summaryrefslogtreecommitdiff
path: root/changelogs
Commit message (Expand)AuthorAgeFilesLines
* Update CHANGELOG.md for 12.2.9GitLab Release Tools Bot2019-10-2814-68/+0
* Return 404 on LFS request if project doesn't existIgor Drozdov2019-10-251-0/+5
* Merge branch 'security-bvl-validate-force-remove-branch-on-mrs-12-2-ce' into ...GitLab Release Tools Bot2019-10-241-0/+6
|\
| * Only assign merge params when allowedBob Van Landuyt2019-10-241-0/+6
* | Merge branch 'security-64519-circular-graphql-queries-12-2' into '12-2-stable'GitLab Release Tools Bot2019-10-241-0/+5
|\ \
| * | Check for recursion and fail if too recursivecharlieablett2019-10-081-0/+5
| |/
* | Improper access control allows the attacker to comment in internal commit aft...Charlie Ablett2019-10-241-0/+5
* | Merge branch 'security-2914-labels-visible-despite-no-access-to-issues-reposi...GitLab Release Tools Bot2019-10-241-0/+5
|\ \
| * | Backport for CE MREugenia Grieff2019-10-221-0/+5
| |/
* | Merge branch 'security-2920-fix-notes-with-label-cross-reference-12-2' into '...GitLab Release Tools Bot2019-10-241-0/+5
|\ \
| * | 12.2 Backport for CE MREugenia Grieff2019-10-011-0/+5
| |/
* | Merge branch 'security-ag-hide-private-members-in-project-member-autocomplete...GitLab Release Tools Bot2019-10-241-0/+3
|\ \
| * | Pick only those groups that the viewing user has access to,Aakriti Gupta2019-10-021-0/+3
| |/
* | Merge branch 'security-remove-leaky-401-responses-12.2' into '12-2-stable'GitLab Release Tools Bot2019-10-241-0/+5
|\ \
| * | Avoid #authenticate_user! in #route_not_foundKerri Miller2019-10-091-0/+5
| |/
* | Merge branch 'security-mask-sentry-token-12-2-ce' into '12-2-stable'GitLab Release Tools Bot2019-10-241-0/+4
|\ \
| * | Mask Sentry auth tokenRyan Cobb2019-10-161-0/+4
| |/
* | Merge branch 'security-stored-xss-using-find-file-12-2' into '12-2-stable'GitLab Release Tools Bot2019-10-241-0/+5
|\ \
| * | Sanitize search text to prevent XSSSamantha Ming2019-10-101-0/+5
| |/
* | Merge branch 'security-developer-transfer-project-12-2' into '12-2-stable'GitLab Release Tools Bot2019-10-241-0/+5
|\ \
| * | Require maintainer permission to transfer projectsmanojmj2019-10-111-0/+5
| |/
* | Merge branch 'security-open-redirect-internalredirect-12-2' into '12-2-stable'GitLab Release Tools Bot2019-10-241-0/+5
|\ \
| * | Add changelog entryJoern Schneeweisz2019-10-141-0/+5
| |/
* | Merge branch 'security-wiki-rdoc-content-12-2-ce' into '12-2-stable'GitLab Release Tools Bot2019-10-241-0/+5
|\ \
| * | Pass all wiki markup formats through pipelinesLuke Duncalfe2019-10-171-0/+5
| |/
* | Handle Stored XSS for Grafana URL in settingsDavid Wilkins2019-10-241-0/+5
|/
* Update CHANGELOG.md for 12.2.6GitLab Release Tools Bot2019-09-2610-53/+0
* Merge branch 'security-gitaly-1-59-3' into '12-2-stable'GitLab Release Tools Bot2019-09-261-0/+5
|\
| * Fix Gitaly SearchBlobs flag RPC injectionPaul Okstad2019-09-241-0/+5
* | Merge branch 'security-sarcila-verify-saml-request-origin-12-2' into '12-2-st...GitLab Release Tools Bot2019-09-261-0/+5
|\ \
| * | Validate that SAML requests are originated from gitlabSebastian Arcila Valenzuela2019-09-161-0/+5
| |/
* | Merge branch 'security-12717-fix-confidential-issue-assignee-visible-to-guest...GitLab Release Tools Bot2019-09-261-0/+5
|\ \
| * | Display only participants that user has permission to seeAlexandru Croitor2019-09-201-0/+5
| |/
* | Merge branch 'security-bypass-email-verification-using-salesforce-12-2' into ...GitLab Release Tools Bot2019-09-261-0/+5
|\ \
| * | Add checking for email_verified keyMałgorzata Ksionek2019-09-111-0/+5
| |/
* | Merge branch 'security-mermaid-block-12-2' into '12-2-stable'GitLab Release Tools Bot2019-09-261-0/+5
|\ \
| * | Only render fixed number of mermaid blocksRajat Jain2019-09-191-0/+5
| |/
* | Merge branch 'security-12718-project-milestones-disclosed-via-groups-12-2-ce'...GitLab Release Tools Bot2019-09-261-0/+6
|\ \
| * | Hide disabled project milestones in project settings on group levelAlexandru Croitor2019-09-261-0/+6
| |/
* | Merge branch 'security-64938-dont-disclose-path-12-2-ce' into '12-2-stable'GitLab Release Tools Bot2019-09-261-0/+6
|\ \
| * | Redirect user to root path after unsubscribing from private resourceAlexandru Croitor2019-09-201-0/+6
| |/
* | Merge branch 'security-12630-private-system-note-disclosed-in-graphql-12-2-ce...GitLab Release Tools Bot2019-09-261-0/+6
|\ \
| * | Add policy check if cross reference system notes are accessibleAlexandru Croitor2019-09-251-0/+6
| |/
* | Merge branch 'security-fp-stop-jobs-when-blocking-user-12-2' into '12-2-stable'GitLab Release Tools Bot2019-09-261-0/+5
|\ \
| * | Cancel all running CI jobs when user is blockedFabio Pitino2019-09-241-0/+5
| |/
* | Filter not accessible label eventsJan Provaznik2019-09-241-0/+5
|/
* Update CHANGELOG.md for 12.2.4GitLab Release Tools Bot2019-09-028-40/+0
* Merge branch '66803-fix-uploads-relative-link-filter' into 'master'12-2-stable-patch-4Grzegorz Bizon2019-09-021-0/+5
* Merge branch 'sh-mermaid-8.2.6' into 'master'Filipa Lacerda2019-09-021-0/+5
* Merge branch 'sh-fix-snippet-visibility-api' into 'master'Rémy Coutable2019-08-301-0/+5