- Nov 08, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
Reuben Pereira authored
Prepare 14.4.2-ee release See merge request gitlab-org/gitlab!73919
-
See https://gitlab.com/gitlab-org/gitlab/-/merge_requests/73715 Changelog: fixed
-
See https://gitlab.com/gitlab-org/gitlab/-/merge_requests/73207 Changelog: changed
-
See https://gitlab.com/gitlab-org/gitlab/-/merge_requests/72925 Changelog: fixed
-
See https://gitlab.com/gitlab-org/gitlab/-/merge_requests/72897 Changelog: fixed
-
See https://gitlab.com/gitlab-org/gitlab/-/merge_requests/72435 Changelog: performance
-
- Oct 28, 2021
-
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
- Oct 27, 2021
-
-
Reuben Pereira authored
Merge branch 'security-518-fix-change-project-visibility-to-restricted-option-14-4' into '14-4-stable-ee' Change project visibility to a restricted option See merge request gitlab-org/security/gitlab!1903
-
GitLab Release Tools Bot authored
Highlight usage of unicode bidi characters See merge request gitlab-org/security/gitlab!1937
-
GitLab Release Tools Bot authored
SCIM token is still Viewable After Creation See merge request gitlab-org/security/gitlab!1906
-
GitLab Release Tools Bot authored
Redact list of groups a project is shared with See merge request gitlab-org/security/gitlab!1910
-
-
GitLab Release Tools Bot authored
Fix path traversal issue with SVG hrefs See merge request gitlab-org/security/gitlab!1929
-
GitLab Release Tools Bot authored
Avoid decoding the whole tiff image on isTIFF check See merge request gitlab-org/security/gitlab!1899
-
GitLab Release Tools Bot authored
Workhorse: Allow uploading only a single file See merge request gitlab-org/security/gitlab!1913
-
GitLab Release Tools Bot authored
Do not allow Applications API to create apps with blank scopes See merge request gitlab-org/security/gitlab!1922
-
GitLab Release Tools Bot authored
Refresh authorizations on transfer of groups having project shares See merge request gitlab-org/security/gitlab!1916
-
GitLab Release Tools Bot authored
Don't allow author to resolve discussions when MR is locked via GraphQL See merge request gitlab-org/security/gitlab!1919
-
GitLab Release Tools Bot authored
Do not display the root password by default See merge request gitlab-org/security/gitlab!1909
-
GitLab Release Tools Bot authored
Iterate over trailing space regex replacements See merge request gitlab-org/security/gitlab!1912
-
GitLab Release Tools Bot authored
Prevent private e-mail from being shown in webhook data See merge request gitlab-org/security/gitlab!1927
-
GitLab Release Tools Bot authored
Match with verified_email? rather than any_email? See merge request gitlab-org/security/gitlab!1926
-
GitLab Release Tools Bot authored
Disallow guests to change severity on incidents See merge request gitlab-org/security/gitlab!1902
-
-
GitLab Release Tools Bot authored
Set imported PipelineSchedules to inactive See merge request gitlab-org/security/gitlab!1911
-
GitLab Release Tools Bot authored
Remove external_webhook_token from exported project See merge request gitlab-org/security/gitlab!1872
-
- Oct 26, 2021
-
-
Robert May authored
Adds markup around unicode bidi characters when highlighting code. These are used primarily for text direction in right-to-left languages, but can be used as an exploit. Changelog: security
-
Dheeraj Joshi authored
This fixes an issue with SVGs href sanitization which was bypassable using path traversal Changelog: security
-
- Oct 25, 2021
-
-
Manoj M J authored
This change makes sure that when a group that has any project-group shares is transferred, it refresh authorizations of projects that are shared to the group. Changelog: security
-