aboutsummaryrefslogtreecommitdiff
path: root/VERSION
AgeCommit message (Collapse)AuthorFilesLines
2025-04-10v1.16.0 (#244)v1.16.0Xe Iaso1-1/+1
* v1.16.0 Signed-off-by: Xe Iaso <me@xeiaso.net> * update packaging docs Signed-off-by: Xe Iaso <me@xeiaso.net> --------- Signed-off-by: Xe Iaso <me@xeiaso.net>
2025-03-31lib/anubis: actually check the result with the correct difficulty (#180)Henri Vasserman1-1/+1
* cmd/anubis actually check the result with the correct difficulty * chore: changelog * test(cmd/anubis): make test check for difficulty * lib: add regression test for CVE-2025-24369 Signed-off-by: Xe Iaso <me@xeiaso.net> * bump VERSION and CHANGELOG Tracks #181 Signed-off-by: Xe Iaso <me@xeiaso.net> --------- Signed-off-by: Xe Iaso <me@xeiaso.net> Co-authored-by: Xe Iaso <me@xeiaso.net>
2025-03-27version 1.15.0 (#144)v1.15.0Xe Iaso1-1/+1
Signed-off-by: Xe Iaso <me@xeiaso.net>
2025-03-21cmd/anubis: delete example RSS reader rule (#67)v1.14.2Xe Iaso1-1/+1
The example/default bot policy document had a rule to allow RSS readers through based on paths that end with ".rss", ".xml", ".atom", or ".json". Frameworks like Rails will treat these specially, meaning that going to /things/12345-whateverhaha.json could bypass Anubis. I checked the history of this rule and it was present in the original example policy file in Xe/x. This rule is likely a mistake and it has been removed. I think it was for making my blog still work with RSS readers. Thanks to Graham Sutherland for reporting this over email. Signed-off-by: Xe Iaso <me@xeiaso.net>
2025-03-21cmd/anubis: set X-Real-Ip based on X-Forwarded-For (#63)v1.14.1Xe Iaso1-1/+1
This triggers a SHAME release[0]. [0]: https://pridever.org/
2025-03-21stage v1.14.0 (#59)v1.14.0Xe Iaso1-1/+1
Signed-off-by: Xe Iaso <me@xeiaso.net>
2025-03-20v1.13.0v1.13.0Xe Iaso1-1/+1
Signed-off-by: Xe Iaso <me@xeiaso.net>
2025-03-19version 1.12.1v1.12.1Xe Iaso1-0/+1
Signed-off-by: Xe Iaso <me@xeiaso.net>