releases.&lt;/li&gt;
&lt;li&gt;Editing custom messages in the Admin Center doesn&#39;t provide emoji suggestions.&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin Center.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/articles/viewing-push-logs/&quot;&gt;Repository push logs&lt;/a&gt; don&#39;t record whether a push was forced.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed. (updated 2016-05-24)&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository. (updated 2016-05-24)&lt;/li&gt;
&lt;li&gt;Migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-06-09)&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https. (updated 2016-08-01)&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM. (updated 2016-08-03)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 17 May 2016 16:00:26 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.6.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.6.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.5.7</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; Final policies that were pending for the ImageMagick vulnerability (first applied in GitHub Enterprise 2.5.6) have now been applied, to address&lt;br /&gt;
&lt;a href=&quot;https://imagetragick.com/&quot;&gt;CVE-2016-3714&lt;/a&gt;. Note that GitHub Enterprise only uses ImageMagick for PSD files to which the vulnerability did not apply. (updated 2016-07-13)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; Release assets from a public repository could be accessed by unauthenticated users in private mode. (updated 2016-05-27)&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;CAS logout failed when the CAS server URL includes a path.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed. (updated 2016-05-24)&lt;/li&gt;
&lt;li&gt;Migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-06-09)&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM. (updated 2016-08-03)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 17 May 2016 16:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.5.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.5.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.4.10</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Release assets could be accessed by unauthenticated users in private mode.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 17 May 2016 16:00:24 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.4.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.4.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.3.14</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Release assets could be accessed by unauthenticated users in private mode.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Email can&#39;t be sent over TLS when SSL is disabled.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 17 May 2016 16:00:23 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.3.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.3.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.20</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Organization invitation emails are sent from the configured support email address rather than the no-reply address.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 17 May 2016 16:00:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.2.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.6.1</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; ImageMagick policies have been updated to address &lt;a href=&quot;https://imagetragick.com/&quot;&gt;CVE-2016-3714&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; OpenSSL packages have been updated to address &lt;a href=&quot;http://www.ubuntu.com/usn/usn-2959-1/&quot;&gt;multiple vulnerabilities&lt;/a&gt;, including &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2105&quot;&gt;CVE-2016-2105&lt;/a&gt;, &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2106&quot;&gt;CVE-2016-2106&lt;/a&gt;, &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2107&quot;&gt;CVE-2016-2107&lt;/a&gt;, &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2108&quot;&gt;CVE-2016-2108&lt;/a&gt;, and &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2109&quot;&gt;CVE-2016-2109&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Remote Code Execution in ImageMagick&lt;/h2&gt;
&lt;p&gt;Several vulnerabilities in ImageMagick, a package commonly used by web services to process images, have been &lt;a href=&quot;https://imagetragick.com/&quot;&gt;discovered and disclosed by members of the Mail.ru Security team&lt;/a&gt;. One of the vulnerabilities is critical and can lead to remote code execution when processing user submitted images.&lt;/p&gt;
&lt;p&gt;Final patches for all the disclosed vulnerabilities within ImageMagick are still pending. This release mitigates the remote code execution vulnerability by implementing the recommended policy to disable the vulnerable ImageMagick coders.&lt;/p&gt;
&lt;p&gt;This vulnerability exists in ImageMagick but there is no evidence that it has been exploited on GitHub Enterprise.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;We strongly recommend that all GitHub Enterprise customers upgrade their instances as soon as possible&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Mitigation&lt;/strong&gt;&lt;br /&gt;
If you can&#39;t immediately upgrade, the issue can be mitigated by implementing the policy changes as follows:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your GitHub Enterprise appliance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Edit the &lt;code&gt;/etc/ImageMagick/policy.xml&lt;/code&gt; file:&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;sudo vi /etc/ImageMagick/policy.xml
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Disable the vulnerable coders by replacing the &lt;code&gt;&amp;lt;policymap&amp;gt;&lt;/code&gt; section with:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;&amp;lt;policymap&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;EPHEMERAL&amp;quot; /&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;URL&amp;quot; /&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;HTTPS&amp;quot; /&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;MVG&amp;quot; /&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;MSL&amp;quot; /&amp;gt;
&amp;lt;/policymap&amp;gt;
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;There is no need to reboot or restart any services; the changes will take effect immediately.&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have any questions.&lt;/p&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Memcached didn&#39;t log warnings or errors.&lt;/li&gt;
&lt;li&gt;Harmless empty lines were added to the admin user&#39;s &lt;code&gt;authorized_keys&lt;/code&gt; file every time the configuration was saved.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;find&lt;/code&gt; command was missing in the &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/developer-workflow/creating-a-pre-receive-hook-environment/&quot;&gt;default pre-receive hook environment&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; Release assets from a public repository can be accessed by unauthenticated users in private mode. (updated 2016-05-27)&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring a protected branch archived whilst running 2.3, will not restore all the settings correctly. This does not affect new instances or protected branches archived on later releases.&lt;/li&gt;
&lt;li&gt;Editing custom messages in the Admin Center doesn&#39;t provide emoji suggestions.&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin Center.&lt;/li&gt;
&lt;li&gt;Custom messages within the Admin Center are not disabled when SAML authentication is used, even though they have no effect since the SAML server is responsible for displaying the relevant messages to users.&lt;/li&gt;
&lt;li&gt;The custom messages Markdown editor in the Admin Center includes buttons for non-applicable functionality.&lt;/li&gt;
&lt;li&gt;Background jobs in the &lt;code&gt;languages&lt;/code&gt; queue aren&#39;t run. This causes repository language statistics to be inaccurate.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/articles/viewing-push-logs/&quot;&gt;Repository push logs&lt;/a&gt; don&#39;t record whether a push was forced. (updated 2016-05-13)&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed. (updated 2016-05-24)&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository. (updated 2016-05-24)&lt;/li&gt;
&lt;li&gt;Migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-06-09)&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https. (updated 2016-08-01)&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM. (updated 2016-08-03)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 04 May 2016 08:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.6.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.6.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.5.6</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; ImageMagick policies have been updated to address &lt;a href=&quot;https://imagetragick.com/&quot;&gt;CVE-2016-3714&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; OpenSSL packages have been updated to address &lt;a href=&quot;http://www.ubuntu.com/usn/usn-2959-1/&quot;&gt;multiple vulnerabilities&lt;/a&gt;, including &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2105&quot;&gt;CVE-2016-2105&lt;/a&gt;, &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2106&quot;&gt;CVE-2016-2106&lt;/a&gt;, &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2107&quot;&gt;CVE-2016-2107&lt;/a&gt;, &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2108&quot;&gt;CVE-2016-2108&lt;/a&gt;, and &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2109&quot;&gt;CVE-2016-2109&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Remote Code Execution in ImageMagick&lt;/h2&gt;
&lt;p&gt;Several vulnerabilities in ImageMagick, a package commonly used by web services to process images, have been &lt;a href=&quot;https://imagetragick.com/&quot;&gt;discovered and disclosed by members of the Mail.ru Security team&lt;/a&gt;. One of the vulnerabilities is critical and can lead to remote code execution when processing user submitted images.&lt;/p&gt;
&lt;p&gt;Final patches for all the disclosed vulnerabilities within ImageMagick are still pending. This release mitigates the remote code execution vulnerability by implementing the recommended policy to disable the vulnerable ImageMagick coders.&lt;/p&gt;
&lt;p&gt;This vulnerability exists in ImageMagick but there is no evidence that it has been exploited on GitHub Enterprise.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;We strongly recommend that all GitHub Enterprise customers upgrade their instances as soon as possible&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Mitigation&lt;/strong&gt;&lt;br /&gt;
If you can&#39;t immediately upgrade, the issue can be mitigated by implementing the policy changes as follows:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your GitHub Enterprise appliance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Edit the &lt;code&gt;/etc/ImageMagick/policy.xml&lt;/code&gt; file:&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;sudo vi /etc/ImageMagick/policy.xml
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Disable the vulnerable coders by replacing the &lt;code&gt;&amp;lt;policymap&amp;gt;&lt;/code&gt; section with:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;&amp;lt;policymap&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;EPHEMERAL&amp;quot; /&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;URL&amp;quot; /&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;HTTPS&amp;quot; /&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;MVG&amp;quot; /&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;MSL&amp;quot; /&amp;gt;
&amp;lt;/policymap&amp;gt;
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;There is no need to reboot or restart any services; the changes will take effect immediately.&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have any questions.&lt;/p&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Memcached didn&#39;t log warnings or errors.&lt;/li&gt;
&lt;li&gt;Harmless empty lines were added to the admin user&#39;s &lt;code&gt;authorized_keys&lt;/code&gt; file every time the configuration was saved.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; Release assets from a public repository can be accessed by unauthenticated users in private mode. (updated 2016-05-27)&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed. (updated 2016-05-24)&lt;/li&gt;
&lt;li&gt;Migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-06-09)&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM. (updated 2016-08-03)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 04 May 2016 08:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.5.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.5.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.4.9</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; ImageMagick policies have been updated to address &lt;a href=&quot;https://imagetragick.com/&quot;&gt;CVE-2016-3714&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; OpenSSL packages have been updated to address &lt;a href=&quot;http://www.ubuntu.com/usn/usn-2959-1/&quot;&gt;multiple vulnerabilities&lt;/a&gt;, including &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2105&quot;&gt;CVE-2016-2105&lt;/a&gt;, &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2106&quot;&gt;CVE-2016-2106&lt;/a&gt;, &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2107&quot;&gt;CVE-2016-2107&lt;/a&gt;, &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2108&quot;&gt;CVE-2016-2108&lt;/a&gt;, and &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2109&quot;&gt;CVE-2016-2109&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Remote Code Execution in ImageMagick&lt;/h2&gt;
&lt;p&gt;Several vulnerabilities in ImageMagick, a package commonly used by web services to process images, have been &lt;a href=&quot;https://imagetragick.com/&quot;&gt;discovered and disclosed by members of the Mail.ru Security team&lt;/a&gt;. One of the vulnerabilities is critical and can lead to remote code execution when processing user submitted images.&lt;/p&gt;
&lt;p&gt;Final patches for all the disclosed vulnerabilities within ImageMagick are still pending. This release mitigates the remote code execution vulnerability by implementing the recommended policy to disable the vulnerable ImageMagick coders.&lt;/p&gt;
&lt;p&gt;This vulnerability exists in ImageMagick but there is no evidence that it has been exploited on GitHub Enterprise.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;We strongly recommend that all GitHub Enterprise customers upgrade their instances as soon as possible&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Mitigation&lt;/strong&gt;&lt;br /&gt;
If you can&#39;t immediately upgrade, the issue can be mitigated by implementing the policy changes as follows:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your GitHub Enterprise appliance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Edit the &lt;code&gt;/etc/ImageMagick/policy.xml&lt;/code&gt; file:&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;sudo vi /etc/ImageMagick/policy.xml
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Disable the vulnerable coders by replacing the &lt;code&gt;&amp;lt;policymap&amp;gt;&lt;/code&gt; section with:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;&amp;lt;policymap&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;EPHEMERAL&amp;quot; /&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;URL&amp;quot; /&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;HTTPS&amp;quot; /&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;MVG&amp;quot; /&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;MSL&amp;quot; /&amp;gt;
&amp;lt;/policymap&amp;gt;
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;There is no need to reboot or restart any services; the changes will take effect immediately.&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have any questions.&lt;/p&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Memcached didn&#39;t log warnings or errors.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 04 May 2016 08:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.4.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.4.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.3.13</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; ImageMagick policies have been updated to address &lt;a href=&quot;https://imagetragick.com/&quot;&gt;CVE-2016-3714&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; OpenSSL packages have been updated to address &lt;a href=&quot;http://www.ubuntu.com/usn/usn-2959-1/&quot;&gt;multiple vulnerabilities&lt;/a&gt;, including &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2105&quot;&gt;CVE-2016-2105&lt;/a&gt;, &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2106&quot;&gt;CVE-2016-2106&lt;/a&gt;, &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2107&quot;&gt;CVE-2016-2107&lt;/a&gt;, &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2108&quot;&gt;CVE-2016-2108&lt;/a&gt;, and &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2109&quot;&gt;CVE-2016-2109&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Remote Code Execution in ImageMagick&lt;/h2&gt;
&lt;p&gt;Several vulnerabilities in ImageMagick, a package commonly used by web services to process images, have been &lt;a href=&quot;https://imagetragick.com/&quot;&gt;discovered and disclosed by members of the Mail.ru Security team&lt;/a&gt;. One of the vulnerabilities is critical and can lead to remote code execution when processing user submitted images.&lt;/p&gt;
&lt;p&gt;Final patches for all the disclosed vulnerabilities within ImageMagick are still pending. This release mitigates the remote code execution vulnerability by implementing the recommended policy to disable the vulnerable ImageMagick coders.&lt;/p&gt;
&lt;p&gt;This vulnerability exists in ImageMagick but there is no evidence that it has been exploited on GitHub Enterprise.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;We strongly recommend that all GitHub Enterprise customers upgrade their instances as soon as possible&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Mitigation&lt;/strong&gt;&lt;br /&gt;
If you can&#39;t immediately upgrade, the issue can be mitigated by implementing the policy changes as follows:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.3/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your GitHub Enterprise appliance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Edit the &lt;code&gt;/etc/ImageMagick/policy.xml&lt;/code&gt; file:&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;sudo vi /etc/ImageMagick/policy.xml
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Disable the vulnerable coders by replacing the &lt;code&gt;&amp;lt;policymap&amp;gt;&lt;/code&gt; section with:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;&amp;lt;policymap&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;EPHEMERAL&amp;quot; /&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;URL&amp;quot; /&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;HTTPS&amp;quot; /&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;MVG&amp;quot; /&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;MSL&amp;quot; /&amp;gt;
&amp;lt;/policymap&amp;gt;
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;There is no need to reboot or restart any services; the changes will take effect immediately.&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have any questions.&lt;/p&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Memcached didn&#39;t log warnings or errors.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Email can&#39;t be sent over TLS when SSL is disabled.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 04 May 2016 08:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.3.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.3.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.19</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; ImageMagick policies have been updated to address &lt;a href=&quot;https://imagetragick.com/&quot;&gt;CVE-2016-3714&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; OpenSSL packages have been updated to address &lt;a href=&quot;http://www.ubuntu.com/usn/usn-2959-1/&quot;&gt;multiple vulnerabilities&lt;/a&gt;, including &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2105&quot;&gt;CVE-2016-2105&lt;/a&gt;, &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2106&quot;&gt;CVE-2016-2106&lt;/a&gt;, &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2107&quot;&gt;CVE-2016-2107&lt;/a&gt;, &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2108&quot;&gt;CVE-2016-2108&lt;/a&gt;, and &lt;a href=&quot;https://openssl.org/news/vulnerabilities.html#2016-2109&quot;&gt;CVE-2016-2109&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Remote Code Execution in ImageMagick&lt;/h2&gt;
&lt;p&gt;Several vulnerabilities in ImageMagick, a package commonly used by web services to process images, have been &lt;a href=&quot;https://imagetragick.com/&quot;&gt;discovered and disclosed by members of the Mail.ru Security team&lt;/a&gt;. One of the vulnerabilities is critical and can lead to remote code execution when processing user submitted images.&lt;/p&gt;
&lt;p&gt;Final patches for all the disclosed vulnerabilities within ImageMagick are still pending. This release mitigates the remote code execution vulnerability by implementing the recommended policy to disable the vulnerable ImageMagick coders.&lt;/p&gt;
&lt;p&gt;This vulnerability exists in ImageMagick but there is no evidence that it has been exploited on GitHub Enterprise.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;We strongly recommend that all GitHub Enterprise customers upgrade their instances as soon as possible&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Mitigation&lt;/strong&gt;&lt;br /&gt;
If you can&#39;t immediately upgrade, the issue can be mitigated by implementing the policy changes as follows:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.2/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your GitHub Enterprise appliance.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Edit the &lt;code&gt;/etc/ImageMagick/policy.xml&lt;/code&gt; file:&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;sudo vi /etc/ImageMagick/policy.xml
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Disable the vulnerable coders by replacing the &lt;code&gt;&amp;lt;policymap&amp;gt;&lt;/code&gt; section with:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;&amp;lt;policymap&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;EPHEMERAL&amp;quot; /&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;URL&amp;quot; /&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;HTTPS&amp;quot; /&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;MVG&amp;quot; /&amp;gt;
  &amp;lt;policy domain=&amp;quot;coder&amp;quot; rights=&amp;quot;none&amp;quot; pattern=&amp;quot;MSL&amp;quot; /&amp;gt;
&amp;lt;/policymap&amp;gt;
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;There is no need to reboot or restart any services; the changes will take effect immediately.&lt;/p&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have any questions.&lt;/p&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Memcached didn&#39;t log warnings or errors.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Organization invitation emails are sent from the configured support email address rather than the no-reply address.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 04 May 2016 08:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.2.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.6.0</title>
					<description>&lt;h2&gt;New Features&lt;/h2&gt;
&lt;p&gt;With the new features added in GitHub Enterprise 2.6.0, you can:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Enforce push policies and optimize workflows with &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/developer-workflow/about-pre-receive-hooks/&quot;&gt;pre-receive hooks&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Create &lt;a href=&quot;https://github.com/blog/2111-issue-and-pull-request-templates&quot;&gt;Issue and pull request templates&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Take advantage of more &lt;a href=&quot;https://github.com/blog/2137-protected-branches-improvements&quot;&gt;flexibility with protected branches&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Add custom messages to the &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/user-management/creating-a-custom-sign-in-message&quot;&gt;sign in&lt;/a&gt; and &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/user-management/suspending-and-unsuspending-users#creating-a-custom-message-for-suspended-users&quot;&gt;suspended user&lt;/a&gt; pages.&lt;/li&gt;
&lt;li&gt;Flexibly &lt;a href=&quot;https://github.com/blog/2123-more-code-review-tools&quot;&gt;review pull requests&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Merge pull requests with &lt;a href=&quot;https://github.com/blog/2141-squash-your-commits&quot;&gt;squash commits&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Add &lt;a href=&quot;https://github.com/blog/2119-add-reactions-to-pull-requests-issues-and-comments&quot;&gt;reactions to Pull Requests, Issues, and Comments&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Save time writing frequently used responses with &lt;a href=&quot;https://github.com/blog/2135-saved-replies&quot;&gt;saved replies&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Use a &lt;a href=&quot;https://github.com/blog/2097-improved-commenting-with-markdown&quot;&gt;markdown toolbar&lt;/a&gt; to style text in comments and issues without learning Markdown.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;Upload files into repositories using GitHub&#39;s interface&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Serve &lt;a href=&quot;https://github.com/blog/2100-github-pages-now-faster-and-simpler-with-jekyll-3-0&quot;&gt;GitHub Pages faster and simpler with Jekyll 3.0&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Configure an Advanced Setting to automatically reactivate suspended LDAP users on their next successful authentication.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The cross-origin resource sharing (CORS) policy has been updated to bring it inline with W3C recommendations.&lt;/li&gt;
&lt;li&gt;Auto-complete is disabled on the password configuration fields in the management console.&lt;/li&gt;
&lt;li&gt;It is no longer possible to filter members of an organization using the &lt;code&gt;is:inactive&lt;/code&gt; filter.&lt;/li&gt;
&lt;li&gt;Admin Tools now has a &#39;Disabled repositories&#39; page.&lt;/li&gt;
&lt;li&gt;The number of simultaneous connections tracked by the appliance firewall has been increased to 524288.&lt;/li&gt;
&lt;li&gt;When the protected branch policy is not fulfilled, we report different states depending on the protected branch required status checks policy.&lt;/li&gt;
&lt;li&gt;Unused scripts have been removed and internal-only scripts have been moved out of the default path.&lt;/li&gt;
&lt;li&gt;All customer-facing scripts print usage information when called with &lt;code&gt;-h&lt;/code&gt; or &lt;code&gt;--help&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;SAML requests can now be configured to use SHA-256 and other common hashing algorithms for the signature and digest methods. The default is now SHA-256. You may need to update your configuration and select SHA-1 if your identity provider does not support SHA-256.&lt;/li&gt;
&lt;li&gt;The management console now contains inline links to the configuration documentation for each section.&lt;/li&gt;
&lt;li&gt;A proxy exclusion (no_proxy) list can now be configured in the management console.&lt;/li&gt;
&lt;li&gt;Logs can be forwarded to multiple locations.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-repl-start&lt;/code&gt; will report if high availability replication is still starting following a reboot.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-repl-status&lt;/code&gt; displays which host is the high availability replica when run on the primary node.&lt;/li&gt;
&lt;li&gt;The license, SSH keys and settings are copied to the high availability replica as and when they&#39;re modified on the primary.&lt;/li&gt;
&lt;li&gt;Custom certificate authority certificates added to the appliance using &lt;code&gt;ghe-ssl-ca-certificate-install&lt;/code&gt; are automatically replicated to the high availability replica.&lt;/li&gt;
&lt;li&gt;All certificates included in the certificate file uploaded via the management console are automatically imported.&lt;/li&gt;
&lt;li&gt;Custom certificate authority certificates are saved with descriptive names for easier identification when running &lt;code&gt;ghe-ssl-ca-certificate-install -l&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;The self-signed certificate generated by the appliance when first configured now includes a wildcard subject alternate name (SAN) entry for the appliance hostname for use with sub-domain isolation.&lt;/li&gt;
&lt;li&gt;Previously built Pages sites are no longer displayed if Pages is subsequently disabled.&lt;/li&gt;
&lt;li&gt;GitHub Pages has been updated to Jekyll 3.0.&lt;/li&gt;
&lt;li&gt;A reason for an email notification is now included in the footer of the email.&lt;/li&gt;
&lt;li&gt;The search index definitions have changed. Some searches may return partial results while the search indices are rebuilt. (updated 2016-04-27)&lt;/li&gt;
&lt;li&gt;GitHub Pages now verifies the SSL connection when cloning sites, so builds will fail if your SSL certificate is invalid. (updated 2016-05-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upgrading&lt;/h2&gt;
&lt;p&gt;Upgrading to the 2.6 release series is supported from GitHub Enterprise 2.4.0 and above.&lt;/p&gt;
&lt;h2&gt;Backup &amp;amp; Restore&lt;/h2&gt;
&lt;p&gt;In order to backup and restore GitHub Enterprise 2.6, you will need to upgrade &lt;a href=&quot;https://github.com/github/backup-utils&quot;&gt;backup-utils&lt;/a&gt; to version 2.6.0.&lt;/p&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Changing a repository&#39;s parent allowed you to reparent onto a folk of the repository being reparented. This would lead to a loop that would fail and leave the repository network in an inconsistent state.&lt;/li&gt;
&lt;li&gt;A migration archive with @mentions in issues or comments that contain dashes were not correctly rewritten when imported using &lt;code&gt;ghe-migrator&lt;/code&gt; on the destination appliance.&lt;/li&gt;
&lt;li&gt;Migrating a repository with issue attachments using &lt;code&gt;ghe-migrator&lt;/code&gt; could fail to import on the destination appliance.&lt;/li&gt;
&lt;li&gt;User sessions were not properly revoked when they reached the expiry limit set by the SAML identity provider (IdP).&lt;/li&gt;
&lt;li&gt;User web browser sessions were revoked after 14 days of inactivity instead of 30 days.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-support-bundle&lt;/code&gt; displayed harmless messages.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Resolved a cross-site scripting (XSS) vulnerability in task lists.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Implemented mitigation for a URI decoding vulnerability that affects modern versions of Microsoft Internet Explorer.&lt;/li&gt;
&lt;li&gt;User sessions were not properly revoked when they reached the expiry limit set by the SAML identity provider (IdP).&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise 2.1&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.1 is now deprecated.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this release. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.2&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.2 will be deprecated as of August 2016.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Deprecation of Support for Internet Explorer 9 and 10&lt;/h2&gt;
&lt;p&gt;Support for Internet Explorer 9 and 10 will be deprecated in a future release. There will be no changes in site functionality, but a warning banner will be displayed to Internet Explorer 9 and 10 users.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of Markdown engines&lt;/h2&gt;
&lt;p&gt;GitHub Pages on GitHub Enterprise 2.7 and later will &lt;a href=&quot;https://github.com/blog/2136-a-look-behind-our-decision-to-standardize-on-a-single-markdown-engine-for-github-pages&quot;&gt;only support kramdown&lt;/a&gt;, Jekyll&#39;s default Markdown engine. If you are currently using Rdiscount or Redcarpet we&#39;ve enabled kramdown&#39;s GitHub-flavored Markdown support by default, meaning kramdown should have all the features of the two deprecated Markdown engines, so the transition should be as simple as updating the Markdown setting to &lt;code&gt;kramdown&lt;/code&gt; in your site&#39;s configuration (or removing it entirely).&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; Release assets from a public repository can be accessed by unauthenticated users in private mode. (updated 2016-05-27)&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring a protected branch archived whilst running 2.3, will not restore all the settings correctly. This does not affect new instances or protected branches archived on later releases.&lt;/li&gt;
&lt;li&gt;Duplicate uploads are stored in more than three hosts in a cluster with more than three replica file servers.&lt;/li&gt;
&lt;li&gt;Editing custom messages in the Admin Center doesn&#39;t provide emoji suggestions.&lt;/li&gt;
&lt;li&gt;Native emoji are lost when saving custom messages in the Admin Center.&lt;/li&gt;
&lt;li&gt;The custom messages setting within the Admin Center is not disabled when SAML authentication is used. The setting has no effect when using SAML as the SAML server is responsible for displaying the relevant pages to users.&lt;/li&gt;
&lt;li&gt;The custom messages Markdown editor in the Admin Center includes buttons for non-applicable functionality.&lt;/li&gt;
&lt;li&gt;Background jobs in the &lt;code&gt;languages&lt;/code&gt; queue aren&#39;t run. This causes repository language statistics to be inaccurate. (updated 2015-04-28)&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;find&lt;/code&gt; command isn&#39;t available in the &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/developer-workflow/creating-a-pre-receive-hook-environment/&quot;&gt;default pre-receive hook environment&lt;/a&gt;. (updated 2015-04-28)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/articles/viewing-push-logs/&quot;&gt;Repository push logs&lt;/a&gt; don&#39;t record whether a push was forced. (updated 2016-05-13)&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed. (updated 2016-05-24)&lt;/li&gt;
&lt;li&gt;Git LFS tracked files &lt;a href=&quot;https://github.com/blog/2105-upload-files-to-your-repositories&quot;&gt;uploaded through the web interface&lt;/a&gt; are incorrectly added directly to the repository. (updated 2016-05-24)&lt;/li&gt;
&lt;li&gt;Migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-06-09)&lt;/li&gt;
&lt;li&gt;GitHub Enterprise clustering can not be configured without https. (updated 2016-08-01)&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM. (updated 2016-08-03)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 26 Apr 2016 08:00:26 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.6.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.6.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.5.5</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A migration archive with @mentions in issues or comments that contain dashes were not correctly rewritten when imported on the destination appliance.&lt;/li&gt;
&lt;li&gt;User sessions were not properly revoked when they reached the expiry limit set by the SAML identity provider (IdP).&lt;/li&gt;
&lt;li&gt;User web browser sessions were revoked after 14 days of inactivity instead of 30 days.&lt;/li&gt;
&lt;li&gt;Initial checkouts using SVN could be slow.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The number of simultaneous connections tracked by the appliance firewall has been increased to 524288.&lt;/li&gt;
&lt;li&gt;Cluster mode now runs with more workers based on the amount of memory assigned to the node.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Resolved a cross-site scripting (XSS) vulnerability in task lists.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Implemented mitigation for a URI decoding vulnerability that affects modern versions of Microsoft Internet Explorer.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; Release assets from a public repository can be accessed by unauthenticated users in private mode. (updated 2016-05-27)&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;Duplicate uploads are stored in more than three hosts in a cluster with more than three replica file servers.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed. (updated 2016-05-24)&lt;/li&gt;
&lt;li&gt;Migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-06-09)&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM. (updated 2016-08-03)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 26 Apr 2016 08:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.5.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.5.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.4.8</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;User sessions were not properly revoked when they reached the expiry limit set by the SAML identity provider (IdP).&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Shell history is written after each command.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Resolved a cross-site scripting (XSS) vulnerability in task lists.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Implemented mitigation for a URI decoding vulnerability that affects modern versions of Microsoft Internet Explorer.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 26 Apr 2016 08:00:24 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.4.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.4.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.3.12</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;User sessions were not properly revoked when they reached the expiry limit set by the SAML identity provider (IdP).&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Shell history is written after each command.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Resolved a cross-site scripting (XSS) vulnerability in task lists.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Implemented mitigation for a URI decoding vulnerability that affects modern versions of Microsoft Internet Explorer.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Email can&#39;t be sent over TLS when SSL is disabled.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 26 Apr 2016 08:00:23 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.3.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.3.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.18</title>
					<description>&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Shell history is written after each command.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Resolved a cross-site scripting (XSS) vulnerability in task lists.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Implemented mitigation for a URI decoding vulnerability that affects modern versions of Microsoft Internet Explorer.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Organization invitation emails are sent from the configured support email address rather than the no-reply address.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 26 Apr 2016 08:00:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.2.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.1.23</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;OpenVM tools was not properly installed.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Shell history is written after each command.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Resolved a cross-site scripting (XSS) vulnerability in task lists.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Implemented mitigation for a URI decoding vulnerability that affects modern versions of Microsoft Internet Explorer.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Promoting a high availability replica can fail if Elasticsearch takes too long to restart.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &#39;Starting...&#39; instead.&lt;/li&gt;
&lt;li&gt;Some processes continued to write to logs after they were rotated. This could cause the root file system to fill up.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation disabled.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;Accessing GitHub Enterprise using a hostname alias with private mode enabled as an unauthenticated user will redirect you to the dashboard instead of the page you were trying to visit after you log in.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise 2.1&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.1 is now deprecated.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this release. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.6/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 26 Apr 2016 08:00:21 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.1.23</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.1.23</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.5.4</title>
					<description>&lt;h2&gt;Remote Code Execution in GitHub Enterprise &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/web-based-management-console/&quot;&gt;Management Console&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;An issue was identified that could allow an attacker to execute arbitrary commands on the GitHub Enterprise appliance. This vulnerability exists in the Management Console which is accessible from port 8080 and 8443. This is only applicable to GitHub Enterprise 2.5.0, 2.5.1, 2.5.2, and 2.5.3.&lt;/p&gt;
&lt;p&gt;We &lt;strong&gt;strongly&lt;/strong&gt; recommend you &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade&lt;/a&gt; your GitHub Enterprise appliance to GitHub Enterprise 2.5.4 immediately.&lt;/p&gt;
&lt;p&gt;This vulnerability was reported to our &lt;a href=&quot;https://bounty.github.com/&quot;&gt;GitHub Security Bug Bounty&lt;/a&gt; program and we have no evidence that it has been exploited in the wild.&lt;/p&gt;
&lt;p&gt;If you&#39;re unable to upgrade immediately, the issue can be mitigated by blocking traffic to port 8080 and 8443 from any untrusted IP addresses. If your GitHub Enterprise appliance is behind a firewall device, you can block inbound requests to port 8443 and 8080 and allow trusted IP addresses. Alternatively, you can do this directly in the appliance,&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;SSH&lt;/a&gt; to your GitHub Enterprise appliancee&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Block all traffic to ports 8080 and 8443&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo ufw insert 1 deny proto tcp from any to any port 8080,8443
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Allow a trusted IP address to access the Management Console by replacing &lt;code&gt;&amp;lt;IPADDRESS&amp;gt;&lt;/code&gt;&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo ufw insert 1 allow proto tcp from &amp;lt;IPADDRESS&amp;gt; to any port 8080,8443
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;To remove the mitigation on your appliance,&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;SSH to your GitHub Enterprise appliance&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Identify the numbered firewall rule to remove&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo ufw status numbered | grep &#39;8080,8443/tcp&#39; | grep DENY | head -n1
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Remove the firewall rule by replacing &lt;code&gt;&amp;lt;NUMBER&amp;gt;&lt;/code&gt;&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ sudo ufw delete &amp;lt;NUMBER&amp;gt;
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Run steps 2 and 3 until the firewall rules from step 2 are removed.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Please contact &lt;a href=&quot;https://enterprise.githubsupport.com/hc/en-us/requests/new&quot;&gt;GitHub Enterprise Support&lt;/a&gt; if you have any questions.&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; There was a remote code execution vulnerability through the Management Console.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Management Console email test could fail due to certificate validation errors. Emails sent from the GitHub application would still be successfully delivered.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Shell history is written after each command.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; Release assets from a public repository can be accessed by unauthenticated users in private mode. (updated 2016-05-27)&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;Duplicate uploads are stored in more than three hosts in a cluster with more than three replica file servers.&lt;/li&gt;
&lt;li&gt;User sessions are not properly revoked when they reach the expiry limit set by the SAML IdP.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed. (updated 2016-05-24)&lt;/li&gt;
&lt;li&gt;Migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-06-09)&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM. (updated 2016-08-03)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Thu, 31 Mar 2016 18:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.5.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.5.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.5.3</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Migrating wikis to the new repository layout could fail if the original migration was interrupted before completion.&lt;/li&gt;
&lt;li&gt;Custom certificate authority (CA) certificates were not maintained across upgrades with SSL disabled.&lt;/li&gt;
&lt;li&gt;Protected branches could be updated when making a Git force push against multiple identical branches.&lt;/li&gt;
&lt;li&gt;Forking a Gist failed with a 500 error.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-support-bundle&lt;/code&gt; could report harmless warning messages.&lt;/li&gt;
&lt;li&gt;GitHub Importer API endpoints were enabled but GitHub Enterprise doesn&#39;t support the Importer.&lt;/li&gt;
&lt;li&gt;A quota limit warning email could be incorrectly triggered when transferring repositories with Git LFS objects.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Automatic Update Checking and downloading now checks for feature releases.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Resolved a cross-site scripting (XSS) vulnerability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; The secure flag was not set for the &lt;code&gt;_gh_render&lt;/code&gt; cookie, potentially allowing the render cookie to be sent in plaintext HTTP requests. However, Enterprise sets the &lt;code&gt;Strict-Transport-Security&lt;/code&gt; header for modern browsers when SSL is enabled, which largely mitigates the issue.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; There is a remote code execution vulnerability through the Management Console, patched in &lt;a href=&quot;https://enterprise.github.com/releases/2.5.4&quot;&gt;GitHub Enterprise 2.5.4&lt;/a&gt;. (updated 2016-03-31)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; Release assets from a public repository can be accessed by unauthenticated users in private mode. (updated 2016-05-27)&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;Duplicate uploads are stored in more than three hosts in a cluster with more than three replica file servers.&lt;/li&gt;
&lt;li&gt;User sessions are not properly revoked when they reach the expiry limit set by the SAML IdP.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed. (updated 2016-05-24)&lt;/li&gt;
&lt;li&gt;Migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-06-09)&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM. (updated 2016-08-03)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 29 Mar 2016 18:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.5.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.5.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.4.7</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Migrating wikis to the new repository layout could fail if the original migration was interrupted before completion.&lt;/li&gt;
&lt;li&gt;Custom certificate authority (CA) certificates were not maintained across upgrades with SSL disabled.&lt;/li&gt;
&lt;li&gt;Protected branches could be updated when making a Git force push against multiple identical branches.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Automatic Update Checking and downloading now checks for feature releases.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Resolved a cross-site scripting (XSS) vulnerability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; The secure flag was not set for the &lt;code&gt;_gh_render&lt;/code&gt; cookie, potentially allowing the render cookie to be sent in plaintext HTTP requests. However, Enterprise sets the &lt;code&gt;Strict-Transport-Security&lt;/code&gt; header for modern browsers when SSL is enabled, which largely mitigates the issue.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;Automatic update checks fail to download the latest ESX package.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 29 Mar 2016 18:00:24 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.4.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.4.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.3.11</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Migrating wikis to the new repository layout could fail if the original migration was interrupted before completion.&lt;/li&gt;
&lt;li&gt;Custom certificate authority (CA) certificates were not maintained across upgrades with SSL disabled.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Resolved a cross-site scripting (XSS) vulnerability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; The secure flag was not set for the &lt;code&gt;_gh_render&lt;/code&gt; cookie, potentially allowing the render cookie to be sent in plaintext HTTP requests. However, Enterprise sets the &lt;code&gt;Strict-Transport-Security&lt;/code&gt; header for modern browsers when SSL is enabled, which largely mitigates the issue.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Email can&#39;t be sent over TLS when SSL is disabled.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 29 Mar 2016 18:00:23 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.3.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.3.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.17</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Migrating wikis to the new repository layout could fail if the original migration was interrupted before completion.&lt;/li&gt;
&lt;li&gt;Custom certificate authority (CA) certificates were not maintained across upgrades with SSL disabled.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Resolved a cross-site scripting (XSS) vulnerability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; The secure flag was not set for the &lt;code&gt;_gh_render&lt;/code&gt; cookie, potentially allowing the render cookie to be sent in plaintext HTTP requests. However, Enterprise sets the &lt;code&gt;Strict-Transport-Security&lt;/code&gt; header for modern browsers when SSL is enabled, which largely mitigates the issue.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Organization invitation emails are sent from the configured support email address rather than the no-reply address.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 29 Mar 2016 18:00:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.2.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.1.22</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Resolved a cross-site scripting (XSS) vulnerability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; The secure flag was not set for the &lt;code&gt;_gh_render&lt;/code&gt; cookie, potentially allowing the render cookie to be sent in plaintext HTTP requests. However, Enterprise sets the &lt;code&gt;Strict-Transport-Security&lt;/code&gt; header for modern browsers when SSL is enabled, which largely mitigates the issue.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Promoting a high availability replica can fail if Elasticsearch takes too long to restart.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &#39;Starting...&#39; instead.&lt;/li&gt;
&lt;li&gt;Some processes continued to write to logs after they were rotated. This could cause the root file system to fill up.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation disabled.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;Accessing GitHub Enterprise using a hostname alias with private mode enabled as an unauthenticated user will redirect you to the dashboard instead of the page you were trying to visit after you log in.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 29 Mar 2016 18:00:21 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.1.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.1.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.5.2</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Changing a public repository to private would cause Git operations to stop replicating to the high availability replica.&lt;/li&gt;
&lt;li&gt;Downloading a release asset from a private repository with the &lt;a href=&quot;https://developer.github.com/enterprise/2.5/v3/repos/releases/&quot;&gt;Releases API&lt;/a&gt; failed with an internal server error.&lt;/li&gt;
&lt;li&gt;Automatic update checks failed to locate an upgrade package.&lt;/li&gt;
