erlend, (edited ) to fediverse
@erlend@writing.exchange avatar

Several years in the making, GitLab is now very actively implementing ! 🙌

https://gitlab.com/groups/gitlab-org/-/epics/11247

The end-goal is to support AP for merge requests (aka pull requests), meaning git.alice.dev can send a merge request to gitlab.com/Bob/project.git

First bite-sized todo on the implementation path there is ‘subscribe to project releases’.

Smart move by ; through ActivityPub they’re getting a distributed version of GitHub’s social layer.

@fediversenews

Codeberg, to github
@Codeberg@social.anoxinon.de avatar

In case you missed it: "State of the Forge Federation: 2023 edition" at https://forgefriends.org/blog/2023/06/21/2023-06-state-forge-federation/

We are looking forward to among software forges. Break vendor lock in of , .com, and all the other.

harrysintonen, to random

The #GitLab #vulnerability allowing trivial account hijacking (CVE-2023-7028) will lead to ton of problems: It will allow malicious actors to perform #supplychain #attacks - something that will allow attacker to gain access to 3rd party who don't themselves run GitLab but just include from projects that do. I would suggest great caution regardless if you run GitLab yourself or not.

Naturally anyone using GitLab themselves must update as soon as possible. I would also suggest performing forensic investigation to find out if you have already been compromised, and take further action in case compromise has already occurred. Check "Were any accounts actually compromised due to this vulnerability?" section in this post for details: https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/

Codeberg, to opensource
@Codeberg@social.anoxinon.de avatar

: Tell us about your favourite / projects that are not available on mainstream platforms, whether on a self-hosted cgit or available as an archive download only.

The world is more than and .

joshbressers, to github

I was in a meeting today and I realized something profound

We are currently in a post world

That probably don’t make sense to a lot of people, and I need to think about it more

But here’s the basics of it

The CVE data is so comically bad, nobody actually doing work can use it. The ID is all we use. We have to look in other databases and collect or own facts

Automated tools rely on sources like , , and . Other than the ID, CVE doesn’t really matter anymore

J12t, to fediverse
@J12t@social.coop avatar

A few weeks ago I asked about Fediverse apps that are as unlike as Mastodon as possible. People pointed me to some quite interesting ones, like playing chess over ActivityPub or public transport delay announcements https://social.coop/@J12t/110843539252937792

Today I hear that is working on decentralized merge requests over ! If this comes into being, this could be a really major development for the . https://gitlab.com/groups/gitlab-org/-/epics/11247

rmader, to random
@rmader@floss.social avatar

Just found out that on one can add a + to an issue or MR link, making the preview show the whole title. I.e. instead of "" you get "Some thing is broken ()" - if you write "+"

So if you don't know, now you know 🤷

kik, (edited ) to fediverse
@kik@techhub.social avatar

So, how is implementation in going? Steadily, if a bit slowly!

In the last four months, we've been working on implementing the first ActivityPub actor, the one allowing to subscribe to projects releases. The ActivityPub part is already written, but there will still be a couple month before it's fully merged. Turns out that the most time consuming part is code review : there is no dedicated team to this (but there is a dedicated developer assisting me, thanks Patrick!), so people reviewing code discover ActivityPub at the time they have to review it (and, by the way, it's incredible how they get out of their way to help a contributor on such a complex subject, they rock). For that reason, we have to make smaller than usual merge requests, splitting the feature as much as possible, and then some again, to make it as easy to understand as possible. And even then it usually takes about a month to get one chunk merged. (more in thread)

RyunoKi, (edited ) to github
@RyunoKi@layer8.space avatar

Hey there 👋

I'm building a smol web app for someone that displays issues on , and resp. together.

Goal is to ease migration from one forge to another.

I could imagine that businesses and Open Source projects would consider this interesting for themselves.

Question for you: would you be willing to donate a small amount of money for tasks like these, so that I can focus on them? (Think Patreon-like funded work for the commons).

GTK, to GNOME
@GTK@floss.social avatar

If you have experience maintaining a GitLab CI runner on macOS, and you wish to contribute to building and testing GLib and GTK on macOS, please join the GNOME Infrastructure channel to help maintaining the macOS server provided by the GNOME Foundation, otherwise we will have to retire it. More details on Discourse: https://discourse.gnome.org/t/potential-retirement-of-the-macos-ci-builder-for-glib-and-gtk/16198

anthraxx, to archlinux
zeab, to fediverse
@zeab@fosstodon.org avatar

Woah. really is planning to federate with . 🤯

https://docs.gitlab.com/ee/development/activitypub/

eisfunke, to random
@eisfunke@inductive.space avatar

If you host a instance, you should update it as soon as possible. There's a critical security update, including a fix for "Account Takeover via password reset without user interactions". Oopsie.

https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/

juliensalort, to sysadmin French
@juliensalort@physfluids.fr avatar

J'ai été victime d'un piratage de mon instance GItlab. J'ai l'impression que la personne a utilisé la vulnérabilité CVE-2023-7028 pour changer le mot de passe du compte admin de l'instance (j'étais en version 16.3.6). D'après les logs, il s'est pas connecté ensuite. L'attaque provient de 3.142.114.26 et whois me dit que c'est Amazonaws. Mais je vois pas d'email d'abuse? Est-ce qu'il y a une procédure de signalement?

