summaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
...
| * Merge branch 'fix_pat_auth-11-3' into 'security-11-3'Robert Speicher2018-10-263-3/+3
| * Update VERSION to 11.3.7v11.3.7GitLab Release Tools Bot2018-10-261-1/+1
| * Update CHANGELOG.md for 11.3.7GitLab Release Tools Bot2018-10-267-30/+12
| * Merge branch 'security-11-3-2717-fix-issue-title-xss' into 'security-11-3'Jan Provaznik2018-10-243-4/+25
| * Merge branch 'security-redact-links-11-3' into 'security-11-3'Jan Provaznik2018-10-2411-1/+382
| * Merge branch 'security-fix/control-headers-11-3' into 'security-11-3'Jan Provaznik2018-10-244-7/+65
| * Merge branch 'sh-validate-wiki-attachments-11-3' into 'security-11-3'Thiago Presa2018-10-244-2/+32
| * Merge branch 'security-11-3-junit-test-report-exposes-stacktrace' into 'secur...Jan Provaznik2018-10-241-4/+4
| * Merge branch 'security-if-51113-hash_tokens-11-3' into 'security-11-3'Jan Provaznik2018-10-2420-69/+701
| * Merge branch 'security-11-3-51527-xss-in-mr-source-branch' into 'security-11-3'Thiago Presa2018-10-243-9/+17
| * Merge branch 'sh-block-other-localhost-11-3' into 'security-11-3'Thiago Presa2018-10-243-0/+37
| * Update VERSION to 11.3.6v11.3.6GitLab Release Tools Bot2018-10-171-1/+1
| * Update CHANGELOG.md for 11.3.6GitLab Release Tools Bot2018-10-171-0/+4
| * Update VERSION to 11.3.5v11.3.511-3-stable-patch-6GitLab Release Tools Bot2018-10-151-1/+1
| * Update CHANGELOG.md for 11.3.5GitLab Release Tools Bot2018-10-153-10/+8
| * Merge branch '51958-fix-mr-discussion-loading-11-3-stable-patch-5' into '11-3...11-3-stable-patch-5Sean McGivern2018-10-1210-92/+96
| |\
| | * Fix MR discussion not loaded issueMark Chao2018-10-1210-92/+96
| |/
| * Revert "Merge branch '51958-fix-mr-discussion-loading' into 'master'"Bob Van Landuyt2018-10-1210-113/+91
| * Merge branch 'sh-fix-project-deletion-with-export' into 'master'Robert Speicher2018-10-123-4/+26
| * Merge branch '51958-fix-mr-discussion-loading' into 'master'Phil Hughes2018-10-1210-91/+113
| * Update VERSION to 11.3.4v11.3.4GitLab Release Tools Bot2018-10-051-1/+1
| * Update CHANGELOG.md for 11.3.4GitLab Release Tools Bot2018-10-054-15/+9
| * Merge branch 'security-bw-confidential-titles-through-markdown-api-11-3' into...Bob Van Landuyt2018-10-045-5/+62
| * Merge branch 'security-fix-leaking-private-project-namespace-11-3' into 'secu...Bob Van Landuyt2018-10-046-33/+80
| * Merge branch 'security-osw-user-info-leak-discussions-11-3' into 'security-11-3'Bob Van Landuyt2018-10-044-1/+39
* | Merge branch 'security-kubeclient-ssrf-11-3' into 'security-11-3'Jan Provaznik2018-10-302-0/+26
|\ \
| * | Monkey kubeclient to not follow any redirects.Thong Kuah2018-10-262-0/+26
* | | Merge branch 'fix_pat_auth-11-3' into 'security-11-3'Robert Speicher2018-10-263-3/+3
|\ \ \ | |/ / |/| |
| * | Fix token lookup for Git over HTTP operations and registryImre Farkas2018-10-263-3/+3
|/ /
* | Merge branch 'sh-validate-wiki-attachments-11-3' into 'security-11-3'Thiago Presa2018-10-244-2/+32
|\ \
| * | Validate Wiki attachments are valid temporary filesStan Hu2018-10-234-2/+32
* | | Merge branch 'security-11-3-2717-fix-issue-title-xss' into 'security-11-3'Jan Provaznik2018-10-243-4/+25
|\ \ \
| * | | Add changelog entryKushal Pandya2018-10-191-0/+5
| * | | Add spec to test HTML escaping while rendering autocompleteKushal Pandya2018-10-191-0/+15
| * | | Escape issue title while template rendering to prevent XSSKushal Pandya2018-10-191-4/+5
* | | | Merge branch 'security-redact-links-11-3' into 'security-11-3'Jan Provaznik2018-10-2411-1/+382
|\ \ \ \
| * | | | Redact unsubscribe links in issuable textsJan Provaznik2018-10-2311-1/+382
| | |/ / | |/| |
* | | | Merge branch 'security-fix/control-headers-11-3' into 'security-11-3'Jan Provaznik2018-10-244-7/+65
|\ \ \ \ | |/ / / |/| | |
| * | | Fix content caching for non auth usersJames Lopez2018-10-234-7/+65
|/ / /
* | | Merge branch 'security-11-3-junit-test-report-exposes-stacktrace' into 'secur...Jan Provaznik2018-10-231-4/+4
|\ \ \
| * | | Remove full exception stack trace from errorMatija Čupić2018-09-211-4/+4
* | | | Merge branch 'security-if-51113-hash_tokens-11-3' into 'security-11-3'Jan Provaznik2018-10-2320-69/+701
|\ \ \ \
| * | | | [11.3] Persist only SHA digest of PersonalAccessToken#tokenImre Farkas2018-10-2320-69/+701
|/ / / /
* | | | Merge branch 'security-11-3-51527-xss-in-mr-source-branch' into 'security-11-3'Thiago Presa2018-10-233-9/+17
|\ \ \ \
| * | | | Fix XSS in MR source branch namePaul Slaughter2018-10-123-9/+17
| | |/ / | |/| |
* | | | Merge branch 'sh-block-other-localhost-11-3' into 'security-11-3'Thiago Presa2018-10-233-0/+37
|\ \ \ \ | |/ / / |/| | |
| * | | Prevent SSRF attacks in HipChat integrationStan Hu2018-10-123-0/+37
|/ / /
* | | Merge branch 'security-bw-confidential-titles-through-markdown-api-11-3' into...Bob Van Landuyt2018-10-045-5/+62
|\ \ \
| * | | post_process markdown redered by APIBrett Walker2018-09-295-5/+62
* | | | Merge branch 'security-fix-leaking-private-project-namespace-11-3' into 'secu...Bob Van Landuyt2018-10-046-33/+80
|\ \ \ \