- Jun 01, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
- May 31, 2021
-
-
Mayra Cabrera authored
Use tag helper for javascript tag in redirect See merge request gitlab-org/security/gitlab!1458
-
Dominic Couture authored
This will automatically include the nonce for CSP
-
Alessio Caiazza authored
Bump BinData version See merge request gitlab-org/security/gitlab!1403
-
Charlie Ablett authored
Changelog: security
-
Alessio Caiazza authored
Updates authorization for lint See merge request gitlab-org/security/gitlab!1430
-
GitLab Release Tools Bot authored
Adds redirect page to OAuth See merge request gitlab-org/security/gitlab!1442
-
GitLab Release Tools Bot authored
Block access to gitlab for users with expired password See merge request gitlab-org/security/gitlab!1445
-
Alessio Caiazza authored
Limit rotations when removing members to those accessible to the member See merge request gitlab-org/security/gitlab!1388
-
Sean Arnold authored
-
GitLab Release Tools Bot authored
OAuth implicit grant access tokens are not logged See merge request gitlab-org/security/gitlab!1436
-
GitLab Release Tools Bot authored
Use xpath instead of css for searching in banzai [RUN AS-IF-FOSS] See merge request gitlab-org/security/gitlab!1415
-
GitLab Release Tools Bot authored
Truncate all non-blob markdown to 1MB by default See merge request gitlab-org/security/gitlab!1419
-
GitLab Release Tools Bot authored
Merge branch 'security-dblessing_update_users_two_factor_required_from_group-13-11' into '13-11-stable-ee' Update users two factor required from group See merge request gitlab-org/security/gitlab!1433
-
GitLab Release Tools Bot authored
Opt in to Atlassians new context qsh See merge request gitlab-org/security/gitlab!1405
-
GitLab Release Tools Bot authored
Merge branch 'security-297665-validate-commit-author-for-x509-signatures-13-11-ee' into '13-11-stable-ee' Only verify commit signatures if the user email is verified See merge request gitlab-org/security/gitlab!1386
-
GitLab Release Tools Bot authored
Prevent XSS on notebooks See merge request gitlab-org/security/gitlab!1422
-
- May 27, 2021
-
-
John Skarbek authored
Cherry-pick !62553 into 13-11-stable-ee See merge request gitlab-org/gitlab!62561
-
- May 26, 2021
-
-
mksionek authored
Changelog: security
-
Marcin Sedlak-Jakubowski authored
-
Ron Chan authored
The goal is to make sure the user to go through js-based redirect Changelog: security
-
- May 25, 2021
-
-
John Skarbek authored
Remove db changelog requirement from danger See merge request gitlab-org/gitlab!62509
-
Backports changes from https://gitlab.com/gitlab-org/gitlab/-/merge_requests/62493 into 13-11-stable-ee branch
-
mksionek authored
Changelog: security Fix rubocop offence Add specs for new method Fix typo in spec title
-
A background migration to ensure users have the correct setting when two factor is required by a group they're a member of. A prior bug caused this setting to be incorrect. That bug is fixed going forward and this is a one-time fix for existing cases. Changelog: security
-
Laura Montemayor authored
* Force some form of authentication in order to access the lint endpoint for unauthenticated users on GitLab instances with restrictions * Adds a method for determining if registration on an instance is limited based on the above * Adds specs for all the cases mentioned above Changelog: security
-
Lukas Eipert authored
Atlassian introduces a [change to their JWTs for Connect apps][0]. There are two types of JWT, the one being affected (Context JWT) is not utilized by us. Therefore we do not need to do any code changes in the auth logic. This change only opts in to the new security model they are rolling out on June 7th. For more details see: https://gitlab.com/gitlab-org/gitlab/-/issues/328267 [0]: https://community.developer.atlassian.com/t/action-required-atlassian-connect-vulnerability-allows-bypass-of-app-qsh-verification-via-context-jwts/47072 Changelog: security
-
- May 24, 2021
-
-
Nick Thomas authored
Currently, users are able to create "verified" commit signatures for emails they don't control. Changelog: security
-
Jacques Erasmus authored
Prevented the use of data attributes for notebooks. Changelog: security
-
- May 22, 2021
-
-
Brett Walker authored
For large node trees, xpath is significantly faster and uses less memory Changelog: security
-
- May 21, 2021
-
-
Brett Walker authored
and prepend a user message if the limit is over a certain threshold Changelog: security
-
- May 14, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
Alessio Caiazza authored
Prepare 13.11.4-ee release See merge request gitlab-org/gitlab!61736
-
- May 13, 2021
-