- Aug 17, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
Robert Speicher authored
Prepare 14.1.3-ee release See merge request gitlab-org/gitlab!68383
-
See https://gitlab.com/gitlab-org/gitlab/-/merge_requests/68005 Changelog: fixed EE: true
-
Resolve "operator does not exist: integer[] || bigint in app/models/namespace/traversal_hierarchy.rb" See https://gitlab.com/gitlab-org/gitlab/-/merge_requests/67288 Changelog: changed
-
See https://gitlab.com/gitlab-org/gitlab/-/merge_requests/66791 Changelog: fixed EE: true
-
Robert Speicher authored
Updating docs to fix UI link See merge request gitlab-org/gitlab!67732
-
- Aug 09, 2021
-
-
Suzanne Selhorn authored
The docs were not updated in time for 14.1 and so the UI help link does not work properly. This MR fixes that issue. https://gitlab.com/gitlab-org/gitlab/-/issues/337876
-
- Aug 03, 2021
-
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
Don't allow to add users to project with email different than group sett See merge request gitlab-org/security/gitlab!1564
-
Henri Philipps authored
Hide project-level CI/CD Analytics page for Guest users See merge request gitlab-org/security/gitlab!1600
-
GitLab Release Tools Bot authored
Merge branch 'security-not-allow-to-impersonate-tokens-while-impersonation-is-off-14-1' into '14-1-stable-ee' Block pushing with impersonation token if impersonation is disabled See merge request gitlab-org/security/gitlab!1583
-
mksionek authored
Changelog: security
-
- Aug 02, 2021
-
-
Nathan Friend authored
This commit updates the project-level CI/CD Analytics page to not be accessible by Guest users of private projects. Changelog: security
-
GitLab Release Tools Bot authored
Add permissions check to pipelines#show action See merge request gitlab-org/security/gitlab!1612
-
GitLab Release Tools Bot authored
Disallow non-members to set issue metadata on issue create See merge request gitlab-org/security/gitlab!1586
-
GitLab Release Tools Bot authored
Do not show email address in error message See merge request gitlab-org/security/gitlab!1596
-
GitLab Release Tools Bot authored
Misleading username could lead to impersonation in using SSH Certificates See merge request gitlab-org/security/gitlab!1609
-
GitLab Release Tools Bot authored
Remove impersonation token from api response for non-admin user See merge request gitlab-org/security/gitlab!1565
-
GitLab Release Tools Bot authored
Only allow invite to be accepted by user with matching email See merge request gitlab-org/security/gitlab!1632
-
Robert Speicher authored
Add html escaping for default branch name See merge request gitlab-org/security/gitlab!1630
-
GitLab Release Tools Bot authored
Configure OmniAuth to use GitLab AppLogger See merge request gitlab-org/security/gitlab!1615
-
GitLab Release Tools Bot authored
Merge branch 'security-prevent-guests-from-creating-issues-with-sentry-error-14-1' into '14-1-stable-ee' Prevent Guest users from creating issues linked to Sentry errors See merge request gitlab-org/security/gitlab!1587
-
GitLab Release Tools Bot authored
Use oauth_app id instead of uid See merge request gitlab-org/security/gitlab!1603
-
GitLab Release Tools Bot authored
Updates oauth to 0.5.6 See merge request gitlab-org/security/gitlab!1592
-
GitLab Release Tools Bot authored
Unauthorized User Can Trigger Deployment to the Protected Environment See merge request gitlab-org/security/gitlab!1606
-
GitLab Release Tools Bot authored
Fix tag ref detection for pipelines See merge request gitlab-org/security/gitlab!1591
-
GitLab Release Tools Bot authored
Restrict access to instance-level security features for reporters See merge request gitlab-org/security/gitlab!1561
-
GitLab Release Tools Bot authored
[14.1] Fix XSS in Mermaid Markdown rendering See merge request gitlab-org/security/gitlab!1488
-
GitLab Release Tools Bot authored
Filter todos whose target users no longer have access to [RUN AS-IF-FOSS] See merge request gitlab-org/security/gitlab!1556
-
- Jul 30, 2021
-
-
Drew Blessing authored
Previously, any user was able to accept an invite even if the user's email addresses didn't match the invite. A note was displayed but the invite could still be accepted. With this change, a user without a matching, confirmed email address is unable to accept the invite. Changelog: security
-
Dheeraj Joshi authored
This escapes html chars for default branch name value in initializing repository instructions This is to prevent XSS vulnerability Changelog: security
-
- Jul 28, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-