Comment on Gitlab – Static passwords set during OmniAuth-based registration (CVE-2022-1162)parentComments−mdaniel4yto require a security engineer to give additional signoff on top of a normal reviewLike this?cc @gitlab-com/gl-security/appsechttps://gitlab.com/gitlab-org/gitlab/-/merge_requests/76318#...I do so desperately hope it doesn't come across as throwing shade, because hindsight-2020-etc, but I do also think there was some kind of weird process breakdown here because this change somehow slipped past a "4 eyes" and an appsec review phase
Comments
Like this?
https://gitlab.com/gitlab-org/gitlab/-/merge_requests/76318#...
I do so desperately hope it doesn't come across as throwing shade, because hindsight-2020-etc, but I do also think there was some kind of weird process breakdown here because this change somehow slipped past a "4 eyes" and an appsec review phase