summaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* Update VERSION to 11.5.1v11.5.1GitLab Release Tools Bot2018-11-261-1/+1
* Update CHANGELOG.md for 11.5.1GitLab Release Tools Bot2018-11-2618-87/+23
* Merge branch 'security-11-5-fj-crlf-injection' into 'security-11-5'Steve Azzopardi2018-11-265-54/+128
|\
| * [11.5] Fix CRLF issue in UrlValidatorFrancisco Javier López2018-11-265-54/+128
|/
* Merge branch 'security-fix-uri-xss-applications-11-5' into 'security-11-5'Steve Azzopardi2018-11-267-2/+121
|\
| * Resolve reflected XSS in Ouath authorize windowJames Lopez2018-11-267-2/+121
* | Merge branch 'security-11-5-fix-webhook-ssrf-ipv6' into 'security-11-5'Steve Azzopardi2018-11-263-13/+112
|\ \
| * | Fix SSRF in project integrationsFrancisco Javier López2018-11-123-13/+112
* | | Merge branch 'security-email-change-notification-11-5' into 'security-11-5'Steve Azzopardi2018-11-265-0/+32
|\ \ \
| * | | Provide email notification on email updatesJames Lopez2018-11-125-0/+32
| |/ /
* | | Merge branch 'security-guest-comments-11-5' into 'security-11-5'Steve Azzopardi2018-11-2613-34/+187
|\ \ \ | |_|/ |/| |
| * | [11.5] Fixed ability to comment on and edit/delete comments on locked or conf...Chantal Rollison2018-11-2613-34/+187
|/ /
* | Merge branch 'security-11-5-pages-toctou-race' into 'security-11-5'Steve Azzopardi2018-11-262-1/+7
|\ \
| * | Upgrade GitLab Pages to v1.3.1Alessio Caiazza2018-11-212-1/+7
* | | Merge branch 'security-fix-pat-web-access-11-5' into 'security-11-5'Steve Azzopardi2018-11-2628-281/+538
|\ \ \
| * | | Update code to use API scope on PAT authJames Lopez2018-11-2328-281/+538
|/ / /
* | | Merge branch 'security-11-5-xss-in-markdown-following-unrecognized-html-eleme...Steve Azzopardi2018-11-235-2/+25
|\ \ \
| * | | Sanitize output of SpacedLinkFilterBrett Walker2018-11-165-2/+25
* | | | Merge branch 'security-mermaid-xss-11-5' into 'security-11-5'Steve Azzopardi2018-11-234-1/+21
|\ \ \ \
| * | | | Configure mermaid to not render HTML content in diagramsWinnie Hellmann2018-11-192-0/+8
| * | | | Add failing test for XSS in mermaid diagramsWinnie Hellmann2018-11-192-1/+13
| | |/ / | |/| |
* | | | Merge branch 'security-bvl-exposure-in-commits-list-11-5' into 'security-11-5'Steve Azzopardi2018-11-233-55/+67
|\ \ \ \
| * | | | Don't use fragment cache on commit pageBob Van Landuyt2018-11-193-55/+67
| |/ / /
* | | | Merge branch 'security-issue_51301-11-5' into 'security-11-5'Steve Azzopardi2018-11-236-12/+96
|\ \ \ \
| * | | | Fix milestone promotion authorizationFelipe Artur2018-11-146-12/+96
| | |_|/ | |/| |
* | | | Merge branch 'security-2736-prometheus-ssrf-11-5' into 'security-11-5'Steve Azzopardi2018-11-234-3/+25
|\ \ \ \
| * | | | No redirects in prometheus servicerpereira22018-11-144-3/+25
| |/ / /
* | | | Merge branch 'security-11-5-stored-xss-for-environments' into 'security-11-5'Steve Azzopardi2018-11-237-6/+67
|\ \ \ \
| * | | | Validate URI scheme also for internal URIAlessio Caiazza2018-11-167-6/+67
| | |_|/ | |/| |
* | | | Merge branch 'security-private-group-11-5' into 'security-11-5'Steve Azzopardi2018-11-233-0/+26
|\ \ \ \
| * | | | Fixed read name of private groupsChantal Rollison2018-11-063-0/+26
| | |/ / | |/| |
* | | | Merge branch 'security-182-update-workhorse-11-5' into 'security-11-5'Steve Azzopardi2018-11-233-1/+9
|\ \ \ \
| * | | | Redact sensitive information on workhorse logMark Chao2018-11-233-1/+9
| | |/ / | |/| |
* | | | Merge branch '11-5-stable' into security-11-5Steve Azzopardi2018-11-23257-1247/+392
|\ \ \ \ | |_|_|/ |/| | |
| * | | Update VERSION to 11.5.0v11.5.0GitLab Release Tools Bot2018-11-211-1/+1
| * | | Update CHANGELOG.md for 11.5.0GitLab Release Tools Bot2018-11-21239-1192/+262
| * | | Update VERSION to 11.5.0-rc13v11.5.0-rc13GitLab Release Tools Bot2018-11-201-1/+1
| * | | Merge branch 'sh-fix-issue-8448-ce' into 'master'Steve Azzopardi2018-11-201-1/+8
| * | | Merge branch 'docs-runbook-guide' into 'master'Mike Lewis2018-11-209-3/+91
| * | | Merge branch '11-5-stable-prepare-rc13' into '11-5-stable'11-5-stable-prepare-rc13Cindy Pallares 🦉2018-11-209-60/+30
| |\ \ \
| | * | | Merge branch 'jramsay/file-tree-docs' into 'master'Achilleas Pipinellis2018-11-192-3/+4
| | * | | Merge branch 'image-discussion-ff-fix' into 'master'Filipa Lacerda2018-11-193-13/+10
| | * | | Merge branch 'docs/clusters-knative' into 'master'Marcia Ramos2018-11-191-13/+11
| | * | | Merge branch 'osw-remove-comment-on-any-diff-line-ff' into 'master'Douwe Maan2018-11-192-28/+1
| | * | | Merge branch 'libre-to-core' into 'master'Marcia Ramos2018-11-191-3/+4
| |/ / /
| * | | Merge branch '11-5-stable-fix-changelog' into '11-5-stable'Stan Hu2018-11-191-0/+0
| |\ \ \
| | * | | Move changelog for issue 54189 to correct locationCindy Pallares2018-11-191-0/+0
| |/ / /
| * | | Update VERSION to 11.5.0-rc12v11.5.0-rc12GitLab Release Tools Bot2018-11-181-1/+1
| * | | Merge branch 'sh-fix-issue-54189-11-5' into 'security-11-5'Steve Azzopardi2018-11-184-1/+37
| * | | Merge branch 'security-11-5-2717-xss-username-autocomplete' into 'security-11-5'Steve Azzopardi2018-11-183-10/+39