Signed-off-by: Junio C Hamano <gitster@pobox.com>
--- /dev/null
--- /dev/null
++Git v1.7.0.9 Release Notes
++==========================
++
++Fixes since v1.7.0.8
++--------------------
++
++ * "gitweb" can sometimes be tricked into parrotting a filename argument
++ given in a request without properly quoting.
#!/bin/sh
GVF=GIT-VERSION-FILE
- DEF_VER=v1.7.0.8
-DEF_VER=v1.6.6.3
++DEF_VER=v1.7.0.9
LF='
'
- Documentation/RelNotes/1.7.0.8.txt
-Documentation/RelNotes/1.6.6.3.txt
++Documentation/RelNotes/1.7.0.9.txt
insert_file($site_footer);
}
- print qq!<script type="text/javascript" src="$javascript"></script>\n!;
+ print qq!<script type="text/javascript" src="!.esc_url($javascript).qq!"></script>\n!;
- if ($action eq 'blame_incremental') {
+ if (defined $action &&
+ $action eq 'blame_incremental') {
print qq!<script type="text/javascript">\n!.
qq!startBlame("!. href(action=>"blame_data", -replay=>1) .qq!",\n!.
qq! "!. href() .qq!");\n!.