- 28 Nov, 2018 6 commits
-
-
Cindy Pallares authored
[master] Stored XSS in Operation Page See merge request gitlab/gitlab-ee!722
-
Reuben Pereira authored
-
Cindy Pallares authored
[master] Authorize user when listing board resources Closes gitlabhq#2738 See merge request gitlab/gitlab-ee!721
-
Cindy Pallares authored
[master] Resolve: Guest can set weight of a new issue See merge request gitlab/gitlab-ee!720
-
Cindy Pallares authored
[master] Fix IDOR at /drafts/publish/ Closes #356 See merge request gitlab/gitlab-ee!710
-
Cindy Pallares authored
[master ee] Fixed ability to comment on and edit/delete comments on locked or confidential issues See merge request gitlab/gitlab-ee!739
-
- 27 Nov, 2018 3 commits
-
-
Mario de la Ossa authored
When creating comments, sending different noteable IDs for target_id and note[:noteable_id] would allow you to bypass comment creation security if the user had creation permissions for target_id. The comment would be created in note[:noteable_id]. Also made it so that users cannot edit/delete their comments on a noteable that becomes unreadable to them (if it gets flagged confidential and they don't have read access for example)
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
- 26 Nov, 2018 31 commits
-
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
GitLab Release Tools Bot authored
[ci skip]
-
Clement Ho authored
Changes the delete custom metric alert Closes #4940 See merge request gitlab-org/gitlab-ee!8430
-
Jose Ivan Vargas authored
-
Stan Hu authored
Resolve "Maven package permissions option wrongly available in Starter" Closes #8316 See merge request gitlab-org/gitlab-ee!8270
-
Stan Hu authored
Merge branch '8581-geo-the-geo-nodes-admin-page-display-secondary-database-state-incorrectly' into 'master' Rails 5: Fix the check whether the database is in read-only mode Closes #8581 See merge request gitlab-org/gitlab-ee!8594
-
Stan Hu authored
Merge branch '8583-rails5-gitlab-database-loadbalancing-caught_up-returns-state-incorrectly' into 'master' Raisl 5: Fix Gitlab::Database::LoadBalancing#caught_up? check Closes #8583 See merge request gitlab-org/gitlab-ee!8595
-
Robert Speicher authored
Extracts EE specific Sidekiq queue config to a new file See merge request gitlab-org/gitlab-ee!8470
-
🤖 GitLab Bot 🤖 authored
CE upstream - 2018-11-26 16:21 UTC See merge request gitlab-org/gitlab-ee!8592
-
Douglas Barbosa Alexandre authored
Rails 5 returns true/false instead of a string 't' or 'f'.
-
Douglas Barbosa Alexandre authored
Rails 5 returns true/false instead of a string 't' or 'f'.
-
Rémy Coutable authored
Enable some frozen string in ee/app See merge request gitlab-org/gitlab-ee!8580
-
GitLab Bot authored
-
Rémy Coutable authored
CE upstream - 2018-11-26 14:21 UTC See merge request gitlab-org/gitlab-ee!8588
-
Dmitriy Zaporozhets authored
i18n: externalize strings from 'app/views/layouts' See merge request gitlab-org/gitlab-ee!8587
-
Filipa Lacerda authored
CE port of "Move merge request approval settings" See merge request gitlab-org/gitlab-ce!23157
-
George Tsiolis authored
-
Dmitriy Zaporozhets authored
Signed-off-by: Dmitriy Zaporozhets <dmitriy.zaporozhets@gmail.com>
-
GitLab Bot authored
# Conflicts: # locale/gitlab.pot [ci skip]
-
Dmitriy Zaporozhets authored
[EE] i18n: externalize strings from 'app/views/shared/members' See merge request gitlab-org/gitlab-ee!8474
-
Fatih Acet authored
Update externalized strings from `/app/views/project/runners` See merge request gitlab-org/gitlab-ce!23347
-
Dmitriy Zaporozhets authored
i18n: externalize strings from 'app/views/shared/members' See merge request gitlab-org/gitlab-ce!23125
-
Tao Wang authored
Signed-off-by: Tao Wang <twang2218@gmail.com>
-
Dmitriy Zaporozhets authored
Packages feature is only available in Premium so we should not show this feature in settings and navigation Signed-off-by: Dmitriy Zaporozhets <dmitriy.zaporozhets@gmail.com>
-
🤖 GitLab Bot 🤖 authored
CE upstream - 2018-11-26 13:21 UTC See merge request gitlab-org/gitlab-ee!8586
-
GitLab Bot authored
-
Stan Hu authored
Batch load only data from same repository when lazy object is accessed See merge request gitlab-org/gitlab-ce!23309
-
Tao Wang authored
Signed-off-by: Tao Wang <twang2218@gmail.com> Signed-off-by: Rémy Coutable <remy@rymai.me>
-
Tao Wang authored
Signed-off-by: Tao Wang <twang2218@gmail.com> Signed-off-by: Rémy Coutable <remy@rymai.me>
-