- Jul 04, 2023
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
Mayra Cabrera authored
Add authorization to the subscriptions group controller See merge request https://gitlab.com/gitlab-org/security/gitlab/-/merge_requests/3381 Merged-by:
Mayra Cabrera <mcabrera@gitlab.com> Approved-by:
Doug Stull <dstull@gitlab.com> Approved-by:
Thong Kuah <tkuah@gitlab.com> Co-authored-by:
Doug Stull <dstull@gitlab.com>
-
Ryan Cobb authored
Merge branch 'security-416797-fix-auth-issue-15-11' into '15-11-stable-ee' See merge request gitlab-org/security/gitlab!3381 Changelog: security
-
- Jun 29, 2023
-
-
GitLab Release Tools Bot authored
-
- Jun 28, 2023
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
John Skarbek authored
Revert 'security-leaked-ci-job-token-permission-15-11' from '15-11'" See merge request https://gitlab.com/gitlab-org/security/gitlab/-/merge_requests/3375 Merged-by:
John Skarbek <jskarbek@gitlab.com> Approved-by:
Dominic Couture <dcouture@gitlab.com> Approved-by:
A Browne <abrowne@gitlab.com> Co-authored-by:
Max Fan <mfan@gitlab.com>
-
GitLab Release Tools Bot authored
Use fully qualified ref when loading code owner file See merge request https://gitlab.com/gitlab-org/security/gitlab/-/merge_requests/3354 Merged-by:
GitLab Release Tools Bot <delivery-team+release-tools@gitlab.com> Approved-by:
Vasilii Iakliushin <viakliushin@gitlab.com> Co-authored-by:
Joe Woodward <jwoodward@gitlab.com>
-
Joe Woodward authored
Merge branch 'security-410123-bypass-code-owner-approvals-15-11' into '15-11-stable-ee' See merge request gitlab-org/security/gitlab!3354 Changelog: security
-
GitLab Release Tools Bot authored
Maintainer can leak masked webhook secrets by manipulating URL masking See merge request https://gitlab.com/gitlab-org/security/gitlab/-/merge_requests/3361 Merged-by:
GitLab Release Tools Bot <delivery-team+release-tools@gitlab.com> Approved-by:
Luke Duncalfe <lduncalfe@gitlab.com> Co-authored-by:
bmarjanovic <bmarjanovic@gitlab.com>
-
Bojan Marjanovic authored
Merge branch 'security-410433-confidential-issue-15-11' into '15-11-stable-ee' See merge request gitlab-org/security/gitlab!3361 Changelog: security
-
GitLab Release Tools Bot authored
Remove approvals when the only commit gets amended See merge request https://gitlab.com/gitlab-org/security/gitlab/-/merge_requests/3368 Merged-by:
GitLab Release Tools Bot <delivery-team+release-tools@gitlab.com> Approved-by:
Patrick Bajao <ebajao@gitlab.com> Co-authored-by:
David Kim <dkim@gitlab.com>
-
Sincheol (David) Kim authored
Merge branch 'security-fix-907-15-11' into '15-11-stable-ee' See merge request gitlab-org/security/gitlab!3368 Changelog: security
-
GitLab Release Tools Bot authored
Fix for fork permissions check in compare controller See merge request https://gitlab.com/gitlab-org/security/gitlab/-/merge_requests/3344 Merged-by:
GitLab Release Tools Bot <delivery-team+release-tools@gitlab.com> Approved-by:
Vasilii Iakliushin <viakliushin@gitlab.com> Co-authored-by:
Robert May <rmay@gitlab.com>
-
Robert May authored
Merge branch 'security-408137-15-11' into '15-11-stable-ee' See merge request gitlab-org/security/gitlab!3344 Changelog: security
-
GitLab Release Tools Bot authored
Webhook token leaked in Sidekiq logs if log format is 'default' See merge request https://gitlab.com/gitlab-org/security/gitlab/-/merge_requests/3347 Merged-by:
GitLab Release Tools Bot <delivery-team+release-tools@gitlab.com> Approved-by:
Roy Zwambag <rzwambag@gitlab.com> Co-authored-by:
bmarjanovic <bmarjanovic@gitlab.com>
-
Bojan Marjanovic authored
Merge branch 'security-409034-confidential-issue-15-11' into '15-11-stable-ee' See merge request gitlab-org/security/gitlab!3347 Changelog: security
