diff options
author | Robert Speicher <robert@gitlab.com> | 2018-01-03 21:00:36 +0300 |
---|---|---|
committer | Rémy Coutable <remy@rymai.me> | 2018-01-15 13:23:06 +0300 |
commit | 6ea4cdcc41e6382e22732119c930b689f5bcdb94 (patch) | |
tree | 58b9794d0ec2d5b5ab3f5ad262c64ca6093ec481 /doc/ci | |
parent | 69c0d7494df25c872411af903f453819ff944dac (diff) |
Merge branch 'ac/fix-path-traversal' into 'security-10-3'
[10.3] Fix path traversal in gitlab-ci.yml cache:key
See merge request gitlab/gitlabhq!2270
(cherry picked from commit c32d0c6807dfd41d7838a35742e6d0986871b389)
df29094a Fix path traversal in gitlab-ci.yml cache:key
Diffstat (limited to 'doc/ci')
-rw-r--r-- | doc/ci/yaml/README.md | 2 |
1 files changed, 1 insertions, 1 deletions
diff --git a/doc/ci/yaml/README.md b/doc/ci/yaml/README.md index 32464cbb259..a3cbb843908 100644 --- a/doc/ci/yaml/README.md +++ b/doc/ci/yaml/README.md @@ -258,7 +258,7 @@ The `cache:key` variable can use any of the [predefined variables](../variables/ The default key is **default** across the project, therefore everything is shared between each pipelines and jobs by default, starting from GitLab 9.0. ->**Note:** The `cache:key` variable cannot contain the `/` character. +>**Note:** The `cache:key` variable cannot contain the `/` character, or the equivalent URI encoded `%2F`; a value made only of dots (`.`, `%2E`) is also forbidden. --- |