Next | Query returned 73 messages, browsing 21 to 30 | Previous

History of commit frequency

CVS Commit History:


   2015-11-03 04:29:40 by Alistair G. Crooks | Files touched by this commit (1995)
Log message:
Add SHA512 digests for distfiles for devel category

Issues found with existing distfiles:
	distfiles/eclipse-sourceBuild-srcIncluded-3.0.1.zip
	distfiles/fortran-utils-1.1.tar.gz
	distfiles/ivykis-0.39.tar.gz
	distfiles/enum-1.11.tar.gz
	distfiles/pvs-3.2-libraries.tgz
	distfiles/pvs-3.2-linux.tgz
	distfiles/pvs-3.2-solaris.tgz
	distfiles/pvs-3.2-system.tgz
No changes made to these distinfo files.

Otherwise, existing SHA1 digests verified and found to be the same on
the machine holding the existing distfiles (morden).  All existing
SHA1 digests retained for now as an audit trail.
   2014-09-24 03:06:26 by Blue Rats | Files touched by this commit (5) | Package updated
Log message:
Update to 1.2.17. pkgsrc changes: Add bash:run to USE_TOOLS and
REPLACE_BASH in installed file. Replace PHP interpreter in installed *.php
files. Move options framework into options.mk. Use INSTALLATION_DIRS
instead of INSTALL_DATA_DIR. From doc/RELEASE:

1.2.17 Security Release (2014-03-04)
-------------------------------------------------

MantisBT 1.2.17 is a security update for the stable 1.2.x branch. All
installations that are currently running any 1.2.x version are strongly advised
to upgrade to this release. Download it from [3].

An SQL injection vulnerability (CVE-2014-2238) in adm_config_report.php was
patched. Refer to issue #17055 for detailed information.

This release also includes a few bug fixes for the tracker, including News API
correction for the regression issue #16940 introduced in 1.2.16, as well as
updated translations in many languages.

A full changelog for the 1.2.x series can be found on the official site. [1]

1.2.16 Security Release (2014-02-07)
-------------------------------------------------

MantisBT 1.2.16 is a security update for the stable 1.2.x branch. All
installations that are currently running any 1.2.x version are strongly advised
to upgrade to this release. Download it from [3].

The following security issues were resolved:

 - Cross-site scripting (XSS) issue in account_sponsor_page.php, allowing a
   malicious user with project manager access to execute arbitrary JavaScript
   code (CVE-2013-4460). Affects MantisBT 1.1.0 and later.
   Refer to issue #16513 for detailed information.

 - SQL injection attacks through the SOAP API's mc_attachment_get() function
   (CVE-2014-1608). Affects MantisBT 1.1.0a4 and later.
   Refer to issue #16879 for detailed information.

 - Additional cases of unsanitized SQL query parameters usage were identified,
   potentially allowing SQL injection attacks (CVE-2014-1609).
   Refer to issue #16880 for detailed information.

This release also includes many bug fixes and enhancements to the tracker
and the SOAP api, as well as updated translations in many languages.

A full changelog for the 1.2.x series can be found on the official site. [1]

[1] The changelog is split between multiple releases:

1.2.17     http://www.mantisbt.org/bugs/changelog_page.php?version_id=189
1.2.16     http://www.mantisbt.org/bugs/changelog_page.php?version_id=183
   2013-06-30 13:47:44 by Ryo ONODERA | Files touched by this commit (3) | Package updated
Log message:
Update to 1.2.15

Changelog:

MantisBT 1.2.15 is a security update for the stable 1.2.x branch. All \ 
installations that are currently running any 1.2.x version are strongly advised \ 
to upgrade to this release.

