jimmyb, to random
@jimmyb@selfhosted.cafe avatar

Just realized the last 10 commits I made to this project are using the wrong email address 🤦🏼‍♂️

Floppy, to random
@Floppy@mastodon.me.uk avatar

If you've got a minute, give https://try.manyfold.app/ a go, I want to see how often it crashes due to resource limits on the very very small node I'm running it on.

amcewen,
@amcewen@mastodon.me.uk avatar

@Floppy yeah, I mostly ignore those in favour of git[hub|lab] and @MCQN_Ltd's self-hosted instance too 😀

I guess I'm staying that version control and issue trackers are an integral part of my workflow. Maybe that just means that easy integration to @manyfold from a collection of git repos so that it could be a read-only sharing front is how I might use it?

jimmyb, to plex
@jimmyb@selfhosted.cafe avatar

Setup backups for my instance this evening. I also fixed an issue I had with my instance and its upgrade to 3.x. And finally I updated my to script so it strips anything which isn't 'a-zA-Z0-9' from the title tag.

Time to play some with my girlfriend for a bit.

Anarcat, to random
@Anarcat@kolektiva.social avatar

gosh i wish would stop turning every dollar sign pair into a LaTeX formula. i basically never need that "feature"

rabc, to github
@rabc@hachyderm.io avatar

I think it would be useful if and had for repository activity. I’d love to track some repositories from my timeline.

juliensalort, to sysadmin French
@juliensalort@physfluids.fr avatar

J'ai été victime d'un piratage de mon instance GItlab. J'ai l'impression que la personne a utilisé la vulnérabilité CVE-2023-7028 pour changer le mot de passe du compte admin de l'instance (j'étais en version 16.3.6). D'après les logs, il s'est pas connecté ensuite. L'attaque provient de 3.142.114.26 et whois me dit que c'est Amazonaws. Mais je vois pas d'email d'abuse? Est-ce qu'il y a une procédure de signalement?

amadeus, to bitwarden
@amadeus@mstdn.social avatar

1/2 I currently use a very good but still somewhat limited (also in terms of performance) shared service from Switzerland. I , and others. In the future I'd like to self host , , and as well.

shalien, to random French
@shalien@projetretro.io avatar

I wish tools like and existed to protect open source code. Guess s I will have to close my GitHub account and

Joseph_of_Earth, to random
@Joseph_of_Earth@fosstodon.org avatar

Thank you to @itguyeric for letting me know that GitLab has dark mode! I no longer am blinded when contributing in the evenings!

itnewsbot, to vmware
@itnewsbot@schleuss.online avatar

This Week in Security: Gitlab, VMware, and PixeFAIL - There’s a Gitlab vulnerability that you should probably pay attention to. Tracked ... - https://hackaday.com/2024/01/19/this-week-in-security-gitlab-vmware-and-pixefail/

jwildeboer, to random
@jwildeboer@social.wildeboer.net avatar

Hm. It seems I cannot create a hierarchy of teams and projects in the way I can in . In the forgejo/gitea world you have organisations and teams. But you cannot have teams under teams. Which is a bit limiting, IMHO. Or am I missing something?

simontsui, to random

VulnCheck wrote about 7777-Botnet with the following information:

  • 7777-Botnet remains active, and VulnCheck used co-located services to theorize the botnet is infecting TP-Link, Xiongmai, and Hikvision devices using CVE-2017-7577, CVE-2018-10088, CVE-2022-45460, CVE-2021-36260, and/or CVE-2022-24355.
  • The botnet also appears to infect other systems like MVPower, Zyxel NAS, and GitLab, although at a very low volume.
  • The botnet doesn’t just start a service on port 7777. It also spins up a SOCKS5 server on port 11228.

🔗 https://vulncheck.com/blog/ip-intel-7777-botnet

gittaca, to LLMs
@gittaca@chaos.social avatar

Amazing how fans of code overlook inconvenient details in industry's own surveys:
> … respondents with more experience were less
> likely to associate AI with productivity gains …
> --https://www.theregister.com/2023/09/05/gitlab_ai_coding/

Sounds like it can replace/augment those with experience levels
But actual specialists? Have -1 incentive now to write down their experience. 📉trends ensue.

mgeisler, to github
@mgeisler@ohai.social avatar

Awesome! doubles the number of CPU cores in the machines we use for our Actions! It's for free for public (typically ) repositories.
https://github.blog/2024-01-17-github-hosted-runners-double-the-power-for-open-source/

finn,
@finn@toot.fan avatar

@Mathemagician @mo8it @mgeisler Yes, shitty code for for GitHub!