-
GitLab Release Tools Bot authored
Mitigate epic reference filter ReDOS See merge request https://gitlab.com/gitlab-org/security/gitlab/-/merge_requests/3339 Merged-by:
GitLab Release Tools Bot <delivery-team+release-tools@gitlab.com> Approved-by:
Vitali Tatarintev <vtatarintev@gitlab.com> Co-authored-by:
Brett Walker <bwalker@gitlab.com>
-
Brett Walker authored
Merge branch 'security-untrusted-epic-reference-15-11' into '15-11-stable-ee' See merge request gitlab-org/security/gitlab!3339 Changelog: security
-
GitLab Release Tools Bot authored
Increasing security for CI_JOB_TOKEN on public and internal projects See merge request https://gitlab.com/gitlab-org/security/gitlab/-/merge_requests/3319 Merged-by:
GitLab Release Tools Bot <delivery-team+release-tools@gitlab.com> Approved-by:
A Browne <abrowne@gitlab.com> Co-authored-by:
Max Fan <mfan@gitlab.com>
-
Max Fan authored
Merge branch 'security-leaked-ci-job-token-permission-15-11' into '15-11-stable-ee' See merge request gitlab-org/security/gitlab!3319 Changelog: security
-
GitLab Release Tools Bot authored
Merge branch 'security-dblessing_fix_html_injection_admin_unconfirmed_user-15-11' into '15-11-stable-ee' Sanitize user email addresses in admin confirm user dialog See merge request https://gitlab.com/gitlab-org/security/gitlab/-/merge_requests/3332 Merged-by:
GitLab Release Tools Bot <delivery-team+release-tools@gitlab.com> Approved-by:
Kassio Borges <kborges@gitlab.com> Co-authored-by:
Drew Blessing <drew@gitlab.com>
-
Drew Blessing authored
Merge branch 'security-dblessing_fix_html_injection_admin_unconfirmed_user-15-11' into '15-11-stable-ee' See merge request gitlab-org/security/gitlab!3332 Changelog: security
-
GitLab Release Tools Bot authored
Obfuscate email of service desk issue creator in issue REST API See merge request https://gitlab.com/gitlab-org/security/gitlab/-/merge_requests/3316 Merged-by:
GitLab Release Tools Bot <delivery-team+release-tools@gitlab.com> Approved-by:
Mario Celi <mcelicalderon@gitlab.com> Co-authored-by:
Peter Leitzen <pleitzen@gitlab.com>
-
Peter Leitzen authored
Merge branch 'security-service-desk-obfuscate-email-api-15-11' into '15-11-stable-ee' See merge request gitlab-org/security/gitlab!3316 Changelog: security
-
- Jun 15, 2023
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
- Jun 14, 2023
-
-
Alessio Caiazza authored
Slowly iterate MigrateSharedVulnerabilityIdentifiers See merge request https://gitlab.com/gitlab-org/gitlab/-/merge_requests/122856 Merged-by:
Alessio Caiazza <acaiazza@gitlab.com> Approved-by:
Raimund Hook <rhook@gitlab.com> Approved-by:
Tianwen Chen <tchen@gitlab.com> Approved-by:
Terri Chu <tchu@gitlab.com> Reviewed-by:
Tianwen Chen <tchen@gitlab.com> Co-authored-by:
Dominic Bauer <dbauer@gitlab.com>
-
Dominic Bauer authored
Changelog: changed EE: true
-
- Jun 06, 2023
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
Alessio Caiazza authored
Fix memory leak in CI config includes entry See merge request https://gitlab.com/gitlab-org/gitlab/-/merge_requests/122540 Merged-by:
Alessio Caiazza <acaiazza@gitlab.com> Approved-by:
Furkan Ayhan <furkanayhn@gmail.com> Approved-by:
Mark Lapierre <mlapierre@gitlab.com> Approved-by:
Grzegorz Bizon <grzegorz@gitlab.com> Co-authored-by:
Grzegorz Bizon <grzesiek.bizon@gmail.com>
-
Alessio Caiazza authored
LFS: Serve pre-signed URLs in `/lfs/objects/batch` (backport to 15.11) See merge request https://gitlab.com/gitlab-org/gitlab/-/merge_requests/122348 Merged-by:
Alessio Caiazza <acaiazza@gitlab.com> Approved-by:
Grzegorz Bizon <grzegorz@gitlab.com> Reviewed-by:
Kamil Trzciński <ayufan@ayufan.eu> Co-authored-by:
Kamil Trzciński <ayufan@ayufan.eu>
-
Alessio Caiazza authored
-