summaryrefslogtreecommitdiff
path: root/lib
Commit message (Expand)AuthorAgeFilesLines
* Fix uninitialized constant with GitLab Pages deployStan Hu2019-01-291-1/+1
* Merge branch 'security-fix-user-email-tag-push-leak-11-5' into 'security-11-5'Yorick Peterse2019-01-241-1/+1
* Merge branch 'security-import-path-logging-11-5' into 'security-11-5'Yorick Peterse2019-01-241-12/+25
* Merge branch 'security-import-project-visibility-11-5' into 'security-11-5'Yorick Peterse2019-01-241-1/+8
* Merge branch 'security-11-5-2769-idn-homograph-attack-1' into '11-5-stable'Yorick Peterse2019-01-243-12/+89
|\
| * Show tooltip for malicious looking linksBrett Walker2019-01-213-12/+89
* | Merge branch 'security-pipeline-trigger-tokens-exposure-11-5' into 'security-...Yorick Peterse2019-01-243-6/+38
* | Merge branch 'security-fix-regex-dos-11-5' into 'security-11-5'Yorick Peterse2019-01-241-1/+2
* | Merge branch 'security-11-5-test-permissions' into 'security-11-5'Yorick Peterse2019-01-241-3/+3
* | Merge branch 'security-fix-lfs-import-project-ssrf-forgery-11-5' into 'securi...Yorick Peterse2019-01-242-5/+7
* | Merge branch 'security-2779-fix-email-comment-permissions-check-11-5' into 's...Yorick Peterse2019-01-241-1/+1
* | Merge branch 'security-extract-pages-with-rubyzip-dev-11-5' into 'security-11-5'Yorick Peterse2019-01-243-0/+206
|/
* Merge branch 'security-2770-verify-bundle-import-files-11-5' into 'security-1...Yorick Peterse2019-01-152-0/+35
* Merge branch 'security-11-5-secret-ci-variables-exposed' into 'security-11-5'John Jarvis2018-12-273-3/+13
|\
| * Backport security fix for 11.5Matija Čupić2018-12-083-3/+13
| * Prevent a path traversal attack on global file templatesNick Thomas2018-12-054-1/+19
* | Merge branch 'security-11-5-guests-jobs-api' into 'security-11-5'John Jarvis2018-12-271-0/+5
|\ \
| * | Move pipeline auth above pipeline assignmentMatija Čupić2018-12-221-1/+1
| * | Authorize read_pipeline before read_buildMatija Čupić2018-12-221-0/+1
| * | Authorize read_build when listing pipeline jobsMatija Čupić2018-12-221-0/+2
| * | Authorize read_build action when listing jobsMatija Čupić2018-12-221-0/+2
* | | Merge branch 'security-label-xss-11-5' into 'security-11-5'John Jarvis2018-12-271-1/+5
|\ \ \
| * | | Escape html entities when no label foundJarka Košanová2018-12-221-1/+5
| |/ /
* | | Merge branch 'ensure-that-build-token-is-always-running-11-5' into 'security-...John Jarvis2018-12-274-21/+36
|\ \ \
| * | | Ensure that build token is only used when runningKamil Trzciński2018-12-184-21/+36
| | |/ | |/|
* | | Merge branch 'security-11-5-url-rel' into 'security-11-5'John Jarvis2018-12-261-6/+6
|\ \ \ | |_|/ |/| |
| * | Set URL rel attribute for broken URLsJan Provaznik2018-12-131-6/+6
* | | Update command_line_util.rb to fix rubocopJames Lopez2018-12-181-1/+1
* | | Fix persistent symlink in project importJames Lopez2018-12-181-3/+5
|/ /
* | Merge branch 'security-54857-fix-templates-path-traversal-11-5' into 'securit...Cindy Pallares2018-12-054-1/+19
* | Merge branch '53778-remove-site-statistics' into 'master'Sean McGivern2018-11-301-15/+0
* | Merge branch 'dm-batch-loader-sidekiq' into 'master'Stan Hu2018-11-301-0/+13
* | Merge branch '53763-fix-encrypt-columns-data-loss' into 'master'Stan Hu2018-11-301-0/+14
* | Merge branch 'if-53347_fix_impersonation_tokens' into 'master'Stan Hu2018-11-302-3/+7
|/
* [11.5] Fix CRLF issue in UrlValidatorFrancisco Javier López2018-11-261-5/+14
* Merge branch 'security-11-5-fix-webhook-ssrf-ipv6' into 'security-11-5'Steve Azzopardi2018-11-261-4/+8
|\
| * Fix SSRF in project integrationsFrancisco Javier López2018-11-121-4/+8
* | Update code to use API scope on PAT authJames Lopez2018-11-232-6/+47
* | Merge branch 'security-11-5-xss-in-markdown-following-unrecognized-html-eleme...Steve Azzopardi2018-11-232-1/+7
|\ \
| * | Sanitize output of SpacedLinkFilterBrett Walker2018-11-162-1/+7
* | | Merge branch 'security-11-5-stored-xss-for-environments' into 'security-11-5'Steve Azzopardi2018-11-231-2/+4
|\ \ \
| * | | Validate URI scheme also for internal URIAlessio Caiazza2018-11-161-2/+4
| |/ /
* | | Merge branch 'sh-fix-issue-54189-11-5' into 'security-11-5'Steve Azzopardi2018-11-181-0/+2
|\ \ \
| * | | Prevent templated services from being importedStan Hu2018-11-181-0/+2
| |/ /
* | | Merge branch '54011-all-files-named-index-have-their-content-rendered-as-if-t...Steve Azzopardi2018-11-161-1/+1
* | | Merge branch 'docs/rs-revert-api-version' into 'master'Evan Read2018-11-161-1/+1
|/ /
* | Merge branch 'osw-comment-on-any-line-on-diffs-w-feature-flag' into 'master'Douwe Maan2018-11-144-4/+275
* | Merge branch 'patch-31' into 'master'Stan Hu2018-11-131-1/+3
* | Merge branch 'rs-revert-api' into 'master'Nick Thomas2018-11-131-0/+34
* | Merge branch 'limit-parallel-to-100' into 'master'Grzegorz Bizon2018-11-091-1/+2