Skip to content

Commit

Permalink
Update CHANGELOG.md for 11.11.7
Browse files Browse the repository at this point in the history
[ci skip]
  • Loading branch information
GitLab Release Tools Bot committed Jul 29, 2019
1 parent 8f26d6b commit f4ec125
Show file tree
Hide file tree
Showing 10 changed files with 15 additions and 45 deletions.
15 changes: 15 additions & 0 deletions CHANGELOG.md
Expand Up @@ -2,6 +2,21 @@
documentation](doc/development/changelog.md) for instructions on adding your own
entry.

## 11.11.7

### Security (9 changes)

- Restrict slash commands to users who can log in.
- Patch XSS issue in wiki links.
- Filter merge request params on the new merge request page.
- Fix Server Side Request Forgery mitigation bypass.
- Show badges if pipelines are public otherwise default to project permissions.
- Do not allow localhost url redirection in GitHub Integration.
- Do not show moved issue id for users that cannot read issue.
- Use source project as permissions reference for MergeRequestsController#pipelines.
- Drop feature to take ownership of trigger token.


## 11.11.6

- Unreleased due to QA failure.
Expand Down

This file was deleted.

This file was deleted.

5 changes: 0 additions & 5 deletions changelogs/unreleased/security-bvl-filter-mr-params.yml

This file was deleted.

5 changes: 0 additions & 5 deletions changelogs/unreleased/security-dns-ssrf-bypass.yml

This file was deleted.

This file was deleted.

5 changes: 0 additions & 5 deletions changelogs/unreleased/security-github-ssrf-redirect.yml

This file was deleted.

5 changes: 0 additions & 5 deletions changelogs/unreleased/security-hide_moved_issue_id.yml

This file was deleted.

5 changes: 0 additions & 5 deletions changelogs/unreleased/security-mr-pipeline-permissions.yml

This file was deleted.

This file was deleted.

0 comments on commit f4ec125

Please sign in to comment.