)]}'
{
  "commit": "ac00f76711959bf56794d7b4bcedee85b2ef8039",
  "tree": "f6dd869bcbbc73bdf300901ccd8c8362e9b494e5",
  "parents": [
    "b8acc9eef933e08041aca8cd2495420a742c4c5b"
  ],
  "author": {
    "name": "Edwin Kempin",
    "email": "ekempin@google.com",
    "time": "Thu Sep 06 08:56:27 2018 +0000"
  },
  "committer": {
    "name": "Edwin Kempin",
    "email": "ekempin@google.com",
    "time": "Fri Sep 07 06:53:55 2018 +0000"
  },
  "message": "Restrict permission to upload patch sets to other users\u0027 changes\n\nThere are some spammers that upload new patch sets to changes that\nbelong to other users (e.g. [1]). To prevent that this happens again\nwe grant the \u0027Add Patch Set\u0027 permission [2] only to the Gerrit\nmaintainers and the gerrit-verifiers group which contains all trusted\nGerrit contributors. Block the \u0027Add Patch Set\u0027 permission for\nAnonymous-Users since on the All-Projects project this permission is\ngranted for Registered-Users).\n\nThis means only Gerrit maintainers and users of the gerrit-verifiers\ngroup can now upload new patch sets to changes that they do not own.\nEveryone is still allowed to upload patch sets to own changes since\nthis is always allowed regardless of the \u0027Add Patch Set\u0027 permission.\n\n[1] https://gerrit-review.googlesource.com/c/plugins/javamelody/+/192431/10..11//COMMIT_MSG\n[2] https://gerrit-review.googlesource.com/Documentation/access-control.html#category_add_patch_set\n\nChange-Id: I99263899fa3a82cbefbc20550b2e07dfd9414184\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "b8fe757fc826c388127ed291df8ed9a1b30006ad",
      "old_mode": 33188,
      "old_path": "project.config",
      "new_id": "89f94c4a4c7c8c8b5f4a6d850b5fb7ecf78b94f5",
      "new_mode": 33188,
      "new_path": "project.config"
    }
  ]
}
