-
v0.0.3.2
Fix XSS vulnerability in conversations#new, #4010
-
v0.0.2.5
* Fix CVE-2013-0269 by updating the gems json to 1.7.7 and multi\_json to 1.5.1. [Read more](https://groups.google.com/forum/?fromgroups=#!topic/rubyonrails-security/4_YvCpLzL58) * Additionally ensure can't affect us by bumping Rails to 3.2.12. [Read more](https://groups.google.com/forum/?fromgroups=#!topic/rubyonrails-security/AFBKNY7VSH8) * And exclude CVE-2013-0262 and CVE-2013-0263 by updating rack to 1.4.5.
-
v0.0.2.4
Fix XSS vulnerabilities caused by not escaping a users name fields when loading it from JSON. #3948
-
v0.0.2.3
Update Devise to 0.0.2.3 http://blog.plataformatec.com.br/2013/01/security-announcement-devise-v2-2-3-v2-1-3-v2-0-5-and-v1-5-3-released/
-
v0.0.2.1
Bump to Rails 3.2.10 as per CVE-2012-5664
-
v0.0.1.1
Hotfix French locale
-
pre-asset-pipeline
the last commit before asset-pipeline madness. use this ref for production setups until further notice