From 52eda8925d53044f20b4c17fa8f6703152b1990b Mon Sep 17 00:00:00 2001 From: GitLab Release Tools Bot Date: Thu, 28 Mar 2019 15:18:32 +0000 Subject: [PATCH] Update CHANGELOG.md for 11.7.10 [ci skip] --- CHANGELOG.md | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index a8e48dee42e..dc8123a5888 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -576,6 +576,19 @@ entry. - Creates mixin to reduce code duplication between CE and EE in graph component. +## 11.7.10 (2019-03-28) + +### Security (7 changes) + +- Disallow guest users from accessing Releases. +- Fix PDF.js vulnerability. +- Hide "related branches" when user does not have permission. +- Fix XSS in resolve conflicts form. +- Added rake task for removing EXIF data from existing uploads. +- Disallow updating namespace when updating a project. +- Use UntrustedRegexp for matching refs policy. + + ## 11.7.8 (2019-03-26) ### Security (7 changes) -- GitLab