BigW Consortium Gitlab
Skip to content
Projects
Groups
Snippets
Help
This project
Loading...
Sign in / Register
Toggle navigation
G
gitlab-ce
Project
Overview
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
Registry
Registry
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Commits
Issue Boards
Open sidebar
Forest Godfrey
gitlab-ce
Commits
6926edd0
Commit
6926edd0
authored
Jan 11, 2018
by
Oswaldo Ferreira
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
Update CHANGELOG.md for 10.1.6
[ci skip]
parent
7b54e82a
Hide whitespace changes
Inline
Side-by-side
Showing
9 changed files
with
14 additions
and
41 deletions
+14
-41
CHANGELOG.md
CHANGELOG.md
+14
-0
ac-41346-xss-ci-job-output.yml
changelogs/unreleased/ac-41346-xss-ci-job-output.yml
+0
-5
api-no-service-pw-output.yml
changelogs/unreleased/api-no-service-pw-output.yml
+0
-5
fix-import-rce.yml
changelogs/unreleased/fix-import-rce.yml
+0
-5
jej-fix-disabled-oauth-access.yml
changelogs/unreleased/jej-fix-disabled-oauth-access.yml
+0
-5
milestones-finder-order-fix.yml
changelogs/unreleased/milestones-finder-order-fix.yml
+0
-5
projectfix.yml
changelogs/unreleased/projectfix.yml
+0
-6
security-10-3.yml
changelogs/unreleased/security-10-3.yml
+0
-5
sh-migrate-can-push-to-deploy-keys-projects.yml
...nreleased/sh-migrate-can-push-to-deploy-keys-projects.yml
+0
-5
No files found.
CHANGELOG.md
View file @
6926edd0
...
...
@@ -2,6 +2,20 @@
documentation](doc/development/changelog.md) for instructions on adding your own
entry.
## 10.1.6 (2018-01-11)
### Security (8 changes, 1 of them is from the community)
-
Fix writable shared deploy keys.
-
Filter out sensitive fields from the project services API. (Robert Schilling)
-
Fix RCE via project import mechanism.
-
Prevent OAuth login POST requests when a provider has been disabled.
-
Prevent a SQL injection in the MilestonesFinder.
-
Check user authorization for source and target projects when creating a merge request.
-
Fix path traversal in gitlab-ci.yml cache:key.
-
Fix XSS vulnerability in pipeline job trace.
## 10.1.5 (2017-12-07)
### Security (5 changes)
...
...
changelogs/unreleased/ac-41346-xss-ci-job-output.yml
deleted
100644 → 0
View file @
7b54e82a
---
title
:
Fix XSS vulnerability in pipeline job trace
merge_request
:
author
:
type
:
security
changelogs/unreleased/api-no-service-pw-output.yml
deleted
100644 → 0
View file @
7b54e82a
---
title
:
Filter out sensitive fields from the project services API
merge_request
:
author
:
Robert Schilling
type
:
security
changelogs/unreleased/fix-import-rce.yml
deleted
100644 → 0
View file @
7b54e82a
---
title
:
Fix RCE via project import mechanism
merge_request
:
author
:
type
:
security
changelogs/unreleased/jej-fix-disabled-oauth-access.yml
deleted
100644 → 0
View file @
7b54e82a
---
title
:
Prevent OAuth login POST requests when a provider has been disabled
merge_request
:
author
:
type
:
security
changelogs/unreleased/milestones-finder-order-fix.yml
deleted
100644 → 0
View file @
7b54e82a
---
title
:
Prevent a SQL injection in the MilestonesFinder
merge_request
:
author
:
type
:
security
changelogs/unreleased/projectfix.yml
deleted
100644 → 0
View file @
7b54e82a
---
title
:
Check user authorization for source and target projects when creating a merge
request.
merge_request
:
author
:
type
:
security
changelogs/unreleased/security-10-3.yml
deleted
100644 → 0
View file @
7b54e82a
---
title
:
Fix path traversal in gitlab-ci.yml cache:key
merge_request
:
author
:
type
:
security
changelogs/unreleased/sh-migrate-can-push-to-deploy-keys-projects.yml
deleted
100644 → 0
View file @
7b54e82a
---
title
:
Fix writable shared deploy keys
merge_request
:
author
:
type
:
security
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment