COMMITS
May 26, 2026
K
Merge pull request #332 from rhmsd/rhmsd/MSRC112143
kangyu committed
R
Replace xml.etree.ElementTree with defusedxml.ElementTree for enhanced security; add defusedxml to requirements.
Ray Huang (from Dev Box) committed
May 15, 2026
R
Merge commit from fork
rhmsd committed
R
Implement session ownership checks to prevent cross-client session reuse
Ray Huang (from Dev Box) committed
R
Merge commit from fork
rhmsd committed
R
Enhance task response handling to prevent cross-device task-result injection
Ray Huang (from Dev Box) committed
May 14, 2026
R
Merge commit from fork
rhmsd committed
R
Add WebSocket connection context to prevent cross-client response hijacking
Ray Huang (from Dev Box) committed
R
Merge commit from fork
rhmsd committed
R
Add regression tests for WebSocket role/identity spoofing hardening and enhance client registration error handling
Ray Huang (from Dev Box) committed
May 13, 2026
K
Merge pull request #330 from rhmsd/rhmsd/GHSA-whcg-fgpx-76f2
kangyu committed
R
Implement task name sanitization and validation to prevent path traversal vulnerabilities
Ray Huang (from Dev Box) committed
May 9, 2026
K
Merge pull request #329 from rhmsd/rhmsd/MSRC114224
kangyu committed
K
Merge pull request #328 from rhmsd/rhmsd/MSRC114053
kangyu committed
May 8, 2026
R
R
Add unit tests for shell command security hardening and enhance path validation
Ray Huang (from Dev Box) committed
April 29, 2026
K
Merge pull request #321 from rhmsd/rhmsd/MSRC114052
kangyu committed
R
Merge branch 'main' of https://github.com/rhmsd/UFO into rhmsd/MSRC114052
Ray Huang (from Dev Box) committed
K
Merge pull request #322 from rhmsd/rhmsd/MSRC114156
kangyu committed
R
R
Add authentication router and enhance path validation for security
Ray Huang (from Dev Box) committed
April 14, 2026
K
Merge pull request #307 from rhmsd/rhmsd/MSRC576143
kangyu committed
R
Enhance documentation for Galaxy WebUI and batch mode; add API key authentication details and security considerations
Ray Huang (from Dev Box) committed
April 3, 2026
K
Merge pull request #301 from rhmsd/rhmsd/MSRC572151
kangyu committed
K
Merge pull request #300 from rhmsd/rhmsd/MSRC563005
kangyu committed
R
Merge branch 'main' into rhmsd/MSRC563005
rhmsd committed
R
Merge branch 'main' into rhmsd/MSRC572151
rhmsd committed
K
Merge pull request #299 from rhmsd/rayhuang/MSRC571925
kangyu committed
R
fix: Update CommandLineExecutor documentation to clarify application launching without shell and adjust example commands
Ray Huang (from Dev Box) committed
April 2, 2026
R
fix: Enhance CORS configuration and improve application process termination logic
Ray Huang (from Dev Box) committed