gitlab-org--gitlab-foss/changelogs/unreleased
Robert Speicher 954a44574f Merge branch 'ac/fix-path-traversal' into 'security-10-3'
[10.3] Fix path traversal in gitlab-ci.yml cache:key

See merge request gitlab/gitlabhq!2270

(cherry picked from commit c32d0c6807dfd41d7838a35742e6d0986871b389)

df29094a Fix path traversal in gitlab-ci.yml cache:key
2018-01-16 17:04:38 -08:00
..
.gitkeep
3968-protected-branch-is-not-set-for-default-branch-on-import.yml Protected branch is now created for default branch on import 2018-01-06 12:20:49 +00:00
4020-rebase-message.yml Store only generic message if rebase fails 2018-01-09 17:04:28 +01:00
13695-order-contributors-in-api.yml Adds ordering to projects contributors in API 2017-12-13 18:02:20 +01:00
15832-fix-access-level-update-for-requesters.yml Bugfix: User can't change the access level of an access requester 2017-12-11 09:53:31 -05:00
15922-validate-file-status-when-commiting-multiple-files.yml Check if file has been modified for each action provided. 2017-12-20 01:24:53 -05:00
15955-improve-search-query.yml Skip projects filter on merge requests search 2017-12-21 15:43:14 +01:00
16036-ignore-lost-found-folder-during-backup-on-a-volume.yml Add changelog 2017-12-20 08:55:15 +00:00
16117-improve-search-for-issues.yml Skip projects filter on issues search 2018-01-02 12:07:26 +01:00
16301-update-removed-assignee-note-to-include-old-assignee-reference.yml Update 'removed assignee' note to include old assignee reference 2018-01-09 14:35:26 +01:00
18040-line-breaks-around-conditional-blocks.yml Adds Rubocop rule for line break around conditionals 2018-01-11 16:34:01 +00:00
19493-fork-does-not-protect-default-branch.yml Fork now protects default branch on completion 2018-01-15 16:03:25 +00:00
20035-pause-resume-runners.yml Add pause/resume button to specific project runners 2017-12-27 09:23:09 -06:00
24347-dont-post-system-note-when-branch-creation-fails.yml Fix when branch creation fails don't post system note 2017-12-26 19:29:54 +01:00
25317-prioritize-author-date-over-commit.yml Use author info on commits list page rather than most recent commit date 2017-12-11 13:49:56 -07:00
28004-consider-refactoring-member-view-by-using-presenter.yml Refactor member view by using presenter 2017-12-11 18:30:56 +01:00
28260-fix-pages-custom-domain-url.yml Generate HTTP URLs for custom Pages domains when appropriate 2018-01-08 01:30:05 +00:00
31995-project-limit-default-fix.yml User#projects_limit remove DB default and added NOT NULL constraint 2017-12-30 14:33:49 -06:00
32364-updating-slack-notification-not-working-by-api.yml Support new chat notifications parameters in Services API 2017-12-22 12:18:05 +00:00
33028-event-tag-links.yml Fix tags in the Activity tab not being clickable 2017-12-19 17:02:56 +00:00
33609-hide-pagination.yml Do not show Vue pagination if only one page 2017-12-21 10:43:08 -06:00
33926-update-issuable-icons.yml Update issuable status icons 2017-12-13 00:11:57 -06:00
34534-switch-to-axios.yml Add changelog for some vue-resource to Axios refactor 2018-01-02 18:01:48 -06:00
36020-private-npm-modules.yml BlobViewer::PackageJson - if private link to homepage 2017-12-18 23:18:23 -06:00
36571-ignore-root-in-repo.yml Update 36571-ignore-root-in-repo.yml 2018-01-15 11:06:16 +00:00
36669-default-mr-title-with-external-issues.yml Give appropriate credit to Ben305 in the changelog 2018-01-10 13:50:38 +00:00
36782-replace-team-user-role-with-add_role-user-in-specs.yml Replace '.team << [user, role]' with 'add_role(user)' in specs 2017-12-22 19:18:28 +11:00
