Commit Graph

  • cbe7c74dd7 update libs develop Andy Miller 2026-02-25 15:30:14 -07:00
  • 8d0b049993 safe upgrade hardening 1.8 Andy Miller 2026-02-25 13:28:09 -07:00
  • 831dfb471e ignore tmp Andy Miller 2026-02-24 21:58:13 -07:00
  • 1a7202f7f3 Add upgrade resilience: maintenance mode, opcache reset, and 1.7.50 compat stubs Andy Miller 2026-02-24 21:47:49 -07:00
  • c4e73d3827 Merge release/1.8.0 fixes: YamlUpdater undefine, upgrade resilience, PHP 8.3 guard, standalone upgrade script Andy Miller 2026-02-24 21:53:15 -07:00
  • 7818f601ea support version ie, typhoon:2.4.8 Andy Miller 2026-02-24 14:03:57 -07:00
  • 1c580f6d54 fixes for modern scheduler Andy Miller 2026-02-22 23:22:01 -05:00
  • 44d26ef7e8 fixes for modern scheduler Andy Miller 2026-02-22 23:22:01 -05:00
  • 420a99f6f8 Fix for undefined array key path triggered through url encoded characters (#4012) Xoriander 2026-02-04 05:14:28 +01:00
  • 5404c3d2a5 More readability for the LogViewerCommand time output (#4009) Xoriander 2026-02-04 18:49:15 +01:00
  • 619dfa26a4 Fix for wrong LogViewer date output (#4007) Xoriander 2026-02-05 18:31:24 +01:00
  • c191b0b47e impoved yaml linter to be more use built-in grav for more detail Andy Miller 2026-02-05 12:16:42 -07:00
  • b8eea21a44 Fix for wrong LogViewer date output (#4007) Xoriander 2026-02-05 18:31:24 +01:00
  • dfdd3786cb update vendor libs Andy Miller 2026-02-04 12:34:26 -07:00
  • db852f3a47 trigger docker workflow on release Andy Miller 2026-02-04 12:34:17 -07:00
  • 13a2093726 Merge branch '1.8' of github.com:getgrav/grav into 1.8 Andy Miller 2026-02-04 12:34:03 -07:00
  • b85e87ae3f Added -v for YamlLinter Andy Miller 2026-02-04 12:33:32 -07:00
  • a5645f3a4c More readability for the LogViewerCommand time output (#4009) Xoriander 2026-02-04 18:49:15 +01:00
  • f31e155269 Fix for undefined array key path triggered through url encoded characters (#4012) Xoriander 2026-02-04 05:14:28 +01:00
  • 2dcf917999 Update system/src/Grav/Common/Twig/Compatibility/Twig3CompatibilityTransformer.php fix/twig3-regex-jit-stack-exhaustion Andy Miller 2026-02-03 19:07:54 -07:00
  • bf7dd2e6c8 Update system/src/Grav/Common/Twig/Compatibility/Twig3CompatibilityTransformer.php Andy Miller 2026-02-03 19:07:46 -07:00
  • e0f5db7c8c Add claude GitHub actions 1770170196497 (#4028) Andy Miller 2026-02-03 18:58:34 -07:00
  • 9185fc519d "Claude Code Review workflow" add-claude-github-actions-1770170196497 Andy Miller 2026-02-03 18:56:38 -07:00
  • 15be03aa41 "Claude PR Assistant workflow" Andy Miller 2026-02-03 18:56:37 -07:00
  • 508650583a Fix JIT stack exhaustion in Twig3 compatibility regex patterns Andy Miller 2026-02-03 18:43:20 -07:00
  • 4a76ba18b6 remove standlone binary Andy Miller 2026-01-30 09:54:45 -07:00
  • 502f53124c remove standlone binary Andy Miller 2026-01-30 09:54:45 -07:00
  • 09be5334d3 cache-cleanup command Andy Miller 2026-01-30 09:48:38 -07:00
  • 607ef2797c cache-cleanup command Andy Miller 2026-01-30 09:48:38 -07:00
  • 07de0cb4e6 prepare for beta release 1.8.0-beta.29 Andy Miller 2025-12-27 19:52:39 -07:00
  • 007b168ad9 don’t do internal gzip, rely on webserver Andy Miller 2025-12-25 21:41:20 -07:00
  • 952830b529 fix gzip encoding issue with newer PHP 8 versions Andy Miller 2025-12-25 21:17:22 -07:00
  • dbd80799fe update vendor libs Andy Miller 2025-12-25 20:49:22 -07:00
  • 853ccb6464 fix for broken symlinks Andy Miller 2025-12-25 16:32:20 -07:00
