From 42b8ba805de2b0b05d4f4a72c0737b76a3f95c01 Mon Sep 17 00:00:00 2001 From: GitLab Release Tools Bot Date: Tue, 26 Mar 2019 21:45:57 +0000 Subject: Update CHANGELOG.md for 11.7.8 [ci skip] --- CHANGELOG.md | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index 4a3228c60ed..9f0369a5d79 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -562,6 +562,19 @@ entry. - Creates mixin to reduce code duplication between CE and EE in graph component. +## 11.7.8 (2019-03-26) + +### Security (7 changes) + +- Disallow guest users from accessing Releases. +- Fix PDF.js vulnerability. +- Hide "related branches" when user does not have permission. +- Fix XSS in resolve conflicts form. +- Added rake task for removing EXIF data from existing uploads. +- Disallow updating namespace when updating a project. +- Use UntrustedRegexp for matching refs policy. + + ## 11.7.7 (2019-03-19) ### Security (2 changes) -- cgit v1.2.1