about summary refs log tree commit diff
Commit message (Expand)AuthorAge
* md2html: Do syntax highlighting tooJason A. Donenfeld2016-02-23
* git: update to v2.7.2Christian Hesse2016-02-23
* ui-plain: fix to show a repo's root directory listing in plain viewJoe Anakata2016-02-22
* cmd: redirect empty about/ to homepage or summaryJason A. Donenfeld2016-02-22
* ui-shared: add homepage to tabsJason A. Donenfeld2016-02-22
* ui-atom: avoid DATE_STRFTIMEJohn Keeping2016-02-08
* Avoid DATE_STRFTIME for long/short datesJohn Keeping2016-02-08
* ui-stats: cast pointer before checking for zeroJohn Keeping2016-02-08
* ui-stats: if we're going to abuse void*, do it safelyJason A. Donenfeld2016-02-08
* git: update to v2.7.1Christian Hesse2016-02-08
* ui-shared: remove cgit_print_date()John Keeping2016-02-08
* ui-atom: use show_date directly for atom datesJohn Keeping2016-02-08
* ui-shared: use show_date for footer timestampJohn Keeping2016-02-08
* ui: show ages in the originator's timezoneJohn Keeping2016-02-08
* ui-{commit,tag}: show dates in originator's timezoneJohn Keeping2016-02-08
* ui-shared: add cgit_date_mode()John Keeping2016-02-08
* parsing: add timezone to ident structuresJohn Keeping2016-02-08
* ui-shared: remove "format" from cgit_print_age()John Keeping2016-02-08
* ui-tree: put reverse path in titleJason A. Donenfeld2016-01-18
* syntax-highlighting: always use utf-8 to avoid ascii codec issuesJason A. Donenfeld2016-01-18
* cache: don't check for match with no keyJohn Keeping2016-01-17
* cache: use size_t for string lengthsJohn Keeping2016-01-17
* ui-log: handle parse_commit() errorsJohn Keeping2016-01-17
* Bump versionJason A. Donenfeld2016-01-14
* ui-plain: add enable-html-serving flagJason A. Donenfeld2016-01-14
* ui-blob: set CSP just in caseJason A. Donenfeld2016-01-14
* ui-blob: always use generic mimetypesJason A. Donenfeld2016-01-14
* ui-blob: Do not accept mimetype from userJason A. Donenfeld2016-01-14
* ui-shared: prevent malicious filename from injecting headersJason A. Donenfeld2016-01-14
* ui-shared: Avoid new line injection into redirect headerJason A. Donenfeld2016-01-14
* Fix missing prototype declarationsPeter Colberg2016-01-14
* ui-repolist: return HTTP 404 if no repositories foundPeter Colberg2016-01-13
* ui-repolist: extract repo visibility criteria to separate functionPeter Colberg2016-01-13
* Fix segmentation fault in hc()Lukas Fleischer2016-01-13
* git: update to v2.7.0Christian Hesse2016-01-13
* ui-repolist: initialize char *buf to NULLChristian Hesse2016-01-13
* filter: avoid integer overflow in authenticate_postJason A. Donenfeld2015-11-24
* about-formatting.sh: comment text out of dateJason A. Donenfeld2015-11-12
* filters: port syntax-highlighting.py to python 3.xChristian Hesse2015-10-12
* md2html: the default of stdin works fineJason A. Donenfeld2015-10-12
* filters: misc cleanupsJason A. Donenfeld2015-10-12
* md2html: use pure pythonJason A. Donenfeld2015-10-12
* cache: fix resource leak: close file handle before returnChristian Hesse2015-10-10
* ui-atom: fix resource leak: free allocation from cgit_pageurlChristian Hesse2015-10-10
* ui-atom: fix resource leak: free before returnChristian Hesse2015-10-10
* ui-atom: fix resource leak: free allocation from cgit_repourlChristian Hesse2015-10-10
* ui-blob: fix resource leak: free before returnChristian Hesse2015-10-10
* ui-blob: fix resource leak: free before returnChristian Hesse2015-10-10
* ui-plain: fix resource leak: free before assigning NULLChristian Hesse2015-10-09