&lt;li&gt;Upgrading to 2.5 could take a very long time on instances with a large number of assets, such as &lt;a href=&quot;https://docs.github.com/enterprise/2.5/user/articles/about-releases/&quot;&gt;release downloads&lt;/a&gt;, Git LFS objects, Avatars, and image attachments to wikis and issues.&lt;/li&gt;
&lt;li&gt;In cluster mode, restoring backups to the nodes of a cluster required &lt;code&gt;storage-server&lt;/code&gt; and &lt;code&gt;git-server&lt;/code&gt; roles to be on the same machine.&lt;/li&gt;
&lt;li&gt;Upgrading to 2.5 could fail during the transition of recently deleted Gists.&lt;/li&gt;
&lt;li&gt;Images in Issue comment emails would not be displayed if private mode is enabled.&lt;/li&gt;
&lt;li&gt;Replication conflicts could occur if cluster nodes are initialized in the wrong order.&lt;/li&gt;
&lt;li&gt;Cluster support bundles could fail to generate.&lt;/li&gt;
&lt;li&gt;Restoring Redis data from a backup could report a &amp;quot;LOADING: integer expression expected&amp;quot; error.&lt;/li&gt;
&lt;li&gt;Importing a migration archive using &lt;code&gt;gh-migrator&lt;/code&gt; with unresolved conflicts could fail with an &amp;quot;undefined method&amp;quot; error.&lt;/li&gt;
&lt;li&gt;The &lt;a href=&quot;https://developer.github.com/enterprise/2.5/v3/issues/events/&quot;&gt;Issues Events API&lt;/a&gt; returned the incorrect actor for an issue assignment event.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;High availability replication now runs with four workers. This will lead to quicker synchronization when initially starting replication and ongoing replication on very busy instances.&lt;/li&gt;
&lt;li&gt;The global Maximum Object Size advanced setting can now be set in the Admin Center.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; OpenSSL packages have been updated to address &lt;a href=&quot;http://www.ubuntu.com/usn/usn-2914-1/&quot;&gt;multiple vulnerabilities&lt;/a&gt;, including &lt;a href=&quot;https://www.openssl.org/news/vulnerabilities.html#2016-0800&quot;&gt;CVE-2016-0800&lt;/a&gt;, known as &lt;a href=&quot;https://www.drownattack.com/&quot;&gt;DROWN&lt;/a&gt;, which did not affect GitHub Enterprise.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Ruby on Rails packages have been updated to address &lt;a href=&quot;http://weblog.rubyonrails.org/2016/2/29/Rails-4-2-5-2-4-1-14-2-3-2-22-2-have-been-released/&quot;&gt;multiple vulnerabilities&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Implemented mitigation for a cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 (&lt;a href=&quot;http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0072&quot;&gt;CVE-2015-0072&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Implemented mitigation for a cross-site scripting (XSS) vulnerability where plain text or other content types could be parsed as HTML.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ca-certificates&lt;/code&gt; package has been updated to remove outdated certificate authority (CA) certificates. This update refreshes the included certificates and removes the SPI CA and CA certificates with 1024-bit RSA keys.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; There is a remote code execution vulnerability through the Management Console, patched in &lt;a href=&quot;https://enterprise.github.com/releases/2.5.4&quot;&gt;GitHub Enterprise 2.5.4&lt;/a&gt;. (updated 2016-03-31)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; Release assets from a public repository can be accessed by unauthenticated users in private mode. (updated 2016-05-27)&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;Duplicate uploads are stored in more than three hosts in a cluster with more than three replica file servers.&lt;/li&gt;
&lt;li&gt;A quota limit warning email can be incorrectly triggered when transferring repositories with Git LFS objects.&lt;/li&gt;
&lt;li&gt;User sessions are not properly revoked when they reach the expiry limit set by the SAML IdP.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed. (updated 2016-05-24)&lt;/li&gt;
&lt;li&gt;Migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-06-09)&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM. (updated 2016-08-03)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 15 Mar 2016 01:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.5.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.5.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.4.6</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Changing a public repository to private would cause Git operations to stop replicating to the high availability replica.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;High availability replication now runs with four workers. This will lead to quicker synchronization when initially starting replication and ongoing replication on very busy instances.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; OpenSSL packages have been updated to address &lt;a href=&quot;http://www.ubuntu.com/usn/usn-2914-1/&quot;&gt;multiple vulnerabilities&lt;/a&gt;, including &lt;a href=&quot;https://www.openssl.org/news/vulnerabilities.html#2016-0800&quot;&gt;CVE-2016-0800&lt;/a&gt;, known as &lt;a href=&quot;https://www.drownattack.com/&quot;&gt;DROWN&lt;/a&gt;, which did not affect GitHub Enterprise.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Ruby on Rails packages have been updated to address &lt;a href=&quot;http://weblog.rubyonrails.org/2016/2/29/Rails-4-2-5-2-4-1-14-2-3-2-22-2-have-been-released/&quot;&gt;multiple vulnerabilities&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Implemented mitigation for a cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 (&lt;a href=&quot;http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0072&quot;&gt;CVE-2015-0072&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Implemented mitigation for a cross-site scripting (XSS) vulnerability where plain text or other content types could be parsed as HTML.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ca-certificates&lt;/code&gt; package has been updated to remove outdated certificate authority (CA) certificates. This update refreshes the included certificates and removes the SPI CA and CA certificates with 1024-bit RSA keys.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 15 Mar 2016 01:00:24 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.4.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.4.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.3.10</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Changing a public repository to private would cause Git operations to stop replicating to the high availability replica.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; OpenSSL packages have been updated to address &lt;a href=&quot;http://www.ubuntu.com/usn/usn-2914-1/&quot;&gt;multiple vulnerabilities&lt;/a&gt;, including &lt;a href=&quot;https://www.openssl.org/news/vulnerabilities.html#2016-0800&quot;&gt;CVE-2016-0800&lt;/a&gt;, known as &lt;a href=&quot;https://www.drownattack.com/&quot;&gt;DROWN&lt;/a&gt;, which did not affect GitHub Enterprise.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Ruby on Rails packages have been updated to address &lt;a href=&quot;http://weblog.rubyonrails.org/2016/2/29/Rails-4-2-5-2-4-1-14-2-3-2-22-2-have-been-released/&quot;&gt;multiple vulnerabilities&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Implemented mitigation for a cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 (&lt;a href=&quot;http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0072&quot;&gt;CVE-2015-0072&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Implemented mitigation for a cross-site scripting (XSS) vulnerability where plain text or other content types could be parsed as HTML.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ca-certificates&lt;/code&gt; package has been updated to remove outdated certificate authority (CA) certificates. This update refreshes the included certificates and removes the SPI CA and CA certificates with 1024-bit RSA keys.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Email can&#39;t be sent over TLS when SSL is disabled.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 15 Mar 2016 01:00:23 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.3.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.3.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.16</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Changing a public repository to private would cause Git operations to stop replicating to the high availability replica.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; OpenSSL packages have been updated to address &lt;a href=&quot;http://www.ubuntu.com/usn/usn-2914-1/&quot;&gt;multiple vulnerabilities&lt;/a&gt;, including &lt;a href=&quot;https://www.openssl.org/news/vulnerabilities.html#2016-0800&quot;&gt;CVE-2016-0800&lt;/a&gt;, known as known as &lt;a href=&quot;https://www.drownattack.com/&quot;&gt;DROWN&lt;/a&gt;, which did not affect GitHub Enterprise.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Ruby on Rails packages have been updated to address &lt;a href=&quot;http://weblog.rubyonrails.org/2016/2/29/Rails-4-2-5-2-4-1-14-2-3-2-22-2-have-been-released/&quot;&gt;multiple vulnerabilities&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Implemented mitigation for a cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 (&lt;a href=&quot;http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0072&quot;&gt;CVE-2015-0072&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Implemented mitigation for a cross-site scripting (XSS) vulnerability where plain text or other content types could be parsed as HTML.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ca-certificates&lt;/code&gt; package has been updated to remove outdated certificate authority (CA) certificates. This update refreshes the included certificates and removes the SPI CA and CA certificates with 1024-bit RSA keys.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Organization invitation emails are sent from the configured support email address rather than the no-reply address.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 15 Mar 2016 01:00:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.2.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.1.21</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; OpenSSL packages have been updated to address &lt;a href=&quot;http://www.ubuntu.com/usn/usn-2914-1/&quot;&gt;multiple vulnerabilities&lt;/a&gt;, including &lt;a href=&quot;https://www.openssl.org/news/vulnerabilities.html#2016-0800&quot;&gt;CVE-2016-0800&lt;/a&gt;, known as known as &lt;a href=&quot;https://www.drownattack.com/&quot;&gt;DROWN&lt;/a&gt;, which did not affect GitHub Enterprise.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Ruby on Rails packages have been updated to address &lt;a href=&quot;http://weblog.rubyonrails.org/2016/2/29/Rails-4-2-5-2-4-1-14-2-3-2-22-2-have-been-released/&quot;&gt;multiple vulnerabilities&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Implemented mitigation for a cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 (&lt;a href=&quot;http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-0072&quot;&gt;CVE-2015-0072&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; Implemented mitigation for a cross-site scripting (XSS) vulnerability where plain text or other content types could be parsed as HTML.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ca-certificates&lt;/code&gt; package has been updated to remove outdated certificate authority (CA) certificates. This update refreshes the included certificates and removes the SPI CA and CA certificates with 1024-bit RSA keys.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Promoting a high availability replica can fail if Elasticsearch takes too long to restart.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &#39;Starting...&#39; instead.&lt;/li&gt;
&lt;li&gt;Some processes continued to write to logs after they were rotated. This could cause the root file system to fill up.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation disabled.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;Accessing GitHub Enterprise using a hostname alias with private mode enabled as an unauthenticated user will redirect you to the dashboard instead of the page you were trying to visit after you log in.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 15 Mar 2016 01:00:21 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.1.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.1.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.5.1</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Collectd log file was not rotated and could grow quite large.&lt;/li&gt;
&lt;li&gt;Duplicate Pages sites in &lt;em&gt;/data/user/pages&lt;/em&gt; differing only by case could cause an upgrade to fail. This may occur if a background job for a rename or deletion had failed on a previous Enterprise release.&lt;/li&gt;
&lt;li&gt;The Audit Log map could fail to render correctly.&lt;/li&gt;
&lt;li&gt;The Audit Log dashboard could fail to load.&lt;/li&gt;
&lt;li&gt;Periodic LDAP user and group memberships synchronization jobs did not run automatically.&lt;/li&gt;
&lt;li&gt;LDAP Sync didn&#39;t remove a user that was no longer a member of an LDAP group.&lt;/li&gt;
&lt;li&gt;LDAP authentication attempted bind multiple times using the same credentials. If these credentials are incorrect, this could cause accounts to be locked on the LDAP server.&lt;/li&gt;
&lt;li&gt;Incorrect permissions on &lt;code&gt;/data/repositories/info/svn-v4-upgraded&lt;/code&gt; could cause restores to fail.&lt;/li&gt;
&lt;li&gt;Saving settings in the management console could overwrite the SAML Issuer with the value of the SAML certificate issuer, causing authentication to fail.&lt;/li&gt;
&lt;li&gt;Upgrading directly from any 2.3 release to 2.5.0 could result in the removal of all personal access tokens.&lt;/li&gt;
&lt;li&gt;Repository disk usage could be incorrectly calculated in the site admin.&lt;/li&gt;
&lt;li&gt;If Git LFS was globally disabled prior to upgrading, manual configuration was required to re-enabled it.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-check-disk-usage&lt;/code&gt; could fail to display filesystem information.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-cluster-status&lt;/code&gt; could exit early without printing the status of all nodes in the cluster.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; &lt;code&gt;glibc&lt;/code&gt; packages have been updated to address &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7547&quot;&gt;CVE-2015-7547&lt;/a&gt;, a &lt;code&gt;getaddrinfo&lt;/code&gt; stack-based buffer overflow.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; &lt;code&gt;libssh&lt;/code&gt; packages have been updated to address &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0739&quot;&gt;CVE-2016-0739&lt;/a&gt;, a weakness in diffie-hellman secret key generation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; &lt;code&gt;nss&lt;/code&gt; packages have been updated to address &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1938&quot;&gt;CVE-2016-1938&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; There is a remote code execution vulnerability through the Management Console, patched in &lt;a href=&quot;https://enterprise.github.com/releases/2.5.4&quot;&gt;GitHub Enterprise 2.5.4&lt;/a&gt;. (updated 2016-03-31)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; Release assets from a public repository can be accessed by unauthenticated users in private mode. (updated 2016-05-27)&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;li&gt;Duplicate uploads are stored in more than three hosts in a cluster with more than three replica file servers.&lt;/li&gt;
&lt;li&gt;In cluster mode, restoring backups to the nodes of a cluster require &lt;code&gt;storage-server&lt;/code&gt; and &lt;code&gt;git-server&lt;/code&gt; roles to be on the same machine.&lt;/li&gt;
&lt;li&gt;Downloading a release asset from a private repository with the &lt;a href=&quot;https://developer.github.com/enterprise/2.5/v3/repos/releases/&quot;&gt;Releases API&lt;/a&gt; fails with an internal server error. (updated 2016-02-23)&lt;/li&gt;
&lt;li&gt;Automatic update checks fail to locate an upgrade package.&lt;/li&gt;
&lt;li&gt;User sessions are not properly revoked when they reach the expiry limit set by the SAML IdP.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed. (updated 2016-05-24)&lt;/li&gt;
&lt;li&gt;Migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-06-09)&lt;/li&gt;
&lt;li&gt;Console text is difficult to read on OpenStack KVM. (updated 2016-08-03)&lt;/li&gt;
&lt;li&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/li&gt;
&lt;li&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 23 Feb 2016 12:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.5.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.5.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.4.5</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Collectd log file was not rotated and could grow quite large.&lt;/li&gt;
&lt;li&gt;Duplicate Pages sites in &lt;em&gt;/data/user/pages&lt;/em&gt; differing only by case could cause an upgrade to fail. This may occur if a background job for a rename or deletion had failed on a previous Enterprise release.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; &lt;code&gt;glibc&lt;/code&gt; packages have been updated to address &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7547&quot;&gt;CVE-2015-7547&lt;/a&gt;, a &lt;code&gt;getaddrinfo&lt;/code&gt; stack-based buffer overflow.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; &lt;code&gt;libssh&lt;/code&gt; packages have been updated to address &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0739&quot;&gt;CVE-2016-0739&lt;/a&gt;, a weakness in diffie-hellman secret key generation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; &lt;code&gt;nss&lt;/code&gt; packages have been updated to address &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1938&quot;&gt;CVE-2016-1938&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails.&lt;/li&gt;
&lt;li&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 23 Feb 2016 12:00:20 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.4.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.4.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.3.9</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; &lt;code&gt;glibc&lt;/code&gt; packages have been updated to address &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7547&quot;&gt;CVE-2015-7547&lt;/a&gt;, a &lt;code&gt;getaddrinfo&lt;/code&gt; stack-based buffer overflow.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; &lt;code&gt;libssh&lt;/code&gt; packages have been updated to address &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0739&quot;&gt;CVE-2016-0739&lt;/a&gt;, a weakness in diffie-hellman secret key generation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; &lt;code&gt;nss&lt;/code&gt; packages have been updated to address &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1938&quot;&gt;CVE-2016-1938&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Email can&#39;t be sent over TLS when SSL is disabled.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 23 Feb 2016 12:00:15 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.3.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.3.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.15</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; &lt;code&gt;glibc&lt;/code&gt; packages have been updated to address &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7547&quot;&gt;CVE-2015-7547&lt;/a&gt;, a &lt;code&gt;getaddrinfo&lt;/code&gt; stack-based buffer overflow.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; &lt;code&gt;libssh&lt;/code&gt; packages have been updated to address &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0739&quot;&gt;CVE-2016-0739&lt;/a&gt;, a weakness in diffie-hellman secret key generation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; &lt;code&gt;nss&lt;/code&gt; packages have been updated to address &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1938&quot;&gt;CVE-2016-1938&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Organization invitation emails are sent from the configured support email address rather than the no-reply address.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 23 Feb 2016 12:00:10 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.2.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.1.20</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; &lt;code&gt;glibc&lt;/code&gt; packages have been updated to address &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-7547&quot;&gt;CVE-2015-7547&lt;/a&gt;, a &lt;code&gt;getaddrinfo&lt;/code&gt; stack-based buffer overflow.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; &lt;code&gt;libssh&lt;/code&gt; packages have been updated to address &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0739&quot;&gt;CVE-2016-0739&lt;/a&gt;, a weakness in diffie-hellman secret key generation.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt; &lt;code&gt;nss&lt;/code&gt; packages have been updated to address &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-1938&quot;&gt;CVE-2016-1938&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Promoting a high availability replica can fail if Elasticsearch takes too long to restart.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &#39;Starting...&#39; instead.&lt;/li&gt;
&lt;li&gt;Some processes continued to write to logs after they were rotated. This could cause the root file system to fill up.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation disabled.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;Accessing GitHub Enterprise using a hostname alias with private mode enabled as an unauthenticated user will redirect you to the dashboard instead of the page you were trying to visit after you log in.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 23 Feb 2016 12:00:05 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.1.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.1.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.5.0</title>
					<description>&lt;h2&gt;New Features&lt;/h2&gt;
&lt;p&gt;With the new features added in GitHub Enterprise 2.5.0, you can:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Increase scalability with GitHub Clustering.&lt;/li&gt;
&lt;li&gt;Configure Advanced Settings in the new Admin Center.&lt;/li&gt;
&lt;li&gt;Configure Protected Branches using the &lt;a href=&quot;https://developer.github.com/enterprise/2.5/v3/repos/#enabling-and-disabling-branch-protection&quot;&gt;preview API&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Enjoy &lt;a href=&quot;https://github.com/blog/2085-a-new-look-for-repositories&quot;&gt;a new look for repositories&lt;/a&gt; and a simplified sign-up and sign-in flow.&lt;/li&gt;
&lt;li&gt;Take full advantage of SVN &lt;a href=&quot;https://subversion.apache.org/docs/release-notes/1.8.html&quot;&gt;1.8&lt;/a&gt; and &lt;a href=&quot;https://subversion.apache.org/docs/release-notes/1.9.html&quot;&gt;1.9&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Be more resilient to the specific problem of a lot of clients fetching the same data at almost the same time.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Wikis are only editable by collaborators by default.&lt;/li&gt;
&lt;li&gt;Markdown can now be used in the announcement banner.&lt;/li&gt;
&lt;li&gt;Pushes that attempt to delete a repository&#39;s default branch are rejected.&lt;/li&gt;
&lt;li&gt;LDAP Sync now gracefully handles user DN changes.&lt;/li&gt;
&lt;li&gt;Git LFS is enabled on all repositories by default.&lt;/li&gt;
&lt;li&gt;The search index definitions have changed. Some searches will return partial results while the search indices are rebuilt. (updated 2016-02-18)&lt;/li&gt;
&lt;li&gt;The SAML authentication flow has been tightened to better conform to the SAML specification. This means all responses from your SAML server for SP-initiated authentication must include the &lt;code&gt;RelayState&lt;/code&gt; parameter as sent from the appliance. For IdP-initiated authentication you must ensure the &amp;quot;IdP initiated SSO (disables AuthnRequest)&amp;quot; setting is checked within the management console. You may experience a redirect loop between your appliance and your SAML server if either of these conditions are not met. (updated 2016-02-29)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upgrading&lt;/h2&gt;
&lt;p&gt;Upgrading to the 2.5 release series is supported from GitHub Enterprise 2.3.0 and above.&lt;/p&gt;
&lt;h2&gt;Backup &amp;amp; Restore&lt;/h2&gt;
&lt;p&gt;In order to backup and restore GitHub Enterprise 2.5, you will need to upgrade &lt;a href=&quot;https://github.com/github/backup-utils&quot;&gt;backup-utils&lt;/a&gt; to version 2.5.0.&lt;/p&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repository maintenance was not run on the high availability replica. This could lead to high load while repositories were repacked when first promoting the replica.&lt;/li&gt;
&lt;li&gt;Accessing the raw URL for a file named &#39;policies&#39; would fail with a 404 error.&lt;/li&gt;
&lt;li&gt;Downloading the diagnostics via the Management Console could time out on instances with many release or Git LFS assets.&lt;/li&gt;
&lt;li&gt;We tried to log timing statistics to an inaccessible statsd server when downloading release assets.&lt;/li&gt;
&lt;li&gt;Repository milestones weren&#39;t updated on repositories migrated from GitHub.com.&lt;/li&gt;
&lt;li&gt;Viewing the Pages section in admin tools would cause a 500 error if no Pages site existed.&lt;/li&gt;
&lt;li&gt;Incorrect permissions could be set on certificate authority certificates installed with &lt;code&gt;ghe-ssl-ca-certificate-install&lt;/code&gt;. This could cause webhooks to fail as the certificates could not be read.&lt;/li&gt;
&lt;li&gt;Backups could fail to restore if a previous Pages migration had failed on the destination appliance.&lt;/li&gt;
&lt;li&gt;The incorrect Pages domain was shown in Pages section of a repository in Admin Tools.&lt;/li&gt;
&lt;li&gt;Two-factor authentication screens and emails would refer to using SMS fallback recovery.&lt;/li&gt;
&lt;li&gt;The management console settings interface didn&#39;t clearly show if you have previously uploaded certificate files or a private key. (updated 2016-02-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; OpenSSH packages have been updated to address multiple vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; An integer overflow in Git could result in incorrect memory allocation values (&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2315&quot;&gt;CVE-2016-2315&lt;/a&gt;, &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2324&quot;&gt;CVE-2016-2324&lt;/a&gt;). (updated 2016-03-17)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; libxml2 and related packages have been updated to address multiple vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; rsync has been updated to address a recently identified vulnerability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; Passwords and two-factor authentication one-time passwords could be written to the exceptions log.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Git LFS Client Vulnerability&lt;/h2&gt;
&lt;p&gt;An issue was identified that could allow an attacker to execute arbitrary commands on a user’s computer if they had Git LFS installed and cloned a malicious repository. Git LFS supports a per-repository configuration file to customize how certain aspects of Git LFS function. However, this file also allowed arbitrary Git configuration options to be modified. We have addressed the vulnerability by whitelisting the set of per-repository Git LFS configuration options that can be used to a safe subset.&lt;/p&gt;
&lt;p&gt;GitHub Enterprise is not directly affected as this is a client-side vulnerability but as Git LFS is now enabled by default, we recommend you upgrade your clients to Git LFS 1.0.1 or later to address this vulnerability.&lt;/p&gt;
&lt;h2&gt;Asset storage changes (updated 2016-02-24)&lt;/h2&gt;
&lt;p&gt;To prepare for GitHub Clustering, this release changes the way GitHub Enterprise stores assets, such as &lt;a href=&quot;https://docs.github.com/enterprise/2.5/user/articles/about-releases/&quot;&gt;release downloads&lt;/a&gt;, Git LFS objects, Avatars, and image attachments to wikis and issues. On instalations with many large assets, moving assets to their new location can take a long time. As always, we encourage you to test the upgrade in a staging environment before upgrading your production instance.&lt;/p&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise 2.0&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.0 is now deprecated.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this release. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.1&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.1 will be deprecated as of April 4, 2016.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Deprecation of Support for Internet Explorer 9 and 10&lt;/h2&gt;
&lt;p&gt;Support for Internet Explorer 9 and 10 will be deprecated in a future release. There will be no changes in site functionality, but a warning banner will be displayed to Internet Explorer 9 and 10 users.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt; There is a remote code execution vulnerability through the Management Console, patched in &lt;a href=&quot;https://enterprise.github.com/releases/2.5.4&quot;&gt;GitHub Enterprise 2.5.4&lt;/a&gt;. (updated 2016-03-31)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;HIGH&lt;/strong&gt; Release assets from a public repository can be accessed by unauthenticated users in private mode. (updated 2016-05-27)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Saving settings in the management console can overwrite the SAML Issuer with the value of the SAML certificate issuer, causing authentication to fail. The SAML Issuer must be set manually each time any settings are saved if a certificate has been uploaded. (updated 2016-02-12)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;del&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/del&gt; (updated 2016-02-10)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;If Git LFS was globally disabled prior to upgrading, manual configuration may be required to re-enabled it.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Upgrading directly from any 2.3 release to 2.5.0 can result in the removal of all personal access tokens. This can be prevented by upgrading to any 2.4 release first. (updated 2016-02-15)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;HIGH (CVE-2015-7547)&lt;/strong&gt; 2.5.0 is vulnerable to &lt;code&gt;glibc getaddrinfo stack-based buffer overflow&lt;/code&gt;. To manually patch your appliance, apply the hotfix by &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;connecting to your appliance via SSH&lt;/a&gt; and running these commands: (updated 2016-02-17)&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ curl -O https://github-enterprise.s3.amazonaws.com/patches/github-enterprise-libc-trusty.hpkg
$ md5sum github-enterprise-libc-trusty.hpkg # 9deaf87e3313e9239e42179b78cd024a
$ chmod +x github-enterprise-libc-trusty.hpkg
$ ./github-enterprise-libc-trusty.hpkg
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Periodic LDAP user and group memberships synchronization jobs do not run automatically. Synchronization can still be &lt;a href=&quot;https://docs.github.com/enterprise/2.5/admin/guides/user-management/using-ldap/#manually-syncing-ldap-accounts&quot;&gt;triggered manually&lt;/a&gt;. (updated 2016-02-18)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Downloading a release asset from a private repository with the &lt;a href=&quot;https://developer.github.com/enterprise/2.5/v3/repos/releases/&quot;&gt;Releases API&lt;/a&gt; fails with an internal server error. (updated 2016-02-23)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Automatic update checks fail to locate an upgrade package.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;User sessions are not properly revoked when they reach the expiry limit set by the SAML IdP.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;code&gt;svn checkout&lt;/code&gt; may timeout while the repository data cache is being built. In most cases, subsequent &lt;code&gt;svn checkout&lt;/code&gt; attempts will succeed. (updated 2016-05-24)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Migration data exported from GitHub Enterprise with &lt;code&gt;ghe-migrator&lt;/code&gt; does not include issue file attachments, which may cause imports to another server to fail. (updated 2016-06-09)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Console text is difficult to read on OpenStack KVM. (updated 2016-08-03)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The initial import of the VMware OVA image may fail when deployed via vCenter Server 6.0 or 6.5. The import will succeed when performed directly on an ESXi host. (updated 2017-02-23)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Git LFS objects may take up to an hour to replicate in a High Availability configuration. (updated 2017-02-23)&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The management console displays a summary of any previously uploaded certificate and private key files as of 2.5.0. (updated 2016-02-10)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 09 Feb 2016 18:00:25 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.5.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.5.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.4.4</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repository maintenance was not run on the high availability replica. This could lead to high load while repositories were repacked when first promoting the replica.&lt;/li&gt;
&lt;li&gt;Accessing the raw URL for a file named &#39;policies&#39; would fail with a 404 error.&lt;/li&gt;
&lt;li&gt;Downloading the diagnostics via the Management Console could time out on instances with many release or Git LFS assets.&lt;/li&gt;
&lt;li&gt;We tried to log timing statistics to an inaccessible statsd server when downloading release assets.&lt;/li&gt;
&lt;li&gt;Repository milestones weren&#39;t updated on repositories migrated from GitHub.com.&lt;/li&gt;
&lt;li&gt;Viewing the Pages section in admin tools would cause a 500 error if no Pages site existed.&lt;/li&gt;
&lt;li&gt;Incorrect permissions could be set on certificate authority certificates installed with &lt;code&gt;ghe-ssl-ca-certificate-install&lt;/code&gt;. This could cause webhooks to fail as the certificates could not be read.&lt;/li&gt;
&lt;li&gt;Backups could fail to restore if a previous Pages migration had failed on the destination appliance.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; OpenSSH packages have been updated to address multiple vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; libxml2 and related packages have been updated to address multiple vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; rsync has been updated to address a recently identified vulnerability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; Passwords and two-factor authentication one-time passwords could be written to the exceptions log.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On instances upgraded from 2.3 and earlier, restoring an archived protected branch will not restore all the settings correctly. This does not affect new instances.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;HIGH (CVE-2015-7547)&lt;/strong&gt; 2.4 is vulnerable to &lt;code&gt;glibc getaddrinfo stack-based buffer overflow&lt;/code&gt;. To manually patch your appliance, apply the hotfix by &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;connecting to your appliance via SSH&lt;/a&gt; and running these commands: (updated 2016-02-17)&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ curl -O https://github-enterprise.s3.amazonaws.com/patches/github-enterprise-libc-precise.hpkg
$ md5sum github-enterprise-libc-precise.hpkg # c068256696f2775579e2cd8223f82306
$ chmod +x github-enterprise-libc-precise.hpkg
$ ./github-enterprise-libc-precise.hpkg
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 09 Feb 2016 18:00:20 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.4.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.4.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.3.8</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repository maintenance was not run on the high availability replica. This could lead to high load while repositories were repacked when first promoting the replica.&lt;/li&gt;
&lt;li&gt;Accessing the raw URL for a file named &#39;policies&#39; would fail with a 404 error.&lt;/li&gt;
&lt;li&gt;Downloading the diagnostics via the Management Console could time out on instances with many release or Git LFS assets.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; OpenSSH packages have been updated to address multiple vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; libxml2 and related packages have been updated to address multiple vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; rsync has been updated to address a recently identified vulnerability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; Passwords and two-factor authentication one-time passwords could be written to the exceptions log.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Email can&#39;t be sent over TLS when SSL is disabled.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Management console sessions can expire too quickly for Safari users.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;HIGH (CVE-2015-7547)&lt;/strong&gt; 2.3 is vulnerable to &lt;code&gt;glibc getaddrinfo stack-based buffer overflow&lt;/code&gt;. To manually patch your appliance, apply the hotfix by &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;connecting to your appliance via SSH&lt;/a&gt; and running these commands: (updated 2016-02-17)&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ curl -O https://github-enterprise.s3.amazonaws.com/patches/github-enterprise-libc-precise.hpkg
$ md5sum github-enterprise-libc-precise.hpkg # c068256696f2775579e2cd8223f82306
$ chmod +x github-enterprise-libc-precise.hpkg
$ ./github-enterprise-libc-precise.hpkg
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 09 Feb 2016 18:00:15 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.3.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.3.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.14</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repository maintenance was not run on the high availability replica. This could lead to high load while repositories were repacked when first promoting the replica.&lt;/li&gt;
&lt;li&gt;Accessing the raw URL for a file named &#39;policies&#39; would fail with a 404 error.&lt;/li&gt;
&lt;li&gt;Downloading the diagnostics via the Management Console could time out on instances with many release or Git LFS assets.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; OpenSSH packages have been updated to address multiple vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; libxml2 and related packages have been updated to address multiple vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; rsync has been updated to address a recently identified vulnerability.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; Passwords and two-factor one-time passwords could be written to the exceptions log.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Organization invitation emails are sent from the configured support email address rather than the no-reply address.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Management console sessions can expire too quickly for Safari users.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Replication setup fails for IPv6 hosts.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;HIGH (CVE-2015-7547)&lt;/strong&gt; 2.2 is vulnerable to &lt;code&gt;glibc getaddrinfo stack-based buffer overflow&lt;/code&gt;. To manually patch your appliance, apply the hotfix by &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;connecting to your appliance via SSH&lt;/a&gt; and running these commands: (updated 2016-02-17)&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ curl -O https://github-enterprise.s3.amazonaws.com/patches/github-enterprise-libc-precise.hpkg
$ md5sum github-enterprise-libc-precise.hpkg # c068256696f2775579e2cd8223f82306
$ chmod +x github-enterprise-libc-precise.hpkg
$ ./github-enterprise-libc-precise.hpkg
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 09 Feb 2016 18:00:10 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.2.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.1.19</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; OpenSSH packages have been updated to address multiple vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; libxml2 and related packages have been updated to address multiple vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; rsync has been updated to address a recently identified vulnerability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; Passwords and two-factor one-time passwords could be written to the exceptions log.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Management console sessions can expire too quickly for Safari users.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Promoting a high availability replica can fail if Elasticsearch takes too long to restart.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &#39;Starting...&#39; instead.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Some processes continued to write to logs after they were rotated. This could cause the root file system to fill up.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation disabled.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;SNMP can&#39;t be run on high availability replicas.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Accessing GitHub Enterprise using a hostname alias with private mode enabled as an unauthenticated user will redirect you to the dashboard instead of the page you were trying to visit after you log in.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;HIGH (CVE-2015-7547)&lt;/strong&gt; 2.1 is vulnerable to &lt;code&gt;glibc getaddrinfo stack-based buffer overflow&lt;/code&gt;. To manually patch your appliance, apply the hotfix by &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/administrative-shell-ssh-access/&quot;&gt;connecting to your appliance via SSH&lt;/a&gt; and running these commands: (updated 2016-02-17)&lt;/p&gt;
&lt;pre lang=&quot;bash&quot;&gt;&lt;code&gt;$ curl -O https://github-enterprise.s3.amazonaws.com/patches/github-enterprise-libc-precise.hpkg
$ md5sum github-enterprise-libc-precise.hpkg # c068256696f2775579e2cd8223f82306
$ chmod +x github-enterprise-libc-precise.hpkg
$ ./github-enterprise-libc-precise.hpkg
&lt;/code&gt;&lt;/pre&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.1&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.1 will be deprecated as of April 4, 2016.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 09 Feb 2016 18:00:05 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.1.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.1.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.0.23</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; OpenSSH packages have been updated to address multiple vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; libxml2 and related packages have been updated to address multiple vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; rsync has been updated to address a recently identified vulnerability.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; Passwords and two-factor one-time passwords could be written to the exceptions log.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are logged twice.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Deprecation of GitHub Enterprise 2.0&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.0 is now deprecated.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this release. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 09 Feb 2016 18:00:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.0.23</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.0.23</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.4.3</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;High availability replication could fail to automatically start after a reboot.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; failed with a 400 error.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again showed the &#39;Starting...&#39;&#39; page instead of the replica status page following a reboot.&lt;/li&gt;
&lt;li&gt;Starting high availability replication printed verbose MySQL status information.&lt;/li&gt;
&lt;li&gt;The connection limit for the longpoll service (used for providing live updates to Issues and Pull Requests) could be exhausted on very busy appliances.&lt;/li&gt;
&lt;li&gt;A team membership invitation email was incorrectly sent to the user when they were added to an Organization&#39;s team using the Add team membership API.&lt;/li&gt;
&lt;li&gt;Git LFS server maintenance jobs could fail to run and throw an exception error.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;X11Forwarding for administrative SSH connections is now disabled.&lt;/li&gt;
&lt;li&gt;The management console now displays a warning when the appliance time is significantly different from the time reported by the browser. This large time different can lead to management console sessions expiring too quickly.&lt;/li&gt;
&lt;li&gt;The LDAP authorization state is now included in the user suspension reason within the LDAP logs. This will help administrators determine why a LDAP user has been suspended.&lt;/li&gt;
&lt;li&gt;Legacy organization admin teams, those teams with &#39;admin&#39; permissions before GitHub Enterprise 2.4.0, are now clearly shown in the organization teams page.&lt;/li&gt;
&lt;li&gt;Management console sessions could expire too quickly for Safari users.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; An integer overflow in Git could result in incorrect memory allocation values (&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2315&quot;&gt;CVE-2016-2315&lt;/a&gt;, &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2324&quot;&gt;CVE-2016-2324&lt;/a&gt;). (updated 2016-03-17)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; libxml2 and related packages have been updated to address multiple vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; OpenSSL packages have been updated to address multiple vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; Auto-completion within several fields of the management console settings could cause SNMP and LDAP secrets to be logged in plaintext.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Git LFS Client Vulnerability&lt;/h2&gt;
&lt;p&gt;An issue has been identified that could allow an attacker to execute arbitrary commands on a user’s computer if they had Git LFS installed and cloned a malicious repository. Git LFS supports a per-repository configuration file to customize how certain aspects of Git LFS function. However, this file also allowed arbitrary Git configuration options to be modified. We have addressed the vulnerability by whitelisting the set of per-repository Git LFS configuration options that can be used to a safe subset.&lt;/p&gt;
&lt;p&gt;GitHub Enterprise is not directly affected as this is a client-side vulnerability and Git LFS is disabled on GitHub Enterprise by default.  If you have enabled Git LFS on your appliance, we recommend you upgrade your clients to Git LFS 1.0.1 or later to address this vulnerability.&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 15 Dec 2015 00:00:24 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.4.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.4.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.3.7</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;High availability replication could fail to automatically start after a reboot.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; An integer overflow in Git could result in incorrect memory allocation values (&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2315&quot;&gt;CVE-2016-2315&lt;/a&gt;, &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2324&quot;&gt;CVE-2016-2324&lt;/a&gt;). (updated 2016-03-17)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; libxml2 and related packages have been updated to address multiple vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; OpenSSL packages have been updated to address multiple vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; Auto-completion within several fields of the management console settings could cause SNMP and LDAP secrets to be logged in plaintext.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Email can&#39;t be sent over TLS when SSL is disabled.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Git LFS Client Vulnerability&lt;/h2&gt;
&lt;p&gt;An issue has been identified that could allow an attacker to execute arbitrary commands on a user’s computer if they had Git LFS installed and cloned a malicious repository. Git LFS supports a per-repository configuration file to customize how certain aspects of Git LFS function. However, this file also allowed arbitrary Git configuration options to be modified. We have addressed the vulnerability by whitelisting the set of per-repository Git LFS configuration options that can be used to a safe subset.&lt;/p&gt;
&lt;p&gt;GitHub Enterprise is not directly affected as this is a client-side vulnerability and Git LFS is disabled on GitHub Enterprise by default.  If you have enabled Git LFS on your appliance, we recommend you upgrade your clients to Git LFS 1.0.1 or later to address this vulnerability.&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 15 Dec 2015 00:00:23 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.3.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.3.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.13</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; An integer overflow in Git could result in incorrect memory allocation values (&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2315&quot;&gt;CVE-2016-2315&lt;/a&gt;, &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2324&quot;&gt;CVE-2016-2324&lt;/a&gt;). (updated 2016-03-17)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; libxml2 and related packages have been updated to address multiple vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; OpenSSL packages have been updated to address multiple vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; Auto-completion within several fields of the management console settings could cause SNMP and LDAP secrets to be logged in plaintext.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Organization invitation emails are sent from the configured support email address rather than the no-reply address.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Git LFS Client Vulnerability&lt;/h2&gt;
&lt;p&gt;An issue has been identified that could allow an attacker to execute arbitrary commands on a user’s computer if they had Git LFS installed and cloned a malicious repository. Git LFS supports a per-repository configuration file to customize how certain aspects of Git LFS function. However, this file also allowed arbitrary Git configuration options to be modified. We have addressed the vulnerability by whitelisting the set of per-repository Git LFS configuration options that can be used to a safe subset.&lt;/p&gt;
&lt;p&gt;GitHub Enterprise is not directly affected as this is a client-side vulnerability and Git LFS is disabled on GitHub Enterprise by default.  If you have enabled Git LFS on your appliance, we recommend you upgrade your clients to Git LFS 1.0.1 or later to address this vulnerability.&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 15 Dec 2015 00:00:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.2.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.1.18</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; An integer overflow in Git could result in incorrect memory allocation values (&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2315&quot;&gt;CVE-2016-2315&lt;/a&gt;, &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2324&quot;&gt;CVE-2016-2324&lt;/a&gt;). (updated 2016-03-17)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; libxml2 and related packages have been updated to address multiple vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; OpenSSL packages have been updated to address multiple vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; Auto-completion within several fields of the management console settings could cause SNMP and LDAP secrets to be logged in plaintext.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Promoting a high availability replica can fail if Elasticsearch takes too long to restart.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &#39;Starting...&#39; instead.&lt;/li&gt;