36906-reordering-issues-to-the-bottom.yml Fixing re-ordering of an issue when dragging it to the bottom a long issue list in the board 2018-01-09 09:24:08 +00:00
36958-enable-ordering-projects-subgroups-by-name.yml Enable sorting by name in the Groups dropdown 2017-12-20 19:34:50 +00:00
37843-ci-trace-ansi-colours-256-bold-have-no-css-due-wrongly-ansi2html-light-color-variant-conversion-feature.yml fix issue #37843 2018-01-03 20:57:41 +00:00
37898-increase-readability-of-colored-text-in-job-output-log.yml fix readability xterm colors 2018-01-16 18:25:06 +00:00
38019-hide-runner-token.yml Hide runner token in CI/CD settings page 2017-12-15 14:06:55 -06:00
38030-add-graph-value-to-hover.yml Resolve "Add graph value to hover" 2018-01-08 09:35:23 +00:00
38068-commits-count.yml Denormalize commits count for merge request diffs 2018-01-10 20:40:02 +01:00
38145_ux_issues_in_system_info_page.yml Fix UX issues in system info page 2017-12-15 12:37:01 +00:00
38239-update-toggle-design.yml Add changelog entry 2017-12-15 22:08:04 +05:30
38318-search-merge-requests-with-api.yml Add optional search param for Merge Requests API 2017-12-20 07:23:57 +00:00
38540-ssh-env-file.yml Remove .ssh/environment file that now breaks the gitlab:check rake task 2017-12-22 13:52:09 +00:00
38541-cancel-alignment.yml fix button alignment on MWPS component 2017-12-11 17:24:06 +11:00
38596-fix-backspace-visual-token-clearing.yml Clears visual token on second backspace 2018-01-02 13:12:54 +00:00
38893-banzai-upload-filter-relative-urls.yml Use relative URLs when linking to uploaded files 2017-12-22 15:09:16 +00:00
39214__pipeline_api.yml Add pipelines endpoint to merge requests API 2017-12-15 19:53:57 +03:00
39246-fork-and-import-jobs-should-only-be-marked-as-failed-when-the-number-of-retries-was-exhausted.yml Fork and Import jobs only get marked as failed when the number of Sidekiq retries were exhausted 2017-12-15 09:54:10 +00:00
39298-list-of-avatars-2.yml List of avatars should never show +1 2017-12-18 11:48:38 +01:00
39608-comment-on-image-discussions-tab-alignment.yml Fix comment on image discussion icon alignment 2017-12-08 04:30:13 -06:00
39957-redirect-to-gpc-page-if-users-try-to-create-a-cluster-but-the-account-is-not-enabled.yml Add CHANGELOG entry 2018-01-06 20:10:08 +01:00
39988-hide-new-branch-tag-empty-repo.yml Hide new branch and tag links for projects with an empty repo 2018-01-09 18:04:41 +00:00
40031-include-assset_sync-gem.yml Resolve "Include asset_sync gem" 2017-12-08 17:04:48 +00:00
40040-decouple-multi-file-editor-from-file-list.yml Resolve "Decouple multi-file editor from file list" 2017-12-21 15:05:47 +00:00
40063-markdown-editor-improvements.yml Hide toolbar in markdown preview mode 2017-12-18 14:20:14 -07:00
40190-fix-slash-commands-dropdown-description-mis-alignement-on-firefox.yml Fix slash commands dropdown description 2018-01-08 09:27:50 +00:00
40228-verify-integrity-of-repositories.yml add missing changelog 2018-01-04 11:22:43 +01:00
40274-user-settings-breadcrumbs.yml Add breadcrumbs to User Settings sub-views 2018-01-01 17:45:20 +00:00
40301-rebase.yml Backport 'Rebase' feature from EE to CE 2018-01-05 09:34:59 +01:00
40418-migrate-existing-data-from-kubernetesservice-to-clusters-platforms-kubernetes.yml Fix change log 2018-01-08 16:22:18 +09:00
40453-fix-api-endpoints-to-edit-wiki-pages-where-project-belongs-to-a-group.yml Fix API endpoints to edit wiki pages where project belongs to a group 2018-01-03 00:22:01 -05:00
