From 592c13cc6169554b075406dae9ca90cdba183fbd Mon Sep 17 00:00:00 2001 From: Simon McVittie Date: Mon, 19 Dec 2016 17:25:35 +0000 Subject: [PATCH 1/1] Update changelog --- debian/changelog | 10 ++++++++++ 1 file changed, 10 insertions(+) diff --git a/debian/changelog b/debian/changelog index ec15142b4..a10770548 100644 --- a/debian/changelog +++ b/debian/changelog @@ -1,8 +1,18 @@ ikiwiki (3.20160906) UNRELEASED; urgency=medium + [ Joey Hess ] * inline: Prevent creating a file named ".mdwn" when the postform is submitted with an empty title. + [ Simon McVittie ] + * Security: tell `git revert` not to follow renames. If it does, then + renaming a file can result in a revert writing outside the wiki srcdir + or altering a file that the reverting user should not be able to alter, + an authorization bypass. Thanks, intrigeri + * cgitemplate: remove some dead code. Thanks, blipvert + * Restrict CSS matches against header class to not break + Pandoc tables with header rows. Thanks, karsk + -- Joey Hess Wed, 21 Sep 2016 13:48:32 -0400 ikiwiki (3.20160905) unstable; urgency=medium -- 2.39.2