summaryrefslogtreecommitdiff
path: root/changelogs
Commit message (Expand)AuthorAgeFilesLines
* Update CHANGELOG.md for 11.3.12GitLab Release Tools Bot2018-12-061-5/+0
* Merge branch 'security-54857-fix-templates-path-traversal-11-3' into 'securit...Cindy Pallares2018-12-051-0/+5
* Update CHANGELOG.md for 11.3.11GitLab Release Tools Bot2018-11-2633-167/+0
* Merge branch 'security-fix-uri-xss-applications-11-3' into 'security-11-3'Steve Azzopardi2018-11-261-0/+5
|\
| * Resolve reflected XSS in Ouath authorize windowJames Lopez2018-11-261-0/+5
* | [11.3] Fix CRLF issue in UrlValidatorFrancisco Javier López2018-11-261-0/+5
* | Merge branch 'security-182-update-workhorse-11-3' into 'security-11-3'Steve Azzopardi2018-11-261-0/+5
|\ \
| * | Redact sensitive information on workhorse logMark Chao2018-11-051-0/+5
* | | Merge branch 'security-11-3-fix-webhook-ssrf-ipv6' into 'security-11-3'Steve Azzopardi2018-11-261-0/+5
|\ \ \
| * | | Fix SSRF in project integrationsFrancisco Javier López2018-11-121-0/+5
| |/ /
* | | Merge branch 'security-email-change-notification-11-3' into 'security-11-3'Steve Azzopardi2018-11-261-0/+5
|\ \ \
| * | | Provide email notification on email updatesJames Lopez2018-11-121-0/+5
| |/ /
* | | [11.3] Fixed ability to comment on and edit/delete comments on locked or conf...Chantal Rollison2018-11-262-0/+10
| |/ |/|
* | Merge branch 'security-11-3-pages-toctou-race' into 'security-11-3'Steve Azzopardi2018-11-261-0/+6
|\ \
| * | Upgrade GitLab Pages to v1.1.1Alessio Caiazza2018-11-211-0/+6
* | | Merge branch 'security-fix-pat-web-access-11-3' into 'security-11-3'Steve Azzopardi2018-11-261-0/+5
|\ \ \
| * | | Update code to use API scope on PAT authJames Lopez2018-11-231-0/+5
| |/ /
* | | Merge branch 'security-11-3-xss-in-markdown-following-unrecognized-html-eleme...Steve Azzopardi2018-11-231-0/+5
|\ \ \
| * | | Sanitize output of SpacedLinkFilterBrett Walker2018-11-161-0/+5
| | |/ | |/|
* | | Merge branch 'security-mermaid-xss-11-3' into 'security-11-3'Steve Azzopardi2018-11-231-0/+5
|\ \ \
| * | | Configure mermaid to not render HTML content in diagramsWinnie Hellmann2018-11-191-0/+5
| | |/ | |/|
* | | Merge branch 'security-bvl-exposure-in-commits-list-11-3' into 'security-11-3'Steve Azzopardi2018-11-231-0/+5
|\ \ \
| * | | Don't use fragment cache on commit pageBob Van Landuyt2018-11-191-0/+5
| |/ /
* | | Merge branch 'security-issue_51301-11-3' into 'security-11-3'Steve Azzopardi2018-11-231-0/+5
|\ \ \
| * | | Fix milestone promotion authorizationFelipe Artur2018-11-141-0/+5
| | |/ | |/|
* | | Merge branch 'security-2736-prometheus-ssrf-11-3' into 'security-11-3'Steve Azzopardi2018-11-231-0/+5
|\ \ \
| * | | No redirects in prometheus servicerpereira22018-11-141-0/+5
| |/ /
* | | Merge branch 'security-11-3-stored-xss-for-environments' into 'security-11-3'Steve Azzopardi2018-11-231-0/+5
|\ \ \
| * | | Validate URI scheme also for internal URIAlessio Caiazza2018-11-141-0/+5
| |/ /
* | | Merge branch 'security-private-group-11-3' into 'security-11-3'Steve Azzopardi2018-11-231-0/+6
|\ \ \ | |_|/ |/| |
| * | Fixed read name of private groupsChantal Rollison2018-11-071-0/+6
| |/
* | Add changelog entryKushal Pandya2018-11-121-0/+5
|/
* Monkey kubeclient to not follow any redirects.Thong Kuah2018-10-261-0/+5
* Merge branch 'sh-validate-wiki-attachments-11-3' into 'security-11-3'Thiago Presa2018-10-241-0/+5
|\
| * Validate Wiki attachments are valid temporary filesStan Hu2018-10-231-0/+5
* | Merge branch 'security-11-3-2717-fix-issue-title-xss' into 'security-11-3'Jan Provaznik2018-10-241-0/+5
|\ \
| * | Add changelog entryKushal Pandya2018-10-191-0/+5
* | | Redact unsubscribe links in issuable textsJan Provaznik2018-10-231-0/+5
| |/ |/|
* | [11.3] Persist only SHA digest of PersonalAccessToken#tokenImre Farkas2018-10-231-0/+5
* | Merge branch 'security-11-3-51527-xss-in-mr-source-branch' into 'security-11-3'Thiago Presa2018-10-231-0/+5
|\ \
| * | Fix XSS in MR source branch namePaul Slaughter2018-10-121-0/+5
| |/
* | Prevent SSRF attacks in HipChat integrationStan Hu2018-10-121-0/+5
|/
* Merge branch 'security-bw-confidential-titles-through-markdown-api-11-3' into...Bob Van Landuyt2018-10-041-0/+5
|\
| * post_process markdown redered by APIBrett Walker2018-09-291-0/+5
* | Merge branch 'security-fix-leaking-private-project-namespace-11-3' into 'secu...Bob Van Landuyt2018-10-041-0/+5
|\ \
| * | Filter system notes with public and private cross referencesBrett Walker2018-10-021-0/+5
| |/
* | Add changelogOswaldo Ferreira2018-10-011-0/+5
|/
* Merge branch 'security-fj-stored-xss-in-repository-imports-11-3' into 'securi...Bob Van Landuyt2018-09-251-0/+5
|\
| * Applied changesFrancisco Javier López2018-09-171-0/+5
* | Merge branch 'security-package-json-xss-11-3' into 'security-11-3'Bob Van Landuyt2018-09-251-0/+5
|\ \