diff --git a/CHANGELOG.md b/CHANGELOG.md index a6d8bf4b..0ebd1ba8 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -4,6 +4,12 @@ All notable changes to this project will be documented in this file. The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html). +## [0.1.3] - 2021-07-28 +### Fixed +- Prevent sending empty file name and zero bytes +- Prevent path traversal on upload directory ([#2](https://github.com/orhun/rustypaste/issues/2)) +- Check the content length while reading bytes for preventing OOM ([#1](https://github.com/orhun/rustypaste/issues/1)) + ## [0.1.2] - 2021-07-27 ### Changed - Update Continuous Deployment workflow to publish Docker images diff --git a/Cargo.lock b/Cargo.lock index 6bd61064..7236f6d4 100644 --- a/Cargo.lock +++ b/Cargo.lock @@ -1507,7 +1507,7 @@ dependencies = [ [[package]] name = "rustypaste" -version = "0.1.2" +version = "0.1.3" dependencies = [ "actix-files", "actix-multipart", diff --git a/Cargo.toml b/Cargo.toml index f04f2486..c244ff55 100644 --- a/Cargo.toml +++ b/Cargo.toml @@ -1,6 +1,6 @@ [package] name = "rustypaste" -version = "0.1.2" +version = "0.1.3" edition = "2018" description = "A minimal file upload/pastebin service" authors = ["Orhun Parmaksız "]