summaryrefslogtreecommitdiff
path: root/spec
Commit message (Expand)AuthorAgeFilesLines
* Support object storage at FileMover classOswaldo Ferreira2019-06-301-36/+83
* Merge branch 'security-notes-in-private-snippets-11-11' into '11-11-stable'GitLab Release Tools Bot2019-06-262-1/+114
|\
| * Correctly check permissions when creating snippet notesMarkus Koller2019-06-062-1/+114
* | Merge branch 'security-fp-prevent-billion-laughs-attack-11-11' into '11-11-st...GitLab Release Tools Bot2019-06-263-4/+132
|\ \
| * | Prevent Billion Laughs attackFabio Pitino2019-06-073-4/+132
| |/
* | Merge branch 'security-prevent-detection-of-merge-request-template-name-11-11...GitLab Release Tools Bot2019-06-262-29/+101
|\ \
| * | Authorize access before serving project templateLuke Duncalfe2019-06-122-29/+101
* | | Merge branch 'security-11-11-mr-head-pipeline-leak' into '11-11-stable'GitLab Release Tools Bot2019-06-261-0/+25
|\ \ \
| * | | Gate MR head_pipeline behind read_pipeline abilityMatija Čupić2019-06-121-0/+25
| |/ /
* | | Merge branch 'security-DOS_issue_comments_banzai-11-11' into '11-11-stable'GitLab Release Tools Bot2019-06-261-0/+5
|\ \ \
| * | | Fix DOS when rendering issue/MR commentsMario de la Ossa2019-06-131-0/+5
| |/ /
* | | Merge branch 'security-persist-tmp-snippet-uploads-11-11' into '11-11-stable'GitLab Release Tools Bot2019-06-265-86/+148
|\ \ \
| * | | Persist tmp snippet uploadsOswaldo Ferreira2019-06-175-86/+148
| |/ /
* | | Merge branch 'security-59581-related-merge-requests-count-11-11' into '11-11-...GitLab Release Tools Bot2019-06-262-4/+41
|\ \ \
| * | | Expose merge requests count based on user accessAlexandru Croitor2019-06-182-4/+41
| |/ /
* | | Merge branch 'security-bvl-enforce-graphql-type-authorization-11-11' into '11...GitLab Release Tools Bot2019-06-265-38/+59
|\ \ \
| * | | Fix failing auhtorizations in GraphQLBob Van Landuyt2019-06-205-38/+59
| |/ /
* | | Merge branch 'security-2858-fix-color-validation-11-11' into '11-11-stable'GitLab Release Tools Bot2019-06-261-0/+43
|\ \ \
| * | | Fix color validation regexHeinrich Lee Yu2019-06-251-0/+43
| |/ /
* | | Merge branch 'security-fix-issue-59379-11-11' into '11-11-stable'GitLab Release Tools Bot2019-06-262-1/+7
|\ \ \
| * | | Disable Rails SQL query cache when applying service templatesStan Hu2019-06-252-1/+7
| |/ /
* | | Merge branch '11-11-stable-patch-4' into '11-11-stable'Marin Jankovski2019-06-264-6/+107
|\ \ \
| * \ \ Merge branch '29769-11-11-port' into '11-11-stable-patch-4'Marin Jankovski2019-06-263-6/+69
| |\ \ \
| | * | | Fix IDE commit to use start_refPaul Slaughter2019-06-263-6/+69
| | |/ /
| * | | Merge branch 'sh-fix-fogbugz-import' into 'master'James Lopez2019-06-261-0/+38
| |/ /
* | | Add client code to call GetObjectDirectorySize RPCpb-quarantine-size-check-11-11-cePatrick Bajao2019-06-252-0/+23
|/ /
* | Merge branch 'sh-fix-openid-connect-defaults' into 'master'Ash McKenzie2019-06-101-0/+8
* | Merge branch 'revert-86900f00' into 'master'Grzegorz Bizon2019-06-105-15/+15
* | Merge branch '62713-fix-uninstalling-cluster-apps' into 'master'Douglas Barbosa Alexandre2019-06-101-0/+24
* | Merge branch 'revert-git-depth-for-merge-request' into 'master'Kamil Trzciński2019-06-101-19/+3
* | Merge branch 'sh-project-import-visibility-error' into 'master'Douglas Barbosa Alexandre2019-06-101-0/+13
|/
* Merge branch 'sh-fix-import-url-update' into 'master'11-11-stable-patch-1Thong Kuah2019-06-041-0/+12
* Merge branch '11-11-stable' into 11-11-stable-patch-1Stan Hu2019-06-0446-130/+955
|\
| * Add DNS rebinding protection settingsOswaldo Ferreira2019-05-294-1/+101
| * Merge branch 'security-60143-address-xss-issue-in-wiki-links' into '11-11-sta...GitLab Release Tools Bot2019-05-281-0/+42
| |\
| | * Reject slug+uri concat if slug is deemed unsafeKerri Miller2019-05-271-0/+42
| * | Fix persistent XSS in note objectsTiger2019-05-284-2/+30
| * | Merge branch 'security-fix-project-existence-disclosure-11-11' into '11-11-st...GitLab Release Tools Bot2019-05-281-14/+18
| |\ \
| | * | Fix url redaction for issue linksPatrick Derichs2019-05-031-14/+18
| * | | Merge branch 'security-60039-11-11' into '11-11-stable'GitLab Release Tools Bot2019-05-285-31/+106
| |\ \ \
| | * | | Validate MR branch namesMark Chao2019-05-065-31/+106
| | |/ /
| * | | Merge branch 'security-unsubscribing-from-issue-11-11' into '11-11-stable'GitLab Release Tools Bot2019-05-281-10/+99
| |\ \ \
| | * | | Hide issue title on unsubscribe for anonymous usersAlexandru Croitor2019-05-161-10/+99
| * | | | Merge branch 'security-fix-confidential-issue-label-visibility-11-11' into '1...GitLab Release Tools Bot2019-05-281-0/+34
| |\ \ \ \
| | * | | | Fix confidential issue label disclosure on milestone viewPatrick Derichs2019-05-171-0/+34
| * | | | | Merge branch 'security-id-leaked-password-in-import-url-frontend-11-11' into ...GitLab Release Tools Bot2019-05-284-2/+105
| |\ \ \ \ \
| | * | | | | Handling password on import by url pageSam Bigelow2019-05-211-2/+12
| | * | | | | Hide password on import by url formIgor Drozdov2019-05-213-0/+93
| | |/ / / /
| * | | | | Merge branch 'security-fix_milestones_search_api_leak-11-11' into '11-11-stable'GitLab Release Tools Bot2019-05-283-4/+83
| |\ \ \ \ \
| | * | | | | Resolve: Milestones leaked via search APIFelipe Artur2019-05-213-4/+83