> Yes, they are adding features nobody asked for like crazy, just to be able to check more boxes in some feature matrix.
This.
If people want "DevOpsSec" then make it a feature or addon tier. I'm certainly in favor of more security and testing, but the few times I've reviewed this feature it doesn't work for our use case. We use external CI/CD services because Gitlab CI (and runners to some degree) don't do what we want. But now, we're forced to pay for this feature as if it helps us. Perhaps Gitlab can't imagine a company that doesn't build cloud connected software.
I moved our organization of hundreds of users from Bitbucket years ago after a week long internal API rate limit in Bitbucket's infrastructure crushed our CI/CD system and took them way too long to acknowledge and fix (of course it wasn't documented). I fear this is the build-up to a similar move again, and I dread it. At the time Gitlab was on a much more impressive trajectory then Github and hence motivated my decision, but this has changed and it's largely self inflicted wound for Gitlab.
Part that pains me the most is I championed the move to Gitlab and encouraged all the teams to double down on it over the years.