summaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
...
* Update VERSION to 11.5.6v11.5.6GitLab Release Tools Bot2018-12-281-1/+1
* Update CHANGELOG.md for 11.5.6GitLab Release Tools Bot2018-12-2819-90/+27
* Merge branch 'security-11-5' of dev.gitlab.org:gitlab/gitlabhq into 11-5-stableJohn Jarvis2018-12-2719-22/+243
|\
| * Merge branch 'security-fix/security-group-user-removal-11-5' into 'security-1...John Jarvis2018-12-2710-11/+120
| |\
| | * Merge branch 'security-11-5' into 'security-fix/security-group-user-removal-1...James Lopez2018-12-2779-176/+1097
| | |\
| | * | Add subresources removal to member destroy serviceJames Lopez2018-12-1310-13/+116
| * | | Merge remote-tracking branch 'origin/security-48259-private-snippet-11-5' int...John Jarvis2018-12-279-11/+123
| |\ \ \ | | |_|/ | |/| |
| | * | Block private snippets from being embeddableMark Chao2018-12-209-11/+123
| | |/
* | | Merge branch 'security-11-5' of dev.gitlab.org:gitlab/gitlabhq into 11-5-stableJohn Jarvis2018-12-2777-179/+1051
|\ \ \ | |/ /
| * | Merge branch 'security-11-5-secret-ci-variables-exposed' into 'security-11-5'John Jarvis2018-12-2719-46/+364
| |\ \
| | * | Stub full ref in build specMatija Čupić2018-12-081-1/+1
| | * | Add CHANGELOG entryMatija Čupić2018-12-081-0/+5
| | * | Backport security fix for 11.5Matija Čupić2018-12-0818-45/+358
| * | | Merge branch 'security-11-5-53543-user-keeps-access-to-mr-issue-when-removed-...John Jarvis2018-12-276-3/+77
| |\ \ \
| | * | | Adds validation to check if user can read projectTiago Botelho2018-12-196-3/+77
| | | |/ | | |/|
| * | | Merge branch 'security-11-5-group-cicd-settings-accessible-to-maintainer' int...John Jarvis2018-12-275-15/+56
| |\ \ \
| | * | | Use old-style controller request paramsMatija Čupić2018-12-241-2/+2
| | * | | Add CHANGELOG entryMatija Čupić2018-12-241-0/+5
| | * | | Check for group admin permissionsMatija Čupić2018-12-244-15/+51
| * | | | Merge branch 'security-11-5-guests-jobs-api' into 'security-11-5'John Jarvis2018-12-273-6/+36
| |\ \ \ \
| | * | | | Add CHANGELOG entryMatija Čupić2018-12-221-0/+5
| | * | | | Move pipeline auth above pipeline assignmentMatija Čupić2018-12-221-1/+1
| | * | | | Authorize read_pipeline before read_buildMatija Čupić2018-12-221-0/+1
| | * | | | Authorize read_build when listing pipeline jobsMatija Čupić2018-12-222-3/+15
| | * | | | Authorize read_build action when listing jobsMatija Čupić2018-12-222-3/+15
| | |/ / /
| * | | | Merge branch 'security-11-5-refs-available-to-project-guest' into 'security-1...John Jarvis2018-12-273-4/+26
| |\ \ \ \
| | * | | | Project guests no longer are able to see refs pageTiago Botelho2018-12-193-4/+26
| | | |/ / | | |/| |
| * | | | Merge branch 'security-11-5-fix-ssrf-lfs-project-import' into 'security-11-5'John Jarvis2018-12-272-17/+77
| |\ \ \ \
| | * | | | Fixed SSRF in project imports with LFSFrancisco Javier López2018-12-182-17/+77
| | |/ / /
| * | | | Merge branch 'security-label-xss-11-5' into 'security-11-5'John Jarvis2018-12-273-1/+28
| |\ \ \ \
| | * | | | Escape html entities when no label foundJarka Košanová2018-12-223-1/+28
| | | |/ / | | |/| |
| * | | | Merge branch 'ensure-that-build-token-is-always-running-11-5' into 'security-...John Jarvis2018-12-277-39/+105
| |\ \ \ \
| | * | | | Ensure that build token is only used when runningKamil Trzciński2018-12-187-39/+105
| * | | | | Merge branch 'security-11-5-fix-ssrf-import-url-remote-mirror' into 'security...John Jarvis2018-12-275-5/+30
| |\ \ \ \ \
| | * | | | | Replaced UrlValidator with PublicUrlValidator for import_url and remote mirro...Francisco Javier López2018-12-135-5/+30
| | | |_|/ / | | |/| | |
| * | | | | Merge branch 'security-11-5-54377-label-milestone-name-xss' into 'security-11-5'John Jarvis2018-12-263-7/+56
| |\ \ \ \ \
| | * | | | | Add changelog entryKushal Pandya2018-12-201-0/+5
| | * | | | | Escape label and milestone titles to prevent XSSKushal Pandya2018-12-202-7/+51
| | |/ / / /
| * | | | | Merge branch 'security-11-5-url-rel' into 'security-11-5'John Jarvis2018-12-263-10/+15
| |\ \ \ \ \
| | * | | | | Set URL rel attribute for broken URLsJan Provaznik2018-12-133-10/+15
| | |/ / / /
| * | | | | Merge branch 'security-todos_not_redacted_for_guests-11-5' into 'security-11-5'John Jarvis2018-12-2614-16/+55
| |\ \ \ \ \
| | * | | | | Delete confidential issue todos for guestsFelipe Artur2018-12-1714-16/+55
| | |/ / / /
| * | | | | Merge branch 'security-bvl-fix-cross-project-mr-exposure-11-5' into 'security...John Jarvis2018-12-264-10/+111
| |\ \ \ \ \ | | |_|_|/ / | |/| | | |
| | * | | | Validate projects in MR build serviceBob Van Landuyt2018-12-144-10/+111
| | |/ / /
| * | | | Merge branch 'security-import-symlink-11-5' into 'security-11-5'John Jarvis2018-12-206-4/+62
| |\ \ \ \ | | |/ / / | |/| | |
| | * | | Update command_line_util.rb to fix rubocopJames Lopez2018-12-181-1/+1
| | * | | Fix persistent symlink in project importJames Lopez2018-12-186-4/+62
| |/ / /
| * | | Merge branch 'security-2754-fix-lfs-import-11-5' into 'security-11-5'John Jarvis2018-12-123-0/+20
| |\ \ \
| | * | | Validate LFS hrefs before downloading themNick Thomas2018-12-123-0/+20
| |/ / /
| * | | Merge remote-tracking branch 'dev/11-5-stable' into security-11-5Nick Thomas2018-12-11118-9255/+103484
| |\ \ \ | | |_|/ | |/| |