Company
Date Published
Author
Harjot Gill
Word count
798
Language
English
Hacker News points
None

Summary

In response to a security vulnerability disclosed by Kudelski Security in January 2025, Coderabbit's CEO Harjot Gill outlined the company's swift action and ongoing dedication to security. The vulnerability involved the Rubocop tool operating outside the intended secure sandbox environment, which was promptly addressed within hours through an incident response protocol. The company ensured no customer data was accessed and implemented several measures to prevent future occurrences, such as automated sandbox enforcement and enhanced deployment gates. Coderabbit values collaboration through its Vulnerability Disclosure Program (VDP), which encourages engagement with security researchers and offers competitive rewards for responsible disclosure. Despite the deviation from standard protocols, the company reaffirmed its commitment to maintaining stringent security standards and compliance, while expressing gratitude for the professional cooperation with Kudelski Security.