Commit message (Expand) | Author | Age | Files | Lines | |
---|---|---|---|---|---|
* | Resolve conflicts in spec/mailers/notify_spec.rb | Stan Hu | 2019-03-04 | 1 | -10/+0 |
* | Resolve conflicts in app/policies/group_policy.rb | Stan Hu | 2019-03-04 | 1 | -3/+0 |
* | Merge dev master into GitLab.com master | Yorick Peterse | 2019-03-04 | 131 | -434/+1577 |
|\ | |||||
| * | Merge branch 'security-2773-milestones-fix' into 'master' | Yorick Peterse | 2019-03-04 | 19 | -73/+187 |
| |\ | |||||
| | * | Check issue milestone availability | Jarka Košanová | 2019-02-14 | 19 | -73/+187 |
| * | | Merge branch 'security-commit-private-related-mr' into 'master' | Yorick Peterse | 2019-03-04 | 6 | -6/+65 |
| |\ \ | |||||
| | * | | Add changelog for security fix | Patrick Bajao | 2019-01-28 | 1 | -0/+5 |
| | * | | Modify MergeRequestsFinder to allow filtering by commit | Patrick Bajao | 2019-01-28 | 4 | -4/+45 |
| | * | | Respond with 403 when non-member requests for private MRs | Patrick Bajao | 2019-01-28 | 2 | -2/+15 |
| * | | | Merge branch 'security-id-restricted-access-to-private-repo' into 'master' | Yorick Peterse | 2019-03-04 | 5 | -60/+137 |
| |\ \ \ | |||||
| | * | | | Forbid creating discussions for users with restricted access | Igor Drozdov | 2019-03-04 | 5 | -60/+137 |
| |/ / / | |||||
| * | | | Merge branch 'security-protect-private-repo-information' into 'master' | Yorick Peterse | 2019-03-04 | 6 | -22/+85 |
| |\ \ \ | |||||
| | * | | | Add changelog entry | Luke Duncalfe | 2019-02-21 | 1 | -0/+5 |
| | * | | | Removing sensitive properties from ProjectType | Luke Duncalfe | 2019-02-18 | 1 | -2/+0 |
| | * | | | Prevent leaking of private repo data through API | Luke Duncalfe | 2019-02-18 | 4 | -20/+80 |
| * | | | | Merge branch 'security-tags-oracle' into 'master' | Yorick Peterse | 2019-03-04 | 3 | -0/+23 |
| |\ \ \ \ | |||||
| | * | | | | Prevent Releases links API to leak tag existance | Alessio Caiazza | 2019-02-08 | 3 | -0/+23 |
| * | | | | | Merge branch 'security-2798-fix-boards-policy' into 'master' | Yorick Peterse | 2019-03-04 | 3 | -8/+19 |
| |\ \ \ \ \ | |||||
| | * | | | | | Disable board policies when issues are disabled | Heinrich Lee Yu | 2019-02-11 | 3 | -8/+19 |
| * | | | | | | Merge branch 'security-2797-milestone-mrs' into 'master' | Yorick Peterse | 2019-03-04 | 4 | -4/+61 |
| |\ \ \ \ \ \ | |||||
| | * | | | | | | Show only MRs visible to user on milestone detail | Jarka Košanová | 2019-02-14 | 4 | -4/+61 |
| | | |_|_|_|/ | | |/| | | | | |||||
| * | | | | | | Merge branch 'security-shared-project-private-group' into 'master' | Yorick Peterse | 2019-03-04 | 4 | -11/+67 |
| |\ \ \ \ \ \ | |||||
| | * | | | | | | Secure vulerability and add specs | Małgorzata Ksionek | 2019-02-28 | 5 | -11/+69 |
| * | | | | | | | Merge branch '2802-security-add-public-internal-groups-as-members-to-your-pro... | Yorick Peterse | 2019-03-04 | 10 | -13/+85 |
| |\ \ \ \ \ \ \ | |||||
| | * | | | | | | | Change policy regarding group visibility | Małgorzata Ksionek | 2019-02-20 | 10 | -13/+85 |
| * | | | | | | | | Merge branch 'security-kubernetes-local-ssrf' into 'master' | Yorick Peterse | 2019-03-04 | 5 | -1/+60 |
| |\ \ \ \ \ \ \ \ | |||||
| | * | | | | | | | | Do not allow local urls in Kubernetes form | Thong Kuah | 2019-02-21 | 5 | -1/+60 |
