- Mar 12, 2019
-
-
Fatih Acet authored
Freeze date in merge request status view spec See merge request gitlab-org/gitlab-ce!25671 (cherry picked from commit c994484d) a05aba61 Freeze date in merge request status view spec
-
- Mar 11, 2019
-
-
Ramya Authappan authored
Quarantine failing push_mirroring_over_http_spec See merge request gitlab-org/gitlab-ce!25590 (cherry picked from commit 68b1ed92) 141c5e4e Quarantine failing spec
-
Douglas Barbosa Alexandre authored
Fix method to mark a project repository as writable See merge request gitlab-org/gitlab-ce!25546 (cherry picked from commit a8a02387) df044542 Fix project set_repository_writable!
-
Nick Thomas authored
Allow `:read_list` when `:read_group` is allowed Closes #58149 See merge request gitlab-org/gitlab-ce!25524 (cherry picked from commit 61c1509c) b81e7c52 Enable `:read_list` when `:read_group` is enabled
-
Grzegorz Bizon authored
Properly handle multiple X-Forwarded-For addresses in runner IP Closes #58103 See merge request gitlab-org/gitlab-ce!25511 (cherry picked from commit dbf0a922) d03b7bb1 Properly handle multiple X-Forwarded-For addresses in runner IP
-
Annabel Dunstone Gray authored
Remove padding for mr-widget-section See merge request gitlab-org/gitlab-ce!25475 (cherry picked from commit a6d52ff8) 7bd65593 Remove padding for mr-widget-section
-
Sean McGivern authored
Docs review: MR diffs external storage Closes #57335 See merge request gitlab-org/gitlab-ce!25433 (cherry picked from commit 56b82db6) 1387983b Docs review: wording, styles, missing links 01680510 Copy edit - add missing preposition
-
Mark Lapierre authored
Retry failing tests Closes gitlab-org/quality/team-tasks#92 See merge request gitlab-org/gitlab-ce!25391 (cherry picked from commit b570f53d) d54cb37d Retry failed tests with rspec-retry
-
- Feb 28, 2019
-
-
GitLab Release Tools Bot authored
[ci skip]
- Feb 27, 2019
-
-
Robert Speicher authored
Display only information visible to current user on Milestone detail See merge request gitlab/gitlabhq!2917
-
Jarka Kadlecova authored
Display only labels and assignees of issues visible by the currently logged user Display only issues visible to user in the burndown chart
-
Yorick Peterse authored
Display the correct number of MRs a user has access to See merge request gitlab/gitlabhq!2929
-
Igor Drozdov authored
-
Yorick Peterse authored
Filter impersonated sessions from active sessions and remove ability to revoke session See merge request gitlab/gitlabhq!2981
-
Yorick Peterse authored
Forbid creating discussions for users with restricted access See merge request gitlab/gitlabhq!2890
-
Yorick Peterse authored
Check issue milestone availability See merge request gitlab/gitlabhq!2904
-
Yorick Peterse authored
Prevent Releases links API to leak tag existence See merge request gitlab/gitlabhq!2908
-
Yorick Peterse authored
Disable issue board policies when issues are disabled See merge request gitlab/gitlabhq!2910
-
Yorick Peterse authored
Show only MRs visible to user on milestone detail See merge request gitlab/gitlabhq!2923
-
Yorick Peterse authored
Don't allow non-members to see private related MRs See merge request gitlab/gitlabhq!2930
-
Yorick Peterse authored
Validate session key when authorizing with GCP to create a cluster See merge request gitlab/gitlabhq!2934
-
Yorick Peterse authored
Fix git clone revealing private repo's presence See merge request gitlab/gitlabhq!2938
-
Yorick Peterse authored
Check snippet attached file to be moved is within designated directory See merge request gitlab/gitlabhq!2941
-
Yorick Peterse authored
Fix blind SSRF in Prometheus Integration See merge request gitlab/gitlabhq!2944
-
Reuben Pereira authored
Check validity before querying so that if the dns entry for the api_url has been changed to something invalid after the model was saved and checked for validity, it will not query. This is to solve a toctou (time of check to time of use) issue.
-
Yorick Peterse authored
Fix leaking private repository information in API See merge request gitlab/gitlabhq!2948
-
Yorick Peterse authored
Arbitrary file read via MergeRequestDiff See merge request gitlab/gitlabhq!2951
-
Francisco Javier López authored
-
Yorick Peterse authored
Remove link after issue move when no permissions See merge request gitlab/gitlabhq!2955
-
Yorick Peterse authored
Block local URLs for Kubernetes integration See merge request gitlab/gitlabhq!2959
-
Yorick Peterse authored
Merge branch 'security-add-public-internal-groups-as-members-to-your-project-idor-11-8' into '11-8-stable' Add public/internal groups as members to your Project(IDOR) See merge request gitlab/gitlabhq!2962
-
Yorick Peterse authored
Stop linking to unrecognized package sources See merge request gitlab/gitlabhq!2969
-
Yorick Peterse authored
[11.8] Prevent disclosing project milestone titles See merge request gitlab/gitlabhq!2973
-
Yorick Peterse authored
Limit number of characters allowed in mermaidjs See merge request gitlab/gitlabhq!2978
-
Imre (Admin) authored
Session ID is used as a parameter for the revoke session endpoint but it should never be included in the HTML as an attacker could obtain it via XSS.
-
Imre (Admin) authored
-
Rajat Jain authored
-