mercurial was updated to fix a potential command injection via sshpeer._validaterepo() (CVE-2014-9462)
Security Issues:
* CVE-2014-9462 <http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9462>