Bug Triage and Reporting
What we learned by taking our bug bounty program public

What we learned by taking our bug bounty program public

7/19/2019 · Ethan Strike

What this post added

This post details the evolution of GitLab's bug bounty program after making it public. It highlights the increase in valid vulnerability reports, particularly from new reporters, and the challenges and improvements in the triage and response process. Key technical contributions include the use of an automated bot for initial responses and ETA estimations, a Slack command to import triaged reports into confidential GitLab issues, and the integration of the GitLab API to provide reporters with expected fix dates based on assigned milestones. The post also discusses how bug bounty findings have informed improvements to the platform's permissions model and the advocacy for code reuse through security-focused libraries.

Read the original post ↗