1. 28 May, 2019 10 commits
  2. 25 May, 2019 1 commit
  3. 24 May, 2019 1 commit
  4. 23 May, 2019 1 commit
  5. 22 May, 2019 1 commit
    • Douwe Maan's avatar
      Protect Gitlab::HTTP against DNS rebinding attack · 1de0a033
      Douwe Maan authored
      Gitlab::HTTP now resolves the hostname only once, verifies the IP is not
      blocked, and then uses the same IP to perform the actual request, while
      passing the original hostname in the `Host` header and SSL SNI field.
      1de0a033
  6. 21 May, 2019 1 commit
  7. 20 May, 2019 1 commit
  8. 19 May, 2019 1 commit
  9. 06 May, 2019 2 commits
    • Mark Chao's avatar
      Validate MR branch names · cec5d2e8
      Mark Chao authored
      Prevents refspec as branch name, which would bypass branch protection
      when used in conjunction with rebase.
      
      HEAD seems to be a special case with lots of occurrence,
      so it is considered valid for now.
      
      Another special case is `refs/head/*`, which can be imported.
      cec5d2e8
    • Patrick Derichs's avatar
      Fix url redaction for issue links · fdaf1b10
      Patrick Derichs authored
      fdaf1b10
  10. 01 May, 2019 6 commits
  11. 30 Apr, 2019 4 commits
  12. 29 Apr, 2019 11 commits