Brion Vibber | 3 Dec 11:00 2004
Picon

New MediaWiki-announce list


Since discussion & setup help traffic on MediaWiki-l has gotten heavier 
than I'd originally expected, I've set up a low traffic 
announcements-only list for those who want to be notified of updates 
without cluttering their inboxes.

MediaWiki-announce will receive only notifications of new releases and 
important security & bug fixes. Those messages will all be on 
MediaWiki-l as well, so there's no need to subscribe to both lists.

To subscribe or unsubscribe to MediaWiki-announce:
   http://mail.wikipedia.org/mailman/listinfo/mediawiki-announce

To subscribe or unsubscribe to MediaWiki-l:
   http://mail.wikipedia.org/mailman/listinfo/mediawiki-l

-- brion vibber (brion  <at>  pobox.com)

Brion Vibber | 3 Dec 15:40 2004
Picon

MediaWiki 1.4beta1 released


MediaWiki 1.4beta1 is an experimental release, to help flush out 
remaining major problems in the code prior to a final public 1.4.0 
release. It is not recommended to use this beta on a public site unless 
you're familiar with MediaWiki innards and are willing and able to help 
diagnose and fix problems that come up.

=== New features ===

* 'Recentchanges Patrol' to mark new edits that haven't yet been viewed.
* New, searchable deletion/upload/protection logs
* Image gallery generation (Special:Newimages and <gallery> tag)
* SVG rasterization support (requires external support)
* Users can select from the available localizations to override the
   default user interface language.
* Traditional/Simplified Chinese conversion support

=== Installation and compatibility ===

* The default MonoBook theme now works with PHP 5.0
* Installation on systems with PHP's safe mode or other oddities
   should work more reliably, as MonoBook no longer needs to
   create a compiled template file for the wiki to run.
* A table prefix may be specified, to avoid conflicts with other
   web applications forced to share a database.
* More thorough UTF-8 input validation; fixes non-ASCII uploaded
   filenames from Safari.
* Command-line database upgrade script.

=== Customizability ===
(Continue reading)

Brion Vibber | 10 Dec 07:56 2004
Picon

MediaWiki 1.4beta2 released


MediaWiki 1.4beta2 is an experimental release, to help flush out 
remaining major problems in the code prior to a final public 1.4.0 
release. It is not recommended to use this beta on a public site unless 
you're familiar with MediaWiki innards and are willing and able to help 
diagnose and fix problems that come up. 

All beta1 users should upgrade as soon as possible.

This release fixes separate input validation issues with image gallery 
rendering and PostgreSQL. Other fixes include Recentchanges in PHP5, 
whitelist-edit mode, table prefixes, page renaming, and other issues. 
Additionally, startup time for cached page views is slightly faster.

Full release notes:
http://sourceforge.net/project/shownotes.php?release_id=288858

Download:
http://prdownloads.sf.net/wikipedia/mediawiki-1.4beta2.tar.gz?download

Wiki admin help mailing list:
http://mail.wikipedia.org/mailman/listinfo/mediawiki-l

Low-traffic release announcements mailing list:
http://mail.wikipedia.org/mailman/listinfo/mediawiki-announce
 
Bug report system: 
http://bugzilla.wikipedia.org/ 
 
Play "stump the developers" live on IRC: 
(Continue reading)

Brion Vibber | 13 Dec 00:58 2004
Picon

MediaWiki 1.4beta3 released


MediaWiki 1.4beta3 is an experimental release, to help flush out 
remaining major problems in the code prior to a final public 1.4.0 
release. It is not recommended to use this beta on a public site unless 
you're familiar with MediaWiki innards and are willing and able to help 
diagnose and fix problems that come up.

Users of the earlier beta releases should upgrade as soon as possible, 
particularly if uploads are enabled. A security vulnerability with 
uploads on some Apache configurations has been fixed in this release.

=== Beta 3 fixes ===

* Hide RC patrol markers when patrol is disabled or not allowed to 
patrol.
* Fix language selection for upgraded accounts
* (bug 1076) navigation links in QueryPage should be translated by 
wgContLang.
* (bug 922) bogus DOS line endings in LanguageEl.php
* Fix index usage in contribs
* Caching and load limiting options for Recentchanges RSS/Atom feed
* (bug 1074) Add stock icons for non-image files in gallery/Newimages
* Add width and height attributes on thumbs in gallery/Newimages
* Enhance upload extension blacklist to protect against vulnerable
   Apache configurations

Release notes:
http://sourceforge.net/project/shownotes.php?release_id=289469

Download:
(Continue reading)

Brion Vibber | 13 Dec 00:59 2004
Picon

MediaWiki 1.3.9 released [security]

MediaWiki 1.3.9 is a security and bug fix release.

A flaw in upload handling has been found which may allow upload and 
execution of arbitrary scripts with the permissions of the web server. 
Only wikis that have enabled uploads and have a vulnerable Apache 
configuration will be affected, but to be safe all wikis should 
upgrade.

Wikis with uploads available should either disable uploads or upgrade 
to 1.3.9 immediately; if other files are customized and require merging 
changes, includes/SpecialUpload.php may be replaced individually to add 
the fix.

(It is also recommended to configure your web server to disable script 
execution in the 'images' subdirectory where uploads are placed, which 
prevents most attacks even if the wiki fails.)

Changes from 1.3.8:
* Backported "Templates used in this page"-feature of EditPage
* Allow "MySkin" as a default skin.
* (bug 938) Parse namespaces correctly on self-interwiki links
* (bug 1010) fix broken Commons image link on Classic & Cologne Blue
* (bug 1004) Norsk language names for interwiki links changed,
   Nauruan language name changed
* Fix upload extension blacklist to protect against vulnerable
   Apache configurations

Release notes:
http://sourceforge.net/project/shownotes.php?release_id=289468

(Continue reading)


Gmane