summaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* Revert "Merge branch 'security-pipeline-trigger-tokens-exposure-11-4' into 's...11-4-stableYorick Peterse2019-01-2411-130/+17
* Merge branch 'security-pipeline-trigger-tokens-exposure-11-4' into 'security-...Yorick Peterse2019-01-2411-17/+130
* Update VERSION to 11.4.14v11.4.14GitLab Release Tools Bot2019-01-151-1/+1
* Update CHANGELOG.md for 11.4.14GitLab Release Tools Bot2019-01-152-5/+7
* Merge branch 'security-2770-verify-bundle-import-files-11-4' into 'security-1...Yorick Peterse2019-01-156-5/+79
* Merge branch 'fix-prepare-build-script' into 'master'Marin Jankovski2019-01-101-1/+1
* Update VERSION to 11.4.13v11.4.13GitLab Release Tools Bot2018-12-281-1/+1
* Update CHANGELOG.md for 11.4.13GitLab Release Tools Bot2018-12-2820-95/+25
* Merge branch 'security-11-4' of dev.gitlab.org:gitlab/gitlabhq into 11-4-stableJohn Jarvis2018-12-2719-22/+243
|\
| * Merge branch 'security-fix/security-group-user-removal-11-4' into 'security-1...John Jarvis2018-12-2710-11/+120
| |\
| | * Merge branch 'security-11-4' into 'security-fix/security-group-user-removal-1...James Lopez2018-12-2792-211/+131631
| | |\
| | * | Add subresources removal to member destroy serviceJames Lopez2018-12-1310-13/+116
| * | | Merge remote-tracking branch 'origin/security-48259-private-snippet-11-4' int...John Jarvis2018-12-279-11/+123
| |\ \ \ | | |_|/ | |/| |
| | * | Block private snippets from being embeddableMark Chao2018-12-209-11/+123
| | |/
* | | Merge branch 'security-11-4' of dev.gitlab.org:gitlab/gitlabhq into 11-4-stableJohn Jarvis2018-12-275-15/+56
|\ \ \ | |/ /
| * | Merge branch 'security-11-4-group-cicd-settings-accessible-to-maintainer' int...John Jarvis2018-12-275-15/+56
| |\ \
| | * | Use old-style controller request paramsMatija Čupić2018-12-241-2/+2
| | * | Add CHANGELOG entryMatija Čupić2018-12-241-0/+5
| | * | Check for group admin permissionsMatija Čupić2018-12-244-15/+51
* | | | Merge branch 'security-11-4' of dev.gitlab.org:gitlab/gitlabhq into 11-4-stableJohn Jarvis2018-12-2785-199/+131529
|\ \ \ \ | |/ / /
| * | | Merge branch 'security-11-4-secret-ci-variables-exposed' into 'security-11-4'John Jarvis2018-12-2720-36/+369
| |\ \ \
| | * | | Add CHANGELOG entryMatija Čupić2018-12-081-0/+5
| | * | | Backport security fix for 11.4Matija Čupić2018-12-0819-36/+364
| * | | | Merge branch 'security-11-4-53543-user-keeps-access-to-mr-issue-when-removed-...John Jarvis2018-12-276-3/+77
| |\ \ \ \
| | * | | | Adds validation to check if user can read projectTiago Botelho2018-12-196-3/+77
| | | |_|/ | | |/| |
| * | | | Merge branch 'security-11-4-refs-available-to-project-guest' into 'security-1...John Jarvis2018-12-273-4/+26
| |\ \ \ \
| | * | | | Project guests no longer are able to see refs pageTiago Botelho2018-12-193-4/+26
| | |/ / /
| * | | | Merge branch 'security-11-4-fix-ssrf-lfs-project-import' into 'security-11-4'John Jarvis2018-12-272-17/+77
| |\ \ \ \
| | * | | | Fixed SSRF in project imports with LFSFrancisco Javier López2018-12-182-17/+77
| | |/ / /
| * | | | Merge branch 'security-wiki-svg-attachment' into 'security-11-4'John Jarvis2018-12-2712-46/+130528
| |\ \ \ \
| | * | | | [11.4] Stored XSS in latest IEFrancisco Javier López2018-12-2712-46/+130528
| |/ / / /
| * | | | Merge branch 'security-label-xss-11-4' into 'security-11-4'John Jarvis2018-12-273-1/+28
| |\ \ \ \
| | * | | | Escape html entities when no label foundJarka Košanová2018-12-223-1/+28
| | | |_|/ | | |/| |
| * | | | Merge branch 'security-11-4-guests-jobs-api' into 'security-11-4'John Jarvis2018-12-273-6/+36
| |\ \ \ \
| | * | | | Add CHANGELOG entryMatija Čupić2018-12-221-0/+5
| | * | | | Move pipeline auth above pipeline assignmentMatija Čupić2018-12-221-1/+1
| | * | | | Authorize read_pipeline before read_buildMatija Čupić2018-12-221-0/+1
| | * | | | Authorize read_build when listing pipeline jobsMatija Čupić2018-12-222-3/+15
| | * | | | Authorize read_build action when listing jobsMatija Čupić2018-12-222-3/+15
| | |/ / /
| * | | | Merge branch 'ensure-that-build-token-is-always-running-11-4' into 'security-...John Jarvis2018-12-277-39/+105
| |\ \ \ \
| | * | | | Ensure that build token is only used when runningKamil Trzciński2018-12-187-39/+105
| * | | | | Merge branch 'security-11-4-fix-ssrf-import-url-remote-mirror' into 'security...John Jarvis2018-12-275-5/+31
| |\ \ \ \ \
| | * | | | | [11.4] SSRF - Scan Internal Ports and GCP/AWS endpointsFrancisco Javier López2018-12-275-5/+31
| |/ / / / /
| * | | | | Merge branch 'security-11-4-54377-label-milestone-name-xss' into 'security-11-4'John Jarvis2018-12-263-6/+56
| |\ \ \ \ \
| | * | | | | Add changelog entryKushal Pandya2018-12-201-0/+5
| | * | | | | Escape label and milestone titles to prevent XSSKushal Pandya2018-12-202-6/+51
| | | |_|/ / | | |/| | |
| * | | | | Merge branch 'security-11-4-url-rel' into 'security-11-4'John Jarvis2018-12-263-10/+15
| |\ \ \ \ \
| | * | | | | Set URL rel attribute for broken URLsJan Provaznik2018-12-133-10/+15
| | |/ / / /
| * | | | | Merge branch 'security-todos_not_redacted_for_guests-11-4' into 'security-11-4'John Jarvis2018-12-2614-16/+55
| |\ \ \ \ \
| | * | | | | Delete confidential issue todos for guestsFelipe Artur2018-12-1714-16/+55
| | |/ / / /