&lt;li&gt;Some processes continued to write to logs after they were rotated. This could cause the root file system to fill up.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation disabled.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;Accessing GitHub Enterprise using a hostname alias with private mode enabled as an unauthenticated user will redirect you to the dashboard instead of the page you were trying to visit after you log in.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 15 Dec 2015 00:00:21 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.1.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.1.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.0.22</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; An integer overflow in Git could result in incorrect memory allocation values (&lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2315&quot;&gt;CVE-2016-2315&lt;/a&gt;, &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2324&quot;&gt;CVE-2016-2324&lt;/a&gt;). (updated 2016-03-17)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; OpenSSL packages have been updated to address multiple vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; Auto-completion within several fields of the management console settings could cause SNMP and LDAP secrets to be logged in plaintext.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are logged twice.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.0&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.0 will be deprecated as of January 1, 2016.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 15 Dec 2015 00:00:20 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.0.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.0.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.4.2</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Running the &lt;code&gt;ghe-diagnostics&lt;/code&gt; command line utility would report a harmless permission denied error.&lt;/li&gt;
&lt;li&gt;The &#39;Enable sign-up&#39; option was displayed in the Management Console when external authentication was configured. Account creation is controlled by your external authentication, so the setting had no effect.&lt;/li&gt;
&lt;li&gt;Old builds of GitHub Pages sites weren&#39;t garbage collected, so they could build up and waste disk space.&lt;/li&gt;
&lt;li&gt;An administrative SSH key was accidentally created and added to the Management Console.&lt;/li&gt;
&lt;li&gt;Alambic and Pages high availability replication reported &#39;UNKNOWN&#39; status for delays less than 30 seconds.&lt;/li&gt;
&lt;li&gt;High availability replication sometimes failed to set the correct master identifier during an upgrade. This prevented MySQL replication from starting.&lt;/li&gt;
&lt;li&gt;Restoring backups taken from previous versions to GitHub Enterprise 2.4 would fail.&lt;/li&gt;
&lt;li&gt;Deleting an impersonation OAuth token via the API would fail.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;An Organization&#39;s event log now reports changes to the default permissions and who made the changes.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 01 Dec 2015 12:00:24 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.4.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.4.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.3.6</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Deleting an impersonation OAuth token via the API would fail.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Email can&#39;t be sent over TLS when SSL is disabled.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 01 Dec 2015 12:00:23 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.3.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.3.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.12</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Organization invitation emails are sent from the configured support email address rather than the no-reply address.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 01 Dec 2015 12:00:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.2.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.1.17</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Promoting a high availability replica can fail if Elasticsearch takes too long to restart.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &#39;Starting...&#39; instead.&lt;/li&gt;
&lt;li&gt;Some processes continued to write to logs after they were rotated. This could cause the root file system to fill up.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation disabled.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;Accessing GitHub Enterprise using a hostname alias with private mode enabled as an unauthenticated user will redirect you to the dashboard instead of the page you were trying to visit after you log in.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 01 Dec 2015 12:00:21 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.1.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.1.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.0.21</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are logged twice.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.0&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.0 will be deprecated as of January 1, 2016.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 01 Dec 2015 12:00:20 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.0.21</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.0.21</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.4.1</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The high availability replication status as reported by &lt;code&gt;ghe-repl-status&lt;/code&gt; would not report a failure if ElasticSearch was not running.&lt;/li&gt;
&lt;li&gt;The temporary support bundle archive wasn&#39;t removed after a successful upload.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-upgrade&lt;/code&gt; would fail with a GPG signature error if run as the root user.&lt;/li&gt;
&lt;li&gt;High availability replication sometimes failed to set the MySQL password correctly which prevented MySQL replication from starting.&lt;/li&gt;
&lt;li&gt;Non-push events for Organization webhooks failed to be recorded in the &#39;Recent Deliveries&#39; list.&lt;/li&gt;
&lt;li&gt;A configuration option in the &lt;code&gt;/etc/ssh/sshd_config&lt;/code&gt; file contained an equals sign which caused cloud-init user data scripts to fail.&lt;/li&gt;
&lt;li&gt;Migrating user, organization, and repository data using &lt;code&gt;ghe-migrator&lt;/code&gt; could fail to import a migration archive if it contained empty records.&lt;/li&gt;
&lt;li&gt;Migrating user, organization, and repository data using &lt;code&gt;ghe-migrator&lt;/code&gt; could fail to set the team maintainer role on the destination team during the import.&lt;/li&gt;
&lt;li&gt;Log forwarding did not include the GitHub application&#39;s Nginx log.&lt;/li&gt;
&lt;li&gt;The tokens added to gist raw links in private mode expired in 30 seconds. These now expire after a week.&lt;/li&gt;
&lt;li&gt;The merge button could remain disabled on pull requests with protected branches and required statuses when all Travis-initiated status checks had passed.&lt;/li&gt;
&lt;li&gt;Pages URLs without a trailing slash redirected incorrectly.&lt;/li&gt;
&lt;li&gt;The default branch selector within the repository settings didn&#39;t correctly search for branches.&lt;/li&gt;
&lt;li&gt;Adding a second unnamed file to a gist would overwrite the first unnamed file added to that gist.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-support-bundle&lt;/code&gt; can now be used to upload arbitrary files directly to GitHub using a new &lt;code&gt;-f path&lt;/code&gt; option.&lt;/li&gt;
&lt;li&gt;Admin Tools now shows whether protected branch status checks are enforced for admin users or not.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; OpenJDK has been updated to address multiple vulnerabilities related to information disclosure, data integrity and availability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; NTP packages have been updated to address &lt;a href=&quot;http://www.ubuntu.com/usn/usn-2783-1/&quot;&gt;multiple vulnerabilities&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/del&gt;&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Restoring backups from previous versions fail. As a workaround, create an instance matching the version the backup was taken from, restore the backup, then upgrade. (updated 2015-11-05)&lt;/li&gt;
&lt;li&gt;High availability replication sometimes fails to set the correct master identifier during an upgrade. This prevents MySQL replication from starting. (updated 2015-11-11)&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The failure to migrate repositories in an incomplete state to the new repository disk layout was resolved in 2.4.0. (updated 2015-12-01)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 03 Nov 2015 10:00:50 -0800</pubDate>
					<link>https://enterprise.github.com/releases/2.4.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.4.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.3.5</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The high availability replication status as reported by &lt;code&gt;ghe-repl-status&lt;/code&gt; would not report a failure if ElasticSearch was not running.&lt;/li&gt;
&lt;li&gt;The temporary support bundle archive wasn&#39;t removed after a successful upload.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-upgrade&lt;/code&gt; would fail with a GPG signature error if run as the root user.&lt;/li&gt;
&lt;li&gt;The slider handle would not show when viewing an SVG diff.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; OpenJDK has been updated to address multiple vulnerabilities related to information disclosure, data integrity and availability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; NTP packages have been updated to address &lt;a href=&quot;http://www.ubuntu.com/usn/usn-2783-1/&quot;&gt;multiple vulnerabilities&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Email can&#39;t be sent over TLS when SSL is disabled.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 03 Nov 2015 10:00:40 -0800</pubDate>
					<link>https://enterprise.github.com/releases/2.3.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.3.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.11</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-upgrade&lt;/code&gt; would fail with a GPG signature error if run as the root user.&lt;/li&gt;
&lt;li&gt;The Gist resqued.log file was not regularly rotated.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; OpenJDK has been updated to address &lt;a href=&quot;http://www.ubuntu.com/usn/usn-2784-1/&quot;&gt;multiple vulnerabilities&lt;/a&gt; related to information disclosure, data integrity and availability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; NTP packages have been updated to address &lt;a href=&quot;http://www.ubuntu.com/usn/usn-2783-1/&quot;&gt;multiple vulnerabilities&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Organization invitation emails are sent from the configured support email address rather than the no-reply address.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 03 Nov 2015 10:00:30 -0800</pubDate>
					<link>https://enterprise.github.com/releases/2.2.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.1.16</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The Gist resqued.log file was not regularly rotated.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; Oracle Java 7.0 is no longer supported by Oracle. We have switched to OpenJDK 7 and updated to the latest version to address &lt;a href=&quot;http://www.ubuntu.com/usn/usn-2784-1/&quot;&gt;multiple vulnerabilities&lt;/a&gt; related to information disclosure, data integrity and availability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; NTP packages have been updated to address &lt;a href=&quot;http://www.ubuntu.com/usn/usn-2783-1/&quot;&gt;multiple vulnerabilities&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Promoting a high availability replica can fail if Elasticsearch takes too long to restart.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &#39;Starting...&#39; instead.&lt;/li&gt;
&lt;li&gt;Some processes continued to write to logs after they were rotated. This could cause the root file system to fill up.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation disabled.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;Accessing GitHub Enterprise using a hostname alias with private mode enabled as an unauthenticated user will redirect you to the dashboard instead of the page you were trying to visit after you log in.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 03 Nov 2015 10:00:20 -0800</pubDate>
					<link>https://enterprise.github.com/releases/2.1.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.1.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.0.20</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; Oracle Java 7.0 is no longer supported by Oracle. We have switched to OpenJDK 7 and updated to the latest version to address &lt;a href=&quot;http://www.ubuntu.com/usn/usn-2784-1/&quot;&gt;multiple vulnerabilities&lt;/a&gt; related to information disclosure, data integrity and availability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; NTP packages have been updated to address &lt;a href=&quot;http://www.ubuntu.com/usn/usn-2783-1/&quot;&gt;multiple vulnerabilities&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are logged twice.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.0&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.0 will be deprecated as of January 1, 2016.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 03 Nov 2015 10:00:10 -0800</pubDate>
					<link>https://enterprise.github.com/releases/2.0.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.0.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.4.0</title>
					<description>&lt;h2&gt;New Features&lt;/h2&gt;
&lt;p&gt;With the new features added in GitHub Enterprise 2.4.0, you can:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/2051-protected-branches-and-required-status-checks&quot;&gt;Protect branches and require status checks&lt;/a&gt; to pass on pull requests before they can be merged. We&#39;ve also made &lt;a href=&quot;https://github.com/blog/2040-clearer-mergability-information-for-pull-requests&quot;&gt;changes to the merge button&lt;/a&gt; so you can clearly see how your build is progressing.&lt;/li&gt;
&lt;li&gt;Powerfully collaborate with &lt;a href=&quot;https://github.com/blog/2020-improved-organization-permissions&quot;&gt;improved organization permissions&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Version large files in production with all of the new &lt;a href=&quot;https://github.com/blog/2069-git-large-file-storage-v1-0&quot;&gt;Git Large File Storage v1.0&lt;/a&gt; features and enhancements, including batch mode. Git LFS is now production ready.&lt;/li&gt;
&lt;li&gt;Render, browse and interact with maps annotated with your geographic data in &lt;a href=&quot;https://github.com/blog/1528-there-s-a-map-for-that&quot;&gt;GeoJSON files&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;View Pages sites hosted on your appliance even if private mode is enabled, and use the &lt;a href=&quot;https://github.com/jekyll/jekyll-feed&quot;&gt;Jekyll-feed plugin&lt;/a&gt; to automatically create an Atom feed of your most recent posts.&lt;/li&gt;
&lt;li&gt;Configure your appliance to &lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/installation/enabling-automatic-update-checks&quot;&gt;automatically check for updates&lt;/a&gt; and download them ready for you to upgrade when you&#39;re ready to do so.&lt;/li&gt;
&lt;li&gt;Use the API to &lt;a href=&quot;https://developer.github.com/enterprise/2.4/v3/users/administration/#delete-a-user&quot;&gt;delete users&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Secure your user accounts using &lt;a href=&quot;https://github.com/blog/2071-github-supports-universal-2nd-factor-authentication&quot;&gt;FIDO Universal 2nd Factor (U2F)&lt;/a&gt;—a rapidly growing open authentication standard.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In private mode, deploy keys now only give access to the repository they are assigned to. The behavior of deploy keys was previously vague and allowed access to every public repository on the appliance in private mode. This behavior wasn&#39;t documented, and is considered unexpected behavior.&lt;/li&gt;
&lt;li&gt;Fullscreen (Zen mode) editing has been removed.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upgrading&lt;/h2&gt;
&lt;p&gt;Upgrading to the 2.4 release series is supported from GitHub Enterprise 2.2.0 and above.&lt;/p&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Email couldn&#39;t be sent over TLS when SSL was disabled.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.3/admin/articles/viewing-push-logs/&quot;&gt;Viewing a repository&#39;s push log&lt;/a&gt; in a web browser displayed the warning &#39;Reflog Sync disabled on this repository. Results maybe out of date.&#39; This was cosmetic only and did not indicate an issue with the push log or repository storage.&lt;/li&gt;
&lt;li&gt;Improved the efficiency of Git LFS operations.&lt;/li&gt;
&lt;li&gt;When a fork was detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path wasn&#39;t updated on a high availability replica until at least one commit had been pushed.&lt;/li&gt;
&lt;li&gt;DNS responses are cached to speed up lookups and to reduce the load on DNS servers.&lt;/li&gt;
&lt;li&gt;Gist repositories were not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Organization user lookup could reveal private members of other organizations.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: DES-based SSH ciphers are disabled for Git operations over SSH.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of authentication using GitHub OAuth&lt;/h2&gt;
&lt;p&gt;User authentication via &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/user-management/using-github-oauth/&quot;&gt;GitHub OAuth&lt;/a&gt; is being deprecated and will be removed in a future feature release. It will be removed &lt;strong&gt;no sooner than November 2015&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;GitHub Enterprise includes support for authenticating users via OAuth to accounts on GitHub.com because it provides a simple way to set up external authentication. However, after speaking with many customers, we&#39;ve found that organizations commonly have other sources they want to use to automate identity and access management.&lt;/p&gt;
&lt;p&gt;We want to focus on features that best meet the needs of our users, so we&#39;re planning to remove support for GitHub OAuth in a future feature release and focus on making ongoing improvements to other authentication methods like &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/user-management/using-saml/&quot;&gt;SAML&lt;/a&gt; and &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/user-management/using-ldap/&quot;&gt;LDAP&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Note that this change will only affect user authentication via GitHub.com and not personal access tokens or OAuth applications added to your GitHub Enterprise instance.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of GitHub Enterprise 2.0&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;GitHub Enterprise 2.0 will be deprecated as of January 1, 2016.&lt;/strong&gt; That means that no patch releases will be made, even for critical security issues, after this date. For better performance, improved security, and new features, &lt;a href=&quot;https://docs.github.com/enterprise/2.4/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/&quot;&gt;upgrade to the newest version of GitHub Enterprise&lt;/a&gt; as soon as possible.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/del&gt;&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Restoring backups from previous versions fail. As a workaround, create an instance matching the version the backup was taken from, restore the backup, then upgrade. (updated 2015-11-05)&lt;/li&gt;
&lt;li&gt;High availability replication sometimes fails to set the MySQL password correctly which prevents MySQL replication from starting. (updated 2015-11-11)&lt;/li&gt;
&lt;li&gt;High availability replication sometimes fails to set the correct master identifier during an upgrade. This prevents MySQL replication from starting. (updated 2015-11-11)&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The failure to migrate repositories in an incomplete state to the new repository disk layout was resolved in 2.4.0. (updated 2015-12-01)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 13 Oct 2015 18:00:00 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.4.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.4.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.3.4</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We didn&#39;t accept OAuth application credentials using Basic Authentication when exchanging the code for a token. This meant developers couldn&#39;t use the standard Go OAuth2 library with GitHub Enterprise forcing developers to maintain their own fork of the library.&lt;/li&gt;
&lt;li&gt;When a member of a team with admin access tried to add a new team member, it failed without an error. Only the Owners team could add new team members.&lt;/li&gt;
&lt;li&gt;SNMP did not start on the high availability replica.&lt;/li&gt;
&lt;li&gt;It was not possible to upload files larger than 1GB with Git LFS.&lt;/li&gt;
&lt;li&gt;GitHub Pages reported a vague error message when page builds failed due to the use of an unsupported syntax highlighter.&lt;/li&gt;
&lt;li&gt;Some repositories could have temporary merge-trees directories left from git operations that timed out but weren&#39;t automatically cleaned up.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; Unvalidated parameters passed to the GitHub Enterprise metrics could be used to generate a denial of service attack against the appliance.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; Large Git updates could trigger an overflow in Git xdiff.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We now retain more of the MySQL binlog files. This helps ensure MySQL replication can be automatically setup following an extended period without any replication.&lt;/li&gt;
&lt;li&gt;Setting up high availability replication can sometimes fail when establishing the VPN connection. We&#39;ve made the output more verbose to help with determining the cause of these failures.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Email can&#39;t be sent over TLS when SSL is disabled.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/del&gt;&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by changing visibility, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Not deleting a user&#39;s gists when deleting the user was fixed in 2.3.0. (updated 2015-10-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 06 Oct 2015 00:00:23 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.3.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.3.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.10</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Some repositories could have temporary merge-trees directories left from git operations that timed out but weren&#39;t automatically cleaned up.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; Unvalidated parameters passed to the GitHub Enterprise metrics could be used to generate a denial of service attack against the appliance.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; Large Git updates could trigger an overflow in Git xdiff.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Setting up high availability replication can sometimes fail when establishing the VPN connection. We&#39;ve made the output more verbose to help with determining the cause of these failures.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Organization invitation emails are sent from the configured support email address rather than the no-reply address.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 06 Oct 2015 00:00:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.2.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.1.15</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; Unvalidated parameters passed to the GitHub Enterprise metrics could be used to generate a denial of service attack against the appliance.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; Large Git updates could trigger an overflow in Git xdiff.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Promoting a high availability replica can fail if Elasticsearch takes too long to restart.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &#39;Starting...&#39; instead.&lt;/li&gt;
&lt;li&gt;Some processes continued to write to logs after they were rotated. This could cause the root file system to fill up.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation disabled.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;Accessing GitHub Enterprise using a hostname alias with private mode enabled as an unauthenticated user will redirect you to the dashboard instead of the page you were trying to visit after you log in.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 06 Oct 2015 00:00:21 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.1.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.1.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.0.19</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt; Unvalidated parameters passed to the GitHub Enterprise metrics could be used to generate a denial of service attack against the appliance.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt; Large Git updates could trigger an overflow in Git xdiff.&lt;/li&gt;
&lt;li&gt;Packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are logged twice.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 06 Oct 2015 00:00:20 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.0.19</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.0.19</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.3.3</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The instance could reboot before MySQL had completely stopped. This could lead to database inconsistencies that may have only come to light during an upgrade.&lt;/li&gt;
&lt;li&gt;The warning message shown when making a public repository on instances with private mode enabled was a little vague and could lead to uncertainly about how public the repository would really be.&lt;/li&gt;
&lt;li&gt;The Elasticsearch logs could contain socket exception errors caused by a health check exiting prematurely.&lt;/li&gt;
&lt;li&gt;Pull request &lt;code&gt;.patch&lt;/code&gt; and &lt;code&gt;.diff&lt;/code&gt; URLs would fail on instances with subdomain isolation disabled.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we showed the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps would always fail. We also didn&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;The installation preflight check didn&#39;t make it clear that two block devices are required.&lt;/li&gt;
&lt;li&gt;The maintenance page on the high availability replica instance used the incorrect information from the primary instance in the link to the primary instance.  This led to a confusing experience for users following this link.&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set would throw errors – the updates are now refused.&lt;/li&gt;
&lt;li&gt;The audit log was missing useful Git activity information.&lt;/li&gt;
&lt;li&gt;Postfix allowed local user and address verification using the RCPT and VRFY commands potentially exposing operating system-level user information.&lt;/li&gt;
&lt;li&gt;Semicolons were allowed to be used in the LDAP Base name settings within the management console leading to problems authenticating users via LDAP.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;core.package-version&lt;/code&gt; variable in the appliance configuration file was not updated to reflect the new appliance version during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.3/admin/articles/viewing-push-logs/&quot;&gt;Viewing a repository&#39;s push log&lt;/a&gt; in a web browser displayed the warning &amp;quot;Reflog Sync disabled on this repository. Results maybe out of date.&amp;quot; This was cosmetic only and did not indicate an issue with the push log or repository storage.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; Read access to public API endpoints of private-mode instances and to specific reporting endpoints can be authenticated by connecting via local trusted ports. This authentication could be bypassed by manipulating specific HTTP headers and lead to information disclosure.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; The Markdown syntax highlighter allowed malicious users to inject unsanitized HTML into comments and Markdown documents.&lt;/li&gt;
&lt;li&gt;Kernel and packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;Mediawiki Math markup within Gists and repository files with the &lt;code&gt;.mediawiki&lt;/code&gt; suffix could leak information to the Google Chart API when they were displayed.&lt;/li&gt;
&lt;li&gt;Raw Gist URLs didn&#39;t include an expiring token when private mode is enabled. This meant raw Gists were always accessible without authentication if you knew the full URL.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Email can&#39;t be sent over TLS when SSL is disabled.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/del&gt;&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;When a member of a team with admin access tries to add a new team member, it fails without an error. Only the Owners team can add new team members.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Not deleting a user&#39;s gists when deleting the user was fixed in 2.3.0. (updated 2015-10-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 15 Sep 2015 00:00:23 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.3.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.3.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.9</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; Read access to public API endpoints of private-mode instances and to specific reporting endpoints can be authenticated by connecting via local trusted ports. This authentication could be bypassed by manipulating specific HTTP headers and lead to information disclosure.&lt;/li&gt;
&lt;li&gt;Kernel and packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;Mediawiki Math markup within Gists and repository files with the &lt;code&gt;.mediawiki&lt;/code&gt; suffix could leak information to the Google Chart API when they were displayed.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Organization invitation emails are sent from the configured support email address rather than the no-reply address.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 15 Sep 2015 00:00:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.2.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.1.14</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; Read access to public API endpoints of private-mode instances and to specific reporting endpoints can be authenticated by connecting via local trusted ports. This authentication could be bypassed by manipulating specific HTTP headers and lead to information disclosure.&lt;/li&gt;
&lt;li&gt;Kernel and packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;Mediawiki Math markup within Gists and repository files with the &lt;code&gt;.mediawiki&lt;/code&gt; suffix could leak information to the Google Chart API when they were displayed.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Promoting a high availability replica can fail if Elasticsearch takes too long to restart.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &#39;Starting...&#39; instead.&lt;/li&gt;
&lt;li&gt;Some processes continued to write to logs after they were rotated. This could cause the root file system to fill up.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation disabled.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;Accessing GitHub Enterprise using a hostname alias with private mode enabled as an unauthenticated user will redirect you to the dashboard instead of the page you were trying to visit after you log in.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 15 Sep 2015 00:00:21 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.1.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.1.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.0.18</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt; Read access to public API endpoints of private-mode instances and to specific reporting endpoints can be authenticated by connecting via local trusted ports. This authentication could be bypassed by manipulating specific HTTP headers and lead to information disclosure.&lt;/li&gt;
&lt;li&gt;Kernel and packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;Mediawiki Math markup within Gists and repository files with the &lt;code&gt;.mediawiki&lt;/code&gt; suffix could leak information to the Google Chart API when they were displayed.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are logged twice.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 15 Sep 2015 00:00:20 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.0.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.0.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.3.2</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We showed a warning in the site admin that an email address wasn&#39;t verified, but email verification is disabled in GitHub Enterprise.&lt;/li&gt;
&lt;li&gt;User profile names containing certain Unicode characters wouldn&#39;t display when synced from an LDAP directory.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;longpoll&lt;/code&gt; service, which provides live updates to Issues and Pull Requests pages, didn&#39;t restart properly if it was terminated.&lt;/li&gt;
&lt;li&gt;Logs for some background jobs were not forwarded.&lt;/li&gt;
&lt;li&gt;Double quotes were being stripped from admin SSH keys added via the management console.&lt;/li&gt;
&lt;li&gt;Deploy keys could not be deleted when LDAP Sync was enabled.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-storage-extend&lt;/code&gt; command, which resizes the storage volume, could fail with a &lt;code&gt;Volume group name ghe_storage_* has invalid characters&lt;/code&gt; error under some circumstances.&lt;/li&gt;
&lt;li&gt;Several actions of the admin API related to LDAP were not working as documented.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Kernel and packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Email can&#39;t be sent over TLS when SSL is disabled.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/del&gt;&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set throw errors.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.3/admin/articles/viewing-push-logs/&quot;&gt;Viewing a repository&#39;s push log&lt;/a&gt; in a web browser displays the warning &amp;quot;Reflog Sync disabled on this repository. Results maybe out of date.&amp;quot; This is cosmetic only and does not indicate an issue with the push log or repository storage. (updated 2015-08-28)&lt;/li&gt;
&lt;li&gt;When a member of a team with admin access tries to add a new team member, it fails without an error. Only the Owners team can add new team members. (updated 2015-09-08)&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Not deleting a user&#39;s gists when deleting the user was fixed in 2.3.0. (updated 2015-10-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 25 Aug 2015 00:00:23 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.3.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.3.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.8</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;longpoll&lt;/code&gt; service, which provides live updates to Issues and Pull Requests pages, didn&#39;t restart properly if it was terminated.&lt;/li&gt;
&lt;li&gt;Logs for some background jobs were not forwarded.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-storage-extend&lt;/code&gt; command, which resizes the storage volume, could fail with a &lt;code&gt;Volume group name ghe_storage_* has invalid characters&lt;/code&gt; error under some circumstances.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Kernel and packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Organization invitation emails are sent from the configured support email address rather than the no-reply address.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed.&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set throw errors.&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 25 Aug 2015 00:00:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.2.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.1.13</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Kernel and packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Promoting a high availability replica can fail if Elasticsearch takes too long to restart.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &#39;Starting...&#39; instead.&lt;/li&gt;
&lt;li&gt;Some processes continued to write to logs after they were rotated. This could cause the root file system to fill up.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation disabled.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;Accessing GitHub Enterprise using a hostname alias with private mode enabled as an unauthenticated user will redirect you to the dashboard instead of the page you were trying to visit after you log in.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message.&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set throw errors.&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 25 Aug 2015 00:00:21 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.1.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.1.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.0.17</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;p&gt;Kernel and packages have been updated to the latest security versions.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are logged twice.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 25 Aug 2015 00:00:20 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.0.17</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.0.17</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.3.1</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Packages have been updated to the latest bugfix versions.&lt;/li&gt;
&lt;li&gt;Administrators couldn&#39;t promote or demote SAML users from the command line.&lt;/li&gt;
&lt;li&gt;Settings downloaded using the management console API couldn&#39;t be applied using the management console API.&lt;/li&gt;
&lt;li&gt;An error in the VMware tools configuration caused excessive logging.&lt;/li&gt;
&lt;li&gt;Organization owners could be prompted to sign up for an early access feature that is not part of GitHub Enterprise.&lt;/li&gt;
&lt;li&gt;During an upgrade, checking the validity of the SSL certificate and key could output an error message. There is nothing wrong, but the error message can look scary.&lt;/li&gt;
&lt;li&gt;Suspended user accounts could be created when unauthorized LDAP users attempted to sign in to GitHub Enterprise.&lt;/li&gt;
&lt;li&gt;A failed login attempt caused multiple LDAP authentication failures, which could cause accounts to be locked on the LDAP server side.&lt;/li&gt;
&lt;li&gt;Gist-specific keyboard shortcuts were not shown when you pressed the &lt;code&gt;?&lt;/code&gt; key on Gist pages.&lt;/li&gt;
&lt;li&gt;Clicking on line numbers in the second file of a multi-file Gist would highlight a code line in the first file, if that code line number exists in the first file.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/del&gt;&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you accessed GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Email can&#39;t be sent over TLS when SSL is disabled.&lt;/li&gt;
&lt;li&gt;It is not possible to modify the LDAP DN mapping for a user using the administrator LDAP API.&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed. (updated 2015-08-13)&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set throw errors. (updated 2015-08-25)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.3/admin/articles/viewing-push-logs/&quot;&gt;Viewing a repository&#39;s push log&lt;/a&gt; in a web browser displays the warning &amp;quot;Reflog Sync disabled on this repository. Results maybe out of date.&amp;quot; This is cosmetic only and does not indicate an issue with the push log or repository storage. (updated 2015-08-28)&lt;/li&gt;
&lt;li&gt;When a member of a team with admin access tries to add a new team member, it fails without an error. Only the Owners team can add new team members. (updated 2015-09-08)&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Not deleting a user&#39;s gists when deleting the user was fixed in 2.3.0. (updated 2015-10-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 11 Aug 2015 00:00:23 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.3.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.3.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.7</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;A failed login attempt caused multiple LDAP authentication failures, which could cause accounts to be locked on the LDAP server side.&lt;/li&gt;
&lt;li&gt;Using uppercase characters in the hostname caused a redirect loop.&lt;/li&gt;
&lt;li&gt;When displaying a commit made with an email address that doesn&#39;t belong to an existing GitHub Enterprise user, we loaded a default avatar from a GitHub.com subdomain.&lt;/li&gt;
&lt;li&gt;An error in the VMware tools configuration caused excessive logging.&lt;/li&gt;
&lt;li&gt;During an upgrade, checking the validity of the SSL certificate and key could output an error message. There is nothing wrong, but the error message can look scary.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Kernel and packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM:&lt;/strong&gt; Cached form objects could cause CSRF tokens to be shared across users.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Organization invitation emails are sent from the configured support email address rather than the no-reply address.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed. (updated 2015-08-13)&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set throw errors. (updated 2015-08-25)&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 11 Aug 2015 00:00:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.2.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.1.12</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;An error in the VMware tools configuration caused excessive logging.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Kernel and packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM:&lt;/strong&gt; Cached form objects could cause CSRF tokens to be shared across users.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Promoting a high availability replica can fail if Elasticsearch takes too long to restart.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &#39;Starting...&#39; instead.&lt;/li&gt;
&lt;li&gt;Some processes continued to write to logs after they were rotated. This could cause the root file system to fill up.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation disabled.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;Accessing GitHub Enterprise using a hostname alias with private mode enabled as an unauthenticated user will redirect you to the dashboard instead of the page you were trying to visit after you log in.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message.&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set throw errors. (updated 2015-08-25)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 11 Aug 2015 00:00:21 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.1.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.1.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.0.16</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Kernel and packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;; Cached form objects could cause CSRF tokens to be shared across users.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are logged twice.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 11 Aug 2015 00:00:20 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.0.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.0.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.3.0</title>
					<description>&lt;h2&gt;New Features&lt;/h2&gt;
&lt;p&gt;With the new features added in GitHub Enterprise 2.3.0, you can:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Use the API to &lt;a href=&quot;https://developer.github.com/enterprise/2.3/v3/users/administration/#create-a-new-user&quot;&gt;create new users&lt;/a&gt; and &lt;a href=&quot;https://developer.github.com/enterprise/2.3/v3/enterprise/orgs/#create-an-organization&quot;&gt;organizations&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.github.com/enterprise/2.3/v3/users/administration/#create-an-impersonation-oauth-token&quot;&gt;Impersonate a user&lt;/a&gt; when making API calls, just as you can through the web interface.&lt;/li&gt;
&lt;li&gt;Have finer control over permissions with &lt;a href=&quot;https://github.com/blog/2024-read-only-deploy-keys&quot;&gt;read-only deploy keys&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Migrate complete repositories from one GitHub instance to another with &lt;code&gt;ghe-migrator&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Configure an HTTP proxy for outbound traffic, such as webhooks.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Updates to the Authorizations API include &lt;a href=&quot;https://developer.github.com/changes/2015-02-20-migration-period-removing-authorizations-token/&quot;&gt;breaking changes&lt;/a&gt;. If you use the Authorizations API, you should review the changes and update your usage before upgrading. (updated 2015-08-06)&lt;/li&gt;
&lt;li&gt;We no longer send email invitations when adding a user to an organization.&lt;/li&gt;
&lt;li&gt;The queues for background jobs can now be paused and resumed using the &lt;code&gt;ghe-resque-info&lt;/code&gt; command line utility.&lt;/li&gt;
&lt;li&gt;Browsers no longer send a Referer header on requests originating from the GitHub Enterprise to prevent leaking the location of your Enterprise instance.&lt;/li&gt;
&lt;li&gt;The search index definitions have changed. Some searches will return partial results while the search indices are rebuilt. (updated 2015-10-07)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upgrading&lt;/h2&gt;
&lt;p&gt;Upgrading to the 2.3 release series is supported from GitHub Enterprise 2.1.0 and above.&lt;/p&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu packages have been updated to the latest bugfix versions.&lt;/li&gt;
&lt;li&gt;When displaying a commit made with an email address that doesn&#39;t belong to an existing GitHub Enterprise user, we loaded a default avatar from a GitHub.com subdomain.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;During an upgrade, checking the validity of the SSL certificate and key could output an error message. There is nothing wrong, but the error message can look scary.&lt;/del&gt;&lt;/li&gt;
&lt;li&gt;Using uppercase characters in the hostname caused a redirect loop.&lt;/li&gt;
&lt;li&gt;CSV files on Pages sites were transferred uncompressed.&lt;/li&gt;
&lt;li&gt;We didn&#39;t show an error if you uploaded an invalid license when the current license was expired.&lt;/li&gt;
&lt;li&gt;The page displayed when GitHub Enterprise is in maintenance mode could show an out of date support email address.&lt;/li&gt;
&lt;li&gt;Gist profile pages didn&#39;t have proper styling when subdomain isolation was disabled.&lt;/li&gt;
&lt;li&gt;Global notices weren&#39;t displayed on mobile devices.&lt;/li&gt;
&lt;li&gt;We didn&#39;t properly show user details in the search section of a user&#39;s profile in the site admin.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links pointed to the wrong hostname after restoring from backup if the hostname had changed.&lt;/li&gt;
&lt;li&gt;We displayed the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Replication setup failed for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;Gists couldn&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters were suspended if LDAP Sync was enabled. (updated 2015-08-20)&lt;/li&gt;
&lt;li&gt;Deleting a user didn&#39;t delete their gists, which could cause problems with replication. (updated 2015-10-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu kernel and packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM:&lt;/strong&gt; Cached form objects could cause CSRF tokens to be shared across users.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Upcoming deprecation of authentication using GitHub OAuth&lt;/h2&gt;
&lt;p&gt;User authentication via &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/user-management/using-github-oauth/&quot;&gt;GitHub OAuth&lt;/a&gt; is being deprecated and will be removed in a future feature release. It will be removed &lt;strong&gt;no sooner than November 2015&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;GitHub Enterprise includes support for authenticating users via OAuth to accounts on GitHub.com because it provides a simple way to set up external authentication. However, after speaking with many customers, we&#39;ve found that organizations commonly have other sources they want to use to automate identity and access management.&lt;/p&gt;
&lt;p&gt;We want to focus on features that best meet the needs of our users, so we&#39;re planning to remove support for GitHub OAuth in a future feature release and focus on making ongoing improvements to other authentication methods like &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/user-management/using-saml/&quot;&gt;SAML&lt;/a&gt; and &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/user-management/using-ldap/&quot;&gt;LDAP&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Note that this change will only affect user authentication via GitHub.com and not personal access tokens or OAuth applications added to your GitHub Enterprise instance.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/del&gt;&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Email can&#39;t be sent over TLS when SSL is disabled.&lt;/li&gt;
&lt;li&gt;During an upgrade, checking the validity of the SSL certificate and key could output an error message. There is nothing wrong, but the error message can look scary.&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed. (updated 2015-08-13)&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set throw errors. (updated 2015-08-25)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.3/admin/articles/viewing-push-logs/&quot;&gt;Viewing a repository&#39;s push log&lt;/a&gt; in a web browser displays the warning &amp;quot;Reflog Sync disabled on this repository. Results maybe out of date.&amp;quot; This is cosmetic only and does not indicate an issue with the push log or repository storage. (updated 2015-08-28)&lt;/li&gt;
&lt;li&gt;When a member of a team with admin access tries to add a new team member, it fails without an error. Only the Owners team can add new team members. (updated 2015-09-08)&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Under some circumstances, it is still possible to trigger a harmless error message when checking the validity of the SSL certificate and key during an upgrade.&lt;/li&gt;
&lt;li&gt;Not deleting a user&#39;s gists when deleting the user was fixed in 2.3.0. (updated 2015-10-12)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 04 Aug 2015 00:00:23 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.3.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.3.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.6</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Services failed to start properly after upgrading if SSL was disabled.&lt;/li&gt;
&lt;li&gt;When trying to merge a pull request through the API where the author didn&#39;t have a primary email address, a server error was returned instead of a useful error message.&lt;/li&gt;
&lt;li&gt;When running GitHub Enterprise on Xen, upgrades could fail due to incorrectly detecting that the hypervisor was HyperV.&lt;/li&gt;
&lt;li&gt;On boot, we automatically fix corruption in the Redis appendonly file but user input was needed, so it appeared to hang.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu packages have been updated to the latest bugfix versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We&#39;ve added resource usage graphs for processes to the monitoring dashboard.&lt;/li&gt;
&lt;li&gt;We added the &lt;code&gt;longpoll&lt;/code&gt; process, which handles live updates to issues, to the &lt;code&gt;ghe-service-list&lt;/code&gt; output.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Organization invitation emails are sent from the configured support email address rather than the no-reply address.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Management console sessions can expire too quickly for Safari users.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Replication setup fails for IPv6 hosts.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Using uppercase characters in the hostname causes a redirect loop.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed. (updated 2015-08-13)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Updates to Wiki pages by users without a primary email address set throw errors. (updated 2015-08-25)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 28 Jul 2015 15:07:30 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.2.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.1.11</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Promoting a high availability replica can fail if Elasticsearch takes too long to restart.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &#39;Starting...&#39; instead.&lt;/li&gt;
