Update docker.io/gitlab/gitlab-ce Docker tag to v19.4.1
No problems automatically updating the monolithic Docker image and run the container by Watchtower with dependency update facilitated by Mend's Renovate Bot.
This MR contains the following updates:
| Package | Update | Change |
|---|---|---|
| docker.io/gitlab/gitlab-ce (changelog) | patch | 19.4.0-ce.0 → 19.4.1-ce.0 |
Release Notes
gitlab-org/gitlab (docker.io/gitlab/gitlab-ce)
v19.4.1
Fixed (1 change)
- Resume mid-delta on the package metadata label path GitLab Enterprise Edition
Security (11 changes)
- Bound compiled size of CI rules regexp patterns (merge request)
- Fix authorization bypass in MemberRole.dependentSecurityPolicies (merge request)
- Hide private child items in Epic API (merge request)
- Authorize GraphQL CiJob.trace with read_build_trace (merge request)
- Restrict mcp scope auth to routes with an mcp route setting (merge request)
- Fix thread-safety race in MCP aggregated tool instances (merge request)
- Resolve Duo Workflow tool governance from the executed workflow and bind the token to it (#605431) (merge request)
- Prevent user resolution downgrade in bulk and third-party importers (merge request)
- Enforce read_build_trace on Duo job trace paths (merge request)
- Reject traversal segments in diff file URLs (merge request)
- Guard regexp compilation in CI rules clauses (merge request)