You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Configure mermaid to not render HTML content in diagrams.
Fix a possible symlink time of check to time of use race condition in GitLab Pages.
Removed ability to see private group names when the group id is entered in the url.
Fix stored XSS for Environments.
Fix persistent symlink in project import.
Fixed ability of guest users to edit/delete comments on locked or confidential issues.
Fixed ability to comment on locked/confidential issues.
Fix CRLF vulnerability in Project hooks.
Fix SSRF in project integrations.
Resolve reflected XSS in Ouath authorize window.
Restrict Personal Access Tokens to API scope on web requests.
Provide email notification when a user changes their email address.
Don't expose confidential information in commit message list.
Validate LFS hrefs before downloading them.
Do not follow redirects in Prometheus service when making http requests to the configured api url.
Escape user fullname while rendering autocomplete template to prevent XSS.
Redact sensitive information on gitlab-workhorse log.
Fix milestone promotion authorization check.
Prevent a path traversal attack on global file templates.
Removed (1 change)
Remove obsolete gitlab_shell rake tasks. !22417
Fixed (86 changes, 13 of them are from the community)
Remove limit of 100 when searching repository code. !8671
Show error message when attempting to reopen an MR and there is an open MR for the same branch. !16447 (Akos Gyimesi)
Fix a bug where internal email pattern wasn't respected. !22516
Fix project selector consistency in groups issues / MRs / boards pages. !22612 (Heinrich Lee Yu)
Add empty state for graphs with no values. !22630
Fix navigating by unresolved discussions on Merge Request page. !22789
Fix "merged with [commit]" info for merge requests being merged automatically by other actions. !22794
Fixing regression issues on pages settings and details. !22821
Remove duplicate primary button in dashboard snippets on small viewports. !22902 (George Tsiolis)
Fix API::Namespaces routing to accept namepaces with dots. !22912
Switch kubernetes:active with checking in Auto-DevOps.gitlab-ci.yml. !22929
Avoid Gitaly RPC errors when fetching diff stats. !22995
Removes promote to group label for anonymous user. !23042 (Jacopo Beschi @jacopo-beschi)
Fix enabling project deploy key for admins. !23043
Align issue status label and confidential icon. !23046 (George Tsiolis)
Fix default sorting for subgroups and projects list. !23058 (Jacopo Beschi @jacopo-beschi)
Hashed Storage: allow migration to be retried in partially migrated projects. !23087
Fix line height of numbers in file blame view. !23090 (Johann Hubert Sonntagbauer)
Fixes an issue where default values from models would override values set in the interface (e.g. users would be set to external even though their emails matches the internal email address pattern). !23114
Remove display of local Sidekiq process in /admin/sidekiq. !23118
Fix unrelated deployment status in MR widget. !23175
Respect confirmed flag on secondary emails. !23181
Restrict member access level to be higher than that of any parent group. !23226
Return real deployment status to frontend. !23270
Handle force_remove_source_branch when creating merge request. !23281
Avoid creating invalid refs using rugged, shelling out for writing refs. !23286
Remove needless auto-capitalization on Wiki page titles. !23288
Modify the wording for the knative cluster application to match upstream. !23289 (Chris Baumbauer)
Change container width for project import. !23318 (George Tsiolis)
Validate chunk size when persist. !23341
Resolve Main navbar is broken in certain viewport widths. !23348
Gracefully handle references with null bytes. !23365
Display commit ID for commit diff discussion on merge request. !23370
Pass commit when posting diff discussions. !23371
Fix flash notice styling for fluid layout. !23382
Add monkey patch to unicorn to fix eof? problem. !23385
Commits API: Preserve file content in move operations if unspecified. !23387
Disable password autocomplete in mirror form fill. !23402
Fix "protected branches only" checkbox not set properly at init. !23409
Support RSA and ECDSA algorithms in Omniauth JWT provider. !23411 (Michael Tsyganov)
Make KUBECONFIG nil if KUBE_TOKEN is nil. !23414
Allow search and sort users at same time on admin users page. !23439
Fix: Unstar icon button is misaligned. !23444
Fix error when searching for group issues with priority or popularity sort. !23445
Fix Order By dropdown menu styling in tablet and mobile screens. !23446