Commit message (Expand) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Merge branch 'security-2767-verify-lfs-finalize-from-workhorse' into 'master' | Yorick Peterse | 2019-01-24 | 4 | -7/+25 |
|\ | |||||
| * | Verify that LFS upload requests are genuine | Nick Thomas | 2019-01-22 | 4 | -7/+25 |
* | | Merge branch 'security-project-move-users' into 'master' | Yorick Peterse | 2019-01-24 | 6 | -7/+59 |
|\ \ | |||||
| * | | Sent notification only to authorized users | Jan Provaznik | 2019-01-23 | 6 | -7/+59 |
| |/ | |||||
* | | Merge branch 'security-fix-user-email-tag-push-leak' into 'master' | Yorick Peterse | 2019-01-24 | 3 | -3/+8 |
|\ \ | |||||
| * | | Fix private user email being visible in tag webhooks | Luke Duncalfe | 2019-01-18 | 3 | -3/+8 |
| * | | Prefer build() rather than create() | Luke Duncalfe | 2019-01-15 | 1 | -1/+1 |
* | | | Merge branch 'security-stored-xss-via-katex' into 'master' | Yorick Peterse | 2019-01-24 | 2 | -1/+22 |
|\ \ \ | |||||
| * | | | [master] Resolve "[Security] Stored XSS via KaTeX" | Constance Okoghenun | 2019-01-24 | 2 | -1/+22 |
|/ / / | |||||
* | | | Merge branch 'extract-pages-with-rubyzip' into 'master' | Yorick Peterse | 2019-01-24 | 17 | -25/+594 |
|\ \ \ | |||||
| * | | | Extract GitLab Pages using RubyZip | Kamil Trzciński | 2019-01-22 | 17 | -25/+594 |
* | | | | Merge branch 'security-commit-status-shown-for-guest-user' into 'master' | Yorick Peterse | 2019-01-24 | 3 | -1/+27 |
|\ \ \ \ | |||||
| * | | | | Stop showing ci for guest users | Steve Azzopardi | 2019-01-23 | 3 | -1/+27 |
* | | | | | Merge branch 'security-fix-lfs-import-project-ssrf-forgery' into 'master' | Yorick Peterse | 2019-01-24 | 13 | -103/+359 |
|\ \ \ \ \ | |||||
| * | | | | | Added validations to prevent LFS object forgery | Francisco Javier López | 2019-01-21 | 13 | -103/+359 |
* | | | | | | Merge branch 'security-pipeline-trigger-tokens-exposure' into 'master' | Yorick Peterse | 2019-01-24 | 11 | -17/+130 |
|\ \ \ \ \ \ | |||||
| * | | | | | | Add changelog for trigger token exposure fix | Grzegorz Bizon | 2019-01-15 | 1 | -0/+5 |
| * | | | | | | Fix subject in trigger presenter tests | Grzegorz Bizon | 2019-01-15 | 1 | -1/+1 |
| * | | | | | | Add some specs for trigger presenter | Grzegorz Bizon | 2019-01-15 | 1 | -0/+51 |
| * | | | | | | Present all pipeline triggers using trigger presenter | Grzegorz Bizon | 2019-01-15 | 3 | -4/+6 |
| * | | | | | | Do not expose trigger token when user should not see it | Grzegorz Bizon | 2019-01-15 | 8 | -13/+68 |
| | |_|_|/ / | |/| | | | | |||||
* | | | | | | Merge branch 'security-fix-regex-dos' into 'master' | Yorick Peterse | 2019-01-24 | 4 | -1/+14 |
|\ \ \ \ \ \ | |||||
| * | | | | | | Fix slow project reference pattern regex | Heinrich Lee Yu | 2019-01-11 | 4 | -1/+14 |
* | | | | | | | Merge branch 'security-fix-wiki-access-rights-with-external-wiki-enabled' int... | Yorick Peterse | 2019-01-24 | 14 | -51/+131 |
|\ \ \ \ \ \ \ | |||||
| * | | | | | | | Fixed bug when external wiki is enabled | Francisco Javier López | 2019-01-18 | 14 | -51/+131 |
| | |_|/ / / / | |/| | | | | | |||||
* | | | | | | | Merge branch 'security-2769-idn-homograph-attack' into 'master' | Yorick Peterse | 2019-01-24 | 9 | -13/+228 |
|\ \ \ \ \ \ \ | |||||
| * | | | | | | | Bump the CACHE_COMMONMARK_VERSION | Brett Walker | 2019-01-21 | 1 | -1/+1 |
