summaryrefslogtreecommitdiff
path: root/app
Commit message (Expand)AuthorAgeFilesLines
* Merge branch 'if-53347_fix_impersonation_tokens' into 'master'Stan Hu2018-11-305-17/+23
* Merge branch 'security-fix-uri-xss-applications-11-5' into 'security-11-5'Steve Azzopardi2018-11-261-1/+1
|\
| * Resolve reflected XSS in Ouath authorize windowJames Lopez2018-11-261-1/+1
* | Merge branch 'security-email-change-notification-11-5' into 'security-11-5'Steve Azzopardi2018-11-262-0/+22
|\ \
| * | Provide email notification on email updatesJames Lopez2018-11-122-0/+22
* | | [11.5] Fixed ability to comment on and edit/delete comments on locked or conf...Chantal Rollison2018-11-267-2/+23
| |/ |/|
* | Update code to use API scope on PAT authJames Lopez2018-11-2311-30/+52
* | Merge branch 'security-11-5-xss-in-markdown-following-unrecognized-html-eleme...Steve Azzopardi2018-11-231-1/+1
|\ \
| * | Sanitize output of SpacedLinkFilterBrett Walker2018-11-161-1/+1
* | | Merge branch 'security-mermaid-xss-11-5' into 'security-11-5'Steve Azzopardi2018-11-231-0/+3
|\ \ \
| * | | Configure mermaid to not render HTML content in diagramsWinnie Hellmann2018-11-191-0/+3
* | | | Merge branch 'security-bvl-exposure-in-commits-list-11-5' into 'security-11-5'Steve Azzopardi2018-11-231-53/+41
|\ \ \ \
| * | | | Don't use fragment cache on commit pageBob Van Landuyt2018-11-191-53/+41
| |/ / /
| * | | Merge branch 'security-11-5-2717-xss-username-autocomplete' into 'security-11-5'Steve Azzopardi2018-11-181-4/+11
| |\ \ \ | | |/ / | |/| |
| | * | Fix user name autocomplete XSS when name contains HTMLKushal Pandya2018-11-121-4/+11
| | |/
* | | Merge branch 'security-issue_51301-11-5' into 'security-11-5'Steve Azzopardi2018-11-233-6/+32
|\ \ \
| * | | Fix milestone promotion authorizationFelipe Artur2018-11-143-6/+32
| | |/ | |/|
* | | Merge branch 'security-2736-prometheus-ssrf-11-5' into 'security-11-5'Steve Azzopardi2018-11-231-1/+1
|\ \ \
| * | | No redirects in prometheus servicerpereira22018-11-141-1/+1
| |/ /
* | | Merge branch 'security-private-group-11-5' into 'security-11-5'Steve Azzopardi2018-11-231-0/+10
|\ \ \
| * | | Fixed read name of private groupsChantal Rollison2018-11-061-0/+10
| |/ /
* | | Merge branch 'image-discussion-ff-fix' into 'master'Filipa Lacerda2018-11-193-13/+10
* | | Merge branch 'osw-remove-comment-on-any-diff-line-ff' into 'master'Douwe Maan2018-11-191-6/+1
* | | Merge branch 'security-11-5-2717-xss-username-autocomplete' into 'security-11-5'Steve Azzopardi2018-11-181-4/+11
| |/ |/|
* | Merge branch 'ignore-environment-validation-failure' into 'master'Kamil Trzciński2018-11-151-0/+4
* | Merge branch '53882-extra-container-diff-version' into 'master'Fatih Acet2018-11-151-2/+25
* | Merge branch 'mr-expand-all-collapsed-files' into 'master'Filipa Lacerda2018-11-151-3/+15
* | Merge branch 'fix-deployment-metrics-in-mr-widget' into 'master'Kamil Trzciński2018-11-152-4/+8
* | Merge branch '53636-fix-rendering-of-any-user-filter' into 'master'11-5-stable-prepare-rc9Clement Ho2018-11-141-4/+5
* | Merge branch 'osw-comment-on-any-line-on-diffs-w-feature-flag' into 'master'Douwe Maan2018-11-148-25/+71
* | Merge branch '53918-snippet-commit-comments' into 'master'Fatih Acet2018-11-142-4/+24
* | Merge branch 'discussion-fixes-2' into 'master'Fatih Acet2018-11-142-2/+2
* | Merge branch 'dark-theme-comments' into 'master'Fatih Acet2018-11-141-0/+4
* | Merge branch 'dm-commit-email-select-options' into 'master'Stan Hu2018-11-141-1/+1
* | Merge branch '54002-activity-feed-missing-padding-in-event-note-when-a-branch...Phil Hughes2018-11-141-2/+2
* | Merge branch '53780-commit-discussion-ui' into 'master'11-5-stable-prepare-rc8Fatih Acet2018-11-135-22/+40
* | Merge branch 'archive-builds-documentation' into 'master'Achilleas Pipinellis2018-11-131-5/+5
* | Merge branch 'rs-revert-api' into 'master'Nick Thomas2018-11-131-2/+6
* | Merge branch 'align-vertical-discussion-line' into 'master'Fatih Acet2018-11-131-3/+3
* | Merge branch '_acet-discussion-redesign-fixes' into 'master'Annabel Dunstone Gray2018-11-131-4/+1
* | Merge branch 'enable-image-comments-for-renamed-files' into 'master'Filipa Lacerda2018-11-131-2/+5
* | Merge branch '53888-missing-favicon' into 'master'Phil Hughes2018-11-131-2/+2
* | Merge branch '53972-fix-fill-shards' into 'master'Stan Hu2018-11-131-6/+5
* | Merge branch '53879-kube-token-nil' into 'master'Kamil Trzciński2018-11-132-1/+3
* | Merge branch 'fix-tags-for-envs' into 'master'11-5-stable-prepare-rc6Stan Hu2018-11-121-5/+2
* | Merge branch 'sh-fix-refresh-service-deleted-branch' into 'master'Douwe Maan2018-11-121-1/+1
* | Merge branch '53768-diff-comment-action-btns' into 'master'11-5-stable-prepare-rc5Phil Hughes2018-11-122-4/+3
* | Merge branch 'fix-error-handling-bugs-in-kubernetes-integration' into 'master'Dmitriy Zaporozhets2018-11-122-3/+1
* | Merge branch 'notes-multiple-discussion-fetches' into 'master'Filipa Lacerda2018-11-121-0/+6
* | Merge branch 'always-proxy-reports' into 'master'Grzegorz Bizon2018-11-122-3/+3