summaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* Default clusters namespace_per_environment to true65251-default-clusters-namespace_per_environment-column-to-trueTiger2019-08-303-1/+18
* Merge branch 'patch-78' into 'master'Ray Paik2019-08-291-1/+1
|\
| * Fixed spellingShan2019-08-291-1/+1
* | Merge branch 'patch-77' into 'master'Ray Paik2019-08-291-1/+1
|\ \
| * | Fixed spellingShan2019-08-291-1/+1
| |/
* | Merge branch 'master' of dev.gitlab.org:gitlab/gitlabhqRobert Speicher2019-08-29150-343/+3045
|\ \
| * \ Merge branch 'security-enable-image-proxy' into 'master'GitLab Release Tools Bot2019-08-2934-17/+592
| |\ \
| | * | disable cop Migration/AddLimitToStringColumnsBrett Walker2019-08-231-2/+2
| | * | Fix failing spec due to changes UpdateServiceBrett Walker2019-08-231-1/+1
| | * | Add support for using a Camo proxy serverBrett Walker2019-08-2333-16/+591
| * | | Merge branch 'security-2853-prevent-comments-on-private-mrs' into 'master'GitLab Release Tools Bot2019-08-296-75/+371
| |\ \ \
| | * | | Prevent unauthorised comments on merge requestsAlex Kalderimis2019-08-076-75/+371
| * | | | Merge branch 'security-epic-notes-api-reveals-historical-info-ce-master' into...GitLab Release Tools Bot2019-08-2911-23/+42
| |\ \ \ \
| | * | | | Use `stub_full_request` to fix spec failureHeinrich Lee Yu2019-08-283-16/+24
| | * | | | Return NO_ACCESS if user is nilPatrick Derichs2019-08-281-0/+2
| | * | | | Filter out old system notes for epicsPatrick Derichs2019-08-287-7/+16
| * | | | | Merge branch 'security-personal-snippets' into 'master'GitLab Release Tools Bot2019-08-2912-10/+77
| |\ \ \ \ \
| | * | | | | Add direct upload support for personal snippetsJan Provaznik2019-08-2312-10/+77
| * | | | | | Merge branch 'security-fix-html-injection-for-label-description-ce-master' in...GitLab Release Tools Bot2019-08-295-3/+29
| |\ \ \ \ \ \
| | * | | | | | Fix HTML injection for label descriptionPatrick Derichs2019-08-055-3/+29
| * | | | | | | Merge branch 'security-fix_jira_ssrf_vulnerability' into 'master'GitLab Release Tools Bot2019-08-294-1/+82
| |\ \ \ \ \ \ \
| | * | | | | | | Fix DNS rebind vulnerability for JIRA integrationFelipe Artur2019-08-084-1/+82
| | | |_|_|/ / / | | |/| | | | |
| * | | | | | | Merge branch 'security-61974-limit-issue-comment-size' into 'master'GitLab Release Tools Bot2019-08-2914-19/+78
| |\ \ \ \ \ \ \
| | * | | | | | | Limit the size of issuable description and commentsAlexandru Croitor2019-08-2214-19/+78
| * | | | | | | | Merge branch 'security-59549-add-capcha-for-failed-logins' into 'master'GitLab Release Tools Bot2019-08-2920-32/+307
| |\ \ \ \ \ \ \ \
| | * | | | | | | | Add captcha if there are multiple failed login attemptsMaƂgorzata Ksionek2019-07-3120-32/+307
| * | | | | | | | | Merge branch 'security-mr-head-pipeline-leak' into 'master'GitLab Release Tools Bot2019-08-293-5/+39
| |\ \ \ \ \ \ \ \ \
| | * | | | | | | | | Permission fix for MergeRequestsController#pipeline_statusdrew cimino2019-08-123-5/+39
| * | | | | | | | | | Merge branch 'security-katex-dos-master' into 'master'GitLab Release Tools Bot2019-08-294-23/+143
| |\ \ \ \ \ \ \ \ \ \
| | * | | | | | | | | | Enforce max chars and max render time in markdown mathMartin Hanzel2019-08-064-23/+143
| | | |_|_|/ / / / / / | | |/| | | | | | | |
| * | | | | | | | | | Merge branch 'security-project-import-bypass' into 'master'GitLab Release Tools Bot2019-08-295-26/+244
| |\ \ \ \ \ \ \ \ \ \
| | * | | | | | | | | | Fix project import restricted visibility bypassGeorge Koltsov2019-08-155-26/+244
| | |/ / / / / / / / /
| * | | | | | | | | | Merge branch 'security-hide_merge_request_ids_on_emails' into 'master'GitLab Release Tools Bot2019-08-295-18/+89
| |\ \ \ \ \ \ \ \ \ \
| | * | | | | | | | | | Prevent disclosure of merge request id via emailFelipe Artur2019-08-195-18/+89
| | |/ / / / / / / / /
| * | | | | | | | | | Merge branch 'security-id-filter-timeline-activities-for-guests' into 'master'GitLab Release Tools Bot2019-08-292-1/+6
| |\ \ \ \ \ \ \ \ \ \
| | * | | | | | | | | | Add merge note type as cross referenceIgor Drozdov2019-08-132-1/+6
| * | | | | | | | | | | Merge branch 'security-group-runners-permissions' into 'master'GitLab Release Tools Bot2019-08-293-43/+173
| |\ \ \ \ \ \ \ \ \ \ \
| | * | | | | | | | | | | admin_group authorization for Groups::RunnersControllerdrew cimino2019-08-223-43/+173
| * | | | | | | | | | | | Merge branch 'security-ci-metrics-permissions' into 'master'GitLab Release Tools Bot2019-08-293-8/+64
| |\ \ \ \ \ \ \ \ \ \ \ \
| | * | | | | | | | | | | | Restrict MergeRequests#test_reports to authenticated users with read-access o...drew cimino2019-08-223-8/+64
| * | | | | | | | | | | | | Merge branch 'security-sarcila-fix-weak-session-management' into 'master'GitLab Release Tools Bot2019-08-294-0/+71
| |\ \ \ \ \ \ \ \ \ \ \ \ \
| | * | | | | | | | | | | | | Add User#will_save_change_to_login? to clear reset_password_tokensSebastian Arcila Valenzuela2019-08-214-0/+71
| * | | | | | | | | | | | | | Merge branch 'security-add-job-activity-limit-ce' into 'master'GitLab Release Tools Bot2019-08-295-2/+43
| |\ \ \ \ \ \ \ \ \ \ \ \ \ \
| | * | | | | | | | | | | | | | Add active_jobs_limit to plans tableFabio Pitino2019-08-215-2/+43
| * | | | | | | | | | | | | | | Merge branch 'security-fix-markdown-xss' into 'master'GitLab Release Tools Bot2019-08-298-13/+76
| |\ \ \ \ \ \ \ \ \ \ \ \ \ \ \
| | * | | | | | | | | | | | | | | Re-escape whole HTML content instead of only matchJan Provaznik2019-08-238-13/+76
| * | | | | | | | | | | | | | | | Merge branch 'security-exposed-default-branch' into 'master'GitLab Release Tools Bot2019-08-294-2/+97
| |\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \
| | * | | | | | | | | | | | | | | | Avoid exposing unaccessible repo data upon GFM processingOswaldo Ferreira2019-08-214-2/+97
| * | | | | | | | | | | | | | | | | Merge branch 'security-ssrf-kubernetes-dns-12-3' into 'master'GitLab Release Tools Bot2019-08-295-18/+269
| |\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \
| | * | | | | | | | | | | | | | | | | Column was renamed in 12.2Thong Kuah2019-08-212-2/+2