summaryrefslogtreecommitdiff
path: root/app
Commit message (Expand)AuthorAgeFilesLines
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-11-0415-45/+104
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-11-044-29/+37
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-11-0417-41/+171
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-11-045-60/+60
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-11-041-1/+1
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-11-021-5/+8
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-11-022-2/+2
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-11-017-67/+44
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-11-013-1/+9
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-11-011-1/+1
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-11-011-1/+9
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-11-0112-6/+392
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-11-0111-8/+139
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-10-3148-797/+383
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-10-311-0/+8
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-10-3110-18/+32
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-10-3125-259/+445
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-10-312-2/+2
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-10-311-21/+0
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-10-307-34/+99
* Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-10-3070-59/+647
* Merge dev.gitlab.org@master into GitLab.com@masterYorick Peterse2019-10-3032-41/+177
|\
| * Merge branch 'security-ag-hide-private-members-in-project-member-autocomplete...GitLab Release Tools Bot2019-10-292-2/+56
| |\
| | * Pick only those groups that the viewing user has access to,Aakriti Gupta2019-09-252-2/+56
| * | Merge branch 'security-64519-nested-graphql-query-can-cause-denial-of-service...GitLab Release Tools Bot2019-10-291-5/+5
| |\ \
| | * | Check for recursion and fail if too recursivecharlieablett2019-10-231-5/+5
| * | | Improper access control allows the attacker to comment in internal commit aft...Charlie Ablett2019-10-291-0/+1
| * | | Merge branch 'security-2914-labels-visible-despite-no-access-to-issues-reposi...GitLab Release Tools Bot2019-10-292-5/+11
| |\ \ \
| | * | | Fix labels finder to filter visible issuablesEugenia Grieff2019-10-222-5/+11
| * | | | Merge branch 'security-2920-fix-notes-with-label-cross-reference' into 'master'GitLab Release Tools Bot2019-10-292-1/+4
| |\ \ \ \
| | * | | | Add milestone and label note types to cross refsEugenia Grieff2019-10-232-1/+4
| * | | | | Merge branch 'security-developer-transfer-project' into 'master'GitLab Release Tools Bot2019-10-293-1/+5
| |\ \ \ \ \
| | * | | | | Require maintainer permission to transfer projectsmanojmj2019-10-093-1/+5
| * | | | | | Merge branch 'security-stored-xss-using-find-file' into 'master'GitLab Release Tools Bot2019-10-291-1/+2
| |\ \ \ \ \ \
| | * | | | | | Sanitize search text to prevent XSSsamantha-dev2019-10-021-1/+2
| * | | | | | | Merge branch 'security-remove-leaky-401-responses-master' into 'master'GitLab Release Tools Bot2019-10-291-2/+4
| |\ \ \ \ \ \ \
| | * | | | | | | Avoid #authenticate_user! in #route_not_foundKerri Miller2019-10-091-2/+4
| | | |/ / / / / | | |/| | | | |
| * | | | | | | Merge branch 'security-bvl-validate-force-remove-branch-on-mrs-ce' into 'master'GitLab Release Tools Bot2019-10-297-8/+52
| |\ \ \ \ \ \ \
| | * | | | | | | Only assign merge params when allowedBob Van Landuyt2019-10-247-8/+52
| * | | | | | | | Merge branch 'security-wiki-rdoc-content-ce' into 'master'GitLab Release Tools Bot2019-10-292-9/+7
| |\ \ \ \ \ \ \ \
| | * | | | | | | | Pass all wiki markup formats through pipelinesLuke Duncalfe2019-10-232-9/+7
| * | | | | | | | | Merge branch 'security-mask-sentry-token-ce' into 'master'GitLab Release Tools Bot2019-10-293-4/+13
| |\ \ \ \ \ \ \ \ \
| | * | | | | | | | | Mask Sentry auth tokenRyan Cobb2019-10-163-4/+13
| | | |_|/ / / / / / | | |/| | | | | | |
| * | | | | | | | | Merge branch 'security-open-redirect-internalredirect' into 'master'GitLab Release Tools Bot2019-10-291-1/+1
| |\ \ \ \ \ \ \ \ \
| | * | | | | | | | | Use the '\A' and '\z' regex anchors in `InternalRedirect` to mitigate an Open...Joern Schneeweisz2019-10-081-1/+1
| | |/ / / / / / / /
| * | | | | | | | | Merge branch 'security-33689-post-filter-search-results-ce' into 'master'GitLab Release Tools Bot2019-10-296-2/+15
| |\ \ \ \ \ \ \ \ \
| | * | | | | | | | | Add #to_ability_name to Project & MilestoneDylan Griffith2019-10-232-0/+8
| | * | | | | | | | | Change Note#to_ability_name to 'note'Dylan Griffith2019-10-234-2/+7
| | | |_|_|_|_|_|/ / | | |/| | | | | | |
| * | | | | | | | | Return 404 on LFS request if project doesn't existIgor Drozdov2019-10-251-0/+1
* | | | | | | | | | Add latest changes from gitlab-org/gitlab@masterGitLab Bot2019-10-3011-50/+187