40492-update-admin-dashboard-content-order.yml Move row containing Projects, Users and Groups count to the top 2018-01-12 19:45:05 +00:00
40509_sorting_tags_api.yml sorting for tags api 2017-12-14 13:42:15 +00:00
40533-groups-tree-updates.yml Add changelog entry 2017-12-26 13:29:35 +05:30
40549-render-emoj-in-groups-overview.yml Rendering of emoji's in Group-Overview 2017-12-24 12:14:17 +01:00
40622-use-left-right-and-max-count.yml Use --left-right and --max-count for counting diverging commits 2018-01-05 16:52:06 +00:00
40780-choose-file.yml Update Browse file to Choose file in all occurences 2017-12-21 17:34:20 +00:00
40818-last-push-widget-does-not-appear-after-pushing-new-commit.yml Last push widget will show banner for new pushes to previously merged branch 2018-01-15 16:45:56 -06:00
40871-todo-notification-count-shows-notification-without-having-a-todo.yml Reset todo counters when the target is deleted 2017-12-18 12:23:00 +00:00
40895-fix-frequent-projects-stale-path.yml Use relative URL for projects to avoid storing domains 2017-12-13 09:16:30 +00:00
41016-import-gitlab-shell-projects.yml Import gitlab_projects.rb from gitlab-shell 2017-12-14 16:00:04 +00:00
41053-extend-cluster-applications-to-allow-install-to-prometheus.yml Extend Cluster Applications to allow installation of Prometheus 2017-12-22 17:23:43 +00:00
41054-disable-creation-of-new-kubernetes-integrations.yml 41054-Disallow creation of new Kubernetes integrations 2018-01-04 09:33:51 +00:00
41056-create-cluster-from-kubernetes-integration-application-template.yml Create Kubernetes based on Application Templates 2018-01-04 22:35:41 +00:00
41163-improve-cluster-ingress-extra-cost-language.yml Update Ingress extra cost note to be more generic 2018-01-11 12:37:54 -06:00
41244-issue-board-shortcut-working-while-no-issues.yml disables the shortcut to the issue boards when issues are disabled 2018-01-08 09:06:25 +00:00
41249-clearing-the-cache.yml Add CHANGELOG entry 2018-01-05 16:54:07 +01:00
41268-bump-ruby-to-2-3-6.yml Update Ruby version to 2.3.6 2017-12-21 15:51:54 +01:00
41424-gitlab-rake-gitlab-import-repos-schedules-an-import.yml Update 41424-gitlab-rake-gitlab-import-repos-schedules-an-import.yml 2018-01-02 10:42:18 +01:00
41468-error-500-trying-to-view-a-merge-request-json-undefined-method-binary-for-nil-nilclass.yml Fix error when viewing diffs without blobs 2018-01-04 14:33:12 +00:00
41476-enable-project-milestons-deletion-via-api.yml Enables Project Milestone Deletion via API 2018-01-16 13:11:59 +01:00
41491-fix-nil-blob-name-error.yml Fix 500 when visiting a commit where blobs do not exist (nil blobs) 2018-01-09 16:51:53 -06:00
41546-count-query-for-issues-and-mrs-runs-twice-on-group-index.yml Fix double execution of COUNT query on group pages 2018-01-09 11:56:41 +00:00
41600-wider-project-readme-on-fixed-layout.yml Make project README containers wider on fixed layout 2018-01-03 04:06:03 +09:00
41613-fix-redundant-modal.yml Add changelog entry 2018-01-11 16:37:16 +05:30
41666-cannot-search-with-keyword-merge-2.yml Only highlight search results under the highlighting size limit 2018-01-16 11:56:07 +00:00
41666-cannot-search-with-keyword-merge.yml Fix project search results for digits surrounded by colons 2018-01-16 11:56:07 +00:00
41709-rich-blob-viewer-margins-for-pc.yml Make rich blob viewer wider for PC 2018-01-10 23:30:55 +09:00
41731-predicate-memoization.yml Add changelog entry 2018-01-12 18:51:52 +08:00
41744-substitute-ui-charcoal-with-ui-indigo.yml Substitute deprecated ui_charcoal with new default ui_indigo 2018-01-07 13:50:40 +09:00