- 0002971: [bugtracker] Reminders are not added to bug history (dregad) - closed.
- 0015470: [bugtracker] Reminders recipient list is truncated (dregad) - closed.
- 0010047: [documentation] Adding new statuses section is missing a step \ 
(dregad) - closed.
- 0010118: [documentation] lang_get_current() returns wrong language if \ 
$g_default_language overwritten (dregad) - closed.
- 0010372: [feature] Don't allow reminders to be sent if the user doesn't have \ 
an email address specificed (dregad) - closed.
- 0013054: [installation] Installer displays a blank page if core.php encounters \ 
a critical error (dregad) - closed.
- 0015357: [bugtracker] uninitialized library path (dregad) - closed.
- 0015471: [bugtracker] bug_reminder.php does not handle unsent reminders \ 
(dregad) - closed.
 - 0015472: [bugtracker] email_bug_reminder() API's return array is always full \ 
list of recipients (dregad) - closed.
- 0015481: [custom fields] Custom fields values are not sorted in the main \ 
filter (dregad) - closed.
- 0015528: [printing] Custom fields user has no access to should not be \ 
displayed on print pages (dregad) - closed.
- 0015538: [bugtracker] Issues list is not displayed when $g_limit_reporters is \ 
ON (dregad) - closed.
- 0015540: [documentation] Wrong example code for custom status translation \ 
(atrol) - closed.
- 0015558: [bugtracker] url_get() does not fall back to other methods when no \ 
data is retrieved (dregad) - closed.
- 0015573: [security] CVE-2013-1883: One query can be issued via current Mantis \ 
interface to take down site (dregad) - closed.
- 0015575: [documentation] Turning on $g_show_queries_list causes Mantis to \ 
crash with an error (dregad) - closed.
- 0015659: [localization] Appears @70@ and @80@ in the list of resolutions in \ 
the "view Issues" page when mantis is in catalan. (dregad) - closed.
- 0015691: [administration] Config report: retrieval of saved project filter \ 
from cookie does not work (dregad) - closed.
- 0015453: [security] CVE-2013-1930: Close button is shown on webpage despite \ 
'close' is not a valid status by workflow (dregad) - closed.
- 0015511: [security] CVE-2013-1931: XSS vulnerability when deleting a version \ 
(atrol) - closed.
- 0015698: [bugtracker] 'extract() expects parameter 1 to be array, boolean \ 
given' in '/srv/www/bugs/account_prof_edit_page.php' line 48 (dregad) - closed.
- 0015704: [documentation] Wrong description of writing custom_functions (atrol) \ 
- closed.
- 0015744: [bugtracker] Reminder bugnote with list of recipients not added if no \ 
text provided (dregad) - closed.
- 0015451: [api soap] Incorrect invocations of SoapObjectsFactory::newSoapFault \ 
(rombert) - closed.
- 0015517: [api soap] mc_project_get_versions() result can't be parsed by C# \ 
(dregad) - closed.
- 0015522: [api soap] mc_project_get_issues does not report due_date (dregad) - \ 
closed.

MantisBT 1.2.14 is a security update for the stable 1.2.x branch. All \ 
installations that are currently running any 1.2.x version are strongly advised \ 
to upgrade to this release.

Please refer to the release notes for details.

- 0015416: [security] CVE-2013-1934: XSS issue in adm_config_report.php when \ 
displaying complex value (dregad) - closed.
- 0015415: [security] CVE-2013-1932: XSS vulnerability on Configuration Report \ 
page (dregad) - closed.
- 0015411: [performance] Huge memory consumption for print_user_option_list() \ 
(dregad) - closed.

MantisBT 1.2.13 had to be withdrawn shortly after release, as it introduced a bug
(#15411) causing the View Issues page to consume significantly more memory for
instances with large numbers of users (order 10k+), leading to system crashes,
as well as an XSS issue (#15415) in the Configuration Report page.

We recommend not to use 1.2.13, and deploy version 1.2.14 instead.

