- Aug 18, 2020
-
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
- Aug 17, 2020
-
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
-
Yorick Peterse authored
Stop deploy token being used as user in ProjectPolicy and GroupPolicy See merge request gitlab-org/security/gitlab!823
-
Yorick Peterse authored
Add check for project access on deploy token check See merge request gitlab-org/security/gitlab!819
-
Thong Kuah authored
This prevents deploy token from getting permissions for users that happen to have the same id as the deploy token.
-
When a deploy token is authenticated, project access is checked and rejected if not allowed. Auth spec is fixed to properly test this scenario Update guard clause to allow nil projects to pass for registry access Update LFS spec - now returns 401 for invalid deploy token Fixing flaky tests Add spec for group deploy token as well
- Aug 05, 2020
-
-
Mayra Cabrera authored
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
-
Balasankar "Balu" C authored
Signed-off-by:
Balasankar "Balu" C <balasankarc@autistici.org>
-
Balasankar "Balu" C authored
Signed-off-by:
Balasankar "Balu" C <balasankarc@autistici.org>
-
Yorick Peterse authored
-
Yorick Peterse authored
-
Yorick Peterse authored
This reverts commit f2bb8f44. The packages for 13.0.11 could not be built, which we have to fix using a 13.0.12 release.
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
-
- Aug 04, 2020
-
-
Mayra Cabrera authored
2FA not enforced on /profile/applications See merge request gitlab-org/security/gitlab!782
-
Add one more spec Add changelog entry Fix changelog Move concern to doorkeeper base controller Add base metal controller Add new controller Fix Remove 2FA from api-endpoints Add if-clause block around helper method Add controllers tests And implement 2FA enforcement in tokens controllers Remove obsolete let in spec Fix Fix Fix
-
GitLab Release Tools Bot authored
Fix XSS on jobs view See merge request gitlab-org/security/gitlab!634
-
Fix the XSS vulnerablity on the jobs view.
-
GitLab Release Tools Bot authored
Revoke OAuth grants when a user revokes an application See merge request gitlab-org/security/gitlab!758
-
GitLab Release Tools Bot authored
Add a prohibited branches system See merge request gitlab-org/security/gitlab!664
-
GitLab Release Tools Bot authored
Verify confirmed email for OAuth Authorize POST endpoint See merge request gitlab-org/security/gitlab!742
-
GitLab Release Tools Bot authored
Add refreshing projects to transfering groups See merge request gitlab-org/security/gitlab!716
-
GitLab Release Tools Bot authored
Escape milestone title in sidebar tooltip See merge request gitlab-org/security/gitlab!735
-
GitLab Release Tools Bot authored
Only support HTML tooltips for scoped labels See merge request gitlab-org/security/gitlab!694
-
GitLab Release Tools Bot authored
Add decompressed archive size validation on Project/Group Import See merge request gitlab-org/security/gitlab!654
-
GitLab Release Tools Bot authored
Stop excess logs from invite email when group no longer exists See merge request gitlab-org/security/gitlab!722
-