summaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* Validate URI scheme also for internal URIAlessio Caiazza2018-11-147-6/+67
* Merge branch 'security-kubeclient-ssrf-11-3' into 'security-11-3'Jan Provaznik2018-10-302-0/+26
|\
| * Monkey kubeclient to not follow any redirects.Thong Kuah2018-10-262-0/+26
* | Merge branch 'fix_pat_auth-11-3' into 'security-11-3'Robert Speicher2018-10-263-3/+3
|\ \ | |/ |/|
| * Fix token lookup for Git over HTTP operations and registryImre Farkas2018-10-263-3/+3
|/
* Merge branch 'sh-validate-wiki-attachments-11-3' into 'security-11-3'Thiago Presa2018-10-244-2/+32
|\
| * Validate Wiki attachments are valid temporary filesStan Hu2018-10-234-2/+32
* | Merge branch 'security-11-3-2717-fix-issue-title-xss' into 'security-11-3'Jan Provaznik2018-10-243-4/+25
|\ \
| * | Add changelog entryKushal Pandya2018-10-191-0/+5
| * | Add spec to test HTML escaping while rendering autocompleteKushal Pandya2018-10-191-0/+15
| * | Escape issue title while template rendering to prevent XSSKushal Pandya2018-10-191-4/+5
* | | Merge branch 'security-redact-links-11-3' into 'security-11-3'Jan Provaznik2018-10-2411-1/+382
|\ \ \
| * | | Redact unsubscribe links in issuable textsJan Provaznik2018-10-2311-1/+382
| | |/ | |/|
* | | Merge branch 'security-fix/control-headers-11-3' into 'security-11-3'Jan Provaznik2018-10-244-7/+65
|\ \ \ | |/ / |/| |
| * | Fix content caching for non auth usersJames Lopez2018-10-234-7/+65
|/ /
* | Merge branch 'security-11-3-junit-test-report-exposes-stacktrace' into 'secur...Jan Provaznik2018-10-231-4/+4
|\ \
| * | Remove full exception stack trace from errorMatija Čupić2018-09-211-4/+4
* | | Merge branch 'security-if-51113-hash_tokens-11-3' into 'security-11-3'Jan Provaznik2018-10-2320-69/+701
|\ \ \
| * | | [11.3] Persist only SHA digest of PersonalAccessToken#tokenImre Farkas2018-10-2320-69/+701
|/ / /
* | | Merge branch 'security-11-3-51527-xss-in-mr-source-branch' into 'security-11-3'Thiago Presa2018-10-233-9/+17
|\ \ \
| * | | Fix XSS in MR source branch namePaul Slaughter2018-10-123-9/+17
| | |/ | |/|
* | | Merge branch 'sh-block-other-localhost-11-3' into 'security-11-3'Thiago Presa2018-10-233-0/+37
|\ \ \ | |/ / |/| |
| * | Prevent SSRF attacks in HipChat integrationStan Hu2018-10-123-0/+37
|/ /
* | Merge branch 'security-bw-confidential-titles-through-markdown-api-11-3' into...Bob Van Landuyt2018-10-045-5/+62
|\ \
| * | post_process markdown redered by APIBrett Walker2018-09-295-5/+62
* | | Merge branch 'security-fix-leaking-private-project-namespace-11-3' into 'secu...Bob Van Landuyt2018-10-046-33/+80
|\ \ \
| * | | Filter system notes with public and private cross referencesBrett Walker2018-10-026-33/+80
* | | | Merge branch 'security-osw-user-info-leak-discussions-11-3' into 'security-11-3'Bob Van Landuyt2018-10-044-1/+39
|\ \ \ \
| * | | | Add changelogOswaldo Ferreira2018-10-011-0/+5
| * | | | Filter user sensitive data from discussions JSONOswaldo Ferreira2018-10-013-1/+34
| | |/ / | |/| |
* | | | Merge branch '11-3-stable' into security-11-3Bob Van Landuyt2018-10-0427-99/+362
|\ \ \ \ | |_|/ / |/| | |
| * | | Update VERSION to 11.3.3v11.3.3GitLab Release Tools Bot2018-10-041-1/+1
| * | | Update CHANGELOG.md for 11.3.3GitLab Release Tools Bot2018-10-041-0/+4
| * | | Merge branch 'fl-revert-21802' into '11-3-stable'Bob Van Landuyt2018-10-044-101/+64
| |\ \ \
| | * | | Regenerates potfilesFilipa Lacerda2018-10-031-12/+0
| | * | | Reverts changes to the runners tableFilipa Lacerda2018-10-033-89/+64
| |/ / /
| * | | Update VERSION to 11.3.2v11.3.2GitLab Release Tools Bot2018-10-031-1/+1
| * | | Update CHANGELOG.md for 11.3.2GitLab Release Tools Bot2018-10-036-25/+14
| * | | Add newly translated strings11-3-stable-patch-2Bob Van Landuyt2018-10-031-0/+12
| * | | Merge branch '51782-fix_rename_login_namespace_migration' into 'master'Sean McGivern2018-10-032-0/+7
| * | | Merge branch '51549-runners-table' into 'master'Annabel Dunstone Gray2018-10-034-64/+94
| * | | Merge branch '51522-add-new-project-via-import-by-url-auto-populates-slug-but...Stan Hu2018-10-023-2/+7
| * | | Merge branch '51747-gitlab-com-unable-to-import-a-project-that-was-just-expor...Douglas Barbosa Alexandre2018-10-025-4/+29
| * | | Merge branch 'sh-fix-forks-with-no-gravatar' into 'master'Rémy Coutable2018-10-026-40/+28
| * | | Merge branch 'mr-discussion-expanding-bug-fixes' into 'master'Filipa Lacerda2018-10-022-1/+39
| * | | Merge branch '50347-fix-scrolling-to-diff-note-after-incremental-rendering' i...Phil Hughes2018-10-025-40/+215
| * | | Merge branch '51657-fix-merge-mr-from-fork-spec' into 'master'Robert Speicher2018-10-022-5/+21
| * | | Merge branch 'jr-wiki-doc' into 'master'Achilleas Pipinellis2018-10-021-5/+8
| * | | Merge branch 'jr-webhook-docs' into 'master'Achilleas Pipinellis2018-10-022-0/+8
| * | | Merge branch 'move-cloud-images-job-stage' into 'master'Robert Speicher2018-10-021-1/+1