Commit message (Expand) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Merge branch 'fix-rubyzip-require' into 'master' | Yorick Peterse | 2019-01-30 | 1 | -1/+1 |
|\ | |||||
| * | Fix requiring the rubyzip Gem | Yorick Peterse | 2019-01-30 | 1 | -1/+1 |
|/ | |||||
* | Merge branch 'dev-master' into 'master' | Yorick Peterse | 2019-01-30 | 3 | -2/+7 |
|\ | |||||
| * | Fix uninitialized constant with GitLab Pages deploy | Stan Hu | 2019-01-29 | 3 | -2/+7 |
* | | Update CHANGELOG.md for 11.7.2 | GitLab Release Tools Bot | 2019-01-29 | 1 | -0/+34 |
|/ | |||||
* | Update CHANGELOG.md for 11.5.8 | GitLab Release Tools Bot | 2019-01-28 | 1 | -0/+27 |
* | Update CHANGELOG.md for 11.7.1 | GitLab Release Tools Bot | 2019-01-28 | 21 | -101/+30 |
* | Merge branch '56860-fix-spec-race-condition-upside-the-head' into 'master' | Douglas Barbosa Alexandre | 2019-01-28 | 1 | -0/+3 |
* | Merge branch 'test-permissions' into 'master' | Yorick Peterse | 2019-01-28 | 35 | -95/+324 |
|\ | |||||
| * | [master] Pipelines section is available to unauthorized users | Kamil Trzciński | 2019-01-28 | 35 | -95/+324 |
|/ | |||||
* | Merge branch 'fix/security-group-user-removal' into 'master' | Yorick Peterse | 2019-01-25 | 10 | -11/+114 |
|\ | |||||
| * | Add subresources removal to member destroy service | James Lopez | 2019-01-25 | 10 | -11/+114 |
* | | Merge branch 'security-import-path-logging' into 'master' | Yorick Peterse | 2019-01-25 | 8 | -17/+107 |
|\ \ | |||||
| * | | Fix path disclosure on Project Import | James Lopez | 2019-01-07 | 8 | -17/+107 |
* | | | Merge branch 'security-guests-can-see-list-of-merge-requests' into 'master' | Yorick Peterse | 2019-01-25 | 7 | -20/+154 |
|\ \ \ | |||||
| * | | | Group Guests are no longer able to see merge requests | Tiago Botelho | 2019-01-21 | 7 | -20/+154 |
* | | | | Merge branch 'security-import-project-visibility' into 'master' | Yorick Peterse | 2019-01-25 | 5 | -2/+219 |
|\ \ \ \ | |||||
| * | | | | Fix tree restorer visibility level | James Lopez | 2019-01-24 | 5 | -2/+219 |
* | | | | | Merge branch 'security-contributed-projects' into 'master' | Yorick Peterse | 2019-01-25 | 4 | -0/+56 |
|\ \ \ \ \ | |||||
| * | | | | | Fix contributed projects finder shown private info | James Lopez | 2019-01-08 | 4 | -0/+56 |
* | | | | | | Merge branch 'security-do-not-process-mr-ref-for-guests' into 'master' | Yorick Peterse | 2019-01-25 | 3 | -2/+17 |
|\ \ \ \ \ \ | |||||
| * | | | | | | Don't process MR refs for guests in the notes | Oswaldo Ferreira | 2019-01-10 | 3 | -2/+17 |
* | | | | | | | Merge branch 'security-22076-sanitize-url-in-names' into 'master' | Yorick Peterse | 2019-01-25 | 40 | -54/+84 |
|\ \ \ \ \ \ \ | |||||
| * | | | | | | | Add changelog entry | Kushal Pandya | 2019-01-22 | 1 | -0/+6 |
| * | | | | | | | Use `sanitize_name` to sanitize URL in user full name | Kushal Pandya | 2019-01-22 | 37 | -54/+56 |
| * | | | | | | | Add `sanitize_name` helper to sanitize URLs in user full name | Kushal Pandya | 2019-01-22 | 2 | -0/+22 |
* | | | | | | | | Merge branch 'sh-fix-import-redirect-vulnerability' into 'master' | Yorick Peterse | 2019-01-25 | 8 | -8/+43 |
|\ \ \ \ \ \ \ \ | |||||
| * | | | | | | | | Alias GitHub and BitBucket OAuth2 callback URLs | Stan Hu | 2019-01-22 | 8 | -8/+43 |
