- 01 Jul, 2020 4 commits
-
-
Yorick Peterse authored
-
Yorick Peterse authored
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
- 29 Jun, 2020 36 commits
-
-
Robert Speicher authored
Fixes RepositoryValidationService spec See merge request gitlab-org/security/gitlab!696
-
Mayra Cabrera authored
Add 'Rspec' at the beginning of the spec
-
Mayra Cabrera authored
Lack of validations importing snippet repository from bundle Closes #159 See merge request gitlab-org/security/gitlab!608
-
GitLab Release Tools Bot authored
Do not show activity for users with private profiles Closes #140 See merge request gitlab-org/security/gitlab!539
-
GitLab Release Tools Bot authored
Check access when sending TODOs related to merge requests Closes #177 See merge request gitlab-org/security/gitlab!667
-
GitLab Release Tools Bot authored
Disable caching for wiki attachments Closes #168 See merge request gitlab-org/security/gitlab!632
-
GitLab Release Tools Bot authored
Fix null byte error in upload path Closes #148 See merge request gitlab-org/security/gitlab!571
-
GitLab Release Tools Bot authored
Resolve "Cross-Site Scripting In BitbucketServer Import" Closes #69 See merge request gitlab-org/security/gitlab!243
-
GitLab Release Tools Bot authored
Fix note author name rendering Closes #173 See merge request gitlab-org/security/gitlab!651
-
GitLab Release Tools Bot authored
Disable github import api by seetings Closes #143 See merge request gitlab-org/security/gitlab!556
-
GitLab Release Tools Bot authored
Fixed group deploy token API authorizations Closes #172 See merge request gitlab-org/security/gitlab!644
-
GitLab Release Tools Bot authored
Change from hybrid to JSON cookies serializer Closes #171 See merge request gitlab-org/security/gitlab!641
-
Drew Blessing authored
JSON has been the default serializer since Rails 4.1. Hybrid serializer was meant to allow backward compatibility when upgrading pre-Rails 4.1. It's been some time since we upgraded to Rails 4.1 so now we don't need the hybrid serializer anymore. This also causes security concerns since the previous serializer was Marshal.
-
GitLab Release Tools Bot authored
Stored XSS on the Error Tracking page Closes #145 See merge request gitlab-org/security/gitlab!563
-
GitLab Release Tools Bot authored
Upgrade swagger-ui to solve XSS issues Closes #170 See merge request gitlab-org/security/gitlab!577
-
GitLab Release Tools Bot authored
Validate group names with Rails HTML sanitizer Closes #149 See merge request gitlab-org/security/gitlab!572
-
GitLab Release Tools Bot authored
Fix XSS in Banzai's `#data_attributes_for` Closes #150 See merge request gitlab-org/security/gitlab!576
-
GitLab Release Tools Bot authored
Update xterm js dependency to latest stable 3.X version Closes #128 See merge request gitlab-org/security/gitlab!501
-
Jeremy Matos authored
-
GitLab Release Tools Bot authored
Update permissions for time tracking endpoints Closes #153 See merge request gitlab-org/security/gitlab!587
-
GitLab Release Tools Bot authored
Update Kaminari gem Closes #152 See merge request gitlab-org/security/gitlab!575
-
GitLab Release Tools Bot authored
Make sure user info is sanitized when rendered Closes #151 See merge request gitlab-org/security/gitlab!579
-
Scott Stern authored
-
GitLab Release Tools Bot authored
Security fix project authorizations for security dashboard Closes #144 See merge request gitlab-org/security/gitlab!561
-
Mehmet Emin INAC authored
-
GitLab Release Tools Bot authored
Fixes pypi XSS Closes #141 See merge request gitlab-org/security/gitlab!555
-
Martin Wortschack authored
Remove append-right-48 utility class See merge request gitlab-org/gitlab!35545
-
Mike Jang authored
Clarify use of private, public, internal groups Closes #211811 See merge request gitlab-org/gitlab!35439
-
Mike Jang authored
-
Mike Jang authored
Improve docs related to LDAP membership lock Closes #217478 See merge request gitlab-org/gitlab!35332
-
Igor Drozdov authored
Static Site Editor can’t be opened in projects belonging to a subgroup See merge request gitlab-org/gitlab!35378
-
Enrique Alcántara authored
-
Jose Vargas authored
This removes the append-right-48 utility class, no replacements were needed
-
Amy Qualls authored
Fix spelling mistakes See merge request gitlab-org/gitlab!35321
-
Oswaldo Ferreira authored
Fix VSA code stage query See merge request gitlab-org/gitlab!35324
-
Jose Ivan Vargas authored
Update docs for group/instance-level security dash See merge request gitlab-org/gitlab!35533
-