| Age | Commit message (Collapse) | Author | Lines |
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
The readme is now escaped plain text unless `about-filter` points at
the new `about-render.lua`, which renders markdown, man pages and plain
text server-side. `enable-markdown` goes away with the renderer.
|
|
|
|
AUTHORS now records the upstream developers as the project's history
rather than as maintainers of the fork.
|
|
The about subpath was confined to the readme directory with a plain
byte-prefix match, so a sibling directory sharing the base name as a
prefix passed the check and its files were served.
|
|
A readme that is not markdown was written to the about page as raw
HTML when no about-filter was configured, so an untrusted repository
could inject script.
|
|
cgit had no markdown support of its own, so a readme was rendered
through an external python filter or not at all. Escaping the source
and formatting it in cgit.js keeps the work in the browser like the
blob highlighter, and the page stays readable as plain text without
scripting.
|
|
The C sources move to source/, the served files to assets/, the bundled
Git submodule to libraries/git and the filter scripts to extensions/.
Everything the build generates now lands in build/, so a clean is a
single remove and the tree stays clean.
|