- protect against too large bug numbers (causes pg errors) - don't access @patch.patch_id@ for displayed_object_id, if it does not exist (view mode) - don't perform message key subsitution in user contributed bug description - add csrf protection for search