summaryrefslogtreecommitdiff
Commit message (Expand)AuthorAgeFilesLines
* Merge branch 'security-personal-snippets' into 'master'GitLab Release Tools Bot2019-08-2912-10/+77
|\
| * Add direct upload support for personal snippetsJan Provaznik2019-08-2312-10/+77
* | Merge branch 'security-fix-html-injection-for-label-description-ce-master' in...GitLab Release Tools Bot2019-08-295-3/+29
|\ \
| * | Fix HTML injection for label descriptionPatrick Derichs2019-08-055-3/+29
* | | Merge branch 'security-fix_jira_ssrf_vulnerability' into 'master'GitLab Release Tools Bot2019-08-294-1/+82
|\ \ \
| * | | Fix DNS rebind vulnerability for JIRA integrationFelipe Artur2019-08-084-1/+82
* | | | Merge branch 'security-61974-limit-issue-comment-size' into 'master'GitLab Release Tools Bot2019-08-2914-19/+78
|\ \ \ \
| * | | | Limit the size of issuable description and commentsAlexandru Croitor2019-08-2214-19/+78
* | | | | Merge branch 'security-59549-add-capcha-for-failed-logins' into 'master'GitLab Release Tools Bot2019-08-2920-32/+307
|\ \ \ \ \
| * | | | | Add captcha if there are multiple failed login attemptsMaƂgorzata Ksionek2019-07-3120-32/+307
* | | | | | Merge branch 'security-mr-head-pipeline-leak' into 'master'GitLab Release Tools Bot2019-08-293-5/+39
|\ \ \ \ \ \
| * | | | | | Permission fix for MergeRequestsController#pipeline_statusdrew cimino2019-08-123-5/+39
* | | | | | | Merge branch 'security-katex-dos-master' into 'master'GitLab Release Tools Bot2019-08-294-23/+143
|\ \ \ \ \ \ \
| * | | | | | | Enforce max chars and max render time in markdown mathMartin Hanzel2019-08-064-23/+143
| | |_|_|/ / / | |/| | | | |
* | | | | | | Merge branch 'security-project-import-bypass' into 'master'GitLab Release Tools Bot2019-08-295-26/+244
|\ \ \ \ \ \ \
| * | | | | | | Fix project import restricted visibility bypassGeorge Koltsov2019-08-155-26/+244
| |/ / / / / /
* | | | | | | Merge branch 'security-hide_merge_request_ids_on_emails' into 'master'GitLab Release Tools Bot2019-08-295-18/+89
|\ \ \ \ \ \ \
| * | | | | | | Prevent disclosure of merge request id via emailFelipe Artur2019-08-195-18/+89
| |/ / / / / /
* | | | | | | Merge branch 'security-id-filter-timeline-activities-for-guests' into 'master'GitLab Release Tools Bot2019-08-292-1/+6
|\ \ \ \ \ \ \
| * | | | | | | Add merge note type as cross referenceIgor Drozdov2019-08-132-1/+6
* | | | | | | | Merge branch 'security-group-runners-permissions' into 'master'GitLab Release Tools Bot2019-08-293-43/+173
|\ \ \ \ \ \ \ \
| * | | | | | | | admin_group authorization for Groups::RunnersControllerdrew cimino2019-08-223-43/+173
* | | | | | | | | Merge branch 'security-ci-metrics-permissions' into 'master'GitLab Release Tools Bot2019-08-293-8/+64
|\ \ \ \ \ \ \ \ \
| * | | | | | | | | Restrict MergeRequests#test_reports to authenticated users with read-access o...drew cimino2019-08-223-8/+64
* | | | | | | | | | Merge branch 'security-sarcila-fix-weak-session-management' into 'master'GitLab Release Tools Bot2019-08-294-0/+71
|\ \ \ \ \ \ \ \ \ \
| * | | | | | | | | | Add User#will_save_change_to_login? to clear reset_password_tokensSebastian Arcila Valenzuela2019-08-214-0/+71
