summaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
...
| | * Return 404 on LFS request if project doesn't existIgor Drozdov2019-10-253-1/+48
| |/
| * Merge branch 'security-bvl-validate-force-remove-branch-on-mrs-12-4-ce' into ...GitLab Release Tools Bot2019-10-2414-15/+191
| |\
| | * Only assign merge params when allowedBob Van Landuyt2019-10-2314-15/+191
| |/ |/|
| * Merge branch 'security-wiki-rdoc-content-12-4-ce' into '12-4-stable'GitLab Release Tools Bot2019-10-246-44/+74
| |\
| | * Pass all wiki markup formats through pipelinesLuke Duncalfe2019-10-236-44/+74
| |/ |/|
| * Merge branch 'security-developer-transfer-project-12-4' into '12-4-stable'GitLab Release Tools Bot2019-10-248-2/+128
| |\
| | * Require maintainer permission to transfer projectsmanojmj2019-10-238-2/+128
| |/ |/|
| * Merge branch 'security-open-redirect-internalredirect-12-4' into '12-4-stable'GitLab Release Tools Bot2019-10-243-2/+8
| |\
| | * Use the '\A' and '\z' regex anchors in `InternalRedirect` to mitigate an Open...Joern Schneeweisz2019-10-223-2/+8
| |/ |/|
| * Merge branch 'security-2914-labels-visible-despite-no-access-to-issues-reposi...GitLab Release Tools Bot2019-10-246-8/+102
| |\
| | * Fix labels finder to filter issuablesEugenia Grieff2019-10-226-8/+102
| |/ |/|
| * Merge branch 'security-2920-fix-notes-with-label-cross-reference-12-4' into '...GitLab Release Tools Bot2019-10-244-1/+66
| |\
| | * Add milestone and label note types to cross refsEugenia Grieff2019-10-244-1/+66
| |/ |/|
| * Merge branch 'security-64519-circular-graphql-queries-12-4' into '12-4-stable'GitLab Release Tools Bot2019-10-248-12/+254
| |\
| | * Tweak test to insulate against magic number changescharlieablett2019-10-231-0/+1
| | * Allow tests to ignore recursioncharlieablett2019-10-232-1/+10
| | * Check for recursion and fail if too recursivecharlieablett2019-10-238-12/+244
| |/ |/|
| * Merge branch 'security-33689-post-filter-search-results-ce-12-4' into '12-4-s...GitLab Release Tools Bot2019-10-249-9/+44
| |\
| | * Add #to_ability_name to Project & MilestoneDylan Griffith2019-10-234-0/+24
| | * Change Note#to_ability_name to 'note'Dylan Griffith2019-10-235-9/+20
| |/ |/|
| * Merge branch 'security-65756-ex-admin-attacker-can-comment-in-internalsecurit...GitLab Release Tools Bot2019-10-243-12/+42
| |\
| | * Modify changelog to be more accuratecharlieablett2019-10-231-1/+1
| | * Users without commit access cannot create notescharlieablett2019-10-232-12/+37
| | * Add changelog filecharlieablett2019-10-231-0/+5
| |/ |/|
| * Merge branch 'security-ag-hide-private-members-in-project-member-autocomplete...GitLab Release Tools Bot2019-10-246-18/+186
| |\ |/ /
| * Pick only those groups that the viewing user has access to,Aakriti Gupta2019-10-246-18/+186
|/
* Update VERSION to 12.4.0v12.4.0GitLab Release Tools Bot2019-10-221-1/+1
* Update CHANGELOG.md for 12.4.0GitLab Release Tools Bot2019-10-22296-1490/+319
* Add latest changes from gitlab-org/gitlab@12-4-stable-eeGitLab Bot2019-10-225562-49750/+261788
* Merge remote-tracking branch 'dev/12-3-stable' into 12-3-stableGitLab Release Tools Bot2019-10-072-1/+5
|\
| * Update VERSION to 12.3.5v12.3.5GitLab Release Tools Bot2019-10-071-1/+1
| * Update CHANGELOG.md for 12.3.5GitLab Release Tools Bot2019-10-071-0/+4
|/
* Merge branch '33216-quarantine-ECDSA' into 'master'Rémy Coutable2019-10-022-2/+2
* Update VERSION to 12.3.4v12.3.4GitLab Release Tools Bot2019-10-021-1/+1
* Update CHANGELOG.md for 12.3.4GitLab Release Tools Bot2019-10-021-0/+4
* Merge remote-tracking branch 'dev/12-3-stable' into 12-3-stableGitLab Release Tools Bot2019-10-028-3/+213
|\
| * Update VERSION to 12.3.3v12.3.3GitLab Release Tools Bot2019-10-011-1/+1
| * Update CHANGELOG.md for 12.3.3GitLab Release Tools Bot2019-10-012-5/+7
| * Merge branch 'security-29491-12-3-ce' into '12-3-stable'Marin Jankovski2019-10-017-2/+210
| |\ |/ /
| * EE port: Fix private feature Elasticsearch leakMark Chao2019-10-017-2/+210
|/
* Merge branch 'fix_expired_gpg_key_specs' into 'master'Stan Hu2019-09-302-151/+270
* Update VERSION to 12.3.2v12.3.2GitLab Release Tools Bot2019-09-261-1/+1
* Update CHANGELOG.md for 12.3.2GitLab Release Tools Bot2019-09-2611-53/+16
* Merge branch 'security-gitaly-1-65-1' into '12-3-stable'GitLab Release Tools Bot2019-09-262-1/+6
|\
| * Fix Gitaly SearchBlobs flag RPC injectionPaul Okstad2019-09-232-1/+6
* | Merge branch 'security-bypass-email-verification-using-salesforce' into '12-3...GitLab Release Tools Bot2019-09-266-26/+80
|\ \
| * | Reduce change in locale fileMałgorzata Ksionek2019-09-251-1/+4884
| * | Add checking for email_verified keyMałgorzata Ksionek2019-09-236-4908/+79
| |/
* | Merge branch 'security-sarcila-verify-saml-request-origin-12-3' into '12-3-st...GitLab Release Tools Bot2019-09-2612-40/+303
|\ \
| * | Validate that SAML requests are originated from gitlabSebastian Arcila Valenzuela2019-09-2012-40/+303