The following process is a supplement to the first few steps of the critical release process
Once a …
This runbook is meant to help AppSec engineers who need to engage and work with SIRT to respond to a …
When evaluating security issues or MRs, it can be useful to have a way to reproduce issues, dig in …
A curated list of the most frequently asked AppSec related questions
This runbook describes the process for times when the Application Security team has team members …
This review template is tailored to application security reviews of GitLab features. Parts of it might be applicable to other software, other parts might not.
This threat modeling process is tailored to GitLab features.
How can AppSec Engineers Contribute to the Secure Code Warrior Training Program? If anyone from the …
Bug Hunting Day Process The Application Security Team has a bug hunting day on the last Friday of …
Please refer to the GitLab CVSS Calculator as the single-source-of-truth to determine CVSS scores on …
This content has been moved to Supply Chain Security for Open Source Dependencies and Libraries.
Certain customers scan containers that GitLab provides for known vulnerabilities and other security …
release-management GitLab Security Patch Release Process This document outlines the process and …
Purpose and Overview of GitLab’s Bug Bounty Program High-level description of the process …
The runbook for handling different scenarios of unintended vulnerability disclosures.
release-management How to handle upstream security patches Third parties Sometimes the root cause …
List of Package Hunter Findings Any Package Hunter related finding can be found on this dashboard …
The Merge Monitor tool looks in public GitLab repositories that JiHu contributes to for merge …
Frequency: Daily
AppSec engineers are responsible for triaging the findings of the GitLab security …
Application Security team members are alphabetically assigned as the responsible individual (DRI) …
The review of a fix by an application security engineer is triggered by the engineer implementing …