Create
cancel
Showing results for 
Search instead for 
Did you mean: 
Sign up Log in

It's not the same without you

Join the community to find out what other Atlassian users are discussing, debating and creating.

Atlassian Community Hero Image Collage

Sourcetree Security Update - Yosemite?

Is there a roadmap for when the SourceTree security update will be available for MacOSX Yosemite?

Also, is there some guidance as to mitigating the chance of the sourcetree:// injection attack in the interim? I'd like to continue using SourceTree until you get it updated for Yosemite, but I'm not keen on having my system pwned.

1 answer

0 votes
Ana Retamal Atlassian Team May 15, 2017

Hi Kurt, the new version of SourceTree requires that you're on OSX 10.11 or later. We support two versions of MacOS and don't support older versions of SourceTree. For more information you can see the response from Rahul at SRCTREE-4738.

In response to your second question, we don't have any official workaround. One of our users provided one (in the previous link too) but it comprises app security signature in exchange, which is just trading one risk for another.

Regards,

Ana

As many people have pointed out in the other threads (with no response from Atlassian), asking people to upgrade their OS is not a reasonable response to a critical security flaw in your product. It's a major undertaking in time and effort, it has the potential to break other products that are being used, and may not even be possible based on hardware or corporate policy.

Yosemite (OSX 10.10) is not end of life, and Apple is still releasing security updates for it. It's less than 3 years old. It's really just feels like Atlassian does not give a sh*t about security.

Jumping on this in 2019... Guys just update your OS.. ive been using Mojave for nearly a year now..

 

Its a good idea to refresh your workspace once in a while (at least once a year).. that way the 2500 you dropped on your fancy macbook will be worthwhile...


Healthy body healthy mind guys.. 

Suggest an answer

Log in or Sign up to answer
TAGS
Community showcase
Published in Sourcetree

Sourcetree for Windows - CVE-2019-11582 - Remote Code Execution vulnerability

A vulnerability has been published today in regards to Sourcetree for Windows.  The goal of this article is to give you a summary of information we have gathered from Atlassian Community as a st...

5,011 views 0 12
Read article

Community Events

Connect with like-minded Atlassian users at free events near you!

Find an event

Connect with like-minded Atlassian users at free events near you!

Unfortunately there are no Community Events near you at the moment.

Host an event

You're one step closer to meeting fellow Atlassian users at your local event. Learn more about Community Events

Events near you