Bug Triage and Reporting
How we work to detect and mitigate Spam on GitLab.com and beyond

How we work to detect and mitigate Spam on GitLab.com and beyond

10/29/2020 · Charl de Wit

What this post added

This post details the Trust and Safety team's work on detecting and mitigating spam on GitLab.com, defining abuse, and providing reporting mechanisms. For self-managed instances, it outlines best practices including enabling 2FA, implementing sign-up and sign-in restrictions (disabling new sign-ups, requiring admin approval, email confirmation, domain allow/denylist), hardening the instance, understanding abuse reporting and management for admins, and imposing rate limits on issue creation and user/IP access. It also mentions upcoming explorations in alternative captcha options and preventing bots from posting URLs, with the potential to integrate successful automation into the product.

Read the original post ↗