summaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* Update VERSION to 11.7.8v11.7.8GitLab Release Tools Bot2019-03-261-1/+1
* Update CHANGELOG.md for 11.7.8GitLab Release Tools Bot2019-03-268-35/+13
* Merge branch 'security-55503-fix-pdf-js-11-7' into '11-7-stable'Yorick Peterse2019-03-268-32169/+50870
|\
| * Updated PDF.js to 2.0.943Natalia Tepluhina2019-03-208-32169/+50870
* | Merge branch 'security-mass-assignment-on-project-update-11-7' into '11-7-sta...Yorick Peterse2019-03-263-5/+30
|\ \
| * | Refactor specs according to the code reviewMałgorzata Ksionek2019-03-261-1/+1
| * | Add cr remarksMałgorzata Ksionek2019-03-253-5/+5
| * | Disallow changing namespace of a project in update methodMałgorzata Ksionek2019-03-213-5/+30
* | | Merge branch 'security-milestone-labels-11-7' into '11-7-stable'GitLab Release Tools Bot2019-03-265-8/+167
|\ \ \
| * | | Check if labels are available for target issuableJarka Košanová2019-03-255-8/+167
| | |/ | |/|
* | | Merge branch 'security-use-untrusted-regexp-11-7' into '11-7-stable'GitLab Release Tools Bot2019-03-2615-96/+198
|\ \ \
| * | | Make CI refs matching to to use UntrustedRegexpKamil Trzciński2019-03-1515-96/+198
* | | | Merge branch 'security-exif-migration-11-7' into '11-7-stable'GitLab Release Tools Bot2019-03-267-1/+364
|\ \ \ \
| * | | | Rake task for removing exif from uploadsJan Provaznik2019-03-257-1/+364
| |/ / /
* | | | Merge branch 'security-2819-xss-resolve-conflicts-branch-name-11-7' into '11-...GitLab Release Tools Bot2019-03-263-1/+21
|\ \ \ \
| * | | | Fix XSS in resolve conflicts formPaul Slaughter2019-03-043-1/+21
| |/ / /
* | | | Merge branch 'security-56224-11-7' into '11-7-stable'GitLab Release Tools Bot2019-03-265-4/+47
|\ \ \ \
| * | | | Hide related branches when user does not have permissionMark Chao2019-03-205-4/+47
| | |/ / | |/| |
* | | | Merge branch 'security-disallow-guests-to-access-releases-11-7' into '11-7-st...GitLab Release Tools Bot2019-03-264-3/+46
|\ \ \ \ | |/ / / |/| | |
| * | | Disallow guest users from accessing ReleasesShinya Maeda2019-03-264-3/+46
|/ / /
* | | Update VERSION to 11.7.7v11.7.7GitLab Release Tools Bot2019-03-191-1/+1
* | | Update CHANGELOG.md for 11.7.7GitLab Release Tools Bot2019-03-193-10/+8
* | | Merge branch 'security-11-7-2826-fix-project-serialization-in-quick-actions' ...Yorick Peterse2019-03-193-1/+37
|\ \ \ | |/ / |/| |
| * | Only return `commands_changes` used in frontendHeinrich Lee Yu2019-03-183-1/+37
|/ /
* | Merge branch 'security-shared-project-private-group-11-7' into '11-7-stable'Yorick Peterse2019-03-044-11/+67
|\ \ | |/ |/|
| * Secure vulerability and add specsMałgorzata Ksionek2019-02-284-11/+67
|/
* Update VERSION to 11.7.6v11.7.6GitLab Release Tools Bot2019-02-281-1/+1
* Update CHANGELOG.md for 11.7.6GitLab Release Tools Bot2019-02-2823-112/+28
* Merge branch '11-7-security-2774-milestones-detail' into '11-7-stable'Robert Speicher2019-02-274-4/+112
|\
| * Display only informaton visible to current userJarka Košanová2019-02-274-4/+112
|/
* Merge branch 'security-id-fix-mr-visibility-11-7' into '11-7-stable'Yorick Peterse2019-02-277-213/+335
|\
| * Display the correct number of MRs a user has access toIgor Drozdov2019-02-277-213/+335
|/
* Merge branch 'security-2818_filter_impersonated_sessions-11-7' into '11-7-sta...Yorick Peterse2019-02-278-52/+38
|\
| * Remove ability to revoke active sessionImre Farkas2019-02-276-49/+7
| * Filter active sessions belonging to an admin impersonating the userImre Farkas2019-02-274-4/+32
* | Merge branch 'security-id-restricted-access-to-private-repo-11-7' into '11-7-...Yorick Peterse2019-02-275-60/+137
|\ \
| * | Forbid creating discussions for users with restricted accessIgor Drozdov2019-02-075-60/+137
| |/
* | Merge branch '11-7-security-2773-milestones-fix' into '11-7-stable'Yorick Peterse2019-02-2719-73/+187
|\ \
| * | Check issue milestone availabilityJarka Košanová2019-02-1319-73/+187
| |/
* | Merge branch 'security-tags-oracle-11-7' into '11-7-stable'Yorick Peterse2019-02-273-0/+23
|\ \
| * | Prevent Releases links API to leak tag existanceAlessio Caiazza2019-02-133-0/+23
| |/
* | Merge branch 'security-2798-fix-boards-policy-11-7' into '11-7-stable'Yorick Peterse2019-02-273-8/+19
|\ \
| * | Disable board policies when issues are disabledHeinrich Lee Yu2019-02-143-8/+19
| |/
* | Merge branch '11-7-security-2797-milestone-mrs' into '11-7-stable'Yorick Peterse2019-02-274-4/+61
|\ \
| * | Show only MRs visible to user on milestone detailJarka Košanová2019-02-144-4/+61
| |/
* | Merge branch 'security-commit-private-related-mr-11-7' into '11-7-stable'Yorick Peterse2019-02-276-6/+65
|\ \
| * | Don't allow non-members to see private related MRsPatrick Bajao2019-02-156-6/+65
| |/
* | Merge branch 'security-kubernetes-google-login-csrf-11-7' into '11-7-stable'Yorick Peterse2019-02-273-30/+67
|\ \
| * | Validate session key when authorizing with GCP to create a clusterTiger2019-02-193-30/+67
| |/
* | Merge branch 'security-50334-11-7' into '11-7-stable'Yorick Peterse2019-02-275-66/+82
|\ \