From 071e9d7812dab73881c24742d84093f5cddff705 Mon Sep 17 00:00:00 2001 From: GitLab Release Tools Bot <delivery-team+release-tools@gitlab.com> Date: Wed, 24 Jan 2024 16:54:59 +0000 Subject: [PATCH] Update changelog for 16.6.6 [ci skip] --- CHANGELOG.md | 14 ++++++++++++++ 1 file changed, 14 insertions(+) diff --git a/CHANGELOG.md b/CHANGELOG.md index ec7cdf9a8315e..8828aa44c00ff 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -1444,6 +1444,20 @@ entry. - [Move export buttons next to each other](gitlab-org/gitlab@106bea7a6246cd153cf66d133936a09d46369ae3) ([merge request](gitlab-org/gitlab!137461)) +## 16.6.6 (2024-01-24) + +### Fixed (1 change) + +- [Bring legacy verification behavior back for repositories](gitlab-org/security/gitlab@36bcdbdd83f726f9e4b89352d5c2c5d3d6a0aed8) **GitLab Enterprise Edition** + +### Security (5 changes) + +- [Devfile parser arbitrary file write](gitlab-org/security/gitlab@d99a6dd3b4db37b4de1e3064059d769233c71ebd) ([merge request](gitlab-org/security/gitlab!3801)) +- [Use public email in tags atom feed](gitlab-org/security/gitlab@0c6e04dd2ad28ea1630e11903b74d74c177fc128) ([merge request](gitlab-org/security/gitlab!3804)) +- [Fix improper username sanitization](gitlab-org/security/gitlab@13d91b4e6248be0f326d0e476e2291360be7a1eb) ([merge request](gitlab-org/security/gitlab!3786)) +- [Escape user input before building regex for linker](gitlab-org/security/gitlab@fa1f908f65d7e2de0f5a5d99d4641e13bad92b10) ([merge request](gitlab-org/security/gitlab!3789)) +- [Do not allow non-team member to set MR assignees/reviewers](gitlab-org/security/gitlab@632f6852c312f29984fb1eebb5fc7e9d1a6de1ae) ([merge request](gitlab-org/security/gitlab!3793)) + ## 16.6.5 (2024-01-13) No changes. -- GitLab