41749-postgres-9-6-for-ci-tests.yml Add reason to keep postgresql 9.2 for CI 2018-01-12 06:53:16 +09:00
41754-update-scss-lint-to-0-56-0.yml Update scss-lint to 0.56.0 2018-01-08 08:50:47 +09:00
41789-fix-up-web-ide-user-preference-copy-and-buttons.yml Fix up Web IDE user preference copy and buttons 2018-01-11 08:23:44 +00:00
41807-15665-consistently-502s-because-it-fetches-every-commit.yml Only search for MR revert commits on notes after MR was merged 2018-01-12 13:19:05 +00:00
41882-respect-only-path-in-relative-link-filter.yml Ensure that emails contain absolute, rather than relative, links to user uploads 2018-01-11 13:06:25 +00:00
41956-fix-ctrl-enter-binding-to-save-comment.yml Fix Ctrl+Enter keyboard shortcut saving comment/note edit 2018-01-11 20:28:56 -06:00
42025-fix-issue-api.yml [API] Fix creating issue when assignee_id is empty 2018-01-15 14:24:16 +02:00
42031-fix-links-to-uploads-in-wikis.yml Fix links to uploaded files on wiki pages 2018-01-16 16:11:02 +00:00
42046-fork-icon.yml Resolve "Icons on forks page are to big" 2018-01-16 15:52:22 +00:00
42047-pg-10-support.yml Support PostgreSQL 10 2018-01-16 14:04:50 +00:00
42055-update-marked-from-0-3-6-to-0-3-12.yml Update marked from 0.3.6 to 0.3.12 2018-01-16 08:24:23 +09:00
ac-autodevopfix-kubectl-version.yml Backport gitlab-org/gitlab-ci-yml!128 - Fix kubectl version to 1.8.6 2018-01-04 10:58:37 +01:00
add-tcp-check-rake-task.yml Add a gitlab:tcp_check rake task 2017-12-13 15:53:32 +00:00
anchor-issue-references.yml Use prefix for TableOfContents filter hrefs 2017-12-08 14:13:18 +01:00
api-domains-expose-project_id.yml Expose project_id on /api/v4/pages/domains 2018-01-03 19:36:54 +01:00
api-no-service-pw-output.yml Merge branch 'security-10-3-do-not-expose-passwords-or-tokens-in-service-integrations-api' into 'security-10-3' 2018-01-16 17:04:38 -08:00
bump_mysql_gem.yml Bumped mysql2 gem version from 0.4.5 to 0.4.10. 2017-12-21 21:28:11 -05:00
bvl-fork-public-project-to-private-namespace.yml Forking a project to a namespace with lower visibility. 2017-12-29 11:15:26 +01:00
change-issues-closed-at-background-migration.yml Use a background migration for issues.closed_at 2018-01-03 12:28:00 +01:00
changes-dropdown-ellipsis.yml Fix changes dropdown ellipsis working across browsers 2018-01-09 11:29:57 +00:00
conditionally-eager-load-event-target-authors.yml Eager load event target authors whenever possible 2018-01-04 14:32:38 +01:00
da-handle-hashed-storage-repos-using-repo-import-task.yml Add CHANGELOG 2018-01-03 16:13:32 -02:00
da-verify-integrity-of-uploaded-files.yml Add CHANGELOG 2018-01-08 19:25:32 -02:00
delay-background-migrations.yml Run background migrations with a minimum interval 2018-01-05 16:23:25 +01:00
disable-pages-on-jobs.yml Use simple Next/Prev paging for jobs to avoid large count queries on arbitrarily large sets of historical jobs 2018-01-11 17:45:42 +00:00
display-mr-in-commit-page.yml Display related merge requests in commit detail page 2018-01-12 20:38:36 +00:00
dm-diff-note-for-line-performance.yml Improve performance of DiffDiscussion#truncated_diff_lines and DiffNote#diff_line by removing expensive diff position calculation and comparison 2017-12-22 18:07:15 +01:00
docs-add-why-do-i-get-signed-out-authentication-section.yml Add docs explaining why you get signed out with "Remember me" 2017-12-08 03:49:48 -06:00
feature-40842-provide-oracles-webgate-cookies-to-jira-requests.yml Fixes 40842 - Adds extra cookies to JIRA service requests 2017-12-18 11:15:41 +00:00
