From 13843483e886298efcf468eed14872079c53a9bf Mon Sep 17 00:00:00 2001 From: Robert Speicher Date: Thu, 7 Sep 2017 20:23:04 -0400 Subject: [PATCH] Remove changelogs we've already released in the security patches --- changelogs/unreleased/29943-environment-folder.yml | 4 ---- changelogs/unreleased/dm-go-get-xss.yml | 4 ---- changelogs/unreleased/fix-escape-commit-block.yml | 5 ----- changelogs/unreleased/rs-issue-36098.yml | 4 ---- changelogs/unreleased/rs-issue-36104.yml | 4 ---- 5 files changed, 21 deletions(-) delete mode 100644 changelogs/unreleased/29943-environment-folder.yml delete mode 100644 changelogs/unreleased/dm-go-get-xss.yml delete mode 100644 changelogs/unreleased/fix-escape-commit-block.yml delete mode 100644 changelogs/unreleased/rs-issue-36098.yml delete mode 100644 changelogs/unreleased/rs-issue-36104.yml diff --git a/changelogs/unreleased/29943-environment-folder.yml b/changelogs/unreleased/29943-environment-folder.yml deleted file mode 100644 index 8434d07d86e..00000000000 --- a/changelogs/unreleased/29943-environment-folder.yml +++ /dev/null @@ -1,4 +0,0 @@ ---- -title: Resolve CSRF token leakage via pathname manipulation on environments page -merge_request: -author: diff --git a/changelogs/unreleased/dm-go-get-xss.yml b/changelogs/unreleased/dm-go-get-xss.yml deleted file mode 100644 index bf0a7f4bd3d..00000000000 --- a/changelogs/unreleased/dm-go-get-xss.yml +++ /dev/null @@ -1,4 +0,0 @@ ---- -title: Fix XSS issue in go-get handling -merge_request: -author: diff --git a/changelogs/unreleased/fix-escape-commit-block.yml b/changelogs/unreleased/fix-escape-commit-block.yml deleted file mode 100644 index 0665c8e5db2..00000000000 --- a/changelogs/unreleased/fix-escape-commit-block.yml +++ /dev/null @@ -1,5 +0,0 @@ ---- -title: Prevent a persistent XSS in the commit author block -merge_request: -author: -type: security diff --git a/changelogs/unreleased/rs-issue-36098.yml b/changelogs/unreleased/rs-issue-36098.yml deleted file mode 100644 index 56b92705a80..00000000000 --- a/changelogs/unreleased/rs-issue-36098.yml +++ /dev/null @@ -1,4 +0,0 @@ ---- -title: Disallow arbitrary properties in `th` and `td` `style` attributes -merge_request: -author: diff --git a/changelogs/unreleased/rs-issue-36104.yml b/changelogs/unreleased/rs-issue-36104.yml deleted file mode 100644 index b050cd83175..00000000000 --- a/changelogs/unreleased/rs-issue-36104.yml +++ /dev/null @@ -1,4 +0,0 @@ ---- -title: Disallow the `name` attribute on all user-provided markup -merge_request: -author: