- May 08, 2024
-
-
JiHu Release Tools Bot authored
[merge-train skip]
-
JiHu Release Tools Bot authored
[ci skip]
-
Chao Mao authored
Prepare 16.10.5 release for gitlab-jh See merge request gitlab-cn/gitlab!2451
-
RELEASE_BOT_PRODUCTION_TOKEN authored
-
RELEASE_BOT_PRODUCTION_TOKEN authored
-
- May 07, 2024
-
-
GitLab Release Tools Bot authored
[merge-train skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
Update GITHUB_MEDIA_CDN to avoid SSRF when importing from Github See merge request https://gitlab.com/gitlab-org/security/gitlab/-/merge_requests/4012 Merged-by:
GitLab Release Tools Bot <delivery-team+release-tools@gitlab.com> Approved-by:
Aaron Huntsman <ahuntsman@gitlab.com> Co-authored-by:
Ivane Gkomarteli <igkomarteli@gitlab.com>
-
Ivane Gkomarteli authored
Merge branch 'security-github-media-cdn-ssrf-16-10' into '16-10-stable-ee' See merge request gitlab-org/security/gitlab!4012 Changelog: security
-
GitLab Release Tools Bot authored
Merge branch 'security-fix-namespace-banned-user-sees-proj-confidential-issue-updates-16-10' into '16-10-stable-ee' Prevent namespace banned users from reading project todos See merge request https://gitlab.com/gitlab-org/security/gitlab/-/merge_requests/3940 Merged-by:
GitLab Release Tools Bot <delivery-team+release-tools@gitlab.com> Approved-by:
Mario Celi <mcelicalderon@gitlab.com> Co-authored-by:
Eugie Limpin <elimpin@gitlab.com>
-
Eugie Limpin authored
Merge branch 'security-fix-namespace-banned-user-sees-proj-confidential-issue-updates-16-10' into '16-10-stable-ee' See merge request gitlab-org/security/gitlab!3940 Changelog: security
-
GitLab Release Tools Bot authored
Merge branch 'security-unauthenticated-redos-in-gitrefsfinder-when-using-wildcards-in-branch-search-16-10' into '16-10-stable-ee' ReDoS in GitRefsFinder when using wildcards in branch search See merge request https://gitlab.com/gitlab-org/security/gitlab/-/merge_requests/3996 Merged-by:
GitLab Release Tools Bot <delivery-team+release-tools@gitlab.com> Approved-by:
Sashi Kumar Kumaresan <skumar@gitlab.com> Co-authored-by:
Javiera Tapia <jtapia@gitlab.com>
-
Javiera Tapia authored
Merge branch 'security-unauthenticated-redos-in-gitrefsfinder-when-using-wildcards-in-branch-search-16-10' into '16-10-stable-ee' See merge request gitlab-org/security/gitlab!3996 Changelog: security
-
GitLab Release Tools Bot authored
ReDos in escape and commit reference filters See merge request https://gitlab.com/gitlab-org/security/gitlab/-/merge_requests/3973 Merged-by:
GitLab Release Tools Bot <delivery-team+release-tools@gitlab.com> Approved-by:
Allison Browne <abrowne@gitlab.com> Co-authored-by:
Brett Walker <bwalker@gitlab.com>
-
Brett Walker authored
Merge branch 'security-fix-escape-filters-16-10' into '16-10-stable-ee' See merge request gitlab-org/security/gitlab!3973 Changelog: security
-
GitLab Release Tools Bot authored
Validate request origin before MR approval See merge request https://gitlab.com/gitlab-org/security/gitlab/-/merge_requests/4008 Merged-by:
GitLab Release Tools Bot <delivery-team+release-tools@gitlab.com> Approved-by:
Drew Blessing <drew@gitlab.com> Co-authored-by:
Sam Figueroa <sfigueroa@gitlab.com>
-
Sam Figueroa authored
Merge branch 'security-sec-1060-gitlab-438686_16-10-ee-backport' into '16-10-stable-ee' See merge request gitlab-org/security/gitlab!4008 Changelog: security