dis, to random

Hey you! If you ever, ever, use , (etc) you need to read this. Every , and most everyone else, ESPECIALLY those of you who are NOT . (Contributors/devs usually have local copies already.)
The first hour of my day was just wasted chasing down an error in that turns out to be "Dev deleted their repositories on github and now is mad"

The problem is not that the developer chose to stop supporting their work. That is their prerogative and my only role is to be sad. The problem is that we learned nothing from https://arstechnica.com/information-technology/2016/03/rage-quit-coder-unpublished-17-lines-of-javascript-and-broke-the-internet/

ONLY WORKS IF YOU HAVE YOUR OWN COPY. The downloads and tarballs are not the same thing. They are partial copies at best. Even "forking" (on the same site) can be deleted at the original author's whim.
To actually have your own copy, it needs to be somewhere else. On a new site (if the original is on you can put your copy on ) or even your laptop. And when you can, use your copy instead.👿

Taffer, to internet
@Taffer@mastodon.gamedev.place avatar

Cloudflare has broken their "security check" widget for Firefox (120 at least) when you've got protection against fingerprinting enabled.

I had to use Chromium to log in to GitLab because of this. It's IE6 all over again. Thanks Cloudflare!

The "security check" is actually DDOS prevention looking for bots. Which frequently just run in browsers/Electron these days.

freemo, to fediverse
@freemo@qoto.org avatar

I just added a feature to Fedipage that now lets me combine the activity from multiple gitlab servers into a single git activity heatmap.

Check out my home page where I now combine all the git servers i work on in one activity heat map:

https://jeffreyfreeman.me/

If you want the code to replicate my site (a hugo based static site generator with full ActivityPub support) check out: https://fedipage.com

marcaurele, to fediverse
@marcaurele@mastodon.social avatar

Super cool work from @kik on adding support for to - progress can be followed on his profile https://gitlab.com/oelmekki

Natureshadow, to random

I feel seriously betrayed by .

They promised a free and open, completely self-hostable development platform.

Now they are, without consent, transmitting my data to from my self-hosted GitLab 😡.

To avoid that, do not use the new Web IDE, which is Visual Studio Code in your browser (cool), sending data to Microsoft servers (very much not cool).

kubikpixel, (edited ) to random
@kubikpixel@chaos.social avatar

Which surfing do you use for your public ? Why did you choose @github, @gitea, , @Codeberg or a completely different one, why & which one? 🧑‍💻 :BoostOK:

(multiple selection possible)

irfan, (edited ) to random

Still no progress/updates on this btw - my data on 2 accounts are essentially still stuck/"held hostage" on .social 🙃

Following up again - @kainoa @thatonecalculator is there really nothing kind folks at firefish.social can do to check on why these multiple notes exports that were done for the past almost ~3 weeks now still have not completed, seeing that according to you it should only take no longer than 15 mins.

I genuinely need an export of my notes on these 2 accounts: @irfan and @afrina. Thank you.

Update (Nov 24 2023):

This might be an instance-specific issue, but since all I've got is Firefish's repo, and it is the Flagship instance after all, I've reported the issue on there.

🔗 https://git.joinfirefish.org/firefish/firefish/-/issues/10814

RE: https://kitsunes.club/notes/9m32a9tcio

nekohayo, to GNOME
@nekohayo@mastodon.social avatar

I think I did a pretty good job at labelling/tagging performance-related issues in and Shell; did I miss any important ones?

I really wish had non-shitty search and could allow using wildcards and "OR" operators for & bug triaging.

rabc, to github
@rabc@hachyderm.io avatar

I think it would be useful if and had for repository activity. I’d love to track some repositories from my timeline.

J12t, to random
@J12t@social.coop avatar

ActivityPub mentioned in Thoughtworks’ Technology Radar:

“We expect ActivityPub will play a significant role in [social media interop], but … we’re intrigued by the possibilities beyond the obvious use cases in social media. An example is ActivityPub support for merge requests, recently proposed for .

They got that right!

https://www.thoughtworks.com/content/dam/thoughtworks/documents/radar/2023/09/tr_technology_radar_vol_29_en.pdf

simplenomad, to security
@simplenomad@rigor-mortis.nmrc.org avatar

My employer is hiring, specifically in the Security division. Security Identity Management is the area, so if you're into and and you're qualified, apply. If not, a few other positions are available, feel free to poke around. Fully remote. I'm not shopping for a referral, I'm shopping for a work colleague, so apply!

https://boards.greenhouse.io/gitlab/jobs/7294564002

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • kavyap
  • DreamBathrooms
  • cisconetworking
  • magazineikmin
  • InstantRegret
  • Durango
  • thenastyranch
  • Youngstown
  • rosin
  • slotface
  • mdbf
  • khanakhh
  • tacticalgear
  • megavids
  • everett
  • modclub
  • Leos
  • cubers
  • ngwrru68w68
  • ethstaker
  • osvaldo12
  • GTA5RPClips
  • anitta
  • provamag3
  • normalnudes
  • tester
  • lostlight
  • All magazines