summaryrefslogtreecommitdiff
path: root/changelogs
Commit message (Expand)AuthorAgeFilesLines
* Update CHANGELOG.md for 12.1.12GitLab Release Tools Bot2019-09-2611-58/+0
* Merge branch 'security-gitaly-1-53-4' into '12-1-stable'GitLab Release Tools Bot2019-09-261-0/+5
|\
| * Fix Gitaly SearchBlobs flag RPC injectionPaul Okstad2019-09-241-0/+5
* | Merge branch 'security-sarcila-verify-saml-request-origin-12-1' into '12-1-st...GitLab Release Tools Bot2019-09-261-0/+5
|\ \
| * | Validate that SAML requests are originated from gitlabSebastian Arcila Valenzuela2019-09-161-0/+5
| |/
* | Merge branch 'security-xss-mermaid-12-1' into '12-1-stable'GitLab Release Tools Bot2019-09-261-0/+5
|\ \
| * | Upgrade mermaid to prevent xss attackRajat Jain2019-09-101-0/+5
| |/
* | Merge branch 'security-12717-fix-confidential-issue-assignee-visible-to-guest...GitLab Release Tools Bot2019-09-261-0/+5
|\ \
| * | Display only participants that user has permission to seeAlexandru Croitor2019-09-201-0/+5
| |/
* | Merge branch 'security-bypass-email-verification-using-salesforce-12-1' into ...GitLab Release Tools Bot2019-09-261-0/+5
|\ \
| * | Add checking for email_verified keyMałgorzata Ksionek2019-09-111-0/+5
| |/
* | Merge branch 'security-mermaid-block-12-1' into '12-1-stable'GitLab Release Tools Bot2019-09-261-0/+5
|\ \
| * | Only render fixed number of mermaid blocksRajat Jain2019-09-191-0/+5
| |/
* | Merge branch 'security-12718-project-milestones-disclosed-via-groups-12-1-ce'...GitLab Release Tools Bot2019-09-261-0/+6
|\ \
| * | Hide disabled project milestones in project settings on group levelAlexandru Croitor2019-09-261-0/+6
| |/
* | Merge branch 'security-64938-dont-disclose-path-12-1-ce' into '12-1-stable'GitLab Release Tools Bot2019-09-261-0/+6
|\ \
| * | Redirect user to root path after unsubscribing from private resourceAlexandru Croitor2019-09-201-0/+6
| |/
* | Merge branch 'security-12630-private-system-note-disclosed-in-graphql-12-1-ce...GitLab Release Tools Bot2019-09-261-0/+6
|\ \
| * | Add policy check if cross reference system notes are accessibleAlexandru Croitor2019-09-251-0/+6
| |/
* | Merge branch 'security-fp-stop-jobs-when-blocking-user-12-1' into '12-1-stable'GitLab Release Tools Bot2019-09-261-0/+5
|\ \
| * | Cancel all running CI jobs when user is blockedFabio Pitino2019-09-241-0/+5
| |/
* | Filter not accessible label eventsJan Provaznik2019-09-241-0/+5
|/
* Update CHANGELOG.md for 12.1.8GitLab Release Tools Bot2019-08-2821-105/+0
* Revert "Update CHANGELOG.md for 12.1.7"John Jarvis2019-08-2821-0/+105
* Update CHANGELOG.md for 12.1.7GitLab Release Tools Bot2019-08-2721-105/+0
* Avoid exposing unaccessible repo data upon GFM processingOswaldo Ferreira2019-08-261-0/+5
* Merge branch 'security-hide_merge_request_ids_on_emails-12-1' into '12-1-stable'GitLab Release Tools Bot2019-08-261-0/+5
|\
| * Prevent disclosure of merge request id via emailFelipe Artur2019-08-211-0/+5
* | Merge branch 'security-64711-fix-commit-todos-12-1' into '12-1-stable'GitLab Release Tools Bot2019-08-261-0/+5
|\ \
| * | Send TODOs for comments on commits correctlyNick Thomas2019-08-231-0/+5
| |/
* | Add captcha if there are multiple failed login attemptsMałgorzata Ksionek2019-08-261-0/+5
* | Merge branch 'security-12-1-enable-image-proxy' into '12-1-stable'GitLab Release Tools Bot2019-08-261-0/+5
|\ \
| * | Add support for using a Camo proxy serverBrett Walker2019-08-151-0/+5
* | | Merge branch 'security-61974-limit-issue-comment-size-12-1' into '12-1-stable'GitLab Release Tools Bot2019-08-262-0/+10
|\ \ \
| * | | Limit the size of issuable description and commentsAlexandru Croitor2019-08-222-0/+10
| | |/ | |/|
* | | Merge branch 'security-mr-head-pipeline-leak-12-1' into '12-1-stable'GitLab Release Tools Bot2019-08-261-0/+5
|\ \ \
| * | | Permission fix for MergeRequestsController#pipeline_statusdrew cimino2019-08-121-0/+5
| |/ /
* | | Merge branch 'security-katex-dos-12-1' into '12-1-stable'GitLab Release Tools Bot2019-08-261-0/+5
|\ \ \
| * | | Enforce max chars and max render time in markdown mathMartin Hanzel2019-08-061-0/+5
* | | | Merge branch 'security-ssrf-kubernetes-dns-12-1' into '12-1-stable'GitLab Release Tools Bot2019-08-261-0/+5
|\ \ \ \
| * | | | Override hostname when connecting via KubeclientThong Kuah2019-08-041-0/+5
| | |_|/ | |/| |
* | | | Merge branch 'security-fix-html-injection-for-label-description-ce-12-1' into...GitLab Release Tools Bot2019-08-261-0/+5
|\ \ \ \
| * | | | Fix HTML injection for label descriptionPatrick Derichs2019-08-051-0/+5
| |/ / /
* | | | Merge branch 'security-2853-prevent-comments-on-private-mrs-12-1' into '12-1-...GitLab Release Tools Bot2019-08-261-0/+3
|\ \ \ \
| * | | | Prevent unauthorised comments on merge requestsAlex Kalderimis2019-08-071-0/+3
| | |/ / | |/| |
* | | | Merge branch 'security-epic-notes-api-reveals-historical-info-ce-12-1' into '...GitLab Release Tools Bot2019-08-261-0/+5
|\ \ \ \
| * | | | Filter out old system notes for epicsPatrick Derichs2019-08-091-0/+5
| |/ / /
* | | | Merge branch 'security-fix_jira_ssrf_vulnerability-12-1' into '12-1-stable'GitLab Release Tools Bot2019-08-261-0/+5
|\ \ \ \
| * | | | Fix DNS rebind vulnerability for JIRA integrationFelipe Artur2019-08-081-0/+5
| |/ / /
| * | | Update CHANGELOG.md for 12.1.4GitLab Release Tools Bot2019-08-054-20/+0