summaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* Update VERSION to 11.6.1v11.6.1GitLab Release Tools Bot2018-12-281-1/+1
* Update CHANGELOG.md for 11.6.1GitLab Release Tools Bot2018-12-2817-80/+25
* Merge branch 'security-11-6' of dev.gitlab.org:gitlab/gitlabhq into 11-6-stableJohn Jarvis2018-12-2720-22/+248
|\
| * Merge branch 'security-fix/security-group-user-removal-11-6' into 'security-1...John Jarvis2018-12-2710-11/+120
| |\
| | * Merge branch 'security-11-6' into 'security-fix/security-group-user-removal-1...James Lopez2018-12-2774-166/+1057
| | |\
| | * | Add subresources removal to member destroy serviceJames Lopez2018-12-1310-13/+116
| * | | Merge branch 'security-import-symlink-11-6' into 'security-11-6'John Jarvis2018-12-276-4/+62
| |\ \ \
| | * | | Fix persistent symlink in project importJames Lopez2018-12-186-4/+62
| | |/ /
| * | | Merge remote-tracking branch 'origin/security-48259-private-snippet-11-6' int...John Jarvis2018-12-279-11/+123
| |\ \ \ | | |_|/ | |/| |
| | * | Block private snippets from being embeddableMark Chao2018-12-209-11/+123
| | |/
* | | Merge branch 'security-11-6' of dev.gitlab.org:gitlab/gitlabhq into 11-6-stableJohn Jarvis2018-12-2775-177/+1047
|\ \ \ | |/ /
| * | Merge branch 'security-11-6-secret-ci-variables-exposed' into 'security-11-6'John Jarvis2018-12-2720-44/+372
| |\ \
| | * | Add CHANGELOG entryMatija Čupić2018-12-081-0/+5
| | * | Backport security fix for 11.6Matija Čupić2018-12-0819-44/+367
| | |/
| * | Merge branch 'security-11-6-user-keeps-access-to-mr-issue-when-removed-from-t...John Jarvis2018-12-276-3/+77
| |\ \
| | * | Adds validation to check if user can read projectTiago Botelho2018-12-266-3/+77
| | |/
| * | Merge branch 'security-11-6-group-cicd-settings-accessible-to-maintainer' int...John Jarvis2018-12-275-15/+56
| |\ \
| | * | Use old-style controller request paramsMatija Čupić2018-12-241-2/+2
| | * | Add CHANGELOG entryMatija Čupić2018-12-241-0/+5
| | * | Check for group admin permissionsMatija Čupić2018-12-244-15/+51
| | |/
| * | Merge branch 'security-11-6-guests-jobs-api' into 'security-11-6'John Jarvis2018-12-273-6/+36
| |\ \
| | * | Add CHANGELOG entryMatija Čupić2018-12-221-0/+5
| | * | Move pipeline auth above pipeline assignmentMatija Čupić2018-12-221-1/+1
| | * | Authorize read_pipeline before read_buildMatija Čupić2018-12-221-0/+1
| | * | Authorize read_build when listing pipeline jobsMatija Čupić2018-12-222-3/+15
| | * | Authorize read_build action when listing jobsMatija Čupić2018-12-222-3/+15
| | |/
| * | Merge branch 'security-11-6-refs-available-to-project-guest' into 'security-1...John Jarvis2018-12-273-4/+26
| |\ \
| | * | Project guests no longer are able to see refs pageTiago Botelho2018-12-103-4/+26
| | |/
| * | Merge branch 'security-11-6-fix-ssrf-lfs-project-import' into 'security-11-6'John Jarvis2018-12-272-13/+88
| |\ \
| | * | [11.6] SSRF in project imports with LFSFrancisco Javier López2018-12-272-13/+88
| |/ /
| * | Merge branch 'security-label-xss-11-6' into 'security-11-6'John Jarvis2018-12-273-1/+28
| |\ \
| | * | Escape html entities when no label foundJarka Košanová2018-12-223-1/+28
| | |/
| * | Merge branch 'ensure-that-build-token-is-always-running' into 'security-11-6'John Jarvis2018-12-277-39/+105
| |\ \
| | * | Ensure that build token is only used when runningKamil Trzciński2018-12-187-39/+105
| * | | Merge branch 'security-11-6-fix-ssrf-import-url-remote-mirror' into 'security...John Jarvis2018-12-275-5/+30
| |\ \ \
| | * | | Replaced UrlValidator with PublicUrlValidator for import_url and remote mirro...Francisco Javier López2018-12-135-5/+30
| | | |/ | | |/|
| * | | Merge branch 'security-11-6-54377-label-milestone-name-xss' into 'security-11-6'John Jarvis2018-12-263-7/+59
| |\ \ \
| | * | | Add changelog entryKushal Pandya2018-12-201-0/+5
| | * | | Escape label and milestone titles to prevent XSSKushal Pandya2018-12-202-7/+54
| | |/ /
| * | | Merge branch 'security-11-6-url-rel' into 'security-11-6'John Jarvis2018-12-263-10/+15
| |\ \ \
| | * | | Set URL rel attribute for broken URLsJan Provaznik2018-12-133-10/+15
| | |/ /
| * | | Merge branch 'security-todos_not_redacted_for_guests-11-6' into 'security-11-6'John Jarvis2018-12-2614-16/+55
| |\ \ \
| | * | | Delete confidential issue todos for guestsFelipe Artur2018-12-1714-16/+55
| | |/ /
| * | | Merge branch 'security-bvl-fix-cross-project-mr-exposure-11-6' into 'security...John Jarvis2018-12-264-10/+111
| |\ \ \ | | |/ / | |/| |
| | * | Validate projects in MR build serviceBob Van Landuyt2018-12-144-10/+111
| |/ /
* | | Merge branch '55402-broken-master-karma-test-failing-in-spec-javascripts-boar...Stan Hu2018-12-271-0/+5
* | | Update VERSION to 11.6.0v11.6.0GitLab Release Tools Bot2018-12-211-1/+1
* | | Update CHANGELOG.md for 11.6.0GitLab Release Tools Bot2018-12-21254-1277/+277
* | | Update VERSION to 11.6.0-rc9v11.6.0-rc9GitLab Release Tools Bot2018-12-191-1/+1
* | | Fix persistent symlink in project importJames Lopez2018-12-196-4/+62