summaryrefslogtreecommitdiff
path: root/spec
Commit message (Expand)AuthorAgeFilesLines
...
* | | Merge branch 'security-11-6' of dev.gitlab.org:gitlab/gitlabhq into 11-6-stableJohn Jarvis2018-12-2733-90/+774
|\ \ \ | |/ /
| * | Merge branch 'security-11-6-secret-ci-variables-exposed' into 'security-11-6'John Jarvis2018-12-2711-27/+301
| |\ \
| | * | Backport security fix for 11.6Matija Čupić2018-12-0811-27/+301
| | |/
| * | Merge branch 'security-11-6-user-keeps-access-to-mr-issue-when-removed-from-t...John Jarvis2018-12-274-2/+71
| |\ \
| | * | Adds validation to check if user can read projectTiago Botelho2018-12-264-2/+71
| | |/
| * | Merge branch 'security-11-6-group-cicd-settings-accessible-to-maintainer' int...John Jarvis2018-12-273-12/+48
| |\ \
| | * | Use old-style controller request paramsMatija Čupić2018-12-241-2/+2
| | * | Check for group admin permissionsMatija Čupić2018-12-243-12/+48
| | |/
| * | Merge branch 'security-11-6-guests-jobs-api' into 'security-11-6'John Jarvis2018-12-271-6/+26
| |\ \
| | * | Authorize read_build when listing pipeline jobsMatija Čupić2018-12-221-3/+13
| | * | Authorize read_build action when listing jobsMatija Čupić2018-12-221-3/+13
| | |/
| * | Merge branch 'security-11-6-refs-available-to-project-guest' into 'security-1...John Jarvis2018-12-271-4/+20
| |\ \
| | * | Project guests no longer are able to see refs pageTiago Botelho2018-12-101-4/+20
| | |/
| * | [11.6] SSRF in project imports with LFSFrancisco Javier López2018-12-271-6/+59
| * | Merge branch 'security-label-xss-11-6' into 'security-11-6'John Jarvis2018-12-271-0/+18
| |\ \
| | * | Escape html entities when no label foundJarka Košanová2018-12-221-0/+18
| | |/
| * | Merge branch 'ensure-that-build-token-is-always-running' into 'security-11-6'John Jarvis2018-12-271-18/+60
| |\ \
| | * | Ensure that build token is only used when runningKamil Trzciński2018-12-181-18/+60
| * | | Merge branch 'security-11-6-fix-ssrf-import-url-remote-mirror' into 'security...John Jarvis2018-12-272-0/+21
| |\ \ \
| | * | | Replaced UrlValidator with PublicUrlValidator for import_url and remote mirro...Francisco Javier López2018-12-132-0/+21
| | | |/ | | |/|
| * | | Merge branch 'security-11-6-54377-label-milestone-name-xss' into 'security-11-6'John Jarvis2018-12-261-0/+44
| |\ \ \
| | * | | Escape label and milestone titles to prevent XSSKushal Pandya2018-12-201-0/+44
| | |/ /
| * | | Merge branch 'security-11-6-url-rel' into 'security-11-6'John Jarvis2018-12-261-4/+4
| |\ \ \
| | * | | Set URL rel attribute for broken URLsJan Provaznik2018-12-131-4/+4
| | |/ /
| * | | Merge branch 'security-todos_not_redacted_for_guests-11-6' into 'security-11-6'John Jarvis2018-12-265-5/+22
| |\ \ \
| | * | | Delete confidential issue todos for guestsFelipe Artur2018-12-175-5/+22
| | |/ /
| * | | Validate projects in MR build serviceBob Van Landuyt2018-12-142-3/+89
| |/ /
* | | Fix persistent symlink in project importJames Lopez2018-12-194-1/+52
* | | Fix failing Rails 4 spec in notification_service_worker_spec.rbStan Hu2018-12-181-1/+8
* | | Merge branch 'fj-remove-forced-disposition-attachment-ssh-keys' into 'master'Douwe Maan2018-12-181-6/+0
* | | Merge branch '55433-un-revert-https-gitlab-com-gitlab-org-gitlab-ce-commit-00...Yorick Peterse2018-12-182-20/+155
* | | Merge branch 'inline-duplicated-discussions' into 'master'Fatih Acet2018-12-181-0/+65
* | | Merge branch '55230-remove-project-cleanup-feature-flag' into 'master'Douwe Maan2018-12-183-66/+62
* | | Merge branch '55276-encoding-issue-with-the-user-centric-tooltips' into 'master'Tim Zallmann2018-12-181-0/+13
* | | Merge branch 'remove-issue-suggestions-flag' into 'master'Douwe Maan2018-12-181-0/+11
* | | Merge branch '11-6-stable-prepare-rc8' into '11-6-stable'Robert Speicher2018-12-1868-152/+2633
|\ \ \
| * | | Fix broken karma testMartin Wortschack2018-12-171-3/+4
| * | | Merge branch 'sh-remove-gitlab-shell-include' into 'master'Rémy Coutable2018-12-171-4/+0
| * | | Merge branch 'winh-timecop-frontend-fixtures' into 'master'Rémy Coutable2018-12-171-0/+7
| * | | Merge branch '39727-registry' into 'master'Phil Hughes2018-12-173-95/+59
| * | | Merge branch 'fix-warnings' into 'master'Rémy Coutable2018-12-172-18/+36
| * | | Merge branch 'sh-reject-refs-with-invalid-chars' into 'master'Douwe Maan2018-12-171-0/+30
| * | | Merge branch '54626-able-to-download-a-single-archive-file-with-api-by-ref-na...Grzegorz Bizon2018-12-172-5/+145
| * | | Merge branch 'osw-update-mr-metrics-with-events-data' into 'master'Douwe Maan2018-12-172-0/+104
| * | | Merge branch 'commit-badge-style-fix' into 'master'Filipa Lacerda2018-12-171-0/+4
| * | | Merge branch 'kp-issue_6086' into 'master'Phil Hughes2018-12-173-0/+417
| * | | Merge branch '51122-fix-navigating-discussions' into 'master'Phil Hughes2018-12-175-4/+82
| * | | Merge branch '50157-extended-user-centric-tooltips' into 'master'Clement Ho2018-12-179-6/+361
| * | | Merge branch 'ce-jej/group-saml-sso-button-link-description' into 'master'Clement Ho2018-12-172-0/+50
| * | | Merge branch 'integrate-csslab' into 'master'Annabel Dunstone Gray2018-12-171-0/+1