gitlab-org--gitlab-foss/changelogs
Robert Speicher edf7dbfacd Merge branch 'html-safe-diff-line-content' into 'security'
Don't accidentally mark unsafe diff lines as HTML safe

Fixes potential XSS issue when a legacy diff note is created on a merge
request whose diff contained HTML

See https://gitlab.com/gitlab-org/gitlab-ce/issues/25249

See merge request !2040
2016-12-08 21:38:35 -03:00
..
unreleased Merge branch 'html-safe-diff-line-content' into 'security' 2016-12-08 21:38:35 -03:00
archive.md Archive CHANGELOG entries prior to 8.0 in changelogs/archive.md 2016-09-09 14:36:01 -04:00