cross-posted from: https://lemm.ee/post/44155947
14 points
Gitlab is a security nightmare. They have zero conception how to write secure code and they don’t care to learn.
I was looking for a link to the previous CVEs I was aware of and there is yet another one that is new to me: https://thehackernews.com/2024/09/urgent-gitlab-patches-critical-flaw.html
This is not a serious service to be hosting source code on.