feature-api_runners_online.yml Add status attribute to runner api entity 2018-01-05 11:10:28 +01:00
fix-abuse-reports-link-url.yml Fixed abuse reports link url 2017-12-28 22:48:52 +00:00
fix-activity-inline-event-line-height.yml Fix activity inline event line height on mobile 2017-12-28 01:54:51 +02:00
fix-create-mr-from-issue-with-template.yml Execute quick actions when creating MR from issue 2017-12-13 10:40:31 +00:00
fix-dashboard-projects-nav-links-height.yml Fix dashboard projects nav links height 2018-01-03 21:21:21 +02:00
fix-docs-help-shortcut.yml Fix shortcut links on help page 2017-12-19 16:18:48 +00:00
fix-gb-fix-import-export-restoring-associations.yml Add changelog entry for import/export associations fix 2018-01-05 15:20:41 +01:00
fix-last-push-event-widget-layout.yml Last push event widget width for fixed layout 2017-12-21 23:25:23 +02:00
fix-move-2fa-disable-button.yml Move 2FA disable button 2018-01-03 20:23:58 +02:00
fix-onion-skin-reenter.yml Fix onion-skin re-entering state 2017-12-19 17:54:36 +00:00
fix-profile-settings-content-width.yml Adjust content width for User Settings, GPG Keys 2017-12-28 01:47:40 +02:00
fix-profile-settings-sidebar-heading.yml Keep typographic hierarchy in User Settings 2017-12-29 01:20:05 +02:00
fix-remove-unnecessary-sidebar-element-alignment.yml Remove unnecessary sidebar element realignment 2018-01-02 20:51:56 +02:00
fix_build_count_in_pipeline_success_maild.yml Fix job count in pipeline success mail 2017-12-18 09:13:46 +00:00
fix_gitlab-ce-41891.yml remove wrong/unneeded margin of custom navigation header logo without logo text 2018-01-12 16:34:03 +01:00
fj-40053-error-500-members-list.yml Fix user membership destroy relation 2018-01-02 15:06:44 +00:00
fj-40279-normalize-ldap-dn-api.yml LDAP extern_uids are not normalized when updated via API 2017-12-21 14:31:15 +00:00
fj-41477-fix-bug-wiki-last-version.yml Fixing bug related to wiki last version 2018-01-09 16:01:09 +00:00
fj-41598-fixing-request-mime-type.yml Fixing request json mime type 2018-01-15 09:09:21 +00:00
fj-41681-add-param-disable-commit-stats-api.yml Add option to disable commit stats to commit API 2018-01-09 11:36:12 +00:00
index-namespaces-lower-name.yml Add index on namespaces lower(name) for UsersController#exists 2017-12-21 23:07:25 +00:00
issue-description-field-typo.yml corrected typo in quick action data attribute 2017-12-11 18:52:19 -08:00
issue_40500.yml Improve filtering issues by label performance 2018-01-05 13:26:30 -02:00
issue_41460.yml Fix error on changes tab when merge request cannot be created 2018-01-15 11:53:40 -02:00
issues-40986-get-participants-from-issues-mr-api.yml API: get participants from merge_requests & issues 2018-01-05 15:21:53 +00:00
jej-backport-authorized-keys-to-ce.yml Adds changelog for backport of authorized_keys DB lookup from EE 2018-01-08 20:34:38 +00:00
jej-lfs-rev-list-handles-non-utf-paths-41627.yml Prevent RevList failing on non utf8 paths 2018-01-16 13:27:59 +00:00
jivl-activate-repo-cookie-preferences.yml Added multi editor setting on the profile preferences page 2018-01-04 18:31:05 +00:00
jivl-fix-import-project-url-bug.yml Fix import project url not updating project name 2018-01-03 09:51:57 -06:00
jramsay-4012-i18n-compare.yml Add changelog entry 2018-01-03 10:32:46 -05:00
jramsay-41590-add-readme-case.yml Remove downcase from special path helper 2018-01-04 11:22:04 -05:00
ldap_username_attributes.yml Modify LDAP::Person to return username value based on attributes 2018-01-04 17:10:40 -06:00