* ui-plain: fix resource leak: free before returnChristian Hesse2015-10-09
low=1'>git: update to v2.19.1Christian Hesse Update to git version v2.19.1. Required changes follow upstream commits: * commit: add repository argument to get_cached_commit_buffer (3ce85f7e5a41116145179f0fae2ce6d86558d099) * commit: add repository argument to lookup_commit_reference (2122f6754c93be8f02bfb5704ed96c88fc9837a8) * object: add repository argument to parse_object (109cd76dd3467bd05f8d2145b857006649741d5c) * tag: add repository argument to deref_tag (a74093da5ed601a09fa158e5ba6f6f14c1142a3e) * tag: add repository argument to lookup_tag (ce71efb713f97f476a2d2ab541a0c73f684a5db3) * tree: add repository argument to lookup_tree (f86bcc7b2ce6cad68ba1a48a528e380c6126705e) * archive.c: avoid access to the_index (b612ee202a48f129f81f8f6a5af6cf71d1a9caef) * for_each_*_object: move declarations to object-store.h (0889aae1cd18c1804ba01c1a4229e516dfb9fe9b) Signed-off-by: Christian Hesse <mail@eworm.de> 2018-09-11ui-ssdiff: ban strcat()Christian Hesse Git upstream bans strcat() with commit: banned.h: mark strcat() as banned 1b11b64b815db62f93a04242e4aed5687a448748 Signed-off-by: Christian Hesse <mail@eworm.de> 2018-09-11ui-ssdiff: ban strncpy()Christian Hesse Git upstream bans strncpy() with commit: banned.h: mark strncpy() as banned e488b7aba743d23b830d239dcc33d9ca0745a9ad Signed-off-by: Christian Hesse <mail@eworm.de> 2018-09-11ui-shared: ban strcat()Christian Hesse Git upstream bans strcat() with commit: banned.h: mark strcat() as banned 1b11b64b815db62f93a04242e4aed5687a448748 To avoid compiler warnings from gcc 8.1.x we get the hard way. Signed-off-by: Christian Hesse <mail@eworm.de> 2018-09-11ui-patch: ban sprintf()Christian Hesse Git upstream bans sprintf() with commit: banned.h: mark sprintf() as banned cc8fdaee1eeaf05d8dd55ff11f111b815f673c58 Signed-off-by: Christian Hesse <mail@eworm.de> 2018-09-11ui-log: ban strncpy()Christian Hesse Git upstream bans strncpy() with commit: banned.h: mark strncpy() as banned e488b7aba743d23b830d239dcc33d9ca0745a9ad Signed-off-by: Christian Hesse <mail@eworm.de> 2018-09-11ui-log: ban strcpy()Christian Hesse Git upstream bans strcpy() with commit: automatically ban strcpy() c8af66ab8ad7cd78557f0f9f5ef6a52fd46ee6dd Signed-off-by: Christian Hesse <mail@eworm.de> 2018-09-11parsing: ban sprintf()Christian Hesse Git upstream bans sprintf() with commit: banned.h: mark sprintf() as banned cc8fdaee1eeaf05d8dd55ff11f111b815f673c58 Signed-off-by: Christian Hesse <mail@eworm.de> 2018-09-11parsing: ban strncpy()Christian Hesse Git upstream bans strncpy() with commit: banned.h: mark strncpy() as banned e488b7aba743d23b830d239dcc33d9ca0745a9ad Signed-off-by: Christian Hesse <mail@eworm.de> 2018-08-28filters: generate anchor links from markdownChristian Hesse This makes the markdown filter generate anchor links for headings. Signed-off-by: Christian Hesse <mail@eworm.de> Tested-by: jean-christophe manciot <actionmystique@gmail.com> 2018-08-03Bump version.Jason A. Donenfeld Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com> 2018-08-03clone: fix directory traversalJason A. Donenfeld This was introduced in the initial version of this code, way back when in 2008. $ curl http://127.0.0.1/cgit/repo/objects/?path=../../../../../../../../../etc/passwd root:x:0:0:root:/root:/bin/sh ... Signed-off-by: Jason A. Donenfeld <Jason@zx2c4.com> Reported-by: Jann Horn <jannh@google.com> 2018-08-03config: record repo.snapshot-prefix in the per-repo configKonstantin Ryabitsev