bircni
bc578b7eba
fix: Various sec fixes ( #38108 ) ( #38147 )
...
Backport #38108
- Enforce repository token scope on RSS/Atom feed endpoints so a PAT
without repo scope can no longer read private repo commit data.
- Block HTTP redirects during repository migration clones to prevent
SSRF reaching internal addresses via an attacker-controlled redirect.
- Redact the notification subject after repo access is revoked so
private issue/PR metadata is no longer leaked through the notification
API.
Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com >
2026-06-28 02:18:12 -05:00
..
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2023-02-04 10:30:43 +08:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2025-04-11 21:41:29 +08:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2025-08-27 16:31:21 +00:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2026-01-08 13:37:36 -08:00
2025-05-09 16:17:08 +00:00
2026-05-07 16:19:45 +02:00
2025-07-31 09:34:51 +08:00
2026-05-31 10:28:25 -05:00
2026-01-08 13:37:36 -08:00
2025-07-31 09:34:51 +08:00
2026-05-07 16:19:45 +02:00
2026-05-07 16:19:45 +02:00
2025-07-30 07:08:59 +00:00
2026-05-31 10:28:25 -05:00
2026-02-16 09:57:18 +00:00
2026-05-07 16:19:45 +02:00
2026-05-31 10:28:25 -05:00
2024-11-20 19:26:12 +00:00
2024-11-20 19:26:12 +00:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2025-06-18 01:48:09 +00:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2026-02-08 20:25:30 +00:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2025-08-27 16:31:21 +00:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2023-12-13 21:02:00 +00:00
2022-11-27 18:20:29 +00:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2025-10-23 08:35:48 +00:00
2022-11-27 18:20:29 +00:00
2024-05-06 18:34:16 +02:00
2024-01-19 17:05:02 +01:00
2026-04-04 16:27:57 -07:00
2025-04-01 10:14:01 +00:00
2026-04-14 12:03:26 +00:00
2026-04-14 12:03:26 +00:00
2026-05-31 10:28:25 -05:00
2019-03-27 17:33:00 +08:00
2025-01-13 14:01:53 +08:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2026-01-08 13:37:36 -08:00
2026-05-31 10:28:25 -05:00
2025-08-27 16:31:21 +00:00
2025-12-25 19:26:23 -08:00
2025-01-19 18:41:15 -05:00
2026-05-31 10:28:25 -05:00
2025-08-27 16:31:21 +00:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2022-11-27 18:20:29 +00:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2023-12-13 21:02:00 +00:00
2026-05-31 10:28:25 -05:00
2025-08-27 16:31:21 +00:00
2026-05-31 10:28:25 -05:00
2025-08-27 16:31:21 +00:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2026-05-07 16:19:45 +02:00
2026-05-31 10:28:25 -05:00
2026-06-28 02:18:12 -05:00
2026-05-31 10:28:25 -05:00
2026-01-08 13:37:36 -08:00
2026-05-31 10:28:25 -05:00
2026-06-28 02:18:12 -05:00
2024-02-09 11:02:53 +08:00
2026-05-31 10:28:25 -05:00
2025-03-31 01:53:48 -04:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2026-05-31 10:28:25 -05:00
2026-05-07 16:19:45 +02:00
2026-05-31 10:28:25 -05:00
2025-11-05 17:48:38 +00:00
2025-07-01 06:55:36 +08:00
2022-11-27 18:20:29 +00:00
2026-05-31 10:28:25 -05:00
2025-11-05 17:48:38 +00:00
2025-12-25 19:26:23 -08:00
2026-04-14 12:03:26 +00:00
2026-05-31 10:28:25 -05:00
2026-04-14 12:03:26 +00:00
2026-05-31 10:28:25 -05:00
2025-11-05 17:48:38 +00:00
2026-05-31 10:28:25 -05:00
2025-08-27 16:31:21 +00:00
2026-05-31 10:28:25 -05:00
2025-07-30 07:08:59 +00:00
2026-05-31 10:28:25 -05:00