Home / Companies / GitLab / Blog / Post Details
Content Deep Dive

What we learned by taking our bug bounty program public

Blog post from GitLab

Post Details
Company
Date Published
Author
Ethan Strike
Word Count
1,180
Company Posts That Month
29
Language
English
Hacker News Points
-
Post removed?
No
Summary

GitLab's public bug bounty program, launched in December 2018, has significantly contributed to enhancing their security by engaging a broader community of reporters, with 42% of initial participants being first-time contributors. The program has doubled the number of valid reports since its public introduction, identifying 205 valid vulnerabilities by July 3rd, including 10 critical ones, although it has also seen an increase in false positives. GitLab has refined its triage and response processes, implementing automation to improve communication and response times, while also adjusting how fixes are scheduled and reported. Transparency is a core value, and GitLab publicly discloses its findings, using them to inform developer training and enhance security practices. The program has helped identify recurring vulnerability patterns, prompting GitLab to focus on secure coding training and the use of security-focused libraries to prevent future issues.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.