Welcome to mirror list, hosted at ThFree Co, Russian Federation.

gitlab.com/gitlab-org/gitlab-foss.git - Unnamed repository; edit this file 'description' to name the repository.
summaryrefslogtreecommitdiff
AgeCommit message (Collapse)Author
2020-01-02Update VERSION to 12.5.6v12.5.6GitLab Release Tools Bot
2020-01-02Update CHANGELOG.md for 12.5.6GitLab Release Tools Bot
[ci skip]
2019-12-31Add latest changes from gitlab-org/security/gitlab@12-5-stable-eeGitLab Bot
2019-12-16Update VERSION to 12.5.5v12.5.5John T Skarbek
2019-12-16Update CHANGELOG.md for 12.5.5John T Skarbek
[ci skip]
2019-12-16Add latest changes from gitlab-org/gitlab@12-5-stable-eeGitLab Bot
2019-12-16Add latest changes from gitlab-org/gitlab@12-5-stable-eeGitLab Bot
2019-12-16Add latest changes from gitlab-org/gitlab@12-5-stable-eeGitLab Bot
2019-12-10Add latest changes from gitlab-org/gitlab@12-5-stable-eeGitLab Bot
2019-12-10Merge remote-tracking branch 'dev/12-5-stable' into 12-5-stableGitLab Release Tools Bot
2019-12-09Update VERSION to 12.5.4v12.5.4GitLab Release Tools Bot
2019-12-09Update CHANGELOG.md for 12.5.4GitLab Release Tools Bot
[ci skip]
2019-12-09Merge branch 'security-37766-transfer-group-reindex-ce-12-5' into '12-5-stable'Alessio Caiazza
Trigger Elasticsearch indexing when public group moved to private See merge request gitlab/gitlabhq!3577
2019-12-06Trigger Elasticsearch indexing when public group moved to privateDylan Griffith
This fixes https://gitlab.com/gitlab-org/gitlab/issues/37766 which is caused by the fact that we leave the stale permissions data in the index after a group is moved to another group.
2019-12-05Add latest changes from gitlab-org/gitlab@12-5-stable-eeGitLab Bot
2019-12-03Add latest changes from gitlab-org/gitlab@12-5-stable-eeGitLab Bot
2019-12-03Update VERSION to 12.5.3v12.5.3GitLab Release Tools Bot
2019-12-03Update CHANGELOG.md for 12.5.3GitLab Release Tools Bot
[ci skip]
2019-12-03Add latest changes from gitlab-org/gitlab@12-5-stable-eeGitLab Bot
2019-11-27Add latest changes from gitlab-org/gitlab@12-5-stable-eeGitLab Bot
2019-11-27Merge remote-tracking branch 'dev/12-5-stable' into 12-5-stableGitLab Release Tools Bot
2019-11-27Update VERSION to 12.5.2v12.5.2GitLab Release Tools Bot
2019-11-27Update CHANGELOG.md for 12.5.2GitLab Release Tools Bot
[ci skip]
2019-11-27Add latest changes from gitlab-org/gitlab@12-5-stable-eeGitLab Bot
2019-11-27Merge remote-tracking branch 'dev/12-5-stable' into 12-5-stableGitLab Release Tools Bot
2019-11-26Merge branch 'security-dos-issue-and-commit-comments-12-5' into '12-5-stable'GitLab Release Tools Bot
Fix invalid byte sequence See merge request gitlab/gitlabhq!3547
2019-11-26Update VERSION to 12.5.1v12.5.1GitLab Release Tools Bot
2019-11-26Update CHANGELOG.md for 12.5.1GitLab Release Tools Bot
[ci skip]
2019-11-26Merge branch 'security-29660-update-dependencies-12-5' into '12-5-stable'GitLab Release Tools Bot
Update Workhorse and Gitaly to fix a security issue See merge request gitlab/gitlabhq!3531
2019-11-26Merge branch 'security-aws-secret-key-2937-ce-12-5' into '12-5-stable'GitLab Release Tools Bot
Hide AWS secret on Admin Integration page See merge request gitlab/gitlabhq!3532
2019-11-26Hide AWS secret on Admin Integration pageJustin Ho Tuan Duong
2019-11-26Merge branch 'security-ag-cycle-analytics-guest-permissions-12-5' into ↵GitLab Release Tools Bot
'12-5-stable' Prevent guests from seeing commits for cycle analytics See merge request gitlab/gitlabhq!3534
