

I have a few projects, some are just for me. And others are available for use. Mostly plugins for other projects, couple hundred people using them.
They all have good cocd pipelines with testing, code validation/ static code analysers. It’s trivial to maintain. Not big projects by any means but 20-50k loc
Google uses https://github.com/google/gvisor in GCP. So it’s not affected by most vulnerabilities like this. But still makes sense they want the tech. Vm escapes would be really bad for them.