Commit Graph

1527 Commits

Author SHA1 Message Date
jamesread 5ff6b5d080 fix: Entity ordering (#886, #762) 2026-03-08 22:16:24 +00:00
jamesread 0fee24089f fix: Restart action button was not working 2026-03-08 21:11:27 +00:00
jamesread 3f46007281 fix: Relax default CSP to allow iconify to work 2026-03-08 20:46:52 +00:00
James Read 276e3f62dd
Next (#915) 2026-03-05 09:51:25 +00:00
jamesread b032ae5e5e chore: fix regression on arguments not being found 2026-03-05 08:29:30 +00:00
James Read 6e7f3b0823
Merge commit from fork
security: GHSA-jf73-858c-54pg (MODERATE) View permission not being checked when returning dashboards
2026-03-05 03:24:56 -05:00
James Read 93d983c506
Merge branch 'next' into advisory-fix-1 2026-03-05 03:24:12 -05:00
jamesread d7962710e7 security: GHSA-jf73-858c-54pg (MODERATE) View permission not being checked when returning dashboards 2026-03-05 08:20:02 +00:00
jamesread 9080577f2b chore: potential crash in unit tests 2026-03-05 08:10:56 +00:00
jamesread 10f5ba62a2 docs: typos in SECURITY.md 2026-03-05 08:07:56 +00:00
jamesread 131393fb2d Merge branch 'next' of github.com:OliveTin/OliveTin into next 2026-03-05 00:24:20 +00:00
jamesread 9d55d4a178 docs: Policy change, 2k will receive security updates much slower 2026-03-05 00:24:00 +00:00
James Read 06557683a1
Merge commit from fork
GHSA-fwhj-785h-43hh
2026-03-04 19:16:35 -05:00
James Read 5e0c052e68
Merge branch 'next' into advisory-fix-1 2026-03-04 19:16:07 -05:00
James Read 6202736d53
Merge commit from fork
security: GHSA-p443-p7w5-2f7f (MODERATE) RestartAction always runs actions as guest
2026-03-04 19:05:48 -05:00
jamesread cb46a597b2 security: GHSA-p443-p7w5-2f7f (MODERATE) RestartAction always runs actions as guest 2026-03-05 00:04:58 +00:00
James Read 32c7fd73b8
Merge commit from fork
security: GHSA-gq2m-77hf-vwgh (MODERATE) Session Fixation: Logout Fails to Invalidate Server-Side Session
2026-03-04 18:36:22 -05:00
jamesread d6a0abc375 security: GHSA-gq2m-77hf-vwgh (MODERATE) Session Fixation: Logout Fails to Invalidate Server-Side Session 2026-03-04 23:31:15 +00:00
jamesread e97d8ecbd8 security: GHSA-g962-2j28-3cg9 (HIGH) JWT Audience Validation Bypass in Local Key and HMAC Modes 2026-03-04 23:13:39 +00:00
jamesread 92a1346edf docs: update security.md with the fix process 2026-03-04 23:12:20 +00:00
jamesread 00cb5a2abf fix: action triggers were broken #914 2026-03-04 23:12:20 +00:00
jamesread 0c47564652 chore: logs are written with 0600 instead of 0644 2026-03-04 23:12:20 +00:00
jamesread bb14c5da3e security: (MED) GHSA-fwhj-785h-43hh Crash on NPE by calling APIs with invalid bindings or log references 2026-03-04 22:51:58 +00:00
James Read 235493e471
Next (#911) 2026-03-02 00:49:13 +00:00
James Read d9aed9d5c5
chore(deps): bump minimatch from 3.1.2 to 3.1.5 in /frontend (#906) 2026-03-01 19:45:05 -05:00
jamesread 87148f05bd chore: Update SECURITY.md 2026-03-02 00:44:49 +00:00
James Read e8e62d22f1
Merge branch 'next' into dependabot/npm_and_yarn/frontend/minimatch-3.1.5 2026-03-01 19:36:51 -05:00
jamesread 0412b9ea1d Merge branch 'next' of github.com:OliveTin/OliveTin into next 2026-03-02 00:35:05 +00:00
jamesread d9804182ea security: GHSA-4fqm-6fmh-82mq Authentication bypass in KillAction - thanks for the responsible disclosure @kule500 and making OliveTin better 2026-03-02 00:29:02 +00:00
James Read 26086576da
feat: Clickable links in outout (#900) (#909) 2026-03-01 19:16:25 -05:00
James Read 58b0a7b8f6
Security remote crash in oauth2 (#910) 2026-03-01 19:14:36 -05:00
jamesread f044d90d55 security: Remote crash in OAuth2 GHSA-45m3-398w-m2m9 Thanks @kule500 for the responsible disclosure. CVE to follow. 2026-03-01 23:52:25 +00:00
James Read a565e1ce4c
chore(deps-dev): bump selenium-webdriver from 4.40.0 to 4.41.0 in /integration-tests (#894) 2026-03-01 18:27:19 -05:00
James Read 159c9d6c4d
chore(deps): bump github.com/bufbuild/buf from 1.65.0 to 1.66.0 in /service (#897) 2026-03-01 18:27:06 -05:00
jamesread 7051aad599 feat: Clickable links in outout (#900) 2026-03-01 23:17:44 +00:00
James Read e67fac17d0
Merge branch 'next' into dependabot/go_modules/service/next/github.com/bufbuild/buf-1.66.0 2026-03-01 17:16:45 -05:00
James Read a8c6366bdd
Merge branch 'next' into dependabot/npm_and_yarn/integration-tests/next/selenium-webdriver-4.41.0 2026-03-01 17:16:37 -05:00
jamesread aa2bd95ccb feat(policy): add policy to show/hide version number
Made-with: Cursor
2026-02-27 21:26:55 +00:00
James Read f41fe2caba
docs: Add autonomy level to README 2026-02-27 11:21:34 +00:00
dependabot[bot] 1c32a389b3
chore(deps): bump minimatch from 3.1.2 to 3.1.5 in /frontend
Bumps [minimatch](https://github.com/isaacs/minimatch) from 3.1.2 to 3.1.5.
- [Changelog](https://github.com/isaacs/minimatch/blob/main/changelog.md)
- [Commits](https://github.com/isaacs/minimatch/compare/v3.1.2...v3.1.5)

