ChiliProject 2.8.0 released: Important Security Update!

ChiliProject 2.8.0 has just been released. This release is a security release to fix a severe security issue of Rails (CVE-2013-0156) which allows attackers to inject and execute arbitrary code on the server hosting ChiliProject. This bug was fixed in Rails 2.3.15, which is included in this release of ChiliProject. This release contains no other bug fixes or new features [...]

Read full story Comments { 1 }

ChiliProject 2.7.4 released

ChiliProject 2.7.4 has just been released. This release is a security release to fix two XSS vulnerabilities (CVE-2012-3464, CVE-2012-3465) and a SQL injection vulnerability (CVE-2012-5664) of Rails. All these bugs were fixed in Rails, we have included the fixes from Rails or backported them to the version of Rails ChiliProject uses right now. This release contains no [...]

Read full story Comments { 0 }

ChiliProject 3.4.0 released

ChiliProject 3.4.0 has just been released. It includes lots of bug fixes for ChiliProject 3.3.0 as well as 3 security fixes. It is suitable for use on production websites and we highly recommend that all users download the release as soon as possible. Download ChiliProject 3.4.0 What’s included 3.4.0 includes 3 security fixes for Rails [...]

Read full story Comments { 1 }

Going forward: get involved!

After the dry spell we went through in the last few months, the ChiliProject Team wants to get things going again. We still want to get more people involved in ChiliProject and are looking for ways for the Team to communicate outwards but also for the Community as a whole to better communicate. We’re also [...]

Read full story Comments { 1 }

Retrospective

So the last 6 months happened. Many of you rightly noted that ChiliProject development halted to near nothingness in that time and Holger and I are not only very sorry but also feel guilty about that (anyone who wants to know why one can feel guilty about a voluntary contribution, go read the excellent article [...]

Read full story Comments { 7 }

Team changes

We’re always looking for people helping us to make ChiliProject better and we are lucky to have some great contributors investing their free time to fix bugs and generally improve ChiliProject. In the last couple of weeks, one contributor stood out in particular as he has been steadily submitting improvements to the user interface part [...]

Read full story Comments { 2 }

ChiliProject 3.3.0 released

ChiliProject 3.3.0 has just been released. It includes some new features and bugfixes for ChiliProject 3.2.2. It is suitable for use on production websites and we recommend that all users download the release as soon as possible. Download ChiliProject 3.3.0 What’s included 3.3.0 includes 12 bug fixes and 8 features for 3.2.2 and fixes 1 regression [...]

Read full story Comments { 3 }

ChiliProject 3.2.2 released

ChiliProject 3.2.2 has just been released. This release is a security release to fix two security issues of Rails (CVE-2012-2694 and CVE-2012-2695) which allowe attackers to inject certain forms of SQL into the database queries generated by ChiliProject. The bugs were fixed in Rails 3.2.6. We have backported them to the version of Rails we [...]

Read full story Comments { 2 }

ChiliProject 2.7.3 released

ChiliProject 2.7.3 has just been released. This release is a security release to fix two security issues of Rails (CVE-2012-2694 and CVE-2012-2695) which allowe attackers to inject certain forms of SQL into the database queries generated by ChiliProject. The bugs were fixed in Rails 3.2.6. We have backported them to the version of Rails we [...]

Read full story Comments { 0 }

ChiliProject 3.2.1 released

A regression has made its way into ChiliProject 3.2.0 causing avatars to always be displayed at the default 80×80 pixel size rather than the sizes defined in the views. ChiliProject 3.2.1 has been released to fix this regression. This update is fully compatible with and recommended for all users of ChiliProject 3.2.0. Many thanks to [...]

Read full story Comments { 0 }