- Nov 05, 2014
-
-
cratz authored
Update sprockets version to address CVE-2014-7819
- Nov 04, 2014
- Oct 31, 2014
-
-
Philipp Tessenow authored
Update ruby version to current stable 2.1.4
-
kgalli authored
This release includes security fixes for the following vulnerabilities: * CVE-2014-8080: Denial of Service XML Expansion * Changed default settings of ext/openssl related to CVE-2014-3566 And there are some bug-fixes.
-
- Oct 30, 2014
-
-
Philipp Tessenow authored
There is an information leak vulnerability in Sprockets. This vulnerability has been assigned the CVE identifier CVE-2014-7819. see: https://groups.google.com/forum/#!topic/rubyonrails-security/wQBeGXqGs3E The patch given in https://15028051456732132684.googlegroups.com/attach/7887e1a7070ca526/2-12-sec-static-files.patch?part=0.0.1&view=1&vt=ANaJVrGrEs8fNpWjOUFuf3p1rWA83Dw-kPMJ8qeYExCi_n6nnuHcw53a2rWDfBwsfeA06s9Okm3LkpBK1W_b0vsqlsNAHGW1g0Z0T8WcmWxvqJCshdVpLts Was manually applied to the backport branch. This commit can be reverted as soon as sprockets 2.12.X is used.
-
Philipp Tessenow authored
This is a security fix against a file existence exposure CVE-2014-7819 see: http://weblog.rubyonrails.org/2014/10/30/Rails_3_2_20_4_0_11_4_1_7_and_4_2_0_beta3_have_been_released/ Conflicts: Gemfile.lock
-
kgalli authored
dead code removal
-
Christian Ratz authored
-
Philipp Tessenow authored
Use new packager installer
-
- Oct 28, 2014
-
-
Philipp Tessenow authored
rake task to backup and restore the database
-
- Oct 24, 2014
-
-
Hagen Schink authored
-
Jens Ulferts authored
When we clear both, the float of the project menu is also factored in.
-
- Oct 23, 2014
-
-
Alex Coles authored
hound config that matches `dev`
-
- Oct 22, 2014
-
-
Martin Linkhorst authored
-
kgalli authored
-
Philipp Tessenow authored
-
Philipp Tessenow authored
-
Philipp Tessenow authored
-
Philipp Tessenow authored
-
Philipp Tessenow authored
-
Philipp Tessenow authored
-
Philipp Tessenow authored
-
Philipp Tessenow authored
-
- Oct 20, 2014
-
-
kgalli authored
-
- Oct 16, 2014
-
-
kgalli authored
-
Cyril Rohr authored
-
Cyril Rohr authored
Postinstall for openproject is now in its own addon at https://github.com/pkgr/addon-openproject. Conflicts: .pkgr.yml
-
- Oct 07, 2014
-
- Sep 23, 2014
-
-
ulferts authored
Fixed double rendering of attachments and repository annotates
-
Björn Blissing authored
-
- Sep 17, 2014
- Sep 12, 2014
-
-
ulferts authored
API v2: Use true/false as rewire parents value
-
Michael Frister authored
-