- 0014871: [api soap] Add support for the built-in soap extension in addition to \ 
nusoap (rombert) - closed.
- 0003693: [bugtracker] Make the username in Manage Projects a clickable link to \ 
edit that user (dregad) - closed.
- 0007586: [customization] generic configuration editor cannot 'EDIT' an option \ 
(dregad) - closed.
- 0010130: [filters] Filter "Assigned to" does not display usernames \ 
when project "All Projects" is selected (dregad) - closed.
- 0011854: [documentation] Parameter $g_default_timezone" is not mentioned \ 
in administration_guide (dregad) - closed.
- 0013298: [preferences] commas and multi-dimensional arrays in adm_config_set \ 
(dregad) - closed.
- 0013680: [performance] Configuration page takes a very long time to load \ 
(dregad) - closed.
- 0014009: [administration] admin/check.php fatal error on PHP 5.1.x (undefined \ 
function timezone_identifiers_list()) (dregad) - closed.
- 0014559: [administration] Adding filter for "Configuration report" \ 
(dregad) - closed.
- 0015199: [other] Update json api error format (rombert) - closed.
- 0015201: [db postgresql] Summary page fail (dregad) - closed.
- 0015384: [security] CVE-2013-1810 XSS vulnerability on summary page (dhx) - closed.
- 0015247: [administration] Protected account change still sends email (dregad) \ 
- closed.
- 0015248: [email] The order of sending emails is inverted when using cron \ 
(dregad) - closed.
- 0015255: [bugtracker] Date filter fields are disabled when $g_use_javascript = \ 
OFF (dregad) - closed.
- 0015257: [filters] Inconsistent use of numeric vs text month in date filter \ 
selection fields (dregad) - closed.
- 0015258: [security] CVE-2013-1811 Reporter can change issue status to 'new' \ 
(dregad) - closed.
- 0015260: [bugtracker] access_get_status_threshold() returns incorrect value \ 
for NEW (dregad) - closed.
- 0015264: [custom fields] custom_field_get_id_from_name() broken since 1.2.12 \ 
(dregad) - closed.
- 0015265: [custom fields] custom_field_get_id_from_name() doesn't cache result \ 
of obsolete custom field names (dregad) - closed.
- 0015280: [code cleanup] Form in manage_columns_inc.php has misleading name and \ 
unnecessary multipart encoding (dregad) - closed.
- 0015320: [filters] Date filters broken since 1.2.12 (rombert) - closed.
- 0015360: [bugtracker] Add Missing config 'reminder_receive_threshold' in \ 
workflow threshold page (dregad) - closed.
- 0015370: [bugtracker] When a bug is resolved on report, default the handler to \ 
the current user (rombert) - closed.
- 0015373: [security] CVE-2013-0197 XSS vulnerability with match_type filter \ 
(dhx) - closed.
- 0015382: [email] Additional improvements to email logging (dregad) - closed.
- 0015388: [filters] Update the match_type parameter to be XSS-safe by itself \ 
(dregad) - closed.
- 0015389: [filters] Display of match_type filter property for unknown types \ 
(dregad) - closed.
- 0015356: [api soap] improve error handling in mc_issue_api.php (rombert) - closed.
- 0014157: [api soap] Array to string conversion error on soap request with PHP \ 
5.4 (rombert) - closed.
- 0014672: [api soap] Slow performance of SOAP calls due to nusuoap (rombert) - \ 
closed.
- 0015222: [api soap] mc_project_delete_category fails to delete category \ 
(rombert) - closed.
   2013-03-16 08:21:26 by OBATA Akio | Files touched by this commit (45)
Log message:
Bump PKGREVISION from default PHP version change to 5.4.
   2012-12-25 22:49:05 by Ryo ONODERA | Files touched by this commit (3) | Package updated
Log message:
Update to 1.2.12 from 1.1.7

* Set LICENSE and pkglint
* Change to 1.2.x branch
* Many security fixes shall be included, but I cannot specify them...

Changelog:
Full log: http://www.mantisbt.org/bugs/changelog_page.php

MantisBT Release Notes

1.2.12 Maintenance Release (2012-11-10)
-------------------------------------------------

MantisBT 1.2.12 resolves over 70 issues mainly in the following categories:
security, MS SQL and PostgreSQL databases support, Change Log page, custom
fields, installation, attachments, SOAP API, XML import/export plugin,
e-mail (including update of the PHPMailer library to version 5.2.1) and others.

In addition, it also brings several enhancements:
 - filter page now allows 'OR' logic and to query by notes' authors
 - improved e-mail logging (see #14630)
 - new 'EVENT_UPDATE_BUG_STATUS_FORM' plugin event
 - updated Admin Guide
 - translations in many languages

All installations that are currently running any 1.2.x or older version are
advised to upgrade to this release.

A full changelog for the 1.2.x series can be found on the official site. [1]

1.2.11 Maintenance Release (2012-06-08)
-------------------------------------------------

MantisBT 1.2.11 is a security update for the stable 1.2.x branch. All
installations that are currently running any 1.2.x or older version are
advised to upgrade to this release.

This release also contains numerous minor bug fixes to MantisBT,
SOAP API fixes, enhancements to the admin guide and improved translations in many
languages.

A full changelog for the 1.2.x series can be found on the official site. [1]

1.2.10 Maintenance Release (2012-04-01)
-------------------------------------------------

MantisBT 1.2.10 is a maintenance release. All installations that are currently
running any 1.2.x version are advised to upgrade to this release.

