-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Sorry for this, but it seems I inadvertantly broke creating new projects
with yesterday's 2.4.8 release. I have deployed a fix on gitorious.org,
and just tagged 2.4.9.

We made some sweeping changes yesterday, by changing attr_protected
(which was the recent target of a Rails vulnerability) to
attr_accessible - basically changing from black-listing to white-listing
in what parameters can be posted to Gitorious and set on DB-backed
models. It seems that one case was not covered by automatic tests, and
was not discovered immediately.

Sorry for the inconvenience.

On behalf of the Gitorious team,
Christian
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.13 (GNU/Linux)

iQEcBAEBAgAGBQJRG5ucAAoJEKwDTN/JAKQJj3wH/1FXk04vLQwwiexiBwEt0LYE
/9N24XSoV1teQ0m8ulk6dPKKeb+6lYnAs5rCI8WJXP+7RKplMKVbcxNfbA3AUkZw
S2b2Zg1zRFmGbnSYvqzI6uzR0HID3gwgUcnTNn8r002gGT/CwTM2k+iiSsDUrsQ/
2DAaI1laZe9nfHDbbk20stgpsnSfmJWLRJ6dnMplqfppRUwuSAXgZaQuPg1RG6aK
jpYffZTAATudvFUcmfhgmEimYk1GFf5nmk9O5Cqa+H2DuqmAkxXHFKqhXY/7FOT3
OZHUCgFaTKz1UuqBScrc9qTPyYWTMPD4WrbL99U5iQO66pGSiSMhYNosTMOWpK0=
=tfa5
-----END PGP SIGNATURE-----

-- 
-- 
To post to this group, send email to gitorious@googlegroups.com
To unsubscribe from this group, send email to
gitorious+unsubscr...@googlegroups.com

--- 
You received this message because you are subscribed to the Google Groups 
"Gitorious" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to gitorious+unsubscr...@googlegroups.com.
For more options, visit https://groups.google.com/groups/opt_out.


Reply via email to