summaryrefslogtreecommitdiff
path: root/spec
Commit message (Expand)AuthorAgeFilesLines
* Authorize access before serving project templateLuke Duncalfe2019-06-132-29/+101
* Merge branch '11-10-stable-patch-6' into '11-10-stable'John Jarvis2019-06-048-4/+78
|\
| * Merge branch 'sh-fix-related-merge-requests-path' into 'master'11-10-stable-patch-6Rémy Coutable2019-06-031-0/+34
| * Merge branch 'use-source-ref-name-in-webhook' into 'master'Ash McKenzie2019-06-031-0/+9
| * Merge branch 'sh-fix-rugged-get-tree-entries-recursive' into 'master'Douglas Barbosa Alexandre2019-06-031-1/+3
| * Merge branch 'fix-project-visibility-level-validation' into 'master'Stan Hu2019-06-031-0/+7
| * Merge branch 'sh-revert-full-gc-after-import' into 'master'Rémy Coutable2019-06-031-1/+1
| * Merge branch '61203-fix-lfs-ui-upload' into 'master'Nick Thomas2019-06-031-0/+19
| * Merge branch 'sh-allow-equal-level-in-subgroup-membership' into 'master'James Lopez2019-06-033-2/+12
* | Add DNS rebinding protection settingsOswaldo Ferreira2019-05-294-1/+101
* | Merge branch 'security-60143-address-xss-issue-11.10' into '11-10-stable'GitLab Release Tools Bot2019-05-281-0/+42
|\ \
| * | Reject slug+uri concat if slug is deemed unsafeKerri Miller2019-05-271-0/+42
| |/
* | Merge branch 'security-58856-persistent-xss-11-10' into '11-10-stable'GitLab Release Tools Bot2019-05-284-2/+30
|\ \
| * | Add `html` to sensitive wordscharlieablett2019-05-012-1/+3
| * | Ensure Issue & MR note_html cannot be importedAsh McKenzie2019-04-302-14/+16
| * | Add disallowed fields to AttributeCleanercharlieablett2019-04-242-1/+25
* | | Merge branch 'security-fix-project-existence-disclosure-11-10' into '11-10-st...GitLab Release Tools Bot2019-05-281-14/+18
|\ \ \
| * | | Fix url redaction for issue linksPatrick Derichs2019-05-061-14/+18
* | | | Merge branch 'security-60039-11-10' into '11-10-stable'GitLab Release Tools Bot2019-05-285-31/+106
|\ \ \ \
| * | | | Validate MR branch namesMark Chao2019-05-065-31/+106
| |/ / /
* | | | Merge branch 'security-unsubscribing-from-issue-11-10' into '11-10-stable'GitLab Release Tools Bot2019-05-281-10/+101
|\ \ \ \
| * | | | Hide issue title on unsubscribe for anonymous usersAlexandru Croitor2019-05-201-10/+101
| |/ / /
* | | | Merge branch 'security-fix-confidential-issue-label-visibility-11-10' into '1...GitLab Release Tools Bot2019-05-281-0/+34
|\ \ \ \
| * | | | Fix confidential issue label disclosure on milestone viewPatrick Derichs2019-05-191-0/+34
| |/ / /
* | | | Merge branch 'security-fix_milestones_search_api_leak-11-10' into '11-10-stable'GitLab Release Tools Bot2019-05-283-4/+83
|\ \ \ \
| * | | | Resolve: Milestones leaked via search APIFelipe Artur2019-05-213-4/+83
| |/ / /
* | | | Merge branch 'security-http-hostname-override-11-10' into '11-10-stable'GitLab Release Tools Bot2019-05-2822-62/+297
|\ \ \ \
| * | | | Protect Gitlab::HTTP against DNS rebinding attackDouwe Maan2019-05-2222-62/+297
| |/ / /
* | | | Merge branch 'security-jej/prevent-web-sign-in-bypass-11-10' into '11-10-stable'GitLab Release Tools Bot2019-05-281-1/+33
|\ \ \ \
| * | | | Prevent password sign in restriction bypassJames Edwards-Jones2019-05-231-1/+33
| |/ / /
* | | | Update Knative version due to a security vulnerabilityTiger Watson2019-05-281-1/+1
* | | | Fix project visibility level validationPeter Marko2019-05-241-0/+7
| |_|/ |/| |
* | | Merge branch '62283-fix-job-app-spec' into 'master'11-10-stable-patch-5Filipa Lacerda2019-05-241-1/+4
|/ /
* | Merge branch 'fix-ref-text-of-mr-pipelines' into 'master'Ash McKenzie2019-04-302-5/+79
* | Merge branch 'fix-environment-on-stop-not-work' into 'master'Sean McGivern2019-04-304-0/+136
* | Merge remote-tracking branch 'origin/11-10-stable' into 11-10-stableJohn T Skarbek2019-04-3016-35/+265
|\ \
| * | Merge branch '60605-karma-failing' into 'master'Michael Kozono2019-04-291-18/+32
| * | Merge branch 'fix-ci-commit-ref-name-and-slug' into 'master'Sean McGivern2019-04-293-0/+68
| * | Merge branch 'sh-fix-slow-partial-rendering' into 'master'Sean McGivern2019-04-291-0/+45
| * | Merge branch 'lock-pipeline-schedule-worker' into 'master'Stan Hu2019-04-291-0/+12
| * | Merge branch '60945-masked-variable-still-printed-in-log-output-on-gitlab-com...Kamil Trzciński2019-04-291-14/+0
| * | Merge branch '60821-deployment-jobs-broken-as-of-11-10-0' into 'master'Douwe Maan2019-04-291-0/+6
| * | Merge branch '60906-fix-wiki-links' into 'master'Stan Hu2019-04-291-0/+24
| * | Merge branch 'fj-60827-fix-web-strategy-error' into 'master'Stan Hu2019-04-291-0/+12
| * | Merge branch '60855-mr-popover-is-not-attached-in-system-notes' into 'master'Filipa Lacerda2019-04-291-0/+6
| * | Merge branch '60687-enviro-dropdown' into 'master'Fatih Acet2019-04-291-1/+1
| * | Merge branch 'id-feature-flag-to-disable-lfs-check' into 'master'Douwe Maan2019-04-291-0/+12
| * | Merge branch '54656-500-error-on-save-of-general-pipeline-settings-timeout' i...Stan Hu2019-04-291-0/+9
| * | Merge branch '60540-merge-request-popover-is-not-working-on-the-to-do-page' i...Phil Hughes2019-04-292-2/+38
* | | Merge branch 'security-disallow-read-user-scope-to-read-project-events-11-10'...GitLab Release Tools Bot2019-04-292-135/+156
|\ \ \ | |/ / |/| |