- Feb 01, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
Sanitize target branch See merge request gitlab-org/security/gitlab!1201
-
GitLab Release Tools Bot authored
Add routes for unmatched url for not-get requests See merge request gitlab-org/security/gitlab!1125
-
Add changelog entry Fix typo in routes Fix git http spec Fix uploads routing spec Add matchers only to project facing paths Add more specs for new routes Add different shared examples Fix rubocop offence Add failure message to new matcher Add cr remarks Add cr remarks
-
GitLab Release Tools Bot authored
Fix DNS rebinding protection for Outbound Requests See merge request gitlab-org/security/gitlab!1193
-
GitLab Release Tools Bot authored
Filter sensitive variables from GraphQL logs See merge request gitlab-org/security/gitlab!1187
-
GitLab Release Tools Bot authored
Sanitize XSS in Epic milestone due date See merge request gitlab-org/security/gitlab!1161
-
GitLab Release Tools Bot authored
Remove Kubernetes IP address from errors returned in Threat Monitoring See merge request gitlab-org/security/gitlab!1159
-
GitLab Release Tools Bot authored
Avoid exposing release links when the user cannot read git-tag/repository See merge request gitlab-org/security/gitlab!1169
-
- Jan 27, 2021
-
-
Jacques Erasmus authored
Sanitized the target branch to prevent XSS
-
- Jan 25, 2021
-
-
Arturo Herrero authored
This fixes DNS rebinding protection bypass when allowing an IP address in Outbound Requests setting.
-
- Jan 22, 2021
-
-
Heinrich Lee Yu authored
This uses the same config we setup for config.filter_parameters
-
- Jan 14, 2021
-
-
GitLab Release Tools Bot authored
-
- Jan 13, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
Alessio Caiazza authored
Deny implicit flow for confidential apps See merge request gitlab-org/security/gitlab!1167
-
Shinya Maeda authored
This commit fixes the security vulnerability that guest can read git-tag through release links.
-
- Jan 12, 2021
-
-
Dominic Couture authored
-
- Jan 07, 2021
-
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
- Jan 06, 2021
-
-
Mayra Cabrera authored
Fix prometheus DoS through Workhorse See merge request gitlab-org/security/gitlab!1145
-
Mayra Cabrera authored
Deny implicit flow for confidential apps See merge request gitlab-org/security/gitlab!1140
-
GitLab Release Tools Bot authored
Set all trusted OAuth apps as confidential See merge request gitlab-org/security/gitlab!1151
-
GitLab Release Tools Bot authored
Fix regex backtracking issue in package_name_regex See merge request gitlab-org/security/gitlab!1110
-
GitLab Release Tools Bot authored
Fix stealing API token and Prometheus DoS through GitLab Pages See merge request gitlab-org/security/gitlab!1137
-
it includes 2 security fixes
-
GitLab Release Tools Bot authored
Update non-negative integer regex to protect against regex DoS See merge request gitlab-org/security/gitlab!1130
-
-
GitLab Release Tools Bot authored
Forbid public cache for private repos See merge request gitlab-org/security/gitlab!1148
-
Rajat Jain authored
Sanitize XSS in milestone title
-
- Jan 04, 2021
-
-
Alan (Maciej) Paruszewski authored
This fix resolves problem with leaked Kubernetes IP address in error messages.
-
-