lfs-badge.yml Added LFS badge to indicate LFS tracked files 2017-12-11 12:17:11 +00:00
milestones-finder-order-fix.yml Merge branch 'milestones-finder-order-fix' into 'security-10-3' 2018-01-16 17:04:38 -08:00
mk-fix-permanent-redirect-validation.yml Add changelog entry 2018-01-11 11:22:13 -08:00
mk-no-op-delete-conflicting-redirects.yml Make DeleteConflictingRedirectRoutes no-op 2018-01-03 12:23:20 -08:00
mr-status-box-update.yml Fixed merge request status badge not updating after merging 2018-01-15 17:06:38 +00:00
multiple-clusters-single-list.yml Add CHANGELOG entry 2017-12-11 15:28:26 +01:00
optimize-issues-avoid-noop-empty-cache-updates2.yml Treat empty markdown and html strings as valid cached text, not missing cache that needs to be updated 2017-12-12 14:01:53 +00:00
osw-introduce-merge-request-statistics.yml Cache merged and closed events data in merge_request_metrics table 2018-01-02 17:45:25 -02:00
remove-incorrect-guidance.yml fix issue #39843 Incorrect guidance stating blocked users will be removed from groups and projects as members 2017-12-15 18:56:39 +00:00
remove-links-mr-empty-state.yml Remove related links in MR widget when empty state 2017-12-19 17:50:38 +00:00
remove-soft-removals.yml Remove soft removals related code 2018-01-08 17:04:45 +01:00
remove-tabindexes-from-tag-form.yml removed tab indexes from tag form 2017-12-12 10:12:25 -08:00
security-10-3.yml Merge branch 'ac/fix-path-traversal' into 'security-10-3' 2018-01-16 17:04:38 -08:00
sh-add-schedule-pipeline-run-now.yml Add button to run scheduled pipeline immediately 2017-12-12 15:07:23 -08:00
sh-catch-invalid-uri-markdown.yml Gracefully handle garbled URIs in Markdown 2017-12-22 23:21:12 -08:00
sh-fix-award-emoji-move-issues.yml Fix bug where award emojis would be lost when moving issues between projects 2018-01-10 17:22:56 -08:00
sh-fix-bare-import-hooks.yml Fix hooks not being set up properly for bare import Rake task 2018-01-09 23:39:19 -08:00
sh-log-when-user-blocked.yml Log and send a system hook if a blocked user fails to login 2018-01-14 22:22:06 -08:00
sh-make-kib-human.yml Humanize the units of "Showing last X KiB of log" in job trace 2017-12-27 08:22:46 -08:00
sh-optimize-commit-stats.yml Speed up generation of commit stats by using Rugged native methods 2018-01-02 23:48:19 -08:00
sh-remove-shared-runners-and-more.yml Remove erroneous text in shared runners page that suggested more runners available 2018-01-15 21:01:14 -08:00
sh-store-user-in-api-logs.yml Save user ID and username in Grape API log (api_json.log) 2018-01-08 21:23:24 -08:00
sh-validate-path-project-import.yml Avoid leaving a push event empty if payload cannot be created 2018-01-03 22:49:02 -08:00
show-inline-edit-btn.yml Show inline edit button for issues 2017-12-19 17:48:29 +00:00
show_proper_labels_in_board_issue_sidebar_when_issue_is_closed.yml added changelog 2017-12-17 21:09:57 +01:00
sophie-h-gitlab-ce-patch-15.yml Hide issues and MRs in labels list if disabled 2017-12-11 20:38:53 +01:00
tc-correct-email-in-reply-to.yml Make mail notifications of discussion notes In-Reply-To of each other 2017-12-13 21:26:01 +01:00
update-redis-rack.yml Update redis-rack to 2.0.4 2018-01-05 14:10:29 +01:00
winh-modal-target-id.yml Add id to modal.vue to support data-toggle="modal" 2018-01-05 12:47:38 +01:00
winh-style-modals.yml Adjust modal style to new design 2018-01-11 10:06:44 +01:00
winh-translate-contributors-page-dates.yml Add createDateTimeFormat to format dates based on locale 2017-12-18 11:13:41 +01:00