&lt;li&gt;Some processes continued to write to logs after they were rotated. This could cause the root file system to fill up.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation disabled.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;Accessing GitHub Enterprise using a hostname alias with private mode enabled as an unauthenticated user will redirect you to the dashboard instead of the page you were trying to visit after you log in.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message.&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set throw errors. (updated 2015-08-25)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 28 Jul 2015 15:07:20 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.1.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.1.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.0.15</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;p&gt;Ubuntu packages have been updated to the latest security versions.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are logged twice.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 28 Jul 2015 15:07:10 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.0.15</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.0.15</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.5</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu kernel and packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH:&lt;/strong&gt; Update HAProxy to address &lt;a href=&quot;https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-3281&quot;&gt;CVE-2015-3281&lt;/a&gt;, which could allow an attacker to use a specially crafted request to read memory contents that might contain data from a past request or session.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM:&lt;/strong&gt; Scopeless access tokens could list private Gists.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW:&lt;/strong&gt; Service hooks could log passwords used for HTTP Basic authentication to disk. (updated 2015-07-28)&lt;/li&gt;
&lt;li&gt;This release and previous releases of GitHub Enterprise are not affected by the OpenSSL Advisory issued 9 July 2015 (CVE-2015-1793)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu kernel and packages have been updated to the latest bugfix versions.&lt;/li&gt;
&lt;li&gt;A repository could be incorrectly deleted from disk after migration to the new repository layout. If a repository was deleted and no other repositories were created before a reboot, we reused the ID of the deleted repository. This happens because when MySQL starts, the auto increment ID system is inititialized with the last ID in the table. This means the first new repository created would have the same ID as the deleted repository, and the repository cleanup job would incorrectly see the new repository as deleted.&lt;/li&gt;
&lt;li&gt;The Redis appendonly file could become corrupt when performing a hard reboot of the appliance, which caused Redis to not start.&lt;/li&gt;
&lt;li&gt;A race condition in the pull request synchronize event could result in incorrect SHAs and timestamps in the webhook payload.&lt;/li&gt;
&lt;li&gt;Collectd could cause lots of tiny writes to the root volume, which could affect the performance of the appliance.&lt;/li&gt;
&lt;li&gt;Old webhook delivery logs were deleted inefficiently. We&#39;ve changed the directory structure so we can delete them more efficiently.&lt;/li&gt;
&lt;li&gt;Viewing compare pages and pull requests could result in a 500 error due to a race condition.&lt;/li&gt;
&lt;li&gt;LDAP restricted groups couldn&#39;t be removed.&lt;/li&gt;
&lt;li&gt;The site admin showed Gravatar icons for users&#39; additional email addresses.&lt;/li&gt;
&lt;li&gt;SNMP couldn&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again didn&#39;t properly show the replica status page, but showed &#39;Starting...&#39; instead.&lt;/li&gt;
&lt;li&gt;Searching Gists could fail after upgrading to GitHub Enterprise 2.2.&lt;/li&gt;
&lt;li&gt;It was not possible to view user profiles or repositories for users with usernames that started with &amp;quot;raw&amp;quot;.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; and &lt;code&gt;haproxy&lt;/code&gt; log streams were being logged twice.&lt;/li&gt;
&lt;li&gt;Setting up high availability replication could fail due to a large entry in one of the MySQL tables.&lt;/li&gt;
&lt;li&gt;Promoting a high availability replica could fail if Elasticsearch took too long to restart.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We&#39;ve added a graph for disk utilization to the monitoring dashboard.&lt;/li&gt;
&lt;li&gt;Direct root SSH access was not possible in the past, but as an additional measure we&#39;ve also added PermitRootLogin to no within the SSH configuration.&lt;/li&gt;
&lt;li&gt;We&#39;ve added support for the C4 and M4 AWS instance types.&lt;/li&gt;
&lt;li&gt;You are now prompted to confirm that you wish high availability replication to continue when we detect you are attempting to setup replication on an instance that is currently, or has been, an active configured instance.  This reduces the chances of accidental replication over an active primary instance.&lt;/li&gt;
&lt;li&gt;The diagnostics output gathered on high availability replicas now only gathers information relevant to replica instances.&lt;/li&gt;
&lt;li&gt;NTP is now configured on the high availability replica when replication is setup.&lt;/li&gt;
&lt;li&gt;Old compressed rotated log files are no longer retained during an upgrade.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Organization invitation emails are sent from the configured support email address rather than the no-reply address.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Management console sessions can expire too quickly for Safari users.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Replication setup fails for IPv6 hosts.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;del&gt;The site admin shows errors in the &#39;repo reflogs&#39; section, which isn&#39;t fully implemented on GitHub Enterprise.&lt;/del&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Services fail to start properly after upgrading to this release if SSL is disabled. (updated 2015-07-20)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Using uppercase characters in the hostname causes a redirect loop.  (updated 2015-07-28)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed. (updated 2015-08-13)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Updates to Wiki pages by users without a primary email address set throw errors. (updated 2015-08-25)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &#39;repo reflogs&#39; section of the site admin was removed in 2.2.4.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 07 Jul 2015 00:00:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.2.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.1.10</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu kernel and packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH:&lt;/strong&gt; Update HAProxy to address &lt;a href=&quot;https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-3281&quot;&gt;CVE-2015-3281&lt;/a&gt;, which could allow an attacker to use a specially crafted request to read memory contents that might contain data from a past request or session.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM:&lt;/strong&gt; Scopeless access tokens could list private Gists.&lt;/li&gt;
&lt;li&gt;This release and previous releases of GitHub Enterprise are not affected by the OpenSSL Advisory issued 9 July 2015 (CVE-2015-1793)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu kernel and packages have been updated to the latest bugfix versions.&lt;/li&gt;
&lt;li&gt;We could fail to properly create the key for the secure connection between a high availability replica and the primary, which caused replication setup to fail.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Direct root SSH access was not possible in the past, but as an additional measure we&#39;ve also added PermitRootLogin to no within the SSH configuration.&lt;/li&gt;
&lt;li&gt;We now gather VMware memory statistics in the diagnostics output.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Promoting a high availability replica can fail if Elasticsearch takes too long to restart.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &#39;Starting...&#39; instead.&lt;/li&gt;
&lt;li&gt;Some processes continued to write to logs after they were rotated. This could cause the root file system to fill up.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation disabled.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;Accessing GitHub Enterprise using a hostname alias with private mode enabled as an unauthenticated user will redirect you to the dashboard instead of the page you were trying to visit after you log in.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set throw errors. (updated 2015-08-25)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 07 Jul 2015 00:00:21 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.1.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.1.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.0.14</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu kernel and packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH:&lt;/strong&gt; Update HAProxy to address &lt;a href=&quot;https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-3281&quot;&gt;CVE-2015-3281&lt;/a&gt;, which could allow an attacker to use a specially crafted request to read memory contents that might contain data from a past request or session.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM:&lt;/strong&gt; Scopeless access tokens could list private Gists.&lt;/li&gt;
&lt;li&gt;This release and previous releases of GitHub Enterprise are not affected by the OpenSSL Advisory issued 9 July 2015 (CVE-2015-1793)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu kernel and packages have been updated to the latest bugfix versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We now gather VMware memory statistics in the diagnostics output.&lt;/li&gt;
&lt;li&gt;Direct root SSH access was not possible in the past, but as an additional measure we&#39;ve also added PermitRootLogin to no within the SSH configuration.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are being logged twice.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 07 Jul 2015 00:00:20 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.0.14</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.0.14</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.4</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu kernel and packages have been updated to the latest bugfix versions.&lt;/li&gt;
&lt;li&gt;Our Collectd checks for enqueued background jobs could cause elevated CPU usage.&lt;/li&gt;
&lt;li&gt;On a Team settings page, the contextual rocket link that site administrators see didn&#39;t properly link to the site admin for the team.&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page served a generic error rather than an informative message.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-resque-info&lt;/code&gt; script incorrectly showed all background job queues as empty.&lt;/li&gt;
&lt;li&gt;In some versions of Internet Explorer 11, creating a repository with a dash in its name crashed the browser. This is a browser bug but we worked around it to avoid the crash.&lt;/li&gt;
&lt;li&gt;Editing a Gist could cause a 500 error. This is an authentication problem between Gist and GitHub Enterprise, so logging out and back in again should fix the problem.&lt;/li&gt;
&lt;li&gt;Expensive Git processes could keep running after the parent Ruby process had died.&lt;/li&gt;
&lt;li&gt;The site admin showed errors in the &#39;repo reflogs&#39; section, which isn&#39;t fully implemented on GitHub Enterprise. We&#39;ve now removed the section. (updated 2015-07-28)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Service hooks may log passwords used for HTTP Basic authentication to disk. (updated 2015-07-28)&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &#39;Starting...&#39; instead.&lt;/li&gt;
&lt;li&gt;Repositories that are in an incomplete state, which is a rare problem, can cause the migration to the new repository disk layout to fail.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;LDAP restricted groups can&#39;t be removed.&lt;/li&gt;
&lt;li&gt;Organization invitation emails are sent from the configured support email address rather than the no-reply address.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;Mail delivery to localhost fails.&lt;/del&gt; (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Promoting a high availability replica can fail if Elasticsearch takes too long to restart.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;The site admin shows errors in the &#39;repo reflogs&#39; section, which isn&#39;t fully implemented on GitHub Enterprise.&lt;/del&gt;&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled. (updated 2015-06-19)&lt;/li&gt;
&lt;li&gt;Using uppercase characters in the hostname causes a redirect loop.  (updated 2015-07-28)&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed. (updated 2015-08-13)&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set throw errors. (updated 2015-08-25)&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Failure to deliver mail to localhost was fixed in 2.2.0. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;The &#39;repo reflogs&#39; section of the site admin was removed in this release.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 16 Jun 2015 00:00:22 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.2.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.1.9</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu kernel and packages have been updated to the latest bugfix versions.&lt;/li&gt;
&lt;li&gt;Avatars, &lt;a href=&quot;https://docs.github.com/enterprise/2.1/user/articles/about-releases/&quot;&gt;release downloads&lt;/a&gt;, and image attachments to wikis and issues were not copied correctly by high availability replication.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu kernel and packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Promoting a high availability replica can fail if Elasticsearch takes too long to restart.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &#39;Starting...&#39; instead.&lt;/li&gt;
&lt;li&gt;Some processes continued to write to logs after they were rotated. This could cause the root file system to fill up.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation disabled.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;Accessing GitHub Enterprise using a hostname alias with private mode enabled as an unauthenticated user will redirect you to the dashboard instead of the page you were trying to visit after you log in.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled. (updated 2015-06-19)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set throw errors. (updated 2015-08-25)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 16 Jun 2015 00:00:21 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.1.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.1.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.0.13</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu kernel and packages have been updated to the latest security versions.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are being logged twice.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 16 Jun 2015 00:00:20 +0000</pubDate>
					<link>https://enterprise.github.com/releases/2.0.13</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.0.13</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.3</title>
					<description>&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We&#39;ve added more graphs to the monitoring dashboard.&lt;/li&gt;
&lt;li&gt;The Linux Out-Of-Memory killer is configured to deprioritize killing MySQL in cases of memory shortage.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Setting up replication now ensures that the replica passes the preflight checks.&lt;/li&gt;
&lt;li&gt;Upgrading to GitHub Enterprise 2.2 with a lot of repositories could be slow due to unnecessary permission changes.&lt;/li&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompted you to upload a license, even though there was already a valid license.&lt;/li&gt;
&lt;li&gt;Creating diagnostics could time out due to large numbers of webhook delivery logs.&lt;/li&gt;
&lt;li&gt;The number of diffs for non-text file types displayed in pull requests was often too small. It&#39;s been increased from 25 to 100.&lt;/li&gt;
&lt;li&gt;Management console monitoring graphs were refreshed too often, and the application server could fail to keep up.&lt;/li&gt;
&lt;li&gt;Checking the high availability Git replication status could throw an error when working out what repositories need to be replicated.&lt;/li&gt;
&lt;li&gt;Upgrading caused private mode to become enabled.&lt;/li&gt;
&lt;li&gt;SAML authentication always provided the optional &lt;code&gt;KeyInfo&lt;/code&gt; element with no signing certificate in the &lt;code&gt;AuthnRequest&lt;/code&gt; response, which caused errors for some identity providers. We don&#39;t include the optional &lt;code&gt;KeyInfo&lt;/code&gt; element at all now.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream were being logged twice.&lt;/li&gt;
&lt;li&gt;Empty Git LFS objects caused errors.&lt;/li&gt;
&lt;li&gt;The Subversion bridge would skip revisions or number them incorrectly.&lt;/li&gt;
&lt;li&gt;Background jobs running during a backup would never be processed if the backup was restored.&lt;/li&gt;
&lt;li&gt;Suspended LDAP users were unsuspended if no LDAP restricted groups were configured.&lt;/li&gt;
&lt;li&gt;We didn&#39;t recognize email addresses with trailing whitespace as valid when inviting users, and showed a confusing error message.&lt;/li&gt;
&lt;li&gt;Enabling Hyper-V Dynamic Memory caused kernel panics.&lt;/li&gt;
&lt;li&gt;A high availability replica set up multiple times could show an out of sync repository as up to date.&lt;/li&gt;
&lt;li&gt;The merge button could break when a high availability replica was promoted to primary.&lt;/li&gt;
&lt;li&gt;Session cookies could become very large and fill the HAProxy buffer when CAS authentication is enabled, causing server errors.&lt;/li&gt;
&lt;li&gt;PubSubHubbub requests could be slow.&lt;/li&gt;
&lt;li&gt;Browsing to the HTTP or HTTPS clone URL didn&#39;t redirect to the repository, which wasn&#39;t consistent with previous versions or GitHub.com.&lt;/li&gt;
&lt;li&gt;On very busy instances, the worker processes delivering webhooks in the background could fall behind. Now there are more worker processes, if you have provisioned enough memory.&lt;/li&gt;
&lt;li&gt;On instances with thousands of users, requests to the discover Gists page could time out.&lt;/li&gt;
&lt;li&gt;The endpoint for marking notifications as read was behind authentication, which caused unneeded traffic and meant that read notifications weren&#39;t correctly archived.&lt;/li&gt;
&lt;li&gt;GitHub Enterprise could become briefly unstable if a Pages site build timed out, for example for very large Pages sites.&lt;/li&gt;
&lt;li&gt;On busy instances, the GitHub application server&#39;s backlog could fill up, causing the web server to time out.&lt;/li&gt;
&lt;li&gt;Git LFS objects were limited to 1 GB. We&#39;ve bumped the limit to 2 GB&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu kernel has been updated to include security fixes.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Service hooks may log passwords used for HTTP Basic authentication to disk. (updated 2015-07-28)&lt;/li&gt;
&lt;li&gt;The site admin shows errors in the &amp;quot;repo reflogs&amp;quot; section, which isn&#39;t fully implemented on GitHub Enterprise.&lt;/li&gt;
&lt;li&gt;Promoting a high availability replica can fail if Elasticsearch takes too long to restart.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Organization invitation emails are sent from the configured support email address rather than the no-reply address.&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &amp;quot;Starting...&amp;quot; instead.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;Mail delivery to localhost fails.&lt;/del&gt; (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes.&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message.&lt;/li&gt;
&lt;li&gt;Enqueued background jobs are sometimes not purged when a repository is deleted.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;We show your gravatar or identicon on Gists instead of your custom profile picture. (updated 2015-06-15)&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-resque-info&lt;/code&gt; script incorrectly shows all background job queues as empty. (updated 2015-06-16)&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled. (updated 2015-06-19)&lt;/li&gt;
&lt;li&gt;Editing a Gist can cause a 500 error. This is an authentication problem between Gist and GitHub Enterprise, so logging out and back in again should fix the problem. (updated 2015-07-15)&lt;/li&gt;
&lt;li&gt;Using uppercase characters in the hostname causes a redirect loop. (updated 2015-07-28)&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed. (updated 2015-08-13)&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set throw errors. (updated 2015-08-25)&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Failure to deliver mail to localhost was fixed in 2.2.0. (updated 2015-07-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 02 Jun 2015 08:00:03 -0700</pubDate>
					<link>https://enterprise.github.com/releases/2.2.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.1.8</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The endpoint for marking notifications as read was behind authentication, which caused unneeded traffic and meant that read notifications weren&#39;t correctly archived.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu kernel has been updated to include security fixes.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Promoting a high availability replica can fail if Elasticsearch takes too long to restart.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &amp;quot;Starting...&amp;quot; instead.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation disabled.&lt;/li&gt;
&lt;li&gt;Some processes continued to write to logs after they were rotated. This could cause the root file system to fill up.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;Accessing GitHub Enterprise using a hostname alias with private mode enabled as an unauthenticated user will redirect you to the dashboard instead of the page you were trying to visit after you log in.&lt;/li&gt;
&lt;li&gt;Individual application logs are not reliably forwarded. (updated 2015-04-20)&lt;/li&gt;
&lt;li&gt;Avatars, &lt;a href=&quot;https://docs.github.com/enterprise/2.1/user/articles/about-releases/&quot;&gt;release downloads&lt;/a&gt;, and image attachments to wikis and issues are not copied correctly by high availability replication. (updated 2015-06-13)&lt;/li&gt;
&lt;li&gt;We show your gravatar or identicon on Gists instead of your custom profile picture. (updated 2015-06-15)&lt;/li&gt;
&lt;li&gt;Repositories with a leading dot in their name fail to replicate if they were created before replication was set up. (updated 2015-06-16)&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled. (updated 2015-06-19)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set throw errors. (updated 2015-08-25)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 02 Jun 2015 08:00:02 -0700</pubDate>
					<link>https://enterprise.github.com/releases/2.1.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.1.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.0.12</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu kernel has been updated to include security fixes.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are being logged twice.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 02 Jun 2015 08:00:01 -0700</pubDate>
					<link>https://enterprise.github.com/releases/2.0.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.0.12</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.2</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu packages have been updated to the latest bug fix versions.&lt;/li&gt;
&lt;li&gt;Upgrading to GitHub Enterprise 2.2 with a lot of repositories could take a very long time.&lt;/li&gt;
&lt;li&gt;Transition to the new repository layout could fail if a repository was missing an owner. We&#39;ve made the transition more resilient to bad data.&lt;/li&gt;
&lt;li&gt;With LDAP authentication enabled, users who renamed their accounts and then had their DN changed couldn&#39;t log in.&lt;/li&gt;
&lt;li&gt;Logging of notification deliveries was extremely verbose, which could put I/O pressure on busy instances.&lt;/li&gt;
&lt;li&gt;Site-wide audit logs didn&#39;t appear in the site admin interface.&lt;/li&gt;
&lt;li&gt;Setting the admin management console password with &lt;code&gt;ghe-set-password&lt;/code&gt; failed.&lt;/li&gt;
&lt;li&gt;When maintenance mode was enabled, we ignored the configured support email address and always showed the default.&lt;/li&gt;
&lt;li&gt;It was not possible to forward logs over IPv6.&lt;/li&gt;
&lt;li&gt;We showed the wrong clone URL when displaying a Gist when subdomain isolation was enabled.&lt;/li&gt;
&lt;li&gt;Elasticsearch wasn&#39;t properly tuned based on available memory.&lt;/li&gt;
&lt;li&gt;Notification, event, and session database entries weren&#39;t properly archived, which could cause those tables to grow very large on busy instances.&lt;/li&gt;
&lt;li&gt;Some valid SSL certificates were incorrectly rejected in the management console.&lt;/li&gt;
&lt;li&gt;Promoting a high availability replica that had previously been a primary could show out of date pages due to a stale cache.&lt;/li&gt;
&lt;li&gt;Pushing large repositories over HTTPS could timeout.&lt;/li&gt;
&lt;li&gt;Some upgrade messages were not shown.&lt;/li&gt;
&lt;li&gt;Replication status did not show queued repositories.&lt;/li&gt;
&lt;li&gt;The activity dashboard graph could dip to zero periodically, creating misleading sawtooth patterns.&lt;/li&gt;
&lt;li&gt;Checking file size limits for Git pushes could be expensive and time consuming.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Unlock repository administrator dialog contained information not relevant to GitHub Enterprise.&lt;/li&gt;
&lt;li&gt;Elasticsearch, Memcached, MySQL, Redis, Nginx, tcpconns and netlink Collectd plugins are now enabled.&lt;/li&gt;
&lt;li&gt;More performance statistics are shown in the administrators&#39; toolbar.&lt;/li&gt;
&lt;li&gt;User sessions are updated less frequently, reducing load on the database.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Ubuntu kernel and packages have been updated to the latest security versions.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;LOW&lt;/strong&gt;: &lt;a href=&quot;https://launchpad.net/ubuntu/+source/openssl/1.0.1-4ubuntu5.27&quot;&gt;OpenSSL 1.0.1-4ubuntu5.27&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Update &lt;code&gt;libssh&lt;/code&gt; to address denial of service vulnerabilities &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8132&quot;&gt;CVE-2014-8132&lt;/a&gt; and &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3145&quot;&gt;CVE-2015-3145&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Repository storage changes&lt;/h2&gt;
&lt;p&gt;Changing the repository storage layout has been improved significantly in this release, cutting down the migration time from hours to minutes. &lt;strong&gt;If your instance contains more than 20,000 repositories (including gists and wikis) you can now upgrade to 2.2.2.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Please refer to the &amp;quot;Repository storage changes&amp;quot; section of the &lt;a href=&quot;https://enterprise.github.com/releases/2.2.0/notes&quot;&gt;2.2.0 release notes&lt;/a&gt; for further advice on upgrading.&lt;/p&gt;
&lt;h2&gt;SAML response requirement changes&lt;/h2&gt;
&lt;p&gt;We&#39;ve improved the validation of the SAML responses we receive. A response message must now contain a &lt;code&gt;Recipient&lt;/code&gt; set to the Assertion Consumer Service URL, &lt;code&gt;http(s)://[hostname]/saml/consume&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;In addition to the &lt;code&gt;Recipient&lt;/code&gt; attribute, GitHub Enterprise will now also verify the &lt;code&gt;Destination&lt;/code&gt; and &lt;code&gt;Audience&lt;/code&gt; attributes, if they are supplied in the response message.&lt;/p&gt;
&lt;p&gt;Most SAML implementations already provide this information in their responses.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Service hooks may log passwords used for HTTP Basic authentication to disk. (updated 2015-07-28)&lt;/li&gt;
&lt;li&gt;Organization invitation emails are sent from the configured support email address rather than the no-reply address.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are being logged twice.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;Mail delivery to localhost fails.&lt;/del&gt; (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Promoting a high availability replica can fail if Elasticsearch takes too long to restart.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &amp;quot;Starting...&amp;quot; instead.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Enabling Hyper-V Dynamic Memory causes kernel panics. (updated 2015-05-30)&lt;/li&gt;
&lt;li&gt;Suspended LDAP users are unsuspended if no LDAP restricted groups are configured. (updated 2015-05-30)&lt;/li&gt;
&lt;li&gt;We show your gravatar or identicon on Gists instead of your custom profile picture. (updated 2015-06-15)&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled. (updated 2015-06-19)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;Editing a Gist can cause a 500 error. This is an authentication problem between Gist and GitHub Enterprise, so logging out and back in again should fix the problem. (updated 2015-07-15)&lt;/li&gt;
&lt;li&gt;Using uppercase characters in the hostname causes a redirect loop. (updated 2015-07-28)&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed. (updated 2015-08-13)&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set throw errors. (updated 2015-08-25)&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Failure to deliver mail to localhost was fixed in 2.2.0. (updated 2015-07-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 19 May 2015 10:30:03 -0700</pubDate>
					<link>https://enterprise.github.com/releases/2.2.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.1.7</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu packages have been updated to the latest bug fix versions.&lt;/li&gt;
&lt;li&gt;With LDAP authentication enabled, users who renamed their accounts and then had their DN changed couldn&#39;t log in.&lt;/li&gt;
&lt;li&gt;LDAP user search in the site admin was limited to 1000 results. This performed poorly when searching some directories, and people are more likely to refine the search than to page through so many results, so it&#39;s now limited to 150 results.&lt;/li&gt;
&lt;li&gt;Setting up static networking could fail when trying to stop the DHCP client.&lt;/li&gt;
&lt;li&gt;Configuring high availability replication incorrectly wrote a key fingerprint to the &lt;code&gt;git&lt;/code&gt; user&#39;s &lt;em&gt;authorized_keys&lt;/em&gt; file, which caused warning messages to be logged on the primary.&lt;/li&gt;
&lt;li&gt;Logging of notification deliveries was extremely verbose, which could put I/O pressure on busy instances.&lt;/li&gt;
&lt;li&gt;When maintenance mode was enabled, we ignored the configured support email address and always showed the default.&lt;/li&gt;
&lt;li&gt;We showed the wrong clone URL when displaying a Gist when subdomain isolation was enabled.&lt;/li&gt;
&lt;li&gt;Elasticsearch wasn&#39;t properly tuned based on available memory.&lt;/li&gt;
&lt;li&gt;Notification, event, and session database entries weren&#39;t properly archived, which could cause those tables to grow very large on busy instances.&lt;/li&gt;
&lt;li&gt;The activity dashboard graph could dip to zero periodically, creating misleading sawtooth patterns.&lt;/li&gt;
&lt;li&gt;Checking file size limits for Git pushes could be expensive and time consuming.&lt;/li&gt;
&lt;li&gt;With LDAP authentication enabled, entering the wrong password could cause a timeout for some users. (updated 2015-09-02)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Ubuntu kernel and packages have been updated to the latest security versions.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;LOW&lt;/strong&gt;: &lt;a href=&quot;https://launchpad.net/ubuntu/+source/openssl/1.0.1-4ubuntu5.27&quot;&gt;OpenSSL 1.0.1-4ubuntu5.27&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Update &lt;code&gt;libssh&lt;/code&gt; to address denial of service vulnerabilities &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8132&quot;&gt;CVE-2014-8132&lt;/a&gt; and &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3145&quot;&gt;CVE-2015-3145&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Disable SSLv2 and SSLv3 in Postfix.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;SAML response validation changes&lt;/h2&gt;
&lt;p&gt;We&#39;ve improved the validation of the SAML responses we receive. A response message must now contain a &lt;code&gt;Recipient&lt;/code&gt; set to the Assertion Consumer Service URL, &lt;code&gt;http(s)://[hostname]/saml/consume&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;In addition to the &lt;code&gt;Recipient&lt;/code&gt; attribute, GitHub Enterprise will now also verify the &lt;code&gt;Destination&lt;/code&gt; and &lt;code&gt;Audience&lt;/code&gt; attributes, if they are supplied in the response message.&lt;/p&gt;
&lt;p&gt;Most SAML implementations already provide this information in their responses.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are being logged twice.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;LDAP Sync fails for groups that have a period in their CN.&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;It&#39;s not possible to convert a user account to an organization.&lt;/li&gt;
&lt;li&gt;Accessing GitHub Enterprise using a hostname alias with private mode enabled as an unauthenticated user will redirect you to the dashboard instead of the page you were trying to visit after you log in.&lt;/li&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &amp;quot;Starting...&amp;quot; instead.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation disabled.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;Some processes continued to write to logs after they were rotated. This could cause the root file system to fill up.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Promoting a high availability replica can fail if Elasticsearch takes too long to restart.&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists, which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;Accessing GitHub Enterprise using a hostname alias with private mode enabled as an unauthenticated user will redirect you to the dashboard instead of the page you were trying to visit after you log in.&lt;/li&gt;
&lt;li&gt;Individual application logs are not reliably forwarded. (updated 2015-04-20)&lt;/li&gt;
&lt;li&gt;Avatars, &lt;a href=&quot;https://docs.github.com/enterprise/2.1/user/articles/about-releases/&quot;&gt;release downloads&lt;/a&gt;, and image attachments to wikis and issues are not copied correctly by high availability replication. (updated 2015-05-20)&lt;/li&gt;
&lt;li&gt;We show your gravatar or identicon on Gists instead of your custom profile picture. (updated 2015-06-15)&lt;/li&gt;
&lt;li&gt;Repositories with a leading dot in their name fail to replicate if they were created before replication was set up. (updated 2015-06-16)&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled. (updated 2015-06-19)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set throw errors. (updated 2015-08-25)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 19 May 2015 10:30:02 -0700</pubDate>
					<link>https://enterprise.github.com/releases/2.1.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.1.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.0.11</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Ubuntu kernel and packages have been updated to the latest security versions.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;LOW&lt;/strong&gt;: &lt;a href=&quot;https://launchpad.net/ubuntu/+source/openssl/1.0.1-4ubuntu5.27&quot;&gt;OpenSSL 1.0.1-4ubuntu5.27&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Update &lt;code&gt;libssh&lt;/code&gt; to address denial of service vulnerabilities &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8132&quot;&gt;CVE-2014-8132&lt;/a&gt; and &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-3145&quot;&gt;CVE-2015-3145&lt;/a&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are being logged twice.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 19 May 2015 10:30:01 -0700</pubDate>
					<link>https://enterprise.github.com/releases/2.0.11</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.0.11</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.1</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu packages have been updated to the latest bugfix versions.&lt;/li&gt;
&lt;li&gt;Multibyte characters in management console configuration options caused an error when saving settings.&lt;/li&gt;
&lt;li&gt;SSH public keys with the = character would not allow administrative SSH access to the instance.&lt;/li&gt;
&lt;li&gt;Upgrading a replica showed harmless syntax errors.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Service hooks may log passwords used for HTTP Basic authentication to disk. (updated 2015-07-28)&lt;/li&gt;
&lt;li&gt;Upgrading to GitHub Enterprise 2.2 with a lot of repositories can take a very long time.&lt;/li&gt;
&lt;li&gt;We show the wrong clone URL when displaying a Gist when subdomain isolation is disabled.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;Mail delivery to localhost fails.&lt;/del&gt; (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Organization invitation emails are sent from the support email address rather than the noreply email address.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &amp;quot;Starting...&amp;quot; instead.&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;It is not possible to forward logs over IPv6. (updated 2015-05-07)&lt;/li&gt;
&lt;li&gt;Site-wide audit logs do not appear in the site admin interface. (updated 2015-05-14)&lt;/li&gt;
&lt;li&gt;Setting the admin SSH password with &lt;code&gt;ghe-set-password&lt;/code&gt; fails. (updated 2015-05-19)&lt;/li&gt;
&lt;li&gt;Enabling Hyper-V Dynamic Memory causes kernel panics. (updated 2015-05-30)&lt;/li&gt;
&lt;li&gt;Suspended LDAP users are unsuspended if no LDAP restricted groups are configured. (updated 2015-05-30)&lt;/li&gt;
&lt;li&gt;We show your gravatar or identicon on Gists instead of your custom profile picture. (updated 2015-06-15)&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled. (updated 2015-06-19)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;Editing a Gist can cause a 500 error. This is an authentication problem between Gist and GitHub Enterprise, so logging out and back in again should fix the problem. (updated 2015-07-15)&lt;/li&gt;
&lt;li&gt;Using uppercase characters in the hostname causes a redirect loop. (updated 2015-07-28)&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed. (updated 2015-08-13)&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set throw errors. (updated 2015-08-25)&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Failure to deliver mail to localhost was fixed in 2.2.0. (updated 2015-07-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 05 May 2015 12:00:00 -0700</pubDate>
					<link>https://enterprise.github.com/releases/2.2.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.2.0</title>
					<description>&lt;h2&gt;New Features&lt;/h2&gt;
&lt;p&gt;With the new features added in GitHub Enterprise 2.2.0, you can:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Connect to your GitHub repositories in &lt;a href=&quot;https://github.com/blog/1989-improving-the-github-workflow-for-the-microsoft-community&quot;&gt;Visual Studio 2015&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Deploy GitHub Enterprise on &lt;a href=&quot;https://docs.github.com/enterprise/2.2/admin/guides/installation/installing-github-enterprise-on-azure&quot;&gt;Azure&lt;/a&gt;, &lt;a href=&quot;https://docs.github.com/enterprise/2.2/admin/guides/installation/installing-github-enterprise-on-hyper-v&quot;&gt;Hyper-V&lt;/a&gt; and &lt;a href=&quot;https://docs.github.com/enterprise/2.2/admin/guides/installation/installing-github-enterprise-on-xenserver&quot;&gt;XenServer&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Version large files with &lt;a href=&quot;https://github.com/blog/1986-announcing-git-large-file-storage-lfs&quot;&gt;Git LFS&lt;/a&gt;. This is an early access technical preview, and is not recommended for production use. (updated 2015-07-29)&lt;/li&gt;
&lt;li&gt;Commit and propose changes faster with &lt;a href=&quot;https://github.com/blog/1945-quick-pull-requests&quot;&gt;quick pull requests&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1974-pdf-viewing&quot;&gt;View PDFs&lt;/a&gt; in your repositories.&lt;/li&gt;
&lt;li&gt;View &lt;a href=&quot;https://github.com/blog/1976-introducing-mobile-web-notifications&quot;&gt;notifications&lt;/a&gt; on your mobile device.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1977-navigate-branches-from-your-phone&quot;&gt;Navigate branches&lt;/a&gt; from your mobile device.&lt;/li&gt;
&lt;li&gt;Communicate with your users using a site-wide banner.&lt;/li&gt;
&lt;li&gt;Determine repository licenses using the &lt;a href=&quot;https://developer.github.com/enterprise/2.2/v3/licenses/&quot;&gt;Repository licensing API&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.2/admin/guides/installation/upgrading-the-github-enterprise-virtual-machine/#restoring-from-a-failed-upgrade&quot;&gt;Roll back&lt;/a&gt; a failed or interrupted upgrade.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We recommend a minimum of 16 GB RAM be provisioned for the GitHub Enterprise virtual machine. We now &lt;strong&gt;enforce a minimum amount of RAM&lt;/strong&gt;. (updated 2015-05-04)&lt;/li&gt;
&lt;li&gt;The way we store repositories has been changed to improve disk usage.&lt;/li&gt;
&lt;li&gt;The undocumented &lt;code&gt;site/stats&lt;/code&gt; API endpoint has been removed.&lt;/li&gt;
&lt;li&gt;We&#39;ve moved to using &lt;em&gt;syslog-ng&lt;/em&gt; for the system logger, which drops support for RELP. Log forwarding will be disabled if you used RELP prior to upgrading.&lt;/li&gt;
&lt;li&gt;We didn&#39;t add files larger than 384 KB to the search index. We&#39;ve now bumped this limit to 10 MB.&lt;/li&gt;
&lt;li&gt;When using &lt;a href=&quot;https://docs.github.com/enterprise/2.2/admin/guides/user-management/using-ldap/&quot;&gt;LDAP authentication&lt;/a&gt;, user account suspension is managed by using restricted group membership. Users will be suspended or unsuspended based on their membership at login. If LDAP Sync is enabled, this process will happen automatically during a synchronization run. (updated 2015-05-21)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/enterprise/2.2/admin/guides/user-management/using-ldap/#enabling-ldap-sync&quot;&gt;LDAP Sync&lt;/a&gt; shows a team error indicator when an LDAP Group isn&#39;t found.&lt;/li&gt;
&lt;li&gt;New users will be added to their &lt;a href=&quot;https://docs.github.com/enterprise/2.2/admin/guides/user-management/creating-teams/#creating-teams-with-ldap-sync-enabled&quot;&gt;LDAP Sync-enabled teams&lt;/a&gt; when they log in for the first time. (updated 2015-05-08)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu packages have been updated to the latest bugfix versions.&lt;/li&gt;
&lt;li&gt;We didn&#39;t give much feedback during an upgrade, so it was hard to know if it was still progressing as expected. We include the current upgrade status on the starting page now.&lt;/li&gt;
&lt;li&gt;Setting up static networking could fail in some circumstances.&lt;/li&gt;
&lt;li&gt;LDAP user search in the site admin was limited to 1000 results. This performed poorly when searching some directories, and people are more likely to refine the search than to page through so many results, so it&#39;s now limited to 150 results.&lt;/li&gt;
&lt;li&gt;With SAML authentication configured, signing out and signing in again could redirect you to a page saying you were still signed out.&lt;/li&gt;
&lt;li&gt;When a new organization was created with LDAP sync enabled, we showed an incorrect hint about importing teams.&lt;/li&gt;
&lt;li&gt;LDAP users could not be suspended or renamed when LDAP sync was off.&lt;/li&gt;
&lt;li&gt;The Owners team was not automatically removed from LDAP sync.&lt;/li&gt;
&lt;li&gt;LDAP sync didn&#39;t sync members of a group where the LDAP group name contained a dot (&lt;code&gt;.&lt;/code&gt;).&lt;/li&gt;
&lt;li&gt;Wiki files larger than 500 KB were cut off when they were served, which could result in large images not loading completely.&lt;/li&gt;
&lt;li&gt;The &lt;a href=&quot;https://docs.github.com/enterprise/admin/articles/command-line-utilities/#btop&quot;&gt;&lt;code&gt;ghe-btop&lt;/code&gt; command line utility&lt;/a&gt; incorrectly dropped &lt;code&gt;--help&lt;/code&gt; and &lt;code&gt;--usage&lt;/code&gt; flags.&lt;/li&gt;
&lt;li&gt;WOFF 2.0 font files did not have their &lt;code&gt;content-type&lt;/code&gt; header set correctly in Pages.&lt;/li&gt;
&lt;li&gt;The top OAuth applications list in the site admin didn&#39;t load.&lt;/li&gt;
&lt;li&gt;Replication needed to be be set up again after upgrading a high availability replica. We restart replication automatically now.&lt;/li&gt;
&lt;li&gt;Under some circumstances, application services didn&#39;t restart properly. This could happen when restoring a backup to a new instance, which could cause a redirect to the old host if it had a different hostname, or when uploading a new license, which caused the old license to be used on some requests.&lt;/li&gt;
&lt;li&gt;CoffeeScript in GitHub Pages sites caused build failures.&lt;/li&gt;
&lt;li&gt;Converting a user to an organization failed with a billing plan error, which shouldn&#39;t have been in effect on GitHub Enterprise.&lt;/li&gt;
&lt;li&gt;Some API endpoints could leak the existence of a private repository.&lt;/li&gt;
&lt;li&gt;A complex series of actions could cause a user&#39;s profile page to load in place of their contributions graph on their profile page; profile page inception.&lt;/li&gt;
&lt;li&gt;MySQL could recycle unique IDs after rebooting GitHub Enterprise. This could lead to strange behavior if you delete the most recently created repository, reboot, then create a new repository.&lt;/li&gt;
&lt;li&gt;Removing admin SSH keys with invisible characters via the Management Console failed silently.&lt;/li&gt;
&lt;li&gt;Git replication could be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;Events in the &lt;em&gt;github_audit&lt;/em&gt; log stream were logged twice.&lt;/li&gt;
&lt;li&gt;Management Console sessions would timeout when accessing GitHub Enterprise in another tab.&lt;/li&gt;
&lt;li&gt;Bad SSL certificates could slip by validation.&lt;/li&gt;
&lt;li&gt;Creating the OpenVPN connection could fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;Git clients could display intermittent &amp;quot;fatal: protocol error: bad pack header&amp;quot; messages when garbage collection ran while fetching a pack file that was bigger than a configured memory limit. (updated 2015-05-06)&lt;/li&gt;
&lt;li&gt;Avatars, &lt;a href=&quot;https://docs.github.com/enterprise/2.1/user/articles/about-releases/&quot;&gt;release downloads&lt;/a&gt;, and image attachments to wikis and issues were not copied correctly by high availability replication. (updated 2015-05-20)&lt;/li&gt;
&lt;li&gt;Repositories with a leading dot in their name failed to replicate if they were created before replication was set up. (updated 2015-06-16)&lt;/li&gt;
&lt;li&gt;Mail delivery to localhost failed. (updated 2015-07-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu packages have been updated to the latest security fix versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Disable SSLv2 and SSLv3 in Postfix.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Repository storage changes&lt;/h2&gt;
&lt;p&gt;This release changes the way GitHub Enterprise stores repositories, which reduces disk usage by sharing Git objects between forks and improves caching performance when reading repository data. This is a major change, and has some implications you need to be aware of.&lt;/p&gt;
&lt;p&gt;&lt;del&gt;Changing the repository storage layout can take several hours if your instance contains many repositories. We&#39;re working on making this faster so if your instance contains more than 20,000 repositories (including gists and wikis) we do not recommend upgrading to GitHub Enterprise 2.2 until further notice.&lt;/del&gt; &lt;strong&gt;Everyone should now upgrade to GitHub Enterprise 2.2.2 or later, as the migration process has been made significantly faster&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;You can check how many repositories you have using the &lt;a href=&quot;https://developer.github.com/enterprise/2.2/v3/enterprise/admin_stats/#get-statistics&quot;&gt;Admin Stats API&lt;/a&gt;. For example, you can SSH into the VM and run the following command, then add together &amp;quot;total_repos&amp;quot;, &amp;quot;total_wikis&amp;quot;, and &amp;quot;total_gists&amp;quot;:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;curl -s http://127.0.0.1:1337/api/v3/enterprise/stats/all
&lt;/code&gt;&lt;/pre&gt;
&lt;h3&gt;Before upgrading&lt;/h3&gt;
&lt;p&gt;As a precaution, before your upgrade you should take a &lt;a href=&quot;https://github.com/github/backup-utils&quot;&gt;backup-utils&lt;/a&gt; snapshot after putting the instance in maintenance mode. We also recommend taking a disk snapshot of the user data volume.&lt;/p&gt;
&lt;h3&gt;Upgrading&lt;/h3&gt;
&lt;p&gt;The upgrade process takes care of moving repository data from the existing storage layout to the new storage layout. If you have a large amount of repository data moving the data can take some time, so we recommend that you test the upgrade on a staging instance first. You can use the test upgrade to make an estimate of how long of a maintenance window you&#39;ll need for your production instance.&lt;/p&gt;
&lt;p&gt;After upgrading, you may notice a large number of background jobs being processed. Each job is optimizing a repository for the new storage layout, but uses a high &lt;code&gt;nice&lt;/code&gt; value, so should have minimal impact on performance. The jobs will be enqueued in the &lt;code&gt;maint_localhost&lt;/code&gt; jobs queue, which may have a large backlog, but it&#39;s a dedicated queue and won&#39;t block other jobs from completing.&lt;/p&gt;
&lt;h3&gt;Repository backups&lt;/h3&gt;
&lt;p&gt;For compatibility with the new repository layout, you need to upgrade &lt;a href=&quot;https://github.com/github/backup-utils&quot;&gt;backup-utils&lt;/a&gt; to version 2.2.&lt;/p&gt;
&lt;p&gt;The first update taken after you upgrade will be a full backup rather than an incremental backup. This means it will take more disk space and more time to complete. Subsequent backups will be incremental again.&lt;/p&gt;
&lt;h3&gt;Other implications of the change&lt;/h3&gt;
&lt;p&gt;Some customers routinely ran Git garbage collection on their repositories. The existing repository layout maps nicely to what you can see in the user interface, so you could easily find a repository on disk at &lt;em&gt;/data/repositories/[owner]/[repository].git&lt;/em&gt;. This is no longer the case with the new repository layout, but it does let us be smarter about running garbage collection, so running it manually shouldn&#39;t be necessary.&lt;/p&gt;
&lt;p&gt;So that they could be restored if necessary, deleted repositories were previously moved to the &lt;em&gt;/data/repositories/__purgatory__&lt;/em&gt; directory. This special area for archived repositories is no longer needed or used. Repositories are kept in their normal location until purged three months after being archived.&lt;/p&gt;
&lt;p&gt;Please &lt;a href=&quot;https://enterprise.github.com/support&quot;&gt;contact Enterprise Support&lt;/a&gt; if you have any questions about this change.&lt;/p&gt;
&lt;h2&gt;Snapshot and rollback recommendations&lt;/h2&gt;
&lt;p&gt;Due to the invasive changes in the repository disk layout in GitHub Enterprise 2.2, we strongly recommend reading the &lt;a href=&quot;https://docs.github.com/enterprise/2.2/admin/guides/installation/upgrading-to-github-enterprise-2-2/&quot;&gt;upgrade guide&lt;/a&gt; prior to upgrading your virtual machine.  This provides information about using snapshots and rolling back to a pre-upgrade state in the event an upgrade fails or is interrupted.&lt;/p&gt;
&lt;h2&gt;Upcoming deprecation of authentication using GitHub OAuth&lt;/h2&gt;
&lt;p&gt;User authentication via &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/user-management/using-github-oauth/&quot;&gt;GitHub OAuth&lt;/a&gt; is being deprecated and will be removed in a future feature release. It will be removed &lt;strong&gt;no sooner than November 2015&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;GitHub Enterprise includes support for authenticating users via OAuth to accounts on GitHub.com because it provides a simple way to set up external authentication. However, after speaking with many customers, we&#39;ve found that organizations commonly have other sources they want to use to automate identity and access management.&lt;/p&gt;
&lt;p&gt;We want to focus on features that best meet the needs of our users, so we&#39;re planning to remove support for GitHub OAuth in a future feature release and focus on making ongoing improvements to other authentication methods like &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/user-management/using-saml/&quot;&gt;SAML&lt;/a&gt; and &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/user-management/using-ldap/&quot;&gt;LDAP&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Note that this change will only affect user authentication via GitHub.com and not personal access tokens or OAuth applications added to your GitHub Enterprise instance.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Service hooks may log passwords used for HTTP Basic authentication to disk. (updated 2015-07-28)&lt;/li&gt;
