Gitlab CI v15.3.4 Release Notes
Release Date: 2022-09-29 // 4 months ago-
๐ Security (15 changes)
- ๐ [Redact user's private email in group member event webhook](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2794))
- ๐ [Redact secrets from WebHookLogs](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2737))
- ๐ [Forbid creating a tag using default branch name](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2799))
- ๐ [Sanitize Url and check for valid numerical errorId in error tracking](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2785))
- ๐ [Add security protection for Github](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2802))
- ๐ [Fix leaking emails in WebHookLogs](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2807))
- ๐ [Restrict max duration to 1 year for trace display](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2815))
- ๐ [Use UntrustedRegexp for upload rewriter](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2791))
- ๐ [Validate httpUrlToRepo to be http or https only](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2760))
- ๐ [Respect instance level rule for editing approval rules](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2782))
- ๐ [Prevent users creating issues in ay project via board/issues controller](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2780))
- ๐ [Prevent serialization of sensible attributes from JsonCache](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2771))
- โก๏ธ [Update TodoPolicy to handle confidential notes](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2748))
- ๐ [Enforce group IP restriction on Dependency Proxy](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2764))
- ๐ [Fixes XSS in widget extensions](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2759))