Security & supply chainGitLab's per-user email token can push code and trigger pipelines
Researcher Joe Leon of Aikido Security disclosed that GitLab's incoming-email addresses embed a long-lived, cross-project token that lets anyone holding the address submit patches, run CI/CD and reach the account's secrets.