diff --git a/CHANGELOG.md b/CHANGELOG.md index 6055223dfd..395ff400fa 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,10 +2,39 @@ documentation](doc/development/changelog.md) for instructions on adding your own entry. -## 13.2.3 (2020-08-05) +## 13.2.5 (2020-08-17) - No changes. +## 13.2.4 (2020-08-11) + +### Security (1 change) + +- Add decompressed archive size validation on Project/Group Import. !38736 + +### Fixed (1 change) + +- Fix automatic issue creation via Prometheus alerts. !37884 + + +## 13.2.3 (2020-08-05) + +### Security (12 changes) + +- Update kramdown gem to version 2.3.0. +- Enforce 2FA on Doorkeeper controllers. +- Revoke OAuth grants when a user revokes an application. +- Refresh project authorizations when transferring groups. +- Stop excess logs from failure to send invite email when group no longer exists. +- Verify confirmed email for OAuth Authorize POST endpoint. +- Fix XSS in Markdown reference tooltips. +- Fix XSS in milestone tooltips. +- Fix xss vulnerability on jobs view. +- Block 40-character hexadecimal branches. +- Prevent a temporary access escalation before group memberships are recalculated when specialized project share workers are enabled. +- Update GitLab Runner Helm Chart to 0.18.2. + + ## 13.2.2 (2020-07-29) ### Fixed (3 changes) diff --git a/GITALY_SERVER_VERSION b/GITALY_SERVER_VERSION index d8308f987e..8c339431c5 100644 --- a/GITALY_SERVER_VERSION +++ b/GITALY_SERVER_VERSION @@ -1 +1 @@ -13.2.3 +13.2.5 diff --git a/Gemfile b/Gemfile index e082094715..83e66ef838 100644 --- a/Gemfile +++ b/Gemfile @@ -142,7 +142,7 @@ gem 'deckar01-task_list', '2.3.1' gem 'gitlab-markup', '~> 1.7.1' gem 'github-markup', '~> 1.7.0', require: 'github/markup' gem 'commonmarker', '~> 0.20' -gem 'kramdown', '~> 2.2.1' +gem 'kramdown', '~> 2.3.0' gem 'RedCloth', '~> 4.3.2' gem 'rdoc', '~> 6.1.2' gem 'org-ruby', '~> 0.9.12' diff --git a/Gemfile.lock b/Gemfile.lock index fbe5cfff1f..f211012331 100644 --- a/Gemfile.lock +++ b/Gemfile.lock @@ -589,7 +589,7 @@ GEM kgio (2.11.3) knapsack (1.17.0) rake - kramdown (2.2.1) + kramdown (2.3.0) rexml kramdown-parser-gfm (1.1.0) kramdown (~> 2.0) @@ -1297,7 +1297,7 @@ DEPENDENCIES jwt (~> 2.1.0) kaminari (~> 1.0) knapsack (~> 1.17) - kramdown (~> 2.2.1) + kramdown (~> 2.3.0) kubeclient (~> 4.6.0) letter_opener_web (~> 1.3.4) license_finder (~> 5.4) diff --git a/VERSION b/VERSION index d8308f987e..8c339431c5 100644 --- a/VERSION +++ b/VERSION @@ -1 +1 @@ -13.2.3 +13.2.5 diff --git a/app/assets/javascripts/jobs/components/environments_block.vue b/app/assets/javascripts/jobs/components/environments_block.vue index c78738221f..9166c13a4f 100644 --- a/app/assets/javascripts/jobs/components/environments_block.vue +++ b/app/assets/javascripts/jobs/components/environments_block.vue @@ -1,11 +1,15 @@