- Nov 26, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
Henri Philipps authored
Prepare 14.3.5-ee release See merge request gitlab-org/gitlab!75145
-
Andrejs Cunskis authored
Fix 2FA e2e tests by setting user password See merge request gitlab-org/gitlab!71528 (cherry picked from commit edd83af0) 04565a60 Set user password when enabling 2FA
-
- Nov 25, 2021
-
-
Fix registry related tests See merge request gitlab-org/gitlab!73825
-
Add container registry to object storage See merge request gitlab-org/gitlab!71905
-
- Nov 23, 2021
-
-
See https://gitlab.com/gitlab-org/gitlab/-/merge_requests/74706 Changelog: fixed EE: true
-
See https://gitlab.com/gitlab-org/gitlab/-/merge_requests/74133 Changelog: fixed EE: true
-
See https://gitlab.com/gitlab-org/gitlab/-/merge_requests/73952 Changelog: fixed EE: true
-
See https://gitlab.com/gitlab-org/gitlab/-/merge_requests/72925 Changelog: fixed
-
See https://gitlab.com/gitlab-org/gitlab/-/merge_requests/72492 Changelog: fixed
-
John Skarbek authored
Allow SSO callbacks through maintenance mode See merge request gitlab-org/gitlab!74706
-
- Nov 17, 2021
-
-
Catalin Irimie authored
When using other authentication methods, like SSO, LDAP, the path and controllers are slightly different, as they redirect back to a callback handled by Omniauth. This adds the specific routes and controller to the allowlist in the read-only middleware to allow them to go through. Changelog: fixed EE: true
-
- Oct 28, 2021
-
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
- Oct 27, 2021
-
-
Reuben Pereira authored
Merge branch 'security-518-fix-change-project-visibility-to-restricted-option-14-3' into '14-3-stable-ee' Change project visibility to a restricted option See merge request gitlab-org/security/gitlab!1904
-
GitLab Release Tools Bot authored
Highlight usage of unicode bidi characters See merge request gitlab-org/security/gitlab!1938
-
GitLab Release Tools Bot authored
SCIM token is still Viewable After Creation See merge request gitlab-org/security/gitlab!1907
-
GitLab Release Tools Bot authored
Redact list of groups a project is shared with See merge request gitlab-org/security/gitlab!1798
-
-
GitLab Release Tools Bot authored
Fix path traversal issue with SVG hrefs See merge request gitlab-org/security/gitlab!1930
-
GitLab Release Tools Bot authored
Avoid decoding the whole tiff image on isTIFF check See merge request gitlab-org/security/gitlab!1900
-
GitLab Release Tools Bot authored
Workhorse: Allow uploading only a single file See merge request gitlab-org/security/gitlab!1914
-
GitLab Release Tools Bot authored
Do not allow Applications API to create apps with blank scopes See merge request gitlab-org/security/gitlab!1923
-
GitLab Release Tools Bot authored
Refresh authorizations on transfer of groups having project shares See merge request gitlab-org/security/gitlab!1917
-
GitLab Release Tools Bot authored
Don't allow author to resolve discussions when MR is locked via GraphQL See merge request gitlab-org/security/gitlab!1920
-
GitLab Release Tools Bot authored
Never display the root password See merge request gitlab-org/security/gitlab!1803
-
GitLab Release Tools Bot authored
Iterate over trailing space regex replacements See merge request gitlab-org/security/gitlab!1897
-
GitLab Release Tools Bot authored
Prevent private e-mail from being shown in webhook data See merge request gitlab-org/security/gitlab!1894
-
GitLab Release Tools Bot authored
Match with verified_email? rather than any_email?[RUN ALL RSPEC] [RUN AS-IF-FOSS] See merge request gitlab-org/security/gitlab!1882
-
GitLab Release Tools Bot authored
Disallow guests to change severity on incidents See merge request gitlab-org/security/gitlab!1875
-
-
GitLab Release Tools Bot authored
Set imported PipelineSchedules to inactive See merge request gitlab-org/security/gitlab!1879
-
GitLab Release Tools Bot authored
Remove external_webhook_token from exported project See merge request gitlab-org/security/gitlab!1866
-
- Oct 26, 2021
-
-
Robert May authored
Adds markup around unicode bidi characters when highlighting code. These are used primarily for text direction in right-to-left languages, but can be used as an exploit. Changelog: security
-
Dheeraj Joshi authored
This fixes an issue with SVGs href sanitization which was bypassable using path traversal Changelog: security
-
- Oct 25, 2021
-
-
Manoj M J authored
This change makes sure that when a group that has any project-group shares is transferred, it refresh authorizations of projects that are shared to the group. Changelog: security
-