- Feb 11, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
- Feb 10, 2021
-
-
Mayra Cabrera authored
Prevent Denial of Service Attack on gitlab-shell See merge request gitlab-org/security/gitlab!1199
-
Mayra Cabrera authored
Merge branch 'security-respect-analytics-enabled-rule-for-project-level-analytics-features-13-7' into '13-7-stable-ee' Respect analytics_enabled policy rule See merge request gitlab-org/security/gitlab!1228
-
Mayra Cabrera authored
Always perform SSL verification for FortiTokenCloud Integration See merge request gitlab-org/security/gitlab!1189
-
GitLab Release Tools Bot authored
Prevent SSRF requests for Prometheus when secured by Google IAP See merge request gitlab-org/security/gitlab!1234
-
GitLab Release Tools Bot authored
Change authorization policy for /lint See merge request gitlab-org/security/gitlab!1212
-
GitLab Release Tools Bot authored
Security check user access on API mr read actions See merge request gitlab-org/security/gitlab!1206
-
GitLab Release Tools Bot authored
Prevent exposure of confidential issue titles in file browser See merge request gitlab-org/security/gitlab!1222
-
GitLab Release Tools Bot authored
Cancel alive jobs on project deletion [RUN ALL RSPEC] [RUN AS-IF-FOSS] See merge request gitlab-org/security/gitlab!1246
-
To avoid using runner resources on deleted projects we cancel all cancelable jobs as the first step in deletion
-
GitLab Release Tools Bot authored
Geo-GL-ID should be passed in JWT token so it's protected properly See merge request gitlab-org/security/gitlab!1217
-
GitLab Release Tools Bot authored
Limit number of invitations for Free tier groups and projects See merge request gitlab-org/security/gitlab!1183
-
- Feb 09, 2021
-
-
Peter Leitzen authored
Strip the `token_credential_uri` key from user-provided JSON.
-
- Feb 08, 2021
-
-
Adam Hegyi authored
Respect analytics_enabled rule when resolving policies for project level analytics features.
-
Mayra Cabrera authored
Merge branch 'fix-hardcoded-ids-in-projects-spec' into 'master' See merge request gitlab-org/security/gitlab!1229
-
Fix hardcoded ids in projects API tests See merge request gitlab-org/gitlab!53036
-
- Feb 04, 2021
-
-
Mayra Cabrera authored
Fixes some datetime dependent spec tests [RUN ALL RSPEC] See merge request gitlab-org/gitlab!53380
-
-
- Feb 01, 2021
-
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
Sanitize target branch See merge request gitlab-org/security/gitlab!1202
-
GitLab Release Tools Bot authored
Add routes for unmatched url for not-get requests See merge request gitlab-org/security/gitlab!1126
-
GitLab Release Tools Bot authored
Fix DNS rebinding protection for Outbound Requests See merge request gitlab-org/security/gitlab!1192
-
GitLab Release Tools Bot authored
Filter sensitive variables from GraphQL logs See merge request gitlab-org/security/gitlab!1186
-
GitLab Release Tools Bot authored
Sanitize XSS in Epic milestone due date See merge request gitlab-org/security/gitlab!1160
-
GitLab Release Tools Bot authored
Remove Kubernetes IP address from errors returned in Threat Monitoring See merge request gitlab-org/security/gitlab!1158
-
GitLab Release Tools Bot authored
Avoid exposing release links when the user cannot read git-tag/repository See merge request gitlab-org/security/gitlab!1170
-
- Jan 31, 2021
-
-
Vasilli Iakliushin authored
Contributes to https://gitlab.com/gitlab-org/gitlab/-/issues/227040 * Remove general cache for `fetch_logs` * Add cache for `repository.tree` call * Add cache for `repository.list_last_commits_for_tree` call * Add additional tests
-
- Jan 29, 2021
-
-
Valery Sizov authored
it will protect the parameter from tampering
-
Laura Montemayor authored
* For /projects/ci/id/lint, change policy to create_pipelinen * For /ci/lint - enforces user authenication if registration is disabled * Adds a changelog
-
- Jan 27, 2021
-
-
Kerri Miller authored
There are a number of places where we were not checking for user access rights (or assuming that authors automatically have them) so we were potentially in situations where a user could create a merge request, have their access rights revoked, and they would still be able to access information or take actions related to their MR. This is potentially a security issue, so we need to block this potential leak.
-
Jacques Erasmus authored
Sanitized the target branch to prevent XSS
-
Igor Drozdov authored
-
- Jan 25, 2021
-
-
alex pooley authored
Free plan on .com will limit invites to 20 per day.
-