[#8627] use |tojson for user-supplied values in inline JS
[#8627] OAuth consent pages: show where the user will be redirected
[#8627] 404 for deleted subprojects unless the user can manage them
[#8627] hide soft-deleted projects' content from search, feeds, and activity
[#8627] forum email replies: only match posts in the same discussion tool
[#8627] GitHub importer: require saved OAuth state, single-use
[#8627] ForgeFeedback: one review per user per project
[#8627] feeds: skip entries from tools the viewer can no longer read
[#8627] don't let shared caches store files served to logged-in users
[#8627] primary email must be one of the user's confirmed addresses
[#8627] ForgeFiles: hide delete activities from users without read
[#8627] check viewer's access for "Related" artifacts on posts
[#8627] password reset: prefer the confirmed owner of an email address
[#8627] require ip_address_header for /auth/repo_permissions
[#8627] require read on the upstream repo to request a merge
[#8627] no API tokens for disabled or pending users
[#8627] SVN: keep path lookups inside the repo
bump python-discovery 1.4.4 -> 1.6.1
bumping virtualenv 21.6.1 -> 21.14.2
docker-compose: try giving solr a longer start period to get healthy (has been unhealthy in CI sometimes)
bumping urllib3 2.7.0 -> 2.8.0
bumping oauthlib 3.3.1 -> 4.0.0
Log raw email headers and SPF/DMARC/DKIM verification results for monitor mode
fix partialFilterExpression: can't do $gt a different type. NEEDS INDEX DROP AND RECREATE
rename CLAUDE.md => AGENTS.md
[#8626] Log raw email headers and SPF/DMARC/DKIM verification results for monitor mode
[#8625] Implemented full field level encryption for audit log messages
[#8625] Add event types for audit log records and backfill script
[#8625] Add encrypted field for audit log messages
[#8624] edit support for OAuth1 and OAuth2 apps
[#8624] validate OAuth1 callback URIs
[#8624] update SECURITY.md and post-install instructions
[#8624] deprecate ForgeChat
[#8624] ForgeFiles: scope the breadcrumb folder lookup to the current tool
[#8624] ForgeUserStats: skip projects the viewer cannot read
[#8624] bound the pagination offset
[#8624] sync content rate limiting in REST API with webpage limiting
[#8624] record OAuth1 nonces instead of accepting any
[#8624] validate the solr sort parameter
[#8624] validate search filter field names
[#8624] apply the moderation status check to post permalinks
[#8624] remove Feed entries when content is deleted or restricted
[#8624] ForgeBlog: restrict fields accepted by the REST create endpoint
[#8624] mark tests that need network, and a --no-network flag to skip them
bumping soupsieve 2.8.4 -> 2.9.2
fix git thread-safety issues
fixup! [#8624] mark tests that need network, and a --no-network flag to skip them
fixup! [#8624] remove Feed entries when content is deleted or restricted
[#8626] Log raw email headers and SPF/DMARC/DKIM verification results for monitor mode
[#8623] bound the easywidgets resource cache and cap _slim requests
[#8623] keep inline script/style bodies raw under easywidgets autoescaping
security fixes: turn on autoescaping for widgets, fix tracker select XSS
Log raw email headers and SPF/DMARC/DKIM verification results for monitor mode
[#8618] optimze the way to read the raw stream and a small change since now the content is bytes
[#8618] harden rev_parse() against git's relative-ref syntax
[#8618] read git blob content via a one-off subprocess, not the shared cat-file pipe
[#8624] edit support for OAuth1 and OAuth2 apps
[#8624] validate OAuth1 callback URIs
[#8624] update SECURITY.md and post-install instructions
[#8624] deprecate ForgeChat
[#8624] ForgeFiles: scope the breadcrumb folder lookup to the current tool
[#8624] ForgeUserStats: skip projects the viewer cannot read
[#8624] bound the pagination offset
[#8624] sync content rate limiting in REST API with webpage limiting
[#8624] record OAuth1 nonces instead of accepting any
[#8624] validate the solr sort parameter
[#8624] validate search filter field names
[#8624] apply the moderation status check to post permalinks
[#8624] remove Feed entries when content is deleted or restricted
[#8624] ForgeBlog: restrict fields accepted by the REST create endpoint
[#8624] mark tests that need network, and a --no-network flag to skip them
fixup! [#8623] bound the easywidgets resource cache and cap _slim requests
bumping gitpython 3.1.59 -> 3.1.62
Implement field level encryption for audit log
error handling around "magic" lib
[#8623] bound the easywidgets resource cache and cap _slim requests
[#8623] keep inline script/style bodies raw under easywidgets autoescaping
security fixes: turn on autoescaping for widgets, fix tracker select XSS
XSS security fix
security fixes: turn on autoescaping for widgets, fix tracker select XSS
[#8619] test for text_contains_hostname substring bypass
[#8619] test for class/id sanitization on void elements
[#8619] test for iframe body mXSS via math/svg reparse
[#8619] test for SVG blocked, MathML allowed
[#8619] test for iframe followed by script
[#8621] test for FTP redirect bypassing internal-host protection
Implement field level encryption for User tool data fields
fix git thread-safety issues
fix on db/8618-cat-file Ended up being re-use after streaming, in same thread, not different threads
[#8618] harden rev_parse() against git's relative-ref syntax
[#8618] read git blob content via a one-off subprocess, not the shared cat-file pipe
[#8617] Cover encrypted-only tool data reads and cleanup
[#8617] Update User's set_tool_data to store encrypted tool data values
add to SECURITY.md