A full changelog for the 1.2.x series can be found on the official site. [1]

1.2.9 Maintenance Release (2012-03-03)
-------------------------------------------------

MantisBT 1.2.9 release delivers 92 fixes and improvements including security
fixes, new MantisBT logo, MantisTouch integration, MS SQL fixes, SOAP API
improvements, and others.  We recommend that all instances be upgraded to this
release.

A full changelog for the 1.2.x series can be found on the official site. [1]

1.2.8 Security Release (2011-09-05)
-------------------------------------------------

MantisBT 1.2.8 is a security update for the stable 1.2.x branch. All
installations that are currently running any 1.2.x version are advised to
upgrade to this release.

Paulino Calderon from Websec, High-Tech Bridge Security Research Lab and Paul
Richards discovered 3 vulnerabilities:
 - 1x local file inclusion (LFI)/directory traversal
 - 2x cross site scriptin (XSS)

These vulnerabilities could have very severe consequences for users of
MantisBT, particularly as a result of the local file inclusion vulnerability.
If an attacker can upload their own PHP script to the server as an attachment,
they may be able to execute this script using the LFI vulnerability.

Refer to issues #13191 and #13281 for detailed information.

A full changelog for the 1.2.x series can be found on the official site. [1]

1.2.7 Security Release (2011-08-19)
-------------------------------------------------

MantisBT 1.2.7 is a security update for the stable 1.2.x branch. All
installations that are currently running any 1.2.x version are advised to
upgrade to this release.

Net.Edit0r from BlACK Hat Group posted a vulnerability report for an XSS issue
in search.php. All MantisBT users (including anonymous users that are not
logged in to public bug trackers) could be impacted by this vulnerability.
Refer to issue #13245 for full details.

This release also contains numerous minor bug fixes to MantisBT and improved
translations in many languages.

A full changelog for the 1.2.x series can be found on the official site. [1]

1.2.6 Maintenance Release (2011-07-26)
-------------------------------------------------

MantisBT 1.2.6 is a maintenance update for the stable 1.2.x branch. It is
recommended that all MantisBT users (including those still using 1.1.x or
earlier versions) upgrade to this latest release.

This release brings bug fixes and improvements across a range of MantisBT
features, especially the SOAP API, authentication, time tracking, and
billing areas. Documentation and translation updates are also included.

A full changelog for the 1.2.x series can be found on the official site. [1]

1.2.5 Maintenance Release (2011-04-05)
-------------------------------------------------

MantisBT 1.2.5 is a maintenance update for the stable 1.2.x branch. It is
recommended that all MantisBT users (including those still using 1.1.x or
earlier versions) upgrade to this latest release.

This release brings improved translations in many languages as well as
numerous bug fixes across a range of MantisBT features.

A full changelog for the 1.2.x series can be found on the official site. [1]

1.2.4 Security Release (2010-12-15)
-------------------------------------------------

MantisBT 1.2.4 is a security update for the stable 1.2.x branch. All
installations that are currently running any 1.2.x version are advised to
upgrade to this release.

Gjoko Krstic of Zero Science Lab reported multiple vulnerabilities in the
admin/upgrade_unattended.php script. Issue #12607 provides more detail on the
vulnerabilities discovered. We thank Gjoko for his detailed assistance with
testing, patching and answering questions. Please note that the /admin/
directory should be removed from all MantisBT installations after the
installation or upgrade has been completed. This is particularly true for
MantisBT installations accessible over the Internet.

Also included with 1.2.4 are some bug fixes relating to fonts in the
MantisGraph plugin, SOAP API, CSV export, custom field values, relationship
graphs, fields on the manage user page, built-in time tracking and the
allow_reporter_close feature. This release includes updated translations for
many languages and improved installation documentation in doc/INSTALL.

A full changelog for the 1.2.x series can be found on the official site. [1]

1.2.3 Security Release (2010-09-14)
-------------------------------------------------

MantisBT 1.2.3 is a security update for the stable 1.2.x branch. All
installations that are currently running any 1.2.x version are advised to
upgrade to this release.

Issue #12312 covers an XSS vulnerability in the upstream NuSOAP library.
The fix has been applied to the library included in MantisBT releases, and a
patch has been submitted upstream for future releases of NuSOAP. See
http://www.mantisbt.org/bugs/view.php?id=12312 for further details.