  • 4774622d26 minor tweak for api script Andy Miller 2025-12-23 21:54:28 -07:00
  • 0e4f37eca7 fix of setEscaper move in Twig 3.9+ Andy Miller 2025-12-22 21:43:10 -07:00
  • 6b54b32140 fix for user editing causing hashed_password to be removed Andy Miller 2025-12-17 14:36:53 -07:00
  • 368982cb46 fix for nested config changes Andy Miller 2025-12-17 12:06:59 -07:00
  • b086561160 fix for unusual format SVGs Andy Miller 2025-12-15 15:08:15 -07:00
  • 15cb068f95 fix for grav not picking up config + page changes Andy Miller 2025-12-12 16:29:43 -07:00
  • d34213232b avoid mail in twig content trigger security error Andy Miller 2025-12-12 16:20:35 -07:00
  • 7a6b8a90d4 prepare for beta release 1.8.0-beta.28 Andy Miller 2025-12-08 20:46:53 -07:00
  • 2813ea0701 Merge branch 'develop' into 1.7.51 1.7.50 Andy Miller 2025-12-08 20:30:32 -07:00
  • 97af1bc35b checkout correct version Andy Miller 2025-11-11 15:16:47 +00:00
  • 306f33f4ae fixes for twig3 loader + improve recovery mode Andy Miller 2025-12-08 18:07:32 -07:00
  • 6cb8229806 fix for missing file Andy Miller 2025-12-08 10:58:46 -07:00
  • 95e285efa4 Merge branch 'performance-part-3' into 1.8 Andy Miller 2025-12-05 21:00:33 -07:00
  • 80410dae13 opcache fix in CompiledFile Andy Miller 2025-12-05 20:59:46 -07:00
  • fae70e5fc9 fixes #4002 - Backups blocking /var/www Andy Miller 2025-12-03 19:30:32 -07:00
  • 9d9247a32f fix false positives in Security with on_events Andy Miller 2025-12-03 14:17:17 -07:00
  • 94d85cd873 add support for environment in grav scheduler Andy Miller 2025-12-03 10:41:29 -07:00
  • 58002f4903 Bump the github-actions group with 2 updates (#3997) dependabot[bot] 2025-12-02 05:35:16 -07:00
  • 19a9fafe37 fix(ci): remove outdated travis config (#3864) Rotzbua 2025-12-01 16:23:10 +01:00
  • 8ad4c006a2 feat(ci): add dependabot to keep GH Actions up to date (#3866) Rotzbua 2025-12-01 16:21:08 +01:00
  • 0f879bd1d4 prepare for beta.27 release 1.8.0-beta.27 Andy Miller 2025-11-30 16:17:37 -07:00
  • fd828d452e trim down default user/config/system.yaml Andy Miller 2025-11-30 16:14:35 -07:00
  • 63bbc1cac6 flex-objects caching fix Andy Miller 2025-11-30 16:06:31 -07:00
  • 528032b11a update changelog Andy Miller 2025-11-29 21:18:57 -07:00
  • a4c3a3af6d Add isindex to XSS dangerous tags (CVE-2023-31506 / GHSA-h85h-xm8x-vfw7) Andy Miller 2025-11-29 21:07:23 -07:00
  • b7e1958a6e Merge branch 'fix/GHSA-4cwq-j7jv-qmwg-title-email-leak' into 1.8 Andy Miller 2025-11-29 18:29:39 -07:00
  • 0c38968c58 Fix email disclosure in user edit page title (GHSA-4cwq-j7jv-qmwg) Andy Miller 2025-11-29 18:27:08 -07:00
  • 9d11094e41 Merge branch 'fix/GHSA-x62q-p736-3997-GHSA-gq3g-666w-7h85-admin-security' into 1.8 Andy Miller 2025-11-29 17:52:03 -07:00
  • ed640a1314 Merge branch 'fix/GHSA-p4ww-mcp9-j6f2-GHSA-m8vh-v6r6-w7p6-GHSA-j422-qmxp-hv94-file-path-security' into 1.8 Andy Miller 2025-11-29 17:45:33 -07:00
  • e37259527d Merge branch 'fix/GHSA-662m-56v4-3r8f-GHSA-858q-77wx-hhx6-GHSA-8535-hvm8-2hmv-GHSA-gjc5-8cfh-653x-GHSA-52hh-vxfw-p6rg-ssti-sandbox' into 1.8 Andy Miller 2025-11-29 17:30:39 -07:00
  • 3462d94d57 Merge branch 'fix/GHSA-h756-wh59-hhjv-GHSA-cjcp-qxvg-4rjm-username-validation' into 1.8 Andy Miller 2025-11-29 17:29:15 -07:00
  • 19c2f8da76 Fix path traversal and uniqueness vulnerabilities in username validation Andy Miller 2025-11-29 13:09:49 -07:00
