Create:Source Code Hardening & Modernization Team
A temporary team that addresses systemic security and frontend problems in Source Code, hands the results over to the feature teams, and disbands.
Why
Source Code is one of the oldest parts of GitLab’s codebase, and most of its engineering capacity goes to maintenance. Two problems are systemic rather than tied to any single feature: security vulnerabilities with recurring root causes, and a fragmented, partially migrated frontend. This team exists to fix them, hand the results over, and disband.
Scope
- Security root causes. Find the recurring root causes behind Source Code vulnerabilities and fix each as a class, with a shared layer or check used by every affected surface.
- Frontend modernization. Finish the Vue 3 migration on Source Code pages, add an integration test harness, clear the flaky-spec quarantine, and unify the many small Vue roots on the busiest pages into coherent applications.
- Feature categories. Split Source Code’s single feature category so each Source Code team has its own error budget.
What this team does not own
- The Source Code security backlog. Security issues stay with the team that owns the feature; we take on classes of issues we can fix systemically.
- Feature maintenance. Every Source Code feature has an owner among the other Source Code teams. We work in their code, with their review.
- Microfrontends. We unify Vue roots into fewer, well-structured apps; microfrontends are a separate team’s direction.
This team is temporary
The team runs 2026-09-21 → 2027-09-10 (end of milestone 20.4), with a go/no-go review after 6 months (19.10). It maintains no surface area of its own, so once the systemic problems are fixed and handed over there is nothing left for it to own.
| Name | Role | Returns to |
|---|---|---|
| Vladimir Shushlin | Engineering Manager | Plan |
| Kerri Miller | Staff Backend Engineer | TBD |
| Emma Park | Backend Engineer | TBD |
| Chaoyue Zhao | Frontend Engineer | TBD |
| Anastasia Khomchenko | Senior Frontend Engineer | Plan:Portfolio Planning |
How we measure success
| Measure | Target |
|---|---|
| Source Code security intake (new issues per quarter) — primary | Flat or falling for two consecutive quarters |
| Source Code security backlog — secondary | No past-due issues; the classes we took on closed |
| Frontend modernization | Metrics to be defined with the team |
| Feature categories | Each Source Code team has its own error budget |
Links
- Tracking issue (confidential)
- Create:Source Code teams
- Slack:
#g_create_source-code-hardening-and-modernization
Last modified September 22, 2026: Add Source Code Hardening & Modernization team page (
e7d9386d)
