24998 Commits (d3e526058f4d6e25fbca9d450be0d01f96bb2c91)
 

Author SHA1 Message Date
Volodymyr Babak d3e526058f Code review changes 4 weeks ago
Volodymyr Babak 4c88676321 defer SNMP polling until transport session is fully registered 2 months ago
Viacheslav Klimov 2a7eab3db5
Version set to 4.2.2.2-SNAPSHOT 2 months ago
Viacheslav Klimov d805fa96e9
Merge pull request #15322 from vvlladd28/fix/vulnerability/30-03-26 2 months ago
Vladyslav_Prykhodko d5d86dcce5 Fixed CVE-2026-33671 2 months ago
Vladyslav_Prykhodko e24f0cbaa5 Fixed CVE-2026-4923 2 months ago
Vladyslav_Prykhodko 0f6eab38fa Fixed CVE-2026-33750 2 months ago
Vladyslav_Prykhodko 479141141e Fixed CVE-2026-33895, CVE-2026-33894, CVE-2026-33896 2 months ago
Viacheslav Klimov 28424b0d23
Merge pull request #15315 from thingsboard/fix/cves 2 months ago
Viacheslav Klimov f0cfd83f2c
Bump netty-bom from 4.1.131.Final to 4.1.132.Final to fix CVE-2026-33870 and CVE-2026-33871 2 months ago
Viacheslav Klimov 0465d96e1a
Bump jackson-bom from 2.19.4 to 2.21.1 to fix GHSA-72hv-8253-57qq 2 months ago
Viacheslav Klimov 71233b4ab5
Update build.sh to skip packaging 2 months ago
Viacheslav Klimov 0cf75a5b72
Merge pull request #15139 from smatvienko-tb/improvement/per-format-packaging-skip-flags 2 months ago
Sergey Matvienko 7bb708888f Address review: fix pkg.skip.bootjar precedence and remove unused surefire.version 2 months ago
Sergey Matvienko d4bc299833 Fix black-box-tests docker-info dependency resolution 2 months ago
Sergey Matvienko ac96b4035b Replace Spotify dockerfile-maven-plugin with exec-maven-plugin 2 months ago
Sergey Matvienko d2cde5ba94 Add per-format packaging skip flags (pkg.skip.bootjar/deb/rpm/zip) 3 months ago
Vladyslav Prykhodko 411b600183
Merge pull request #15273 from vvlladd28/fix/string-items-list-autocomplete 2 months ago
Vladyslav Prykhodko 00e35f745e Fix proxy error handling for 502/503/504 HTTP status codes 2 months ago
Vladyslav Prykhodko 46ef7c51a0 Fixed CVE-2026-33228 2 months ago
Viacheslav Klimov 665887c517
Merge pull request #15278 from thingsboard/fix/cves 2 months ago
Viacheslav Klimov 0b72297916
Restore lombok.version property required by maven-compiler-plugin annotationProcessorPaths 2 months ago
Viacheslav Klimov 9dcb6d53bf
Update lombok from 1.18.38 to 1.18.44 managed by Spring Boot 3.5.12 2 months ago
Viacheslav Klimov caffeb7ce8
Update jedis from 5.1.5 to 6.0.0 and snakeyaml from 2.2 to 2.4 for Spring Boot 3.5.12 compatibility 2 months ago
Viacheslav Klimov 7646f79cfe
Implement addBundleRegisterHandler for Spring Boot 3.5 SslBundles compatibility 2 months ago
Viacheslav Klimov 0eabe6ce46
Fix CVE-2026-22731, CVE-2026-22732, CVE-2026-22733, CVE-2026-22737 2 months ago
Vladyslav_Prykhodko 93bc81e5b8 UI: Use explicit null check in onOptionSelected to handle falsy values 2 months ago
Vladyslav_Prykhodko 66d263f81b UI: Fix string-items-list autocomplete selection and blur handling 2 months ago
Vladyslav_Prykhodko 95d2e77c82 UI: Fixed yarn.lock 2 months ago
Viacheslav Klimov c2ff92772e
Merge pull request #15266 from thingsboard/fix-csp-example 2 months ago
Viacheslav Klimov 02529029c5
Update default CSP value covering core ThingsBoard functionality 2 months ago
Viacheslav Klimov 628fe04032
Make SsrfProtectionValidator-dependent tests more stable 2 months ago
Viacheslav Klimov de0c2850f7
Fix CSP example value to include img-src and font-src directives 2 months ago
Maksym Tsymbarov 061b997457 Fixed resetting of validation on storeLink property 3 months ago
Viacheslav Klimov 5f93a5a0a2
Merge pull request #15262 from thingsboard/fix/verbose-error-messages 2 months ago
Viacheslav Klimov 688a1d52b3
Sanitize database error messages 2 months ago
Viacheslav Klimov 4f7e232ee7
Merge pull request #15251 from vvlladd28/fix/vulnerability/16-03-26 3 months ago
Viacheslav Klimov 2a3ac2972b
Merge pull request #15219 from vvlladd28/fix/ws-reconnect-backoff-rate-limit 3 months ago
Viacheslav Klimov 5f56345722
Merge pull request #15253 from thingsboard/fix/ssrf 3 months ago
Viacheslav Klimov d83a28beaa
Optimize SsrfSafeAddressResolverGroup, remove dead isEnabled checks 3 months ago
Viacheslav Klimov 959a1a84a4
Make SSRF resolver conditional, sanitize error messages, improve test coverage 3 months ago
Viacheslav Klimov 3747553527
Improve SSRF validator test coverage 3 months ago
Viacheslav Klimov 5d7bfe4ee1
Merge pull request #15254 from thingsboard/fix/cors 3 months ago
Viacheslav Klimov 61bccb005a
Restore runtime SSRF validation in CustomOAuth2ClientMapper 3 months ago
Viacheslav Klimov 014c612bf1
Fix boolean/string comparison for env var overrides in web-ui security headers 3 months ago
Viacheslav Klimov 493140f1b2
Remove dead else branch in web-ui security headers config 3 months ago
Viacheslav Klimov c1dd327b47
Add description comments for security headers properties in thingsboard.yml 3 months ago
Viacheslav Klimov 3a765209ff
Address PR review comments 3 months ago
Viacheslav Klimov 2f39347dd2
Address PR review comments 3 months ago
Viacheslav Klimov 07af263997
Add configurable security headers and env-var-backed CORS configuration 3 months ago