- Jan 07, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
- Jan 06, 2021
-
-
Mayra Cabrera authored
Fix prometheus DoS through Workhorse See merge request gitlab-org/security/gitlab!1145
-
Mayra Cabrera authored
Deny implicit flow for confidential apps See merge request gitlab-org/security/gitlab!1140
-
GitLab Release Tools Bot authored
Set all trusted OAuth apps as confidential See merge request gitlab-org/security/gitlab!1151
-
GitLab Release Tools Bot authored
Fix regex backtracking issue in package_name_regex See merge request gitlab-org/security/gitlab!1110
-
GitLab Release Tools Bot authored
Fix stealing API token and Prometheus DoS through GitLab Pages See merge request gitlab-org/security/gitlab!1137
-
it includes 2 security fixes
-
GitLab Release Tools Bot authored
Update non-negative integer regex to protect against regex DoS See merge request gitlab-org/security/gitlab!1130
-
-
GitLab Release Tools Bot authored
Forbid public cache for private repos See merge request gitlab-org/security/gitlab!1148
-
- Jan 04, 2021
-
-
-
Fix Redis HLL weekly keys See merge request gitlab-org/gitlab!50358
-
- Dec 29, 2020
-
-
Dominic Couture authored
Migrate all trusted apps to confidential to avoid potential access token leak abusing implicit flow
-
- Dec 28, 2020
-
-
Igor Drozdov authored
When project is public but the repository is private, we don't want to cache it as public. In this case, anybody will be able to see the cached version of the private content during 60s after an eligible user has viewed it.
-
- Dec 23, 2020
-
-
Dominic Couture authored
-
Alessio Caiazza authored
Run test at a fixed time See merge request gitlab-org/gitlab!50488
-
Due to how HLLRedisCounter#weekly_redis_keys converts dates to calendar week, it would result in an empty array when the calendar week of end_date occurs before the calendar week of start_date. For example, given start_date 2020-12-01 and end_date 2021-01-01, the calendar week would be reversed, resulting in empty array from #weekly_redis_keys
-
- Dec 10, 2020
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
Amy Phillips authored
Prepare 13.6.3-ee release See merge request gitlab-org/gitlab!49686
-
Merge branch '291160-merge-request-doesn-t-fully-render-when-user-is-a-tool-admin-if-not-part-of-project' into 'master' Fix MR rendering issue when user is tool admin See merge request gitlab-org/gitlab!49258 (cherry picked from commit 982e2c63) 6721d25c Resolve if user is tool admin on MR 2b3183eb Move changelog out of ee as it affects FOSS also
-
Merge branch '285076-400-bad-request-during-authentication-due-to-password-format-length-or-special-chars' into 'master' Resolve ""400 Bad Request" during authentication due to password format (length or special chars)" See merge request gitlab-org/gitlab!49044 (cherry picked from commit 37f4b059) 496c3612 Add other method to handle strings middleware 218bcfa2 Fix rubocop offence 9a281ff0 Modify string_malformed middleware d90dcc29 Reformat new specs 227ec822 Add changelog entry
-
Resolve Members page 500 error after Invitation sent via API See merge request gitlab-org/gitlab!48937 (cherry picked from commit 27da16c9) ba13e6cf Add case to revoke access for requestor that was also invited 2464e35e Remove requested_at being set at invite create 24c0a1c7 Remove requested_at search from invitations tests d3d9ecee Replace requested_at with created_at for Invitations api 63a59d96 Review feedback: Add changelog and remove spacing
-
- Dec 07, 2020
-
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
- Dec 04, 2020
-
-
GitLab Release Tools Bot authored
Do not expose starred projects of users with private profile via API See merge request gitlab-org/security/gitlab!1105
-