Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Security testing of Gitlab self-hosted deployments (github.com/kulkansecurity)
3 points by laserspeed 6 months ago | hide | past | favorite | 3 comments


A checklist to help pentesters and auditors assess Self-Hosted GitLab instances. Checks include misconfigurations and weaknesses that could lead to privilege escalation and code or secrets theft/abuse. It's a first version focused on Authentication, CI/CD Runners, CI/CD Variables and Project configurations.


Good start, covers the big GitLab pitfalls (auth, runners, vars, project config). The the fun part to be added: runner isolation/cleanup, built-in scans (SAST/dep/secret), logging/audit trails, push-rules (signed commits), and secret management practices. Solid so far tho.


Agreed! Those are indeed some nice pointers to add.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: