Permalink
Commits on Feb 11, 2012
  1. Sprockets 2.3.1

    josh committed Feb 11, 2012
  2. rbx 2 isn't on travis anymore

    josh committed Feb 11, 2012
  3. Changelog for 2.3.1

    josh committed Feb 11, 2012
  4. Add bytesize to manifest

    josh committed Feb 11, 2012
  5. Merge pull request #292 from jfirebaugh/traversal

    josh committed Feb 11, 2012
    Check for directory traversal after unescaping
  6. Merge pull request #288 from kevmoo/patch-1

    josh committed Feb 11, 2012
    2.3 is released
Commits on Feb 9, 2012
  1. Check for directory traversal after unescaping

    jfirebaugh committed Feb 9, 2012
    The `forbidden_request?` check could be trivially bypassed
    by percent encoding .. as %2e%2e.
    
    After auditing Sprockets and Hike and fuzzing a simple
    server, I don't believe this is exploitable. However,
    better safe than sorry/defense in depth/etc.
Commits on Jan 31, 2012
  1. 2.3 is released

    kevmoo committed Jan 31, 2012
Commits on Jan 16, 2012
  1. Sprockets 2.3.0

    josh committed Jan 16, 2012
Commits on Jan 13, 2012
  1. Sprockets 2.3.0.beta

    josh committed Jan 13, 2012
Commits on Jan 10, 2012
  1. Add sass note to changelog

    josh committed Jan 10, 2012
  2. Merge pull request #268 from sstephenson/sass

    josh committed Jan 10, 2012
    Sass
  3. Update 2.2 changelog

    josh committed Jan 10, 2012
  4. Lazy require importer

    josh committed Jan 10, 2012
  5. Merge branch 'master' into sass

    josh committed Jan 10, 2012
  6. Sprockets 2.2.0

    josh committed Jan 10, 2012
  7. Disable test for CI

    josh committed Jan 10, 2012
  8. Fix unused data var warning

    josh committed Jan 10, 2012
  9. Merge pull request #273 from botandrose/automatic_binary_encoding

    josh committed Jan 10, 2012
    force binary encoding for assets with mime types that begin with "image/", "audio/", or "video/".
  10. Merge pull request #271 from KODerFunk/patch-1

    josh committed Jan 10, 2012
    Fix raise text in lib/sprockets/directive_processor.rb
  11. Add option for number of assets to keep

    josh committed Jan 10, 2012
    Fixes #276
Commits on Dec 29, 2011
  1. force binary encoding for assets with mime types that begin with "ima…

    botandrose committed Dec 28, 2011
    …ge/", "audio/", or "video/".
Commits on Dec 28, 2011
Commits on Dec 21, 2011
  1. Prepend sass/ to key

    josh committed Dec 21, 2011
  2. Add cache store

    josh committed Dec 21, 2011
  3. Merge branch 'master' into sass

    josh committed Dec 21, 2011
  4. Some docs

    josh committed Dec 21, 2011
Commits on Dec 20, 2011
Commits on Dec 19, 2011
  1. Revert version change

    josh committed Dec 19, 2011
  2. Fix relative nested imports

    josh committed Dec 19, 2011
  3. Merge branch 'master' into sass

    josh committed Dec 19, 2011
  4. Fix unused var warning

    josh committed Dec 19, 2011