From 3a00e194d2dcda520e1aaf00180921a15a7cf483 Mon Sep 17 00:00:00 2001 From: Bryce Kwon Date: Thu, 1 Oct 2026 20:54:22 -1000 Subject: Keep the version numbers off the pages The generator meta, the footer and the patch signature named the exact cgit and git versions on every response, which only helps someone matching a site against an advisory. The shipped server configs already hide the server's own version for the same reason, and `cgit --version` still answers on the host. --- source/ui-patch.c | 2 +- source/ui-shared.c | 10 +++------- 2 files changed, 4 insertions(+), 8 deletions(-) (limited to 'source') diff --git a/source/ui-patch.c b/source/ui-patch.c index 1dcdfbe..2c595ca 100644 --- a/source/ui-patch.c +++ b/source/ui-patch.c @@ -131,6 +131,6 @@ void cgit_print_patch(const char *new_rev, const char *old_rev, const char *pref // Two dashes and a space is the mail signature separator, so // git am and mail readers drop the version note below rather // than carrying it into the commit message. - printf("-- \ncgit %s\n\n", cgit_version); + printf("-- \ncgit\n\n"); } } diff --git a/source/ui-shared.c b/source/ui-shared.c index 2c4db2c..c23e2e1 100644 --- a/source/ui-shared.c +++ b/source/ui-shared.c @@ -1529,7 +1529,7 @@ void cgit_print_docstart(void) html_attr(ctx.cfg.root_desc); html("'>\n"); } - htmlf("\n", cgit_version); + html("\n"); if (ctx.cfg.robots && *ctx.cfg.robots) { html("generated by " - "cgit %s " - "(git %s)\n", - cgit_version, git_version_string); - } + else + html("\n"); html("\n"); html("\n\n"); } -- cgit v2.8.0