Because bias and incentives matter.
There's a reason disclosures are obligatory in academic papers.
They pulled a little sneaky on ya, mentioning GitLab security features available to GitLab users in a GitLab Security blog post with GitLab logos everywhere.
Call me a conspiracy theorist, but I start to think these people might be affiliated with GitLab.
It’s published on gitlab.com, not arxiv