Security

'Exclusive swag' up for grabs as GitLab flings bug bounty scheme open to world+dog

Don't worry, there are cheques, too


DevOps outfit GitLab has opened its bug bounty scheme to world+dog, having paid out $200,000 last year and fixed "nearly 200 vulnerabilities reported to us".

"In managing a public bug bounty program, we will now be able to reward our hacker community for reporting security vulnerabilities to us directly through the program," said security director Kathy Wang in a blog post.

Get rich with Firefox or *(int *)NULL = 0 trying: Automated bug-bounty hunter build touted

READ MORE

Through its HackerOne page, GitLab promised to pay out up to $12,000 for critical bugs responsibly disclosed to it. It also pledged to respond to submitted reports "within 5 business days" or fewer.

Back in 2014, GitLab first ran a public vuln disclosure programme, according to an online Q&A with Wang. While that did not offer bug bounties, the code repo site did start coughing up in December 2017 to selected partners.

As for why GitLab is taking the bug bounty program public, Wang said it was all down to "open source contribution values".

"We currently make the details of security vulnerabilities public 30 days after the mitigations have been released," she said, which compares rather well with some firms who take months to mention anything publicly – if at all.

GitLab will also be killing off support for TLS1.0 and 1.1 in a couple of weeks' time, and bounty-hunting hackers can look forward to receiving "exclusive HackerOne-only GitLab swag" as well as reasonably-sized cheques in return for disclosing vulns.

GitLab was last in the news for accidentally splitting its brains in half, as well as shifting its main site onto Google Cloud after Microsoft bought out rival site Github. ®

Send us news
7 Comments

Patch time: Critical GitLab vulnerability exposes 2FA-less users to account takeovers

The bug with a perfect 10 severity score has been ripe for exploitation since May

GitLab admits IT ineptitude in finance reporting is ongoing

Code shack has had two years since auditor's 'adverse opinion' to get house in order

GitLab deploys on a Friday and ... is down for a few hours

Snafu blamed on config change

AI coding is 'inescapable' and here to stay, says GitLab

Getting strong FOMO vibes from devs – tho how ML is actually used among engineers may surprise you

One third wiped off value of GitLab shares, Wall Street didn't like weaker outlook

Investors nervous in same week that Silicon Valley Bank failed

Tech job bonfire rages on as Microsoft, GitLab and others join in

Hundreds of thousands of techies looking for work, with ultimate cost to vendors not yet tallied

GitLab versus The Zombie Repos: An old plot needs a new twist

Git back, git back, git back to where your files belong

GitLab plans to delete dormant projects in free accounts

Hopes to save a quarter of hosting costs by binning repos that haven't been touched for a year

GitLab U-turns on deleting dormant projects after backlash

Now makes vague pledge to shove inactive repos into slow object storage

GitLab spots huge opportunity for DevOps platform as revenue soars

All companies will need to embrace modern software development, says CEO, and we'll be waiting for them

GitLab version 15 goes big on visibility and observability

GitOps fans can take a spin on the free tier for pull-based deployment