summaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* Update VERSION to 12.1.10v12.1.1012-1-stable-patch-11GitLab Release Tools Bot2019-09-191-1/+1
* Update CHANGELOG.md for 12.1.10GitLab Release Tools Bot2019-09-191-0/+4
* Merge branch '12-1-stable-patch-10' into '12-1-stable'John Jarvis2019-09-192-7/+4
|\
| * Merge branch 'sh-fix-captcha-state-pollution-spec' into 'master'12-1-stable-patch-10Mayra Cabrera2019-09-191-7/+1
| * Merge branch 'sh-fix-no-downtime-upgrades-ce' into '12-1-stable-patch-10'John Jarvis2019-09-191-0/+3
| |\ |/ /
| * Re-add ignore_column for import columnssh-fix-no-downtime-upgrades-ceStan Hu2019-09-171-0/+3
|/
* Merge remote-tracking branch 'dev/12-1-stable' into 12-1-stableGitLab Release Tools Bot2019-09-113-2/+9
|\
| * Update VERSION to 12.1.9v12.1.9GitLab Release Tools Bot2019-09-101-1/+1
| * Update CHANGELOG.md for 12.1.9GitLab Release Tools Bot2019-09-102-5/+7
| * Merge branch 'security-12-1-bump-pages' into '12-1-stable'GitLab Release Tools Bot2019-09-102-1/+6
| |\ |/ /
| * Upgrade pages to 1.7.2Vladimir Shushlin2019-09-092-1/+6
|/
* Update VERSION to 12.1.8v12.1.8GitLab Release Tools Bot2019-08-281-1/+1
* Update CHANGELOG.md for 12.1.8GitLab Release Tools Bot2019-08-2822-105/+27
* Merge branch '66641-broken-master-real-http-connections-are-disabled-unregist...Jan Provaznik2019-08-280-0/+0
* Revert "Update CHANGELOG.md for 12.1.7"John Jarvis2019-08-2822-24/+106
* Merge branch 'security-fix-something-went-wrong-on-when-not-logged-in-ce-12-1...GitLab Release Tools Bot2019-08-284-16/+26
|\
| * Use `stub_full_request` to fix spec failureHeinrich Lee Yu2019-08-283-16/+24
| * Return NO_ACCESS if user is nilPatrick Derichs2019-08-281-0/+2
|/
* Update VERSION to 12.1.7v12.1.7GitLab Release Tools Bot2019-08-271-1/+1
* Update CHANGELOG.md for 12.1.7GitLab Release Tools Bot2019-08-2722-105/+27
* Merge branch 'security-exposed-default-branch-12-1' into '12-1-stable'GitLab Release Tools Bot2019-08-264-2/+97
|\
| * Avoid exposing unaccessible repo data upon GFM processingOswaldo Ferreira2019-08-264-2/+97
|/
* Merge branch 'security-hide_merge_request_ids_on_emails-12-1' into '12-1-stable'GitLab Release Tools Bot2019-08-265-18/+89
|\
| * Prevent disclosure of merge request id via emailFelipe Artur2019-08-215-18/+89
* | Merge branch 'security-64711-fix-commit-todos-12-1' into '12-1-stable'GitLab Release Tools Bot2019-08-263-20/+112
|\ \
| * | Send TODOs for comments on commits correctlyNick Thomas2019-08-233-20/+112
| |/
* | Merge branch 'security-59549-add-capcha-for-failed-logins-12-1' into '12-1-st...GitLab Release Tools Bot2019-08-2620-31/+307
|\ \
| * | Add captcha if there are multiple failed login attemptsMaƂgorzata Ksionek2019-08-2620-31/+307
|/ /
* | Merge branch 'security-12-1-enable-image-proxy' into '12-1-stable'GitLab Release Tools Bot2019-08-2633-25/+603
|\ \
| * | Add support for using a Camo proxy serverBrett Walker2019-08-1533-25/+603
* | | Merge branch 'security-61974-limit-issue-comment-size-12-1' into '12-1-stable'GitLab Release Tools Bot2019-08-2614-19/+103
|\ \ \
| * | | Limit the size of issuable description and commentsAlexandru Croitor2019-08-2214-19/+103
| | |/ | |/|
* | | Merge branch 'security-mr-head-pipeline-leak-12-1' into '12-1-stable'GitLab Release Tools Bot2019-08-263-5/+39
|\ \ \
| * | | Permission fix for MergeRequestsController#pipeline_statusdrew cimino2019-08-123-5/+39
* | | | Merge branch 'security-katex-dos-12-1' into '12-1-stable'GitLab Release Tools Bot2019-08-264-23/+143
|\ \ \ \
| * | | | Enforce max chars and max render time in markdown mathMartin Hanzel2019-08-064-23/+143
* | | | | Merge branch 'security-ssrf-kubernetes-dns-12-1' into '12-1-stable'GitLab Release Tools Bot2019-08-265-18/+269
|\ \ \ \ \
| * | | | | Override hostname when connecting via KubeclientThong Kuah2019-08-045-18/+269
| | |_|_|/ | |/| | |
* | | | | Merge branch 'security-fix-html-injection-for-label-description-ce-12-1' into...GitLab Release Tools Bot2019-08-265-3/+29
|\ \ \ \ \
| * | | | | Fix HTML injection for label descriptionPatrick Derichs2019-08-055-3/+29
| |/ / / /
* | | | | Merge branch 'security-2853-prevent-comments-on-private-mrs-12-1' into '12-1-...GitLab Release Tools Bot2019-08-266-75/+371
|\ \ \ \ \
| * | | | | Prevent unauthorised comments on merge requestsAlex Kalderimis2019-08-076-75/+371
| | |/ / / | |/| | |
* | | | | Merge branch 'security-epic-notes-api-reveals-historical-info-ce-12-1' into '...GitLab Release Tools Bot2019-08-267-8/+21
|\ \ \ \ \
| * | | | | Filter out old system notes for epicsPatrick Derichs2019-08-097-8/+21
| |/ / / /
* | | | | Merge branch 'security-fix_jira_ssrf_vulnerability-12-1' into '12-1-stable'GitLab Release Tools Bot2019-08-264-1/+82
|\ \ \ \ \
| * | | | | Fix DNS rebind vulnerability for JIRA integrationFelipe Artur2019-08-084-1/+82
| |/ / / /
* | | | | Merge branch 'security-id-filter-timeline-activities-for-guests-12-1' into '1...GitLab Release Tools Bot2019-08-262-1/+6
|\ \ \ \ \
| * | | | | Add merge note type as cross referenceIgor Drozdov2019-08-142-1/+6
* | | | | | Merge branch 'security-project-import-bypass-12-1' into '12-1-stable'GitLab Release Tools Bot2019-08-265-26/+244
|\ \ \ \ \ \
| * | | | | | Fix project import restricted visibility bypassGeorge Koltsov2019-08-155-26/+244
| | |_|_|/ / | |/| | | |