* | | | | | | | | | Merge branch 'security-fix-protected-branches-creation-access-rights-ce' into... | Yorick Peterse | 2019-01-25 | 2 | -23/+8 |
|\ \ \ \ \ \ \ \ \ | |||||
| * | | | | | | | | | [master] Check access rights when creating/updating ProtectedRefs | Francisco Javier López | 2019-01-25 | 2 | -23/+8 |
|/ / / / / / / / / | |||||
* | | | | | | | | | Merge branch 'security-2780-disable-git-v2-protocol' into 'master' | Yorick Peterse | 2019-01-25 | 3 | -1/+13 |
|\ \ \ \ \ \ \ \ \ | |||||
| * | | | | | | | | | Disable git v2 protocol temporarily | Nick Thomas | 2019-01-24 | 3 | -1/+13 |
* | | | | | | | | | | Merge branch 'security-55320-stored-xss-in-user-status' into 'master' | Tim Zallmann | 2019-01-25 | 3 | -7/+12 |
|\ \ \ \ \ \ \ \ \ \ | |_|_|_|_|_|_|_|_|/ |/| | | | | | | | | | |||||
| * | | | | | | | | | Use sanitized user status message for user popover | Dennis Tang | 2019-01-23 | 3 | -7/+12 |
| | |/ / / / / / / | |/| | | | | | | | |||||
* | | | | | | | | | Merge branch 'security-2767-verify-lfs-finalize-from-workhorse' into 'master' | Yorick Peterse | 2019-01-24 | 4 | -7/+25 |
|\ \ \ \ \ \ \ \ \ | |||||
| * | | | | | | | | | Verify that LFS upload requests are genuine | Nick Thomas | 2019-01-22 | 4 | -7/+25 |
| |/ / / / / / / / | |||||
* | | | | | | | | | Merge branch 'security-project-move-users' into 'master' | Yorick Peterse | 2019-01-24 | 6 | -7/+59 |
|\ \ \ \ \ \ \ \ \ | |||||
| * | | | | | | | | | Sent notification only to authorized users | Jan Provaznik | 2019-01-23 | 6 | -7/+59 |
| |/ / / / / / / / | |||||
* | | | | | | | | | Merge branch 'security-fix-user-email-tag-push-leak' into 'master' | Yorick Peterse | 2019-01-24 | 3 | -3/+8 |
|\ \ \ \ \ \ \ \ \ | |||||
| * | | | | | | | | | Fix private user email being visible in tag webhooks | Luke Duncalfe | 2019-01-18 | 3 | -3/+8 |
| * | | | | | | | | | Prefer build() rather than create() | Luke Duncalfe | 2019-01-15 | 1 | -1/+1 |
| | |_|/ / / / / / | |/| | | | | | | | |||||
* | | | | | | | | | Merge branch 'security-stored-xss-via-katex' into 'master' | Yorick Peterse | 2019-01-24 | 2 | -1/+22 |
|\ \ \ \ \ \ \ \ \ | |||||
| * | | | | | | | | | [master] Resolve "[Security] Stored XSS via KaTeX" | Constance Okoghenun | 2019-01-24 | 2 | -1/+22 |
|/ / / / / / / / / | |||||
* | | | | | | | | | Merge branch 'extract-pages-with-rubyzip' into 'master' | Yorick Peterse | 2019-01-24 | 17 | -25/+594 |
|\ \ \ \ \ \ \ \ \ | |||||
| * | | | | | | | | | Extract GitLab Pages using RubyZip | Kamil Trzciński | 2019-01-22 | 17 | -25/+594 |
* | | | | | | | | | | Merge branch 'security-commit-status-shown-for-guest-user' into 'master' | Yorick Peterse | 2019-01-24 | 3 | -1/+27 |
|\ \ \ \ \ \ \ \ \ \ | |||||
| * | | | | | | | | | | Stop showing ci for guest users | Steve Azzopardi | 2019-01-23 | 3 | -1/+27 |
* | | | | | | | | | | | Merge branch 'security-fix-lfs-import-project-ssrf-forgery' into 'master' | Yorick Peterse | 2019-01-24 | 13 | -103/+359 |
|\ \ \ \ \ \ \ \ \ \ \ | |||||
| * | | | | | | | | | | | Added validations to prevent LFS object forgery | Francisco Javier López | 2019-01-21 | 13 | -103/+359 |
| | |_|_|_|_|_|/ / / / | |/| | | | | | | | | | |||||
* | | | | | | | | | | | Merge branch 'security-pipeline-trigger-tokens-exposure' into 'master' | Yorick Peterse | 2019-01-24 | 11 | -17/+130 |
|\ \ \ \ \ \ \ \ \ \ \ |