Bug Triage and Reporting
How GitLab handles security bugs (and why it matters)

How GitLab handles security bugs (and why it matters)

2/17/2022 · Nick Malcolm

What this post added

This post details GitLab's process for handling security bugs, emphasizing transparency and public disclosure. It explains the role of CVEs, the Common Vulnerability Scoring System (CVSS), and GitLab's internal CVSS calculator. The post highlights GitLab's commitment to transparency by assigning a CVE to every vulnerability, disclosing issues publicly via security release blog posts and HackerOne Hacktivity, and aiming to publicly disclose GitLab issues 30 days after a patch is released. It also discusses supply chain risks and encourages customers to inquire about their vendors' security disclosure processes. The post also mentions the combination of patch and security releases into unified patch releases delivered twice a month.

Read the original post ↗