Skip to content

Comment on Gitlab – Static passwords set during OmniAuth-based registration (CVE-2022-1162)parent

Comments

to require a security engineer to give additional signoff on top of a normal review

Like this?

cc @gitlab-com/gl-security/appsec

https://gitlab.com/gitlab-org/gitlab/-/merge_requests/76318#...

I do so desperately hope it doesn't come across as throwing shade, because hindsight-2020-etc, but I do also think there was some kind of weird process breakdown here because this change somehow slipped past a "4 eyes" and an appsec review phase

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.