Hi all,

On Thursday we will be issuing a security and maintenance release to all supported branches of MediaWiki.

The new releases will be:

- 1.35.6
- 1.36.4
- 1.37.2

This will resolve four issues in MediaWiki core and also includes some fixes previously committed to git, including minor security and hardening patches along with bug fixes included for maintenance reasons. One issue does not affect MediaWiki 1.35 and 1.36.

In addition to those, these releases will resolve other issues in MediaWiki core and also include some fixes previously committed to git, including minor security and hardening patches along with bug fixes included for maintenance reasons.

We will make the fixes available in the respective release branches and master in git. Tarballs will be available for the above mentioned point releases as well.

A summary of some of the security fixes that have gone into non-bundled MediaWiki extensions will also follow later.

As a reminder, 1.36 is due to become end of life (EOL) in May 2022. 1.36.4 is expected to be the last release for this branch. It is recommended to upgrade to 1.37, or to 1.38 due to be released in May 2022.

[1] https://www.mediawiki.org/wiki/Version_lifecycle