Gitlab CI v14.10.5 Release Notes
Release Date: 2022-06-30 // 11 months ago-
๐ Security (17 changes)
- ๐ [Fix group IP restrictions not enforced for container registry requests](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2552))
- โก๏ธ [Update rack gem to version 2.2.3.1](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2554))
- ๐ [Gitlab Runner version upgrade](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2567))
- โก๏ธ [Update ProjectAttributesTransformer to use fixed number of attributes](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2549))
- ๐ [Escape deploy key title to prevent XSS](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2494))
- ๐ [Sanitize ZenTao breadcrumb links](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2557))
- ๐ [Fix permissions in the project labels API](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2534))
- ๐ [Security fix sentry issue leaks and access level check](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2501))
- ๐ [Check permissions before exposing user two factor enabled](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2525))
- ๐ [Filter milestone release by user access](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2537))
- ๐ [Fix the required access level in the Conan packages finder](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2485))
- ๐ [Allow inviting only groups with subset of allowed domains to groups](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2512))
- ๐ [Fix open redirect vulnerability](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2540))
- ๐ [Adds a filter based on user access to Runner jobs endpoint](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2497))
- ๐ [Prevent runners from picking IP restricted jobs](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2503))
- ๐ [Restrict CI lint access to pipeline creators](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2515))
- ๐ [Catch endless headers when reading HTTP responses](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2529))