There are some remaining non-security bugs with this that I'll follow up on in T13682. I believe the security side of this is now resolved.
- Queries
- All Stories
- Search
- Advanced Search
- Transactions
- Transaction Logs
Advanced Search
Oct 26 2022
The details of this attack will be disclosed at a later date, once installs have had some sort of plausible chance to upgrade.
May 27 2022
Dec 16 2021
See also T13588.
Dec 2 2021
Purely venting, but the advanced version of "click here to schedule a mysterious meeting" is to outright lie -- pretending that you deeply respect the recipient's achievements -- before asking them to schedule a mysterious meeting.
Aug 19 2021
Apr 26 2021
Apr 25 2021
Mar 12 2021
I think lint could reasonably emit two warnings about this:
Oct 19 2020
Aug 5 2020
Jul 27 2020
Jul 22 2020
Please use Discourse to discuss Phabricator.
This task references more details on "Excuses" and "Prompts", but there isn't any. Is there any way to provide context around lint issues?
Jul 21 2020
Jul 3 2020
Jun 9 2020
Jun 8 2020
Jun 7 2020
Jun 4 2020
Jun 2 2020
May 30 2020
Feb 24 2020
See also PHI1605 (internal), which provides some evidence that:
Feb 21 2020
Feb 15 2020
Jan 14 2020
In jira 8.6.1 settings are now in:
- Administration → Applications → Application links
Aug 28 2019
Another variation of this is "add more documentation", although I think the pattern around this one is more rarely a sort of "problem domain / solution domain mismatch" sort of issue and more often a "human communication" issue, usually with one of these two templates:
Aug 15 2019
May 16 2019
For all who might need to migrate from trac to Phabricator, feel free to borrow from this bare-bone script: https://gitlab.com/simevo/trac2phab
May 3 2019
The answer here is now pretty unambiguously "Use Webhooks". feed.http-hooks is formally deprecated, Herald remains a terrible idea, and anyone brave enough to touch Doorkeeper can probably figure things out for themselves.
Apr 23 2019
(This seems stable now, and there's no specific action here.)
Mar 27 2019
Mar 19 2019
This seems to have quieted down, now.
Mar 13 2019
See PHI1125. Recent versions of JIRA (JIRA 8?) still work with approximately the same instructions, but you have to fill out a modal dialog with about 7 required fields first, and none of the fields have real values. That is, the configuration instructions for recent JIRA are:
Feb 22 2019
This change broke the search dialog on tags typeaheads...
Feb 16 2019
Feb 12 2019
Feb 11 2019
Jan 25 2019
Jan 24 2019
Not exactly related, but PEAR got compromised: https://news.ycombinator.com/item?id=18987518
Dec 19 2018
(Please use Discourse for this sort of discussion.)
It's been several year's since this task has been opened up, and it's not clear what the current progress on this. Is there a way that versioning please be added to GitHub, per the recommendations on https://github.com/Homebrew/homebrew-php/pull/3864 ? I'm not able to install arcanist currently using homebrew because there isn't a stable tagged version newer than one from 2012.
Dec 17 2018
This appears to be stable and working properly. D19897 removes a straggling guardrail.
Dec 13 2018
Dec 12 2018
There are probably some stragglers that have yet to turn up, but we appear to have survived this largely unscathed.
Nov 27 2018
Are colons (:) supported between the keywords and the objects? E.g. Fixes: adcbdef or Depends On: D123?
Nov 25 2018
Nov 17 2018
Nov 15 2018
Nov 13 2018
I'm going to start landing this stuff now. master will start complaining about unsafe queries all over the place (although much less frequently than it was when I first added the warning). Depending on how much complaining still exists on Friday I might make the warning developer-only, but I'm currently hopeful that I can clean up most of it before the next release promotes.