-
-
-
-
-
-
-
v0.0.2.5f2ce9fa1 · ·
* Fix CVE-2013-0269 by updating the gems json to 1.7.7 and multi\_json to 1.5.1. [Read more](https://groups.google.com/forum/?fromgroups=#!topic/rubyonrails-security/4_YvCpLzL58) * Additionally ensure can't affect us by bumping Rails to 3.2.12. [Read more](https://groups.google.com/forum/?fromgroups=#!topic/rubyonrails-security/AFBKNY7VSH8) * And exclude CVE-2013-0262 and CVE-2013-0263 by updating rack to 1.4.5.
-
v0.0.2.47134513b · ·
Fix XSS vulnerabilities caused by not escaping a users name fields when loading it from JSON. #3948
-
v0.0.2.38a8ee42e · ·
Update Devise to 0.0.2.3 http://blog.plataformatec.com.br/2013/01/security-announcement-devise-v2-2-3-v2-1-3-v2-0-5-and-v1-5-3-released/
-
-
-
-
-
-
-
-
pre-asset-pipeline0e4f9ae9 · ·
the last commit before asset-pipeline madness. use this ref for production setups until further notice
-
-
-