&lt;li&gt;The management console incorrectly strips the &lt;code&gt;=&lt;/code&gt; character from new and current administrative SSH keys when adding or removing keys.  This will cause administrative SSH access to the instance to fail for those keys.&lt;/li&gt;
&lt;li&gt;Upgrading to GitHub Enterprise 2.2 with a lot of repositories can take a very long time.&lt;/li&gt;
&lt;li&gt;We show the wrong clone URL when displaying a Gist when subdomain isolation is disabled.&lt;/li&gt;
&lt;li&gt;Gist repositories are not garbage collected by the maintenance scheduler.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;Mail delivery to localhost fails.&lt;/del&gt; (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;Deleting a user doesn&#39;t delete their gists which can cause problems with replication.&lt;/li&gt;
&lt;li&gt;In our instructions to merge a pull request on the command line, we show the steps to merge using the Git protocol even when private mode is on. Private mode forces authentication but the Git protocol is unauthenticated so the steps will always fail. We also don&#39;t show the steps to merge using SSH.&lt;/li&gt;
&lt;li&gt;We incorrectly redirect to the dashboard if you access GitHub Enterprise using an alias while in private mode. This might happen if you set a fully qualified domain name but the subdomain resolves correctly.&lt;/li&gt;
&lt;li&gt;Organization invitation emails are sent from the support email address rather than the noreply email address.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation is disabled.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &amp;quot;Starting...&amp;quot; instead.&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;It is not possible to forward logs over IPv6. (updated 2015-05-07)&lt;/li&gt;
&lt;li&gt;Site-wide audit logs do not appear in the site admin interface. (updated 2015-05-14)&lt;/li&gt;
&lt;li&gt;Setting the admin SSH password with &lt;code&gt;ghe-set-password&lt;/code&gt; fails. (updated 2015-05-19)&lt;/li&gt;
&lt;li&gt;Enabling Hyper-V Dynamic Memory causes kernel panics. (updated 2015-05-30)&lt;/li&gt;
&lt;li&gt;Suspended LDAP users are unsuspended if no LDAP restricted groups are configured. (updated 2015-05-30)&lt;/li&gt;
&lt;li&gt;We show your gravatar or identicon on Gists instead of your custom profile picture. (updated 2015-06-15)&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled. (updated 2015-06-19)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;Editing a Gist can cause a 500 error. This is an authentication problem between Gist and GitHub Enterprise, so logging out and back in again should fix the problem. (updated 2015-07-15)&lt;/li&gt;
&lt;li&gt;Using uppercase characters in the hostname causes a redirect loop. (updated 2015-07-28)&lt;/li&gt;
&lt;li&gt;When a fork is detached from its repository network by an administrator or by &lt;a href=&quot;https://docs.github.com/enterprise/user/articles/what-happens-to-forks-when-a-repository-is-deleted-or-changes-visibility/&quot;&gt;changing visibility&lt;/a&gt;, its filesystem path won&#39;t be updated on a high availability replica until at least one commit has been pushed. (updated 2015-08-13)&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set throw errors. (updated 2015-08-25)&lt;/li&gt;
&lt;li&gt;Viewing raw files in repositories owned by a user or organization named &amp;quot;github&amp;quot; fails with a 400 error. (updated 2015-12-15)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Failure to deliver mail to localhost was fixed in 2.2.0. (updated 2015-07-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Wed, 29 Apr 2015 11:00:00 -0700</pubDate>
					<link>https://enterprise.github.com/releases/2.2.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.2.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.1.6</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The organisation creation page gave incorrect details about when LDAP groups could be synced as teams.&lt;/li&gt;
&lt;li&gt;LDAP users could not be suspended or renamed when LDAP sync was off.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-btop&lt;/code&gt;&#39;s &lt;code&gt;--usage&lt;/code&gt; and &lt;code&gt;--help&lt;/code&gt; flags were not being passed correctly.&lt;/li&gt;
&lt;li&gt;WOFF 2.0 font files did not have their content-type set correctly in Pages.&lt;/li&gt;
&lt;li&gt;The top third party OAuth applications were not displayed.&lt;/li&gt;
&lt;li&gt;The Owners team was not automatically removed from LDAP sync.&lt;/li&gt;
&lt;li&gt;Replication was not restarted automatically after an upgrade.&lt;/li&gt;
&lt;li&gt;Unicorn masters were not always restarted correctly which left behind stale processes.&lt;/li&gt;
&lt;li&gt;LDAP sync wasn&#39;t syncing members of a group where the LDAP group name contained a &lt;code&gt;.&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-repl-setup&lt;/code&gt; did not warn if the master had an existing replica.&lt;/li&gt;
&lt;li&gt;The system did not always shut down cleanly due to using &lt;code&gt;kexec&lt;/code&gt; rather than &lt;code&gt;reboot&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-service-list&lt;/code&gt; did not list &lt;code&gt;github-svn-proxy&lt;/code&gt; or &lt;code&gt;github-timerd&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;resqued&lt;/code&gt;, &lt;code&gt;svn-proxy&lt;/code&gt; and &lt;code&gt;timerd&lt;/code&gt; held on to a deleted log file rather than rotating correctly.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: &lt;a href=&quot;https://www.ruby-lang.org/en/news/2015/04/13/ruby-2-1-6-released/&quot;&gt;Ruby 2.1.6&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Branch names were not escaped correctly so could allow a XSS vulnerability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: A bug in URL parsing in Safari could allow the bypass of the same origin checks in JavaScript.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are being logged twice.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation disabled.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &amp;quot;Starting...&amp;quot; instead.&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;It&#39;s not possible to convert a user account to an organization.&lt;/li&gt;
&lt;li&gt;Accessing GitHub Enterprise using a hostname alias with private mode enabled as an unauthenticated user will redirect you to the dashboard instead of the page you were trying to visit after you log in.&lt;/li&gt;
&lt;li&gt;Individual application logs are not reliably forwarded. (updated 2015-04-20)&lt;/li&gt;
&lt;li&gt;Avatars, &lt;a href=&quot;https://docs.github.com/enterprise/2.1/user/articles/about-releases/&quot;&gt;release downloads&lt;/a&gt;, and image attachments to wikis and issues are not copied correctly by high availability replication. (updated 2015-05-20)&lt;/li&gt;
&lt;li&gt;We show your gravatar or identicon on Gists instead of your custom profile picture. (updated 2015-06-15)&lt;/li&gt;
&lt;li&gt;Repositories with a leading dot in their name fail to replicate if they were created before replication was set up. (updated 2015-06-16)&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled. (updated 2015-06-19)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set throw errors. (updated 2015-08-25)&lt;/li&gt;
&lt;li&gt;With LDAP authentication enabled, entering the wrong password can cause a timeout for some users. (updated 2015-09-02)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 21 Apr 2015 10:15:00 -0700</pubDate>
					<link>https://enterprise.github.com/releases/2.1.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.1.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.0.10</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: &lt;a href=&quot;https://www.ruby-lang.org/en/news/2015/04/13/ruby-2-1-6-released/&quot;&gt;Ruby 2.1.6&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Note the 2.0.x releases are not susceptible to the XSS vulnerability mentioned in the 2.1.6 release notes.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are being logged twice.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 21 Apr 2015 10:15:00 -0700</pubDate>
					<link>https://enterprise.github.com/releases/2.0.10</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.0.10</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.354</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: &lt;a href=&quot;https://launchpad.net/ubuntu/+source/openssl/1.0.1-4ubuntu5.25&quot;&gt;OpenSSL 1.0.1-4ubuntu5.25&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Release series end of life&lt;/h2&gt;
&lt;p&gt;The 11.10.354 release is part of the 11.10.340 release series. No more security patches will be released in this series after 7 July 2015, even for critical security issues. All customers are encouraged to &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/migrating-to-a-different-platform-or-from-github-enterprise-11-10-34x/&quot;&gt;upgrade&lt;/a&gt; to the &lt;a href=&quot;https://enterprise.github.com/download&quot;&gt;latest release&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 24 Mar 2015 10:22:13 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.354</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.354</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.0.9</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;One of the Percona database tools we ship with the VM was phoning home to check for updates.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Using an access token with &lt;code&gt;public_repo&lt;/code&gt; scope, requests for lists of issues would return issues from private repositories.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: &lt;a href=&quot;https://launchpad.net/ubuntu/+source/openssl/1.0.1-4ubuntu5.25&quot;&gt;OpenSSL 1.0.1-4ubuntu5.25&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Integration with GitHub for Mac&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;For reasons outside our control, the implementation behind the &amp;quot;Clone in desktop&amp;quot; button for GitHub for Mac doesn&#39;t work any more. We now use the same method for both desktop applications and check you have an application configured. This means we&#39;ll only show the button when you&#39;re logged in.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are being logged twice.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Individual application logs are not reliably forwarded. (updated 2015-04-20)&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 24 Mar 2015 10:22:12 -0700</pubDate>
					<link>https://enterprise.github.com/releases/2.0.9</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.0.9</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.1.5</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Pull requests didn&#39;t properly trigger repository replication.&lt;/li&gt;
&lt;li&gt;In rare circumstances, Git clients displayed a misleading repository corruption message when garbage collection ran while fetching a pack file that was bigger than a configured memory limit. We&#39;ve bumped up the configured memory limit to make that situation even less likely.&lt;/li&gt;
&lt;li&gt;If the credentials of the LDAP bind user became incorrect—for example, if a password expired—LDAP sync incorrectly removed users from teams. If those users had forks of private repositories, the forks were deleted.&lt;/li&gt;
&lt;li&gt;We incorrectly performed some LDAP searches as the authenticating user instead of the LDAP bind user. This user might have less access than the bind user, which could cause errors.&lt;/li&gt;
&lt;li&gt;The user API only returned a user&#39;s LDAP mapping if LDAP sync was enabled.&lt;/li&gt;
&lt;li&gt;We added support for the &amp;quot;SSH&amp;quot; and &amp;quot;SSHKey&amp;quot; prefixes for ActiveDirectory&#39;s &lt;code&gt;altSecurityIdentities&lt;/code&gt; attributes.&lt;/li&gt;
&lt;li&gt;With LDAP Sync enabled, it was possible to set the special Owners team to sync with an LDAP group, but the sync couldn&#39;t complete. We disable syncing the Owners team now.&lt;/li&gt;
&lt;li&gt;When LDAP Sync was set to sync emails, we showed a banner message suggesting users add an email address even though they couldn&#39;t.&lt;/li&gt;
&lt;li&gt;Inviting a user to join an organization could return a &amp;quot;Not found&amp;quot; error when all the teams in an organization were mapped to LDAP groups and the invited user wasn&#39;t already a member of another team.&lt;/li&gt;
&lt;li&gt;After configuring a fresh instance to use static networking, we could still request a DHCP lease. Restarting the VM stopped the DHCP requests, but we fixed the problem and don&#39;t ask for a lease now.&lt;/li&gt;
&lt;li&gt;When saving settings, the &amp;quot;Restarting system services&amp;quot; spinner could keep spinning even after the services had restarted properly.&lt;/li&gt;
&lt;li&gt;The HAProxy logs were rotated weekly, so on busy instances they could get very large. We rotate them daily now.&lt;/li&gt;
&lt;li&gt;We kept too many logs for webhooks, which slowed stuff down. We purge older logs now.&lt;/li&gt;
&lt;li&gt;Some network setups made browsers send headers too big for us to handle, causing a &amp;quot;Request header or cookie too large&amp;quot; error. We&#39;ve made our header buffers bigger.&lt;/li&gt;
&lt;li&gt;We added some flags to the &lt;code&gt;ghe-support-bundle&lt;/code&gt; command line utility to make it possible to upload a support bundle directly to GitHub from the VM.&lt;/li&gt;
&lt;li&gt;Email hooks were incorrectly sent from &amp;quot;&lt;a href=&quot;mailto:noreply@github.com&quot;&gt;noreply@github.com&lt;/a&gt;&amp;quot; if &amp;quot;Send from author&amp;quot; wasn&#39;t selected. Some email services would reject those emails, making it seem like the hook was failing.&lt;/li&gt;
&lt;li&gt;One of the Percona database tools we ship with the VM was phoning home to check for updates.&lt;/li&gt;
&lt;li&gt;When the Status API was used to set a pending status on a pull request, we incorrectly said some checks had failed.&lt;/li&gt;
&lt;li&gt;There was a race condition in our assets server, which delivers resources like profile pictures and downloads, that could cause file handle leakage. If that happened, performance could be degraded. (updated 2015-03-25)&lt;/li&gt;
&lt;li&gt;Chrome 42 users weren&#39;t able to edit wiki pages or upload images via drag and drop, and autocomplete menus and repository graphs didn&#39;t display. (updated 2015-05-06)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Using an access token with &lt;code&gt;public_repo&lt;/code&gt; scope, requests for lists of issues would return issues from private repositories.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: &lt;a href=&quot;https://launchpad.net/ubuntu/+source/openssl/1.0.1-4ubuntu5.25&quot;&gt;OpenSSL 1.0.1-4ubuntu5.25&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Integration with GitHub for Mac&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;For reasons outside our control, the implementation behind the &amp;quot;Clone in desktop&amp;quot; button for GitHub for Mac doesn&#39;t work any more. We now use the same method for both desktop applications and check you have an application configured. This means we&#39;ll only show the button when you&#39;re logged in.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are being logged twice.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation disabled.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &amp;quot;Starting...&amp;quot; instead.&lt;/li&gt;
&lt;li&gt;LDAP Sync fails for groups that have a period in their CN.&lt;/li&gt;
&lt;li&gt;Replication setup fails for IPv6 hosts.&lt;/li&gt;
&lt;li&gt;It&#39;s not possible to convert a user account to an organization.&lt;/li&gt;
&lt;li&gt;Accessing GitHub Enterprise using a hostname alias with private mode enabled as an unauthenticated user will redirect you to the dashboard instead of the page you were trying to visit after you log in.&lt;/li&gt;
&lt;li&gt;Can&#39;t suspend or rename users when LDAP Sync is off. (updated 2015-04-20)&lt;/li&gt;
&lt;li&gt;Individual application logs are not reliably forwarded. (updated 2015-04-20)&lt;/li&gt;
&lt;li&gt;Avatars, &lt;a href=&quot;https://docs.github.com/enterprise/2.1/user/articles/about-releases/&quot;&gt;release downloads&lt;/a&gt;, and image attachments to wikis and issues are not copied correctly by high availability replication. (updated 2015-05-20)&lt;/li&gt;
&lt;li&gt;We show your gravatar or identicon on Gists instead of your custom profile picture. (updated 2015-06-15)&lt;/li&gt;
&lt;li&gt;Repositories with a leading dot in their name fail to replicate if they were created before replication was set up. (updated 2015-06-16)&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled. (updated 2015-06-19)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set throw errors. (updated 2015-08-25)&lt;/li&gt;
&lt;li&gt;With LDAP authentication enabled, entering the wrong password can cause a timeout for some users. (updated 2015-09-02)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Tue, 24 Mar 2015 10:22:10 -0700</pubDate>
					<link>https://enterprise.github.com/releases/2.1.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.1.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.353</title>
					<description>&lt;h2&gt;GitHub Enterprise 11.10.353 Update Released&lt;/h2&gt;
&lt;p&gt;The 11.10.353 release for GitHub Enterprise is now available for download from &lt;a href=&quot;https://enterprise.github.com/download&quot;&gt;https://enterprise.github.com/download&lt;/a&gt;. The full release notes for 11.10.353 follow:&lt;/p&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: OpenSSL 1.0.1-4ubuntu5.21 (&lt;a href=&quot;https://freakattack.com&quot;&gt;https://freakattack.com&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;FREAK attack&lt;/h3&gt;
&lt;p&gt;Researchers from INRIA, Microsoft Research and IMDEA have discovered a vulnerability that can cause affected servers to use weakened encryption on SSL connections, making it easier for an attacker with access to the connection to decrypt the communication.&lt;/p&gt;
&lt;p&gt;GitHub Enterprise versions 2.0.7, 2.1.0 and newer are not vulnerable to this attack as they were already updated to OpenSSL 1.0.1-4ubuntu5.21 before this attack was published.&lt;/p&gt;
&lt;h2&gt;Release series end of life&lt;/h2&gt;
&lt;p&gt;The 11.10.353 release is part of the 11.10.340 release series. No more security patches will be released in this series after 7 July 2015, even for critical security issues. All customers are encouraged to &lt;a href=&quot;https://docs.github.com/enterprise/admin/guides/installation/migrating-to-a-different-platform-or-from-github-enterprise-11-10-34x/&quot;&gt;upgrade&lt;/a&gt; to the &lt;a href=&quot;https://enterprise.github.com/download&quot;&gt;latest release&lt;/a&gt;.&lt;/p&gt;</description>
					<pubDate>Tue, 10 Mar 2015 02:30:28 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.353</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.353</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.0.8</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu packages have been updated to the latest security versions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: There was an XSS vulnerability in wikis.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: We didn&#39;t require SAML responses to be signed. We enforce that now.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are being logged twice.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Individual application logs are not reliably forwarded. (updated 2015-04-20)&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Tue, 03 Mar 2015 09:41:19 -0800</pubDate>
					<link>https://enterprise.github.com/releases/2.0.8</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.0.8</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.1.4</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu packages have been updated to the latest bugfix/security versions.&lt;/li&gt;
&lt;li&gt;Enabling LDAP Sync for emails could cause background jobs to be continuously queued, which in turn could affect performance.&lt;/li&gt;
&lt;li&gt;Viewing a PSD or STL file with more than one revision results in an error being thrown.&lt;/li&gt;
&lt;li&gt;The GitHub application server could fail to start, because under some circumstances there could be a stale zero-downtime restart flag file.&lt;/li&gt;
&lt;li&gt;Scheduled maintenance mode didn&#39;t activate, so GitHub Enterprise was still available when it shouldn&#39;t have been.&lt;/li&gt;
&lt;li&gt;Saving settings in the management console with invalid LDAP connection settings caused an error. We fail with an appropriate message now.&lt;/li&gt;
&lt;li&gt;Promoting a high availability replica failed if the primary wasn&#39;t accessible.&lt;/li&gt;
&lt;li&gt;MySQL replication could fail on really, really busy instances.&lt;/li&gt;
&lt;li&gt;With SSL disabled, regenerating the self-signed certificate enabled SSL. This would happen if you use the IP address as the hostname and change the IP address of the VM.&lt;/li&gt;
&lt;li&gt;The admin SSH user didn&#39;t have proper access to &lt;code&gt;man&lt;/code&gt; pages.&lt;/li&gt;
&lt;li&gt;There was an unused Redis stats bubble in the site admin toolbar, which looked like a warning. We&#39;ve taken out the bubble.&lt;/li&gt;
&lt;li&gt;Chrome Canary didn&#39;t show the number of open pull requests when you viewed a repository.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-upgrade&lt;/code&gt; command produced the following harmless error: &lt;code&gt;line 205: /dev/null/: Is a directory&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: There was an XSS vulnerability in wikis.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are being logged twice.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Gist profile pages don&#39;t have proper styling when subdomain isolation disabled.&lt;/li&gt;
&lt;li&gt;After initial set up, an instance with static networking configured that has not been rebooted can try to get a DHCP lease.&lt;/li&gt;
&lt;li&gt;Management console sessions can expire too quickly for Safari users.&lt;/li&gt;
&lt;li&gt;We can fail to properly create the key for the secure connection between a high availability replica and the primary, which causes replication setup to fail.&lt;/li&gt;
&lt;li&gt;Custom firewall rules aren&#39;t maintained during an upgrade.&lt;/li&gt;
&lt;li&gt;A high availability replica that&#39;s been promoted to primary and then set up as a replica again doesn&#39;t properly show the replica status page, but shows &amp;quot;Starting...&amp;quot; instead.&lt;/li&gt;
&lt;li&gt;Individual application logs are not reliably forwarded. (updated 2015-04-20)&lt;/li&gt;
&lt;li&gt;When using Chrome 42 or newer, wiki pages can&#39;t be edited, images can&#39;t be uploaded via drag and drop, and autocomplete menus and repository graphs may not display. (updated 2015-05-06)&lt;/li&gt;
&lt;li&gt;Avatars, &lt;a href=&quot;https://docs.github.com/enterprise/2.1/user/articles/about-releases/&quot;&gt;release downloads&lt;/a&gt;, and image attachments to wikis and issues are not copied correctly by high availability replication. (updated 2015-05-20)&lt;/li&gt;
&lt;li&gt;We show your gravatar or identicon on Gists instead of your custom profile picture. (updated 2015-06-15)&lt;/li&gt;
&lt;li&gt;Repositories with a leading dot in their name fail to replicate if they were created before replication was set up. (updated 2015-06-16)&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled. (updated 2015-06-19)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set throw errors. (updated 2015-08-25)&lt;/li&gt;
&lt;li&gt;With LDAP authentication enabled, entering the wrong password can cause a timeout for some users. (updated 2015-09-02)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Tue, 03 Mar 2015 09:41:13 -0800</pubDate>
					<link>https://enterprise.github.com/releases/2.1.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.1.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.1.3</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu packages have been updated to the latest bugfix/security versions.&lt;/li&gt;
&lt;li&gt;Downloading code archives failed when private mode was enabled.&lt;/li&gt;
&lt;li&gt;The assets server didn&#39;t always properly close file handles, which could cause performance issues if the file handle limit was reached.&lt;/li&gt;
&lt;li&gt;Custom CA certificates installed with &lt;code&gt;ghe-ssl-ca-certificate-install&lt;/code&gt; were lost after upgrading.&lt;/li&gt;
&lt;li&gt;Maintenance mode wasn&#39;t maintained after upgrading, so applications were unexpectedly accessible to users.&lt;/li&gt;
&lt;li&gt;Updating a license in the management console was not reflected in the GitHub application under some circumstances.&lt;/li&gt;
&lt;li&gt;Diagnostics always said avatars are disabled, regardless of reality.&lt;/li&gt;
&lt;li&gt;Some organization names were incorrectly blacklisted.&lt;/li&gt;
&lt;li&gt;We didn&#39;t require SAML responses to be signed. We enforce that now.&lt;/li&gt;
&lt;li&gt;We didn&#39;t properly support SAML single sign on URLs with query parameters.&lt;/li&gt;
&lt;li&gt;Our validation when adding restricted LDAP groups in the management console was overly strict, and stopped you adding groups whose name was a substring of existing groups.&lt;/li&gt;
&lt;li&gt;We weren&#39;t properly suspending users when they were suspended in ActiveDirectory.&lt;/li&gt;
&lt;li&gt;We failed to properly sync LDAP users&#39; email addresses in some cases.&lt;/li&gt;
&lt;li&gt;LDAP Sync unsuspended users who&#39;d been suspended if the &lt;code&gt;userAccountControl&lt;/code&gt; attribute wasn&#39;t present. That&#39;s usually the case when the directory isn&#39;t ActiveDirectory unless the attribute was added with a custom schema.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-org-owner-promote&lt;/code&gt; command line utility was broken.&lt;/li&gt;
&lt;li&gt;Wildcard SSL certificates in the management console could be incorrectly marked invalid under some circumstances.&lt;/li&gt;
&lt;li&gt;We only copied admin SSH keys when initially setting up replication, so the keys on the high availability replica could be out of sync. We regularly update them now.&lt;/li&gt;
&lt;li&gt;The management console settings and GitHub Enterprise license were only copied the first time replication was set up, so the high availability replica could be out of sync. Now we update the settings and license each time replication is set up.&lt;/li&gt;
&lt;li&gt;The monitoring graphs were set to PST timezone. We always use UTC now.&lt;/li&gt;
&lt;li&gt;We ignored region settings in the AWS CodeDeploy service hook, causing it to fail.&lt;/li&gt;
&lt;li&gt;Switching to a different authentication method didn&#39;t expire existing sessions.&lt;/li&gt;
&lt;li&gt;Profile pictures migrated from an avatar service could revert to identicons under some circumstances.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The &lt;code&gt;ghe-upgrade&lt;/code&gt; command will output the following harmless error: &lt;code&gt;line 205: /dev/null/: Is a directory&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;Replica promotion can hang when running &lt;code&gt;ghe-repl-promote&lt;/code&gt;.&lt;/del&gt;&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are being logged twice.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Enabling LDAP Sync for emails can cause background jobs to be continuously queued, which in turn can affect performance. We recommend disabling email sync in this version. (updated 2015-02-25)&lt;/li&gt;
&lt;li&gt;Viewing a PSD or STL file with more than one revision results in an error being thrown. (updated 2015-02-27)&lt;/li&gt;
&lt;li&gt;Individual application logs are not reliably forwarded. (updated 2015-04-20)&lt;/li&gt;
&lt;li&gt;When using Chrome 42 or newer, wiki pages can&#39;t be edited, images can&#39;t be uploaded via drag and drop, and autocomplete menus and repository graphs may not display. (updated 2015-05-06)&lt;/li&gt;
&lt;li&gt;Avatars, &lt;a href=&quot;https://docs.github.com/enterprise/2.1/user/articles/about-releases/&quot;&gt;release downloads&lt;/a&gt;, and image attachments to wikis and issues are not copied correctly by high availability replication. (updated 2015-05-20)&lt;/li&gt;
&lt;li&gt;We show your gravatar or identicon on Gists instead of your custom profile picture. (updated 2015-06-15)&lt;/li&gt;
&lt;li&gt;Repositories with a leading dot in their name fail to replicate if they were created before replication was set up. (updated 2015-06-16)&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled. (updated 2015-06-19)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set throw errors. (updated 2015-08-25)&lt;/li&gt;
&lt;li&gt;With LDAP authentication enabled, entering the wrong password can cause a timeout for some users. (updated 2015-09-02)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: SAML authentication responses weren&#39;t signed.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Replica promotion hanging when running &lt;code&gt;ghe-repl-promote&lt;/code&gt; was fixed in 2.0.2.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Tue, 17 Feb 2015 04:46:27 -0800</pubDate>
					<link>https://enterprise.github.com/releases/2.1.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.1.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.0.7</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu packages have been updated to the latest bugfix/security versions.&lt;/li&gt;
&lt;li&gt;Updating a license in the management console was not reflected in the GitHub application under some circumstances.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;We didn&#39;t require SAML responses to be signed. We enforce that now.&lt;/del&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;Replica promotion can hang when running &lt;code&gt;ghe-repl-promote&lt;/code&gt;.&lt;/del&gt;&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-org-owner-promote&lt;/code&gt; command line utility is currently broken.&lt;/li&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Switching to a different authentication method doesn&#39;t expire existing sessions.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are being logged twice.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;del&gt;&lt;strong&gt;LOW&lt;/strong&gt;: SAML authentication responses weren&#39;t signed.&lt;/del&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;del&gt;LOW&lt;/del&gt; HIGH&lt;/strong&gt;: &lt;a href=&quot;https://launchpad.net/ubuntu/+source/openssl/1.0.1-4ubuntu5.21&quot;&gt;OpenSSL 1.0.1-4ubuntu5.21&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;We didn&#39;t include the fix to sign SAML authentication responses in this release.&lt;/li&gt;
&lt;li&gt;Replica promotion hanging when running &lt;code&gt;ghe-repl-promote&lt;/code&gt; was fixed in 2.0.2.&lt;/li&gt;
&lt;li&gt;The OpenSSL 1.0.1-4ubuntu5.21 update was upgraded to a &lt;strong&gt;HIGH&lt;/strong&gt; security fix due to the publication of &lt;a href=&quot;https://freakattack.com&quot;&gt;Freak Attack&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Tue, 17 Feb 2015 04:46:26 -0800</pubDate>
					<link>https://enterprise.github.com/releases/2.0.7</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.0.7</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.1.2</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Static network configuration had to be reapplied after upgrading from 2.1.0 to 2.1.1. We now properly maintain these settings during an upgrade.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;Replica promotion can hang when running &lt;code&gt;ghe-repl-promote&lt;/code&gt;.&lt;/del&gt;&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-org-owner-promote&lt;/code&gt; command line utility is currently broken.&lt;/li&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Switching to a different authentication method doesn&#39;t expire existing sessions.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are being logged twice.&lt;/li&gt;
&lt;li&gt;Replication needs to be reconfigured after upgrading a replica with &lt;code&gt;ghe-upgrade&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Updating a license in the management console is not reflected in the GitHub application under some circumstances. (updated 2015-02-02)&lt;/li&gt;
&lt;li&gt;Enabling LDAP Sync for emails can cause background jobs to be continuously queued, which in turn can affect performance. We recommend disabling email sync in this version. (updated 2015-02-25)&lt;/li&gt;
&lt;li&gt;Viewing a PSD or STL file with more than one revision results in an error being thrown. (updated 2015-02-27)&lt;/li&gt;
&lt;li&gt;Individual application logs are not reliably forwarded. (updated 2015-04-20)&lt;/li&gt;
&lt;li&gt;When using Chrome 42 or newer, wiki pages can&#39;t be edited, images can&#39;t be uploaded via drag and drop, and autocomplete menus and repository graphs may not display. (updated 2015-05-06)&lt;/li&gt;
&lt;li&gt;Avatars, &lt;a href=&quot;https://docs.github.com/enterprise/2.1/user/articles/about-releases/&quot;&gt;release downloads&lt;/a&gt;, and image attachments to wikis and issues are not copied correctly by high availability replication. (updated 2015-05-20)&lt;/li&gt;
&lt;li&gt;We show your gravatar or identicon on Gists instead of your custom profile picture. (updated 2015-06-15)&lt;/li&gt;
&lt;li&gt;Repositories with a leading dot in their name fail to replicate if they were created before replication was set up. (updated 2015-06-16)&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled. (updated 2015-06-19)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set throw errors. (updated 2015-08-25)&lt;/li&gt;
&lt;li&gt;With LDAP authentication enabled, entering the wrong password can cause a timeout for some users. (updated 2015-09-02)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Replica promotion hanging when running &lt;code&gt;ghe-repl-promote&lt;/code&gt; was fixed in 2.0.2.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Sat, 31 Jan 2015 11:42:05 -0800</pubDate>
					<link>https://enterprise.github.com/releases/2.1.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.1.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.1.1</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu packages have been updated to the latest bugfix/security versions.&lt;/li&gt;
&lt;li&gt;With more than seven tabs open, dynamic content could fail to load due to browser connection limits. We&#39;ve returned to using polling instead.&lt;/li&gt;
&lt;li&gt;When a SAML response incorrectly had an email as the &lt;code&gt;NameID&lt;/code&gt;, but didn&#39;t include &lt;code&gt;email&lt;/code&gt; as a released attribute, users could sign in the first time but couldn&#39;t sign in again after signing out.&lt;/li&gt;
&lt;li&gt;If an SSH key contained extra whitespace or a comment, LDAP Sync sent emails warning that an SSH key was added to your account each time sync ran.&lt;/li&gt;
&lt;li&gt;When synchronizing an LDAP Group mapped to multiple GitHub Teams, we queried the LDAP directory for each Team. We now query once for the Group and update all the Teams at the same time. We also improved the performance of searching for group members.&lt;/li&gt;
&lt;li&gt;Creating LDAP users through the site admin caused an error if their LDAP username included characters that would be normalized in their GitHub username, like &lt;code&gt;$&lt;/code&gt;, &lt;code&gt;_&lt;/code&gt;, &lt;code&gt;.&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Members of the LDAP admin group were given admin privileges on account creation or LDAP Sync, but not when they signed in.&lt;/li&gt;
&lt;li&gt;We incorrectly hid avatar options in the management console if a service URL was set but avatars were disabled.&lt;/li&gt;
&lt;li&gt;If your management console session timed out, connectivity tests failed without any error message. Now you&#39;re redirected to log in again.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;From:&lt;/code&gt; address was wrong in notification emails if the &amp;quot;no-reply&amp;quot; email address was configued, using the SMTP HELO domain instead.&lt;/li&gt;
&lt;li&gt;SASL was enabled even if SMTP authentication wasn&#39;t turned on, which could cause email delivery failures.&lt;/li&gt;
&lt;li&gt;Doing an initial installation using the management console API failed if you didn&#39;t include the port, because we dropped data when redirecting.&lt;/li&gt;
&lt;li&gt;If Pages on a replica fell too far behind the primary, the alert shown by &lt;code&gt;ghe-repl-status&lt;/code&gt; was missing how far behind replication was.&lt;/li&gt;
&lt;li&gt;Diagnostics always said Log Forwarding was disabled, regardless of reality.&lt;/li&gt;
&lt;li&gt;The Git gateway tried to log timing statistics to an inaccessible statsd server.&lt;/li&gt;
&lt;li&gt;Hovering over the timing statistics graph in the site admin showed &lt;code&gt;undefined&lt;/code&gt; instead of the hostname and Ruby version.&lt;/li&gt;
&lt;li&gt;Compressing a support bundle could be slow, so we sped it up using more than one core (but with a high &lt;code&gt;nice&lt;/code&gt; so it won&#39;t affect anything else).&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;Replica promotion can hang when running &lt;code&gt;ghe-repl-promote&lt;/code&gt;.&lt;/del&gt;&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-org-owner-promote&lt;/code&gt; command line utility is currently broken.&lt;/li&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Switching to a different authentication method doesn&#39;t expire existing sessions.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are being logged twice.&lt;/li&gt;
&lt;li&gt;Replication needs to be reconfigured after upgrading a replica with &lt;code&gt;ghe-upgrade&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Updating a license in the management console is not reflected in the GitHub application under some circumstances. (updated 2015-02-02)&lt;/li&gt;
&lt;li&gt;Enabling LDAP Sync for emails can cause background jobs to be continuously queued, which in turn can affect performance. We recommend disabling email sync in this version. (updated 2015-02-25)&lt;/li&gt;
&lt;li&gt;Viewing a PSD or STL file with more than one revision results in an error being thrown. (updated 2015-02-27)&lt;/li&gt;
&lt;li&gt;Individual application logs are not reliably forwarded. (updated 2015-04-20)&lt;/li&gt;
&lt;li&gt;When using Chrome 42 or newer, wiki pages can&#39;t be edited, images can&#39;t be uploaded via drag and drop, and autocomplete menus and repository graphs may not display. (updated 2015-05-06)&lt;/li&gt;
&lt;li&gt;Avatars, &lt;a href=&quot;https://docs.github.com/enterprise/2.1/user/articles/about-releases/&quot;&gt;release downloads&lt;/a&gt;, and image attachments to wikis and issues are not copied correctly by high availability replication. (updated 2015-05-20)&lt;/li&gt;
&lt;li&gt;We show your gravatar or identicon on Gists instead of your custom profile picture. (updated 2015-06-15)&lt;/li&gt;
&lt;li&gt;Repositories with a leading dot in their name fail to replicate if they were created before replication was set up. (updated 2015-06-16)&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled. (updated 2015-06-19)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set throw errors. (updated 2015-08-25)&lt;/li&gt;
&lt;li&gt;With LDAP authentication enabled, entering the wrong password can cause a timeout for some users. (updated 2015-09-02)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Buffer overflow in &lt;code&gt;gethostbyname&lt;/code&gt;. Also known as the GHOST vulnerability.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;GHOST vulnerability&lt;/h3&gt;
&lt;p&gt;Qualys researchers have &lt;a href=&quot;http://seclists.org/oss-sec/2015/q1/274&quot;&gt;found a buffer overflow vulnerability&lt;/a&gt; in the &lt;code&gt;gethostbyname&lt;/code&gt; function in the C standard library that could allow remote code execution under some circumstances. There is currently no known way to exploit GitHub Enterprise remotely using this vulnerability, as &lt;a href=&quot;http://seclists.org/oss-sec/2015/q1/283&quot;&gt;many services don&#39;t use &lt;code&gt;gethostbyname&lt;/code&gt; in a way that is exploitable&lt;/a&gt;. However, as a precaution we recommend upgrading to this latest patch release or to a &lt;a href=&quot;https://enterprise.github.com/releases/&quot;&gt;later version&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Replica promotion hanging when running &lt;code&gt;ghe-repl-promote&lt;/code&gt; was fixed in 2.0.2.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://enterprise.github.com/releases&quot;&gt;https://enterprise.github.com/releases&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://enterprise.github.com/releases/2.1.1&quot;&gt;https://enterprise.github.com/releases/2.1.1&lt;/a&gt;&lt;/p&gt;
&lt;h1&gt;Security Notification&lt;/h1&gt;
&lt;h2&gt;Important Security Vulnerabilities Fixed in GitHub Enterprise 2.1.1&lt;/h2&gt;
&lt;p&gt;The following important security vulnerabilities have been fixed in the 2.1.1 release:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Buffer overflow in &lt;code&gt;gethostbyname&lt;/code&gt;. Also known as the GHOST vulnerability.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;GHOST vulnerability&lt;/h3&gt;
&lt;p&gt;Qualys researchers have &lt;a href=&quot;http://seclists.org/oss-sec/2015/q1/274&quot;&gt;found a buffer overflow vulnerability&lt;/a&gt; in the &lt;code&gt;gethostbyname&lt;/code&gt; function in the C standard library that could allow remote code execution under some circumstances. There is currently no known way to exploit GitHub Enterprise remotely using this vulnerability, as &lt;a href=&quot;http://seclists.org/oss-sec/2015/q1/283&quot;&gt;many services don&#39;t use &lt;code&gt;gethostbyname&lt;/code&gt; in a way that is exploitable&lt;/a&gt;. However, as a precaution we recommend upgrading to this latest patch release or to a &lt;a href=&quot;https://enterprise.github.com/releases/&quot;&gt;later version&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you have any questions, please contact support at &lt;a href=&quot;mailto:enterprise@github.com&quot;&gt;enterprise@github.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Fri, 30 Jan 2015 16:19:14 -0800</pubDate>
					<link>https://enterprise.github.com/releases/2.1.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.1.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.0.6</title>
					<description>&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu packages have been updated to the latest bugfix/security versions.&lt;/li&gt;
&lt;li&gt;With private mode enabled, redirects could leak the Nginx version we use.&lt;/li&gt;
&lt;li&gt;Changes to authentication settings in the management console were lost if any settings failed to validate.&lt;/li&gt;
&lt;li&gt;Adding an SSH key that contained non-ASCII characters like smart quotes would break the management console.&lt;/li&gt;
&lt;li&gt;If your management console session timed out, connectivity tests failed without any error message. Now you&#39;re redirected to log in again.&lt;/li&gt;
&lt;li&gt;We stopped you from adding a duplicate or broken SSH key to the management console, but the error didn&#39;t show up properly.&lt;/li&gt;
&lt;li&gt;The HAProxy connection limits were incorrectly configured, making them a little bit lower than they should have been.&lt;/li&gt;
&lt;li&gt;When a SAML response incorrectly had an email as the &lt;code&gt;NameID&lt;/code&gt;, but didn&#39;t include &lt;code&gt;email&lt;/code&gt; as a released attribute, users could sign in the first time but couldn&#39;t sign in again after signing out.&lt;/li&gt;
&lt;li&gt;Checking replica status with &lt;code&gt;ghe-repl-status&lt;/code&gt; was really slow. We made it faster.&lt;/li&gt;
&lt;li&gt;If Pages on a replica fell too far behind the primary, the alert shown by &lt;code&gt;ghe-repl-status&lt;/code&gt; was missing how far behind replication was.&lt;/li&gt;
&lt;li&gt;Replication didn&#39;t restart properly after rebooting a high availability replica.&lt;/li&gt;
&lt;li&gt;Replication didn&#39;t replicate custom DNS settings.&lt;/li&gt;
&lt;li&gt;The SSH key used for replication didn&#39;t survive upgrades and had to be regenerated.&lt;/li&gt;
&lt;li&gt;The Git gateway tried to log timing statistics to an inaccessible statsd server.&lt;/li&gt;
&lt;li&gt;The Git gateway included the repository twice in SSH log entries.&lt;/li&gt;
&lt;li&gt;The Git gateway logs were messed up when we tried to rotate them.&lt;/li&gt;
&lt;li&gt;The Git gateway was being restarted every day, but we didn&#39;t need to do that.&lt;/li&gt;
&lt;li&gt;The hypervisor console script timed out every five seconds and respawned, spamming the logs.&lt;/li&gt;
&lt;li&gt;Git clone events weren&#39;t being forwarded as part of the &lt;code&gt;github_audit&lt;/code&gt; log stream.&lt;/li&gt;
&lt;li&gt;Hovering over the timing statistics graph in the site admin showed &lt;code&gt;undefined&lt;/code&gt; instead of the hostname and Ruby version.&lt;/li&gt;
&lt;li&gt;Compressing a support bundle could be slow, so we sped it up using more than one core (but with a high &lt;code&gt;nice&lt;/code&gt; so it won&#39;t affect anything else).&lt;/li&gt;
&lt;li&gt;Diagnostics always said Log Forwarding was disabled, regardless of reality.&lt;/li&gt;
&lt;li&gt;Creating the diagnostics file for support could timeout if there were lots of webhook delivery logs.&lt;/li&gt;
&lt;li&gt;In Pages sites, JSON files were served with the wrong MIME type.&lt;/li&gt;
&lt;li&gt;We sometimes didn&#39;t show the gateway address in the hypervisor console.&lt;/li&gt;
&lt;li&gt;Accessing GitHub Enterprise in Firefox with the default certificate still enabled displayed the SSL warning twice.&lt;/li&gt;
&lt;li&gt;The &#39;Revert&#39; button didn&#39;t work properly when trying to revert a pull request from a fork.&lt;/li&gt;
&lt;li&gt;Git authentication could fail after changing the hostname.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;Replica promotion can hang when running &lt;code&gt;ghe-repl-promote&lt;/code&gt;.&lt;/del&gt;&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;The management console settings interface doesn&#39;t clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restoring from backup if the hostname has changed.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-org-owner-promote&lt;/code&gt; command line utility is currently broken.&lt;/li&gt;
&lt;li&gt;In some circumstances, after an upgrade we prompt you to upload a license, even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Switching to a different authentication method doesn&#39;t expire existing sessions.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are being logged twice.&lt;/li&gt;
&lt;li&gt;Replication needs to be reconfigured after upgrading a replica with &lt;code&gt;ghe-upgrade&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode.&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas.&lt;/li&gt;
&lt;li&gt;Individual application logs are not reliably forwarded. (updated 2015-04-20)&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Buffer overflow in &lt;code&gt;gethostbyname&lt;/code&gt;. Also known as the GHOST vulnerability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Desktop applications were granted API tokens with more access scope than was necessary.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;GHOST vulnerability&lt;/h3&gt;
&lt;p&gt;Qualys researchers have &lt;a href=&quot;http://seclists.org/oss-sec/2015/q1/274&quot;&gt;found a buffer overflow vulnerability&lt;/a&gt; in the &lt;code&gt;gethostbyname&lt;/code&gt; function in the C standard library that could allow remote code execution under some circumstances. There is currently no known way to exploit GitHub Enterprise remotely using this vulnerability, as &lt;a href=&quot;http://seclists.org/oss-sec/2015/q1/283&quot;&gt;many services don&#39;t use &lt;code&gt;gethostbyname&lt;/code&gt; in a way that is exploitable&lt;/a&gt;. However, as a precaution we recommend upgrading to this latest patch release or to a &lt;a href=&quot;https://enterprise.github.com/releases/&quot;&gt;later version&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Replica promotion hanging when running &lt;code&gt;ghe-repl-promote&lt;/code&gt; was fixed in 2.0.2.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://enterprise.github.com/releases&quot;&gt;https://enterprise.github.com/releases&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://enterprise.github.com/releases/2.0.6&quot;&gt;https://enterprise.github.com/releases/2.0.6&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://enterprise.github.com/staff/releases/2.0.6/edit&quot;&gt;https://enterprise.github.com/staff/releases/2.0.6/edit&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;&lt;a href=&quot;https://enterprise.github.com/staff/notifications/206-update-released/&quot;&gt;https://enterprise.github.com/staff/notifications/206-update-released/&lt;/a&gt;&lt;/p&gt;
&lt;h1&gt;Security Notification&lt;/h1&gt;
&lt;h2&gt;Important Security Vulnerabilities Fixed in GitHub Enterprise 2.0.6&lt;/h2&gt;
&lt;p&gt;The following important security vulnerabilities have been fixed in the 2.0.6 release:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Buffer overflow in &lt;code&gt;gethostbyname&lt;/code&gt;. Also known as the GHOST vulnerability.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;GHOST vulnerability&lt;/h3&gt;
&lt;p&gt;Qualys researchers have &lt;a href=&quot;http://seclists.org/oss-sec/2015/q1/274&quot;&gt;found a buffer overflow vulnerability&lt;/a&gt; in the &lt;code&gt;gethostbyname&lt;/code&gt; function in the C standard library that could allow remote code execution under some circumstances. There is currently no known way to exploit GitHub Enterprise remotely using this vulnerability, as &lt;a href=&quot;http://seclists.org/oss-sec/2015/q1/283&quot;&gt;many services don&#39;t use &lt;code&gt;gethostbyname&lt;/code&gt; in a way that is exploitable&lt;/a&gt;. However, as a precaution we recommend upgrading to this latest patch release or to a &lt;a href=&quot;https://enterprise.github.com/releases/&quot;&gt;later version&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you have any questions, please contact support at &lt;a href=&quot;mailto:enterprise@github.com&quot;&gt;enterprise@github.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Fri, 30 Jan 2015 16:19:07 -0800</pubDate>
					<link>https://enterprise.github.com/releases/2.0.6</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.0.6</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.352</title>
					<description>&lt;h2&gt;Important Security Vulnerability Fixed in 11.10.352&lt;/h2&gt;
&lt;p&gt;The following important security vulnerability has been fixed in the 11.10.352 release:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Buffer overflow in &lt;code&gt;gethostbyname&lt;/code&gt;. Also known as the GHOST vulnerability.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;GHOST vulnerability&lt;/h3&gt;
&lt;p&gt;Qualys researchers have &lt;a href=&quot;http://seclists.org/oss-sec/2015/q1/274&quot;&gt;found a buffer overflow vulnerability&lt;/a&gt; in the &lt;code&gt;gethostbyname&lt;/code&gt; function in the C standard library that could allow remote code execution under some circumstances. There is currently no known way to exploit GitHub Enterprise remotely using this vulnerability, as &lt;a href=&quot;http://seclists.org/oss-sec/2015/q1/283&quot;&gt;many services don&#39;t use &lt;code&gt;gethostbyname&lt;/code&gt; in a way that is exploitable&lt;/a&gt;. However, as a precaution we recommend upgrading to this latest patch release or to a &lt;a href=&quot;https://enterprise.github.com/releases/&quot;&gt;later version&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you have any questions, please contact support at &lt;a href=&quot;mailto:enterprise@github.com&quot;&gt;enterprise@github.com&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Thanks!&lt;/p&gt;
&lt;p&gt;The GitHub Team&lt;/p&gt;</description>
					<pubDate>Fri, 30 Jan 2015 16:18:55 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.352</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.352</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.1.0</title>
					<description>&lt;h2&gt;GitHub Enterprise 2.1.0 Update Released&lt;/h2&gt;
&lt;p&gt;The 2.1.0 release for GitHub Enterprise is now available for download from &lt;a href=&quot;https://enterprise.github.com/download&quot;&gt;https://enterprise.github.com/download&lt;/a&gt;. We&#39;ve listed out all the included features, bug fixes, and known issues below, and have also drafted up a set of &lt;a href=&quot;https://docs.github.com/enterprise/2.1/admin/guides/installation/upgrading-to-github-enterprise-2-1&quot;&gt;upgrade instructions&lt;/a&gt; to help make your migration as smooth as possible.&lt;/p&gt;
&lt;h2&gt;New Features&lt;/h2&gt;
&lt;p&gt;With the new features added in GitHub Enterprise 2.1.0, you can:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Automate user and team management with &lt;a href=&quot;https://docs.github.com/enterprise/2.1/admin/guides/user-management/using-ldap#enabling-ldap-sync&quot;&gt;LDAP Sync&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Deploy GitHub Enterprise on &lt;a href=&quot;https://docs.github.com/enterprise/2.1/admin/guides/installation/installing-github-enterprise-on-openstack-kvm&quot;&gt;OpenStack KVM&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Audit all user actions across your instance with the &lt;a href=&quot;https://docs.github.com/enterprise/2.1/admin/guides/user-management/auditing-users-across-your-instance&quot;&gt;Instance Audit Log&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Monitor the performance of GitHub Enterprise with the &lt;a href=&quot;https://docs.github.com/enterprise/2.1/admin/guides/installation/system-resource-monitoring-and-alerting#accessing-the-internal-monitoring-dashboard&quot;&gt;Instance Monitoring Dashboard&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/articles/about-webhooks/&quot;&gt;Configure webhooks&lt;/a&gt; at the organization level.&lt;/li&gt;
