<?xml version="1.0"?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" version="2.0">
  <channel>
    <title>Transition Technology: Ticket Query</title>
    <link>http://localhost:8080/trac/query?status=assigned&amp;status=new&amp;status=accepted&amp;status=reopened&amp;component=Mediawiki&amp;milestone=Maintenance&amp;group=status&amp;desc=1&amp;order=type</link>
    <description>Support and issues tracking for the Transition Network Web Project.</description>
    <language>en-US</language>
    <image>
      <title>Transition Technology</title>
      <url>/trac/chrome/site/TransitionNetwork-Logo-Web-Small.jpg</url>
      <link>http://localhost:8080/trac/query?status=assigned&amp;status=new&amp;status=accepted&amp;status=reopened&amp;component=Mediawiki&amp;milestone=Maintenance&amp;group=status&amp;desc=1&amp;order=type</link>
    </image>
    <generator>Trac 0.12.5</generator>
    <item>
        <link>http://localhost:8080/trac/ticket/879</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/879</guid>
        <title>#879: MediaWiki 1.23.11</title>
        <pubDate>Fri, 16 Oct 2015 08:42:45 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Email on &lt;a class="ext-link" href="https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-October/000180.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;the announcements list&lt;/a&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;Tomorrow we will be issuing a security release to all supported
branches of MediaWiki.
The new releases will be:
1.25.3
1.24.4
1.23.11
Fixes will be available in these respective release branches, the
unreleased 1.26.x branch, and master. Tarballs will be available
for the above mentioned point releases as well.
This security release will encompass core only, no bundled extensions
are affected.
&lt;/pre&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/879#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/892</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/892</guid>
        <title>#892: MediWiki Security Release: 1.26.1, 1.25.4, 1.24.5 and 1.23.12</title>
        <pubDate>Fri, 18 Dec 2015 10:46:18 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
Email to the &lt;a class="ext-link" href="https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-December/000186.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;announcements list&lt;/a&gt;:
&lt;/p&gt;
&lt;pre class="wiki"&gt;I would like to announce the release of MediaWiki 1.26.1, 1.25.4, 1.24.5,
and
1.23.12.
These releases fix five security issues in core, in addition to other bug
fixes. Download links are given at the end of this email
== Security fixes ==
(T117899) SECURITY: $wgArticlePath can no longer be set to relative paths
that
do not begin with a slash. This enabled trivial XSS attacks. Configuration
values such as "http://my.wiki.com/wiki/$1" are fine, as are "/wiki/$1". A
value such as "$1" or "wiki/$1" is not and will now throw an error
(T119309) SECURITY: Use hash_compare() for edit token comparison
(T118032) SECURITY: Don't allow cURL to interpret POST parameters starting
with
'@' as file uploads
(T115522) SECURITY: Passwords generated by User::randomPassword() can no
longer
be shorter than $wgMinimalPasswordLength
(T97897) SECURITY: Improve IP parsing and trimming. Previous behavior could
result in improper blocks being issued
(T109724) SECURITY: Special:MyPage, Special:MyTalk, Special:MyContributions
and
related pages no longer use HTTP redirects and are now redirected by
MediaWiki
== Note about EOL of 1.24.x ==
Please note that 1.24.5 marks the end of support for the 1.24.x series of
releases. Technically this ended a few weeks ago with the release of 1.26.0
but
we dropped one final release of 1.24.x here to give it a nicer send off for
those who have not yet upgraded.
== Release notes ==
Full release notes for 1.26.1:
&amp;lt;https://www.mediawiki.org/wiki/Release_notes/1.26&amp;gt;
Full release notes for 1.25.4:
&amp;lt;https://www.mediawiki.org/wiki/Release_notes/1.25&amp;gt;
Full release notes for 1.24.5:
&amp;lt;https://www.mediawiki.org/wiki/Release_notes/1.24&amp;gt;
Full release notes for 1.23.12:
&amp;lt;https://www.mediawiki.org/wiki/Release_notes/1.23&amp;gt;
For information about how to upgrade, see
&amp;lt;https://www.mediawiki.org/wiki/Manual:Upgrading&amp;gt;
&lt;/pre&gt;</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/892#changelog</comments>
    </item><item>
        <link>http://localhost:8080/trac/ticket/870</link>
        <guid isPermaLink="false">http://localhost:8080/trac/ticket/870</guid>
        <title>#870: MediaWiki 1.23.10</title>
        <pubDate>Mon, 24 Aug 2015 12:18:48 GMT</pubDate>
        
        <dc:creator>chris</dc:creator>

        <description>&lt;p&gt;
The &lt;a class="ext-link" href="https://https://lists.wikimedia.org/pipermail/mediawiki-announce/2015-August/000179.html"&gt;&lt;span class="icon"&gt;​&lt;/span&gt;announcement&lt;/a&gt; contains:
&lt;/p&gt;
&lt;blockquote class="citation"&gt;
&lt;h2 id="BugFixesin1.23.10"&gt;Bug Fixes in 1.23.10&lt;/h2&gt;
&lt;ul&gt;&lt;li&gt;(bug 67644) Make AutoLoaderTest handle namespaces
&lt;/li&gt;&lt;li&gt;(T91653) Minimal PSR-3 debug logger to support backports from 1.25+.
&lt;/li&gt;&lt;li&gt;(T102562) Fix InstantCommons parameters to handle the new HTTPS-only policy of Wikimedia Commons.
&lt;/li&gt;&lt;/ul&gt;&lt;/blockquote&gt;
</description>
        <category>Results</category>
        <comments>http://localhost:8080/trac/ticket/870#changelog</comments>
    </item>
 </channel>
</rss>