- Dec 13, 2019
-
-
GitLab Release Tools Bot authored
[ci skip]
-
Alessio Caiazza authored
-
The buffering of the output may be causing issues, so let's disable it for now.
-
John Skarbek authored
Install lsb-release for repo URL construction See merge request gitlab/gitlabhq!3591
-
Kyle Wiebers authored
-
John Skarbek authored
-
John Skarbek authored
This reverts commit 0455f2f3.
-
John Skarbek authored
This reverts commit d2e3962c.
- Dec 12, 2019
-
-
GitLab Release Tools Bot authored
[ci skip]
-
John Skarbek authored
-
John Skarbek authored
This reverts commit 2404e6c7.
-
John Skarbek authored
This reverts commit fa242b39.
- Dec 11, 2019
-
-
GitLab Release Tools Bot authored
[ci skip]
- Dec 10, 2019
-
-
John Skarbek authored
Backport reliable fetcher to 12.1 See merge request gitlab/gitlabhq!3584
-
- Dec 09, 2019
-
-
Valery Sizov authored
- Oct 24, 2019
-
-
GitLab Release Tools Bot authored
Sanitize search text to prevent XSS See merge request gitlab/gitlabhq!3471
-
GitLab Release Tools Bot authored
Handle Stored XSS for Grafana URL in settings See merge request gitlab/gitlabhq!3483
-
David Wilkins authored
- Extend Gitlab::UrlBlocker to allow relative urls (require_absolute setting). The new `require_absolute` setting defaults to true, which is the existing behavior. - Extend AddressableUrlValidator to accept `require_abosolute` and default to the existing behavior - Add validation for ApplicationSetting#grafana_url to validate that the URL does not contain XSS but can be a valid relative or absolute url. - In the case of existing stored URLs, validate the stored URL does not contain XSS. If the stored URL contains stored XSS or is an otherwise invalid URL, return the default database column value. - Add tests for Gitlab::UrlBlocker to test require_absolute setting - Add tests for AddressableUrlValidator - Add tests for ApplicationSetting#grafana_url
-
- Oct 10, 2019
-
-
- Oct 07, 2019
-
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[ci skip]
-
- Oct 02, 2019
-
-
GitLab Release Tools Bot authored
-
- Oct 01, 2019
-
-
GitLab Release Tools Bot authored
[ci skip]
-
Marin Jankovski authored
Fix private feature Elasticsearch leak See merge request gitlab/gitlabhq!3452
-
Mark Chao authored
Add spec to test different combinations. Accept string for required_minimum_access_level Allow more flexible project membership query
- Sep 30, 2019
-
-
Stan Hu authored
Fix broken specs : Generate new GPG key in place of expired one Closes #32956 See merge request gitlab-org/gitlab!17853
-
- Sep 26, 2019
-
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
Fix Gitaly SearchBlobs flag RPC injection [Gitaly v1.53.4] See merge request gitlab/gitlabhq!3435
-
GitLab Release Tools Bot authored
Check that SAML identity linking validates the origin of the request See merge request gitlab/gitlabhq!3376
-
GitLab Release Tools Bot authored
Gitlab XSS in markdown preview page See merge request gitlab/gitlabhq!3400
-
GitLab Release Tools Bot authored
Merge branch 'security-12717-fix-confidential-issue-assignee-visible-to-guests-12-1' into '12-1-stable' Display only participants that user has permission to see See merge request gitlab/gitlabhq!3403
-
GitLab Release Tools Bot authored
Prevent Bypassing Email Verification using Salesforce See merge request gitlab/gitlabhq!3407
-
GitLab Release Tools Bot authored
Only render fixed number of mermaid blocks See merge request gitlab/gitlabhq!3413