darkghosthunter, to php
@darkghosthunter@mastodon.social avatar

Just going to nonchalantly shove in some awareness to my GitHub Sponsorship.

If you value my contributions to Open Source and Laravel, just leave a small tip or become a sponsor. It helps me pay the bills.

https://github.com/sponsors/DarkGhostHunter

vingtroiseize, to github
@vingtroiseize@mastodon.world avatar
governa, to github
@governa@fosstodon.org avatar
smxi, to github
@smxi@fosstodon.org avatar

It continues to strike me that now, almost 4 months after last commit on any project, including , gh users keep starring my gh repos, even though all of them clearly state that the code is migrated to @Codeberg in the README, which is why I got sick of gh users, they don't read as a whole, and tended to post annoying issues. The users who read, tend to post good issues. that's what I see on codeberg smxi repos now. Not perfect, nothing is, but better. So happy with switch.

darklang, to github

#introduction #introductions

Hey folks!

Darklang is a #ProgrammingLanguage, editor, and #PaaS, developed in public on #GitHub.

It started in 2017 and has had a tumultuous time, but is still being actively worked on by a small team led by @paulbiggar.

Darklang's goal is to make it 100x easier to build #backend #services. It's a #functional programming language, with some novel ideas, such as #TraceDrivenDevelopment and #deployless.

1/🧵

sycarion, to github

Quick note while I am thinking about it. I was unhappy with Publii for a while because I couldn't get it to sync with github.

That has been fixed and I redid the authorization in my Github account and it works beautifully.

I prefer Publii because it is local markdown files and I can copy them over to Obsidian.

I have converted my old WP site to markdown and will publish it through Publii as well.

vincentbiret, to github
@vincentbiret@hachyderm.io avatar
Edent, to github
@Edent@mastodon.social avatar

Hmmm. I have an SSH key which I use for both and .

GitLab has just warned me it will expire in 7 days (but no notification from GitHub!).

So, my wizard friends:

Is there a way to update my key? (I assume no and I need to create a new one.)

Should I have different keys for Hub/Lab?

What's the real danger to my personal repos of having never-expiring keys?

THANKS CLEVER PEOPLE WHO ALMOST CERTAINLY KNOW MORE THAN AN LLM!

Edent, to github
@Edent@mastodon.social avatar

Oh, nifty! now allows you to connect your . When did that happen?

karlcow, to github French
@karlcow@mastodon.cloud avatar

Reminder: In case you need to monitor your own activity for your work on , there is a feed for the user activity.

[https://github.com/github_username.atom](https://github.com/github_username.atom`)

Practical to automatically create a .

mhoye, to random
@mhoye@mastodon.social avatar

The sad and hilarious thing is that computer nerds already control the means of production they're just not doing anything with it other than what they're told.

dimitrisk,
@dimitrisk@floss.social avatar

@mhoye Then, they opted for #github to host their code, they built it around Github's CI/CD. They adopted #copilot. Ah, they also built their community on #discord and release their work on centralized proprietary platforms (e.g. #googleplay). Now, they own nothing.

Codeberg, to github
@Codeberg@social.anoxinon.de avatar

If there was malicious code in a legitimate project hosted on , would we remove access to it, including for security researchers?

Short: No!

We are considering how to prevent fetching malicious code by accident, though.

In any case, we are open to collaborating with security researchers. Interested? Help us build a malware hunting team: https://codeberg.org/Codeberg/Contributing/issues/44

Background: locked access to source code of xz, which was background of active investigation from the community.

wyri, to github
@wyri@haxim.us avatar

Writing this month's sponsors update while watching The Cup Head Show on the side: https://github.com/sponsors/WyriHaximus

(It includes a blog post preview 😎 .)

davidbures, to github
@davidbures@mstdn.social avatar

Does anyone out there have experience with GitHub build workflows for macOS apps that include codesigning and notarizing the app? I'm having some trouble with setting mine up and I don't know what to do at all 😖

kissaki, to github

Krita is a KDE project which hosts its development on a KDE GitLab instance. They also have a GitHub mirror repository.

The GitHub mirror is starred by 6.5k accounts. Their GitLab repository is starred by 75 accounts.

And their ticketing system is Bugzilla. Which I greatly disliked before, but I don't even see an obvious way to search for issues by text filtered to the Krita project.

