Skip to content

Commit

Permalink
Update CHANGELOG.md for 12.9.8
Browse files Browse the repository at this point in the history
[ci skip]
  • Loading branch information
GitLab Release Tools Bot committed May 27, 2020
1 parent b4f4e4e commit a06a67f
Show file tree
Hide file tree
Showing 14 changed files with 19 additions and 65 deletions.
19 changes: 19 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,25 @@
documentation](doc/development/changelog.md) for instructions on adding your own
entry.

## 12.9.8 (2020-05-27)

### Security (13 changes)

- Hide EKS secret key in admin integrations settings.
- Added data integrity check before updating a deploy key.
- Display only verified emails on notifications and profile page.
- Disable caching on repo/blobs/[sha]/raw endpoint.
- Require confirmed email address for GitLab OAuth authentication.
- Kubernetes cluster details page no longer exposes Service Token.
- Fix confirming unverified emails with soft email confirmation flow enabled.
- Disallow user to control PUT request using mermaid markdown in issue description.
- Check forked project permissions before allowing fork.
- Limit memory footprint of a command that generates ZIP artifacts metadata.
- Fix file enuming using Group Import.
- Prevent XSS in the monitoring dashboard.
- Use `gsub` instead of the Ruby `%` operator to perform variable substitution in Prometheus proxy API.


## 12.9.7 (2020-05-13)

### Added (1 change)
Expand Down

This file was deleted.

This file was deleted.

This file was deleted.

This file was deleted.

This file was deleted.

This file was deleted.

5 changes: 0 additions & 5 deletions changelogs/unreleased/security-fix-email-confirmation-bug.yml

This file was deleted.

5 changes: 0 additions & 5 deletions changelogs/unreleased/security-fix-mermaid-issue.yml

This file was deleted.

5 changes: 0 additions & 5 deletions changelogs/unreleased/security-forked-from.yml

This file was deleted.

This file was deleted.

5 changes: 0 additions & 5 deletions changelogs/unreleased/security-group-import-file-enuming.yml

This file was deleted.

This file was deleted.

This file was deleted.

0 comments on commit a06a67f

Please sign in to comment.