| * | | | | | | | Show tooltip for malicious looking links | Brett Walker | 2019-01-21 | 8 | -12/+227 |
* | | | | | | | | Merge branch 'security-fix-new-issues-login-message' into 'master' | Yorick Peterse | 2019-01-24 | 3 | -10/+7 |
|\ \ \ \ \ \ \ \ | |||||
| * | | | | | | | | Use common error for unauthenticated users | Heinrich Lee Yu | 2019-01-14 | 3 | -10/+7 |
| | |_|_|/ / / / | |/| | | | | | | |||||
* | | | | | | | | Merge branch 'security-2776-fix-add-reaction-permissions' into 'master' | Yorick Peterse | 2019-01-24 | 3 | -0/+8 |
|\ \ \ \ \ \ \ \ | |||||
| * | | | | | | | | Prevent award_emoji to notes not visible to user | Heinrich Lee Yu | 2019-01-15 | 3 | -0/+8 |
| |/ / / / / / / | |||||
* | | | | | | | | Merge branch 'security-2779-fix-email-comment-permissions-check' into 'master' | Yorick Peterse | 2019-01-24 | 12 | -37/+94 |
|\ \ \ \ \ \ \ \ | |||||
| * | | | | | | | | Prevent comments by email when issue is locked | Heinrich Lee Yu | 2019-01-22 | 12 | -37/+94 |
| | |_|_|_|_|/ / | |/| | | | | | | |||||
* | | | | | | | | Merge branch 'qa/testing/cng/189' into 'master' | Rémy Coutable | 2019-01-24 | 3 | -10/+9 |
|\ \ \ \ \ \ \ \ | |||||
| * | | | | | | | | Use $CI_COMMIT_REF_NAME for tags in trigger-build | Rémy Coutable | 2019-01-24 | 2 | -5/+4 |
| * | | | | | | | | Use $CI_COMMIT_REF_SLUG in review-apps.sh | Rémy Coutable | 2019-01-24 | 1 | -5/+5 |
* | | | | | | | | | Merge branch '54385-board-policy-ce' into 'master' | Rémy Coutable | 2019-01-24 | 4 | -19/+22 |
|\ \ \ \ \ \ \ \ \ | |||||
| * | | | | | | | | | Backport of 54385-board-policy | Mario de la Ossa | 2019-01-18 | 4 | -19/+22 |
* | | | | | | | | | | Merge branch '56556-fix-markdown-table-border' into 'master' | Kushal Pandya | 2019-01-24 | 2 | -0/+6 |
|\ \ \ \ \ \ \ \ \ \ | |||||
| * | | | | | | | | | | Fix markdown table border | Jacques Erasmus | 2019-01-24 | 2 | -0/+6 |
|/ / / / / / / / / / | |||||
* | | | | | | | | | | Merge branch '8621-new-feature-flag-vue-ce-backport' into 'master' | Phil Hughes | 2019-01-24 | 1 | -1/+1 |
|\ \ \ \ \ \ \ \ \ \ | |||||
| * | | | | | | | | | | Adds extra sizes in responsive tables | Filipa Lacerda | 2019-01-23 | 1 | -1/+1 |
| | |_|_|_|_|_|_|/ / | |/| | | | | | | | | |||||
* | | | | | | | | | | Merge branch '56763-docs-lint-passes-if-a-relative-link-starts-with-doc-docs'... | Rémy Coutable | 2019-01-24 | 1 | -1/+1 |
|\ \ \ \ \ \ \ \ \ \ | |_|_|/ / / / / / / |/| | | | | | | | | | |||||
| * | | | | | | | | | Use the same path of the docs site as in production | Achilleas Pipinellis | 2019-01-23 | 1 | -1/+1 |
* | | | | | | | | | | Merge branch 'qa-quarantine-auto-dev-ops-tests' into 'master' | Rémy Coutable | 2019-01-24 | 1 | -1/+4 |
|\ \ \ \ \ \ \ \ \ \ | |||||
| * | | | | | | | | | | Quarantine auto devops tests | Sanad Liaquat | 2019-01-24 | 1 | -1/+4 |
* | | | | | | | | | | | Merge branch 'docs/document-built-in-templates' into 'master' | Achilleas Pipinellis | 2019-01-24 | 5 | -47/+102 |
|\ \ \ \ \ \ \ \ \ \ \ | |||||
| * | | | | | | | | | | | Restructure projects template topics | Evan Read | 2019-01-24 | 5 | -47/+102 |
|/ / / / / / / / / / / | |||||
* | | | | | | | | | | | Merge branch 'docs/fix-bare-urls' into 'master' | Achilleas Pipinellis | 2019-01-24 | 67 | -152/+151 |
|\ \ \ \ \ \ \ \ \ \ \ |