* | | | | | | | | | | Merge branch 'security-add-job-activity-limit-ce' into 'master'GitLab Release Tools Bot2019-08-295-2/+43
|\ \ \ \ \ \ \ \ \ \ \
| * | | | | | | | | | | Add active_jobs_limit to plans tableFabio Pitino2019-08-215-2/+43
* | | | | | | | | | | | Merge branch 'security-fix-markdown-xss' into 'master'GitLab Release Tools Bot2019-08-298-13/+76
|\ \ \ \ \ \ \ \ \ \ \ \
| * | | | | | | | | | | | Re-escape whole HTML content instead of only matchJan Provaznik2019-08-238-13/+76
* | | | | | | | | | | | | Merge branch 'security-exposed-default-branch' into 'master'GitLab Release Tools Bot2019-08-294-2/+97
|\ \ \ \ \ \ \ \ \ \ \ \ \
| * | | | | | | | | | | | | Avoid exposing unaccessible repo data upon GFM processingOswaldo Ferreira2019-08-214-2/+97
* | | | | | | | | | | | | | Merge branch 'security-ssrf-kubernetes-dns-12-3' into 'master'GitLab Release Tools Bot2019-08-295-18/+269
|\ \ \ \ \ \ \ \ \ \ \ \ \ \
| * | | | | | | | | | | | | | Column was renamed in 12.2Thong Kuah2019-08-212-2/+2
| * | | | | | | | | | | | | | Override hostname when connecting via KubeclientThong Kuah2019-08-215-18/+269
| | |_|_|_|/ / / / / / / / / | |/| | | | | | | | | | | |
* | | | | | | | | | | | | | Merge branch 'security-64711-fix-commit-todos' into 'master'GitLab Release Tools Bot2019-08-293-20/+112
|\ \ \ \ \ \ \ \ \ \ \ \ \ \
| * | | | | | | | | | | | | | Send TODOs for comments on commits correctlyNick Thomas2019-08-233-20/+112
* | | | | | | | | | | | | | | Merge branch 'security-gitaly-1.61.0' into 'master'GitLab Release Tools Bot2019-08-292-1/+6
|\ \ \ \ \ \ \ \ \ \ \ \ \ \ \
| * | | | | | | | | | | | | | | Use Gitaly 1.61.0Jacob Vosmaer2019-08-262-1/+6
* | | | | | | | | | | | | | | | Update CHANGELOG.md for 12.2.3GitLab Release Tools Bot2019-08-281-0/+28
* | | | | | | | | | | | | | | | Update CHANGELOG.md for 12.2.2GitLab Release Tools Bot2019-08-271-0/+28
* | | | | | | | | | | | | | | | Update CHANGELOG.md for 12.0.7GitLab Release Tools Bot2019-08-271-0/+28
|/ / / / / / / / / / / / / / /
* | | | | | | | | | | | | | | Merge branch 'renovate/gitlab-packages' into 'master'Kushal Pandya2019-08-262-5/+5
|\ \ \ \ \ \ \ \ \ \ \ \ \ \ \
| * | | | | | | | | | | | | | | Update dependency @gitlab/svgs to ^1.70.0Lukas Eipert2019-08-232-5/+5
* | | | | | | | | | | | | | | | Merge branch 'sh-upgrade-ruby-prof' into 'master'Ash McKenzie2019-08-262-3/+3
|\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \
| * | | | | | | | | | | | | | | | Bump ruby-prof to 1.0.0sh-upgrade-ruby-profStan Hu2019-08-242-3/+3
* | | | | | | | | | | | | | | | | Merge branch 'add-unleash-gem' into 'master'Thong Kuah2019-08-262-0/+5
|\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \
| * | | | | | | | | | | | | | | | | Install Unleash Client GemJason Goodman2019-08-262-0/+5
|/ / / / / / / / / / / / / / / / /
* | | | | | | | | | | | | | | | | Merge branch 'ee-10586-geo-object-storage-replication' into 'master'Ash McKenzie2019-08-261-0/+4
|\ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \ \
| * | | | | | | | | | | | | | | | | Backport expired job artifact traitee-10586-geo-object-storage-replicationGabriel Mazetto2019-08-241-0/+4
| |/ / / / / / / / / / / / / / / /