- Jun 01, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
- May 31, 2021
-
-
Mayra Cabrera authored
Use tag helper for javascript tag in redirect See merge request gitlab-org/security/gitlab!1457
-
Dominic Couture authored
This will automatically include the nonce for CSP
-
Alessio Caiazza authored
Bump BinData version See merge request gitlab-org/security/gitlab!1414
-
Charlie Ablett authored
Changelog: security
-
Alessio Caiazza authored
Updates authorization for lint See merge request gitlab-org/security/gitlab!1429
-
GitLab Release Tools Bot authored
Adds redirect page to OAuth See merge request gitlab-org/security/gitlab!1441
-
GitLab Release Tools Bot authored
Block access to gitlab for users with expired password See merge request gitlab-org/security/gitlab!1446
-
Alessio Caiazza authored
Limit rotations when removing members to those accessible to the member See merge request gitlab-org/security/gitlab!1410
-
GitLab Release Tools Bot authored
OAuth implicit grant access tokens are not logged See merge request gitlab-org/security/gitlab!1435
-
GitLab Release Tools Bot authored
Use xpath instead of css for searching in banzai [RUN AS-IF-FOSS] See merge request gitlab-org/security/gitlab!1416
-
GitLab Release Tools Bot authored
Truncate all non-blob markdown to 1MB by default See merge request gitlab-org/security/gitlab!1420
-
GitLab Release Tools Bot authored
Merge branch 'security-dblessing_update_users_two_factor_required_from_group-13-12' into '13-12-stable-ee' Update users two factor required from group See merge request gitlab-org/security/gitlab!1432
-
GitLab Release Tools Bot authored
Opt in to Atlassians new context qsh See merge request gitlab-org/security/gitlab!1408
-
GitLab Release Tools Bot authored
Merge branch 'security-297665-validate-commit-author-for-x509-signatures-13-12-ee' into '13-12-stable-ee' Only verify commit signatures if the user email is verified See merge request gitlab-org/security/gitlab!1385
-
GitLab Release Tools Bot authored
Prevent XSS on notebooks See merge request gitlab-org/security/gitlab!1421
-
- May 27, 2021
-
-
John Skarbek authored
Cherry-pick !62553 into 13-12-stable-ee See merge request gitlab-org/gitlab!62563
-
- May 26, 2021
-
-
mksionek authored
Changelog: security
-
Marcin Sedlak-Jakubowski authored
-
Ron Chan authored
The goal is to make sure the user to go through js-based redirect Changelog: security
-
- May 25, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
John Skarbek authored
Prepare 13.12.1-ee release See merge request gitlab-org/gitlab!62466
-
John Skarbek authored
Remove db changelog requirement from danger See merge request gitlab-org/gitlab!62493
-
This backports the fix from https://gitlab.com/gitlab-org/gitlab/-/merge_requests/62054 into 13.12
-
mksionek authored
Changelog: security Fix rubocop offence Add specs for new method Fix typo in spec title
-
Mayra Cabrera authored
The new changelog workflow deprecates changelog file entries, this commits updates changelog.rb not to fail if a changelog entry is not included when a database migration is added Related to https://gitlab.com/gitlab-com/gl-infra/delivery/-/issues/1767
-
A background migration to ensure users have the correct setting when two factor is required by a group they're a member of. A prior bug caused this setting to be incorrect. That bug is fixed going forward and this is a one-time fix for existing cases. Changelog: security
-
Laura Montemayor authored
* Force some form of authentication in order to access the lint endpoint for unauthenticated users on GitLab instances with restrictions * Adds a method for determining if registration on an instance is limited based on the above * Adds specs for all the cases mentioned above Changelog: security
-
Create 13.12 What's New entry See merge request gitlab-org/gitlab!62247 (cherry picked from commit 23f945c4) cd00ce83 Create 13.12 What's New entry 531830d0 Switch release to verify to fix linting error 214e9202 Update 202105220001_13_12.yml 83b8ec1d Adjust GA wording based on Sid feedback e6e99973 Switch generic images to new ones that render better b947070d Fix FLOC URL ddb11240 Update delete packages in API doc link
-
Add documentation for the FLoC feature See merge request gitlab-org/gitlab!62210 (cherry picked from commit 1edd2c44) 21f0e9b1 Add documentation for the FLoC feature 490187e9 Apply 1 suggestion(s) to 1 file(s)
-
Document new Vulnerability Report vendor option in the Scanner filter See merge request gitlab-org/gitlab!61656 (cherry picked from commit 05c95010) 49e95625 Document VR report vendor filter bb1d166b Change order of instruction 3d8ec142 Apply 2 suggestion(s) to 1 file(s) 32cb4520 Apply 2 suggestion(s) to 1 file(s) ccc9e0bf Apply 2 suggestion(s) to 1 file(s)
-