summaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
...
| * | Merge branch 'security-2920-fix-notes-with-label-cross-reference-12-3' into '...GitLab Release Tools Bot2019-10-244-1/+66
| |\ \
| | * | 12.3 Backport for CE MREugenia Grieff2019-10-014-1/+66
| | |/
| * | Merge branch 'security-ag-hide-private-members-in-project-member-autocomplete...GitLab Release Tools Bot2019-10-246-18/+186
| |\ \
| | * | Pick only those groups that the viewing user has access to,Aakriti Gupta2019-09-256-18/+186
| * | | Merge branch 'security-remove-leaky-401-responses-12.3' into '12-3-stable'GitLab Release Tools Bot2019-10-2412-17/+41
| |\ \ \
| | * | | Avoid #authenticate_user! in #route_not_foundKerri Miller2019-10-0912-17/+41
| |/ / / |/| | |
| * | | Merge branch 'security-mask-sentry-token-12-3-ce' into '12-3-stable'GitLab Release Tools Bot2019-10-246-4/+51
| |\ \ \
| | * | | Mask Sentry auth tokenRyan Cobb2019-10-166-4/+51
| |/ / / |/| | |
| * | | Merge branch 'security-64519-circular-graphql-queries-12-3' into '12-3-stable'GitLab Release Tools Bot2019-10-248-12/+254
| |\ \ \
| | * | | Tweak test to insulate against magic number changescharlieablett2019-10-231-0/+1
| | * | | Allow tests to ignore recursioncharlieablett2019-10-082-1/+10
| | * | | Check for recursion and fail if too recursivecharlieablett2019-10-088-12/+244
| |/ / / |/| | |
| * | | Merge branch 'security-stored-xss-using-find-file-12-3' into '12-3-stable'GitLab Release Tools Bot2019-10-243-13/+32
| |\ \ \
| | * | | Sanitize search text to prevent XSSsamantha-dev2019-10-103-13/+32
| |/ / / |/| | |
| * | | Merge branch 'security-developer-transfer-project-12-3' into '12-3-stable'GitLab Release Tools Bot2019-10-248-2/+128
| |\ \ \
| | * | | Require maintainer permission to transfer projectsmanojmj2019-10-118-2/+128
| |/ / / |/| | |
| * | | Merge branch 'security-open-redirect-internalredirect-12-3' into '12-3-stable'GitLab Release Tools Bot2019-10-243-2/+8
| |\ \ \
| | * | | Add changelog entryJoern Schneeweisz2019-10-141-0/+5
| | * | | Use the '\A' and '\z' regex anchors in `InternalRedirect` to mitigate an Open...Joern Schneeweisz2019-10-142-2/+3
| |/ / / |/| | |
| * | | Merge branch 'security-wiki-rdoc-content-12-3-ce' into '12-3-stable'GitLab Release Tools Bot2019-10-246-44/+74
| |\ \ \
| | * | | Pass all wiki markup formats through pipelinesLuke Duncalfe2019-10-176-44/+74
| |/ / / |/| | |
| * | | Merge branch 'security-xss-grafana-url-12-3' into '12-3-stable'GitLab Release Tools Bot2019-10-248-15/+186
| |\ \ \
| | * | | Handle Stored XSS for Grafana URL in settingsDavid Wilkins2019-10-248-15/+186
| |/ / /
| * | | Merge branch 'security-33689-post-filter-search-results-ce-12-3' into '12-3-s...GitLab Release Tools Bot2019-10-249-9/+44
| |\ \ \ |/ / / /
| * | | Add #to_ability_name to Project & MilestoneDylan Griffith2019-10-234-0/+24
| * | | Change Note#to_ability_name to 'note'Dylan Griffith2019-10-235-9/+20
|/ / /
* | | Merge remote-tracking branch 'dev/12-3-stable' into 12-3-stableGitLab Release Tools Bot2019-10-072-1/+5
|\ \ \
| * | | Update VERSION to 12.3.5v12.3.5GitLab Release Tools Bot2019-10-071-1/+1
| * | | Update CHANGELOG.md for 12.3.5GitLab Release Tools Bot2019-10-071-0/+4
|/ / /
* | | Merge branch '33216-quarantine-ECDSA' into 'master'Rémy Coutable2019-10-022-2/+2
* | | Update VERSION to 12.3.4v12.3.4GitLab Release Tools Bot2019-10-021-1/+1
* | | Update CHANGELOG.md for 12.3.4GitLab Release Tools Bot2019-10-021-0/+4
* | | Merge remote-tracking branch 'dev/12-3-stable' into 12-3-stableGitLab Release Tools Bot2019-10-028-3/+213
|\ \ \ | |_|/ |/| |
| * | Update VERSION to 12.3.3v12.3.3GitLab Release Tools Bot2019-10-011-1/+1
| * | Update CHANGELOG.md for 12.3.3GitLab Release Tools Bot2019-10-012-5/+7
| * | Merge branch 'security-29491-12-3-ce' into '12-3-stable'Marin Jankovski2019-10-017-2/+210
| |\ \ |/ / /
| * | EE port: Fix private feature Elasticsearch leakMark Chao2019-10-017-2/+210
|/ /
* | Merge branch 'fix_expired_gpg_key_specs' into 'master'Stan Hu2019-09-302-151/+270
* | Update VERSION to 12.3.2v12.3.2GitLab Release Tools Bot2019-09-261-1/+1
* | Update CHANGELOG.md for 12.3.2GitLab Release Tools Bot2019-09-2611-53/+16
* | Merge branch 'security-gitaly-1-65-1' into '12-3-stable'GitLab Release Tools Bot2019-09-262-1/+6
|\ \
| * | Fix Gitaly SearchBlobs flag RPC injectionPaul Okstad2019-09-232-1/+6
* | | Merge branch 'security-bypass-email-verification-using-salesforce' into '12-3...GitLab Release Tools Bot2019-09-266-26/+80
|\ \ \
| * | | Reduce change in locale fileMałgorzata Ksionek2019-09-251-1/+4884
| * | | Add checking for email_verified keyMałgorzata Ksionek2019-09-236-4908/+79
| |/ /
* | | Merge branch 'security-sarcila-verify-saml-request-origin-12-3' into '12-3-st...GitLab Release Tools Bot2019-09-2612-40/+303
|\ \ \
| * | | Validate that SAML requests are originated from gitlabSebastian Arcila Valenzuela2019-09-2012-40/+303
* | | | Merge branch 'security-mermaid-block' into '12-3-stable'GitLab Release Tools Bot2019-09-263-1/+48
|\ \ \ \
| * | | | Only render fixed number of mermaid blocksRajat Jain2019-09-133-1/+48
* | | | | Merge branch 'security-12717-fix-confidential-issue-assignee-visible-to-guest...GitLab Release Tools Bot2019-09-263-1/+47
|\ \ \ \ \