What a lie. What a self-serving baldfaced lie. I have a record of my report to GitLab on August 12, 2021 regarding the same SSPR vulnerabilities. Hey Obsidian: email account takeovers work just like a SIM swap. I can name at least two more sites that are vulnerable. I've disclosed to the site owners, so I'm just politely waiting out the 90 days or so before going public.
Prior discussion right here from yours truly: https://news.ycombinator.com/item?id=36726414