1. 23 1月, 2019 1 次提交
    • K
      Extract GitLab Pages using RubyZip · 1a8100cf
      Kamil Trzciński 提交于
      RubyZip allows us to perform strong validation of
      expanded paths where we do extract file.
      
      We introduce the following additional checks
      to extract routines:
      
      1. None of path components can be symlinked,
      2. We drop privileges support for directories,
      3. Symlink source needs to point within the target directory,
         like `public/`,
      4. The symlink source needs to exist ahead of time.
      1a8100cf
  2. 22 1月, 2019 14 次提交
  3. 21 1月, 2019 13 次提交
  4. 20 1月, 2019 2 次提交
  5. 19 1月, 2019 10 次提交