
3/4/2021 · Heather Simpson
What this post added
This post features an interview with a bug bounty hunter who discusses their motivations, why they focus on GitLab's Bug Bounty Program (BBP), and their preferred bug hunting methodology (white/grey box with source code access). They highlight the value of open source and open issue response for identifying critical security issues. The hunter also provides advice on having a clear policy for reporting security vulnerabilities and expresses a desire for improved markdown editing capabilities within GitLab for issue tracking and wikis. They also touch upon supply chain attacks as an area deserving more research.