Also included with 1.2.3 are another round of XSS fixes to MantisBT, improved
excel export, translation updates, and bug fixes to the SOAP API, installation,
plugin system, and email notifications.

A full changelog for the 1.2.x series can be found on the official site. [1]

1.2.2 Security Release (2010-07-29)
-------------------------------------------------

MantisBT 1.2.2 is a security update for the stable 1.2.x branch. All
installations that are currently running any 1.2.x version are advised to
upgrade to this release.

Issue #11952 covers a security fix to the display of inline attachments, where
"Arbitrary inline attachment rendering could lead to cross-domain scripting or
other browser attacks".  See http://www.mantisbt.org/bugs/view.php?id=11952
for further details and information.

Also included with 1.2.2 are a range of translation updates, regression fixes,
and bug fixes, including multiple SOAP API-related bugs and regressions.

A full changelog for the 1.2.x series can be found on the official site. [1]

1.2.1 Maintenance Release (2010-04-23)
-------------------------------------------------

MantisBT 1.2.1 is a maintenance update for the stable 1.2.x branch. All
installations that are currently running any 1.1.x or 1.2.0 version are
advised to upgrade to this release.

Included with 1.2.1 are a range of bug fixes, translation updates, and general
improvements over the initial 1.2.0 release.  Highlights include an improved
installation, a fixed upgrade path from 1.1.x, fixes to the URL and path
detection, and updates to the plugin event system.

A full changelog for the 1.2.x series can be found on the official site. [1]

1.2.0 Stable Release (2010-02-22)
-------------------------------------------------

This release marks the first official release in the 1.2.x series of MantisBT.
1.2.0 is a major feature release for MantisBT, and includes many bugfixes and
enhancements over the 1.1.x stable branch.  All users of 1.1.x are highly
encouraged to upgrade as soon as possible.

There are many new features added to 1.2.0, including:

 - Converted the MantisBT Manual to Docbook format, and added a new Developer's
   Guide manual, both of which are compiled and included in every release

 - Implemented a plugin system with many plugins already released [2]

 - Global categories available to all projects, as well as project categories
   inheriting from parent projects to child projects;  both are optional

 - Tracked change history for textarea fields (Description, etc) and bug notes

 - Customizable sets of columns for View Issues page and export formats

 - Combined simple and advanced views into a single, configurable view that
   allows selecting exactly what fields to show or hide

 - Improved roadmap and changelog pages, including version release dates, and
   permalinks to individual versions

 - Marking versions as obsolete to hide them from the roadmap and changelog

 - More configuration options for rebranding MantisBT installations

 - Improved support for PostgreSQL databases

 - Improved support for UTF-8 localizations and content

 - Implemented custom search providers for Firefox and Internet Explorer

 - Implemented localized timestamps using according to user-preferred timezones

There have also been many improvements to the codebase beyond adding features:

 - Migrated to parameterised database queries throughout the codebase for both
   performance and security improvements

 - Added PHPDoc compatible documentation to all internal API's

 - Removed many hardcoded references to access levels and other enumerations,
   for improved customizability.

 - Migrated away from DATETIME fields to integer timestamps for timezone usage

 - All 3rd party code is now contained within the library/ path, including
   documentation on library versions and any patches applied

 - Initial support for MySQL 6 and PHP 5.3
   2012-10-31 12:19:55 by Aleksej Saushev | Files touched by this commit (1460)
Log message:
Drop superfluous PKG_DESTDIR_SUPPORT, "user-destdir" is default these days.
   2012-02-02 10:59:39 by Hans Rosenfeld | Files touched by this commit (1)
Log message:
Use ${RM} -f to avoid failure if no files are found to be removed.
   2011-09-16 07:46:27 by OBATA Akio | Files touched by this commit (29)
Log message:
Bump PKGREVISION from PHP_VERSION_DEFAULT changes.
   2010-09-30 10:27:53 by OBATA Akio | Files touched by this commit (1)
Log message:
No need to buildlink with database library.

Bump PKGREVISION to relax dependency.
   2009-07-17 20:00:26 by Adrian Portelli | Files touched by this commit (126)
Log message:
Give up MAINTAINER

Next | Query returned 73 messages, browsing 21 to 30 | Previous