I think it's a shame they evade GitHub as a platform for contributions. It certainly makes me give up contributing to it. Even on issue tickets.

The star difference is absurd.

lukzmu, to github

I moved all my private and public repositories from to and I must say I’m happy with that change. I love how smart the pipelines are - much cleaner code for CICD than with Actions. The only problem I see for now is the fact that adding to the GitLab profile doesn’t add the rel=me, so it doesn’t show as green on my profile here.

joeyh, to github
@joeyh@hachyderm.io avatar

Worth noting that some Jia Tan commits to were made with the github web interface. You can tell because they are signed by a gpg key github uses for web edits (4AEE18F83AFDEB23).

The most recent one is 62efd48a825e8f439e84c85e165d8774ddc68fd2.

So if keeps logs since January, they might have IP address information or other info.

vwbusguy, to github
@vwbusguy@mastodon.online avatar

Lasse Colin posted an update on the backdoor situation. It doesn't give a lot of details, but still useful as a primary source of information.

TL;DR: Damage control is underway in the project, but it's been somewhat inhibited by taking it down and suspending Lasse's account.

https://tukaani.org/xz-backdoor/

janriemer, to github

Excellent video by Dreams of Code ✨

Why I'm no longer using Copilot - by Dreams of Code

Invidious:
https://farside.link/https://www.youtube.com/watch?v=Wap2tkgaT1Q

(or YT: https://www.youtube.com/watch?v=Wap2tkgaT1Q)

mms, to github
@mms@emacs.ch avatar

It’s almost April 2024. You still can’t search without an account.

It’s almost April 2024. You still can’t send patches without an account on GitHub.

rysiek, to microsoft
@rysiek@mstdn.social avatar

Hey it's totally cool that blocked access to one of the repositories in the very center of the backdoor saga. :blobeyes:

It's not like a bunch of people are scrambling to try and make sense of all this right now, or that specific commits got linked to directly from media and blogposts and the like. :blobcatcoffee:

Cool, cool. :blobcatfingerguns:

governa, to github
@governa@fosstodon.org avatar

Disables The Repository Following Today's Malicious Disclosure ⚠️

https://www.phoronix.com/news/GitHub-Disables-XZ-Repo

scy, to random
@scy@chaos.social avatar

Eek. Apparently liblzma (part of the xz package) has a backdoor in versions 5.6.0 and 5.6.1, causing SSH to be compromised.

https://www.openwall.com/lists/oss-security/2024/03/29/4

This might even have been done on purpose by the upstream devs.

Developing story, please take with a grain of salt.

The 5.6 versions are somewhat recent, depending on how bleeding edge your distro is you might not be affected.

#liblzma #xz #lzma #backdoor #ITsecurity #OpenSSH #SSH

scy, (edited )
@scy@chaos.social avatar

Hell yeah , that's certainly going to help the researchers who are working on the weekend trying to reverse engineer the backdoor.

What a great idea. 🙄

Edit: This also deleted the project's GitHub-hosted website.

Mirrors of the repo can be found here:

https://hachyderm.io/@joeyh/112181981560074232
https://git.tukaani.org/?p=xz.git;a=summary

petersuber, to github

I think this is the beginning of a beautiful friendship:

" and are delighted to announce the signing of a Memorandum of Understanding (MOU) committing the two organizations to coordinate efforts encouraging the adoption of ORCID iDs through the research lifecycle."
https://info.orcid.org/orcid-and-github-sign-memorandum-of-understanding/

esparta, to ruby
@esparta@ruby.social avatar

The executive director of @rubycentral, @adarsh which gives kudos to the people who contributors to rubygems.org

meetup

esparta,
@esparta@ruby.social avatar

In the stage @marcoroth talking about ruby

meetup

  • All
  • Subscribed
  • Moderated
  • Favorites
  • JUstTest
  • mdbf
  • InstantRegret
  • ethstaker
  • magazineikmin
  • GTA5RPClips
  • rosin
  • modclub
  • Youngstown
  • ngwrru68w68
  • slotface
  • osvaldo12
  • kavyap
  • DreamBathrooms
  • Leos
  • thenastyranch
  • everett
  • cubers
  • cisconetworking
  • normalnudes
  • Durango
  • anitta
  • khanakhh
  • tacticalgear
  • tester
  • provamag3
  • megavids
  • lostlight
  • All magazines