- Jan 13, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
Alessio Caiazza authored
Deny implicit flow for confidential apps See merge request gitlab-org/security/gitlab!1168
-
- Jan 12, 2021
-
-
Dominic Couture authored
-
- Jan 07, 2021
-
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
- Jan 06, 2021
-
-
Mayra Cabrera authored
Fix prometheus DoS through Workhorse See merge request gitlab-org/security/gitlab!1146
-
Mayra Cabrera authored
Deny implicit flow for confidential apps See merge request gitlab-org/security/gitlab!1141
-
GitLab Release Tools Bot authored
Set all trusted OAuth apps as confidential See merge request gitlab-org/security/gitlab!1152
-
GitLab Release Tools Bot authored
Fix regex backtracking issue in package_name_regex See merge request gitlab-org/security/gitlab!1111
-
GitLab Release Tools Bot authored
Fix stealing API token and Prometheus DoS through GitLab Pages See merge request gitlab-org/security/gitlab!1138
-
-
GitLab Release Tools Bot authored
Update non-negative integer regex to protect against regex DoS See merge request gitlab-org/security/gitlab!1133
-
-
GitLab Release Tools Bot authored
Forbid public cache for private repos See merge request gitlab-org/security/gitlab!1149
-
- Jan 04, 2021
-
-
-
Mayra Cabrera authored
Fix weekly Redis HLL keys for 13-5-stable-ee See merge request gitlab-org/gitlab!50776
-
Fix Redis HLL weekly keys See merge request gitlab-org/gitlab!50358
-
- Dec 29, 2020
-
-
Dominic Couture authored
Migrate all trusted apps to confidential to avoid potential access token leak abusing implicit flow
-
- Dec 28, 2020
-
-
Igor Drozdov authored
When project is public but the repository is private, we don't want to cache it as public. In this case, anybody will be able to see the cached version of the private content during 60s after an eligible user has viewed it.
-
- Dec 23, 2020
-
-
Dominic Couture authored
-
Alessio Caiazza authored
Run test at a fixed time See merge request gitlab-org/gitlab!50489
-
Due to how HLLRedisCounter#weekly_redis_keys converts dates to calendar week, it would result in an empty array when the calendar week of end_date occurs before the calendar week of start_date. For example, given start_date 2020-12-01 and end_date 2021-01-01, the calendar week would be reversed, resulting in empty array from #weekly_redis_keys
-
- Dec 07, 2020
-
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
- Dec 04, 2020
-
-
GitLab Release Tools Bot authored
Do not expose starred projects of users with private profile via API See merge request gitlab-org/security/gitlab!1084
-
GitLab Release Tools Bot authored
Hide starred & contributed projects of users with private profile See merge request gitlab-org/security/gitlab!1082
-
GitLab Release Tools Bot authored
Do not show emails of users in confirmation page See merge request gitlab-org/security/gitlab!1080
-
GitLab Release Tools Bot authored
Validate zoom links to start with https only See merge request gitlab-org/security/gitlab!1078
-
GitLab Release Tools Bot authored
Cleanup confidential epic todos See merge request gitlab-org/security/gitlab!1092
-
GitLab Release Tools Bot authored
Ensure group and project memberships are not leaked See merge request gitlab-org/security/gitlab!1087
-
GitLab Release Tools Bot authored
Fix mermaid resource consumption in GFM fields See merge request gitlab-org/security/gitlab!1067
-