summaryrefslogtreecommitdiff
AgeCommit message (Expand)Author
2023-08-05Rename test file so it is run with the test suitetest_cleanupMark Felder
2023-08-05Remove test leftover from experimentation on the XXE vulnerabilityMark Felder
2023-08-05Merge branch 'docs/gentoo-otp-intro' into 'develop'Haelwenn
2023-08-05Merge branch 'mergeback/2.5.4' into 'develop'Haelwenn
2023-08-05Mergeback release 2.5.4Haelwenn (lanodan) Monnier
2023-08-05Document and test that XXE processing is disabledMark Felder
2023-08-05Add unit test for external entity loadingFloatingGhost
2023-08-04Prevent XML parser from loading external entitiesMae
2023-08-04gentoo_otp_en.md: Indicate which install method it coversHaelwenn (lanodan) Monnier
2023-08-04Merge branch 'mergeback/2.5.3' into 'develop'Haelwenn
2023-08-04Release 2.5.53Haelwenn (lanodan) Monnier
2023-08-04release_runtime_provider_test: chmod config for hardened permissionsHaelwenn (lanodan) Monnier
2023-08-04changelog: Entry for config permissions restrictionsHaelwenn (lanodan) Monnier
2023-08-04instance gen: Reduce permissions of pleroma directories and config filesHaelwenn (lanodan) Monnier
2023-08-04Config: Restrict permissions of OTP config fileHaelwenn (lanodan) Monnier
2023-08-04Resolve information disclosure vulnerability through emoji pack archive downl...Mark Felder
2023-08-03Merge branch 'tusooa/3154-attachment-type-check' into 'develop'Haelwenn
2023-07-28Merge branch 'fix/2927-disallow-unauthenticated-access' into 'develop'tusooa
2023-07-28add changelog entryfaried nawaz
2023-07-28cleaner ecto query to handle restrict_unauthenticated for activitiesFaried Nawaz
2023-07-28status context: perform visibility check on activities around a statusfaried nawaz
2023-07-18Restrict attachments to only uploaded files onlytusooa/3154-attachment-type-checktusooa
2023-07-17Merge branch '2023-06-deps-update' into 'develop'release/2.6.0Haelwenn
2023-07-07Merge branch 'tusooa/2775-emoji-policy' into 'develop'Haelwenn
2023-07-07Make regex-to-string descriptor reusabletusooa
2023-07-07Fix edge casestusooa
2023-07-07Add changelogtusooa
2023-07-07Test that unicode emoji reactions are not affectedtusooa
2023-07-07Make EmojiPolicy aware of custom emoji reactionstusooa
2023-07-07Improve config examples for EmojiPolicytusooa
2023-07-07Update config cheatsheettusooa
2023-07-07Move emoji_policy.ex to the right placetusooa
2023-07-07EmojiPolicy: Implement delisttusooa
2023-07-07EmojiPolicy: implement remove by shortcodetusooa
2023-07-07Add emoji policy to remove emojis matching certain urlstusooa
2023-07-04Merge branch 'deprecate-scrobbles' into 'develop'tusooa
2023-07-04Merge branch 'hotfix/docs-broken-links' into 'develop'Haelwenn
2023-07-04docs: Fix broken linksHaelwenn (lanodan) Monnier
2023-07-04Merge branch 'fix/pipeline-triggers' into 'develop'Haelwenn
2023-07-04Deprecate audio scrobblingHaelwenn (lanodan) Monnier
2023-07-04CI: Use CI_JOB_TOKEN for cross-repo pipeline triggersHaelwenn (lanodan) Monnier
2023-07-04CI: Let curl return non-0 on http failure codeHaelwenn (lanodan) Monnier
2023-07-03Merge branch 'gentoo_otp' into 'develop'Haelwenn
2023-07-02Merge branch 'tusooa/media-altdomain' into 'develop'Haelwenn
2023-07-02Merge branch 'testfix/system-config-use' into 'develop'Haelwenn
2023-07-02Merge branch 'tusooa/3131-handle-report-from-deactivated-user' into 'develop'Haelwenn
2023-07-02Merge branch 'tusooa/3142-featured-collection-shouldnt-break-user-fetch' into...Haelwenn
2023-07-02Merge branch 'tusooa/3151-amd64-runner' into 'develop'Haelwenn
2023-07-02Fix handling report from a deactivated usertusooa
2023-07-02Fix user fetch completely broken if featured collection is not in a supported...tusooa