
We improve consistency across severity ratings and payouts in our bug bounty program with collaboration, iteration, and async communication.

We talk with bug bounty hunter Alex Chapman about his favorite type of vulnerability to research and the one piece of security advice he’d offer to the company he hacks.

Eight team members from our Security department talk about what they've learned working in Tech and what advice they’d offer to someone considering a career in security.

Some customers will need to take specific action to manually update their Dependency Scanning image to receive a bug fix.

How we responded to a masked variable vulnerability in GitLab Runner version 13.9.0-rc1 and actions users should take.

A review of the deprecations and removals in 14.0 for the Secure Composition Analysis group.

We held a public, ask me anything with our Red Team. Here’s what people asked.
All fields required