
2/17/2022 · Nick Malcolm
What this post added
This post details GitLab's process for handling security bugs, emphasizing transparency and public disclosure. It explains the role of CVEs, the Common Vulnerability Scoring System (CVSS), and GitLab's internal CVSS calculator. The post highlights GitLab's commitment to transparency by assigning a CVE to every vulnerability, disclosing issues publicly via security release blog posts and HackerOne Hacktivity, and aiming to publicly disclose GitLab issues 30 days after a patch is released. It also discusses supply chain risks and encourages customers to inquire about their vendors' security disclosure processes. The post also mentions the combination of patch and security releases into unified patch releases delivered twice a month.