- Apr 13, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
Robert Speicher authored
Check content type before running exiftool See merge request gitlab-org/security/gitlab!1348
-
Robert Speicher authored
Security ruby saml auth bypass fix See merge request gitlab-org/security/gitlab!1335
-
Robert Speicher authored
Detect file format before checking exif headers See merge request gitlab-org/security/gitlab!1340
-
- Apr 12, 2021
-
-
Jan Provaznik authored
-
Jan Provaznik authored
-
Jacob Vosmaer (GitLab) authored
-
Jacob Vosmaer (GitLab) authored
[ci skip]
-
Jacob Vosmaer (GitLab) authored
Check content type before running exiftool See merge request gitlab-org/security/gitlab-workhorse!36
-
- Apr 11, 2021
-
-
Jan Provaznik authored
Assures that exiftool runs for jpeg/tiff images only.
-
- Apr 09, 2021
-
-
Before running exiftool from rake task, file's MIME type is checked.
-
- Apr 08, 2021
-
-
- Mar 31, 2021
-
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
- Mar 30, 2021
-
-
Robert Speicher authored
Escape HTML on scoped labels tooltip See merge request gitlab-org/security/gitlab!1325
-
GitLab Release Tools Bot authored
Fixes XSS with source branch in the merge request sidebar See merge request gitlab-org/security/gitlab!1320
-
GitLab Release Tools Bot authored
Merge branch 'security-360-prevent-any-users-from-deleting-metrics-issue-images-13-8' into '13-8-stable-ee' Adjust issuable policy for metric images See merge request gitlab-org/security/gitlab!1307
-
GitLab Release Tools Bot authored
Only accept POST request to trigger system hooks See merge request gitlab-org/security/gitlab!1313
-
GitLab Release Tools Bot authored
Leave pool repository on fork unlinking See merge request gitlab-org/security/gitlab!1297
-
GitLab Release Tools Bot authored
Prevent infinite loop when checking if collaboration is allowed See merge request gitlab-org/security/gitlab!1295
-
GitLab Release Tools Bot authored
Kroki Arbitrary File Read/Write See merge request gitlab-org/security/gitlab!1285
-
- Mar 29, 2021
-
-
Mario Sebastián Celi Calderón authored
-
- Mar 26, 2021
-
-
Robert Speicher authored
Cherry-pick mimemagic-related changes to 13-8-stable-ee See merge request gitlab-org/gitlab!57616
-
Yorick Peterse authored
Use ruby-magic-static for the time being See merge request gitlab-org/gitlab!57487
-
Heinrich Lee Yu authored
Use upstream ruby-magic project See merge request gitlab-org/gitlab!57463
-
Robert Speicher authored
Don't use Git in the mimemagic shim See merge request gitlab-org/gitlab!57516
-
Heinrich Lee Yu authored
Update ruby-magic-static to v0.3.1 See merge request gitlab-org/gitlab!57458
-
Heinrich Lee Yu authored
Create a fake mimemagic gem in the vendors folder [RUN ALL RSPEC] [RUN AS-IF-FOSS] See merge request gitlab-org/gitlab!57443
-
Dylan Griffith authored
Replace mimemagic dependency and introduce a Gitlab::Utils::MimeType class See merge request gitlab-org/gitlab!57387
-
Thong Kuah authored
Initial introduction of Gitlab::Utils::MimeType class See merge request gitlab-org/gitlab!57421
-
Luke Duncalfe authored
Remove hipchat gem, and make HipChat service a no-op See merge request gitlab-org/gitlab!57434
-
- Mar 23, 2021
-
-
Ron Chan authored
Adding changelog for system hooks trigger Adding the changelog file security-trigger-system-hook-by-post.yml Added spec for POST request to system hooks Remove GET request endpoints for system hooks
-
- Mar 22, 2021
-
-
Sean Arnold authored
- Prevent non members from having destructive permisions
-