-
GitLab Release Tools Bot authored
Check request size before updating user pins See merge request https://gitlab.com/gitlab-org/security/gitlab/-/merge_requests/4015 Merged-by:
GitLab Release Tools Bot <delivery-team+release-tools@gitlab.com> Approved-by:
Mario Celi <mcelicalderon@gitlab.com> Co-authored-by:
Thomas Hutterer <thutterer@gitlab.com>
-
Thomas Hutterer authored
Merge branch 'security-pins-max-size-16-10' into '16-10-stable-ee' See merge request gitlab-org/security/gitlab!4015 Changelog: security
-
GitLab Release Tools Bot authored
Enforce per_page validation for Branches/TagsFinders See merge request https://gitlab.com/gitlab-org/security/gitlab/-/merge_requests/3999 Merged-by:
GitLab Release Tools Bot <delivery-team+release-tools@gitlab.com> Approved-by:
Hunter Stewart <hustewart@gitlab.com> Co-authored-by:
Vasilii Iakliushin <viakliushin@gitlab.com>
-
Vasilii Iakliushin authored
Merge branch 'security-enforce-max_page-validation-16-10' into '16-10-stable-ee' See merge request gitlab-org/security/gitlab!3999 Changelog: security
-
GitLab Release Tools Bot authored
Update Integrations::Discord::ATTACHMENT_REGEX regex See merge request https://gitlab.com/gitlab-org/security/gitlab/-/merge_requests/3987 Merged-by:
GitLab Release Tools Bot <delivery-team+release-tools@gitlab.com> Approved-by:
Luke Duncalfe <lduncalfe@gitlab.com> Co-authored-by:
George Koltsov <gkoltsov@gitlab.com>
-
George Koltsov authored
Merge branch 'security-discord-integration-regex-16-10' into '16-10-stable-ee' See merge request gitlab-org/security/gitlab!3987 Changelog: security
-
GitLab Release Tools Bot authored
Update BaseMessage::RELATIVE_LINK_REGEX regex See merge request https://gitlab.com/gitlab-org/security/gitlab/-/merge_requests/3993 Merged-by:
GitLab Release Tools Bot <delivery-team+release-tools@gitlab.com> Approved-by:
Robert May <rmay@gitlab.com> Co-authored-by:
George Koltsov <gkoltsov@gitlab.com>
-
George Koltsov authored
Merge branch 'security-google-chat-integration-regex-16-10' into '16-10-stable-ee' See merge request gitlab-org/security/gitlab!3993 Changelog: security
-
GitLab Release Tools Bot authored
Require confirmation before linking JWT identity See merge request https://gitlab.com/gitlab-org/security/gitlab/-/merge_requests/3991 Merged-by:
GitLab Release Tools Bot <delivery-team+release-tools@gitlab.com> Approved-by:
Bogdan Denkovych <bdenkovych@gitlab.com> Co-authored-by:
Drew Blessing <drew@gitlab.com>
-
Drew Blessing authored
Merge branch 'security-dblessing_jwt_confirm_id_link-16-10' into '16-10-stable-ee' See merge request gitlab-org/security/gitlab!3991 Changelog: security
-
GitLab Release Tools Bot authored
Fix confidentiality check optimization See merge request https://gitlab.com/gitlab-org/security/gitlab/-/merge_requests/4003 Merged-by:
GitLab Release Tools Bot <delivery-team+release-tools@gitlab.com> Approved-by:
Stan Hu <stanhu@gmail.com> Co-authored-by:
Heinrich Lee Yu <heinrich@gitlab.com>
-
Heinrich Lee Yu authored
Merge branch 'security-1079-fix-confidentiality-check-optimization-16-10' into '16-10-stable-ee' See merge request gitlab-org/security/gitlab!4003 Changelog: security
-
- May 03, 2024
-
-
Mayra Cabrera authored
Cherry-pick MR 151750 into '16-10-stable-ee' See merge request https://gitlab.com/gitlab-org/gitlab/-/merge_requests/151904 Merged-by:
