- Apr 13, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
Robert Speicher authored
Check content type before running exiftool See merge request gitlab-org/security/gitlab!1347
-
Robert Speicher authored
Security ruby saml auth bypass fix See merge request gitlab-org/security/gitlab!1333
-
Robert Speicher authored
Detect file format before checking exif headers See merge request gitlab-org/security/gitlab!1339
-
- Apr 12, 2021
-
-
Jan Provaznik authored
-
Jan Provaznik authored
-
Jacob Vosmaer (GitLab) authored
-
Jacob Vosmaer (GitLab) authored
[ci skip]
-
Jacob Vosmaer (GitLab) authored
Check content type before running exiftool See merge request gitlab-org/security/gitlab-workhorse!35
-
- Apr 11, 2021
-
-
Jan Provaznik authored
Assures that exiftool runs for jpeg/tiff images only.
-
- Apr 09, 2021
-
-
Before running exiftool from rake task, file's MIME type is checked.
-
- Apr 08, 2021
-
-
alex pooley authored
-
- Mar 31, 2021
-
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
- Mar 30, 2021
-
-
GitLab Release Tools Bot authored
Escape HTML on scoped labels tooltip See merge request gitlab-org/security/gitlab!1324
-
GitLab Release Tools Bot authored
Fixes XSS with source branch in the merge request sidebar See merge request gitlab-org/security/gitlab!1319
-
Robert Speicher authored
Disable arbitrary URI and file reads in JSON validator See merge request gitlab-org/security/gitlab!1315
-
GitLab Release Tools Bot authored
Merge branch 'security-360-prevent-any-users-from-deleting-metrics-issue-images-13-9' into '13-9-stable-ee' Adjust issuable policy for metric images See merge request gitlab-org/security/gitlab!1306
-
GitLab Release Tools Bot authored
Only accept POST request to trigger system hooks See merge request gitlab-org/security/gitlab!1312
-
GitLab Release Tools Bot authored
Leave pool repository on fork unlinking See merge request gitlab-org/security/gitlab!1296
-
GitLab Release Tools Bot authored
Prevent infinite loop when checking if collaboration is allowed See merge request gitlab-org/security/gitlab!1294
-
GitLab Release Tools Bot authored
Kroki Arbitrary File Read/Write See merge request gitlab-org/security/gitlab!1286
-
- Mar 29, 2021
-
-
Mario Sebastián Celi Calderón authored
-
- Mar 26, 2021
-
-
Robert Speicher authored
Cherry-pick mimemagic-related changes to 13-9-stable-ee See merge request gitlab-org/gitlab!57613
-
Yorick Peterse authored
Use ruby-magic-static for the time being See merge request gitlab-org/gitlab!57487
-
Heinrich Lee Yu authored
Use upstream ruby-magic project See merge request gitlab-org/gitlab!57463
-
Robert Speicher authored
Don't use Git in the mimemagic shim See merge request gitlab-org/gitlab!57516
-
Heinrich Lee Yu authored
Update ruby-magic-static to v0.3.1 See merge request gitlab-org/gitlab!57458
-
Heinrich Lee Yu authored
Create a fake mimemagic gem in the vendors folder [RUN ALL RSPEC] [RUN AS-IF-FOSS] See merge request gitlab-org/gitlab!57443
-
Dylan Griffith authored
Replace mimemagic dependency and introduce a Gitlab::Utils::MimeType class See merge request gitlab-org/gitlab!57387
-
Thong Kuah authored
Initial introduction of Gitlab::Utils::MimeType class See merge request gitlab-org/gitlab!57421
-
Luke Duncalfe authored
Remove hipchat gem, and make HipChat service a no-op See merge request gitlab-org/gitlab!57434
-
- Mar 25, 2021
-
-
Stan Hu authored
Relates to https://gitlab.com/gitlab-org/gitlab/-/issues/325562
-