Hi all,

Tomorrow we will be issuing a security and maintenance release to all supported branches of MediaWiki.

The new releases will be:

- 1.31.16
- 1.35.4
- 1.36.2

This will resolve 3 issues in MediaWiki core and also includes some fixes previously committed to git, including minor security and hardening patches along with bug fixes included for maintenance reasons.

It also fixes 1 issue in a MediaWiki tarball bundled extension.

We will make the fixes available in these respective release branches, master and the currently unreleased 1.37 branch. Tarballs will be available for the above mentioned point releases as well.

A summary of some of the security fixes that have gone into non-bundled MediaWiki extensions will also follow.

As a reminder, 1.31 (the old LTS) was due to become end of life (EOL) in June 2021. 1.35 (the new LTS) is supported until September 2023. However, to try and meet our LTS-LTS overlap commitments (1.35 was late due to COVID), 1.31 got best-efforts extra support until the end of September 2021.

As the end of September 2021 is now upon us, this means 1.31.16 will be the final security (and maintenance) release, and therefore it is considered EOL as of tomorrow, September 30, 2021.

[1] https://www.mediawiki.org/wiki/Version_lifecycle