mealie/frontend
Hayden 13850cda1f
security: multiple reported CVE fixes (#1515)
* update out of date license

* update typing / refactor

* fix arbitrarty path injection

* use markdown sanatizer to prevent XSS CWE-79

* fix CWE-918 SSRF by validating url and mime type

* add security docs

* update recipe-scrapers

* resolve DOS from arbitrary url

* update changelog

* bump version

* add ref to #1506

* add #1511 to changelog

* use requests decoder

* actually fix encoding issue
2022-07-31 13:10:20 -08:00
..
2022-07-26 17:41:33 -08:00
2021-08-08 17:01:45 -08:00
2021-07-31 14:00:28 -08:00
2022-05-29 09:09:36 -08:00
2021-07-31 14:00:28 -08:00