Gitlab CI v13.1.2 Release Notes

Release Date: 2020-07-01 // almost 4 years ago
  • ๐Ÿ”’ Security (18 changes)

    • โšก๏ธ Update xterm js dependency to latest stable 3.x version.
    • Do not show activity for users with private profiles.
    • ๐Ÿ›  Fix stored XSS in markdown renderer.
    • โฌ†๏ธ Upgrade swagger-ui to solve XSS issues.
    • ๐Ÿ›  Fix group deploy token API authorizations.
    • ๐Ÿ”€ Check access when sending TODOs related to merge requests.
    • ๐Ÿ”„ Change from hybrid to JSON cookies serializer.
    • Prevent XSS in group name validations.
    • Disable caching for wiki attachments.
    • Disable Github Importer API by settings.
    • ๐Ÿ›  Fix null byte error in upload path.
    • โšก๏ธ Update permissions for time tracking endpoints.
    • โž• Add snippet repository validation after bundle import.
    • โšก๏ธ Update Kaminari gem.
    • ๐Ÿ›  Fix note author name rendering.
    • Sanitize bitbucket repo urls to mitigate XSS.
    • Stored XSS on the Error Tracking page.
    • ๐Ÿ›  Fix security issue when rendering issuable.