&lt;li&gt;Set your GitHub Enterprise &lt;a href=&quot;https://docs.github.com/enterprise/2.1/user/articles/how-do-i-set-up-my-profile-picture&quot;&gt;profile picture&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;See the results from &lt;a href=&quot;https://github.com/blog/1935-see-results-from-all-pull-request-status-checks&quot;&gt;multiple pull requests status checks&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;View and diff &lt;a href=&quot;https://docs.github.com/articles/rendering-and-diffing-images/&quot;&gt;SVG files&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Manage todos with the &lt;a href=&quot;https://docs.github.com/articles/viewing-all-of-your-issues-and-pull-requests/&quot;&gt;&lt;code&gt;/pulls&lt;/code&gt; and &lt;code&gt;/issues&lt;/code&gt; dashboard pages&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;More easily review changes to code with &lt;a href=&quot;https://github.com/blog/1932-syntax-highlighted-diffs&quot;&gt;syntax highlighted diffs&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Automate deployments from GitHub Enterprise repositories with &lt;a href=&quot;https://developer.github.com/enterprise/2.1/v3/repos/deployments/&quot;&gt;the Deployments API&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Run GitHub Enterprise within your IPv6 network.&lt;/li&gt;
&lt;li&gt;Find what you&#39;re looking for on the go with &lt;a href=&quot;https://github.com/blog/1924-mobile-search&quot;&gt;mobile search&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;See what Git operations are running on GitHub Enterprise with the &lt;a href=&quot;https://docs.github.com/enterprise/2.1/admin/articles/command-line-utilities#ghe-btop&quot;&gt;&lt;code&gt;ghe-btop&lt;/code&gt; command line utility&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://docs.github.com/articles/generating-ssh-keys/&quot;&gt;Use Ed25519 SSH client keys&lt;/a&gt; for Git operations.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;To stop users committing large files that can harm server performance, files larger than 100MB are now rejected by default. The file size limit can be &lt;a href=&quot;https://docs.github.com/enterprise/2.1/admin/articles/setting-git-push-limits/&quot;&gt;changed or removed&lt;/a&gt;. (updated 2015-02-02)&lt;/li&gt;
&lt;li&gt;With the release of the &lt;a href=&quot;https://github.com/blog/1803-switch-your-picture-with-ease&quot;&gt;profile pictures&lt;/a&gt; feature, support for external avatar services has been deprecated. (updated 2015-02-02)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu packages have been updated to the latest bugfix/security versions.&lt;/li&gt;
&lt;li&gt;When installing, you had to upload the license and then set the password. Now we do it in one step, so someone nasty can&#39;t set a password after you&#39;ve uploaded the license and gone for coffee.&lt;/li&gt;
&lt;li&gt;With private mode enabled, redirects could leak the Nginx version we use.&lt;/li&gt;
&lt;li&gt;When talking to an LDAP server multiple times in a request, we&#39;d start a new connection each time. Now we reuse connections where possible, so it&#39;s much faster.&lt;/li&gt;
&lt;li&gt;Checking replica status with &lt;code&gt;ghe-repl-status&lt;/code&gt; was really slow. We made it faster.&lt;/li&gt;
&lt;li&gt;We sometimes didn&#39;t show the gateway address in the hypervisor console.&lt;/li&gt;
&lt;li&gt;We stopped you from adding a duplicate or broken SSH key to the management console, but the error didn&#39;t show up properly.&lt;/li&gt;
&lt;li&gt;Accessing GitHub Enterprise in Firefox with the default certificate still enabled displayed the SSL warning twice.&lt;/li&gt;
&lt;li&gt;It was easy to accidentally change network settings in the VMware console. Now you have to hit &#39;s&#39; instead of any key.&lt;/li&gt;
&lt;li&gt;In the security section of the settings page, we incorrectly showed requests coming from 127.0.0.1 if they came from a private network.&lt;/li&gt;
&lt;li&gt;Replication didn&#39;t restart properly after rebooting a high availability replica.&lt;/li&gt;
&lt;li&gt;Replication didn&#39;t replicate custom DNS settings.&lt;/li&gt;
&lt;li&gt;If a high availability replica was offline for a while, restarting it could fail if MySQL had moved on too far.&lt;/li&gt;
&lt;li&gt;The SSH key used for replication didn&#39;t survive upgrades and had to be regenerated.&lt;/li&gt;
&lt;li&gt;Memcached didn&#39;t restart after a crash, which broke Gist and other pages.&lt;/li&gt;
&lt;li&gt;In Pages sites, JSON files were served with the wrong MIME type.&lt;/li&gt;
&lt;li&gt;People expected to be able to invite users to an organization by their full name. Now you can.&lt;/li&gt;
&lt;li&gt;Wiki links to other wiki pages were rendered as images when a repository contained a directory with the same name.&lt;/li&gt;
&lt;li&gt;Adding an SSH key that contained non-ASCII characters like smart quotes would break the management console.&lt;/li&gt;
&lt;li&gt;The &#39;Revert&#39; button didn&#39;t work properly when trying to revert a pull request from a fork.&lt;/li&gt;
&lt;li&gt;The hypervisor console script timed out every five seconds and respawned, spamming the logs.&lt;/li&gt;
&lt;li&gt;Git clone events weren&#39;t being forwarded as part of the &lt;code&gt;github_audit&lt;/code&gt; log stream.&lt;/li&gt;
&lt;li&gt;The Git gateway logs were messed up when we tried to rotate them.&lt;/li&gt;
&lt;li&gt;Creating the diagnostics file for support could timeout if there were lots of webhook delivery logs.&lt;/li&gt;
&lt;li&gt;The page that users see when maintenance mode is enabled linked to &lt;a href=&quot;mailto:enterprise@github.com&quot;&gt;enterprise@github.com&lt;/a&gt; instead of your configured support email address.&lt;/li&gt;
&lt;li&gt;The &amp;quot;Open in desktop&amp;quot; button only worked if you already had the desktop application installed.&lt;/li&gt;
&lt;li&gt;PSD files didn&#39;t render with the default self-signed certificate.&lt;/li&gt;
&lt;li&gt;Git authentication could fail after changing the hostname. (updated 2015-02-02)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Desktop applications were granted API tokens with more access scope than was necessary.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;&lt;del&gt;LOW&lt;/del&gt; HIGH&lt;/strong&gt;: &lt;a href=&quot;https://launchpad.net/ubuntu/+source/openssl/1.0.1-4ubuntu5.21&quot;&gt;OpenSSL 1.0.1-4ubuntu5.21&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Removal of RC4 SSL cipher&lt;/h2&gt;
&lt;p&gt;To keep GitHub Enterprise as secure as possible, we have removed support for the cryptographically weak RC4 cipher in our SSL configuration. With the removal of RC4, Internet Explorer on Windows XP will no longer be able to access GitHub Enterprise. You can read more about this change in our &lt;a href=&quot;https://github.com/blog/1937-improving-github-s-ssl-setup&quot;&gt;announcement on GitHub.com&lt;/a&gt;.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;Replica promotion can hang when running &lt;code&gt;ghe-repl-promote&lt;/code&gt;.&lt;/del&gt;&lt;/li&gt;
&lt;li&gt;Git replication can be slow and CPU intense during initial push of large/complex repositories.&lt;/li&gt;
&lt;li&gt;The management console settings interface does not clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to the wrong hostname after restore if the hostname has changed.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-org-owner-promote&lt;/code&gt; command line utility is currently broken.&lt;/li&gt;
&lt;li&gt;In some circumstances after an upgrade, we prompt you to upload a license even though there&#39;s already a valid license.&lt;/li&gt;
&lt;li&gt;If your management console session has timed out, connectivity tests can fail without any error message.&lt;/li&gt;
&lt;li&gt;On a freshly set up GitHub Enterprise instance without any users, an attacker could create the first admin user.&lt;/li&gt;
&lt;li&gt;Switching to a different authentication method doesn&#39;t expire existing sessions.&lt;/li&gt;
&lt;li&gt;Events in the &lt;code&gt;github_audit&lt;/code&gt; log stream are being logged twice.&lt;/li&gt;
&lt;li&gt;Replication needs to be reconfigured after upgrading a replica with &lt;code&gt;ghe-upgrade&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Gists can&#39;t be created when using Safari 8.x in Private Mode. (updated 2015-01-27)&lt;/li&gt;
&lt;li&gt;SNMP can&#39;t be run on high availability replicas. Our previous fix was incomplete. (updated 2015-02-02)&lt;/li&gt;
&lt;li&gt;Updating a license in the management console is not reflected in the GitHub application under some circumstances. (updated 2015-02-02)&lt;/li&gt;
&lt;li&gt;Enabling LDAP Sync for emails can cause background jobs to be continuously queued, which in turn can affect performance. We recommend disabling email sync in this version. (updated 2015-02-25)&lt;/li&gt;
&lt;li&gt;Viewing a PSD or STL file with more than one revision results in an error being thrown. (updated 2015-02-27)&lt;/li&gt;
&lt;li&gt;Individual application logs are not reliably forwarded. (updated 2015-04-20)&lt;/li&gt;
&lt;li&gt;When using Chrome 42 or newer, wiki pages can&#39;t be edited, images can&#39;t be uploaded via drag and drop, and autocomplete menus and repository graphs may not display. (updated 2015-05-06)&lt;/li&gt;
&lt;li&gt;Avatars, &lt;a href=&quot;https://docs.github.com/enterprise/2.1/user/articles/about-releases/&quot;&gt;release downloads&lt;/a&gt;, and image attachments to wikis and issues are not copied correctly by high availability replication. (updated 2015-05-20)&lt;/li&gt;
&lt;li&gt;We show your gravatar or identicon on Gists instead of your custom profile picture. (updated 2015-06-15)&lt;/li&gt;
&lt;li&gt;Repositories with a leading dot in their name fail to replicate if they were created before replication was set up. (updated 2015-06-16)&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Users with LDAP DNs longer than 255 characters are suspended if LDAP Sync is enabled. (updated 2015-06-19)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;Updates to Wiki pages by users without a primary email address set throw errors. (updated 2015-08-25)&lt;/li&gt;
&lt;li&gt;With LDAP authentication enabled, entering the wrong password can cause a timeout for some users. (updated 2015-09-02)&lt;/li&gt;
&lt;li&gt;Trying to add a file to a repository with Subversion 1.9 clients incorrectly detects the file already exists and fails. (updated 2016-01-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Replica promotion hanging when running &lt;code&gt;ghe-repl-promote&lt;/code&gt; was fixed in 2.0.2.&lt;/li&gt;
&lt;li&gt;The OpenSSL 1.0.1-4ubuntu5.21 update was upgraded to a &lt;strong&gt;HIGH&lt;/strong&gt; security fix due to the publication of &lt;a href=&quot;https://freakattack.com&quot;&gt;Freak Attack&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Tue, 20 Jan 2015 09:04:22 -0800</pubDate>
					<link>https://enterprise.github.com/releases/2.1.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.1.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.0.5</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: Remote code execution possible via &lt;code&gt;ntpd&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Specially crafted Gist updates could bypass the Git client protection introduced in 2.0.4.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: The web editor could be used to bypass the Git client protection introduced in 2.0.4.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;NTP vulnerability&lt;/h3&gt;
&lt;p&gt;Critical vulnerabilities in the Network Time Protocol (NTP) have been &lt;!-- raw HTML omitted --&gt;discovered and disclosed&lt;!-- raw HTML omitted --&gt; by members of the Google Security Team. These vulnerabilities make it possible for a remote attacker to send a carefully crafted packet with malicious arbitrary code that will execute at the privilege level of the &lt;code&gt;ntpd&lt;/code&gt; process.&lt;/p&gt;
&lt;p&gt;This release includes patches to NTP from upstream to make sure it is not exploitable. As an additional measure, we&#39;ve also updated the firewall rules to be more strict. &lt;strong&gt;We strongly recommend that all GitHub Enterprise customers upgrade their instances as soon as possible&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;More details on the vulnerabilities can be found in &lt;!-- raw HTML omitted --&gt;the ICSA-14-353-01 advisory&lt;!-- raw HTML omitted --&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Mitigation&lt;/strong&gt;&lt;br /&gt;
If you can&#39;t immediately upgrade, the attack can be mitigated by removing the firewall rule that accepts traffic to port 123. To temporarily remove the rule, SSH into the appliance and run:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;sudo ufw delete allow ghe-123
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;If you have any questions, please contact support at &lt;a href=&quot;mailto:enterprise@github.com&quot;&gt;enterprise@github.com&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;Replica promotion can hang when running &lt;code&gt;ghe-repl-promote&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Replicas need to be restarted after upgrading with &lt;code&gt;ghe-upgrade&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Git replication slow and CPU intense during initial push of large/complex repositories.&lt;/li&gt;
&lt;li&gt;First run in Firefox displays the SSL warning twice.&lt;/li&gt;
&lt;li&gt;Admin is prompted to reapply the license after &lt;code&gt;ghe-upgrade&lt;/code&gt; runs even though the license file is present.&lt;/li&gt;
&lt;li&gt;The management console doesn&#39;t handle non-ASCII characters in &lt;em&gt;authorized_keys&lt;/em&gt;.&lt;/li&gt;
&lt;li&gt;Management console settings interface does not clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Downloading diagnostics from the web can time out if there are a lot of hook deliveries.&lt;/li&gt;
&lt;li&gt;Memcache doesn&#39;t restart properly after a crash and must be manually restarted.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restore if the hostname has changed.&lt;/li&gt;
&lt;li&gt;A user cannot be invited to an organization by their full name.&lt;/li&gt;
&lt;li&gt;Wiki links to other wiki pages are rendered as images when a repository contains a directory with the same name.&lt;/li&gt;
&lt;li&gt;Individual application logs are not reliably forwarded. (updated 2015-04-20)&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Mon, 22 Dec 2014 03:26:08 -0800</pubDate>
					<link>https://enterprise.github.com/releases/2.0.5</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.0.5</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.351</title>
					<description>&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRITICAL&lt;/strong&gt;: Remote code execution possible via &lt;code&gt;ntpd&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: Specially crafted Gist updates could bypass the Git client protection introduced in 11.10.349.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MEDIUM&lt;/strong&gt;: The web editor could be used to bypass the Git client protection introduced in 11.10.349.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;NTP vulnerability&lt;/h3&gt;
&lt;p&gt;Critical vulnerabilities in the Network Time Protocol (NTP) have been &lt;!-- raw HTML omitted --&gt;discovered and disclosed&lt;!-- raw HTML omitted --&gt; by members of the Google Security Team. These vulnerabilities make it possible for a remote attacker to send a carefully crafted packet with malicious arbitrary code that will execute at the privilege level of the &lt;code&gt;ntpd&lt;/code&gt; process.&lt;/p&gt;
&lt;p&gt;This release includes patches to NTP from upstream to make sure it is not exploitable. As an additional measure, we&#39;ve also updated the firewall rules to be more strict. &lt;strong&gt;We strongly recommend that all GitHub Enterprise customers upgrade their instances as soon as possible&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;More details on the vulnerabilities can be found in &lt;!-- raw HTML omitted --&gt;the ICSA-14-353-01 advisory&lt;!-- raw HTML omitted --&gt;.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Mitigation&lt;/strong&gt;&lt;br /&gt;
If you can&#39;t immediately upgrade, the attack can be mitigated by removing the firewall rule that accepts traffic to port 123. To temporarily remove the rule, SSH into the appliance and run:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;sudo ufw delete allow ghe-123
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;The rule will be re-enabled if settings are saved or a configuration run is performed. To prevent the rule from being restored, SSH into the appliance and run:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;sudo rm /data/enterprise/cookbooks/ufw/files/default/ufw_apps/ghe-123
sudo rm /etc/ufw/applications.d/ghe-123
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;If you have any questions, please contact support at &lt;a href=&quot;mailto:enterprise@github.com&quot;&gt;enterprise@github.com&lt;/a&gt;&lt;/p&gt;</description>
					<pubDate>Mon, 22 Dec 2014 03:07:34 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.351</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.351</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.349</title>
					<description>&lt;h3&gt;Git client vulnerability&lt;/h3&gt;
&lt;p&gt;Yesterday a &lt;a href=&quot;http://article.gmane.org/gmane.linux.kernel/1853266&quot;&gt;critical Git security vulnerability&lt;/a&gt; was announced that affects all versions of the official Git client and all related software that interacts with Git repositories.&lt;/p&gt;
&lt;p&gt;While GitHub Enterprise itself is not directly affected, it may be used as a distribution point for an attacker to reach unpatched clients. This release detects and blocks malicious trees from being pushed to an Enterprise instance, eliminating it as an attack vector.&lt;/p&gt;
&lt;h4&gt;Important details&lt;/h4&gt;
&lt;p&gt;It it critical to note that this release only provides mitigation against low-levels attacks where a user with write access could attempt to push malicious files to a GitHub Enterprise instance. It does not prevent interactions with malicious external Git servers that can open up command-line level attack vectors, as those must be dealt with at the Git client level.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;For full protection, we strongly recommend you ensure that all developers update their Git clients, in addition to upgrading to this release.&lt;/strong&gt; Installing this update alone does not mean your organization is fully safe against this vulnerability. The only way to make sure none of your developers are vulnerable is to have everyone upgrade their Git client.&lt;/p&gt;
&lt;p&gt;More details on the vulnerability can be found in the &lt;a href=&quot;http://article.gmane.org/gmane.linux.kernel/1853266&quot;&gt;official Git mailing list announcement&lt;/a&gt;, on the &lt;a href=&quot;http://git-blame.blogspot.com.es/2014/12/git-1856-195-205-214-and-221-and.html&quot;&gt;&lt;code&gt;git-blame&lt;/code&gt; blog&lt;/a&gt;, and on &lt;a href=&quot;https://github.com/blog/1938-vulnerability-announced-update-your-git-clients&quot;&gt;the GitHub blog&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you have any questions, please contact support at &lt;a href=&quot;mailto:enterprise@github.com&quot;&gt;enterprise@github.com&lt;/a&gt;&lt;/p&gt;</description>
					<pubDate>Fri, 19 Dec 2014 14:09:38 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.349</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.349</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.0.4</title>
					<description>&lt;h3&gt;Git client vulnerability&lt;/h3&gt;
&lt;p&gt;Yesterday a &lt;a href=&quot;http://article.gmane.org/gmane.linux.kernel/1853266&quot;&gt;critical Git security vulnerability&lt;/a&gt; was announced that affects all versions of the official Git client and all related software that interacts with Git repositories.&lt;/p&gt;
&lt;p&gt;While GitHub Enterprise itself is not directly affected, it may be used as a distribution point for an attacker to reach unpatched clients. This release detects and blocks malicious trees from being pushed to an Enterprise instance, eliminating it as an attack vector.&lt;/p&gt;
&lt;h4&gt;Important details&lt;/h4&gt;
&lt;p&gt;It it critical to note that this release only provides mitigation against low-levels attacks where a user with write access could attempt to push malicious files to a GitHub Enterprise instance. It does not prevent interactions with malicious external Git servers that can open up command-line level attack vectors, as those must be dealt with at the Git client level.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;For full protection, we strongly recommend you ensure that all developers update their Git clients, in addition to upgrading to this release.&lt;/strong&gt; Installing this update alone does not mean your organization is fully safe against this vulnerability. The only way to make sure none of your developers are vulnerable is to have everyone upgrade their Git client.&lt;/p&gt;
&lt;p&gt;More details on the vulnerability can be found in the &lt;a href=&quot;http://article.gmane.org/gmane.linux.kernel/1853266&quot;&gt;official Git mailing list announcement&lt;/a&gt;, on the &lt;a href=&quot;http://git-blame.blogspot.com.es/2014/12/git-1856-195-205-214-and-221-and.html&quot;&gt;git-blame blog&lt;/a&gt;, and on &lt;a href=&quot;https://github.com/blog/1938-vulnerability-announced-update-your-git-clients&quot;&gt;the GitHub blog&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;If you have any questions, please contact support at &lt;a href=&quot;mailto:enterprise@github.com&quot;&gt;enterprise@github.com&lt;/a&gt;&lt;/p&gt;
&lt;h2&gt;Bug Fixes and Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Maintenance pages now display the configured support email rather than the &lt;code&gt;enterprise@github.com&lt;/code&gt; default.&lt;/li&gt;
&lt;li&gt;The version number is displayed correctly on AWS installations.&lt;/li&gt;
&lt;li&gt;The index entries in Index Management correctly change the cursor to indicate they are clickable links.&lt;/li&gt;
&lt;li&gt;The welcome screen will no longer blank and requires &lt;code&gt;s&lt;/code&gt; rather than any key to start network setup.&lt;/li&gt;
&lt;li&gt;There is now a &lt;code&gt;/usr/local/bin/ghe-btop&lt;/code&gt; utility to query the status of &lt;code&gt;babeld&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;Replica promotion can hang when running &lt;code&gt;ghe-repl-promote&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Replicas need to be restarted after upgrading with &lt;code&gt;ghe-upgrade&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Git replication slow and CPU intense during initial push of large/complex repositories.&lt;/li&gt;
&lt;li&gt;First run in Firefox displays the SSL warning twice.&lt;/li&gt;
&lt;li&gt;Admin is prompted to reapply the license after &lt;code&gt;ghe-upgrade&lt;/code&gt; runs even though the license file is present.&lt;/li&gt;
&lt;li&gt;The management console doesn&#39;t handle non-ASCII characters in &lt;em&gt;authorized_keys&lt;/em&gt;.&lt;/li&gt;
&lt;li&gt;Management console settings interface does not clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Downloading diagnostics from the web can time out if there are a lot of hook deliveries.&lt;/li&gt;
&lt;li&gt;Memcache doesn&#39;t restart properly after a crash and must be manually restarted.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restore if the hostname has changed.&lt;/li&gt;
&lt;li&gt;A user cannot be invited to an organization by their full name.&lt;/li&gt;
&lt;li&gt;Wiki links to other wiki pages are rendered as images when a repository contains a directory with the same name.&lt;/li&gt;
&lt;li&gt;Individual application logs are not reliably forwarded. (updated 2015-04-20)&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Fri, 19 Dec 2014 14:09:36 -0800</pubDate>
					<link>https://enterprise.github.com/releases/2.0.4</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.0.4</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.0.3</title>
					<description>&lt;h2&gt;Bug Fixes and Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Fixes a regression in 2.0.2 that prevented new AWS installations when the second block device was attached before the instance was first started.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;The version number is incorrectly shown on AWS installations as 2.0.2.&lt;/li&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;Replica promotion can hang when running &lt;code&gt;ghe-repl-promote&lt;/code&gt;.&lt;/del&gt;&lt;/li&gt;
&lt;li&gt;Replicas need to be restarted after upgrading with &lt;code&gt;ghe-upgrade&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Git replication slow and CPU intense during initial push of large/complex repositories.&lt;/li&gt;
&lt;li&gt;First run in Firefox displays the SSL warning twice.&lt;/li&gt;
&lt;li&gt;Admin is prompted to reapply the license after &lt;code&gt;ghe-upgrade&lt;/code&gt; runs even though the license file is present.&lt;/li&gt;
&lt;li&gt;The management console doesn&#39;t handle non-ASCII characters in &lt;em&gt;authorized_keys&lt;/em&gt;.&lt;/li&gt;
&lt;li&gt;Management console settings interface does not clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Downloading diagnostics from the web can time out if there are a lot of hook deliveries.&lt;/li&gt;
&lt;li&gt;Memcache doesn&#39;t restart properly after a crash and must be manually restarted.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restore if the hostname has changed.&lt;/li&gt;
&lt;li&gt;A user cannot be invited to an organization by their full name.&lt;/li&gt;
&lt;li&gt;Wiki links to other wiki pages are rendered as images when a repository contains a directory with the same name.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Replica promotion hanging when running &lt;code&gt;ghe-repl-promote&lt;/code&gt; was fixed in 2.0.2.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Tue, 16 Dec 2014 13:59:31 -0800</pubDate>
					<link>https://enterprise.github.com/releases/2.0.3</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.0.3</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.0.2</title>
					<description>&lt;h2&gt;Bug Fixes and Updates&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Updated installed packages and Ubuntu kernel to latest released versions.&lt;/li&gt;
&lt;li&gt;Services would not start properly in some circumstances, so the appliance would get stuck in a &amp;quot;Starting...&amp;quot; state.&lt;/li&gt;
&lt;li&gt;SSH keys were deleted during sign in when SAML authentication was used.&lt;/li&gt;
&lt;li&gt;It was possible to upload an invalid SAML idP certificate, which caused an error when trying to log in.&lt;/li&gt;
&lt;li&gt;Updating a license didn&#39;t take effect until settings had been saved.&lt;/li&gt;
&lt;li&gt;A 404 Not Found error was returned when visiting the user page of a suspended user.&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-user-csv&lt;/code&gt; command line utility didn&#39;t include email addresses in some circumstances.&lt;/li&gt;
&lt;li&gt;After upgrading, the appliance could briefly revert to using the default self-signed SSL certificate.&lt;/li&gt;
&lt;li&gt;Changing network settings could break the HAProxy SSL certificate, making services on the appliance unreachable.&lt;/li&gt;
&lt;li&gt;Our handling of deleted refs could cause high availability Git replication to fail for affected repositories.&lt;/li&gt;
&lt;li&gt;The management console could report the pre-upgrade version number after an upgrade.&lt;/li&gt;
&lt;li&gt;Events that trigger notification emails could cause 500 errors if the configured SMTP server timed out.&lt;/li&gt;
&lt;li&gt;Testing domain settings in the management console failed if the uploaded SSL certificate didn&#39;t have &#39;Subject Alternative Name&#39; extensions.&lt;/li&gt;
&lt;li&gt;Testing domain settings in the management console failed when the DNS server wasn&#39;t reachable or valid.&lt;/li&gt;
&lt;li&gt;Testing LDAP group membership in the management console returned incorrect results when only an admin group was set.&lt;/li&gt;
&lt;li&gt;Searching for a repository in the site admin could miss exact matches.&lt;/li&gt;
&lt;li&gt;User creation could time out if the LDAP administrator group wasn&#39;t set.&lt;/li&gt;
&lt;li&gt;Gist log level was set too high, so the Gist logs could grow very big.&lt;/li&gt;
&lt;li&gt;Some management console styles and functionality were broken for supported versions of IE.&lt;/li&gt;
&lt;li&gt;When restoring to a backup with &lt;code&gt;ghe-restore&lt;/code&gt;, maintenance mode was automatically enabled, which could be confusing. Maintenance mode now has to be enabled manually through the management console, using the management console API, or using the &lt;code&gt;ghe-maintenance&lt;/code&gt; command line utility.&lt;/li&gt;
&lt;li&gt;Resizing the root partition caused upgrades to fail.&lt;/li&gt;
&lt;li&gt;The web user interface and API could be slow to update after Git pushes.&lt;/li&gt;
&lt;li&gt;During initial installation, the self-signed certificate warning screen suggested verifying the certificate over SSH when no SSH keys were installed. The certificate fingerprint is now shown in the hypervisor console.&lt;/li&gt;
&lt;li&gt;SSH password authentication was incorrectly enabled for admin access, even though no password was set.&lt;/li&gt;
&lt;li&gt;The support email couldn&#39;t be set without enabling outgoing email.&lt;/li&gt;
&lt;li&gt;Slow response times from NetApp storage could cause the root partition to be remounted as read only.&lt;/li&gt;
&lt;li&gt;Some metadata was missing when importing the OVA.&lt;/li&gt;
&lt;li&gt;It wasn&#39;t possible to add more than 8 vCPUs under ESXi without upgrading the virtual hardware version.&lt;/li&gt;
&lt;li&gt;The raw Gist main page returned an error.&lt;/li&gt;
&lt;li&gt;Inconsistent 404 Not Found error pages were displayed in some cases.&lt;/li&gt;
&lt;li&gt;Sending malformed JSON to the management console API caused an error rather than being handled gracefully.&lt;/li&gt;
&lt;li&gt;Links to help articles didn&#39;t link to the Enterprise-specific articles.&lt;/li&gt;
&lt;li&gt;The color used to highlight search term results in code was too similar to the fold highlighting color.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-upgrade&lt;/code&gt; expects the upgrade filename to be &lt;code&gt;github-enterprise-esx-2.0.2.pkg&lt;/code&gt; on VMWare or &lt;code&gt;github-enterprise-ami-2.0.2.pkg&lt;/code&gt; on AWS.&lt;/li&gt;
&lt;li&gt;Creating the OpenVPN connection can fail, causing replication set up with &lt;code&gt;ghe-repl-setup&lt;/code&gt; to hang.&lt;/li&gt;
&lt;li&gt;&lt;del&gt;Replica promotion can hang when running &lt;code&gt;ghe-repl-promote&lt;/code&gt;.&lt;/del&gt;&lt;/li&gt;
&lt;li&gt;Replicas need to be restarted after upgrading with &lt;code&gt;ghe-upgrade&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Git replication slow and CPU intense during initial push of large/complex repositories.&lt;/li&gt;
&lt;li&gt;First run in Firefox displays the SSL warning twice.&lt;/li&gt;
&lt;li&gt;Admin is prompted to reapply the license after &lt;code&gt;ghe-upgrade&lt;/code&gt; runs even though the license file is present.&lt;/li&gt;
&lt;li&gt;The management console doesn&#39;t handle non-ASCII characters in &lt;em&gt;authorized_keys&lt;/em&gt;.&lt;/li&gt;
&lt;li&gt;Management console settings interface does not clearly show if you have previously uploaded certificate files or a private key.&lt;/li&gt;
&lt;li&gt;Downloading diagnostics from the web can time out if there are a lot of hook deliveries.&lt;/li&gt;
&lt;li&gt;Memcache doesn&#39;t restart properly after a crash and must be manually restarted.&lt;/li&gt;
&lt;li&gt;Jobs stuck on code indexing can delay other jobs from running.&lt;/li&gt;
&lt;li&gt;Dashboard activity feed links point to wrong hostname after restore if the hostname has changed.&lt;/li&gt;
&lt;li&gt;A user cannot be invited to an organization by their full name.&lt;/li&gt;
&lt;li&gt;Wiki links to other wiki pages are rendered as images when a repository contains a directory with the same name.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Errata&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Replica promotion hanging when running &lt;code&gt;ghe-repl-promote&lt;/code&gt; was fixed in this release.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Tue, 16 Dec 2014 00:25:11 -0800</pubDate>
					<link>https://enterprise.github.com/releases/2.0.2</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.0.2</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.0.1</title>
					<description>&lt;h2&gt;Bug Fixes and Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Ubuntu packages have been updated to the latest bugfix/security versions.&lt;/li&gt;
&lt;li&gt;Data migration failed if there were organizations without administrators.&lt;/li&gt;
&lt;li&gt;Services could fail to start correctly if configuration was applied without storage being prepared.&lt;/li&gt;
&lt;li&gt;A race condition could cause a configuration failure to be incorrectly reported.&lt;/li&gt;
&lt;li&gt;When saving Management Console settings, redirecting to the progress page could fail.&lt;/li&gt;
&lt;li&gt;Saving Management Console settings with an inaccessible LDAP server caused an error.&lt;/li&gt;
&lt;li&gt;Static network settings would be lost across upgrades.&lt;/li&gt;
&lt;li&gt;Gist Git repositories could not be pushed to directly.&lt;/li&gt;
&lt;li&gt;The number of Rails worker processes was static, and now depends on the provisioned memory.&lt;/li&gt;
&lt;li&gt;GitHub OAuth did not redirect to the requested page when login was required.&lt;/li&gt;
&lt;li&gt;Diagnostic output did not include the EC2 instance type.&lt;/li&gt;
&lt;li&gt;MySQL replication was shown as a running query in the Management Console maintenance page.&lt;/li&gt;
&lt;li&gt;A SAML single logout URL was incorrectly published. GitHub Enterprise does not currently support single logout.&lt;/li&gt;
&lt;li&gt;Excessive log entries were generated because the MySQL slow transaction threshold was set too low.&lt;/li&gt;
&lt;li&gt;The default memory for the OVA was incorrectly set to 8GB, instead of the recommended 16GB.&lt;/li&gt;
&lt;li&gt;Lowercase hostnames were not enforced in the Management Console settings.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;collectd&lt;/code&gt; and log data are were not preserved through upgrades.&lt;/li&gt;
&lt;li&gt;Support bundles did not include configuration logs.&lt;/li&gt;
&lt;li&gt;SAML times did not append &lt;code&gt;Z&lt;/code&gt; for compliance with the SAML Core 1.3.3 standard.&lt;/li&gt;
&lt;li&gt;Incorrect license information was shown in diagnostic output.&lt;/li&gt;
&lt;li&gt;The Git HTTPS daemon contained a file descriptor leak.&lt;/li&gt;
&lt;li&gt;Added &lt;code&gt;ghe-mysql-checksum&lt;/code&gt; script to checksum InnoDB tables.&lt;/li&gt;
&lt;li&gt;Management Console restore messaging was imprecise.&lt;/li&gt;
&lt;li&gt;Subdomain isolation caused a redirect loop when accessing the Pages root URL.&lt;/li&gt;
&lt;li&gt;The crash kernel was unnecessarily enabled, causing 128M of memory to be used.&lt;/li&gt;
&lt;li&gt;Webhook logs did not include timestamps.&lt;/li&gt;
&lt;li&gt;Excessive log entries were generated if Gitmon could not open its data store.&lt;/li&gt;
&lt;li&gt;Non-DST time changes caused ambiguous Russian timezones.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;DNS Servers&lt;/h2&gt;
&lt;p&gt;&lt;em&gt;Major change:&lt;/em&gt; DNS settings are no longer configured via the the Management Console, and any custom nameservers specified via the console will be lost after upgrading to 2.0.1.&lt;/p&gt;
&lt;p&gt;When configured to use DHCP, GitHub Enterprise now relies on the DNS nameservers provided by the DHCP server. This is the default configuration for GitHub on AWS, and no changes are required when upgrading an EC2 instance.&lt;/p&gt;
&lt;p&gt;If you are using DHCP on VMWare and your server does not provide nameservers, or if you need custom nameservers that are different from your DHCP lease, please add them to &lt;code&gt;/etc/resolvconf/resolv.conf.d/head&lt;/code&gt; after upgrading.&lt;/p&gt;
&lt;p&gt;If you are using a static IP configuration, please reconfigure static network configuration after upgrading to 2.0.1, either via tty1 or &lt;code&gt;sudo ghe-setup-network -v&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Note: You may also choose to add custom nameservers to &lt;code&gt;/etc/resolvconf/resolv.conf.d/head&lt;/code&gt; before running &lt;code&gt;ghe-upgrade&lt;/code&gt;. These settings will be retained across the upgrade to 2.0.1 and future releases.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;p&gt;The 2.0.1 release ships with some known issues that we were unable to fix before release. If any of these will cause major problems for your organization, we recommending waiting for 2.1.0 or 2.0.2 before upgrading.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;News feed activity links point to the hostname and protocol used when they were generated (affects renamed hosts).&lt;/li&gt;
&lt;li&gt;&amp;quot;Test domain settings&amp;quot; will fail when a DNS server is invalid or not reachable.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-restore&lt;/code&gt; should require that maintenance mode is enabled before restoring.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-repl-status-git&lt;/code&gt; is CPU intensive and may be slow on the primary node.&lt;/li&gt;
&lt;li&gt;The Site Admin dashboard has an autofocus issue in Firefox.&lt;/li&gt;
&lt;li&gt;Accessing the Gist raw subdomain can cause an error.&lt;/li&gt;
&lt;li&gt;Git replication is slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;Webhook deliveries may be delayed when search indexing jobs are running.&lt;/li&gt;
&lt;li&gt;The lock issue dialog does not link to the versioned Enterprise Help URL: &lt;a href=&quot;https://docs.github.com/enterprise/2.0/user/articles/what-are-the-different-access-permissions&quot;&gt;https://docs.github.com/enterprise/2.0/user/articles/what-are-the-different-access-permissions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Search on Pages 404 pages does not work.&lt;/li&gt;
&lt;li&gt;404 pages are not consistent across Assets, Gist and GitHub URLs.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-user-csv&lt;/code&gt; script doesn&#39;t return valid email addresses.&lt;/li&gt;
&lt;li&gt;SMTP over SSL/SMTPS on port 465 is not supported.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Thu, 20 Nov 2014 04:13:11 -0800</pubDate>
					<link>https://enterprise.github.com/releases/2.0.1</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.0.1</guid>
				</item>
			
		
			
		  
				<item>
					<title>2.0.0</title>
					<description>&lt;h2&gt;Features and Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Runs on Amazon Web Services EC2 with officially supported Amazon Machine Images.&lt;/li&gt;
&lt;li&gt;Now running on Ubuntu 12.04 LTS.&lt;/li&gt;
&lt;li&gt;High availability support with replication and failover: &lt;a href=&quot;https://docs.github.com/enterprise/2.0/admin-guide/ha-cluster/&quot;&gt;https://docs.github.com/enterprise/2.0/admin-guide/ha-cluster/&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;SAML 2.0 authentication with support for OneLogin, PingIdentity, Okta, and Shibboleth.&lt;/li&gt;
&lt;li&gt;Inbound email - replies to pull request/issue/commit emails show up as comments: &lt;a href=&quot;https://github.com/blog/811-reply-to-comments-from-email&quot;&gt;https://github.com/blog/811-reply-to-comments-from-email&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Diffs have a split view: &lt;a href=&quot;https://github.com/blog/1884-introducing-split-diffs&quot;&gt;https://github.com/blog/1884-introducing-split-diffs&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;GitHub Issues has improved search, status, and notifications: &lt;a href=&quot;https://github.com/blog/1866-the-new-github-issues&quot;&gt;https://github.com/blog/1866-the-new-github-issues&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Gist design update: &lt;a href=&quot;https://github.com/blog/1850-gist-design-update&quot;&gt;https://github.com/blog/1850-gist-design-update&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Users receive notifications when issues are assigned to them.&lt;/li&gt;
&lt;li&gt;Users added to organizations receive email invites: &lt;a href=&quot;https://github.com/blog/1868-inviting-people-to-your-organization&quot;&gt;https://github.com/blog/1868-inviting-people-to-your-organization&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;New mobile views with design improvements.&lt;/li&gt;
&lt;li&gt;Search code by filename, e.g., &lt;code&gt;servolux filename:Gemfile&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Folder paths expand to allow quick access to deeply nested hierarchies: &lt;a href=&quot;https://github.com/blog/1877-folder-jumping&quot;&gt;https://github.com/blog/1877-folder-jumping&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Organizations have improved audit logs: &lt;a href=&quot;https://github.com/blog/1872-improved-audit-log&quot;&gt;https://github.com/blog/1872-improved-audit-log&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Markdown task lists can now be nested.&lt;/li&gt;
&lt;li&gt;PSD files can be viewed inline and compared: &lt;a href=&quot;https://github.com/blog/1845-psd-viewing-diffing&quot;&gt;https://github.com/blog/1845-psd-viewing-diffing&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Lock conversations, so only collaborators can post further comments: &lt;a href=&quot;https://github.com/blog/1847-locking-conversations&quot;&gt;https://github.com/blog/1847-locking-conversations&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Branches pages have improved UI and filters: &lt;a href=&quot;https://github.com/blog/1852-a-better-branches-page&quot;&gt;https://github.com/blog/1852-a-better-branches-page&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Pull requests can be reverted with a button that creates a reversed, revert pull request: &lt;a href=&quot;https://github.com/blog/1857-introducing-the-revert-button&quot;&gt;https://github.com/blog/1857-introducing-the-revert-button&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Emoji and team autocompletion are smarter.&lt;/li&gt;
&lt;li&gt;Users can set up 2FA with a TOTP application, and they&#39;ll get more reminders to download their recovery codes in case of a lock out.&lt;/li&gt;
&lt;li&gt;Pages uses Jekyll 2.2.0: &lt;a href=&quot;https://github.com/blog/1867-github-pages-now-runs-jekyll-2-2-0&quot;&gt;https://github.com/blog/1867-github-pages-now-runs-jekyll-2-2-0&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Webhook services have added for VisualOps.io, Bugzilla 4.4.3, Snap-CI, tinyPM, CodeReviewHub, Heroku deployments, GoCD, and AWS OpsWorks deployments support.&lt;/li&gt;
&lt;li&gt;SSH appliance administration is now on port 122.&lt;/li&gt;
&lt;li&gt;Configuration runs no longer use Chef and are much faster and more reliable.&lt;/li&gt;
&lt;li&gt;New Git daemon for all protocols provides increased reliability, performance, and maximum number of parallel connections.&lt;/li&gt;
&lt;li&gt;Future upgrades can be done with the &lt;code&gt;ghe-upgrade&lt;/code&gt; command-line tool over SSH.&lt;/li&gt;
&lt;li&gt;The admin SSH user has full &lt;code&gt;sudo&lt;/code&gt; access to perform regular administrative tasks and troubleshooting.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Bug Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Pull requests could include the wrong commits.&lt;/li&gt;
&lt;li&gt;Webhooks would only keep the most recent 150 deliveries per hook.&lt;/li&gt;
&lt;li&gt;LDAP authentication failed when using Oracle Unified Directory LDAP.&lt;/li&gt;
&lt;li&gt;Git clone could fail for large repositories.&lt;/li&gt;
&lt;li&gt;MySQL could not be restarted without rebooting the VM.&lt;/li&gt;
&lt;li&gt;Experimental: Active Directory users could not be found when the user was in a nested group (ask Enterprise Support for access to this bug fix).&lt;/li&gt;
&lt;li&gt;GitHub Pages URLs were case insensitive, which defied W3C guidelines. (updated 2015-04-17)&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;Security Fixes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: Subdomain Isolation (strongly recommended but disabled by default) hosts Archives, Gist, Assets, Pages, content rendering, user uploads, and raw files on separate subdomains. This feature isolates these potentially insecure resources from user sessions and mitigates cross-site scripting attacks by moving them to different origins.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: Multiple cross-site scripting vulnerabilities and configuration file injection issues fixed in management console. Exploitation required authentication.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt;: Management console now runs on port 8443 (or 8080 when SSL is disabled) to separate user and administrative interfaces.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt;: SSL is enabled by default and uses self-signed certificates on initial setup.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt;: Management console now uses password-based authentication instead of authentication using license files.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;LDAP Support&lt;/h2&gt;
&lt;p&gt;Supported LDAP servers are now Active Directory, FreeIPA, Oracle Directory Server Enterprise Edition, OpenLDAP, Open Directory and 389 Directory Server. These are the servers that we will test before shipping a GitHub Enterprise release. If you need support for another LDAP server please contact GitHub Enterprise Support.&lt;/p&gt;
&lt;h2&gt;VirtualBox Unsupported&lt;/h2&gt;
&lt;p&gt;Enterprise 2.0 OVAs will no longer run with VirtualBox. VirtualBox has previously offered a poor customer experience for GitHub Enterprise. The supported hypervisors are VMware ESX and Amazon Web Service&#39;s EC2. VMware desktop products (e.g. VMware Workstation, VMware Fusion, VMware Player) are supported for trial purposes but should not be used in production.&lt;/p&gt;
&lt;h2&gt;Known Issues&lt;/h2&gt;
&lt;p&gt;The 2.0.0 release ships with some known issues that we were unable to fix before release. If any of these will cause major problems for your organization, we recommending waiting for 2.1.0 or 2.0.1 before upgrading.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Dashboard activity feed links point to the hostname and protocol used when they were generated.&lt;/li&gt;
&lt;li&gt;&amp;quot;Test domain settings&amp;quot; will fail when a DNS server is not reachable or invalid.&lt;/li&gt;
&lt;li&gt;Gist Git repositories cannot be pushed to.&lt;/li&gt;
&lt;li&gt;GitHub OAuth does not redirect to the requested page when login is required.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-restore&lt;/code&gt; should require that maintenance mode is enabled before restoring.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-repl-status-git&lt;/code&gt; is CPU intense and may be slow on the primary node.&lt;/li&gt;
&lt;li&gt;Saving settings with an inaccessible LDAP server results in an error.&lt;/li&gt;
&lt;li&gt;The Site Admin dashboard has an autofocus issue in Firefox.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;collectd&lt;/code&gt; data is not preserved through upgrades.&lt;/li&gt;
&lt;li&gt;Accessing the Gist raw subdomain can cause an error.&lt;/li&gt;
&lt;li&gt;Git replication is slow and CPU intense during initial push of large or complex repositories.&lt;/li&gt;
&lt;li&gt;Webhook deliveries may be delayed when search indexing jobs are running.&lt;/li&gt;
&lt;li&gt;The lock issue dialog does not link to the versioned Enterprise Help URL: &lt;a href=&quot;https://docs.github.com/enterprise/2.0/user/articles/what-are-the-different-access-permissions&quot;&gt;https://docs.github.com/enterprise/2.0/user/articles/what-are-the-different-access-permissions&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;Search on Pages 404 pages does not work.&lt;/li&gt;
&lt;li&gt;Inconsistent 404 behaviour for Assets, Gist and GitHub URLs.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-user-csv&lt;/code&gt; script doesn&#39;t return valid email addresses.&lt;/li&gt;
&lt;li&gt;Uppercase hostnames cause redirect loops and are not rejected by the management console.&lt;/li&gt;
&lt;li&gt;SMTP over SSL/SMTPS on port 465 is not supported.&lt;/li&gt;
&lt;li&gt;We display the time in the scheduled maintenance banner in UTC instead of the viewer&#39;s timezone. (updated 2015-06-18)&lt;/li&gt;
&lt;li&gt;Images uploaded to issues save with an absolute URL, so they can be broken if the hostname changes. (updated 2015-07-14)&lt;/li&gt;
&lt;li&gt;With private mode enabled, a Pages site with no default page serves a generic error rather than an informative message. (updated 2015-07-14)&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Tue, 11 Nov 2014 03:29:35 -0800</pubDate>
					<link>https://enterprise.github.com/releases/2.0.0</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/2.0.0</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.348</title>
					<description>&lt;h3&gt;Bug Fixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Quickly recreating a repository after deletion could result in the new repository being deleted.&lt;/li&gt;
&lt;li&gt;A GitHub.com billing plan could be incorrectly assigned to a user, causing upgrades to fail.&lt;/li&gt;
&lt;li&gt;MOTD was incorrectly enabled for non-interactive SSH sessions.&lt;/li&gt;
&lt;li&gt;The Subversion bridge could fail to restart.&lt;/li&gt;
&lt;li&gt;Repositories with missing discussion metadata were not properly deleted.&lt;/li&gt;
&lt;li&gt;Gists from previous versions were not shown in searches after upgrade.&lt;/li&gt;
&lt;li&gt;Duplicate repository records could cause upgrades to fail.&lt;/li&gt;
&lt;li&gt;Git garbage collection could run while a backup was in progress.&lt;/li&gt;
&lt;li&gt;Internal hooks could cause poor Git performance.&lt;/li&gt;
&lt;li&gt;Active Directory LDAP subgroups were not searched recursively.&lt;/li&gt;
&lt;li&gt;Diffs of STL files did not work in private mode.&lt;/li&gt;
&lt;li&gt;Clicking links in Gists in Firefox redirected incorrectly to an error page.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Google Chrome&lt;/h3&gt;
&lt;p&gt;A bug in Chrome  caused our security middleware to incorrectly forbid file uploads, causing an empty response. This could cause initial installation, upgrades, or unlocking with a license file to fail for all instances using the 11.10.320 OVA. The bug is fixed in the 11.10.320.1 OVA included with this release.&lt;/p&gt;
&lt;h3&gt;Security Fixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH:&lt;/strong&gt; OpenSSL SSLv3 POODLE Vulnerability (&lt;a href=&quot;http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3566&quot;&gt;http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3566&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED:&lt;/strong&gt; OpenSSL 1.0.1-4ubuntu5.20 (&lt;a href=&quot;https://www.openssl.org/news/secadv_20141015.txt&quot;&gt;https://www.openssl.org/news/secadv_20141015.txt&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED:&lt;/strong&gt; Bash 4.2-2ubuntu2.6 (&lt;a href=&quot;http://www.ubuntu.com/usn/usn-2380-1/&quot;&gt;http://www.ubuntu.com/usn/usn-2380-1/&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;SSLv3 disabled&lt;/h3&gt;
&lt;p&gt;Google researchers have found a &lt;a href=&quot;http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-3566&quot;&gt;critical vulnerability in the SSLv3 protocol&lt;/a&gt;. This protocol is very old and has been replaced with TLS 1.0, 1.1 and 1.2. Due to the vulnerability we have disabled SSLv3 support by default in 11.10.348.&lt;/p&gt;
&lt;p&gt;We strongly recommend against reenabling SSLv3 but if it is needed after upgrading to 11.10.348 by legacy software the following steps will reenable it:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;ghe-unlock

WARNING: This command opens root access to the admin user via sudo. It is
provided as a troubleshooting facility and should be used only under the
guidance of GitHub Enterprise support.

While unlocked, any user with admin SSH access will have full root access to
the VM. Please use with caution and run the ghe-lock command when finished to
prevent accidental modification of system files.

Do you understand? [Y/n] Y
Okay. Full sudo access via the admin user is now enabled.
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Replace the line &lt;code&gt;ssl_protocols TLSv1 TLSv1.1 TLSv1.2;&lt;/code&gt; in &lt;code&gt;/etc/nginx/sites-enabled/github.conf&lt;/code&gt; with &lt;code&gt;ssl_protocols SSLv3 TLSv1 TLSv1.1 TLSv1.2;&lt;/code&gt;:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;sudo sed &#39;s/ssl_protocols TLSv1 TLSv1.1 TLSv1.2/ssl_protocols SSLv3 TLSv1 TLSv1.1 TLSv1.2/&#39; -i /etc/nginx/sites-enabled/github.conf
sudo service nginx reload
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;You can verify if the change was successful by running the following command from outside the instance:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;openssl s_client -connect my-enterprise-instance:443 -ssl3
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;This should show a message similar to the following:&lt;/p&gt;
&lt;pre&gt;&lt;code&gt;CONNECTED(00000003)
..
