Earlier quoted context omitted.
> Why do you feel you would need to review the entire codebase to deploy Gitlab? I already answered this. Quoting my post above: > so I can deploy it with confidence Emphasis is important. Background: I do application security consulting. Do you expect me to trust the code that other developers write without verifying that it's not a pile of lacey Swiss first? Also, if I do find any bugs, I'll report them upstream (s…
We welcome all the paranoia we can get. Please be informed that multiple organizations have done security audits for GitLab and we have paid external parties to perform them for us. That doesn't mean there are no bugs anymore.
Not to speak badly about any of my peers in particular, but I've come in after other security auditing teams and found really obvious bugs that they've overlooked.
Though I usually give them the benefit of the doubt and omit my feelings when I write my report. Maybe it was a time constraint or a scoping issue that prevented them from seeing it? I have no way of knowing.
So, kudos for not having a single point of failure.