summaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
...
| * | | | | | Add User#will_save_change_to_login? to clear reset_password_tokensSebastian Arcila Valenzuela2019-08-214-0/+71
| |/ / / / /
* | | | | | Merge branch 'security-ci-metrics-permissions-12-0' into '12-0-stable'GitLab Release Tools Bot2019-08-263-8/+64
|\ \ \ \ \ \
| * | | | | | Restrict MergeRequests#test_reports to authenticated users with read-access o...drew cimino2019-08-223-8/+64
| | |/ / / / | |/| | | |
* | | | | | Merge branch 'security-personal-snippets-12-0' into '12-0-stable'GitLab Release Tools Bot2019-08-2612-10/+77
|\ \ \ \ \ \
| * | | | | | Add direct upload support for personal snippetsJan Provaznik2019-08-2312-10/+77
| | |/ / / / | |/| | | |
* | | | | | Merge branch 'security-group-runners-permissions-12-0' into '12-0-stable'GitLab Release Tools Bot2019-08-263-43/+173
|\ \ \ \ \ \
| * | | | | | admin_group authorization for Groups::RunnersControllerdrew cimino2019-08-223-43/+173
| |/ / / / /
* | | | | | Merge branch 'security-fix-markdown-xss-12-0' into '12-0-stable'GitLab Release Tools Bot2019-08-268-13/+76
|\ \ \ \ \ \ | |/ / / / / |/| | | | |
| * | | | | Re-escape whole HTML content instead of only matchJan Provaznik2019-08-238-13/+76
|/ / / / /
* | | | | Merge branch 'jts/12-0-changelog-update' into '12-0-stable'Marin Jankovski2019-08-161-4/+3
|\ \ \ \ \ | |/ / / / |/| | | |
| * | | | Updates changelog to reflect appropriate release versionsJohn T Skarbek2019-08-121-4/+3
|/ / / /
* | | | Update VERSION to 12.0.6v12.0.6GitLab Release Tools Bot2019-08-121-1/+1
* | | | Update CHANGELOG.md for 12.0.6GitLab Release Tools Bot2019-08-121-0/+4
* | | | Update VERSION to 12.0.5v12.0.5GitLab Release Tools Bot2019-08-091-1/+1
* | | | Update CHANGELOG.md for 12.0.5GitLab Release Tools Bot2019-08-093-10/+8
* | | | Merge branch 'pokstad1-12-0-stable-patch-69973' into '12-0-stable'John Skarbek2019-08-092-1/+6
|\ \ \ \
| * | | | Update Gitaly to v1.47.2 for security fixPaul Okstad2019-08-092-1/+6
|/ / / /
* | | | Merge branch 'security-12-0-pages-api-token-recovery' into '12-0-stable'John Skarbek2019-08-092-1/+6
|\ \ \ \ | |/ / / |/| | |
| * | | Upgrade pages version to 1.6.2Vladimir Shushlin2019-08-022-1/+6
|/ / /
* | | Merge branch 'fix-docs-lint-12-0' into '12-0-stable'John Jarvis2019-08-012-2/+2
|\ \ \ | |_|/ |/| |
| * | Fix broken internal links in docsfix-docs-lint-12-0Sean McGivern2019-08-012-2/+2
|/ /
* | Update VERSION to 12.0.4v12.0.4GitLab Release Tools Bot2019-07-251-1/+1
* | Update CHANGELOG.md for 12.0.4GitLab Release Tools Bot2019-07-2510-45/+15
* | Merge branch 'security-fix-badges-leaked-to-unauthorized-users-12-0' into '12...GitLab Release Tools Bot2019-07-243-31/+101
|\ \
| * | Don't display badges when builds are restrictedFabio Pitino2019-06-273-31/+101
* | | Merge branch 'security-github-ssrf-redirect-12-0' into '12-0-stable'GitLab Release Tools Bot2019-07-246-3/+100
|\ \ \
| * | | Do not allow localhost url redirection in GitHub Integrationmanojmj2019-07-096-3/+100
| | |/ | |/|
* | | Merge branch 'security-dns-ssrf-bypass-12-0' into '12-0-stable'GitLab Release Tools Bot2019-07-244-15/+51
|\ \ \
| * | | Fix Server Side Request Forgery mitigation bypassFrancisco Javier López2019-07-044-15/+51
| |/ /
* | | Merge branch 'security-mr-pipeline-permissions-12-0' into '12-0-stable'GitLab Release Tools Bot2019-07-244-6/+102
|\ \ \
| * | | Use MergeRequest#source_project as permissions reference for MergeRequest#all...drew cimino2019-07-054-6/+102
| |/ /
* | | Merge branch 'security-60143-patch-additional-xss-issue-12.0' into '12-0-stable'GitLab Release Tools Bot2019-07-249-93/+233
|\ \ \
| * | | Extract SanitizeNodeLink and apply to WikiLinkFilterKerri Miller2019-07-089-93/+233
| |/ /
* | | Merge branch 'security-remove-take-trigger-ownership-feature-12-0' into '12-0...GitLab Release Tools Bot2019-07-2411-141/+9
|\ \ \
| * | | Drop feature to take ownership of a trigger tokenFabio Pitino2019-07-1711-141/+9
* | | | Merge branch 'security-2873-restrict-slash-commands-to-users-who-can-log-in-1...GitLab Release Tools Bot2019-07-245-0/+51
|\ \ \ \
| * | | | Restrict slash commands to users who can log inHordur Freyr Yngvason2019-07-125-0/+51
| | |/ / | |/| |
* | | | Merge branch 'security-bvl-filter-mr-params-12-0' into '12-0-stable'GitLab Release Tools Bot2019-07-244-8/+83
|\ \ \ \
| * | | | Filter params in MR build serviceBob Van Landuyt2019-07-174-8/+83
| | |/ / | |/| |
* | | | Merge branch 'security-hide_moved_issue_id-12-0' into '12-0-stable'GitLab Release Tools Bot2019-07-243-1/+44
|\ \ \ \ | |/ / / |/| | |
| * | | Do not show moved issue ids for user not authorizedFelipe Artur2019-07-153-1/+44
| |/ /
* | | Merge branch 'sh-fix-appearance-spec-failure' into 'master'Douglas Barbosa Alexandre2019-07-161-2/+1
|/ /
* | Update CHANGELOG.md for 12.0.3v12.0.3GitLab Release Tools Bot2019-07-011-0/+1
* | Merge branch 'security-support-object-storage-at-file-mover-12-0' into '12-0-...Marin Jankovski2019-07-012-54/+126
|\ \
| * | Support object storage at FileMover classOswaldo Ferreira2019-06-302-54/+126
|/ /
* | Update VERSION to 12.0.3GitLab Release Tools Bot2019-06-271-1/+1
* | Update CHANGELOG.md for 12.0.3GitLab Release Tools Bot2019-06-2711-50/+16
|/
* Merge branch 'security-notes-in-private-snippets-12-0' into '12-0-stable'GitLab Release Tools Bot2019-06-265-10/+132
|\
| * Correctly check permissions when creating snippet notesMarkus Koller2019-06-065-10/+132
* | Merge branch 'security-fp-prevent-billion-laughs-attack-12-0' into '12-0-stable'GitLab Release Tools Bot2019-06-267-8/+249
|\ \