Bugpocalypse, or reporting bugs in an AI age

“…perfect software doesn’t exist. No one in the brief history of computing has ever written a piece of perfect software.”

  • Andrew Hunt, The Pragmatic Programmer, Chapter 4

In June this year we updated our security process to make the reporting of security bugs broadly the same procedure as reporting other bugs. The only difference is asking reporters to set GitLab’s confidential flag to limit its visibility to project members. The previous email address routed through a volunteer had become unsustainable as the rate of reports rose. While more people can see the reports now, there is at least a chance to distribute the triage work across more of the projects volunteers.