- Jun 03, 2020
-
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
-
Alessio Caiazza authored
Prevent fetching repository code with unauthorized ci token See merge request gitlab-org/security/gitlab!589
- Jun 02, 2020
-
-
Furkan Ayhan authored
Users have ability to fetch other projects' code via gitlab-ci-token. This permission is controlled by "build_download_code". However, this permission is not prevented when "repository_disabled" for the users. This commit fixes this.
-
- Jun 01, 2020
-
-
Stan Hu authored
Fix expired SSL cert in PagesDomain test See merge request gitlab-org/gitlab!33462
-
- May 28, 2020
-
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
-
John Skarbek authored
Prepare 12.10.8-ee release See merge request gitlab-org/gitlab!33328
-
Merge branch '215616-geo-synchronisation-status-is-empty-when-nothing-is-synchronised' into 'master' Geo: Fix empty synchronisation status when nothing is synchronised Closes #215616 See merge request gitlab-org/gitlab!30710 (cherry picked from commit d59c866b) a0b7c619 Geo: Synchronisation status is empty when nothing is synchronised 15fc37c9 Apply suggestion to...
-
Resolve "Geo: Design thumbnails are not replicated" Closes #218557 See merge request gitlab-org/gitlab!32703 (cherry picked from commit 64ae30b5) 56c14674 Add design thumbnails to Geo upload types a17fc5d4 Apply suggestion to ee/spec/lib/gitlab/geo/replication/base_transfer_spec.rb 1bec3bd7 Apply suggestion to ee/spec/lib/gitlab/geo/replication/base_transfer_spec.rb d7ffd8fa Add changelog entry
- May 27, 2020
-
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
-
Alessio Caiazza authored
Fix failing user spec See merge request gitlab-org/security/gitlab!552
-
Jan Provaznik authored
Assures that user.emails is not empty
-
- May 26, 2020
-
-
GitLab Release Tools Bot authored
Added data integrity check before update See merge request gitlab-org/security/gitlab!476
-
GitLab Release Tools Bot authored
Display only verified emails on notifications page See merge request gitlab-org/security/gitlab!549
-
GitLab Release Tools Bot authored
Limit resources when processing artifacts metadata - gitlab-rails See merge request gitlab-org/security/gitlab!532
-
-
Alessio Caiazza authored
Add an extra validation to Static Site Editor payload See merge request gitlab-org/security/gitlab!498
-
Alessio Caiazza authored
Substitute variables using gsub in Prometheus proxy API See merge request gitlab-org/security/gitlab!470
-
GitLab Release Tools Bot authored
Fix email confirmation bug when soft email confirmation is enabled See merge request gitlab-org/security/gitlab!516
-
GitLab Release Tools Bot authored
Require confirmed email address for GitLab OAuth authentication See merge request gitlab-org/security/gitlab!536
-
GitLab Release Tools Bot authored
Merge branch 'security-fix-group-domain-allowed-email-should-be-verified-12-10' into '12-10-stable-ee' Allow only verified user to be members of group with domain restriction See merge request gitlab-org/security/gitlab!543
-
GitLab Release Tools Bot authored
Respect forked projects permissions See merge request gitlab-org/security/gitlab!437
-
Alessio Caiazza authored
Do not auto-confirm email in Trial registration See merge request gitlab-org/security/gitlab!509
-
GitLab Release Tools Bot authored
Hide EKS secret key in admin integrations settings See merge request gitlab-org/security/gitlab!546
-
GitLab Release Tools Bot authored
Fix file enuming using Group Import See merge request gitlab-org/security/gitlab!485
-
GitLab Release Tools Bot authored
Fix security issue in mermaid markdown See merge request gitlab-org/security/gitlab!478
-
Add data attr to close issue link and avoid getting url from href which can be set via mermaid
-
GitLab Release Tools Bot authored
Prevent XSS in the monitoring dashboard See merge request gitlab-org/security/gitlab!453
-
This prevents the branch name from the duplicate dashboard modal to execute XSS scripts
-
GitLab Release Tools Bot authored
Do not expose Kubernetes cluster token See merge request gitlab-org/security/gitlab!504
-