summaryrefslogtreecommitdiff
path: root/app
Commit message (Expand)AuthorAgeFilesLines
* Merge branch 'security-55503-fix-pdf-js-11-8' into '11-8-stable'Yorick Peterse2019-03-261-1/+1
|\
| * Updated PDF.js to 2.0.943Natalia Tepluhina2019-03-201-1/+1
* | Merge branch 'security-mass-assignment-on-project-update-11-8' into '11-8-sta...GitLab Release Tools Bot2019-03-261-5/+8
|\ \
| * | Add cr remarksMałgorzata Ksionek2019-03-251-3/+3
| * | Disallow changing namespace of a project in update methodMałgorzata Ksionek2019-03-211-5/+8
| |/
* | Merge branch 'security-milestone-labels-11-8' into '11-8-stable'GitLab Release Tools Bot2019-03-263-8/+76
|\ \
| * | Check if labels are available for target issuableJarka Košanová2019-03-253-8/+76
| |/
* | Merge branch 'security-2819-xss-resolve-conflicts-branch-name-11-8' into '11-...GitLab Release Tools Bot2019-03-261-1/+1
|\ \
| * | Fix XSS in resolve conflicts formPaul Slaughter2019-03-141-1/+1
* | | Merge branch 'security-56224-11-8' into '11-8-stable'GitLab Release Tools Bot2019-03-263-3/+7
|\ \ \
| * | | Hide related branches when user does not have permissionMark Chao2019-03-203-3/+7
| | |/ | |/|
* | | Disallow guest users from accessing ReleasesShinya Maeda2019-03-261-1/+1
|/ /
* | Only return `commands_changes` used in frontendHeinrich Lee Yu2019-03-181-1/+1
|/
* Merge branch 'modify_group_policy' into 'master'Rémy Coutable2019-03-131-1/+2
* Secure vulerability and add specsMałgorzata Ksionek2019-03-121-1/+0
* Merge branch 'jc-fix-set-project-writable' into 'master'Douglas Barbosa Alexandre2019-03-111-1/+1
* Merge branch '58149-fix-read-list-board-policy' into 'master'Nick Thomas2019-03-111-0/+1
* Merge branch 'ps-remove-mr-widget-section-padding' into 'master'Annabel Dunstone Gray2019-03-112-2/+1
* Display only informaton visible to current userJarka Košanová2019-02-272-2/+14
* Display the correct number of MRs a user has access toIgor Drozdov2019-02-275-14/+21
* Merge branch 'security-2818_filter_impersonated_sessions-11-8' into '11-8-sta...Yorick Peterse2019-02-273-18/+5
|\
| * Remove ability to revoke active sessionImre Farkas2019-02-272-15/+0
| * Filter active sessions belonging to an admin impersonating the userImre Farkas2019-02-272-3/+5
* | Merge branch '11-8-security-2773-milestones-fix' into '11-8-stable'Yorick Peterse2019-02-275-5/+24
|\ \
| * | Check issue milestone availabilityJarka Košanová2019-02-135-5/+24
* | | Merge branch 'security-2798-fix-boards-policy-11-8' into '11-8-stable'Yorick Peterse2019-02-271-0/+2
|\ \ \
| * | | Disable board policies when issues are disabledHeinrich Lee Yu2019-02-141-0/+2
* | | | Merge branch '11-8-security-2797-milestone-mrs' into '11-8-stable'Yorick Peterse2019-02-272-3/+10
|\ \ \ \
| * | | | Show only MRs visible to user on milestone detailJarka Košanová2019-02-142-3/+10
| |/ / /
* | | | Merge branch 'security-commit-private-related-mr-11-8' into '11-8-stable'Yorick Peterse2019-02-272-2/+13
|\ \ \ \
| * | | | Don't allow non-members to see private related MRsPatrick Bajao2019-02-152-2/+13
* | | | | Merge branch 'security-kubernetes-google-login-csrf-11-8' into '11-8-stable'Yorick Peterse2019-02-271-11/+21
|\ \ \ \ \
| * | | | | Validate session key when authorizing with GCP to create a clusterTiger2019-02-191-11/+21
* | | | | | Merge branch 'security-56348-11-8' into '11-8-stable'Yorick Peterse2019-02-271-0/+8
|\ \ \ \ \ \
| * | | | | | Check snippet attached file to be moved is within designated directoryMark Chao2019-02-211-0/+8
| |/ / / / /
* | | | | | Check validity of prometheus_service before queryReuben Pereira2019-02-271-1/+5
* | | | | | Merge branch 'security-protect-private-repo-information-11-8' into '11-8-stable'Yorick Peterse2019-02-271-2/+0
|\ \ \ \ \ \
| * | | | | | Removing sensitive properties from ProjectTypeLuke Duncalfe2019-02-201-2/+0
* | | | | | | Arbitrary file read via MergeRequestDiffFrancisco Javier López2019-02-273-1/+12
* | | | | | | Merge branch '11-8-security-2799-emails' into '11-8-stable'Yorick Peterse2019-02-273-4/+12
|\ \ \ \ \ \ \
| * | | | | | | Remove link after issue move when no permissionsJarka Košanová2019-02-223-4/+12
| | |_|_|_|_|/ | |/| | | | |
* | | | | | | Merge branch 'security-kubernetes-local-ssrf-11-8' into '11-8-stable'Yorick Peterse2019-02-271-1/+1
|\ \ \ \ \ \ \
| * | | | | | | Do not allow local urls in Kubernetes formThong Kuah2019-02-211-1/+1
| |/ / / / / /
* | | | | | | Merge branch 'security-add-public-internal-groups-as-members-to-your-project-...Yorick Peterse2019-02-272-4/+11
|\ \ \ \ \ \ \
| * | | | | | | Change policy regarding group visibilityMałgorzata Ksionek2019-02-202-4/+11
| | |/ / / / / | |/| | | | |
* | | | | | | Merge branch 'security-osw-stop-linking-to-packages-11-8' into '11-8-stable'Yorick Peterse2019-02-271-5/+0
|\ \ \ \ \ \ \
| * | | | | | | Stop linking to unrecognized package sourcesOswaldo Ferreira2019-02-241-5/+0
| | |/ / / / / | |/| | | | |
* | | | | | | Merge branch 'security-issue_54789_2-11-8' into '11-8-stable'Yorick Peterse2019-02-271-0/+2
|\ \ \ \ \ \ \
| * | | | | | | Prevent disclosing project milestone titlesFelipe Artur2019-02-251-0/+2
| |/ / / / / /
* | | | | | | Limit number of characters allowed in mermaidjsRajat Jain2019-02-271-0/+19
|/ / / / / /