Gitlab CI v15.4.1 Release Notes
Release Date: 2022-09-29 // 4 months ago-
๐ Security (15 changes)
- ๐ [Redact user's private email in group member event webhook](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2809))
- ๐ [Redact secrets from WebHookLogs](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2805))
- ๐ [Forbid creating a tag using default branch name](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2798))
- ๐ [Sanitize Url and check for valid numerical errorId in error tracking](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2819))
- ๐ [Add security protection for Github](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2803))
- ๐ [Fix leaking emails in WebHookLogs](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2806))
- ๐ [Restrict max duration to 1 year for trace display](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2817))
- ๐ [Use UntrustedRegexp for upload rewriter](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2790))
- ๐ [Validate httpUrlToRepo to be http or https only](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2811))
- ๐ [Respect instance level rule for editing approval rules](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2796))
- ๐ [Prevent users creating issues in ay project via board/issues controller](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2781))
- ๐ [Prevent serialization of sensible attributes from JsonCache](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2818))
- โก๏ธ [Update TodoPolicy to handle confidential notes](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2833))
- ๐ [Enforce group IP restriction on Dependency Proxy](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2801))
- ๐ [Fixes XSS in widget extensions](gitlab-org/security/[email protected]) ([merge request](gitlab-org/security/gitlab!2832))