bircni
9e84deb969
fix: Various sec fixes 2 ( #38108 )
...
- Enforce repository token scope on RSS/Atom feed endpoints so a PAT
without repo scope can no longer read private repo commit data.
- Block HTTP redirects during repository migration clones to prevent
SSRF reaching internal addresses via an attacker-controlled redirect.
- Redact the notification subject after repo access is revoked so
private issue/PR metadata is no longer leaked through the notification
API.
---------
Co-authored-by: Lunny Xiao <xiaolunwen@gmail.com >
2026-06-17 06:50:25 +02:00
..
2026-05-26 15:49:31 -07:00
2026-05-26 15:49:31 -07:00
2026-06-12 07:35:59 +02:00
2023-02-04 10:30:43 +08:00
2026-05-26 15:49:31 -07:00
2026-05-26 15:49:31 -07:00
2025-04-11 21:41:29 +08:00
2026-05-26 15:49:31 -07:00
2026-05-26 15:49:31 -07:00
2026-05-26 15:49:31 -07:00
2025-08-27 16:31:21 +00:00
2026-05-26 15:49:31 -07:00
2026-05-26 15:49:31 -07:00
2026-05-26 15:49:31 -07:00
2026-05-26 15:49:31 -07:00
2026-05-26 15:49:31 -07:00
2026-01-08 13:37:36 -08:00
2025-05-09 16:17:08 +00:00
2026-05-07 16:19:45 +02:00
2026-05-13 09:00:41 +02:00
2026-05-26 15:49:31 -07:00
2026-01-08 13:37:36 -08:00
2025-07-31 09:34:51 +08:00
2026-06-15 17:55:31 +00:00
2026-06-15 17:55:31 +00:00
2026-05-07 16:19:45 +02:00
2026-05-07 16:19:45 +02:00
2025-07-30 07:08:59 +00:00
2026-05-26 15:49:31 -07:00
2026-02-16 09:57:18 +00:00
2026-06-11 18:08:55 +00:00
2026-06-11 18:08:55 +00:00
2024-11-20 19:26:12 +00:00
2024-11-20 19:26:12 +00:00
2026-05-26 15:49:31 -07:00
2026-06-04 13:56:16 +00:00
2025-06-18 01:48:09 +00:00
2026-05-26 15:49:31 -07:00
2026-05-26 15:49:31 -07:00
2026-02-08 20:25:30 +00:00
2026-06-04 13:56:16 +00:00
2026-05-26 15:49:31 -07:00
2025-08-27 16:31:21 +00:00
2026-05-26 15:49:31 -07:00
2026-05-26 15:49:31 -07:00
2026-05-26 15:49:31 -07:00
2023-12-13 21:02:00 +00:00
2022-11-27 18:20:29 +00:00
2026-05-26 15:49:31 -07:00
2026-05-26 15:49:31 -07:00
2026-05-26 15:49:31 -07:00
2026-05-26 15:49:31 -07:00
2025-10-23 08:35:48 +00:00
2022-11-27 18:20:29 +00:00
2024-05-06 18:34:16 +02:00
2024-01-19 17:05:02 +01:00
2026-04-04 16:27:57 -07:00
2026-06-11 18:08:55 +00:00
2026-04-14 12:03:26 +00:00
2026-05-13 09:00:41 +02:00
2026-05-26 15:49:31 -07:00
2025-01-13 14:01:53 +08:00
2026-06-12 18:27:38 +00:00
2026-06-06 11:06:08 +00:00
2026-05-26 15:49:31 -07:00
2026-01-08 13:37:36 -08:00
2026-05-26 15:49:31 -07:00
2025-08-27 16:31:21 +00:00
2025-12-25 19:26:23 -08:00
2025-01-19 18:41:15 -05:00
2026-05-26 15:49:31 -07:00
2025-08-27 16:31:21 +00:00
2026-05-26 15:49:31 -07:00
2026-06-11 17:12:30 +00:00
2026-06-06 11:06:08 +00:00
2026-06-11 18:08:55 +00:00
2026-06-13 04:43:25 +00:00
2026-05-26 15:49:31 -07:00
2026-05-26 15:49:31 -07:00
2026-05-26 15:49:31 -07:00
2026-06-11 18:08:55 +00:00
2022-11-27 18:20:29 +00:00
2026-05-26 15:49:31 -07:00
2026-05-26 15:49:31 -07:00
2023-12-13 21:02:00 +00:00
2026-05-26 15:49:31 -07:00
2025-08-27 16:31:21 +00:00
2026-06-12 18:27:38 +00:00
2025-08-27 16:31:21 +00:00
2026-05-26 15:49:31 -07:00
2026-05-26 15:49:31 -07:00
2026-05-26 15:49:31 -07:00
2026-05-07 16:19:45 +02:00
2026-05-26 15:49:31 -07:00
2026-06-17 06:50:25 +02:00
2026-05-26 15:49:31 -07:00
2026-01-08 13:37:36 -08:00
2026-05-26 15:49:31 -07:00
2026-06-17 06:50:25 +02:00
2024-02-09 11:02:53 +08:00
2026-05-26 15:49:31 -07:00
2025-03-31 01:53:48 -04:00
2026-05-26 15:49:31 -07:00
2026-05-26 15:49:31 -07:00
2026-05-26 15:49:31 -07:00
2026-05-07 16:19:45 +02:00
2026-05-26 15:49:31 -07:00
2025-11-05 17:48:38 +00:00
2025-07-01 06:55:36 +08:00
2022-11-27 18:20:29 +00:00
2026-05-26 15:49:31 -07:00
2026-05-13 09:00:41 +02:00
2025-12-25 19:26:23 -08:00
2026-04-14 12:03:26 +00:00
2026-05-26 15:49:31 -07:00
2026-04-14 12:03:26 +00:00
2026-05-26 15:49:31 -07:00
2025-11-05 17:48:38 +00:00
2026-06-06 11:06:08 +00:00
2025-08-27 16:31:21 +00:00
2026-05-26 15:49:31 -07:00
2025-07-30 07:08:59 +00:00
2026-05-26 15:49:31 -07:00