---
updated-dependencies:
- dependency-name: minimatch
  dependency-version: 3.1.5
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
2026-02-27 00:25:25 +00:00
James Read 2eb5f0ba79
Next (#905) 2026-02-27 00:24:07 +00:00
jamesread 54eb2a6586 fix: User login log message fixed when password matches, but user lookup fails 2026-02-27 00:10:45 +00:00
jamesread 03da2ff2e7 security: Try to set cookies secure, with force override option 2026-02-26 23:43:50 +00:00
jamesread 4744169aa0 chore: code cleanup, remove todos, etc 2026-02-26 23:07:07 +00:00
jamesread e9a3863b1b chore: codestyle 2026-02-26 20:56:51 +00:00
jamesread f3549b035e Remove dead CORS package (L-2)
The CORS helper was unused; its import was commented out in webuiServer.go.
Deleting the package removes the dormant origin-reflection security issue.
2026-02-26 20:46:11 +00:00
jamesread 4af4d516be fix: ShowDiagnostics now behind policy checks 2026-02-26 20:43:14 +00:00
jamesread 24cced0c8c security: IDOR on ExecutionStatus API 2026-02-26 20:23:48 +00:00
jamesread 5cbcf29704 Merge branch 'next' of github.com:OliveTin/OliveTin into next 2026-02-26 17:42:30 +00:00
jamesread 7717f735aa chore: dep update 2026-02-26 17:42:12 +00:00