summaryrefslogtreecommitdiff
path: root/spec
Commit message (Expand)AuthorAgeFilesLines
* Merge branch 'security-2770-verify-bundle-import-files-11-5' into 'security-1...Yorick Peterse2019-01-153-5/+39
* Merge branch 'security-11-5' of dev.gitlab.org:gitlab/gitlabhq into 11-5-stableJohn Jarvis2018-12-276-7/+155
|\
| * Merge branch 'security-fix/security-group-user-removal-11-5' into 'security-1...John Jarvis2018-12-273-7/+59
| |\
| | * Merge branch 'security-11-5' into 'security-fix/security-group-user-removal-1...James Lopez2018-12-2736-86/+818
| | |\
| | * | Add subresources removal to member destroy serviceJames Lopez2018-12-133-7/+59
| * | | Merge remote-tracking branch 'origin/security-48259-private-snippet-11-5' int...John Jarvis2018-12-273-0/+96
| |\ \ \ | | |_|/ | |/| |
| | * | Block private snippets from being embeddableMark Chao2018-12-203-0/+96
| | |/
* | | Merge branch 'security-11-5' of dev.gitlab.org:gitlab/gitlabhq into 11-5-stableJohn Jarvis2018-12-2732-85/+766
|\ \ \ | |/ /
| * | Merge branch 'security-11-5-secret-ci-variables-exposed' into 'security-11-5'John Jarvis2018-12-2710-22/+296
| |\ \
| | * | Stub full ref in build specMatija Čupić2018-12-081-1/+1
| | * | Backport security fix for 11.5Matija Čupić2018-12-0810-21/+295
| | * | Prevent a path traversal attack on global file templatesNick Thomas2018-12-053-1/+66
| * | | Merge branch 'security-11-5-53543-user-keeps-access-to-mr-issue-when-removed-...John Jarvis2018-12-274-2/+71
| |\ \ \
| | * | | Adds validation to check if user can read projectTiago Botelho2018-12-194-2/+71
| | | |/ | | |/|
| * | | Merge branch 'security-11-5-group-cicd-settings-accessible-to-maintainer' int...John Jarvis2018-12-273-12/+48
| |\ \ \
| | * | | Use old-style controller request paramsMatija Čupić2018-12-241-2/+2
| | * | | Check for group admin permissionsMatija Čupić2018-12-243-12/+48
| * | | | Merge branch 'security-11-5-guests-jobs-api' into 'security-11-5'John Jarvis2018-12-271-6/+26
| |\ \ \ \
| | * | | | Authorize read_build when listing pipeline jobsMatija Čupić2018-12-221-3/+13
| | * | | | Authorize read_build action when listing jobsMatija Čupić2018-12-221-3/+13
| | |/ / /
| * | | | Merge branch 'security-11-5-refs-available-to-project-guest' into 'security-1...John Jarvis2018-12-271-4/+20
| |\ \ \ \
| | * | | | Project guests no longer are able to see refs pageTiago Botelho2018-12-191-4/+20
| | | |/ / | | |/| |
| * | | | Merge branch 'security-11-5-fix-ssrf-lfs-project-import' into 'security-11-5'John Jarvis2018-12-271-9/+50
| |\ \ \ \
| | * | | | Fixed SSRF in project imports with LFSFrancisco Javier López2018-12-181-9/+50
| | |/ / /
| * | | | Merge branch 'security-label-xss-11-5' into 'security-11-5'John Jarvis2018-12-271-0/+18
| |\ \ \ \
| | * | | | Escape html entities when no label foundJarka Košanová2018-12-221-0/+18
| | | |/ / | | |/| |
| * | | | Merge branch 'ensure-that-build-token-is-always-running-11-5' into 'security-...John Jarvis2018-12-271-18/+60
| |\ \ \ \
| | * | | | Ensure that build token is only used when runningKamil Trzciński2018-12-181-18/+60
| | | |_|/ | | |/| |
| * | | | Merge branch 'security-11-5-fix-ssrf-import-url-remote-mirror' into 'security...John Jarvis2018-12-272-0/+21
| |\ \ \ \
| | * | | | Replaced UrlValidator with PublicUrlValidator for import_url and remote mirro...Francisco Javier López2018-12-132-0/+21
| | | |_|/ | | |/| |
| * | | | Merge branch 'security-11-5-54377-label-milestone-name-xss' into 'security-11-5'John Jarvis2018-12-261-0/+41
| |\ \ \ \
| | * | | | Escape label and milestone titles to prevent XSSKushal Pandya2018-12-201-0/+41
| | |/ / /
| * | | | Merge branch 'security-11-5-url-rel' into 'security-11-5'John Jarvis2018-12-261-4/+4
| |\ \ \ \
| | * | | | Set URL rel attribute for broken URLsJan Provaznik2018-12-131-4/+4
| | |/ / /
| * | | | Merge branch 'security-todos_not_redacted_for_guests-11-5' into 'security-11-5'John Jarvis2018-12-265-5/+22
| |\ \ \ \
| | * | | | Delete confidential issue todos for guestsFelipe Artur2018-12-175-5/+22
| | |/ / /
| * | | | Merge branch 'security-bvl-fix-cross-project-mr-exposure-11-5' into 'security...John Jarvis2018-12-262-3/+89
| |\ \ \ \ | | |_|_|/ | |/| | |
| | * | | Validate projects in MR build serviceBob Van Landuyt2018-12-142-3/+89
| | |/ /
| * | | Fix persistent symlink in project importJames Lopez2018-12-184-1/+52
| |/ /
| * | Validate LFS hrefs before downloading themNick Thomas2018-12-121-0/+12
* | | Merge branch '55402-broken-master-karma-test-failing-in-spec-javascripts-boar...Stan Hu2018-12-271-3/+4
* | | Merge branch 'security-import-symlink-11-5' into 'security-11-5'John Jarvis2018-12-204-1/+52
* | | Merge branch 'security-2754-fix-lfs-import-11-5' into 'security-11-5'John Jarvis2018-12-131-0/+12
|/ /
* | Merge branch 'security-54857-fix-templates-path-traversal-11-5' into 'securit...Cindy Pallares2018-12-053-1/+66
* | Merge branch '53778-remove-site-statistics' into 'master'Sean McGivern2018-11-304-126/+0
* | Merge branch '_acet-fix-unable-to-reply-resolved-nondiff-discussion' into 'ma...Phil Hughes2018-11-301-0/+44
* | Merge branch 'sh-fix-hash-filename-handling' into 'master'Douglas Barbosa Alexandre2018-11-301-0/+28
* | Merge branch '53763-fix-encrypt-columns-data-loss' into 'master'Stan Hu2018-11-302-0/+55
* | Merge branch 'fix-not-render-emoji' into 'master'Mike Greiling2018-11-301-1/+1
* | Merge branch 'if-53347_fix_impersonation_tokens' into 'master'Stan Hu2018-11-304-2/+16
|/