Just a reminder that and exist 🙂

nerdeiro, to homelab
@nerdeiro@fosstodon.org avatar

I'm moving away from on my . It's not that I don't like it, I do. A lot. But it's way too much for my humble needs, so I moved all my local repos to with for CI/CD.

I just finished the pipeline that builds and publishes my blog and it's working nicely.

praveen, to debian
@praveen@social.masto.host avatar

We are working on rebuilding #gitlab 16.6.x on #debian #bookworm.

It is a good way to start contributing to debian as rebuilding is usually very simple.

I'd be happy to help if you are interested to join the effort.

We have to do this once in a month or two months usually.

This is the list of packages we need to rebuild.

https://storm.debian.net/grain/zgriFDoyuAzzWBTodnaD6Z

and this is the list of steps we usually need https://salsa.debian.org/ruby-team/gitlab/-/wikis/bookworm-backports

You can also contribute by testing the gitlab packages.

#FreeSoftware

Xitnelat, to random German
@Xitnelat@wue.social avatar

Momente, in denen Du (hoffentlich) froh bist, dass Du ein hast... 😕

smallcircles, to security
@smallcircles@social.coop avatar

⚠️ ALERT: Critical issue in self-hosted and upgrade required.

Affected versions:

16.1 to 16.1.5
16.2 to 16.2.8
16.3 to 16.3.6
16.4 to 16.4.4
16.5 to 16.5.5
16.6 to 16.6.3
16.7 to 16.7.1

See: https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/

RonaldTooTall, to technology

Patch time: Critical GitLab vulnerability exposes 2FA-less users to account takeovers

The bug with a perfect 10 severity score has been ripe for exploitation since May.

https://www.theregister.com/2024/01/15/critical_gitlab_vulnerability/

snafu, to security
@snafu@digitalcourage.social avatar

So, in case anyone still thinks that patching and security in general is not so important nowadays: Found already several tries of exploiting the recent critical CVE-2023-7028 vulnerability in the logs of my GitLab instance although it was only published a few days ago.

Conclusion:
✅ Install security updates literally ASAP.
✅ Turn on mandatory 2FA for all users.

jwildeboer, to random
@jwildeboer@social.wildeboer.net avatar

Dear @bagder Thank you a gazillion again for that just allowed me to fill a instance with issues having creation dates in the past.

certbund, to random German
@certbund@social.bund.de avatar

❗️❗️
Eine kritische in erlaubt es Konten ohne 2FA zu übernehmen. Durch die Veröffentlichung eines Proof-of-Conecepts ist von einer stattfindenden Ausnutzung auszugehen.
https://www.bsi.bund.de/SharedDocs/Cybersicherheitswarnungen/DE/2024/2024-205245-1032

feudjais, to random French
@feudjais@eldritch.cafe avatar

Si vous avez des vieilles instances , message d'utilité publique : faites la dernière mise à jour !

Une faille permet de passer admin d'une instance via une requête POST, sans compte.

jwildeboer, to random
@jwildeboer@social.wildeboer.net avatar

Dear — scoped labels shouldn't be hidden behind your paywall.

tbernard, to random
@tbernard@mastodon.social avatar

It's 2024 and Gitlab still has 10+ useless color options but no way to follow the system dark mode preference 👌️

nekohayo,
@nekohayo@mastodon.social avatar

@tbernard dark mode, episode IV: A New Hope https://gitlab.com/gitlab-org/gitlab/-/merge_requests/141459

Now maybe in Episode V we will get "The prefers-color-scheme strikes back"

  • All
  • Subscribed
  • Moderated
  • Favorites
  • megavids
  • kavyap
  • DreamBathrooms
  • thenastyranch
  • magazineikmin
  • InstantRegret
  • GTA5RPClips
  • Youngstown
  • everett
  • slotface
  • rosin
  • osvaldo12
  • mdbf
  • ngwrru68w68
  • JUstTest
  • cubers
  • modclub
  • normalnudes
  • tester
  • khanakhh
  • Durango
  • ethstaker
  • tacticalgear
  • Leos
  • provamag3
  • anitta
  • cisconetworking
  • lostlight
  • All magazines