summaryrefslogtreecommitdiff
path: root/changelogs
Commit message (Expand)AuthorAgeFilesLines
* Update CHANGELOG.md for 11.4.10GitLab Release Tools Bot2018-12-061-5/+0
* Merge branch 'security-54857-fix-templates-path-traversal-11-4' into 'securit...Cindy Pallares2018-12-051-0/+5
* Update CHANGELOG.md for 11.4.9GitLab Release Tools Bot2018-12-032-10/+0
* Merge branch 'if-53347_fix_impersonation_tokens' into 'master'Stan Hu2018-11-301-0/+5
* Merge branch '53763-fix-encrypt-columns-data-loss' into 'master'Stan Hu2018-11-301-0/+5
* Update CHANGELOG.md for 11.4.8GitLab Release Tools Bot2018-11-2724-122/+0
* Merge branch 'security-11-4-fix-webhook-ssrf-ipv6' into 'security-11-4'Steve Azzopardi2018-11-261-0/+5
|\
| * Fix SSRF in project integrationsFrancisco Javier López2018-11-261-0/+5
* | Merge branch 'security-fix-uri-xss-applications-11-4' into 'security-11-4'Steve Azzopardi2018-11-261-0/+5
|\ \
| * | Resolve reflected XSS in Ouath authorize windowJames Lopez2018-11-261-0/+5
* | | [11.4] Fix CRLF issue in UrlValidatorFrancisco Javier López2018-11-261-0/+5
| |/ |/|
* | Merge branch 'security-email-change-notification-11-4' into 'security-11-4'Steve Azzopardi2018-11-261-0/+5
|\ \ | |/ |/|
| * Provide email notification on email updatesJames Lopez2018-11-121-0/+5
* | [11.4] Fixed ability to comment on and edit/delete comments on locked or conf...Chantal Rollison2018-11-262-0/+10
* | Merge branch 'security-11-4-pages-toctou-race' into 'security-11-4'Steve Azzopardi2018-11-261-0/+6
|\ \
| * | Upgrade GitLab Pages to v1.1.1Alessio Caiazza2018-11-211-0/+6
* | | Merge branch 'security-fix-pat-web-access-11-4' into 'security-11-4'Steve Azzopardi2018-11-261-0/+5
|\ \ \
| * | | Update code to use API scope on PAT authJames Lopez2018-11-231-0/+5
| |/ /
* | | Merge branch 'security-11-4-xss-in-markdown-following-unrecognized-html-eleme...Steve Azzopardi2018-11-231-0/+5
|\ \ \
| * | | Sanitize output of SpacedLinkFilterBrett Walker2018-11-161-0/+5
* | | | Merge branch 'security-mermaid-xss-11-4' into 'security-11-4'Steve Azzopardi2018-11-231-0/+5
|\ \ \ \
| * | | | Configure mermaid to not render HTML content in diagramsWinnie Hellmann2018-11-141-0/+5
| |/ / /
* | | | Merge branch 'security-bvl-exposure-in-commits-list-11-4' into 'security-11-4'Steve Azzopardi2018-11-231-0/+5
|\ \ \ \
| * | | | Don't use fragment cache on commit pageBob Van Landuyt2018-11-191-0/+5
| | |/ / | |/| |
* | | | Merge branch 'security-issue_51301-11-4' into 'security-11-4'Steve Azzopardi2018-11-231-0/+5
|\ \ \ \
| * | | | Fix milestone promotion authorizationFelipe Artur2018-11-141-0/+5
| | |_|/ | |/| |
* | | | Merge branch 'security-2736-prometheus-ssrf-11-4' into 'security-11-4'Steve Azzopardi2018-11-231-0/+5
|\ \ \ \
| * | | | No redirects in prometheus servicerpereira22018-11-141-0/+5
| | |_|/ | |/| |
* | | | Merge branch 'security-11-4-stored-xss-for-environments' into 'security-11-4'Steve Azzopardi2018-11-231-0/+5
|\ \ \ \
| * | | | Validate URI scheme also for internal URIAlessio Caiazza2018-11-151-0/+5
| |/ / /
* | | | Merge branch 'security-private-group-11-4' into 'security-11-4'Steve Azzopardi2018-11-231-0/+6
|\ \ \ \
| * | | | Fixed read name of private groupsChantal Rollison2018-11-071-0/+6
| | |/ / | |/| |
* | | | Merge branch 'security-182-update-workhorse-11-4' into 'security-11-4'Steve Azzopardi2018-11-231-0/+5
|\ \ \ \ | |_|_|/ |/| | |
| * | | Redact sensitive information on workhorse logMark Chao2018-11-051-0/+5
| |/ /
* | | Merge branch 'security-11-4-2717-xss-username-autocomplete' into 'security-11-4'Steve Azzopardi2018-11-181-0/+5
|\ \ \ | |_|/ |/| |
| * | Add changelog entryKushal Pandya2018-11-121-0/+5
| |/
* | Merge remote-tracking branch 'dev.gitlab.org/11-4-stable' into security-11-4Winnie Hellmann2018-11-14194-982/+0
|\ \ | |/ |/|
| * Update CHANGELOG.md for 11.4.5GitLab Release Tools Bot2018-11-045-24/+0
| * Update gitlab-ui dependency to 1.8.0-hotfix.111-4-stable-patch-5Clement Ho2018-11-021-0/+5
| * Fix stage dropdown rendering only in EnglishFilipa Lacerda2018-11-021-0/+4
| * Remove duplicate escape in job sidebarFilipa Lacerda2018-11-021-0/+5
| * Merge branch '53070-fix-usage-ping-link' into 'master'Stan Hu2018-10-311-0/+5
| * Merge branch 'mr-file-tree-inline-fluid-width-fix' into 'master'Filipa Lacerda2018-10-311-0/+5
| * Update CHANGELOG.md for 11.4.2GitLab Release Tools Bot2018-10-255-25/+0
| * Merge branch 'sh-block-other-localhost' into 'master'Thiago Presa2018-10-241-0/+5
| * Merge branch 'security-11-4-2717-fix-issue-title-xss' into 'security-11-4'Jan Provaznik2018-10-241-0/+5
| * Merge branch 'security-redact-links-11-4' into 'security-11-4'Jan Provaznik2018-10-241-0/+5
| * Merge branch 'sh-validate-wiki-attachments-11-4' into 'security-11-4'Thiago Presa2018-10-241-0/+5
| * Merge branch 'security-if-51113-hash_tokens-11-4' into 'security-11-4'Jan Provaznik2018-10-241-0/+5
| * Update CHANGELOG.md for 11.4.1GitLab Release Tools Bot2018-10-232-10/+0