- Apr 30, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
- Apr 29, 2021
-
-
John Skarbek authored
Prepare 13.11.3-ee release See merge request gitlab-org/gitlab!60669
-
- Apr 28, 2021
-
-
GitLab Release Tools Bot authored
-
- Apr 27, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
Do not expose pull mirror username and password See merge request gitlab-org/security/gitlab!1365
-
GitLab Release Tools Bot authored
Merge branch 'security-disallow-changing-timestamps-on-issue-create-update-13-11' into '13-11-stable-ee' Prevent non-owners to set system_note_timestamp See merge request gitlab-org/security/gitlab!1358
-
GitLab Release Tools Bot authored
Merge branch 'security-322500-disable-gitaly-branch-pagination-ff-by-default-13-11' into '13-11-stable-ee' Disable keyset pagination for branches by default See merge request gitlab-org/security/gitlab!1366
-
GitLab Release Tools Bot authored
Restrict the dependency proxy auth service See merge request gitlab-org/security/gitlab!1369
-
GitLab Release Tools Bot authored
Bump Carrierwave gem to v1.3.2 See merge request gitlab-org/security/gitlab!1357
-
GitLab Release Tools Bot authored
Merge branch 'security-327155-prevent-mutation-execution-with-read-api-tokens-13-11' into '13-11-stable-ee' Prevent mutation execution with read api tokens See merge request gitlab-org/security/gitlab!1374
-
- Apr 26, 2021
-
-
Alexis Kalderimis authored
Verify that read_api tokens cannot run mutations. Also: adds tests use of OAuth tokens for GraphQL We make some changes to the sessionless_authentication module in order to capture the request_authenticator, so that we can access the token scopes, without making any extra queries. We ensure we always authorize the mutation, which, like all resolvers, needs to opt in to the check. Unlike resolvers, mutations should always raise. So `BaseMutation.authorized?` raises on failure. Logic for handling scopes is pushed down to the `ObjectAuthorization` class, and encapsulated in the `ScopeValidator`, which limits the methods that can be called by resolvers.
-
David Fernandez authored
Any objects other than `User` (such as `DeployToken`) are not allowed Changelog: security
-
- Apr 23, 2021
-
-
Nick Thomas authored
It seems that with this feature flag enabled, pagination doesn't work correctly in conjunction with a search. The FF is already disabled on GitLab.com, but disabling it in the YAML file means that self-managed instances will also be protected from the security issue (unless they explicitly opt-in to some beta code, of course). Changelog: security
-
Alexandru Croitor authored
When an issue is created or updated though API for import purposes we allow providing created_at and updated_at params these would then be reflected also in system notes. Only admins and project owners should be able to set these dates.
-
Vasilli Iakliushin authored
Contributes to https://gitlab.com/gitlab-org/gitlab/-/issues/230864 * Remove password value from the pull mirror form * Hide username from mirror url
-
- Apr 22, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
Robert Speicher authored
Prepare 13.11.1-ee release See merge request gitlab-org/gitlab!60045
-
Remove legacy storage key from notification check See merge request gitlab-org/gitlab!59199 (cherry picked from commit 4e6b6761) ebc6e0d9 Remove legacy storage key from notification check d5f47942 Create What's New entry for 13.11 733223b3 Update 202104220001_13_11.yml 7a89f7a7 Make Core entries Free 8a360163 Update 202104220001_13_11.yml
-
Change unsubscribe language for email campaign See merge request gitlab-org/gitlab!59121 (cherry picked from commit 6defe730) 03efae83 Change unsubscribe language for email campaign ec3b64f2 Check if text is empty and not just nil 15db49f3 Use marketing preference link 0faad983 Move current series info up d58aa096 Use to_param for preference link
-
- Apr 21, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-