Skip to content
This repository was archived by the owner on Oct 6, 2021. It is now read-only.

Version 1.1.3 - Fixes the Auto-Updater

Choose a tag to compare

@paragonie-scott paragonie-scott released this 01 Jul 22:19
· 534 commits to master since this release
v1.1.3
  • Fixed E_NOTICEs with the auto-updater.
  • Identified a bug in the backend server that wasn't publishing commit hashes
    in CMS Airship core updates. Going forward, the commit hash should be
    included in each release.
  • Only allow HTTP and HTTPS URLs in blog comments, in case someone provides
    a JavaScript URI and someone else is careless enough to click it. HackerOne report.
  • Proactively mitigate stored XSS in other invocations of __().