2019-11-26Merge branch 'security-filter-related-branches-from-activity-feed-12.5' into ↵GitLab Release Tools Bot
'12-5-stable' Related Branches Visible to Guests in Issue Activity See merge request gitlab/gitlabhq!3538
2019-11-26Merge branch 'security-2943-encrypt-plaintext-tokens-12-5' into '12-5-stable'GitLab Release Tools Bot
GitLab stores AWS, Slack, Askimet, reCaptcha tokens in plaintext See merge request gitlab/gitlabhq!3543
2019-11-26Merge branch 'security-dns-rebind-ssrf-in-slack-notifications-12-5-ce' into ↵GitLab Release Tools Bot
'12-5-stable' Use Gitlab::HTTP for all chat notifications See merge request gitlab/gitlabhq!3544
2019-11-26Merge branch 'security-33712-ce-12-5' into '12-5-stable'GitLab Release Tools Bot
Fix private comment Elasticsearch leak See merge request gitlab/gitlabhq!3546
2019-11-26Merge branch 'security-fix-xss-in-label-namespace-12-5' into '12-5-stable'GitLab Release Tools Bot
Escape namespace in label references See merge request gitlab/gitlabhq!3550
2019-11-26Merge branch 'security-28802-respect-fork-parent-visibility-12-5' into ↵GitLab Release Tools Bot
'12-5-stable' Check permissions before showing a forked project's source See merge request gitlab/gitlabhq!3555
2019-11-26Merge branch 'security-exclude_ids_attribute_cleaning-12-5-ce' into ↵GitLab Release Tools Bot
'12-5-stable' Ensure attributes that end in `_ids` are cleaned See merge request gitlab/gitlabhq!3558
2019-11-26Spec to ensure `_ids` are cleaned by ImportExport::AttributeCleanerImre Farkas
2019-11-26Ensure attributes that end in `_ids` are cleanedDJ Mountney
This prevents an issue where you can steal other projects objects by asking for ids that don't belong to you in import.
2019-11-25Check permissions before showing a forked project's sourceNick Thomas
2019-11-25Encrypt application settings with pre and post deploymentsArturo Herrero
We had concerns about the cached values on Redis with the previous two releases strategy: First release (this commit): - Create new encrypted fields in the database. - Start populating new encrypted fields, read the encrypted fields or fallback to the plaintext fields. - Backfill the data removing the plaintext fields to the encrypted fields. Second release: - Remove the virtual attribute (created in step 2). - Drop plaintext columns from the database (empty columns after step 3). We end up with a better strategy only using migration scripts in one release: - Pre-deployment migration: Add columns required for storing encrypted values. - Pre-deployment migration: Store the encrypted values in the new columns. - Post-deployment migration: Remove the old unencrypted columns
2019-11-25Escape namespace in label referencesHeinrich Lee Yu
When referencing cross-namespace labels, we append the namespace name to the rendered label. This MR escapes the name to prevent XSS attacks.
2019-11-22Add latest changes from gitlab-org/gitlab@12-5-stable-eeGitLab Bot
2019-11-22Fix invalid byte sequencePatrick Derichs
2019-11-22Add search_helpers changes from security-33712Dylan Griffith
2019-11-22Fix group created from other test from pollutingMark Chao
2019-11-22Test admin for search accessibilityMark Chao
Disabled features are ignored as they are grey areas
2019-11-22Internalize private project minimum access levelMark Chao
Some feature allows GUEST to access only if project is not private. This method returns access level when targeting private projects.