On 07/19/2016 05:30 PM, Matthew Flaschen wrote:
Two security issues related to topic title visibility and log entry hiding were fixed in Flow:
If you are using master, please pull.
Patches are coming for release branches (see follow ups to this thread).
Patches for both supported release branches (REL1_26 and REL1_27) are merged as well, so you should pull for them too: * https://gerrit.wikimedia.org/r/#/c/299882/ * https://gerrit.wikimedia.org/r/#/c/299883/ * https://gerrit.wikimedia.org/r/#/c/299884/ * https://gerrit.wikimedia.org/r/#/c/299885/
Note that these are the only supported release branches for Flow (other than current WMF deployment release branches).
Flow was previously marked as supporting 1.24+. We no longer support 1.24 or 1.25 (Core also does not; see https://www.mediawiki.org/wiki/Version_lifecycle#Versions_and_their_end-of-l...).
If you are using 1.24 or 1.25, you should upgrade as soon as possible.
Matt