- Aug 18, 2020
-
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
- Aug 17, 2020
-
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
-
Yorick Peterse authored
Stop deploy token being used as user in ProjectPolicy and GroupPolicy See merge request gitlab-org/security/gitlab!821
-
Yorick Peterse authored
Add check for project access on deploy token check See merge request gitlab-org/security/gitlab!817
-
Thong Kuah authored
This prevents deploy token from getting permissions for users that happen to have the same id as the deploy token.
-
When a deploy token is authenticated, project access is checked and rejected if not allowed. Auth spec is fixed to properly test this scenario Update guard clause to allow nil projects to pass for registry access Update LFS spec - now returns 401 for invalid deploy token Fixing flaky tests Add spec for group deploy token as well
- Aug 11, 2020
-
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
- Aug 10, 2020
-
-
Mayra Cabrera authored
Prepare 13.2.4-ee release See merge request gitlab-org/gitlab!39093
-
Mayra Cabrera authored
Merge branch '233017-pick-preload-associations-in-graphql-vulnerability-type' into '13-2-stable-ee-patch-4' Merge branch '233017-preload-associations-in-graphql-vulnerability-type' into '13-2-stable-ee-patch-4' See merge request gitlab-org/gitlab!39119
-
Preload all associations in Vulnerability GraphQL API See merge request gitlab-org/gitlab!38556
-
Yorick Peterse authored
This reverts commit 39e376b3
-
Create issue automatically from Prometheus alert Closes #231497 See merge request gitlab-org/gitlab!37884 (cherry picked from commit 275dd46f) f085ec5f Create issue automatically from Prometheus alert 105f3b6d Ensure prometheus traited alert is valid 41833edb Add tests for Prometheus alert processing 96eb1301 Add changelog file ee5157b0 Use strong memoization 6b5c7c91 Apply 1 suggestion(s) to 1 file(s) b69e3a04 Rename some variables
-
Yorick Peterse authored
Add decompressed archive size validation See merge request gitlab-org/gitlab!38736
-
- Aug 05, 2020
-
-
George Koltsov authored
- Validate Project/Group Import incoming compressed archive to make sure decompressed size is within acceptabe range
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
-
- Aug 04, 2020
-
-
Mayra Cabrera authored
2FA not enforced on /profile/applications See merge request gitlab-org/security/gitlab!781
-
Add one more spec Add changelog entry Fix changelog Move concern to doorkeeper base controller Add base metal controller Add new controller Fix Remove 2FA from api-endpoints Add if-clause block around helper method Add controllers tests And implement 2FA enforcement in tokens controllers Remove obsolete let in spec Fix Fix
-
Mayra Cabrera authored
Upgrade kramdown to 2.3.0 See merge request gitlab-org/security/gitlab!780
-
Mayra Cabrera authored
Merge branch 'security-specialized_project_share_worker_to_respect_access_level-13-2' into '13-2-stable-ee' Specialized worker for project share to respect access level See merge request gitlab-org/security/gitlab!769
-
Mayra Cabrera authored
Update GitLab Runner version See merge request gitlab-org/security/gitlab!754
-
GitLab Release Tools Bot authored
Fix XSS on jobs view See merge request gitlab-org/security/gitlab!737
-
GitLab Release Tools Bot authored
Revoke OAuth grants when a user revokes an application See merge request gitlab-org/security/gitlab!760
-
GitLab Release Tools Bot authored
Add a prohibited branches system See merge request gitlab-org/security/gitlab!763
-
GitLab Release Tools Bot authored
Verify confirmed email for OAuth Authorize POST endpoint See merge request gitlab-org/security/gitlab!740
-