- Mar 04, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
- Mar 03, 2021
-
-
Robert Speicher authored
Workhorse: prevent escaped router path traversal See merge request gitlab-org/security/gitlab!1267
-
GitLab Release Tools Bot authored
Clean up active session file See merge request gitlab-org/security/gitlab!1271
-
From to-do items Remove binding.pry Fix warden to-do Add warden guard clause Add changelog entry Change naming in changelog
-
GitLab Release Tools Bot authored
Bump swagger-ui-dist version See merge request gitlab-org/security/gitlab!1278
-
GitLab Release Tools Bot authored
Bump thrift to 0.14.0 See merge request gitlab-org/security/gitlab!1274
-
GitLab Release Tools Bot authored
Allow only group owners to manage group variables See merge request gitlab-org/security/gitlab!1258
-
Patrick Bajao authored
-
Patrick Bajao authored
-
Alessio Caiazza authored
-
Alessio Caiazza authored
[ci skip]
-
Alessio Caiazza authored
Stop logging when path is excluded See merge request gitlab-org/security/gitlab-workhorse!33
-
Patrick Bajao authored
This causes logging a lot and reporting to sentry which can cause performance issues.
-
- Mar 01, 2021
-
-
Jacques Erasmus authored
Bumped the swagger-ui-dist version to the latest
-
- Feb 25, 2021
-
-
Bob Van Landuyt authored
This is a minor bump of the thrift gem. This is a dependency of labkit through jaeger-client
-
- Feb 24, 2021
-
-
Jacob Vosmaer (GitLab) authored
-
Jacob Vosmaer (GitLab) authored
-
Patrick Bajao authored
-
Patrick Bajao authored
[ci skip]
-
Patrick Bajao authored
Use URL.EscapePath() in upstream router (8-58-stable) See merge request gitlab-org/security/gitlab-workhorse!26
-
- Feb 23, 2021
-
-
Jacob Vosmaer (GitLab) authored
-
- Feb 19, 2021
-
-
Marius Bobin authored
Before this change we were allowing maintainers to manage group variables even though our permissions page list only owners.
-
- Feb 11, 2021
-
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
- Feb 10, 2021
-
-
Mayra Cabrera authored
Prevent Denial of Service Attack on gitlab-shell See merge request gitlab-org/security/gitlab!1199
-
Mayra Cabrera authored
Merge branch 'security-respect-analytics-enabled-rule-for-project-level-analytics-features-13-7' into '13-7-stable-ee' Respect analytics_enabled policy rule See merge request gitlab-org/security/gitlab!1228
-
Mayra Cabrera authored
Always perform SSL verification for FortiTokenCloud Integration See merge request gitlab-org/security/gitlab!1189
-
GitLab Release Tools Bot authored
Prevent SSRF requests for Prometheus when secured by Google IAP See merge request gitlab-org/security/gitlab!1234
-
GitLab Release Tools Bot authored
Change authorization policy for /lint See merge request gitlab-org/security/gitlab!1212
-
GitLab Release Tools Bot authored
Security check user access on API mr read actions See merge request gitlab-org/security/gitlab!1206
-
GitLab Release Tools Bot authored
Prevent exposure of confidential issue titles in file browser See merge request gitlab-org/security/gitlab!1222
-
GitLab Release Tools Bot authored
Cancel alive jobs on project deletion [RUN ALL RSPEC] [RUN AS-IF-FOSS] See merge request gitlab-org/security/gitlab!1246
-
To avoid using runner resources on deleted projects we cancel all cancelable jobs as the first step in deletion
-
GitLab Release Tools Bot authored
Geo-GL-ID should be passed in JWT token so it's protected properly See merge request gitlab-org/security/gitlab!1217
-