summaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* Update VERSION to 11.10.5v11.10.511-10-stable-prepare-rc6GitLab Release Tools Bot2019-05-301-1/+1
* Update CHANGELOG.md for 11.10.5GitLab Release Tools Bot2019-05-3013-60/+18
* Merge branch 'osw-disable-dns-rebind-protection-settings-11-10' into '11-10-s...GitLab Release Tools Bot2019-05-3014-13/+184
|\
| * Rename UrlBlocker argument: schemes -> protocolsStan Hu2019-05-291-1/+1
| * Use Rails migration v5.0 for GitLab 11.10Stan Hu2019-05-291-1/+1
| * Add changelogOswaldo Ferreira2019-05-291-0/+5
| * Add DNS rebinding protection settingsOswaldo Ferreira2019-05-2913-13/+179
|/
* Merge branch 'security-60143-address-xss-issue-11.10' into '11-10-stable'GitLab Release Tools Bot2019-05-283-0/+55
|\
| * Reject slug+uri concat if slug is deemed unsafeKerri Miller2019-05-273-0/+55
* | Merge branch 'security-58856-persistent-xss-11-10' into '11-10-stable'GitLab Release Tools Bot2019-05-286-3/+41
|\ \
| * | Change `prohibited_key` to use regexescharlieablett2019-05-011-4/+2
| * | Add `html` to sensitive wordscharlieablett2019-05-013-2/+4
| * | Add changelog entrycharlieablett2019-04-301-0/+5
| * | Ensure Issue & MR note_html cannot be importedAsh McKenzie2019-04-302-14/+16
| * | Add newline to AttributeCleanercharlieablett2019-04-301-1/+1
| * | Refactor AttributeCleaner` for readabilitycharlieablett2019-04-301-2/+3
| * | Refactor AttributeCleaner` for readabilitycharlieablett2019-04-301-7/+2
| * | Tighten up prohibited_key methodcharlieablett2019-04-261-4/+3
| * | Add disallowed fields to AttributeCleanercharlieablett2019-04-243-2/+38
* | | Merge branch 'security-fix-project-existence-disclosure-11-10' into '11-10-st...GitLab Release Tools Bot2019-05-283-16/+28
|\ \ \
| * | | Fix url redaction for issue linksPatrick Derichs2019-05-063-16/+28
* | | | Merge branch 'security-60039-11-10' into '11-10-stable'GitLab Release Tools Bot2019-05-288-33/+144
|\ \ \ \
| * | | | Validate MR branch namesMark Chao2019-05-068-33/+144
| |/ / /
* | | | Merge branch 'security-unsubscribing-from-issue-11-10' into '11-10-stable'GitLab Release Tools Bot2019-05-284-11/+111
|\ \ \ \
| * | | | Hide issue title on unsubscribe for anonymous usersAlexandru Croitor2019-05-204-11/+111
| |/ / /
* | | | Merge branch 'security-fix-confidential-issue-label-visibility-11-10' into '1...GitLab Release Tools Bot2019-05-283-1/+40
|\ \ \ \
| * | | | Fix confidential issue label disclosure on milestone viewPatrick Derichs2019-05-193-1/+40
| |/ / /
* | | | Merge branch 'security-fix_milestones_search_api_leak-11-10' into '11-10-stable'GitLab Release Tools Bot2019-05-287-6/+130
|\ \ \ \
| * | | | Resolve: Milestones leaked via search APIFelipe Artur2019-05-217-6/+130
| |/ / /
* | | | Merge branch 'security-http-hostname-override-11-10' into '11-10-stable'GitLab Release Tools Bot2019-05-2828-87/+412
|\ \ \ \
| * | | | Protect Gitlab::HTTP against DNS rebinding attackDouwe Maan2019-05-2228-87/+412
| |/ / /
* | | | Merge branch 'security-jej/prevent-web-sign-in-bypass-11-10' into '11-10-stable'GitLab Release Tools Bot2019-05-283-1/+48
|\ \ \ \
| * | | | Prevent password sign in restriction bypassJames Edwards-Jones2019-05-233-1/+48
| |/ / /
* | | | Merge branch 'security-knative-0.5-11-10' into '11-10-stable'GitLab Release Tools Bot2019-05-286-4/+29
|\ \ \ \
| * | | | Update Knative version due to a security vulnerabilityTiger Watson2019-05-286-4/+29
|/ / / /
* | | | Merge branch 'sh-fix-issue-59379-11-10' into '11-10-stable'GitLab Release Tools Bot2019-05-283-2/+18
|\ \ \ \ | |_|_|/ |/| | |
| * | | Fix project visibility level validationPeter Marko2019-05-243-2/+18
|/ / /
* | | Merge branch '62283-fix-job-app-spec' into 'master'11-10-stable-patch-5Filipa Lacerda2019-05-241-1/+4
|/ /
* | Update VERSION to 11.10.4v11.10.4GitLab Release Tools Bot2019-05-011-1/+1
* | Update CHANGELOG.md for 11.10.4GitLab Release Tools Bot2019-05-0115-71/+23
* | Merge branch '11-10-stable-patch-4' into '11-10-stable'John Jarvis2019-05-0115-20/+272
|\ \
| * | Merge branch 'fix-ref-text-of-mr-pipelines' into 'master'Ash McKenzie2019-04-305-15/+103
| * | Merge branch 'fix-environment-on-stop-not-work' into 'master'Sean McGivern2019-04-3010-5/+169
|/ /
* | Merge remote-tracking branch 'origin/11-10-stable' into 11-10-stableJohn T Skarbek2019-04-3058-87/+512
|\ \
| * \ Merge branch '11-10-stable-patch-3' into '11-10-stable'John Jarvis2019-04-3058-87/+512
| |\ \
| | * | Merge branch '60605-karma-failing' into 'master'Michael Kozono2019-04-291-18/+32
| | * | Revert "Merge branch 'docs-review-MR27275' into 'master'"John T Skarbek2019-04-291-22/+9
| | * | Merge branch '11-10-stable-ie11-fix' into '11-10-stable-patch-3'John Skarbek2019-04-292-5/+5
| | |\ \
| | | * | Update gitlab-ui to 3.2.0-hotfix.1Clement Ho2019-04-292-5/+5
| | |/ / | |/| |
| | * | Merge branch 'update-workhorse-11-10' into '11-10-stable-patch-3'John Skarbek2019-04-292-1/+6
| | |\ \