Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Pi-hole web v5.2.2 #1666

Merged
merged 32 commits into from
Dec 24, 2020
Merged

Pi-hole web v5.2.2 #1666

merged 32 commits into from
Dec 24, 2020

Conversation

PromoFaux
Copy link
Member

We may want to get @yubiuser's changeset in from #1663, too?

yubiuser and others added 28 commits September 30, 2020 20:19
…tions to red

Signed-off-by: yubiuser <ckoenig@posteo.de>
* autoprefixer  ^9.8.6  →  ^10.0.4
* postcss-cli   ^7.1.2  →   ^8.3.0

Also, cleanup our browserslist config.

Signed-off-by: XhmikosR <xhmikosr@gmail.com>
Signed-off-by: dnhp <34394848+dnhp@users.noreply.github.com>
Update development from Web v5.2.1 release
Signed-off-by: Aidan Woods <aidantwoods@gmail.com>
This should prevent a timing attack against this parameter to
disclose the stored passsword hash.

Signed-off-by: Aidan Woods <aidantwoods@gmail.com>
Use hash_equals when comparing to pwhash from cookie
Bumps [ini](https://github.com/isaacs/ini) from 1.3.5 to 1.3.7. **This update includes a security fix.**
- [Release notes](https://github.com/isaacs/ini/releases)
- [Commits](npm/ini@v1.3.5...v1.3.7)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Fix issue 1643 - Show status of retried DNS queries in query log correctly
Change color of blocked queries in dashboard piechart forward destination to red
Switch from fontawesome webfonts to SVG + JS
Bumps [autoprefixer](https://github.com/postcss/autoprefixer) from 10.0.4 to 10.1.0.
- [Release notes](https://github.com/postcss/autoprefixer/releases)
- [Changelog](https://github.com/postcss/autoprefixer/blob/main/CHANGELOG.md)
- [Commits](postcss/autoprefixer@10.0.4...10.1.0)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Bumps [xo](https://github.com/xojs/xo) from 0.35.0 to 0.36.1.
- [Release notes](https://github.com/xojs/xo/releases)
- [Commits](xojs/xo@v0.35.0...v0.36.1)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Bumps [postcss](https://github.com/postcss/postcss) from 8.1.10 to 8.2.1.
- [Release notes](https://github.com/postcss/postcss/releases)
- [Changelog](https://github.com/postcss/postcss/blob/main/CHANGELOG.md)
- [Commits](postcss/postcss@8.1.10...8.2.1)

Signed-off-by: dependabot-preview[bot] <support@dependabot.com>
Signed-off-by: yubiuser <ckoenig@posteo.de>
Signed-off-by: yubiuser <ckoenig@posteo.de>
Signed-off-by: yubiuser <ckoenig@posteo.de>
Signed-off-by: yubiuser <ckoenig@posteo.de>
Signed-off-by: yubiuser <ckoenig@posteo.de>
Validate target domain for CNAME records
Signed-off-by: DL6ER <dl6er@dl6er.de>
…y log

Signed-off-by: Adam Warner <me@adamwarner.co.uk>
Signed-off-by: Adam Warner <me@adamwarner.co.uk>
Prevent malformed DNS queries executing JS on querylog/long term query pages
@DL6ER
Copy link
Member

DL6ER commented Dec 24, 2020

#1663 needs a bit more work, I've just seen that I've made review comments but forgot to actually hit the "store my review" button.

@DL6ER DL6ER changed the title Release/v5.2.2 Pi-hole web v5.2.2 Dec 24, 2020
Signed-off-by: yubiuser <ckoenig@posteo.de>
Signed-off-by: yubiuser <ckoenig@posteo.de>
@yubiuser
Copy link
Member

Updated the PR if you still want to include it.

@DL6ER
Copy link
Member

DL6ER commented Dec 24, 2020

@yubiuser I just submitted an additional review suggestion to #1663. If we can get this resolved, we'll still merge it.

yubiuser and others added 2 commits December 24, 2020 10:23
Signed-off-by: yubiuser <ckoenig@posteo.de>
Add hint to the web interface about the limits of CNAME records
@PromoFaux PromoFaux merged commit 780dff0 into master Dec 24, 2020
@DL6ER DL6ER deleted the release/v5.2.2 branch September 10, 2021 06:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

8 participants