nixpkgs/pkgs
Florian Klink 5bf07d665f gitlab: 12.5.3 -> 12.5.4
https://about.gitlab.com/blog/2019/12/10/critical-security-release-gitlab-12-5-4-released/

Insufficient parameter sanitization for Maven package registry could lead to privilege escalation and remote code execution vulnerabilities under certain conditions. The issue is now mitigated in the latest release and is assigned CVE-2019-19628.

When transferring a public project to a private group, private code would be disclosed via the Group Search API provided by Elasticsearch integration. The issue is now mitigated in the latest release and is assigned CVE-2019-19629.

The Git dependency has been upgraded to 2.22.2 in order to apply security fixes detailed here.

CVE-2019-19604 was identified by the GitLab Security Research team. For more information on that issue, please visit the GitLab Security Research Advisory

closes #75506.
2019-12-11 15:16:36 +01:00
..
applications gitlab: 12.5.3 -> 12.5.4 2019-12-11 15:16:36 +01:00
build-support Merge pull request #73266 from demin-dmitriy/fix-libredirect-open-bug 2019-12-10 00:46:21 +01:00
common-updater common-updater-scripts: Fix breakage 2019-11-26 14:18:33 +01:00
data Merge pull request #74966 from Fuzen-py/sweet 2019-12-10 23:32:46 -05:00
desktops Merge pull request #75226 from r-ryantm/auto-update/gnome-desktop 2019-12-10 20:42:18 +01:00
development ocamlPackages.merlin: 3.3.2 → 3.3.3 2019-12-11 09:58:21 +01:00
games hexen: remove abandoned software 2019-12-11 01:03:44 +01:00
misc vimPlugins.LanguageClient-neovim: 0.1.154 -> 0.1.155 2019-12-10 12:57:15 +01:00
os-specific linux_testing: 5.4-rc7 -> 5.5-rc1 2019-12-09 10:05:01 -06:00
servers samba: 4.10.10 -> 4.10.11 (#75456) 2019-12-11 11:12:49 +01:00
shells Merge pull request #75434 from kampka/zsh-history 2019-12-10 23:59:38 -05:00
stdenv setup.sh: rewrite stripHash 2019-11-12 14:38:41 +01:00
test
tools Merge pull request #75335 from veprbl/pr/texlive-bin-dvisvgm_fix 2019-12-11 00:21:41 -05:00
top-level mbedtls_1_3: clarify deprecation message 2019-12-11 10:55:40 +01:00