- 04 May, 2017 6 commits
-
-
Robert Speicher authored
Fix XSS in branches dropdown See merge request !2093
-
Douwe Maan authored
Respect project features in wiki and blob search See merge request !2089
-
Sean McGivern authored
Fix snippets visibility for show action - external users can not see internal snippets See merge request !2087
-
Douwe Maan authored
Sanitize submodule URLs before linking to them in the file tree view See merge request !2084
-
Robert Speicher authored
Render asciidoc & other markup using banzai in a pipeline See merge request !2088
-
Robert Speicher authored
Add correct `rel` attributes to external links when rendering markdown See merge request !2086
-
- 06 Apr, 2017 2 commits
-
-
DJ Mountney authored
-
DJ Mountney authored
[ci skip]
-
- 05 Apr, 2017 6 commits
-
-
Sean McGivern authored
Fix for three open redirect vulns using redirect_to url_for(params.merge))) See merge request !2082
-
DJ Mountney authored
Fix for path disclosure in project import/export See merge request !2080
-
DJ Mountney authored
Previously accidently added a test for a feature that does not exist in this release : preserved styles in labels
-
Sean McGivern authored
Fix for open redirect vuln involving continue[to] params See merge request !2083
-
Sean McGivern authored
Don’t show source project name when user does not have access See merge request !2081
-
Robert Speicher authored
Remove class from SanitizationFilter whitelist See merge request !2079
-
- 19 Mar, 2017 2 commits
-
-
James Lopez authored
-
James Lopez authored
[ci skip]
-
- 18 Mar, 2017 5 commits
-
-
Rubén Dávila authored
nil check for url_blocker? See merge request !2076
-
DJ Mountney authored
fix for render json include leaks See merge request !2074 Conflicts: app/controllers/projects/merge_requests_controller.rb spec/controllers/projects/issues_controller_spec.rb
-
Jacob Schatz authored
Adds rel="noopener noreferrer" to all links with target="_blank" See merge request !2071 Conflicts: app/assets/javascripts/environments/components/environment_external_url.js
-
Douwe Maan authored
Protect server against SSRF in project import URLs See merge request !2068
-
Rémy Coutable authored
Only show public emails in atom feeds See merge request !2066
-
- 15 Mar, 2017 4 commits
-
-
Robert Speicher authored
Backport GitLab.com Pages IP change to 8.17 [ci skip] See merge request !9934
-
Rémy Coutable authored
Signed-off-by: Rémy Coutable <remy@rymai.me>
-
Rémy Coutable authored
Signed-off-by: Rémy Coutable <remy@rymai.me>
-
Rémy Coutable authored
Signed-off-by: Rémy Coutable <remy@rymai.me>
-
- 14 Mar, 2017 3 commits
-
-
Rémy Coutable authored
Include instructions to update /etc/default/gitlab See merge request !9926
-
Achilleas Pipinellis authored
Docs: update GL Pages IP on GL.com See merge request !9739
-
Achilleas Pipinellis authored
We were missing some info on updating /etc/default/gitlab In particular, changes needed to be made in order for Pages to work, see https://gitlab.com/gitlab-org/gitlab-ce/issues/29372
-
- 07 Mar, 2017 3 commits
-
-
Regis authored
-
Regis authored
[ci skip]
-
Felipe Artur authored
-
- 06 Mar, 2017 6 commits
-
-
Felipe Artur authored
Move all Pages related content to a single location See merge request !9695
-
Felipe Artur authored
-
Robert Speicher authored
Fix creating a file in an empty repo using the API Closes #28626 See merge request !9632
-
Felipe Artur authored
This reverts commit 4b692487.
-
Felipe Artur authored
This reverts commit 071bf3b7.
-
Jacob Schatz authored
Small improvements for Cycle Analytics See merge request !9153
-
- 03 Mar, 2017 3 commits
-
-
Achilleas Pipinellis authored
-
Alfredo Sumaran authored
Show milestone ID in a consistent way Closes #23602 See merge request !8820
-
Alfredo Sumaran authored
Default to dangerous MR merge button Closes #28010 See merge request !9245
-