Download GitLab 8.15.4 / 8.14.6 / 8.13.11

Spread the love

You can compare GitLab with the more famous GitHubbut contains some subtle differences. It is an environment for managing Git repositories on-premises and is released under the MIT Expat license and developed in Ruby on Rails. It is available in two versions, namely the free to use Community Edition and a paid Enterprise Edition with more features aimed at large companies. The two flavors are on this page explained. The development team has released GitLab 8.15.4, 8.14.6 and 8.13.11 with the following announcement:

GitLab 8.15.4, 8.14.6, and 8.13.11 Released

Today we are releasing versions 8.15.4, 8.14.6, and 8.13.11 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions contain important security fixes, and we recommend that all affected GitLab installations be upgraded to one of these versions. Additionally, the 8.15.4 version resolves a number of regressions and bugs in last month’s 8.15 release.

Security fixes in 8.15.4, 8.14.6 and 8.13.11

Cross-Site Scripting Vulnerability in Turbolinks
These releases include a patch for a cross-site scripting vulnerability in the Ruby gem Turbolinks. Versions 2.5.4 and earlier of Turbolinks are vulnerable to cross-site scripting attacks when loading attachments with HTML content types. We’ve released a temporary GitLab fork of Turbolinks while we make a decision on migrating to Turbolinks version 5 or abandoning Turbolinks.

Cross-Site Scripting Vulnerability in GitLab Markup
Also included with these releases is a patch for a cross-site scripting vulnerability in the GitLab Markup gem, forked from the GitHub Markup gem. This vulnerability can be exploited by tricking users into clicking on ReStructuredText files that specify a raw HTML format. Thanks to Jason Ritzke (@Rtzq0) for reporting this vulnerability.

Additional changes in 8.15.4

  • CE/EE: Use #parts instead of #part to read all the parts of the Message.
  • CE/EE: Re-add Google Cloud Storage as a backup strategy
  • CE/EE: Don’t instrument 405 Grape calls
  • CE/EE: Speed ​​up group milestone index by passing group_id to IssuesFinder
  • CE/EE: With Gitea v1.0.0, notes are imported
  • CE/EE: Make successful pipeline emails off for watchers
  • Omnibus GitLab: Switch to using gitlab-psql for query against db
  • Omnibus GitLab: Adding /bin/sh to command for analyze_new_cluster.sh call

Upgrade barometer

These versions have no migrations and should not require any downtime. Please be aware that by default the Omnibus packages will stop, run migrations, and start again, no matter how “big” or “small” the upgrade is. This behavior can be changed by adding a /etc/gitlab/skip-auto-migrations file.

Version number 8.15.4 / 8.14.6 / 8.13.11
Release status Final
Operating systems Linux
Website GitLab
Download
License type Conditions (GNU/BSD/etc.)
You might also like
Exit mobile version