- Feb 11, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
- Feb 10, 2021
-
-
Mayra Cabrera authored
Prevent Denial of Service Attack on gitlab-shell See merge request gitlab-org/security/gitlab!1200
-
GitLab Release Tools Bot authored
Prevent SSRF requests for Prometheus when secured by Google IAP See merge request gitlab-org/security/gitlab!1235
-
GitLab Release Tools Bot authored
Change authorization policy for /lint See merge request gitlab-org/security/gitlab!1213
-
GitLab Release Tools Bot authored
Security check user access on API mr read actions See merge request gitlab-org/security/gitlab!1219
-
GitLab Release Tools Bot authored
Prevent exposure of confidential issue titles in file browser See merge request gitlab-org/security/gitlab!1221
-
GitLab Release Tools Bot authored
Cancel alive jobs on project deletion [RUN ALL RSPEC] [RUN AS-IF-FOSS] See merge request gitlab-org/security/gitlab!1247
-
To avoid using runner resources on deleted projects we cancel all cancelable jobs as the first step in deletion
-
GitLab Release Tools Bot authored
Geo-GL-ID should be passed in JWT token so it's protected properly See merge request gitlab-org/security/gitlab!1218
-
GitLab Release Tools Bot authored
Limit number of invitations for Free tier groups and projects See merge request gitlab-org/security/gitlab!1098
-
- Feb 09, 2021
-
-
Peter Leitzen authored
Strip the `token_credential_uri` key from user-provided JSON.
-
- Feb 04, 2021
-
-
Mayra Cabrera authored
Fixes some datetime dependent spec tests See merge request gitlab-org/gitlab!53382
-
-
- Feb 01, 2021
-
-
GitLab Release Tools Bot authored
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
Sanitize target branch See merge request gitlab-org/security/gitlab!1201
-
GitLab Release Tools Bot authored
Add routes for unmatched url for not-get requests See merge request gitlab-org/security/gitlab!1125
-
Add changelog entry Fix typo in routes Fix git http spec Fix uploads routing spec Add matchers only to project facing paths Add more specs for new routes Add different shared examples Fix rubocop offence Add failure message to new matcher Add cr remarks Add cr remarks
-
GitLab Release Tools Bot authored
Fix DNS rebinding protection for Outbound Requests See merge request gitlab-org/security/gitlab!1193
-
GitLab Release Tools Bot authored
Filter sensitive variables from GraphQL logs See merge request gitlab-org/security/gitlab!1187
-
GitLab Release Tools Bot authored
Sanitize XSS in Epic milestone due date See merge request gitlab-org/security/gitlab!1161
-
GitLab Release Tools Bot authored
Remove Kubernetes IP address from errors returned in Threat Monitoring See merge request gitlab-org/security/gitlab!1159
-
GitLab Release Tools Bot authored
Avoid exposing release links when the user cannot read git-tag/repository See merge request gitlab-org/security/gitlab!1169
-
- Jan 31, 2021
-
-
Vasilli Iakliushin authored
Contributes to https://gitlab.com/gitlab-org/gitlab/-/issues/227040 * Remove general cache for `fetch_logs` * Add cache for `repository.tree` call * Add cache for `repository.list_last_commits_for_tree` call * Add additional tests
-
- Jan 29, 2021
-
-
Kerri Miller authored
There are a number of places where we were not checking for user access rights (or assuming that authors automatically have them) so we were potentially in situations where a user could create a merge request, have their access rights revoked, and they would still be able to access information or take actions related to their MR. This is potentially a security issue, so we need to block this potential leak.
-
Valery Sizov authored
it will protect the parameter from tampering
-
Laura Montemayor authored
* For /projects/ci/id/lint, change policy to create_pipelinen * For /ci/lint - enforces user authenication if registration is disabled * Adds a changelog
-
- Jan 27, 2021
-
-
Jacques Erasmus authored
Sanitized the target branch to prevent XSS
-
Igor Drozdov authored
-
- Jan 25, 2021
-
-
Arturo Herrero authored
This fixes DNS rebinding protection bypass when allowing an IP address in Outbound Requests setting.
-
- Jan 24, 2021
-
-
alex pooley authored
Free plan on .com will limit invites to 20 per day.
-
- Jan 22, 2021
-
-
Heinrich Lee Yu authored
This uses the same config we setup for config.filter_parameters
-
- Jan 14, 2021
-
-
GitLab Release Tools Bot authored
-
- Jan 13, 2021
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-