Server certificate
-----BEGIN CERTIFICATE-----
&lt;/code&gt;&lt;/pre&gt;</description>
					<pubDate>Thu, 16 Oct 2014 08:05:52 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.348</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.348</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.337</title>
					<description>&lt;h3&gt;Security fixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;HIGH: A fix for &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7186&quot;&gt;CVE-2014-7186&lt;/a&gt; and &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7187&quot;&gt;CVE-2014-7187&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Sun, 28 Sep 2014 10:25:50 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.337</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.337</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.347</title>
					<description>&lt;h3&gt;Security fixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;HIGH: A fix for &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7186&quot;&gt;CVE-2014-7186&lt;/a&gt; and &lt;a href=&quot;https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-7187&quot;&gt;CVE-2014-7187&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Bugfixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Forking regression which resulted in substantially more disk space and resource utilization.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Sun, 28 Sep 2014 10:25:49 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.347</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.347</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.346</title>
					<description>&lt;h3&gt;Security fixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;CRIT: A fix for &lt;a href=&quot;http://seclists.org/oss-sec/2014/q3/685&quot;&gt;CVE-2014-7169: remote code execution through bash&lt;/a&gt; has been applied to GitHub Enterprise.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Thu, 25 Sep 2014 16:02:23 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.346</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.346</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.336</title>
					<description>&lt;h3&gt;Security fixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;CRIT: A fix for &lt;a href=&quot;http://seclists.org/oss-sec/2014/q3/685&quot;&gt;CVE-2014-7169: remote code execution through bash&lt;/a&gt; has been applied to GitHub Enterprise.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Thu, 25 Sep 2014 16:02:08 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.336</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.336</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.345</title>
					<description>&lt;h3&gt;Security fixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;CRIT: A fix for &lt;a href=&quot;http://seclists.org/oss-sec/2014/q3/649&quot;&gt;CVE-2014-6271: remote code execution through bash&lt;/a&gt; has been applied to GitHub Enterprise.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Wed, 24 Sep 2014 16:19:03 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.345</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.345</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.335</title>
					<description>&lt;h3&gt;Security fixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;CRIT: A fix for &lt;a href=&quot;http://seclists.org/oss-sec/2014/q3/649&quot;&gt;CVE-2014-6271: remote code execution through bash&lt;/a&gt; has been applied to GitHub Enterprise.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Wed, 24 Sep 2014 16:09:47 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.335</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.335</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.344</title>
					<description>&lt;h3&gt;Bugfixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Site admin rocket icon did not show in Internet Explorer 11.&lt;/li&gt;
&lt;li&gt;Proxy services for Git, Git HTTP and SVN did not log correctly.&lt;/li&gt;
&lt;li&gt;Recent webhook delivery metadata were not displayed in repository settings under some circumstances.&lt;/li&gt;
&lt;li&gt;Pull request synchronization in the site admin could cause a Not Found error.&lt;/li&gt;
&lt;li&gt;Compiled GitHub Pages sites could be improperly removed.&lt;/li&gt;
&lt;li&gt;Support bundles could be extremely large. Rotated logs are now excluded by default.&lt;/li&gt;
&lt;li&gt;Visiting the user page of a suspended user incorrectly caused a Not Found error.&lt;/li&gt;
&lt;li&gt;LDAP user listing in the site admin could time out.&lt;/li&gt;
&lt;li&gt;LDAP &lt;code&gt;posixGroup&lt;/code&gt; membership checks failed improperly.&lt;/li&gt;
&lt;li&gt;Testing connection settings caused an error when the LDAP server was unreachable.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Security fixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRIT&lt;/strong&gt;: Public repository archives were not protected by private mode.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: &lt;a href=&quot;https://launchpad.net/ubuntu/+source/openssl/1.0.1-4ubuntu5.17&quot;&gt;OpenSSL 1.0.1-4ubuntu5.17&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Tue, 02 Sep 2014 06:04:30 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.344</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.344</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.343</title>
					<description>&lt;h3&gt;Bugfixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Incorrect rendering of repository pages when following a link from a Gist.&lt;/li&gt;
&lt;li&gt;Pages generation could fail with SSL enabled.&lt;/li&gt;
&lt;li&gt;reStructuredText files failed to render.&lt;/li&gt;
&lt;li&gt;To prevent broken avatars, set GitHub.com as the default fallback for serving identicons.&lt;/li&gt;
&lt;li&gt;Filtered SNMP community string from the support bundles.&lt;/li&gt;
&lt;li&gt;LDAP authentication timeouts could cause sign in and HTTP clones to fail.&lt;/li&gt;
&lt;li&gt;Upgrades could fail if VMware tools had been installed.&lt;/li&gt;
&lt;li&gt;Collectd was sending duplicate packets when forwarding messages.&lt;/li&gt;
&lt;li&gt;Changed authentication settings could fail to take effect.&lt;/li&gt;
&lt;li&gt;To prevent system authentication logs from becoming too large, we now rotate the auth.log daily and discard them after one week.&lt;/li&gt;
&lt;li&gt;Administrators did not have permission to update firewall rules with UFW.&lt;/li&gt;
&lt;li&gt;Git incorrectly detected commits as unreachable on fetch.&lt;/li&gt;
&lt;li&gt;Elasticsearch status was inconsistent after upgrade.&lt;/li&gt;
&lt;li&gt;When creating a repository with the same name as a deleted repository, the deleted code was restored.&lt;/li&gt;
&lt;li&gt;Upgrade could fail with a large user sessions table.&lt;/li&gt;
&lt;li&gt;Improved styling of search results sort order button.&lt;/li&gt;
&lt;li&gt;Better handling errors when renaming users from stafftools.&lt;/li&gt;
&lt;li&gt;Seat count was misreported.&lt;/li&gt;
&lt;li&gt;Gists with legacy ID URLs cound not be cloned.&lt;/li&gt;
&lt;li&gt;Commit build statuses were not shown after upgrade.&lt;/li&gt;
&lt;li&gt;Removed site_admin API scope from metadata calls.&lt;/li&gt;
&lt;li&gt;Unlocking repositories failed after a sudo timeout with LDAP authentication enabled.&lt;/li&gt;
&lt;li&gt;Webhooks status icons remained grey on delivery.&lt;/li&gt;
&lt;li&gt;Image diffs did not load consistently.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Security fixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;MED: Pages repository submodule could access other repositories on the VM.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Upgrade path&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Please upgrade your instance to GitHub Enterprise 11.10.317 or later before upgrading to 11.10.343.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Wed, 30 Jul 2014 06:22:57 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.343</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.343</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.342</title>
					<description>&lt;h3&gt;Bugfixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Upgrade could fail due to incorrect process ordering&lt;/li&gt;
&lt;li&gt;Upgrade could timeout during database migration&lt;/li&gt;
&lt;li&gt;Upgrade could fail when repository data cannot be found&lt;/li&gt;
&lt;li&gt;Incorrectly allowed duplicate SSH keys in the Management Console&lt;/li&gt;
&lt;li&gt;Gist log files were not rotated&lt;/li&gt;
&lt;li&gt;API rate limiting incorrectly enabled&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Upgrade path&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Please upgrade your instance to GitHub Enterprise 11.10.317 or later before upgrading to 11.10.342.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Thu, 10 Jul 2014 14:49:16 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.342</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.342</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.341</title>
					<description>&lt;h3&gt;Bugfixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Upgrades could fail when using LDAP.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;11.10.340 Improvements&lt;/h2&gt;
&lt;p&gt;This release also includes all features and bug fixes from 11.10.340, including:&lt;/p&gt;
&lt;h3&gt;New Features&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Enterprise Activity Dashboard.&lt;/li&gt;
&lt;li&gt;Git bitmap performance improvements.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1763-better-organizations&quot;&gt;Better organization&lt;/a&gt; and team management.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1819-write-line-notes-from-your-phone&quot;&gt;Mobile line notes&lt;/a&gt; and &lt;a href=&quot;https://github.com/blog/1642-merge-pull-requests-from-your-phone&quot;&gt;mobile pull request merging&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.github.com/help/articles/site-admin-dashboard#reports&quot;&gt;Two-factor authentication status&lt;/a&gt; added to user reports.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1778-webhooks-level-up&quot;&gt;Webhooks configuration and customization improvements&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1827-updated-services-ui&quot;&gt;Updated Services UI&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://developer.github.com/v3/repos/releases/&quot;&gt;Releases API&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1786-enhanced-oauth-security-for-ssh-keys&quot;&gt;Enhanced OAuth security for SSH keys&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1794-recent-activity-for-authentication-credentials&quot;&gt;Recent activity audit for authentication credentials&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1658-view-active-browser-sessions&quot;&gt;Auditing for active browser sessions&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1727-introducing-forward-secrecy-and-authenticated-encryption-ciphers&quot;&gt;Forward secrecy and authenticated encryption ciphers&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.github.com/help/articles/blocking-force-pushes-to-a-repository&quot;&gt;Advanced settings for blocking force pushes&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1707-soft-wrapping-on-prose-diffs&quot;&gt;Soft-wrapping&lt;/a&gt; and &lt;a href=&quot;https://github.com/blog/1784-rendered-prose-diffs&quot;&gt;rendered views&lt;/a&gt; for prose diffs.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1647-viewing-yaml-metadata-in-your-documents&quot;&gt;Embedded YAML metadata rendering&lt;/a&gt; in prose documents.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1825-task-lists-in-all-markdown-documents&quot;&gt;Expanded task lists support&lt;/a&gt; and &lt;a href=&quot;https://github.com/blog/1841-nested-task-lists&quot;&gt;nesting&lt;/a&gt; in prose documents.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1705-expanding-context-in-diffs&quot;&gt;Expanding context in diffs&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1767-redesigned-conversations&quot;&gt;Redesigned conversations&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1828-wikis-now-with-more-love&quot;&gt;Wikis UI improvements&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1833-github-pages-3&quot;&gt;Metadata, sitemaps, build feedback, and pagebuild events&lt;/a&gt; in Pages.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1465-stl-file-viewing&quot;&gt;3D file rendering&lt;/a&gt; and &lt;a href=&quot;https://github.com/blog/1633-3d-file-diffs&quot;&gt;diffing&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Added support for &lt;code&gt;go-import&lt;/code&gt; meta tag.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.github.com/help/articles/firewall&quot;&gt;Ubuntu&#39;s UFW firewall enabled by default&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;LDAP improvements&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.github.com/help/articles/configuring-ldap-authentication&quot;&gt;LDAP users can change their username and still be mapped to the same distinguished name&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.github.com/help/articles/about-ldap-authentication&quot;&gt;Support for group definitions using &lt;code&gt;posixGroup&lt;/code&gt; and &lt;code&gt;groupOfUniqueNames&lt;/code&gt; in addition to the current &lt;code&gt;groupOfNames&lt;/code&gt;&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.github.com/help/articles/about-ldap-authentication&quot;&gt;Support for nested group definitions&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.github.com/help/articles/configuring-ldap-authentication&quot;&gt;More flexible mapping of user fields&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Bugfixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Improperly displayed information about Git alternate networks on the repository admin page.&lt;/li&gt;
&lt;li&gt;Blacklist &amp;quot;network&amp;quot; for user/organization names.&lt;/li&gt;
&lt;li&gt;Improperly displayed &lt;code&gt;Mirrors&lt;/code&gt; filter on repositories listing.&lt;/li&gt;
&lt;li&gt;Inconsistent interface elements displayed when interacting with internal links on custom tabs.&lt;/li&gt;
&lt;li&gt;Improperly excluded some system log files from log forwarding.&lt;/li&gt;
&lt;li&gt;Error during sign in when LDAP passwords contain accented characters.&lt;/li&gt;
&lt;li&gt;Error when creating an LDAP user through the site admin if the login was normalized.&lt;/li&gt;
&lt;li&gt;Failed to load LDAP users page when the directory server&#39;s size limit was exceeded.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Security fixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;MED: Timing attack vulnerability in Management Console.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Mon, 07 Jul 2014 14:23:43 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.341</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.341</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.334</title>
					<description>&lt;h3&gt;Security fixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;CRIT: Improperly standardized user logins could allow users to log in to other user accounts when using GitHub OAuth. Enterprise installations using other authentication methods are not affected.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Mon, 07 Jul 2014 10:14:48 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.334</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.334</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.333</title>
					<description>&lt;h3&gt;CCS Injection Vulnerability (CVE-2014-0224)&lt;/h3&gt;
&lt;p&gt;The ChangeCipherSpec vulnerability in the OpenSSL library allows third parties to perform man-in-the-middle attacks. In other words, if attackers can intercept encrypted network traffic they can decrypt it without their victims knowing.&lt;/p&gt;
&lt;p&gt;This attack only works on servers that use OpenSSL version 1.0.1 or later. The version at the client doesn&#39;t matter. GitHub Enterprise itself is not vulnerable because it ships with OpenSSL 1.0.0.&lt;/p&gt;
&lt;p&gt;However, webhooks might be vulnerable to this attack. If the server that is the target of the webhook is running a vulnerable version of OpenSSL and an attacker can intercept network traffic, they would be able to decrypt the communication.&lt;/p&gt;
&lt;p&gt;We care about the security of our customers and therefore decided that even though the risk is minimal the best solution is to issue an update.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MED&lt;/strong&gt;: Updated OpenSSL to the latest version due to some recently identified security vulnerabilities (&lt;a href=&quot;https://www.openssl.org/news/secadv_20140605.txt&quot;&gt;OpenSSL Security Advisory (05 Jun 2014)&lt;/a&gt;).&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Bugfixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Fixed an upgrade issue that would cause failures when upgrading from versions prior to 11.10.260.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Tue, 10 Jun 2014 06:40:53 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.333</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.333</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.332</title>
					<description>&lt;h3&gt;Heartbleed Vulnerability Information&lt;/h3&gt;
&lt;p&gt;GitHub Enterprise is not (and was not) affected by the Heartbleed vulnerability. The version of OpenSSL included with the appliance is not vulnerable to the attack. Please contact us at &lt;a href=&quot;mailto:enterprise@github.com&quot;&gt;enterprise@github.com&lt;/a&gt; if we can help elaborate on this in any way.&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRIT:&lt;/strong&gt; An authorized user could perform remote command execution with specially crafted Git requests.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH:&lt;/strong&gt; Remote content could be loaded in faceboxes by injecting &lt;code&gt;rel=facebox&lt;/code&gt; in user-editable content.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH:&lt;/strong&gt; Java applications were potentially remotely exploitable (&lt;a href=&quot;http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/2188432.xml&quot;&gt;Oracle&#39;s April 2014 Critical Patch Update&lt;/a&gt;).&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED:&lt;/strong&gt; A potential regex DoS attack vector existed in the API.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED:&lt;/strong&gt; A public repository could be compared to a private fork by an unauthorized user using the API.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED:&lt;/strong&gt; YAML URI parsing could allow arbitrary code execution through a heap overflow (&lt;a href=&quot;http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-2525&quot;&gt;CVE-2014-2525&lt;/a&gt;).&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Bugfixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;A race condition during configuration could prevent some processes from restarting.&lt;/li&gt;
&lt;li&gt;Repository size on disk was miscalculated in some circumstances.&lt;/li&gt;
&lt;li&gt;Paths were not always properly UTF-8 encoded when using Subversion.&lt;/li&gt;
&lt;li&gt;File size limits were too restrictive when using Subversion.&lt;/li&gt;
&lt;li&gt;Merging a pull request could introduce repository corruption in some cases.&lt;/li&gt;
&lt;li&gt;Web requests to repository pages were not properly redirected when .git was appended.&lt;/li&gt;
&lt;li&gt;Users could create repositories via the API that they subsequently couldn&#39;t access under some conditions.&lt;/li&gt;
&lt;li&gt;The API incorrectly returned a 404 Not Found status in some cases when an incorrect LDAP password was used.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Wed, 23 Apr 2014 07:47:40 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.332</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.332</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.331</title>
					<description>&lt;p&gt;Last month GitHub launched a &lt;a href=&quot;https://github.com/blog/1770-github-security-bug-bounty&quot;&gt;Security Bug Bounty program&lt;/a&gt;, which has been wildly successful in identifying a number of security vulnerabilities ranging from low to critical risk on GitHub.com. To get these fixes to you more quickly, we&#39;ve pushed the 11.10.330 Feature Release back to 11.10.340. Between now and then, we&#39;ll be using the 11.10.33x series for further security/bugfix releases.&lt;/p&gt;
&lt;p&gt;This release addresses the following issues:&lt;/p&gt;
&lt;h3&gt;Security&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRIT:&lt;/strong&gt; Root exploit vulnerability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CRIT:&lt;/strong&gt; Authentication bypass vulnerability for LDAP under certain conditions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH:&lt;/strong&gt; Gist vulnerability that could grant access to private repos under a targeted chain attack.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH:&lt;/strong&gt; Content Security Policy (CSP) bypass vulnerability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH:&lt;/strong&gt; Flash Cross Site Scripting (XSS) vulnerability for raw blobs.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH:&lt;/strong&gt; DOM-based XSS + CSP bypass vulnerability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED:&lt;/strong&gt; JSONP callback vulnerability that could result in arbitrary Flash execution.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED:&lt;/strong&gt; OAuth URL parsing open redirect vulnerability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MED:&lt;/strong&gt; Vulnerability where raw gist content could be viewed without authentication for public gists when Private Mode was enabled.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW:&lt;/strong&gt; Issue where the &lt;code&gt;dotcom_user&lt;/code&gt; session cookie wasn&#39;t being removed on logout.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW:&lt;/strong&gt; Open redirect vulnerability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW:&lt;/strong&gt; SSH key audit verification CSRF vulnerability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW:&lt;/strong&gt; Contributor Graph XSS vulnerability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW:&lt;/strong&gt; OAuth URL parsing path traversal vulnerability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW:&lt;/strong&gt; Login open redirect vulnerability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW:&lt;/strong&gt; OAuth subdomain bypass vulnerability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW:&lt;/strong&gt; Java updated to pull in a variety of security and bug fixes.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;General&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-user-demote&lt;/code&gt; was demoting admins improperly (they still lost admin privileges).&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;audit.log&lt;/code&gt; file was unreadable by the admin SSH user.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;GitHub&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Pull request mergeability checks were failing under some conditions when opening new pull requests.&lt;/li&gt;
&lt;li&gt;System emails being sent to a user with no primary email set would cause an error.&lt;/li&gt;
&lt;li&gt;Exceptions weren&#39;t being reported properly in some cases.&lt;/li&gt;
&lt;li&gt;Audit log data wasn&#39;t being printed as valid JSON.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Authentication&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;The first LDAP user who logged in wasn&#39;t being auto-promoted to Site Admin if no Admin Group was specified.&lt;/li&gt;
&lt;li&gt;Not all errors were displayed if any were encountered when a user first signed in under LDAP.&lt;/li&gt;
&lt;li&gt;GitHub for Mac would fail to authenticate properly if Private Mode was enabled.&lt;/li&gt;
&lt;li&gt;GitHub for Mac would fail to authenticate properly with user logins that had to be normalized (e.g., had a period or underscore in them).&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Git&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Git push performance regression affecting repositories with large numbers of refs (branches/tags).&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;API&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;API scope validation issue producing false positives.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Thu, 20 Feb 2014 15:46:01 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.331</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.331</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.329</title>
					<description>&lt;h4&gt;Security&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: Fixed a vulnerability affecting Pages that would allow arbitrary file reads and writes on the installation.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;General&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a bug where Pull Request merge status checks were failing in some cases when opening a new Pull Request.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Authentication&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a bug where invalid data in LDAP mail attributes would prevent new user accounts from being created.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Thu, 09 Jan 2014 14:29:33 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.329</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.329</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.328</title>
					<description>&lt;h4&gt;General&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a bug where editing files in the web editor using Safari under Mavericks resulted in the cursor being displayed incorrectly.&lt;/li&gt;
&lt;li&gt;Fixed a bug where migrating from older releases would trigger errors during the configuration process.&lt;/li&gt;
&lt;li&gt;Fixed a bug where viewing a user&#39;s comments in the Admin Tools dashboard would throw a 500 if a Gist comment was included.&lt;/li&gt;
&lt;li&gt;Fixed a bug that could cause race conditions when attempting to merge pull requests that would result in a 500 error.&lt;/li&gt;
&lt;li&gt;Removed rate limiting options from the OAuth application settings as rate limiting is globally disabled on Enterprise.&lt;/li&gt;
&lt;li&gt;Fixed a bug where gravatars continued being displayed on repository network graphs even when they were disabled.&lt;/li&gt;
&lt;li&gt;Fixed a bug where pull requests that were far behind their head ref would be incorrectly closed automatically.&lt;/li&gt;
&lt;li&gt;Fixed a bug where a branch could be deleted from a merged pull request when another open pull request was using it as its base.&lt;/li&gt;
&lt;li&gt;Suspended users now get see the email address of the GitHub Enterprise administrator, if they&#39;ve added it in the settings.&lt;/li&gt;
&lt;li&gt;Fixed a bug where the support bundle was attempting to include a non-existent directory.&lt;/li&gt;
&lt;li&gt;Fixed a bug where the configured support email wasn&#39;t being used on the maintenance page.&lt;/li&gt;
&lt;li&gt;Fixed a bug where ProTips for GitHub.com where being shown instead of the ones specific to GitHub Enterprise.&lt;/li&gt;
&lt;li&gt;Added support for large cookies (up to 32 kb) to better support highly proxied environments.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Authentication&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a bug where the All LDAP users section of the Admin Tools dashboard would yield a 500 error under some conditions.&lt;/li&gt;
&lt;li&gt;Fixed a bug where login errors due to not being in an allowed LDAP group were not distinguished from incorrect credentials at login time.&lt;/li&gt;
&lt;li&gt;Fixed a bug where multiple attempts at creating LDAP user emails were being made on initial login resulting in an error.&lt;/li&gt;
&lt;li&gt;Fixed a bug where a 500 error could occur if none of the restricted LDAP groups were found.&lt;/li&gt;
&lt;li&gt;Fixed a bug where the LDAP configuration test wasn&#39;t limiting its user search to the specified groups.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Gist&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a bug where navigation links weren&#39;t respecting the custom appliance hostname.&lt;/li&gt;
&lt;li&gt;Fixed a bug where embedded gists weren&#39;t rendering properly.&lt;/li&gt;
&lt;li&gt;Fixed a bug where viewing gists in IE11 would result in a 422 Unprocessable Entity browser error.&lt;/li&gt;
&lt;li&gt;Fixed a bug where previewing comments in gists would fail.&lt;/li&gt;
&lt;li&gt;Fixed a bug where the Google Analytics code for GitHub.com was being included in gist pages.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Wed, 18 Dec 2013 10:26:29 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.328</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.328</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.327</title>
					<description>&lt;h4&gt;Security&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRIT&lt;/strong&gt;: Updated Java and other system packages to address critical vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CRIT&lt;/strong&gt;: Updated Ruby to protect against a buffer overflow vulnerability.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;CRIT&lt;/strong&gt;: Fixed a bug where a user could craft a special request that would allow arbitrary command execution on the appliance.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: Updated git for 32-bit and 64-bit installs to prevent a buffer overflow under some conditions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: Kernel updated to prevent an exploit where an SSH user on the appliance could potentially gain elevated root permissions.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: Fixed a bug in the API that would allow for brute force password guessing.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;HIGH&lt;/strong&gt;: Updated Gist to address new Rails security vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Fixed a bug that allowed users to inject LDAP filters into the username field on the login page.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Fixed an issue where a Gist&#39;s content wasn&#39;t filtered correctly and therefore appeared in the log files.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Wed, 04 Dec 2013 15:17:14 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.327</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.327</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.326</title>
					<description>&lt;h4&gt;Bugfixes&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed an issue that occurred under specific conditions that caused erroneous LDAP validation errors which prevented settings from being changed in the Management Console.&lt;/li&gt;
&lt;li&gt;Fixed an issue that caused Gists to display error messages when browsed to if they had been commented on.&lt;/li&gt;
&lt;li&gt;Fixed an issue where the email service hook wasn&#39;t respecting the TLS SMTP option configured for the installation.&lt;/li&gt;
&lt;li&gt;Fixed a bug where moving a block device that had previously been used on another installation and attaching it to a new installation would result in any data it contained being deleted.&lt;/li&gt;
&lt;li&gt;Fixed a bug where Reports being generated would include partial datasets under some conditions.&lt;/li&gt;
&lt;li&gt;Fixed a bug where Gist indexing was occurring in-line during upgrades rather than in the background, which caused some upgrades to fail due to a timeout.&lt;/li&gt;
&lt;li&gt;Re-enabled &amp;quot;Detach from network&amp;quot; option for repositories in the Admin Tools dashboard.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Mon, 28 Oct 2013 11:05:29 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.326</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.326</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.325</title>
					<description>&lt;h4&gt;Security&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Fixed a bug where service hook delivery lists were accessible to unauthenticated users on publicly accessible installations. No customer data would have been accessible from this page.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Bugfixes&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a bug where email service hooks weren&#39;t delivering mail properly for installations with SMTP Authentication set to &amp;quot;none&amp;quot;.&lt;/li&gt;
&lt;li&gt;Fixed LDAP issues related to bases and groups not validating properly in some cases when attempting to save settings or test.&lt;/li&gt;
&lt;li&gt;Fixed a bug where teams added as collaborators on repositories were showing up twice. To fix cases where this is already present, remove and re-add the team.&lt;/li&gt;
&lt;li&gt;Re-enabled the public push option for repositories.&lt;/li&gt;
&lt;li&gt;Fixed a bug where the &lt;code&gt;ghe-es-reindex&lt;/code&gt; utility wasn&#39;t applying to all search indexes.&lt;/li&gt;
&lt;li&gt;Removed the &lt;code&gt;ghe-es-reset&lt;/code&gt; utility since its functionality has been superseded by &lt;code&gt;ghe-es-reindex&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Fixed a bug where archives weren&#39;t building properly for private repositories.&lt;/li&gt;
&lt;li&gt;Fixed a bug where the Gist API was providing an incorrect URL for raw files.&lt;/li&gt;
&lt;li&gt;Fixed a bug where re-authorization prompts were happening when adding users to teams under CAS authentication (where re-authorization prompts don&#39;t work).&lt;/li&gt;
&lt;li&gt;Fixed a bug where use of non-https image URLs in Gist was resulting in broken images.&lt;/li&gt;
&lt;li&gt;Fixed a bug where two-factor authentication wouldn&#39;t work properly with GitHub for Mac when using the GitHub OAuth authentication option.&lt;/li&gt;
&lt;li&gt;Fixed a bug where users with disallowed characters in their LDAP username (which are converted to dashes ordinarily) couldn&#39;t log in using GitHub native clients.&lt;/li&gt;
&lt;li&gt;Fixed a bug where Pages sites weren&#39;t being properly renamed after a user or organization was renamed.&lt;/li&gt;
&lt;li&gt;Fixed a bug where a variety of errors were showing up due to users not having a primary email set.&lt;/li&gt;
&lt;li&gt;Fixed a bug where HTML tables weren&#39;t being rendered properly in inline comments.&lt;/li&gt;
&lt;li&gt;Fixed a bug where services weren&#39;t always being restarted as they should after configuration runs. This resolves an issue with hostname updates when viewing service hook deliveries and viewing gists when private mode is disabled.&lt;/li&gt;
&lt;li&gt;Fixed a bug where the &amp;quot;All Gists&amp;quot; link was no longer being displayed in Gist.&lt;/li&gt;
&lt;li&gt;Fixed CSS rendering issue on the Explore page.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Thu, 17 Oct 2013 15:23:50 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.325</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.325</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.324</title>
					<description>&lt;h4&gt;Security&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRIT&lt;/strong&gt;: Fixed a vulnerability that would allow an individual to login as any user under LDAP authentication. &lt;strong&gt;Other methods of authentication and releases prior to 11.10.320 are unaffected.&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Mon, 23 Sep 2013 18:08:36 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.324</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.324</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.323</title>
					<description>&lt;h4&gt;Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Added a banner to remind users to add an email address if they don&#39;t have one.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Bugfixes&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a bug where disk usage units in the admin stats bar are wrong.&lt;/li&gt;
&lt;li&gt;ElasticSearch cluster status was incorrectly displayed as &#39;yellow&#39;.&lt;/li&gt;
&lt;li&gt;Fixed a bug where email service hooks weren&#39;t delivering emails properly.&lt;/li&gt;
&lt;li&gt;Fixed a bug where saving settings in the Management Console doesn&#39;t work if SSL is enabled.&lt;/li&gt;
&lt;li&gt;Fixed a bug where GitHub OAuth authentication caused a redirect loop at login.&lt;/li&gt;
&lt;li&gt;Fixed a bug where previewing a wiki page would throw a 500 error.&lt;/li&gt;
&lt;li&gt;Fixed a bug where public repos were showing up with private repo styling.&lt;/li&gt;
&lt;li&gt;Fixed a bug where the signout confirmation page wasn&#39;t mobile friendly.&lt;/li&gt;
&lt;li&gt;Fixed a bug with database migrations that affected really old installations upgrading to the latest version.&lt;/li&gt;
&lt;li&gt;Fixed a bug where pushing to a gist using git over http(s) would throw an exception in the post-receive hook.&lt;/li&gt;
&lt;li&gt;Fixed a bug where wiki spam check jobs were queueing mistakenly and never processed.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Fri, 20 Sep 2013 11:29:57 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.323</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.323</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.322</title>
					<description>&lt;h4&gt;Security&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;MOD&lt;/strong&gt;: Fixed a bug where passwords weren&#39;t being filtered properly when an exception occurred while logging in.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Bugfixes&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a bug involving the two-factor authentication configuration. &lt;strong&gt;Note that this will invalidate 2FA for accounts where it&#39;s enabled. Use Forgot Password workflow to re-enable affected accounts.&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;Fixed a bug where Gist would throw a 500 error under some conditions when an SSL certificate was installed.&lt;/li&gt;
&lt;li&gt;Fixed a bug where old style Gist URLs weren&#39;t redirecting properly.&lt;/li&gt;
&lt;li&gt;Fixed a bug where LDAP logins were breaking when using SSL encryption.&lt;/li&gt;
&lt;li&gt;Fixed a bug where LDAP groups weren&#39;t behaving as expected with some LDAP server variants.&lt;/li&gt;
&lt;li&gt;Fixed a bug where LDAP searches weren&#39;t filtering as expected with some LDAP server variants.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Mon, 16 Sep 2013 00:12:51 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.322</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.322</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.321</title>
					<description>&lt;h4&gt;Bugfixes&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a bug that was preventing notifications from sending properly.&lt;/li&gt;
&lt;li&gt;Fixed a bug that was causing upgrades to fail if you were using GitHub OAuth authentication.&lt;/li&gt;
&lt;li&gt;Made some adjustments to the LDAP Users view to help it work better under some LDAP implementations.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Fri, 13 Sep 2013 10:20:20 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.321</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.321</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.320</title>
					<description>&lt;h3&gt;New&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.github.com/help/articles/configuring-ldap-authentication&quot;&gt;&lt;strong&gt;LDAP Group Authentication&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.github.com/help/articles/configuring-collectd&quot;&gt;&lt;strong&gt;Collectd Monitoring&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1614-two-factor-authentication&quot;&gt;&lt;strong&gt;Two-factor Authentication&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1559-github-s-on-your-phone&quot;&gt;&lt;strong&gt;Mobile Views&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1276-welcome-to-a-new-gist&quot;&gt;&lt;strong&gt;New Gist&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1547-release-your-software&quot;&gt;&lt;strong&gt;Releases&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1529-repository-next&quot;&gt;&lt;strong&gt;Repository Next UI Refresh&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1586-identicons&quot;&gt;&lt;strong&gt;Identicons&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1585-explore-what-is-trending-on-github&quot;&gt;&lt;strong&gt;New Explore &amp;amp; Trending Views&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1564-code-search-api&quot;&gt;&lt;strong&gt;Code Search API&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1582-checking-out-pull-requests&quot;&gt;&lt;strong&gt;Checking out Pull Requests&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1523-oauth-improvements&quot;&gt;&lt;strong&gt;OAuth Improvements&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1554-explore-everyone-s-stars&quot;&gt;&lt;strong&gt;Explore Everyone&#39;s Stars&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1545-deleting-files-on-github&quot;&gt;&lt;strong&gt;Deleting files on GitHub&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1542-task-lists-in-gist&quot;&gt;&lt;strong&gt;Task Lists in Gist&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1508-repository-redirects-are-here&quot;&gt;&lt;strong&gt;Repository redirects&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1533-new-file-size-limits&quot;&gt;&lt;strong&gt;File Size Limits&lt;/strong&gt;&lt;/a&gt; (note: no pushes are rejected currently)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.github.com/help/articles/troubleshooting-service-hooks&quot;&gt;&lt;strong&gt;Improved Service Hook Backend&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Enhancements&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Upgraded git to v1.8.4. This should fix some repository corruption issues caused by git race conditions.&lt;/li&gt;
&lt;li&gt;Removed solr (all searching is now uses ElasticSearch).&lt;/li&gt;
&lt;li&gt;Admin CSV reports are now only cached for an hour (down from 24 hours).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Additional information is available &lt;a href=&quot;https://github.com/blog/1627-github-enterprise-11-10-320-release&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
					<pubDate>Fri, 13 Sep 2013 06:56:18 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.320</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.320</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.317</title>
					<description>&lt;h4&gt;Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Updated server-side gitconfig to remove the &lt;code&gt;packSizeLimit&lt;/code&gt;. This should result in better performance for very large repositories.&lt;/li&gt;
&lt;li&gt;Added stale &lt;code&gt;.keep&lt;/code&gt; file check to &lt;code&gt;ghe-cleanup-repos&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Bugfixes&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed an issue where service hooks sending payloads to external services using self-signed SSL certificates would fail silently.&lt;/li&gt;
&lt;li&gt;Fixed an issue where attempting to upgrade an expired license resulted in a 403 error.&lt;/li&gt;
&lt;li&gt;Fixed an issue where uploading new license files would sometimes result in 401 unauthorized errors.&lt;/li&gt;
&lt;li&gt;Fixed an issue preventing email addresses with apostrophes in them from working properly.&lt;/li&gt;
&lt;li&gt;Fixed an issue where the URLs provided by the root API URL were incorrect.&lt;/li&gt;
&lt;li&gt;Fixed an issue that caused the &lt;code&gt;/applications&lt;/code&gt; API endpoint to fail when Private Mode was enabled.&lt;/li&gt;
&lt;li&gt;Fixed a bug where the admin SSH &lt;code&gt;.profile&lt;/code&gt; wasn&#39;t being managed which could lead to a broken PATH.&lt;/li&gt;
&lt;li&gt;Fixed a bug where an organization&#39;s ATOM feed was inaccessible when running the appliance in Private Mode.&lt;/li&gt;
&lt;li&gt;Fixed a bug affecting image asset uploads in issues and pull request comments that were made by pasting an image from the clipboard.&lt;/li&gt;
&lt;li&gt;Fixed an issue where some MySQL imports using &lt;code&gt;ghe-import-mysql&lt;/code&gt; would fail with &lt;code&gt;max_allowed_packet&lt;/code&gt; errors.&lt;/li&gt;
&lt;li&gt;Fixed an issue that would cause networking issues for some OVAs after being cloned.&lt;/li&gt;
&lt;li&gt;Fixed a bug where admin SSH public key fingerprints weren&#39;t matching &lt;code&gt;ssh-keygen -lf&lt;/code&gt; output.&lt;/li&gt;
&lt;li&gt;Fixed a bug where nodeload archives were being exported with repositories when using &lt;code&gt;ghe-export-repositories&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Fixed a bug in the Management Console API that prevented settings updates from working in some cases.&lt;/li&gt;
&lt;li&gt;Fixed a bug where UTF-8 encoding errors would prevent license installation under some conditions.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Wed, 21 Aug 2013 14:09:51 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.317</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.317</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.316</title>
					<description>&lt;h4&gt;Bugfixes&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a bug where changes to SMTP settings weren&#39;t being properly applied to all processes.&lt;/li&gt;
&lt;li&gt;Fixed a bug where user and organization Pages sites weren&#39;t being built properly.&lt;/li&gt;
&lt;li&gt;Fixed a bug where reports would time out on large installations.&lt;/li&gt;
&lt;li&gt;Fixed a bug where Language rankings weren&#39;t being calculated or displayed properly.&lt;/li&gt;
&lt;li&gt;Removed GitHub.com-specific error message for git protocol operations when the maintenance page was up.&lt;/li&gt;
&lt;li&gt;Removed &lt;code&gt;ghe-import&lt;/code&gt; and &lt;code&gt;ghe-export&lt;/code&gt; meta utilities that were broken and shouldn&#39;t be used over the more specific &lt;code&gt;ghe-{import,export}-*&lt;/code&gt; utilities.&lt;/li&gt;
&lt;li&gt;Indexing of &lt;code&gt;/setup/*&lt;/code&gt; by search indexing robots is now prevented.&lt;/li&gt;
&lt;li&gt;Fixed a bug where a race condition could occur when uploading a GHP via the Management Console API that would cause the GHP to be deleted before it was unpacked.&lt;/li&gt;
&lt;li&gt;Fixed a bug where an unnecessary post-receive hook would cause &lt;code&gt;--mirror&lt;/code&gt; git push operations for repositories with large numbers of refs to take extremely long.&lt;/li&gt;
&lt;li&gt;Disallowed http clones for CAS authentication and hid http cloning URLs in the UI (http authentication doesn&#39;t work under CAS authentication).&lt;/li&gt;
&lt;li&gt;Updated &lt;code&gt;ghe-cleanup-repos&lt;/code&gt; utility to detect zero byte ref files and fix them when possible.&lt;/li&gt;
&lt;li&gt;Fixed a bug where the owner email address would always show up as &lt;code&gt;nil&lt;/code&gt; in webhook API payloads if the owner was an organization.&lt;/li&gt;
&lt;li&gt;Fixed a bug where the embed URL of a gist was shown html escaped.&lt;/li&gt;
&lt;li&gt;Fixed a bug where password reset notification emails were referring to GitHub.com.&lt;/li&gt;
&lt;li&gt;Fixed a bug where the Enterprise Stats API wasn&#39;t returning the correct count of suspended users.&lt;/li&gt;
&lt;li&gt;Fixed a bug that caused migrations from GitHub:FI to fail during the database migration.&lt;/li&gt;
&lt;li&gt;Log forwarding now includes &lt;code&gt;auth.log&lt;/code&gt; and &lt;code&gt;production.log&lt;/code&gt; files in the stream.&lt;/li&gt;
&lt;li&gt;Removed &amp;quot;Email&amp;quot; wording from the Pages generation notification.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Mon, 08 Jul 2013 10:19:52 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.316</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.316</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.315</title>
					<description>&lt;h4&gt;Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Added the ability for users to add notes to OAuth tokens created via the web UI.&lt;/li&gt;
&lt;li&gt;Added the ability to cleanup zip/tarball archives and repositories in purgatory via &lt;code&gt;ghe-cleanup-caches&lt;/code&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Bugfixes&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed some bugs involving switching repository storage from using the root filesystem to a block device.&lt;/li&gt;
&lt;li&gt;Fixed an issue where LDAP authentication using SSL could break when updating settings.&lt;/li&gt;
&lt;li&gt;The &amp;quot;search&amp;quot; username is now reserved.&lt;/li&gt;
&lt;li&gt;Fixed a bug where service hook payloads could be truncated if they contained multibyte characters.&lt;/li&gt;
&lt;li&gt;Fixed a bug where the &lt;code&gt;ghe-cleanup-repos&lt;/code&gt; utility threw errors when trying to cleanup repositories that were in the database, but not on disk.&lt;/li&gt;
&lt;li&gt;Re-added the solr-related utilities for gist.&lt;/li&gt;
&lt;li&gt;Fixed a bug where GitHub OAuth settings were being left out of diagnostics output.&lt;/li&gt;
&lt;li&gt;Fixed a bug where &lt;code&gt;ghe-export-pages&lt;/code&gt; wouldn&#39;t provide any feedback when no pages data existed.&lt;/li&gt;
&lt;li&gt;Fixed a bug where dormant users weren&#39;t showing up properly in Reports and Dormant Users listing.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Wed, 05 Jun 2013 12:33:24 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.315</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.315</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.314</title>
					<description>&lt;h4&gt;Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Users can now generate OAuth tokens via the web UI in the Account Settings &amp;gt; Applications area.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Bugfixes&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a bug that prevented Pages from being generated properly.&lt;/li&gt;
&lt;li&gt;Fixed a bug where issue and pull request notification status information disappeared for past notifications in the web UI.&lt;/li&gt;
&lt;li&gt;Fixed a problem that prevented the configuration run from completing on a new VM when adding a new repository block device.&lt;/li&gt;
&lt;li&gt;Fixed a problem where the last configuration step would show as completed before the run was actually done.&lt;/li&gt;
&lt;li&gt;Fixed a bug where users weren&#39;t being considered dormant if they had private repositories.&lt;/li&gt;
&lt;li&gt;Fixed a bug where changing certain settings could break images and formatting under some conditions.&lt;/li&gt;
&lt;li&gt;Removed &amp;quot;Open Source&amp;quot; wording from Contributions graph.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Thu, 16 May 2013 15:50:51 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.314</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.314</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.313</title>
					<description>&lt;h4&gt;Bugfixes&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a bug preventing service hooks from firing properly.&lt;/li&gt;
&lt;li&gt;Resolved some problems in 11.10.312 related to internal build issues.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Fri, 10 May 2013 14:11:26 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.313</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.313</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.312</title>
					<description>&lt;h4&gt;Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Added checks to fail early if a GHP is uploaded for the wrong architecture.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Bugfixes&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Increased unicorn failed timeout for Management Console to avoid some timeout errors.&lt;/li&gt;
&lt;li&gt;Fixed a bug where SSH pushes were failing with 0x06 errors under some conditions due to timeouts.&lt;/li&gt;
&lt;li&gt;Fixed a load order issue that caused upgrades to fail with certain sets of configuration settings.&lt;/li&gt;
&lt;li&gt;Fixed a bug involving javascript error handling on the Management Console upgrade page.&lt;/li&gt;
&lt;li&gt;Fixed a bug where the &amp;quot;Sync Pull Request&amp;quot; link in the Admin Tools repository facebox would 404.&lt;/li&gt;
&lt;li&gt;Fixed a bug where the Suspended users view would throw 500 errors.&lt;/li&gt;
&lt;li&gt;Fixed a bug where some post-receive hooks would throw encoder errors.&lt;/li&gt;
&lt;li&gt;Fixed a bug where downloading a repository report would lead to a 500 error under certain conditions.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Thu, 09 May 2013 17:14:13 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.312</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.312</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.311</title>
					<description>&lt;h4&gt;Bugfixes&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed bug causing a LoadError during git clone and push operations.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Wed, 08 May 2013 02:23:52 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.311</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.311</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.310</title>
					<description>&lt;h3&gt;Security&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;CRIT&lt;/strong&gt;: Fixed potential authentication bypass in the Management Console.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;MOD&lt;/strong&gt;: Fixed privilege escalation vulnerability due to world writable executable.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;LOW&lt;/strong&gt;: Session cookie expiration time lowered to 1 week.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;New&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1395-relative-links-in-markup-files&quot;&gt;&lt;strong&gt;Relative links in markup files&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1396-sorting-through-search-results&quot;&gt;&lt;strong&gt;Sorting through search results&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1399-quick-quotes&quot;&gt;&lt;strong&gt;Quick quotes&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1408-global-issue-search&quot;&gt;&lt;strong&gt;Global Issue Search&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1410-sortable-stars&quot;&gt;&lt;strong&gt;Sortable Stars&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1437-better-live-updates&quot;&gt;&lt;strong&gt;Better live updates&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1436-moving-and-renaming-files-on-github&quot;&gt;&lt;strong&gt;Moving and Renaming Files on GitHub&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1439-closing-issues-across-repositories&quot;&gt;&lt;strong&gt;Closing Issues Across Repositories&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1451-branch-and-tag-labels-for-commit-pages&quot;&gt;&lt;strong&gt;Branch and Tag Labels for Commit Pages&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1458-quickly-access-repositories-you-contribute-to&quot;&gt;&lt;strong&gt;Quickly access Repositories you contribute to&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1461-a-smarter-more-complete-y-search-bar&quot;&gt;&lt;strong&gt;A smarter, more complete search bar&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1469-redesigned-merge-button&quot;&gt;&lt;strong&gt;Redesigned merge button&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1476-get-up-to-speed-with-pulse&quot;&gt;&lt;strong&gt;Get up to speed with Pulse&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1484-check-the-status-of-your-branches&quot;&gt;&lt;strong&gt;Check the status of your branches&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.githubsupport.com/entries/23754178-GitHub-OAuth-Configuration&quot;&gt;&lt;strong&gt;GitHub OAuth Authentication&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Enhancements&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Upgraded git to v1.8.1.6.&lt;/li&gt;
&lt;li&gt;Added ElasticSearch disk usage information to diagnostics.&lt;/li&gt;
&lt;li&gt;Removed git-daemon max connections limit.&lt;/li&gt;
&lt;li&gt;Increased MySQL innodb_buffer_pool_size from 8MB to 128MB.&lt;/li&gt;
&lt;li&gt;Added better sysctl defaults and the ability to customize them (see /etc/sysctl.conf for details).&lt;/li&gt;
&lt;li&gt;Added access to some limited sudo capabilities (netstat, kill, lsof, tcpdump, strace, tail, grep, shutdown).&lt;/li&gt;
