summaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
...
| * | | | | Merge branch 'security-bvl-fix-cross-project-mr-exposure-11-4' into 'security...John Jarvis2018-12-264-10/+111
| |\ \ \ \ \ | | |_|_|/ / | |/| | | |
| | * | | | Validate projects in MR build serviceBob Van Landuyt2018-12-144-10/+111
| | |/ / /
| * | | | Merge branch 'security-import-symlink-11-4' into 'security-11-4'John Jarvis2018-12-206-4/+62
| |\ \ \ \ | | |/ / / | |/| | |
| | * | | Update command_line_util.rbJames Lopez2018-12-181-1/+1
| | * | | Fix persistent symlink in project importJames Lopez2018-12-186-4/+62
| |/ / /
| * | | Merge branch 'security-2754-fix-lfs-import-11-4' into 'security-11-4'John Jarvis2018-12-123-0/+20
| |\ \ \ | | |_|/ | |/| |
| | * | Validate LFS hrefs before downloading themNick Thomas2018-12-123-0/+20
| |/ /
| * | Merge branch 'security-54857-fix-templates-path-traversal-11-4' into 'securit...Cindy Pallares2018-12-058-2/+90
| |\ \ | | |/ | |/|
| | * Prevent a path traversal attack on global file templatesNick Thomas2018-12-058-2/+90
| |/
* | Merge branch 'sh-disble-docs-internal-links-lint' into 'master'Clement Ho2018-12-271-1/+2
* | Update VERSION to 11.4.12v11.4.12GitLab Release Tools Bot2018-12-201-1/+1
* | Update CHANGELOG.md for 11.4.12GitLab Release Tools Bot2018-12-202-5/+7
* | Merge branch 'security-import-symlink-11-4' into 'security-11-4'John Jarvis2018-12-206-4/+62
* | Update VERSION to 11.4.11v11.4.11GitLab Release Tools Bot2018-12-131-1/+1
* | Update CHANGELOG.md for 11.4.11GitLab Release Tools Bot2018-12-132-5/+7
* | Merge branch 'security-2754-fix-lfs-import-11-4' into 'security-11-4'John Jarvis2018-12-133-0/+20
* | Update VERSION to 11.4.10v11.4.10GitLab Release Tools Bot2018-12-061-1/+1
* | Update CHANGELOG.md for 11.4.10GitLab Release Tools Bot2018-12-062-5/+7
* | Merge branch 'security-54857-fix-templates-path-traversal-11-4' into 'securit...Cindy Pallares2018-12-058-2/+90
* | Update VERSION to 11.4.9v11.4.9GitLab Release Tools Bot2018-12-031-1/+1
* | Update CHANGELOG.md for 11.4.9GitLab Release Tools Bot2018-12-033-10/+8
* | Merge branch '11-4-stable-patch-9' into '11-4-stable'Steve Azzopardi2018-12-0320-33/+150
|\ \
| * | Remove `ee` directory for `ce` repoSteve Azzopardi2018-12-031-5/+0
| * | Remove QA/ElementWithPatternJan Provaznik2018-11-301-1/+1
| * | Merge branch 'if-53347_fix_impersonation_tokens' into 'master'Stan Hu2018-11-3014-27/+55
| * | Merge branch '53763-fix-encrypt-columns-data-loss' into 'master'Stan Hu2018-11-305-2/+96
|/ /
* | Update VERSION to 11.4.8v11.4.8GitLab Release Tools Bot2018-11-271-1/+1
* | Update CHANGELOG.md for 11.4.8GitLab Release Tools Bot2018-11-2725-122/+30
|/
* Merge branch 'security-11-4-fix-webhook-ssrf-ipv6' into 'security-11-4'Steve Azzopardi2018-11-263-13/+114
|\
| * Fix SSRF in project integrationsFrancisco Javier López2018-11-263-13/+114
* | Merge branch 'security-fix-uri-xss-applications-11-4' into 'security-11-4'Steve Azzopardi2018-11-267-2/+121
|\ \
| * | Resolve reflected XSS in Ouath authorize windowJames Lopez2018-11-267-2/+121
* | | Merge branch 'security-11-4-fj-crlf-injection' into 'security-11-4'Steve Azzopardi2018-11-265-39/+113
|\ \ \ | |_|/ |/| |
| * | [11.4] Fix CRLF issue in UrlValidatorFrancisco Javier López2018-11-265-39/+113
|/ /
* | Merge branch '11-4-stable' into security-11-4Steve Azzopardi2018-11-261-1/+2
|\ \
| * \ Merge branch 'charts-gitlab-937-pass-compile-assets' into '11-4-stable'Rémy Coutable2018-11-211-1/+2
| |\ \
| | * | CI: Add COMPILE_ASSETS to cng build triggercharts-gitlab-937-pass-compile-assetsJason Plum2018-11-201-1/+2
| |/ /
* | | Merge branch 'security-email-change-notification-11-4' into 'security-11-4'Steve Azzopardi2018-11-265-0/+32
|\ \ \ | |_|/ |/| |
| * | Provide email notification on email updatesJames Lopez2018-11-125-0/+32
* | | Merge branch 'security-guest-comments-11-4' into 'security-11-4'Steve Azzopardi2018-11-2613-34/+187
|\ \ \
| * | | [11.4] Fixed ability to comment on and edit/delete comments on locked or conf...Chantal Rollison2018-11-2613-34/+187
|/ / /
* | | Merge branch 'security-11-4-pages-toctou-race' into 'security-11-4'Steve Azzopardi2018-11-262-1/+7
|\ \ \
| * | | Upgrade GitLab Pages to v1.1.1Alessio Caiazza2018-11-212-1/+7
* | | | Merge branch 'security-fix-pat-web-access-11-4' into 'security-11-4'Steve Azzopardi2018-11-2628-277/+538
|\ \ \ \
| * | | | Update code to use API scope on PAT authJames Lopez2018-11-2328-277/+538
| |/ / /
* | | | Merge branch 'security-11-4-xss-in-markdown-following-unrecognized-html-eleme...Steve Azzopardi2018-11-235-2/+25
|\ \ \ \
| * | | | Sanitize output of SpacedLinkFilterBrett Walker2018-11-165-2/+25
* | | | | Merge branch 'security-mermaid-xss-11-4' into 'security-11-4'Steve Azzopardi2018-11-234-1/+21
|\ \ \ \ \
| * | | | | Configure mermaid to not render HTML content in diagramsWinnie Hellmann2018-11-142-0/+8
| * | | | | Add failing test for XSS in mermaid diagramsWinnie Hellmann2018-11-142-1/+13
| |/ / / /