  • a161399c84 Fix DoS via cron expressions and password hash exposure Andy Miller 2025-11-29 15:51:51 -07:00
  • 5f120c328b Fix file read, DoS, and path traversal vulnerabilities Andy Miller 2025-11-29 14:27:09 -07:00
  • db924c4a26 Expand SSTI sandbox blacklist to block known attack vectors Andy Miller 2025-11-29 13:16:34 -07:00
  • 9fc1b42d59 prepare beta release 1.8.0-beta.26 Andy Miller 2025-11-29 11:02:20 -07:00
  • c8878dfc80 upgrade to symfony 7.4 stable Andy Miller 2025-11-29 10:58:03 -07:00
  • 779661ab8a more improvements for JS minification and now pulls any broken JS out of pipeline Andy Miller 2025-11-27 20:56:07 +00:00
  • 3985638a8f more debug in the Pipeline.php to identify issues Andy Miller 2025-11-27 19:19:02 +00:00
  • 52fd9a6e7b update gitignore Andy Miller 2025-11-25 09:47:28 +00:00
  • 45e6ed941f Fix double execution of preflight checks during self-upgrade Andy Miller 2025-11-20 11:16:07 +00:00
  • 2c2b2fc2e4 Optimize preflight Monolog checks by skipping vendor directories Andy Miller 2025-11-20 11:12:03 +00:00
  • b0301beee3 Fix slow SafeUpgradeServiceTest by optimizing snapshot pruning Andy Miller 2025-11-20 10:51:45 +00:00
  • ce6a1b3bcb Ensure file permissions are preserved during safe-upgrade copy operations Andy Miller 2025-11-18 18:28:46 +00:00
  • d42adcd593 Fix safe-upgrade snapshot creation (copy vs move) and implement pruning Andy Miller 2025-11-18 18:21:34 +00:00
  • bcd93c321b try again Andy Miller 2025-11-24 22:18:43 +00:00
  • 8bd711f6b1 fixes for versions Andy Miller 2025-11-24 21:42:03 +00:00
  • fa707eb7eb vendor updates Andy Miller 2025-11-24 21:38:55 +00:00
  • 18d285ec36 Merge branch 'develop' of github.com:getgrav/grav into develop Andy Miller 2025-11-24 21:06:07 +00:00
  • 04c6bdf287 disallow xref/xhref in SVGs Andy Miller 2025-11-24 21:04:44 +00:00
  • a78789b291 upgrade compoer libs Andy Miller 2025-11-24 21:05:46 +00:00
  • caa127cd53 disallow xref/xhref in SVGs Andy Miller 2025-11-24 21:04:44 +00:00
  • 3ddc548d51 Add new Twig filter/function array_group_by for grouping arrays and collections (#3970) pmoreno.rodriguez 2025-11-23 19:09:12 +01:00
  • 48343d7714 fix range requests for partial content in Utils::downloads() - Fixes #3990 Andy Miller 2025-11-23 17:55:28 +00:00
  • 5f087d3a43 fix range requests for partial content in Utils::downloads() - Fixes #3990 Andy Miller 2025-11-23 17:55:28 +00:00
  • 1bc6e5e13a prepare for beta release 1.8.0-beta.25 Andy Miller 2025-11-22 11:17:37 +00:00
  • f339bb83c5 update composer Andy Miller 2025-11-22 11:16:08 +00:00
  • 27789991ae prepare for beta release 1.8.0-beta.24 Andy Miller 2025-11-21 12:45:03 +00:00
  • 114aebae7c more robust deferred logic + deprecated fixes Andy Miller 2025-11-21 12:25:58 +00:00
  • 370dfd6016 updated vendor libs Andy Miller 2025-11-21 11:37:28 +00:00
  • 1d05e6bdc4 pages rebuild optimization Andy Miller 2025-11-21 11:16:34 +00:00
  • 3acff8a9f8 update changelog Andy Miller 2025-11-20 11:18:20 +00:00
  • ea59bdb1d4 Fix double execution of preflight checks during self-upgrade Andy Miller 2025-11-20 11:16:07 +00:00
  • 02330b96d9 Optimize preflight Monolog checks by skipping vendor directories Andy Miller 2025-11-20 11:12:03 +00:00
  • 2b1d73fd26 fix for slow tests Andy Miller 2025-11-20 10:54:24 +00:00
  • 4e11ca7c8e Fix slow SafeUpgradeServiceTest by optimizing snapshot pruning Andy Miller 2025-11-20 10:51:45 +00:00