
3/25/2019 · Kathy Wang
What this post added
This post details a security vulnerability in quick actions for issues that could expose project runner registration tokens to unauthorized users. It describes the response and mitigation, including applying a patch on GitLab.com and expediting a critical security fix for self-managed customers. It also outlines the action required for GitLab.com users with automation relying on runner registration tokens (resetting tokens) and reports the results of the investigation, stating no evidence of security compromise but a commitment to further investigation and security posture improvement.