- Aug 10, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
Henri Philipps authored
Prepare 13.12.10-ee release See merge request gitlab-org/gitlab!67748
-
- Aug 09, 2021
-
-
Sean McGivern authored
Fix: Sidekiq workers delete each other's metrics See merge request gitlab-org/gitlab!66432
-
Resolve "operator does not exist: integer[] || bigint in app/models/namespace/traversal_hierarchy.rb" See https://gitlab.com/gitlab-org/gitlab/-/merge_requests/67288 Changelog: changed
-
See https://gitlab.com/gitlab-org/gitlab/-/merge_requests/65954 Changelog: fixed
-
See https://gitlab.com/gitlab-org/gitlab/-/merge_requests/65504 Changelog: fixed EE: true
-
- Aug 03, 2021
-
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
Don't allow to add users to project with email different than group sett See merge request gitlab-org/security/gitlab!1562
-
Henri Philipps authored
Merge branch 'security-nfriend-hide-project-ci-cd-analytics-for-guests-13-12' into '13-12-stable-ee' Hide project-level CI/CD Analytics page for Guest users See merge request gitlab-org/security/gitlab!1575
-
GitLab Release Tools Bot authored
Merge branch 'security-not-allow-to-impersonate-tokens-while-impersonation-is-off-13-12' into '13-12-stable-ee' Block pushing with impersonation token if impersonation is disabled See merge request gitlab-org/security/gitlab!1585
-
mksionek authored
Changelog: security
-
mksionek authored
Changelog: security
-
- Aug 02, 2021
-
-
Nathan Friend authored
This commit updates the project-level CI/CD Analytics page to not be accessible by Guest users of private projects. Changelog: security
-
GitLab Release Tools Bot authored
Add permissions check to pipelines#show action See merge request gitlab-org/security/gitlab!1618
-
GitLab Release Tools Bot authored
Do not show email address in error message See merge request gitlab-org/security/gitlab!1598
-
GitLab Release Tools Bot authored
Misleading username could lead to impersonation in using SSH Certificates See merge request gitlab-org/security/gitlab!1611
-
GitLab Release Tools Bot authored
Remove impersonation token from api response for non-admin user See merge request gitlab-org/security/gitlab!1567
-
GitLab Release Tools Bot authored
Only allow invite to be accepted by user with matching email See merge request gitlab-org/security/gitlab!1634
-
GitLab Release Tools Bot authored
Configure OmniAuth to use GitLab AppLogger See merge request gitlab-org/security/gitlab!1617
-
GitLab Release Tools Bot authored
Merge branch 'security-prevent-guests-from-creating-issues-with-sentry-error-13-12' into '13-12-stable-ee' Prevent Guest users from creating issues linked to Sentry errors See merge request gitlab-org/security/gitlab!1599
-
GitLab Release Tools Bot authored
Updates oauth to 0.5.6 See merge request gitlab-org/security/gitlab!1569
-
GitLab Release Tools Bot authored
Unauthorized User Can Trigger Deployment to the Protected Environment See merge request gitlab-org/security/gitlab!1608
-
GitLab Release Tools Bot authored
Fix tag ref detection for pipelines See merge request gitlab-org/security/gitlab!1549
-
GitLab Release Tools Bot authored
Restrict access to instance-level security features for reporters See merge request gitlab-org/security/gitlab!1540
-
-
GitLab Release Tools Bot authored
[13.12] Fix XSS in Mermaid Markdown rendering See merge request gitlab-org/security/gitlab!1487
-
GitLab Release Tools Bot authored
Filter todos whose target users no longer have access to [RUN AS-IF-FOSS] See merge request gitlab-org/security/gitlab!1555
-
- Jul 30, 2021
-
-
Drew Blessing authored
Previously, any user was able to accept an invite even if the user's email addresses didn't match the invite. A note was displayed but the invite could still be accepted. With this change, a user without a matching, confirmed email address is unable to accept the invite. Changelog: security
-
- Jul 28, 2021
-
-
Drew Blessing authored
OmniAuth logger was not being configured properly and some logs were being dropped. This change ensures OmniAuth log messages are output to `application.log` and/or `application_json.log` as appropriate depending on configuration. Changelog: security Fix Group SAML Spec order dependency Change `allow/expect_any_instance_of` to `allow/expect_next_instance_of` to avoid leaking state from other tests. Changelog: security
-
Shinya Maeda authored
Protected Environment Accesses were not automatically cleaned up when a user was removed from the project membership. Also, the leftover user/group entry in the access list couldn't be removed manually. This commit fixes these security related bugs. Changelog: security EE: true
-
- Jul 27, 2021
-
-
Jose Ivan Vargas Lopez authored
This check renders a 404 in case the user trying to access the pipeline details page doesn't have enough permissions Changelog: security
-
Robert May authored
Updates the gitlab-shell version to include a security patch. Changelog: security
-
- Jul 23, 2021
-
-
Sean Arnold authored
Changelog: security
-
- Jul 22, 2021
-
-
Dominic Couture authored
Changelog: security EE: true
-