&lt;li&gt;Added timeout cache clearing to &amp;quot;Clear Page Cache&amp;quot; functionality in Admin Tools facebox (hit backslash while viewing a repo).&lt;/li&gt;
&lt;li&gt;Added new Reports section in the Admin Tools dashboard to download CSV reports of users, organizations, and repositories.&lt;/li&gt;
&lt;li&gt;Added the ability to bulk suspend dormant users.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3&gt;Bugfixes&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;Site Admins can now create wikis without disabling admin mode.&lt;/li&gt;
&lt;li&gt;In-repo source code searches for public repositories would throw 404 errors.&lt;/li&gt;
&lt;li&gt;Importing from MySQL backups taken prior to 11.10.300 could prevent logins from working if a configuration run wasn&#39;t performed.&lt;/li&gt;
&lt;li&gt;ElasticSearch indexes weren&#39;t being properly created under some conditions. This release will perform a full reindex.&lt;/li&gt;
&lt;li&gt;Ignore whitespace in diffs wasn&#39;t working as expected.&lt;/li&gt;
&lt;li&gt;Customer license information wasn&#39;t being displayed in diagnostics output.&lt;/li&gt;
&lt;li&gt;Logging out under CAS authentication wasn&#39;t working.&lt;/li&gt;
&lt;li&gt;Display issues on the license expiration page.&lt;/li&gt;
&lt;li&gt;An interrupted upgrade could put the install in a bad state.&lt;/li&gt;
&lt;li&gt;Upgrading would sometimes throw a 500 error while uploading the new GHP.&lt;/li&gt;
&lt;li&gt;Exporting/importing ssh authorized keys raised an error.&lt;/li&gt;
&lt;li&gt;Caching wasn&#39;t being properly cleared when gravatars were enabled, the hostname was changed or SSL was enabled.&lt;/li&gt;
&lt;li&gt;Gravatars stopped showing up properly even when email addresses were present.&lt;/li&gt;
&lt;li&gt;Some process monitoring-related issues would sometimes prevent git-daemon from starting properly after upgrades.&lt;/li&gt;
&lt;li&gt;Submodules living on GitHub.com would be linked to as if they were local.&lt;/li&gt;
&lt;li&gt;Some cookies were not being set to HttpOnly.&lt;/li&gt;
&lt;li&gt;Deleting an organization was failing.&lt;/li&gt;
&lt;li&gt;Downloading support bundles would sometimes throw 500 errors preventing them from being downloaded via the web UI.&lt;/li&gt;
&lt;li&gt;Pull requests from forks defaulted the target branch to master rather than the corresponding upstream branch.&lt;/li&gt;
&lt;li&gt;Timeouts when opening pull requests resulted in a 500 rather than a more user-friendly error message.&lt;/li&gt;
&lt;li&gt;User to Organization conversions were throwing a 500 error, making it impossible to convert a user to an organization.&lt;/li&gt;
&lt;li&gt;Unlocking private repositories as a site admin now works as expected.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Additional information is available &lt;a href=&quot;https://github.com/blog/1494-github-enterprise-11-10-310-release&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
					<pubDate>Wed, 08 May 2013 02:23:46 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.310</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.310</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.302</title>
					<description>&lt;h4&gt;Security&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed Rack::Session::Cookie timing attack vulnerability (&lt;a href=&quot;http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-0263&quot;&gt;CVE-2013-0263&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Fixed unsafe object creation vulnerability in JSON (&lt;a href=&quot;http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-0269&quot;&gt;CVE-2013-0269&lt;/a&gt; | &lt;a href=&quot;https://groups.google.com/forum/?fromgroups=#!topic/rubyonrails-security/4_YvCpLzL58&quot;&gt;more info&lt;/a&gt;)&lt;/li&gt;
&lt;li&gt;Fixed unsafe YAML attribute serialization vulnerability (&lt;a href=&quot;http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-0277&quot;&gt;CVE-2013-0277&lt;/a&gt; | &lt;a href=&quot;https://groups.google.com/forum/?fromgroups=#!topic/rubyonrails-security/KtmwSbEpzrU&quot;&gt;more info&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Upgraded git to our latest custom build, fixing some issues with refs going missing under certain conditions.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Mon, 11 Feb 2013 18:17:00 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.302</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.302</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.301</title>
					<description>&lt;h4&gt;New&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Additional CLI utility:
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-ssl-ca-certificate&lt;/code&gt; to install custom root CA certificates.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Added ability to authenticate against Management Console API via Basic Auth.&lt;/li&gt;
&lt;li&gt;Added new &lt;code&gt;complete&lt;/code&gt; parameter to the &lt;code&gt;configure&lt;/code&gt; Management Console API call to force a full configuration.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a bug where hitting back while viewing files in the file browser didn&#39;t work.&lt;/li&gt;
&lt;li&gt;Site Admin users will no longer show up as GitHub Staff.&lt;/li&gt;
&lt;li&gt;Enabling and disabling Gravatars will now flush memcached to ensure no cached avatars remain.&lt;/li&gt;
&lt;li&gt;Fixed an &lt;code&gt;ohai&lt;/code&gt; error that showed up when generating a Support Bundle via &lt;code&gt;ghe-support-bundle&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;Fixed a bug where switching Repository Storage from using the root filesystem to a block device failed to migrate repositories that were already on disk.&lt;/li&gt;
&lt;li&gt;Fixed a bug where unrecognized or invalid SSH authorized keys for the admin user could cause the Management Console settings page to throw 500 errors.&lt;/li&gt;
&lt;li&gt;Fixed a bug where uploading new GHL licenses through the web UI wasn&#39;t properly updating the license information on the appliance.&lt;/li&gt;
&lt;li&gt;Fixed a display bug where the tease commit above the repository file tree displayed the author as &amp;quot;Unknown&amp;quot; if the author email wasn&#39;t associated with an existing user.&lt;/li&gt;
&lt;li&gt;Fixed a configuration issue where image assets wouldn&#39;t load properly if the hostname was changed.&lt;/li&gt;
&lt;li&gt;Fixed an LDAP bug where the underlying LDAP library would sometimes emit a packet with a zero-length control sequence, which would result in an LDAP Protocol Error. This only affected some LDAP servers (ActiveDirectory was not affected).&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Thu, 07 Feb 2013 19:41:14 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.301</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.301</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.300</title>
					<description>&lt;h4&gt;New&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1387-viewing-past-contributions&quot;&gt;&lt;strong&gt;Viewing Past Contributions&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1379-zen-writing-mode&quot;&gt;&lt;strong&gt;Zen Writing Mode&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1386-closing-issues-via-commit-messages&quot;&gt;&lt;strong&gt;Closing Issues via Commit Comments&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1381-a-whole-new-code-search&quot;&gt;&lt;strong&gt;Improvements to Code Search&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1378-view-long-running-pull-requests&quot;&gt;&lt;strong&gt;View Long-running Pull Requests&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1375-task-lists-in-gfm-issues-pulls-comments&quot;&gt;&lt;strong&gt;Task Lists&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1377-create-and-delete-branches&quot;&gt;&lt;strong&gt;Create and delete branches&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1369-restore-tidied-pull-requests&quot;&gt;&lt;strong&gt;Restore deleted branches from Pull Requests&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1360-introducing-contributions&quot;&gt;&lt;strong&gt;Contributions&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1365-a-more-transparent-clipboard-button&quot;&gt;&lt;strong&gt;More Transparent Clipboard Buttons&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1357-issue-autocompletion&quot;&gt;&lt;strong&gt;Issue Autocompletion&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1347-issue-attachments&quot;&gt;&lt;strong&gt;Issue Attachments&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1327-creating-files-on-github&quot;&gt;&lt;strong&gt;Create files on GitHub&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1335-tidying-up-after-pull-requests&quot;&gt;&lt;strong&gt;Delete merged branches from Pull Requests&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1323-retiring-impact-graphs&quot;&gt;&lt;strong&gt;Removed Impact Graphs&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1320-command-bar-autocompletes-stars&quot;&gt;&lt;strong&gt;Command bar autocompletes stars&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1392-github-enterprise-11-10-300-release&quot;&gt;&lt;strong&gt;Repository Archives&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1392-github-enterprise-11-10-300-release&quot;&gt;&lt;strong&gt;Improved speed of configuration runs significantly&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.githubsupport.com/entries/23032152-management-console-api&quot;&gt;&lt;strong&gt;Management Console API&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1392-github-enterprise-11-10-300-release&quot;&gt;&lt;strong&gt;Repository restore capability&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1392-github-enterprise-11-10-300-release&quot;&gt;&lt;strong&gt;Support for multiple admin SSH keys&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.githubsupport.com/entries/23050336-search-indexing-api&quot;&gt;&lt;strong&gt;Search Indexing API&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;System preflight checks before upgrades&lt;/strong&gt;&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Additional export/import utilities for a more complete backup&lt;/strong&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Major overhaul of Admin Tools dashboard.&lt;/li&gt;
&lt;li&gt;Dropped support for IE 7/8.&lt;/li&gt;
&lt;li&gt;Fixed longstanding hostname verification bug.&lt;/li&gt;
&lt;li&gt;Fixed many pull request creation timeout issues.&lt;/li&gt;
&lt;li&gt;Improved performance of file listing on repos.&lt;/li&gt;
&lt;li&gt;Updated ghe-export-mysql so it no longer locks tables.&lt;/li&gt;
&lt;li&gt;New CLI Utilies:
&lt;ul&gt;
&lt;li&gt;&lt;code&gt;ghe-es-status&lt;/code&gt; for detecting and fixing common ElasticSearch issues.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-es-reindex&lt;/code&gt; for reindexing all items in ElasticSearch.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;ghe-check-disk-usage&lt;/code&gt; for finding large files consuming space on the root volume.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Added better error checking to &lt;code&gt;ghe-user-{promote,demote}&lt;/code&gt; and &lt;code&gt;ghe-user-{suspend,unsuspend}&lt;/code&gt; utilities.&lt;/li&gt;
&lt;li&gt;Git pull/clone operations will now be logged to the audit.log file.&lt;/li&gt;
&lt;li&gt;Anonymous git pull/clone operations will now log the real ip performing the operation.&lt;/li&gt;
&lt;li&gt;Added a more informative error when the root volume runs out of space while upgrading.&lt;/li&gt;
&lt;li&gt;Renamed the repository admin area to &amp;quot;Settings&amp;quot;.&lt;/li&gt;
&lt;li&gt;Updated the process monitoring configuration to help make it more reliable.&lt;/li&gt;
&lt;li&gt;Fixed a bug where a 405 http status code was received if someone was POSTing while maintenance mode was enabled.&lt;/li&gt;
&lt;li&gt;Fixed a bug where installations could get stuck in a bad state if an upgrade failed partway through.&lt;/li&gt;
&lt;li&gt;Added audit logging for site admin and suspension changes for users.&lt;/li&gt;
&lt;li&gt;Added the ability to delete users who are members of orgs (so long as they aren&#39;t the sole owner).&lt;/li&gt;
&lt;li&gt;Updated to latest linux-generic-pae kernel. [requires VM reboot to take advantage of upgrade]&lt;/li&gt;
&lt;li&gt;Removed &amp;quot;Page build successful!&amp;quot; notifications for Pages.&lt;/li&gt;
&lt;li&gt;Fixed bug where the incorrect hostname was being used in Test Emails.&lt;/li&gt;
&lt;li&gt;Fixed bug where hitting escape in a commit comment would cause anything written to be lost.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Security&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a JSON related vulnerability (&lt;a href=&quot;http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-0333&quot;&gt;CVE-2013-0333&lt;/a&gt;)&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Additional information is available &lt;a href=&quot;https://github.com/blog/1392-github-enterprise-11-10-300-release&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
					<pubDate>Thu, 31 Jan 2013 09:27:47 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.300</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.300</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.293</title>
					<description>&lt;h4&gt;Security&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed an issue where SSL aNULL ciphers were still being allowed in some cases.&lt;/li&gt;
&lt;li&gt;Fixed a potential XSS security vulnerability where search results were being evaluated in-line for repository source code searches.&lt;/li&gt;
&lt;li&gt;Disabled asciidoc rendering due to a potential security vulnerability.&lt;/li&gt;
&lt;li&gt;Disabled XML response parsing to handle a potential Rails YAML unmarshaling exploit.&lt;/li&gt;
&lt;li&gt;Fixed an ActiveRecord dynamic finder vulnerability.&lt;/li&gt;
&lt;li&gt;Hardened sshd_config permissions.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Wed, 09 Jan 2013 17:46:32 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.293</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.293</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.292</title>
					<description>&lt;h4&gt;Security&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Code search previews will no longer be evaluated inline.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Audit log entries will now be made via background job.&lt;/li&gt;
&lt;li&gt;The Email Test will now use the new notification headers.&lt;/li&gt;
&lt;li&gt;Added validation for No-Reply and Support Email addresses.&lt;/li&gt;
&lt;li&gt;Added the ability to specify the broadcast address for static IP configurations to prevent 0.0.0.0 default. (VM restart required)&lt;/li&gt;
&lt;li&gt;The header will no longer be displayed twice when renaming a repository.&lt;/li&gt;
&lt;li&gt;&#39;help&#39; will now work as expected in the command bar.&lt;/li&gt;
&lt;li&gt;Image files will no longer cause a 500 error when checking out via SVN with some clients.&lt;/li&gt;
&lt;li&gt;Fixed a bug where the last digit of some static IP configurations wasn&#39;t being displayed.&lt;/li&gt;
&lt;li&gt;DHCP will no longer override manually assigned DNS nameservers.&lt;/li&gt;
&lt;li&gt;Elastic Search index checks will no longer take 10 minutes to timeout.&lt;/li&gt;
&lt;li&gt;Email Test errors will now be displayed properly.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Wed, 28 Nov 2012 10:11:05 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.292</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.292</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.291</title>
					<description>&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed an issue that prevented some installations from upgrading successfully due to a rsyslog dependency issue.&lt;/li&gt;
&lt;li&gt;Fixed an issue causing some installations to fail while attempting to install the elasticsearch package.&lt;/li&gt;
&lt;li&gt;Fixed some non-critical module load errors that surfaced when rebooting after having upgraded to 11.10.290.&lt;/li&gt;
&lt;li&gt;Fixed an issue where elasticsearch wasn&#39;t binding to all ports as expected under some conditions.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Thu, 01 Nov 2012 16:51:02 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.291</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.291</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.290</title>
					<description>&lt;h4&gt;New&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.githubsupport.com/entries/22286547-maintenance-mode&quot;&gt;&lt;strong&gt;Maintenance Mode&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.githubsupport.com/entries/22260573-audit-logging&quot;&gt;&lt;strong&gt;Audit Logging&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1236-searching-and-filtering-stars&quot;&gt;&lt;strong&gt;Searching &amp;amp; Filtering Stars&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1184-contributing-guidelines&quot;&gt;&lt;strong&gt;Contributing Guidelines&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1264-introducing-the-command-bar&quot;&gt;&lt;strong&gt;Command Bar&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1267-github-launch-page&quot;&gt;&lt;strong&gt;Launch Page&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1256-new-user-profile-pages&quot;&gt;&lt;strong&gt;New User Profile Page&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1270-easier-builds-and-deployments-using-git-over-https-and-oauth&quot;&gt;&lt;strong&gt;OAuth Cloning&lt;/strong&gt;&lt;/a&gt; (built-in authentication only)&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1289-emoji-autocomplete&quot;&gt;&lt;strong&gt;Emoji Autocomplete&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1301-latest-commit-per-directory&quot;&gt;&lt;strong&gt;Last Commit Per Directory&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1306-notifications-api&quot;&gt;&lt;strong&gt;Notifications API&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1307-new-close-and-merge-notifications&quot;&gt;&lt;strong&gt;Close and Merge Notifications&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Improved code, user, and repository search backend.&lt;/li&gt;
&lt;li&gt;Disabling gravatars now properly affects the contributors graph as well.&lt;/li&gt;
&lt;li&gt;The VM hostname will no longer return to the default of &amp;quot;github-enterprise-11-10&amp;quot; after reboots.&lt;/li&gt;
&lt;li&gt;The ghe-cleanup-repos utility will no longer incorrectly identify gists and wikis as deleted repositories.&lt;/li&gt;
&lt;li&gt;Fixed some truncation issues with really long repository names.&lt;/li&gt;
&lt;li&gt;LDAP connection testing is now available in the Management Console.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Additional information is available &lt;a href=&quot;https://github.com/blog/1308-github-enterprise-11-10-290-release&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
					<pubDate>Wed, 31 Oct 2012 11:38:50 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.290</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.290</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.284</title>
					<description>&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Email confirmations are no longer sent when a user deletes their own user account.&lt;/li&gt;
&lt;li&gt;Content Security Violation errors will no longer occur when browsing to the site as an admin user when using Firefox.&lt;/li&gt;
&lt;li&gt;Rsyslog will now reload settings properly when log forwarding options are changed.&lt;/li&gt;
&lt;li&gt;The admin stats API will now report accurate numbers for repo counts.&lt;/li&gt;
&lt;li&gt;Fixed a bug where license expiration warnings were not showing up as expected in all cases.&lt;/li&gt;
&lt;li&gt;Fixed a &lt;a href=&quot;https://github.com/github/github-services/issues/387&quot;&gt;bug in the JIRA service hook&lt;/a&gt; that prevented it from working as intended.&lt;/li&gt;
&lt;li&gt;Fixed a variety of SVN-related errors encountered when using the SVN bridge.&lt;/li&gt;
&lt;li&gt;Fixed a bug where the API would return https URLs regardless of the SSL settings of the installation.&lt;/li&gt;
&lt;li&gt;Fixed a bug in the ghe-cleanup-repos utility that was causing it to identify all gists as bad repositories.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Wed, 17 Oct 2012 15:00:54 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.284</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.284</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.283</title>
					<description>&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a bug that prevented the SVN bridge from starting properly.&lt;/li&gt;
&lt;li&gt;Fixed a long-standing issue that would cause successful configuration runs to incorrectly display as failed under certain conditions.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Wed, 03 Oct 2012 08:55:44 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.283</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.283</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.282</title>
					<description>&lt;h4&gt;New&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;No-reply and support email addresses are now configurable.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Performance improvements
&lt;ul&gt;
&lt;li&gt;Resque worker counts are now scaled based on CPU rather than memory.&lt;/li&gt;
&lt;li&gt;Memcached max cache size is now greatly increased for installations with 12GB or more of memory.&lt;/li&gt;
&lt;li&gt;Future upgrades will now consume much less memory.&lt;/li&gt;
&lt;li&gt;Number of web processes serving the Management Console has been reduced.&lt;/li&gt;
&lt;li&gt;Repository network graphs are no longer built after every git push.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;SVN commits will now work as expected.&lt;/li&gt;
&lt;li&gt;Fixed an issue where GitHub would sometimes become unresponsive after upgrading or saving settings.&lt;/li&gt;
&lt;li&gt;The email notification beacon will now properly mark notifications as read when Private Mode is enabled.&lt;/li&gt;
&lt;li&gt;Atom feed URLs will now work in Private Mode.&lt;/li&gt;
&lt;li&gt;Fixed an issue where failed upgrades would cause the Management Console to redirect to /setup/start.&lt;/li&gt;
&lt;li&gt;Fixed an issue where ghe-reindex was failing to execute properly.&lt;/li&gt;
&lt;li&gt;The Management Console will create a session as expected now (i.e., it won&#39;t require an unlock every time it&#39;s browsed to).&lt;/li&gt;
&lt;li&gt;404s occurring during a fresh installation will now properly show up as a 500 error.&lt;/li&gt;
&lt;li&gt;Requests to api.[hostname] and gist.[hostname] will no longer be automatically redirected to [hostname].&lt;/li&gt;
&lt;li&gt;Fixed a bug where ghe-dbconsole utility wasn&#39;t working as expected.&lt;/li&gt;
&lt;li&gt;/setup/diagnostics and ghe-diagnostics utility will take less time to execute.&lt;/li&gt;
&lt;li&gt;User-to-user repo transfers will happen as expected now.&lt;/li&gt;
&lt;li&gt;Email service hook will now use the appropriate domain name.&lt;/li&gt;
&lt;li&gt;Fixed a bug where organization creation was being prevented when at the license seat limit.&lt;/li&gt;
&lt;li&gt;Fixed a bug where gist comment previews weren&#39;t working properly.&lt;/li&gt;
&lt;li&gt;The default gravatar image used for users who don&#39;t have a gravatar will work as expected now.&lt;/li&gt;
&lt;li&gt;Upgraded git to 1.7.10 (the same version used on GitHub.com).&lt;/li&gt;
&lt;li&gt;Updated the ghe-cleanup-repos script to handle empty repo directories.&lt;/li&gt;
&lt;li&gt;Fixed an upgrade issue that would cause failures while attempting to install the god gem.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Mon, 01 Oct 2012 19:42:21 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.282</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.282</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.281</title>
					<description>&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed an issue that caused some valid GHL licenses to fail to unlock the Management Console for an installation, displaying a &amp;quot;license mismatch&amp;quot; error.&lt;/li&gt;
&lt;li&gt;Fixed a timeout issue while uploading GHPs – after installing this release there should be fewer errors immediately following upload of a new GHP package.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Tue, 11 Sep 2012 17:54:13 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.281</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.281</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.280</title>
					<description>&lt;h4&gt;New&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1178-collaborating-on-github-with-subversion&quot;&gt;&lt;strong&gt;SVN Bridge&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.githubsupport.com/entries/21983828-log-forwarding&quot;&gt;&lt;strong&gt;Log Forwarding&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1204-notifications-stars&quot;&gt;&lt;strong&gt;Notifications &amp;amp; Stars&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1214-notification-email-improvements&quot;&gt;&lt;strong&gt;HTML Notification Emails&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1217-friendlier-edit-and-delete-actions&quot;&gt;&lt;strong&gt;Friendlier Edit &amp;amp; Delete Actions&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1239-github-enterprise-11-10-280-release&quot;&gt;&lt;strong&gt;New Enterprise Header Design&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1239-github-enterprise-11-10-280-release&quot;&gt;&lt;strong&gt;Sticky Protocol Selection&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1239-github-enterprise-11-10-280-release&quot;&gt;&lt;strong&gt;New CLI Utilities&lt;/strong&gt;&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;&lt;em&gt;ghe-vm-reboot&lt;/em&gt; – reboot the appliance from the CLI if you don&#39;t have hypervisor access&lt;/li&gt;
&lt;li&gt;&lt;em&gt;ghe-repos-repair&lt;/em&gt; – find repositories that need permission changes and fix them&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.githubsupport.com/entries/21925333-installing-virtualbox-guest-additions&quot;&gt;&lt;em&gt;ghe-install-virtualbox-tools&lt;/em&gt;&lt;/a&gt; – install VirtualBox Guest Additions&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;All requests to installations that don&#39;t use the hostname specified in the Management Console will automatically get redirected to the configured hostname.&lt;/li&gt;
&lt;li&gt;Fixed a bug where the ghe-export-redis utility was generated corrupt backups.&lt;/li&gt;
&lt;li&gt;Fixed a bug where disk usage for the repositories block device wasn&#39;t being exported by SNMP.&lt;/li&gt;
&lt;li&gt;Fixed problem where search indexing background jobs could pile up causing degraded performance for installations.&lt;/li&gt;
&lt;li&gt;User-to-user repository transfers should now work as expected.&lt;/li&gt;
&lt;li&gt;Fixed a bug where long issue labels were getting truncated prematurely.&lt;/li&gt;
&lt;li&gt;Adjustments were made that should help decrease load when there are large numbers of active SSH connections.&lt;/li&gt;
&lt;li&gt;NTP will no longer hang indefinitely during configuration runs if the NTP servers are unreachable.&lt;/li&gt;
&lt;li&gt;Renaming a repository will now properly rename its associated wiki.&lt;/li&gt;
&lt;li&gt;OpenSearch now references the specified hostname rather than github.com.&lt;/li&gt;
&lt;li&gt;Filenames with multiple periods in their name will no longer cause errors.&lt;/li&gt;
&lt;li&gt;All user agents are now allowed in the robots.txt file.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Additional information is available &lt;a href=&quot;https://github.com/blog/1239-github-enterprise-11-10-280-release&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
					<pubDate>Mon, 10 Sep 2012 09:25:38 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.280</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.280</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.273</title>
					<description>&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed an issue that caused HTTP clones to fail under some conditions.&lt;/li&gt;
&lt;li&gt;Fixed a problem that was causing upgrades from older releases to fail.&lt;/li&gt;
&lt;li&gt;Fixed a bug in the &lt;code&gt;ghe-cleanup-repos&lt;/code&gt; utility where affected repos weren&#39;t being deleted from the database.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Tue, 24 Jul 2012 21:57:14 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.273</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.273</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.272</title>
					<description>&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a bug that caused errors during the upgrade process under some conditions. If you&#39;ve successfully upgraded to 11.10.271 already, then this bug does not affect you.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Thu, 05 Jul 2012 13:07:05 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.272</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.272</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.271</title>
					<description>&lt;h4&gt;New&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Added ghe-time-sync utility to force a one-time large time correction.&lt;/li&gt;
&lt;li&gt;Added ghe-cleanup-repos utility to cleanup failed repo forks, empty wiki repos, and repos that failed to delete for customers affected by the background job bug mentioned below.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a bug that caused background jobs to fail after upgrading under some conditions (introduced in 11.10.270).&lt;/li&gt;
&lt;li&gt;Fixed an issue that caused errors at the end of configuration runs (this did not impact the outcome of the configuration run).&lt;/li&gt;
&lt;li&gt;The &lt;code&gt;ghe-user-csv&lt;/code&gt; utility will now always output all fields. Added repository count, ssh key count, and organization membership count columns. Use &lt;code&gt;-h&lt;/code&gt; flag to view new options.&lt;/li&gt;
&lt;li&gt;Changes to prevent failed configuration runs due to certain processes failing to restart immediately.&lt;/li&gt;
&lt;li&gt;Corrected a number of places where GitHub.com-specific email addresses and URLs were hardcoded.&lt;/li&gt;
&lt;li&gt;Fixed a bug that caused an error when deleting organizations from the Admin Tools dashboard.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Thu, 28 Jun 2012 10:48:34 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.271</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.271</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.270</title>
					<description>&lt;h4&gt;New&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1106-say-hello-to-octicons&quot;&gt;&lt;strong&gt;Octicons&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1121-introducing-team-mentions&quot;&gt;&lt;strong&gt;Team Mentions&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1126-section-links-in-readmes-and-blob-pages&quot;&gt;&lt;strong&gt;README Section Links&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.githubsupport.com/entries/21499701-configuring-time-zone-ntp-settings&quot;&gt;&lt;strong&gt;Configurable Time Zone &amp;amp; NTP Settings&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.githubsupport.com/entries/21514813-enabling-disabling-gravatars&quot;&gt;&lt;strong&gt;Ability to Disable Gravatars&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;http://cl.ly/3H3c45250g0C2v1b3w36/content&quot;&gt;&lt;strong&gt;Improved Configuration Page&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.githubsupport.com/entries/21254402-command-line-utilities&quot;&gt;&lt;strong&gt;Additional CLI Utilities&lt;/strong&gt;&lt;/a&gt;
&lt;ul&gt;
&lt;li&gt;ghe-user-suspend / ghe-user-unsuspend&lt;/li&gt;
&lt;li&gt;ghe-logs-tail&lt;/li&gt;
&lt;li&gt;ghe-diskusage (passes arguments to &lt;code&gt;du&lt;/code&gt; command as root)&lt;/li&gt;
&lt;li&gt;ghe-repo-reindex&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;SSL certificate validation improved.&lt;/li&gt;
&lt;li&gt;User-to-organization conversions now work as expected.&lt;/li&gt;
&lt;li&gt;Improvements to the &lt;code&gt;ghe-user-csv&lt;/code&gt; and &lt;code&gt;ghe-grow-root&lt;/code&gt; utilities.&lt;/li&gt;
&lt;li&gt;Renaming a user will now rename corresponding directories on the filesystem as well.&lt;/li&gt;
&lt;li&gt;Better error messaging in the Management Console.&lt;/li&gt;
&lt;li&gt;Fixed an infinite redirect loop during configuration that would occur under some conditions.&lt;/li&gt;
&lt;li&gt;Long-running network graph generation should no longer block other background jobs.&lt;/li&gt;
&lt;li&gt;Fixed an issue that would cause search indexing to fail when issues contained no body.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Additional information is available &lt;a href=&quot;https://github.com/blog/1144-github-enterprise-11-10-270-release&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;</description>
					<pubDate>Wed, 06 Jun 2012 11:45:42 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.270</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.270</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.262</title>
					<description>&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a bug that caused errors when forking repos or adding collaborators.&lt;/li&gt;
&lt;li&gt;Rally service hook has been added.&lt;/li&gt;
&lt;li&gt;Refinements to the ghe-grow-root script (new syntax -- use -h flag for more info).&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Fri, 11 May 2012 12:16:10 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.262</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.262</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.261</title>
					<description>&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a bug where admin SSH access wasn&#39;t enabling properly under some conditions.&lt;/li&gt;
&lt;li&gt;Fixed a bug with the ghe-user-csv utility that prevented printing only non-admin users.&lt;/li&gt;
&lt;li&gt;Fixed a bug in the ghe-solr-recreate utility that prevented it from reindexing properly.&lt;/li&gt;
&lt;li&gt;Fixed a service hook bug that caused hooks with custom names to break. This fixes the Jenkins service hooks.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Wed, 02 May 2012 15:11:16 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.261</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.261</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.260</title>
					<description>&lt;h4&gt;Security&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;aNULL SSL ciphers are no longer allowed.&lt;/li&gt;
&lt;li&gt;Added CSRF protection to Gists (this will break creating gists by POSTing directly to /gist -- &lt;a href=&quot;http://developer.github.com/v3/gists/&quot;&gt;please use the API&lt;/a&gt;).&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;New&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1081-instantly-beautiful-project-pages&quot;&gt;&lt;strong&gt;Pages 2.0&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1093-introducing-the-new-github-graphs&quot;&gt;&lt;strong&gt;New Graphs&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1105-an-easier-way-to-create-repositories&quot;&gt;&lt;strong&gt;Easier Repo Creation&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.githubsupport.com/entries/21243936-ssh-access&quot;&gt;&lt;strong&gt;SSH Access&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.githubsupport.com/entries/21356241-monitoring-using-snmp&quot;&gt;&lt;strong&gt;SNMP Support&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.githubsupport.com/entries/21383718-suspending-and-unsuspending-users&quot;&gt;&lt;strong&gt;Suspended Users&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.githubsupport.com/entries/21356491-disable-force-pushes&quot;&gt;&lt;strong&gt;Deny Force Pushes&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://enterprise.githubsupport.com/entries/21355851-installing-vmware-tools&quot;&gt;&lt;strong&gt;VMware Tools Installer&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;CAS authentication fixes and enhancements.&lt;/li&gt;
&lt;li&gt;Custom DNS nameservers are now always enabled. This fixes a bug where custom DNS nameservers entered at the console prompt could get disabled unintentionally on first setup. By default, it will try to use Google Public DNS nameservers.&lt;/li&gt;
&lt;li&gt;Fixed an issue that would sometimes cause 404s when uploading new GHPs.&lt;/li&gt;
&lt;li&gt;Fixed a bug that would result in an infinite redirect loop during initial setup under certain conditions.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Tue, 01 May 2012 10:10:03 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.260</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.260</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.259</title>
					<description>&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed an issue where the Orgs tab in the Admin Tools dashboard wasn&#39;t loading properly.&lt;/li&gt;
&lt;li&gt;Fixed a caching issue related to the header buttons and using the Fake Login feature.&lt;/li&gt;
&lt;li&gt;Improvements to help prevent the git-daemon from causing configuration runs to fail in some cases.&lt;/li&gt;
&lt;li&gt;The Fork Queue has been removed (details &lt;a href=&quot;https://github.com/blog/1091-spring-cleaning&quot;&gt;here&lt;/a&gt;).&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Wed, 04 Apr 2012 09:13:35 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.259</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.259</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.257</title>
					<description>&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;SSH key add password confirmation will now also prompt for username when using LDAP authentication.&lt;/li&gt;
&lt;li&gt;Admins who test other accounts using the Fake Login feature can now resume their admin session by logging out.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Fri, 30 Mar 2012 11:33:06 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.257</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.257</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.254</title>
					<description>&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a bug that prevented trial installations from inviting users.&lt;/li&gt;
&lt;li&gt;Fixed a bug that resulted in an &amp;quot;unrecognized command&amp;quot; error when push/pulling (only existed on 11.10.253 release).&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Tue, 20 Mar 2012 16:49:49 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.254</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.254</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.252</title>
					<description>&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a bug where the Invite User form wasn&#39;t working properly for Built-in Authentication.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Sat, 17 Mar 2012 14:37:59 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.252</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.252</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.251</title>
					<description>&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;SSH key password confirmation will now work with LDAP and CAS authentication.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Thu, 15 Mar 2012 23:50:26 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.251</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.251</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.250</title>
					<description>&lt;h4&gt;Security&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Nginx security vulnerability fixed. Details &lt;a href=&quot;http://seclists.org/oss-sec/2012/q1/644&quot;&gt;here&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;SSH Key Audit feature added. Details &lt;a href=&quot;https://gist.github.com/be30e33ea9b5182dac79&quot;&gt;here&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Adding new SSH keys will now prompt for a password and send an email notification.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;New&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1077-oauth-application-enhancements&quot;&gt;&lt;strong&gt;OAuth Application Enhancements&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Organization links in Account Settings now use the correct domain.&lt;/li&gt;
&lt;li&gt;Transferring a repository will no longer cause its wiki to disappear.&lt;/li&gt;
&lt;li&gt;Fixed bug that prevented GitHub:FI migrations from completing under some conditions.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Thu, 15 Mar 2012 13:51:57 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.250</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.250</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.240</title>
					<description>&lt;h4&gt;Security&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Vulnerability in the SSH public key update form fixed. Details &lt;a href=&quot;https://github.com/blog/1068-public-key-security-vulnerability-and-mitigation&quot;&gt;here&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;New&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1035-settings-refresh&quot;&gt;&lt;strong&gt;Settings Refresh&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1037-highlighting-repository-languages&quot;&gt;&lt;strong&gt;Repository Language Highlighting&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1039-easier-pull-request-creation&quot;&gt;&lt;strong&gt;Easier Pull Request Creation&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href=&quot;https://github.com/blog/1056-blob-contributions-box&quot;&gt;&lt;strong&gt;Blob Contributions Box&lt;/strong&gt;&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Logs are now being rotated. Please click &lt;a href=&quot;https://gist.github.com/e39677251050a82ef150&quot;&gt;here&lt;/a&gt; for more details including how to retain all existing logs.&lt;/li&gt;
&lt;li&gt;Significant performance increases for VMs with more than 4GB of memory (NOTE: reboot required to take advantage of this).&lt;/li&gt;
&lt;li&gt;Suggested minimum memory requirements are being increased to 8GB as of this release.&lt;/li&gt;
&lt;li&gt;Email service hook now works with more SMTP server configurations.&lt;/li&gt;
&lt;li&gt;User profiles will now save properly under LDAP and CAS authentication.&lt;/li&gt;
&lt;li&gt;Growing the filesystem of the attached repository storage is now possible. Instructions are available &lt;a href=&quot;https://gist.github.com/8be0899981e4bfe9472b&quot;&gt;here&lt;/a&gt;.&lt;/li&gt;
&lt;li&gt;Admin interface improvements
&lt;ul&gt;
&lt;li&gt;On initial setup the first LDAP or CAS user that logs in will automatically be promoted to Admin status now.&lt;/li&gt;
&lt;li&gt;Admin Tools dashboard now has separate tabs for Users and Organizations.&lt;/li&gt;
&lt;li&gt;Invite User tab now hidden in Admin Tools for LDAP and CAS authentication.&lt;/li&gt;
&lt;li&gt;Admin Tools link now shows up properly for users who are promoted to Admin status.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;li&gt;Reset password and change username options are now hidden under LDAP and CAS authentication.&lt;/li&gt;
&lt;li&gt;SSH connection limit has been increased significantly.&lt;/li&gt;
&lt;li&gt;Configuration runs now give feedback when they fail and link to logs.&lt;/li&gt;
&lt;li&gt;Various UI and performance enhancements.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Wed, 07 Mar 2012 00:45:52 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.240</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.240</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.205</title>
					<description>&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed a bug where some background jobs were not being processed under certain conditions.&lt;/li&gt;
&lt;li&gt;Another fix related to configuration runs without internet access.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Thu, 09 Feb 2012 19:03:45 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.205</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.205</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.195</title>
					<description>&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Fixed an additional bug related to configuration runs without internet access.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Wed, 08 Feb 2012 22:18:26 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.195</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.195</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.179</title>
					<description>&lt;h4&gt;New&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;https://gist.github.com/ada932a9d0fb5c92eeab&quot;&gt;&lt;strong&gt;Admin stats API&lt;/strong&gt;&lt;/a&gt; is now available.&lt;/li&gt;
&lt;li&gt;The root disk for Enterprise installs created with the new OVA will now default to 75GB when using VMware ESXi.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Installations without internet access will now complete the configuration process after Management Console saves.&lt;/li&gt;
&lt;li&gt;Fixed a bug causing the search service (Solr) to crash on new installs.&lt;/li&gt;
&lt;li&gt;Signup link is no longer available in the header when using LDAP authentication.&lt;/li&gt;
&lt;li&gt;Clippy flash widget will no longer burn CPU cycles with many commit pages open.&lt;/li&gt;
&lt;li&gt;Milestones and assignees added to Pull Requests.&lt;/li&gt;
&lt;li&gt;Admin stats bar now displays breakdown of page load time and root disk usage information.&lt;/li&gt;
&lt;li&gt;Various UI and performance enhancements.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Tue, 07 Feb 2012 21:24:28 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.179</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.179</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.143</title>
					<description>&lt;h4&gt;New&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href=&quot;http://pages.github.com&quot;&gt;&lt;strong&gt;GitHub Pages&lt;/strong&gt;&lt;/a&gt; feature now available. CNAME files and user subdomains are not supported.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Bugfixes / Enhancements&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Problem with console prompt and configuration fixed (this is why 11.10.135 was yanked).&lt;/li&gt;
&lt;li&gt;Network graph will now show a much larger range of commits for repos with long histories.&lt;/li&gt;
&lt;li&gt;SSL certificates with passphrases or in unsupported formats will no longer be accepted.&lt;/li&gt;
&lt;li&gt;PivotalTracker service hook now supports on-premise Tracker installs.&lt;/li&gt;
&lt;li&gt;UI enhancements for user dashboard and repository/README views.&lt;/li&gt;
&lt;li&gt;Reparent Admin Tool feature for repositories is now enabled.&lt;/li&gt;
&lt;/ul&gt;
&lt;h4&gt;Security / Maintenance&lt;/h4&gt;
&lt;ul&gt;
&lt;li&gt;Additional log filtering was added.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Tue, 17 Jan 2012 11:44:32 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.143</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.143</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.112</title>
					<description>&lt;ul&gt;
&lt;li&gt;API authentication now works properly under LDAP.&lt;/li&gt;
&lt;li&gt;LDAP connections will no longer stop working after short periods of time.&lt;/li&gt;
&lt;li&gt;Fixed a slow connection problem for SSH git operations caused by a configuration issue.&lt;/li&gt;
&lt;li&gt;Fixed a bug with network graphs that prevented hover information from showing over a commit.&lt;/li&gt;
&lt;li&gt;Fixed an issue with SMTP email tests that kept successful tests from logging debug output.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Wed, 28 Dec 2011 15:35:06 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.112</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.112</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.104</title>
					<description>&lt;ul&gt;
&lt;li&gt;New &lt;a href=&quot;https://github.com/blog/1007-skinny-header&quot;&gt;skinny header&lt;/a&gt; integrated.&lt;/li&gt;
&lt;li&gt;Fixed a bug with moving repositories from users to organizations. If you experienced this issue, &lt;a href=&quot;mailto:enterprise@github.com&quot;&gt;contact support&lt;/a&gt; to find out how to get your repository back in a good state so you can take advantage of this fix.&lt;/li&gt;
&lt;li&gt;Fixed a bug where some pull requests or commit views were generating 500 errors.&lt;/li&gt;
&lt;li&gt;Fixed a code indexing issue with search. Code results should now show up in searches. Keep in mind that code, users, and repos are indexed periodically rather than immediately after they&#39;re created. If it doesn&#39;t show up immediately, wait for 20-30 minutes or so and it should show up.&lt;/li&gt;
&lt;li&gt;A checksum is now performed on GHP files after they&#39;ve been uploaded to the Management Console to detect in-transit corruption.&lt;/li&gt;
&lt;li&gt;Added additional SMTP debug logging when sending test emails in the Management Console. Note that this logging only shows up if the message was not sent successfully.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Wed, 21 Dec 2011 23:36:57 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.104</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.104</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.87</title>
					<description>&lt;ul&gt;
&lt;li&gt;Block storage devices now mount properly after reboot.&lt;/li&gt;
&lt;li&gt;Fixed a bug with switching from Root Filesystem to Block Device storage&lt;br /&gt;
that caused the root filesystem backup to attempt to run on every&lt;br /&gt;
configuration.&lt;/li&gt;
&lt;li&gt;Fixed a variety of SMTP configuration issues.&lt;/li&gt;
&lt;li&gt;Added support for explicitly disabling TLS for SMTP.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Mon, 12 Dec 2011 16:35:04 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.87</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.87</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.75</title>
					<description>&lt;p&gt;There are no release notes for this release.&lt;/p&gt;</description>
					<pubDate>Thu, 08 Dec 2011 11:56:01 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.75</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.75</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.65</title>
					<description>&lt;p&gt;There are no release notes for this release.&lt;/p&gt;</description>
					<pubDate>Mon, 05 Dec 2011 18:38:33 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.65</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.65</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.64</title>
					<description>&lt;p&gt;There are no release notes for this release.&lt;/p&gt;</description>
					<pubDate>Fri, 02 Dec 2011 16:39:02 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.64</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.64</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.60</title>
					<description>&lt;p&gt;There are no release notes for this release.&lt;/p&gt;</description>
					<pubDate>Fri, 02 Dec 2011 00:14:22 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.60</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.60</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.55</title>
					<description>&lt;p&gt;There are no release notes for this release.&lt;/p&gt;</description>
					<pubDate>Wed, 30 Nov 2011 18:58:14 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.55</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.55</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.51</title>
					<description>&lt;p&gt;There are no release notes for this release.&lt;/p&gt;</description>
					<pubDate>Wed, 30 Nov 2011 11:51:11 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.51</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.51</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.38</title>
					<description>&lt;p&gt;There are no release notes for this release.&lt;/p&gt;</description>
					<pubDate>Fri, 18 Nov 2011 19:25:22 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.38</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.38</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.37</title>
					<description>&lt;p&gt;There are no release notes for this release.&lt;/p&gt;</description>
					<pubDate>Wed, 16 Nov 2011 18:05:06 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.37</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.37</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.36</title>
					<description>&lt;p&gt;There are no release notes for this release.&lt;/p&gt;</description>
					<pubDate>Tue, 15 Nov 2011 18:40:27 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.36</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.36</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.32</title>
					<description>&lt;p&gt;There are no release notes for this release.&lt;/p&gt;</description>
					<pubDate>Thu, 10 Nov 2011 15:07:56 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.32</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.32</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.31</title>
					<description>&lt;p&gt;There are no release notes for this release.&lt;/p&gt;</description>
					<pubDate>Tue, 08 Nov 2011 15:25:48 -0800</pubDate>
					<link>https://enterprise.github.com/releases/11.10.31</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.31</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.29</title>
					<description>&lt;p&gt;There are no release notes for this release.&lt;/p&gt;</description>
					<pubDate>Sat, 05 Nov 2011 16:09:23 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.29</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.29</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.27</title>
					<description>&lt;h2&gt;Enterprise Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Bug fixes related to LDAP integration.&lt;/li&gt;
&lt;li&gt;Fix the default .ovf path to be compatible with windows paths.&lt;/li&gt;
&lt;li&gt;Display the default network adapters MAC address on the console welcome screen.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2&gt;GitHub Changes&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Fix the LDAP uid lookup which caused usernames to include DC information.&lt;/li&gt;
&lt;li&gt;Fixed bug in unicorn reloading related to environment variables.&lt;/li&gt;
&lt;/ul&gt;</description>
					<pubDate>Fri, 04 Nov 2011 00:45:26 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.27</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.27</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.22</title>
					<description>&lt;p&gt;There are no release notes for this release.&lt;/p&gt;</description>
					<pubDate>Tue, 01 Nov 2011 00:56:44 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.22</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.22</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.20</title>
					<description>&lt;p&gt;There are no release notes for this release.&lt;/p&gt;</description>
					<pubDate>Mon, 31 Oct 2011 18:54:41 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.20</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.20</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.11.18</title>
					<description>&lt;p&gt;There are no release notes for this release.&lt;/p&gt;</description>
					<pubDate>Sun, 30 Oct 2011 08:56:50 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.11.18</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.11.18</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.16</title>
					<description>&lt;p&gt;There are no release notes for this release.&lt;/p&gt;</description>
					<pubDate>Sat, 29 Oct 2011 04:33:06 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.16</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.16</guid>
				</item>
			
		
			
		  
				<item>
					<title>11.10.12</title>
					<description>&lt;p&gt;Initial release.&lt;/p&gt;</description>
					<pubDate>Sat, 15 Oct 2011 00:24:54 -0700</pubDate>
					<link>https://enterprise.github.com/releases/11.10.12</link>
					<guid isPermaLink="true">https://enterprise.github.com/releases/11.10.12</guid>
				</item>
			
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
			
		  
		
	</channel>
</rss>