| | | |_|/ / / / / | | |/| | | | | | | |||||
| * | | | | | | | | Merge branch 'security-kubernetes-google-login-csrf' into 'master' | Yorick Peterse | 2019-03-04 | 3 | -30/+67 |
| |\ \ \ \ \ \ \ \ | |||||
| | * | | | | | | | | Validate session key when authorizing with GCP to create a cluster | Tiger | 2019-02-19 | 3 | -30/+67 |
| * | | | | | | | | | Merge branch 'security-56348' into 'master' | Yorick Peterse | 2019-03-04 | 5 | -2/+60 |
| |\ \ \ \ \ \ \ \ \ | |||||
| | * | | | | | | | | | Check snippet attached file to be moved is within designated directory | Mark Chao | 2019-02-21 | 5 | -0/+59 |
| | * | | | | | | | | | Align spec with actual usage | Mark Chao | 2019-02-13 | 1 | -2/+1 |
| | |/ / / / / / / / | |||||
| * | | | | | | | | | Merge branch 'security-55468-check-validity-before-querying' into 'master' | Yorick Peterse | 2019-03-04 | 3 | -19/+53 |
| |\ \ \ \ \ \ \ \ \ | |||||
| | * | | | | | | | | | Check validity of prometheus_service before query | Reuben Pereira | 2019-03-04 | 3 | -19/+53 |
| |/ / / / / / / / / | |||||
| * | | | | | | | | | Merge branch 'security-2799-emails' into 'master' | Yorick Peterse | 2019-03-04 | 5 | -17/+60 |
| |\ \ \ \ \ \ \ \ \ | |||||
| | * | | | | | | | | | Remove link after issue move when no permissions | Jarka Košanová | 2019-02-20 | 5 | -17/+60 |
| | | |/ / / / / / / | | |/| | | | | | | | |||||
| * | | | | | | | | | Merge branch 'security-osw-stop-linking-to-packages' into 'master' | Yorick Peterse | 2019-03-04 | 20 | -51/+207 |
| |\ \ \ \ \ \ \ \ \ | |||||
| | * | | | | | | | | | Add changelog | Oswaldo Ferreira | 2019-02-26 | 1 | -0/+5 |
| | * | | | | | | | | | Raise not implemented error on BaseLinker for package_url | Oswaldo Ferreira | 2019-02-25 | 1 | -0/+4 |
| | * | | | | | | | | | Stop linking to unrecognized package sources | Oswaldo Ferreira | 2019-02-21 | 19 | -51/+198 |
| | |/ / / / / / / / | |||||
| * | | | | | | | | | Merge branch 'security-50334' into 'master' | Yorick Peterse | 2019-03-04 | 5 | -66/+82 |
| |\ \ \ \ \ \ \ \ \ | |||||
| | * | | | | | | | | | Fix git clone revealing private repo's presence | Mark Chao | 2019-02-19 | 5 | -66/+82 |
| * | | | | | | | | | | Merge branch 'security-fj-diff-import-file-read-fix' into 'master' | Yorick Peterse | 2019-03-04 | 10 | -4/+103 |
| |\ \ \ \ \ \ \ \ \ \ | |||||
| | * | | | | | | | | | | Arbitrary file read via MergeRequestDiff | Francisco Javier López | 2019-03-04 | 10 | -4/+103 |
| |/ / / / / / / / / / | |||||
| * | | | | | | | | | | Merge branch 'security-mermaid' into 'master' | Yorick Peterse | 2019-03-04 | 3 | -0/+27 |
| |\ \ \ \ \ \ \ \ \ \ | |||||
| | * | | | | | | | | | | Limit number of characters allowed in mermaidjs | Rajat Jain | 2019-02-27 | 3 | -0/+27 |
| * | | | | | | | | | | | Merge branch 'security-issue_54789_2' into 'master' | Yorick Peterse | 2019-03-04 | 3 | -0/+38 |
| |\ \ \ \ \ \ \ \ \ \ \ | |||||
| | * | | | | | | | | | | | Prevent disclosing project milestone titles | Felipe Artur | 2019-02-25 | 3 | -0/+38 |
| * | | | | | | | | | | | | Merge branch 'security-2818_filter_impersonated_sessions' into 'master' | Yorick Peterse | 2019-03-04 | 8 | -52/+38 |
| |\ \ \ \ \ \ \ \ \ \ \ \ | |||||
| | * | | | | | | | | | | | | Remove ability to revoke active session | Imre Farkas | 2019-02-27 | 6 | -49/+7 |