1
0
Fork 1
mirror of https://github.com/NixOS/nixpkgs.git synced 2024-12-11 15:15:36 +00:00
nixpkgs/pkgs/applications/version-management
Florian Klink 5bf07d665f gitlab: 12.5.3 -> 12.5.4
https://about.gitlab.com/blog/2019/12/10/critical-security-release-gitlab-12-5-4-released/

Insufficient parameter sanitization for Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions. The issue is now mitigated in the latest release and is assigned CVE-2019-19628.

When transferring a public project to a private group, private code would be disclosed via the Group Search API provided by Elasticsearch integration. The issue is now mitigated in the latest release and is assigned CVE-2019-19629.

The Git dependency has been upgraded to 2.22.2 in order to apply security fixes detailed here.

CVE-2019-19604 was identified by the GitLab Security Research team. For more information on that issue, please visit the GitLab Security Research Advisory

closes #75506.
2019-12-11 15:16:36 +01:00
..
arch
bazaar
bcompare
bitkeeper
blackbox
cvs
cvs-fast-export
cvs2svn
cvsps
dvc
fossil
gerrit
git-and-tools git: 2.24.0 -> 2.24.1 2019-12-11 00:01:06 +00:00
git-backup
git-crecord
git-lfs
git-repo
git-review
git-sizer
git-up
gitea gitea: 1.10.0 -> 1.10.1 2019-12-05 22:39:19 +01:00
gitinspector
gitkraken
gitlab gitlab: 12.5.3 -> 12.5.4 2019-12-11 15:16:36 +01:00
gitless
gitolite gitolite: wrap gitolite-shell 2019-12-08 12:26:02 +01:00
gitstats
gogs
gource
guitone
meld
mercurial
monotone
monotone-viz
mr
nbstripout
nitpick
p4v
peru
pijul
rabbitvcs
rapidsvn
rcs
redmine
reposurgeon
sit
smartgithg
sourcehut sourcehut.listssrht: add pygit2 2019-11-30 09:31:58 -08:00
src
srcml
sublime-merge
subversion
tailor
tkcvs
tortoisehg
vcprompt
vcsh
yadm Merge pull request #74695 from r-ryantm/auto-update/yadm 2019-12-02 07:55:15 -08:00