considering Gitlab has integrated CI, I'd say this is more than "tangentially" related. Developers are going to wonder if their CI tool is protected from this kind of issue.
> To be clear, letting third party JS run in a trusted environment like a dashboard is an industry wide problem. If we assume CircleCI is the only bad actor we're kind of missing the point of the exercise.