- Mar 04, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
- Mar 03, 2021
-
-
Robert Speicher authored
Workhorse: prevent escaped router path traversal See merge request gitlab-org/security/gitlab!1266
-
Robert Speicher authored
Possible XSS in wiki author name See merge request gitlab-org/security/gitlab!1251
-
GitLab Release Tools Bot authored
Clean up active session file See merge request gitlab-org/security/gitlab!1270
-
GitLab Release Tools Bot authored
Bump swagger-ui-dist version See merge request gitlab-org/security/gitlab!1277
-
GitLab Release Tools Bot authored
Bump thrift to 0.14.0 See merge request gitlab-org/security/gitlab!1273
-
GitLab Release Tools Bot authored
Allow only group owners to manage group variables See merge request gitlab-org/security/gitlab!1257
-
Patrick Bajao authored
-
Patrick Bajao authored
-
Alessio Caiazza authored
-
Alessio Caiazza authored
[ci skip]
-
Alessio Caiazza authored
Stop logging when path is excluded See merge request gitlab-org/security/gitlab-workhorse!32
-
Patrick Bajao authored
This causes logging a lot and reporting to sentry which can cause performance issues.
-
- Mar 02, 2021
-
-
Bumped the swagger-ui-dist version to the latest
-
Robert Speicher authored
Fix date dependent spec with useFakeDate See merge request gitlab-org/gitlab!55515
-
Paul Slaughter authored
- Blocking other 13.8 backports
-
- Feb 25, 2021
-
-
Bob Van Landuyt authored
This is a minor bump of the thrift gem. This is a dependency of labkit through jaeger-client
-
mksionek authored
From to-do items Remove binding.pry Fix warden to-do Add warden guard clause Add changelog entry Change naming in changelog
-
- Feb 24, 2021
-
-
Jacob Vosmaer (GitLab) authored
-
Jacob Vosmaer (GitLab) authored
-
Patrick Bajao authored
-
Patrick Bajao authored
[ci skip]
-
Patrick Bajao authored
Use URL.EscapePath() in upstream router (8-59-stable) See merge request gitlab-org/security/gitlab-workhorse!27
-
- Feb 23, 2021
-
-
Jacob Vosmaer (GitLab) authored
-
- Feb 19, 2021
-
-
Marius Bobin authored
Before this change we were allowing maintainers to manage group variables even though our permissions page list only owners.
-
- Feb 15, 2021
-
-
Francisco Javier López authored
In this commit we fix a XSS when rendering the wiki commit info in the header.
-
- Feb 11, 2021
-
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
- Feb 10, 2021
-
-
Mayra Cabrera authored
Prevent Denial of Service Attack on gitlab-shell See merge request gitlab-org/security/gitlab!1198
-
Mayra Cabrera authored
Merge branch 'security-respect-analytics-enabled-rule-for-project-level-analytics-features-13-8' into '13-8-stable-ee' Respect analytics_enabled policy rule See merge request gitlab-org/security/gitlab!1227
-
Mayra Cabrera authored
Always perform SSL verification for FortiTokenCloud Integration See merge request gitlab-org/security/gitlab!1188
-
GitLab Release Tools Bot authored
Prevent SSRF requests for Prometheus when secured by Google IAP See merge request gitlab-org/security/gitlab!1233
-
GitLab Release Tools Bot authored
Change authorization policy for /lint See merge request gitlab-org/security/gitlab!1211
-
GitLab Release Tools Bot authored
Security check user access on API mr read actions See merge request gitlab-org/security/gitlab!1205
-