- Jul 01, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
Mayra Cabrera authored
Prevent GraphQL API access by deactivated users See merge request gitlab-org/security/gitlab!1526
-
-
Mayra Cabrera authored
Forbid GET requests with mutations See merge request gitlab-org/security/gitlab!1529
-
- Jun 30, 2021
-
-
Amy Phillips authored
Bump rails gem version to 6.0.3.7 See merge request gitlab-org/security/gitlab!1515
-
GitLab Release Tools Bot authored
Copy feature visibility settings to a fork See merge request gitlab-org/security/gitlab!1523
-
GitLab Release Tools Bot authored
Update rdoc to 6.3.1 See merge request gitlab-org/security/gitlab!1534
-
GitLab Release Tools Bot authored
Add new username validation See merge request gitlab-org/security/gitlab!1495
-
GitLab Release Tools Bot authored
Avoid disclosing project in web IDE See merge request gitlab-org/security/gitlab!1512
-
GitLab Release Tools Bot authored
Clipboard DOM-based XSS in Markdown [RUN AS-IF-FOSS] See merge request gitlab-org/security/gitlab!1453
-
GitLab Release Tools Bot authored
Add sanitizing for name field See merge request gitlab-org/security/gitlab!1490
-
GitLab Release Tools Bot authored
Fix XSS in release Edits See merge request gitlab-org/security/gitlab!1486
-
GitLab Release Tools Bot authored
Fix XSS on audit log for feature flag actions See merge request gitlab-org/security/gitlab!1474
-
GitLab Release Tools Bot authored
Update Nokogiri to 1.11.4 See merge request gitlab-org/security/gitlab!1479
-
GitLab Release Tools Bot authored
Add omniauth_user check when verifying user cap See merge request gitlab-org/security/gitlab!1502
-
GitLab Release Tools Bot authored
Add total http read timeout See merge request gitlab-org/security/gitlab!1427
-
GitLab Release Tools Bot authored
Some users can push to Protected Branch with Deploy keys See merge request gitlab-org/security/gitlab!1478
-
GitLab Release Tools Bot authored
Fix merge request diff display issue with unsupported encoding See merge request gitlab-org/security/gitlab!1424
-
It contains multiple security fixes. One of them prevents string polymorphic route arguments and causes some additional changes to be made along with just bumping gem version Changelog: security
-
- Jun 28, 2021
-
-
Alishan Ladhani authored
Created a fork because rdoc 6.3.1 is missing a file. Changelog: security
-
- Jun 24, 2021
-
-
mksionek authored
Changelog: security
-
Alexis Kalderimis authored
Verify that mutations are forbidden in GET requests This ensures that GET requests do not execute mutations. Changelog: security
-
- Jun 23, 2021
-
-
Igor Drozdov authored
When a public project with a private feature is forked, it's expected that the fork will also have the feature private For example, forking a public project with private repo might accidently lead to a repository code exposure Changelog: security
-
- Jun 22, 2021
-
-
Etienne Baqué authored
Checking user identities presence in that check. Also added related rspecs. Changelog: added EE: true
-
Francisco Javier López authored
In this commit we avoid disclosing project info through the web IDE by checking if the user can read the project. Changelog: security
-
- Jun 21, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
Alessio Caiazza authored
Prepare 13.12.5-ee release See merge request gitlab-org/gitlab!64488
-
Alessio Caiazza authored
Fix failing spec See merge request gitlab-org/gitlab!64499
-
mksionek authored
Changelog: fixed
-
See https://gitlab.com/gitlab-org/gitlab/-/merge_requests/63764 EE: true Changelog: fixed
-
See https://gitlab.com/gitlab-org/gitlab/-/merge_requests/63466 Changelog: fixed
-
Only update required instance ci template when the parameter is present See merge request gitlab-org/gitlab!63344 (cherry picked from commit 304aff34) 63077d2d Only update required instance ci template when the parameter is present 9bc395a3 Apply suggestion to use .empty instead of .blank 43f87431 Apply suggestion to fix failing test c1dfd2c3 Add test spec for required_instance_ci_template setting when no parameter key is provided
-
- Jun 16, 2021
- Jun 14, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-