summaryrefslogtreecommitdiff
path: root/changelogs
Commit message (Expand)AuthorAgeFilesLines
* Update CHANGELOG.md for 11.4.13GitLab Release Tools Bot2018-12-2819-95/+0
* Merge branch 'security-11-4' of dev.gitlab.org:gitlab/gitlabhq into 11-4-stableJohn Jarvis2018-12-272-0/+10
|\
| * Merge branch 'security-fix/security-group-user-removal-11-4' into 'security-1...John Jarvis2018-12-271-0/+5
| |\
| | * Merge branch 'security-11-4' into 'security-fix/security-group-user-removal-1...James Lopez2018-12-2715-0/+75
| | |\
| | * | Add subresources removal to member destroy serviceJames Lopez2018-12-131-0/+5
| * | | Merge remote-tracking branch 'origin/security-48259-private-snippet-11-4' int...John Jarvis2018-12-271-0/+5
| |\ \ \ | | |_|/ | |/| |
| | * | Block private snippets from being embeddableMark Chao2018-12-201-0/+5
| | |/
* | | Merge branch 'security-11-4' of dev.gitlab.org:gitlab/gitlabhq into 11-4-stableJohn Jarvis2018-12-271-0/+5
|\ \ \ | |/ /
| * | Merge branch 'security-11-4-group-cicd-settings-accessible-to-maintainer' int...John Jarvis2018-12-271-0/+5
| |\ \
| | * | Add CHANGELOG entryMatija Čupić2018-12-241-0/+5
* | | | Merge branch 'security-11-4' of dev.gitlab.org:gitlab/gitlabhq into 11-4-stableJohn Jarvis2018-12-2716-0/+80
|\ \ \ \ | |/ / /
| * | | Merge branch 'security-11-4-secret-ci-variables-exposed' into 'security-11-4'John Jarvis2018-12-272-0/+10
| |\ \ \
| | * | | Add CHANGELOG entryMatija Čupić2018-12-081-0/+5
| | * | | Backport security fix for 11.4Matija Čupić2018-12-081-0/+5
| * | | | Merge branch 'security-11-4-53543-user-keeps-access-to-mr-issue-when-removed-...John Jarvis2018-12-271-0/+5
| |\ \ \ \
| | * | | | Adds validation to check if user can read projectTiago Botelho2018-12-191-0/+5
| | | |_|/ | | |/| |
| * | | | Merge branch 'security-11-4-refs-available-to-project-guest' into 'security-1...John Jarvis2018-12-271-0/+5
| |\ \ \ \
| | * | | | Project guests no longer are able to see refs pageTiago Botelho2018-12-191-0/+5
| | |/ / /
| * | | | [11.4] Stored XSS in latest IEFrancisco Javier López2018-12-271-0/+5
| * | | | Merge branch 'security-label-xss-11-4' into 'security-11-4'John Jarvis2018-12-271-0/+5
| |\ \ \ \
| | * | | | Escape html entities when no label foundJarka Košanová2018-12-221-0/+5
| | | |_|/ | | |/| |
| * | | | Merge branch 'security-11-4-guests-jobs-api' into 'security-11-4'John Jarvis2018-12-271-0/+5
| |\ \ \ \
| | * | | | Add CHANGELOG entryMatija Čupić2018-12-221-0/+5
| | |/ / /
| * | | | Merge branch 'ensure-that-build-token-is-always-running-11-4' into 'security-...John Jarvis2018-12-271-0/+5
| |\ \ \ \
| | * | | | Ensure that build token is only used when runningKamil Trzciński2018-12-181-0/+5
| * | | | | [11.4] SSRF - Scan Internal Ports and GCP/AWS endpointsFrancisco Javier López2018-12-271-0/+5
| * | | | | Merge branch 'security-11-4-54377-label-milestone-name-xss' into 'security-11-4'John Jarvis2018-12-261-0/+5
| |\ \ \ \ \
| | * | | | | Add changelog entryKushal Pandya2018-12-201-0/+5
| | | |_|/ / | | |/| | |
| * | | | | Merge branch 'security-11-4-url-rel' into 'security-11-4'John Jarvis2018-12-261-0/+5
| |\ \ \ \ \
| | * | | | | Set URL rel attribute for broken URLsJan Provaznik2018-12-131-0/+5
| | |/ / / /
| * | | | | Merge branch 'security-todos_not_redacted_for_guests-11-4' into 'security-11-4'John Jarvis2018-12-261-0/+5
| |\ \ \ \ \
| | * | | | | Delete confidential issue todos for guestsFelipe Artur2018-12-171-0/+5
| | |/ / / /
| * | | | | Merge branch 'security-bvl-fix-cross-project-mr-exposure-11-4' into 'security...John Jarvis2018-12-261-0/+5
| |\ \ \ \ \ | | |_|_|/ / | |/| | | |
| | * | | | Validate projects in MR build serviceBob Van Landuyt2018-12-141-0/+5
| | |/ / /
| * | | | Fix persistent symlink in project importJames Lopez2018-12-181-0/+5
| |/ / /
| * | | Validate LFS hrefs before downloading themNick Thomas2018-12-121-0/+5
| | |/ | |/|
| * | Prevent a path traversal attack on global file templatesNick Thomas2018-12-051-0/+5
| |/
* | Update CHANGELOG.md for 11.4.12GitLab Release Tools Bot2018-12-201-5/+0
* | Merge branch 'security-import-symlink-11-4' into 'security-11-4'John Jarvis2018-12-201-0/+5
* | Update CHANGELOG.md for 11.4.11GitLab Release Tools Bot2018-12-131-5/+0
* | Merge branch 'security-2754-fix-lfs-import-11-4' into 'security-11-4'John Jarvis2018-12-131-0/+5
* | Update CHANGELOG.md for 11.4.10GitLab Release Tools Bot2018-12-061-5/+0
* | Merge branch 'security-54857-fix-templates-path-traversal-11-4' into 'securit...Cindy Pallares2018-12-051-0/+5
* | Update CHANGELOG.md for 11.4.9GitLab Release Tools Bot2018-12-032-10/+0
* | Merge branch 'if-53347_fix_impersonation_tokens' into 'master'Stan Hu2018-11-301-0/+5
* | Merge branch '53763-fix-encrypt-columns-data-loss' into 'master'Stan Hu2018-11-301-0/+5
* | Update CHANGELOG.md for 11.4.8GitLab Release Tools Bot2018-11-2724-122/+0
|/
* Merge branch 'security-11-4-fix-webhook-ssrf-ipv6' into 'security-11-4'Steve Azzopardi2018-11-261-0/+5
|\
| * Fix SSRF in project integrationsFrancisco Javier López2018-11-261-0/+5
* | Merge branch 'security-fix-uri-xss-applications-11-4' into 'security-11-4'Steve Azzopardi2018-11-261-0/+5
|\ \