summaryrefslogtreecommitdiff
AgeCommit message (Expand)Author
2023-09-04docs: clang is also supporteddocs/max-elixir-erlangHaelwenn (lanodan) Monnier
2023-09-04docs: Put a max version on erlang and elixirHaelwenn (lanodan) Monnier
2023-09-03Merge branch 'check-attachment-attribution' into 'develop'Haelwenn
2023-09-03CommonAPI: Prevent users from accessing media of other usersMint
2023-08-31Merge branch 'tusooa/lint' into 'develop'Haelwenn
2023-08-30Skip changelogtusooa
2023-08-30Make lint happytusooa
2023-08-16Merge branch 'csp-flash' into 'develop'Haelwenn
2023-08-16Apply lanodan's suggestion(s) to 1 file(s)Haelwenn
2023-08-10Merge branch 'fix-dockerfile-perms' into 'develop'tusooa
2023-08-08Fix config ownership in dockerfile to pass restriction testCat pony Black
2023-08-06Merge branch 'disable-xml-entities-completely' into 'develop'Haelwenn
2023-08-05Completely disable xml entity resolutionmae
2023-08-05Merge branch 'docs/gentoo-otp-intro' into 'develop'Haelwenn
2023-08-05Merge branch 'mergeback/2.5.4' into 'develop'Haelwenn
2023-08-05Mergeback release 2.5.4Haelwenn (lanodan) Monnier
2023-08-05Document and test that XXE processing is disabledMark Felder
2023-08-05Add unit test for external entity loadingFloatingGhost
2023-08-04Prevent XML parser from loading external entitiesMae
2023-08-04gentoo_otp_en.md: Indicate which install method it coversHaelwenn (lanodan) Monnier
2023-08-04Merge branch 'mergeback/2.5.3' into 'develop'Haelwenn
2023-08-04Release 2.5.53Haelwenn (lanodan) Monnier
2023-08-04release_runtime_provider_test: chmod config for hardened permissionsHaelwenn (lanodan) Monnier
2023-08-04changelog: Entry for config permissions restrictionsHaelwenn (lanodan) Monnier
2023-08-04instance gen: Reduce permissions of pleroma directories and config filesHaelwenn (lanodan) Monnier
2023-08-04Config: Restrict permissions of OTP config fileHaelwenn (lanodan) Monnier
2023-08-04Resolve information disclosure vulnerability through emoji pack archive downl...Mark Felder
2023-08-03Merge branch 'tusooa/3154-attachment-type-check' into 'develop'Haelwenn
2023-07-28Merge branch 'fix/2927-disallow-unauthenticated-access' into 'develop'tusooa
2023-07-28add changelog entryfaried nawaz
2023-07-28cleaner ecto query to handle restrict_unauthenticated for activitiesFaried Nawaz
2023-07-28status context: perform visibility check on activities around a statusfaried nawaz
2023-07-18Restrict attachments to only uploaded files onlytusooa/3154-attachment-type-checktusooa
2023-07-17Merge branch '2023-06-deps-update' into 'develop'release/2.6.0Haelwenn
2023-07-07Merge branch 'tusooa/2775-emoji-policy' into 'develop'Haelwenn
2023-07-07Make regex-to-string descriptor reusabletusooa
2023-07-07Fix edge casestusooa
2023-07-07Add changelogtusooa
2023-07-07Test that unicode emoji reactions are not affectedtusooa
2023-07-07Make EmojiPolicy aware of custom emoji reactionstusooa
2023-07-07Improve config examples for EmojiPolicytusooa
2023-07-07Update config cheatsheettusooa
2023-07-07Move emoji_policy.ex to the right placetusooa
2023-07-07EmojiPolicy: Implement delisttusooa
2023-07-07EmojiPolicy: implement remove by shortcodetusooa
2023-07-07Add emoji policy to remove emojis matching certain urlstusooa
2023-07-04Merge branch 'deprecate-scrobbles' into 'develop'tusooa
2023-07-04Merge branch 'hotfix/docs-broken-links' into 'develop'Haelwenn
2023-07-04docs: Fix broken linksHaelwenn (lanodan) Monnier
2023-07-04Merge branch 'fix/pipeline-triggers' into 'develop'Haelwenn