summaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* Update Gitaly to 1.42.4jc-bump-gitaly-stderr-log-fixJohn Cai2019-06-061-1/+1
* Update VERSION to 11.11.2v11.11.2GitLab Release Tools Bot2019-06-041-1/+1
* Update CHANGELOG.md for 11.11.2GitLab Release Tools Bot2019-06-049-40/+17
* Merge branch '11-11-stable-patch-1' into '11-11-stable'John Skarbek2019-06-0429-23/+205
|\
| * Merge branch 'sh-fix-import-url-update' into 'master'11-11-stable-patch-1Thong Kuah2019-06-043-0/+19
| * Merge branch '11-11-stable' into 11-11-stable-patch-1Stan Hu2019-06-0477-176/+1323
| |\ | |/ |/|
* | Update VERSION to 11.11.1v11.11.1GitLab Release Tools Bot2019-05-301-1/+1
* | Update CHANGELOG.md for 11.11.1GitLab Release Tools Bot2019-05-3013-60/+18
* | Merge branch 'osw-disable-dns-rebind-protection-settings-11-11' into '11-11-s...GitLab Release Tools Bot2019-05-3014-13/+184
|\ \
| * | Add changelogOswaldo Ferreira2019-05-291-0/+5
| * | Add DNS rebinding protection settingsOswaldo Ferreira2019-05-2913-13/+179
* | | Merge branch 'id-fix-overriding-of-import-params' into '11-11-stable'Yorick Peterse2019-05-292-7/+12
|\ \ \ | |/ / |/| |
| * | Fix the overriding of EE import paramsIgor Drozdov2019-05-292-7/+12
|/ /
* | Merge branch 'security-60143-address-xss-issue-in-wiki-links' into '11-11-sta...GitLab Release Tools Bot2019-05-283-0/+55
|\ \
| * | Reject slug+uri concat if slug is deemed unsafeKerri Miller2019-05-273-0/+55
* | | Merge branch 'security-58856-persistent-xss-11-11' into '11-11-stable'Robert Speicher2019-05-286-3/+41
|\ \ \
| * | | Fix persistent XSS in note objectsTiger2019-05-286-3/+41
|/ / /
* | | Merge branch 'security-fix-project-existence-disclosure-11-11' into '11-11-st...GitLab Release Tools Bot2019-05-283-16/+28
|\ \ \
| * | | Fix url redaction for issue linksPatrick Derichs2019-05-033-16/+28
* | | | Merge branch 'security-60039-11-11' into '11-11-stable'GitLab Release Tools Bot2019-05-288-33/+144
|\ \ \ \
| * | | | Validate MR branch namesMark Chao2019-05-068-33/+144
| |/ / /
* | | | Merge branch 'security-unsubscribing-from-issue-11-11' into '11-11-stable'GitLab Release Tools Bot2019-05-284-11/+109
|\ \ \ \
| * | | | Hide issue title on unsubscribe for anonymous usersAlexandru Croitor2019-05-164-11/+109
* | | | | Merge branch 'security-fix-confidential-issue-label-visibility-11-11' into '1...GitLab Release Tools Bot2019-05-283-1/+46
|\ \ \ \ \
| * | | | | Fix confidential issue label disclosure on milestone viewPatrick Derichs2019-05-173-1/+46
* | | | | | Merge branch 'security-id-leaked-password-in-import-url-frontend-11-11' into ...GitLab Release Tools Bot2019-05-2811-18/+168
|\ \ \ \ \ \
| * | | | | | Handling password on import by url pageSam Bigelow2019-05-214-18/+22
| * | | | | | Hide password on import by url formIgor Drozdov2019-05-2111-14/+160
| |/ / / / /
* | | | | | Merge branch 'security-fix_milestones_search_api_leak-11-11' into '11-11-stable'GitLab Release Tools Bot2019-05-287-7/+131
|\ \ \ \ \ \
| * | | | | | Resolve: Milestones leaked via search APIFelipe Artur2019-05-217-7/+131
* | | | | | | Merge branch 'security-http-hostname-override-11-11' into '11-11-stable'GitLab Release Tools Bot2019-05-2829-90/+419
|\ \ \ \ \ \ \
| * | | | | | | Protect Gitlab::HTTP against DNS rebinding attackDouwe Maan2019-05-2229-90/+419
* | | | | | | | Merge branch 'security-pb-fix-get-archive-11-11' into '11-11-stable'GitLab Release Tools Bot2019-05-282-1/+6
|\ \ \ \ \ \ \ \
| * | | | | | | | Update Gitaly to fix GetArchive vulnerabilityPatrick Bajao2019-05-232-1/+6
| |/ / / / / / /
* | | | | | | | Merge branch 'security-jej/prevent-web-sign-in-bypass-11-11' into '11-11-stable'GitLab Release Tools Bot2019-05-283-1/+47
|\ \ \ \ \ \ \ \ | |_|_|_|_|_|/ / |/| | | | | | |
| * | | | | | | Prevent password sign in restriction bypassJames Edwards-Jones2019-05-233-1/+47
| |/ / / / / /
| | | | | | * Merge remote-tracking branch 'origin/11-11-stable-patch-2' into 11-11-stable-...John T Skarbek2019-06-033-1/+7
| | | | | | |\
| | | | | | | * Merge branch 'sh-fix-issue-58714' into 'master'11-11-stable-patch-2Yorick Peterse2019-06-033-1/+7
| | | | | | * | Merge branch 'zj-bump-gitaly' into '11-11-stable-patch-1'Mayra Cabrera2019-06-034-7/+7
| | | | | | |\ \ | | | | | | | |/ | | | | | | |/|
| | | | | | | * Bump Gitaly version to 1.42.3Zeger-Jan van de Weg2019-06-034-7/+7
| | | | | | |/
| | | | | | * Merge branch 'dm-disable-two-step-rebase' into 'master'Mayra Cabrera2019-06-032-1/+6
| | | | | | * Merge branch 'use-source-ref-name-in-webhook' into 'master'Ash McKenzie2019-06-033-1/+15
| | | | | | * Merge branch 'sh-fix-omniauth-generic-strategy' into 'master'Douglas Barbosa Alexandre2019-06-033-1/+41
| | | | | | * Merge branch 'jp-label-fix' into 'master'Lin Jen-Shin2019-06-0310-19/+101
| | | | | | * Merge branch 'patch-64' into 'master'Kamil TrzciƄski2019-06-032-0/+6
| | | | | | * Merge branch '60778-input-text-height' into 'master'Filipa Lacerda2019-06-033-0/+10
| |_|_|_|_|/ |/| | | | |
* | | | | | Merge branch '62283-fix-job-app-spec' into 'master'Filipa Lacerda2019-05-241-1/+4
|/ / / / /
* | | | | Update VERSION to 11.11.0v11.11.0GitLab Release Tools Bot2019-05-221-1/+1
* | | | | Update CHANGELOG.md for 11.11.0GitLab Release Tools Bot2019-05-22166-832/+185
* | | | | Update VERSION to 11.11.0-rc5v11.11.0-rc5GitLab Release Tools Bot2019-05-211-1/+1