Skip to content

3.8.x: security: fix include bypass of EntryFilter#filter symlink check#7228

Merged
jekyllbot merged 2 commits into3.8-stablefrom
3.8-stable-backport-7226
Sep 18, 2018
Merged

3.8.x: security: fix include bypass of EntryFilter#filter symlink check#7228
jekyllbot merged 2 commits into3.8-stablefrom
3.8-stable-backport-7226

Conversation

@parkr
Copy link
Copy Markdown
Member

@parkr parkr commented Sep 7, 2018

Backports #7226 for 3.8.x series of releases.

@parkr parkr added ⏪ backport Changes will be merged into an older stable branch security labels Sep 7, 2018
@parkr parkr requested a review from a team September 7, 2018 19:20
@ashmaroli
Copy link
Copy Markdown
Member

Why is the base branch for this master instead of 3.8-stable..?

@parkr parkr changed the base branch from master to 3.8-stable September 7, 2018 19:32
@DirtyF
Copy link
Copy Markdown
Member

DirtyF commented Sep 18, 2018

@jekyllbot: merge +bug

@jekyllbot jekyllbot merged commit d9a2758 into 3.8-stable Sep 18, 2018
@jekyllbot jekyllbot deleted the 3.8-stable-backport-7226 branch September 18, 2018 16:24
jekyllbot added a commit that referenced this pull request Sep 18, 2018
@ashmaroli ashmaroli added this to the v3.8.4 milestone Sep 18, 2018
koppen added a commit to koppen/mentalized that referenced this pull request Mar 25, 2019
Fixes a minor security issue jekyll/jekyll#7228 and
includes a few bug fixes.
@jekyll jekyll locked and limited conversation to collaborators Sep 18, 2019
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

bug 🐛 fix frozen-due-to-age ⏪ backport Changes will be merged into an older stable branch security

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants