Update CHANGELOG.md for 12.8.8

[ci skip]
上级 cf65cef7
......@@ -2,6 +2,29 @@
documentation](doc/development/changelog.md) for instructions on adding your own
entry.
## 12.8.8 (2020-03-26)
### Security (17 changes)
- Redact notes in moved confidential issues.
- Ignore empty remote_id params from Workhorse accelerated uploads.
- External user can not create personal snippet through API.
- Prevent malicious entry for group name.
- Restrict mirroring changes to admins only when mirroring is disabled.
- Reject all container registry requests from blocked users.
- Deny localhost requests on fogbugz importer.
- Change GitHub service integration token input to password.
- Add permission check for pipeline status of MR.
- Fix UploadRewriter Path Traversal vulnerability.
- Block hotlinking to repository archives.
- Restrict access to project pipeline metrics reports.
- vulnerability_feedback records should be restricted to a dev role and above.
- Exclude Carrierwave remote URL methods from import.
- Update Nokogiri to fix CVE-2020-7595.
- Prevent updating trigger by other maintainers.
- Fix XSS vulnerability in `admin/email` "Recipient Group" dropdown.
## 12.8.7 (2020-03-16)
### Fixed (1 change, 1 of them is from the community)
......
---
title: Redact notes in moved confidential issues
merge_request:
author:
type: security
---
title: Ignore empty remote_id params from Workhorse accelerated uploads
merge_request:
author:
type: security
---
title: External user can not create personal snippet through API
merge_request:
author:
type: security
---
title: Prevent malicious entry for group name
merge_request:
author:
type: security
---
title: Restrict mirroring changes to admins only when mirroring is disabled
merge_request:
author:
type: security
---
title: Reject all container registry requests from blocked users
merge_request:
author:
type: security
---
title: Deny localhost requests on fogbugz importer
merge_request:
author:
type: security
---
title: Change GitHub service integration token input to password
merge_request:
author:
type: security
---
title: Add permission check for pipeline status of MR
merge_request:
author:
type: security
---
title: Fix UploadRewriter Path Traversal vulnerability
merge_request:
author:
type: security
---
title: Block hotlinking to repository archives
merge_request:
author:
type: security
---
title: Restrict access to project pipeline metrics reports
merge_request:
author:
type: security
---
title: vulnerability_feedback records should be restricted to a dev role and above
merge_request:
author:
type: security
---
title: Exclude Carrierwave remote URL methods from import
merge_request:
author:
type: security
---
title: Update Nokogiri to fix CVE-2020-7595
merge_request:
author:
type: security
---
title: Prevent updating trigger by other maintainers
merge_request:
author:
type: security
---
title: Fix XSS vulnerability in `admin/email` "Recipient Group" dropdown
merge_request:
author:
type: security
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册