summaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* Update VERSION to 11.9.12v11.9.1211-9-stableGitLab Release Tools Bot2019-05-301-1/+1
* Update CHANGELOG.md for 11.9.12GitLab Release Tools Bot2019-05-3013-60/+18
* Merge branch 'osw-disable-dns-rebind-protection-settings-11-9' into '11-9-sta...GitLab Release Tools Bot2019-05-3013-13/+183
|\
| * Rename UrlBlocker argument: schemes -> protocolsStan Hu2019-05-291-1/+1
| * Use Rails migration v5.0 for GitLab 11.9Stan Hu2019-05-291-1/+1
| * Add changelogOswaldo Ferreira2019-05-291-0/+5
| * Add DNS rebinding protection settingsOswaldo Ferreira2019-05-2912-13/+178
|/
* Merge branch 'security-60143-address-xss-issue-11.09' into '11-9-stable'GitLab Release Tools Bot2019-05-283-0/+55
|\
| * Reject slug+uri concat if slug is deemed unsafeKerri Miller2019-05-273-0/+55
* | Merge branch 'security-http-hostname-override-11-9' into '11-9-stable'GitLab Release Tools Bot2019-05-2827-87/+410
|\ \
| * | Protect Gitlab::HTTP against DNS rebinding attackDouwe Maan2019-05-2227-87/+410
* | | Merge branch 'security-58856-persistent-xss-11-9' into '11-9-stable'GitLab Release Tools Bot2019-05-286-3/+41
|\ \ \
| * | | Change `prohibited_key` to use regexescharlieablett2019-05-011-4/+2
| * | | Add `html` to sensitive wordscharlieablett2019-05-013-2/+4
| * | | Add changelog entrycharlieablett2019-04-301-0/+5
| * | | Ensure Issue & MR note_html cannot be importedAsh McKenzie2019-04-302-14/+16
| * | | Add newline to AttributeCleanercharlieablett2019-04-301-1/+1
| * | | Refactor AttributeCleaner` for readabilitycharlieablett2019-04-301-2/+3
| * | | Refactor AttributeCleaner` for readabilitycharlieablett2019-04-301-7/+2
| * | | Tighten up prohibited_key methodcharlieablett2019-04-261-4/+3
| * | | Add disallowed fields to AttributeCleanercharlieablett2019-04-243-2/+38
* | | | Merge branch 'security-fix-project-existence-disclosure-11-9' into '11-9-stable'GitLab Release Tools Bot2019-05-283-16/+28
|\ \ \ \
| * | | | Fix url redaction for issue linksPatrick Derichs2019-05-033-16/+28
* | | | | Merge branch 'security-60039-11-9' into '11-9-stable'GitLab Release Tools Bot2019-05-288-33/+144
|\ \ \ \ \
| * | | | | Validate MR branch namesMark Chao2019-05-068-33/+144
| | |_|/ / | |/| | |
* | | | | Merge branch 'security-unsubscribing-from-issue-11-9' into '11-9-stable'GitLab Release Tools Bot2019-05-284-11/+111
|\ \ \ \ \
| * | | | | Hide issue title on unsubscribe for anonymous usersAlexandru Croitor2019-05-204-11/+111
| |/ / / /
* | | | | Merge branch 'security-fix-confidential-issue-label-visibility-11-9' into '11...GitLab Release Tools Bot2019-05-283-1/+40
|\ \ \ \ \
| * | | | | Fix confidential issue label disclosure on milestone viewPatrick Derichs2019-05-193-1/+40
| |/ / / /
* | | | | Merge branch 'security-fix_milestones_search_api_leak-11-9' into '11-9-stable'GitLab Release Tools Bot2019-05-287-6/+130
|\ \ \ \ \
| * | | | | Resolve: Milestones leaked via search APIFelipe Artur2019-05-217-6/+130
| |/ / / /
* | | | | Merge branch 'security-jej/prevent-web-sign-in-bypass-11-9' into '11-9-stable'GitLab Release Tools Bot2019-05-283-1/+48
|\ \ \ \ \
| * | | | | Prevent password sign in restriction bypassJames Edwards-Jones2019-05-233-1/+48
| |/ / / /
* | | | | Merge branch 'security-knative-0.5-11-9' into '11-9-stable'GitLab Release Tools Bot2019-05-283-3/+8
|\ \ \ \ \
| * | | | | Update Knative version due to a security vulnerabilityTiger Watson2019-05-283-3/+8
|/ / / / /
* | | | | Merge branch 'sh-fix-issue-59379-11-9' into '11-9-stable'GitLab Release Tools Bot2019-05-283-2/+18
|\ \ \ \ \ | |_|_|_|/ |/| | | |
| * | | | Fix project visibility level validationPeter Marko2019-05-243-2/+18
|/ / / /
* | | | Merge branch '62283-fix-job-app-spec' into 'master'Filipa Lacerda2019-05-241-1/+4
|/ / /
* | | Update VERSION to 11.9.11v11.9.11GitLab Release Tools Bot2019-04-301-1/+1
* | | Update CHANGELOG.md for 11.9.11GitLab Release Tools Bot2019-04-302-5/+7
* | | Merge branch 'security-disallow-read-user-scope-to-read-project-events-11-9' ...GitLab Release Tools Bot2019-04-297-182/+224
|\ \ \
| * | | Add new api class for projects eventsMaƂgorzata Ksionek2019-04-257-182/+224
| |/ /
* | | Update VERSION to 11.9.10v11.9.10GitLab Release Tools Bot2019-04-261-1/+1
* | | Update CHANGELOG.md for 11.9.10GitLab Release Tools Bot2019-04-266-25/+11
|/ /
* | Merge branch 'security-approval-race-condition-11-9' into '11-9-stable'GitLab Release Tools Bot2019-04-252-3/+33
|\ \
| * | Add ApplicationRecord#safe_ensure_unique methodPatrick Bajao2019-04-122-3/+33
* | | Merge branch 'security-upgrade-to-rails-5-0-7-2-11-9' into '11-9-stable'GitLab Release Tools Bot2019-04-253-36/+41
|\ \ \
| * | | Upgrade Rails to 5.0.7.2Heinrich Lee Yu2019-04-123-36/+41
| |/ /
* | | Merge branch 'security-pb-email-watchers-no-access-11-9' into '11-9-stable'GitLab Release Tools Bot2019-04-253-12/+53
|\ \ \
| * | | Stop sending emails to users who can't read commitPatrick Bajao2019-04-163-12/+53
| |/ /