"No manual overrides, no exceptions."
"Our VDP isn't just a bug bounty—it's a security partnership"
Another:
> Security isn't just a checkbox for us; it's fundamental to our mission.
> The researchers identified that Rubocop, one of our tools, was running outside our secure sandbox environment — a configuration that deviated from our standard security protocols.
This is still ultra-LLM-speak (and no, not just because of the em-dash).
The usual "we take full responsibility" platitudes.
Then on the flip side, I’m not just worried about an intern using an LLM. I’m worried about the unmonitored LLM performing intern, junior, and ops tasks, and then companies simply using “an LLM did it” as a scapegoat for their extreme cost cutting.
- within 8 months: published the details after researchers publish it first.
However their response doesn't remediate putting secrets into environment variables in the first place - that is apparently acceptable to them and sets off a red flag for me.
Isn't that standard? The other options I've seen are .env files (amazing dev experience but not as secure), and AWS Secrets Manager and similar competition like Infisical. Even in the latter, you need keys to authenticate with the secrets manager and I believe it's recommended to store those as env vars.
Edit: Formatting
Everything else was fine, just this one tool chosen by the security researcher out of a dozen of tools was not sandboxed.
https://web.archive.org/web/diff/20250819165333/202508192240...