Mayra Cabrera <mcabrera@gitlab.com> Approved-by:
David Dieulivol <ddieulivol@gitlab.com> Co-authored-by:
Dat Tang <dattang@gitlab.com>
-
Dat Tang authored
Fix passing down variables to release_environments pipeline See merge request https://gitlab.com/gitlab-org/gitlab/-/merge_requests/151750 Merged-by:
Dat Tang <dattang@gitlab.com> Approved-by:
Rémy Coutable <remy@rymai.me> (cherry picked from commit cc2a6cbf) ec48511c Fix passing down variables to release_environments pipeline Co-authored-by:
Dat Tang <dattang@gitlab.com>
-
- May 02, 2024
-
-
Mayra Cabrera authored
Changed the email validation for only encoded chars See merge request https://gitlab.com/gitlab-org/gitlab/-/merge_requests/151529 Merged-by:
Mayra Cabrera <mcabrera@gitlab.com> Approved-by:
Bogdan Denkovych <bdenkovych@gitlab.com> Approved-by:
Mayra Cabrera <mcabrera@gitlab.com> Co-authored-by:
smriti <sgarg@gitlab.com>
-
- Apr 30, 2024
-
-
Mayra Cabrera authored
Merge branch 'release-environment-notification' into '16-10-stable-ee' See merge request https://gitlab.com/gitlab-org/gitlab/-/merge_requests/151535 Merged-by:
Mayra Cabrera <mcabrera@gitlab.com> Approved-by:
Mayra Cabrera <mcabrera@gitlab.com> Co-authored-by:
Dat Tang <dattang@gitlab.com>
-
Dat Tang authored
Add release environment notification See merge request https://gitlab.com/gitlab-org/gitlab/-/merge_requests/149268 Merged-by:
Dat Tang <dattang@gitlab.com> Approved-by:
David Dieulivol <ddieulivol@gitlab.com> Reviewed-by:
Mayra Cabrera <mcabrera@gitlab.com> Reviewed-by:
David Dieulivol <ddieulivol@gitlab.com> (cherry picked from commit b0cf85c4 ) a44f6097 Add release environment notification 0f664361 Change stage names to be start and finish to be more extendable 00055bdf Improve release environment pipeline fd76aeec Write spec for release environment notification 1b3e181d Add delivery as feature_category to the spec c8ed2307 Update from feedback 4c1d75c8 Update from feedback 94086cbe Fix rspec after removing checking CI_PIPELINE_ID 5ad5ad9f Add notification when QA fails 5fee001a Rename environment variables a47f7799 Remove feature branch when calling pipeline aa3c4ccf Update rspec for release_environment 15b63838 Fix code coverage c427c30c Small refactors from MR review feedback 2c67b70d Fix passing VERSION variable to jobs correctly c3d89451 Speed up downloading gitlab repo in CI jobs 8c7ddfe1 Add rspec for initialize method 43774757 Update GIT_DEPTH to 20 Co-authored-by:
Dat Tang <dattang@gitlab.com>
-
smriti authored
Email validation was added earlier to stop user from entering encoded email format. Regexp introduced earlier caused existing email ids in system to throw errors while logging in. With this change we are limiting the regex to only check for ecoded emails. Changelog: fixed MR: https://gitlab.com/gitlab-org/gitlab/-/merge_requests/151484/
-
- Apr 25, 2024
-
-
Mayra Cabrera authored
Return or display Gitlab version if GITLAB_KAS_VERSION is a SHA See merge request https://gitlab.com/gitlab-org/gitlab/-/merge_requests/150602 Merged-by:
Mayra Cabrera <mcabrera@gitlab.com> Approved-by:
Anna Vovchenko <avovchenko@gitlab.com> Approved-by:
Hunter Stewart <hustewart@gitlab.com> Co-authored-by:
Pam Artiaga <partiaga@gitlab.com>
-
JiHu Release Tools Bot authored
[merge-train skip]
-
JiHu Release Tools Bot authored
[ci skip]
-
Chao Mao authored
-