summaryrefslogtreecommitdiff
path: root/lib
Commit message (Expand)AuthorAgeFilesLines
* Merge branch 'security-2770-verify-bundle-import-files-11-4' into 'security-1...Yorick Peterse2019-01-152-0/+35
* Merge branch 'security-11-4' of dev.gitlab.org:gitlab/gitlabhq into 11-4-stableJohn Jarvis2018-12-2710-31/+65
|\
| * Merge branch 'security-11-4-secret-ci-variables-exposed' into 'security-11-4'John Jarvis2018-12-273-3/+13
| |\
| | * Backport security fix for 11.4Matija Čupić2018-12-083-3/+13
| * | Merge branch 'security-label-xss-11-4' into 'security-11-4'John Jarvis2018-12-271-1/+5
| |\ \
| | * | Escape html entities when no label foundJarka Košanová2018-12-221-1/+5
| * | | Merge branch 'security-11-4-guests-jobs-api' into 'security-11-4'John Jarvis2018-12-271-0/+5
| |\ \ \
| | * | | Move pipeline auth above pipeline assignmentMatija Čupić2018-12-221-1/+1
| | * | | Authorize read_pipeline before read_buildMatija Čupić2018-12-221-0/+1
| | * | | Authorize read_build when listing pipeline jobsMatija Čupić2018-12-221-0/+2
| | * | | Authorize read_build action when listing jobsMatija Čupić2018-12-221-0/+2
| | |/ /
| * | | Merge branch 'ensure-that-build-token-is-always-running-11-4' into 'security-...John Jarvis2018-12-274-21/+36
| |\ \ \
| | * | | Ensure that build token is only used when runningKamil Trzciński2018-12-184-21/+36
| * | | | Merge branch 'security-11-4-url-rel' into 'security-11-4'John Jarvis2018-12-261-6/+6
| |\ \ \ \ | | |_|/ / | |/| | |
| | * | | Set URL rel attribute for broken URLsJan Provaznik2018-12-131-6/+6
| | | |/ | | |/|
| * | | Update command_line_util.rbJames Lopez2018-12-181-1/+1
| * | | Fix persistent symlink in project importJames Lopez2018-12-181-3/+5
| |/ /
| * | Prevent a path traversal attack on global file templatesNick Thomas2018-12-054-1/+19
| |/
* | Merge branch 'security-import-symlink-11-4' into 'security-11-4'John Jarvis2018-12-201-3/+5
* | Merge branch 'security-54857-fix-templates-path-traversal-11-4' into 'securit...Cindy Pallares2018-12-054-1/+19
* | Merge branch 'if-53347_fix_impersonation_tokens' into 'master'Stan Hu2018-11-302-3/+7
* | Merge branch '53763-fix-encrypt-columns-data-loss' into 'master'Stan Hu2018-11-301-0/+14
|/
* Merge branch 'security-11-4-fix-webhook-ssrf-ipv6' into 'security-11-4'Steve Azzopardi2018-11-261-4/+10
|\
| * Fix SSRF in project integrationsFrancisco Javier López2018-11-261-4/+10
* | [11.4] Fix CRLF issue in UrlValidatorFrancisco Javier López2018-11-261-5/+14
|/
* Merge branch 'security-fix-pat-web-access-11-4' into 'security-11-4'Steve Azzopardi2018-11-262-6/+47
|\
| * Update code to use API scope on PAT authJames Lopez2018-11-232-6/+47
* | Merge branch 'security-11-4-xss-in-markdown-following-unrecognized-html-eleme...Steve Azzopardi2018-11-232-1/+7
|\ \
| * | Sanitize output of SpacedLinkFilterBrett Walker2018-11-162-1/+7
* | | Merge branch 'security-11-4-stored-xss-for-environments' into 'security-11-4'Steve Azzopardi2018-11-231-2/+4
|\ \ \ | |_|/ |/| |
| * | Validate URI scheme also for internal URIAlessio Caiazza2018-11-151-2/+4
| |/
* | Merge branch 'sh-fix-issue-54189-11-4' into 'security-11-4'Steve Azzopardi2018-11-181-0/+2
|\ \ | |/ |/|
| * Prevent templated services from being importedStan Hu2018-11-181-0/+2
| * Merge branch 'security-11-4-junit-test-report-exposes-stacktrace' into 'secur...Jan Provaznik2018-10-231-4/+4
| |\
| | * Remove full exception stack trace from errorMatija Čupić2018-10-031-4/+4
| * | [11.4] Persist only SHA digest of PersonalAccessToken#tokenImre Farkas2018-10-234-12/+61
* | | Merge branch 'fix_pat_auth-11-4' into 'security-11-4'Robert Speicher2018-10-261-3/+1
* | | Merge branch 'sh-block-other-localhost' into 'master'Thiago Presa2018-10-241-0/+7
* | | Merge branch 'security-redact-links-11-4' into 'security-11-4'Jan Provaznik2018-10-241-0/+62
* | | Merge branch 'sh-validate-wiki-attachments-11-4' into 'security-11-4'Thiago Presa2018-10-242-2/+17
* | | Merge branch 'security-11-4-junit-test-report-exposes-stacktrace' into 'secur...Jan Provaznik2018-10-241-4/+4
* | | Merge branch 'security-if-51113-hash_tokens-11-4' into 'security-11-4'Jan Provaznik2018-10-244-12/+61
|/ /
* | Merge branch 'patch-29' into 'master'Kamil Trzciński2018-10-081-3/+6
|\ \
| * | Updates Laravel.gitlab-ci.yml templatePaul Giberson2018-10-061-3/+6
* | | Merge branch 'backport-ce-to-ee-merge' into 'master'Stan Hu2018-10-061-1/+1
|\ \ \ | |/ / |/| |
| * | Fix CE to EE merge (backport)Kamil Trzciński2018-10-051-1/+1
* | | Add timed incremental rollout to Auto DevOpsAlessio Caiazza2018-10-051-31/+57
* | | Merge branch 'master' of dev.gitlab.org:gitlab/gitlabhqBob Van Landuyt2018-10-054-5/+18
|\ \ \
| * \ \ Merge branch 'security-bw-confidential-titles-through-markdown-api' into 'mas...Bob Van Landuyt2018-10-052-4/+10
| |\ \ \
| | * | | post_process markdown redered by APIBrett Walker2018-09-292-4/+10