Gitlab CI v15.2.4 Release Notes
Release Date: 2022-08-30 // 9 months ago-
๐ Security (18 changes)
- ๐ [No overriding methods for Sawyer class](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2755))
- โก๏ธ [Update Oj to v3.13.21](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2729))
- ๐ [Bump yajl-ruby gem version](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2689))
- ๐ [Prevent long loops when generating suggested branch name](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2744))
- ๐ [IDOR in Zentao integration issue show page](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2741))
- ๐ [Patch VULNDB-255039 (potential Rack cache poisoning)](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2694))
- ๐ [HTML escape the label background color](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2720))
- ๐ [Sandbox jupyter notebook HTML output](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2711))
- ๐ [Fix unauthorized GFM references in Incident Timeline](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2708))
- โก๏ธ [Optimize handling repositories with huge trees](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2666))
- ๐ [Parse commit trailers without using regexp](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2700))
- ๐ [Check for pathological markdown input](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2732))
- ๐ [Replaced smooshpack to fix the vulnerability in LivePreview](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2662))
- โก๏ธ [Update package auth for group IP allowlist](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2684))
- ๐ [Don't show pipeline status](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2680))
- ๐ [Sanitize img attributes in Banzai::Filter::ImageLinkFilter](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2676))
- ๐ [Validate description length for snippets](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2703))
- ๐ [Prevent brute force vuln for Git over HTTP(S) requests](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2717))