- Jun 01, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
- May 31, 2021
-
-
Mayra Cabrera authored
Use tag helper for javascript tag in redirect See merge request gitlab-org/security/gitlab!1459
-
Dominic Couture authored
This will automatically include the nonce for CSP
-
Alessio Caiazza authored
Bump BinData version See merge request gitlab-org/security/gitlab!1402
-
Charlie Ablett authored
Changelog: security
-
Alessio Caiazza authored
Updates authorization for lint See merge request gitlab-org/security/gitlab!1449
-
GitLab Release Tools Bot authored
Adds redirect page to OAuth See merge request gitlab-org/security/gitlab!1443
-
GitLab Release Tools Bot authored
Block access to gitlab for users with expired password See merge request gitlab-org/security/gitlab!1444
-
GitLab Release Tools Bot authored
OAuth implicit grant access tokens are not logged See merge request gitlab-org/security/gitlab!1437
-
GitLab Release Tools Bot authored
Use xpath instead of css for searching in banzai [RUN AS-IF-FOSS] See merge request gitlab-org/security/gitlab!1417
-
GitLab Release Tools Bot authored
Truncate all non-blob markdown to 1MB by default See merge request gitlab-org/security/gitlab!1418
-
GitLab Release Tools Bot authored
Merge branch 'security-dblessing_update_users_two_factor_required_from_group-13-10' into '13-10-stable-ee' Update users two factor required from group See merge request gitlab-org/security/gitlab!1434
-
GitLab Release Tools Bot authored
Opt in to Atlassians new context qsh See merge request gitlab-org/security/gitlab!1406
-
GitLab Release Tools Bot authored
Merge branch 'security-297665-validate-commit-author-for-x509-signatures-13-10-ee' into '13-10-stable-ee' Only verify commit signatures if the user email is verified See merge request gitlab-org/security/gitlab!1387
-
GitLab Release Tools Bot authored
Prevent XSS on notebooks See merge request gitlab-org/security/gitlab!1423
-
- May 27, 2021
-
-
Laura Montemayor authored
* Force some form of authentication in order to access the lint endpoint for unauthenticated users on GitLab instances with restrictions * Adds a method for determining if registration on an instance is limited based on the above * Adds specs for all the cases mentioned above Changelog: security
-
Ron Chan authored
The goal is to make sure the user to go through js-based redirect Changelog: security
-
- May 26, 2021
-
-
John Skarbek authored
-
Rémy Coutable authored
-
mksionek authored
Changelog: security
-
- May 25, 2021
-
-
John Skarbek authored
Remove db changelog requirement from danger See merge request gitlab-org/gitlab!62519
-
Backports changes from https://gitlab.com/gitlab-org/gitlab/-/merge_requests/62493 into 13-10-stable-ee branch
-
A background migration to ensure users have the correct setting when two factor is required by a group they're a member of. A prior bug caused this setting to be incorrect. That bug is fixed going forward and this is a one-time fix for existing cases. Changelog: security
-
mksionek authored
Changelog: security Fix rubocop offence Add specs for new method Fix typo in spec title
-
Lukas Eipert authored
Atlassian introduces a [change to their JWTs for Connect apps][0]. There are two types of JWT, the one being affected (Context JWT) is not utilized by us. Therefore we do not need to do any code changes in the auth logic. This change only opts in to the new security model they are rolling out on June 7th. For more details see: https://gitlab.com/gitlab-org/gitlab/-/issues/328267 [0]: https://community.developer.atlassian.com/t/action-required-atlassian-connect-vulnerability-allows-bypass-of-app-qsh-verification-via-context-jwts/47072 Changelog: security
-
- May 24, 2021
-
-
Nick Thomas authored
Currently, users are able to create "verified" commit signatures for emails they don't control. Changelog: security
-
Jacques Erasmus authored
Prevented the use of data attributes for notebooks. Changelog: security
-
- May 22, 2021
-
-
Brett Walker authored
For large node trees, xpath is significantly faster and uses less memory Changelog: security
-
- May 21, 2021
-
-
Brett Walker authored
and prepend a user message if the limit is over a certain threshold Changelog: security
-
- Apr 28, 2021
-
-
GitLab Release Tools Bot authored
-
- Apr 27, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
Henri Philipps authored
Update mermaid to version 8.9.2 See merge request gitlab-org/security/gitlab!1363
-
GitLab Release Tools Bot authored
Do not expose pull mirror username and password See merge request gitlab-org/security/gitlab!1355
-
GitLab Release Tools Bot authored
Merge branch 'security-disallow-changing-timestamps-on-issue-create-update-13-10' into '13-10-stable-ee' Prevent non-owners to set system_note_timestamp See merge request gitlab-org/security/gitlab!1359
-
GitLab Release Tools Bot authored
Merge branch 'security-322500-disable-gitaly-branch-pagination-ff-by-default-13-10' into '13-10-stable-ee' Disable keyset pagination for branches by default See merge request gitlab-org/security/gitlab!1367
-
GitLab Release Tools Bot authored
Restrict the dependency proxy auth service See merge request gitlab-org/security/gitlab!1370
-