BMO/Recent Changes: Difference between revisions

From MozillaWiki
< BMO
Jump to navigation Jump to search
No edit summary
No edit summary
Line 1: Line 1:
= Recent Changes =
= Recent Changes =
== 2026-04-07 ==
[https://github.com/mozilla-bteam/bmo/tree/release-20260407.1 release-20260407.1]
* {{bug|2028704}} [PHAB-BOT] The feed query has a bug where the last feed id is not being updated properly when a single story fails due to database rollback
* {{bug|2029517}} Update CONTRIBUTING.md with current conventions and fix stale links
* {{bug|2029518}} README.rst has stale CircleCI badge, outdated Ubuntu 16.04 section, and old Docker Hub references
* {{bug|2029520}} ReadTheDocs webhook has stopped triggering builds since Feb 17
* {{bug|1934846}} Show both banners if a bug is marked as security sensitive and moco confidential
* {{bug|2029523}} Selenium tests flake with element click intercepted errors in CI


== 2026-03-19 ==
== 2026-03-19 ==
Line 29: Line 39:
* {{bug|2012069}} [HackerOne] unauthenticated blind SQL injection in search feature
* {{bug|2012069}} [HackerOne] unauthenticated blind SQL injection in search feature
* {{bug|1764214}} add a warning that the BMO uplift request flow will soon be deprecated
* {{bug|1764214}} add a warning that the BMO uplift request flow will soon be deprecated
== 2026-01-20 ==
[https://github.com/mozilla-bteam/bmo/tree/release-20260120.1 release-20260120.1]
* {{bug|2009746}} Whine events allow newlines in subject line which can be used to inject email headers
* {{bug|1996136}} Create a new cron script (weekly) that accesses the Recorded Future API and looks for compromised BMO accounts
* {{bug|2007378}} [HackerOne] Path traversal on bugzilla.mozilla.org via improper path canonicalization leads to arbitrary content loading
* {{bug|2009837}} After recent update sitemap extensions is including improperly formatted urls in the sitemap gz files


= Archive =
= Archive =

Revision as of 21:22, 7 April 2026

Recent Changes

2026-04-07

release-20260407.1

  • bug 2028704 [PHAB-BOT] The feed query has a bug where the last feed id is not being updated properly when a single story fails due to database rollback
  • bug 2029517 Update CONTRIBUTING.md with current conventions and fix stale links
  • bug 2029518 README.rst has stale CircleCI badge, outdated Ubuntu 16.04 section, and old Docker Hub references
  • bug 2029520 ReadTheDocs webhook has stopped triggering builds since Feb 17
  • bug 1934846 Show both banners if a bug is marked as security sensitive and moco confidential
  • bug 2029523 Selenium tests flake with element click intercepted errors in CI

2026-03-19

release-20260319.1

  • bug 2003867 reviewer rotation seems to always assign patches to the same reviewers within the group

2026-03-12

release-20260305.2

  • bug 1995468 Support URL pasting in markdown editor
  • bug 2018260 "Fields You Can Search On" is blocking people from making it through quicksearch.html doc
  • bug 2022581 Support Git trailer convention when parsing bug numbers out of commit messages
  • bug 2022370 Support updated uplift request form field names from Lando

2026-03-02

release-20260302.2

  • bug 2017436 Updates for bmo.readthedocs.org to fix a recent issue building the RST docs
  • bug 2016490 Create dedicated group for viewing user group memberships
  • bug 2017743 Errors are occurring intermittently when submitting a new job to the job queue to send email
  • bug 2019859 [HackerOne] IDOR in REST API Reminder Deletion — Any Authenticated User Can Delete Other Users' Reminders
  • bug 2015155 [HackerOne] Faulty Phabricator-Bugzilla integration logic leads to secure revision takeover and bug title disclosure

2026-02-04

release-20260204.1

  • bug 2009883 [HackerOne] [Bugzilla] Account Takeover via Side-Channel Attack
  • bug 2012069 [HackerOne] unauthenticated blind SQL injection in search feature
  • bug 1764214 add a warning that the BMO uplift request flow will soon be deprecated

Archive