summaryrefslogtreecommitdiff
path: root/lib
Commit message (Expand)AuthorAgeFilesLines
* Merge branch 'security-11-5-secret-ci-variables-exposed' into 'security-11-5'John Jarvis2018-12-273-3/+13
|\
| * Backport security fix for 11.5Matija Čupić2018-12-083-3/+13
| * Prevent a path traversal attack on global file templatesNick Thomas2018-12-054-1/+19
* | Merge branch 'security-11-5-guests-jobs-api' into 'security-11-5'John Jarvis2018-12-271-0/+5
|\ \
| * | Move pipeline auth above pipeline assignmentMatija Čupić2018-12-221-1/+1
| * | Authorize read_pipeline before read_buildMatija Čupić2018-12-221-0/+1
| * | Authorize read_build when listing pipeline jobsMatija Čupić2018-12-221-0/+2
| * | Authorize read_build action when listing jobsMatija Čupić2018-12-221-0/+2
* | | Merge branch 'security-label-xss-11-5' into 'security-11-5'John Jarvis2018-12-271-1/+5
|\ \ \
| * | | Escape html entities when no label foundJarka Košanová2018-12-221-1/+5
| |/ /
* | | Merge branch 'ensure-that-build-token-is-always-running-11-5' into 'security-...John Jarvis2018-12-274-21/+36
|\ \ \
| * | | Ensure that build token is only used when runningKamil Trzciński2018-12-184-21/+36
| | |/ | |/|
* | | Merge branch 'security-11-5-url-rel' into 'security-11-5'John Jarvis2018-12-261-6/+6
|\ \ \ | |_|/ |/| |
| * | Set URL rel attribute for broken URLsJan Provaznik2018-12-131-6/+6
* | | Update command_line_util.rb to fix rubocopJames Lopez2018-12-181-1/+1
* | | Fix persistent symlink in project importJames Lopez2018-12-181-3/+5
|/ /
* | Merge branch 'security-54857-fix-templates-path-traversal-11-5' into 'securit...Cindy Pallares2018-12-054-1/+19
* | Merge branch '53778-remove-site-statistics' into 'master'Sean McGivern2018-11-301-15/+0
* | Merge branch 'dm-batch-loader-sidekiq' into 'master'Stan Hu2018-11-301-0/+13
* | Merge branch '53763-fix-encrypt-columns-data-loss' into 'master'Stan Hu2018-11-301-0/+14
* | Merge branch 'if-53347_fix_impersonation_tokens' into 'master'Stan Hu2018-11-302-3/+7
|/
* [11.5] Fix CRLF issue in UrlValidatorFrancisco Javier López2018-11-261-5/+14
* Merge branch 'security-11-5-fix-webhook-ssrf-ipv6' into 'security-11-5'Steve Azzopardi2018-11-261-4/+8
|\
| * Fix SSRF in project integrationsFrancisco Javier López2018-11-121-4/+8
* | Update code to use API scope on PAT authJames Lopez2018-11-232-6/+47
* | Merge branch 'security-11-5-xss-in-markdown-following-unrecognized-html-eleme...Steve Azzopardi2018-11-232-1/+7
|\ \
| * | Sanitize output of SpacedLinkFilterBrett Walker2018-11-162-1/+7
* | | Merge branch 'security-11-5-stored-xss-for-environments' into 'security-11-5'Steve Azzopardi2018-11-231-2/+4
|\ \ \
| * | | Validate URI scheme also for internal URIAlessio Caiazza2018-11-161-2/+4
| |/ /
* | | Merge branch 'sh-fix-issue-54189-11-5' into 'security-11-5'Steve Azzopardi2018-11-181-0/+2
|\ \ \
| * | | Prevent templated services from being importedStan Hu2018-11-181-0/+2
| |/ /
* | | Merge branch '54011-all-files-named-index-have-their-content-rendered-as-if-t...Steve Azzopardi2018-11-161-1/+1
* | | Merge branch 'docs/rs-revert-api-version' into 'master'Evan Read2018-11-161-1/+1
|/ /
* | Merge branch 'osw-comment-on-any-line-on-diffs-w-feature-flag' into 'master'Douwe Maan2018-11-144-4/+275
* | Merge branch 'patch-31' into 'master'Stan Hu2018-11-131-1/+3
* | Merge branch 'rs-revert-api' into 'master'Nick Thomas2018-11-131-0/+34
* | Merge branch 'limit-parallel-to-100' into 'master'Grzegorz Bizon2018-11-091-1/+2
* | Merge branch 'osw-revert-comment-in-any-diff-line' into 'master'Sean McGivern2018-11-084-275/+4
* | Merge branch 'sh-paginate-bitbucket-server-imports' into 'master'Douglas Barbosa Alexandre2018-11-073-10/+49
|\ \
| * | Paginate Bitbucket Server importer projectsStan Hu2018-11-073-10/+49
* | | Merge branch 'jira-ping-differentiate-cloud' into 'master'Sean McGivern2018-11-071-1/+17
|\ \ \
| * | | Usage ping - Differentiate Jira Server and Cloudjira-ping-differentiate-cloudMario de la Ossa2018-11-071-1/+17
* | | | Allow limiting quick actions to executeBob Van Landuyt2018-11-071-5/+9
* | | | Apply patches when creating MR via emailBob Van Landuyt2018-11-076-2/+155
* | | | Merge branch 'fj-41213-api-update-submodule-commit' into 'master'Sean McGivern2018-11-074-0/+88
|\ \ \ \
| * | | | Add submodule update API endpointFrancisco Javier López2018-11-074-0/+88
* | | | | Merge branch 'max_retries_when' into 'master'Grzegorz Bizon2018-11-073-8/+115
|\ \ \ \ \
| * | | | | use Ci::Build instead of CommitStatus as per feedbackMarkus Doits2018-11-071-1/+1
| * | | | | small fixes to doc and remove on whitespace noiseMarkus Doits2018-11-071-2/+0
| * | | | | refactoring after latest feedbackMarkus Doits2018-11-071-1/+15