Linux, to fediverse
@Linux@sakurajima.social avatar

The Sharkey leadership is a little incompetent. 🙄

Join Sharkey dot Org has been OFFLINE for over 2 months. The reason given was hosting issues, and this was before the whole Hetzner drama. Join Sharkey dot Org is supposed to be the gateway for people to learn about Sharkey and how they can join.

The Documentation Page (Wiki) is still up, using the subdomain, Doc dot Join Sharkey dot Org, but the URLs are broken. I have repeatedly reported the broken URLs for over 2 months (both in the Git and on their Discord Server). No one seems to want to address that.

They have a private copy of GitLab located at ActivityPub dot Software, that you cannot find via a search looking for Sharkey (DuckDuckGo, Bing, Google). That is where you can report code changes and fixes, but you would likely not know that unless you stumbled upon the URL somewhere (or someone gave you that URL).

Sharkey raised a lot of money so they can host their own content, safely, and securely. They now own their own physical server and lease the space to have that server housed (hosted) remotely. And while the lead developer promotes that server partially as a minecraft server, Join Sharkey dot Org still remains, OFFLINE.

I have pulled funding from Sharkey and will not be supporting it further until they get their act together. It is a good software, and it is my preferred method to use the Fediverse, but you would assume they would want their website working.

-- edit-- for grammar and clarify

#Sharkey #Fediverse #Misskey #IceShrimp #Minecraft #Hetzner #GitLab

bortzmeyer, to random French
@bortzmeyer@mastodon.gougere.fr avatar

@Framasoft "Your account [Framagit] has been deactivated" "Les comptes sont désactivés après un an sans activité" C'est du grand n'importe quoi, j'utilise régulièrement .

nekohayo, to accessibility
@nekohayo@mastodon.social avatar

As GitLab 17.0 is coming next week, it looks like my very polite reminder nudge might have encouraged the maintainers to request reviews from specific people for the automatic ("system") light/dark theme mode implementation, hopefully this lands in time for 17.0 🤞 so that we don't have to wait another full year to enjoy this and improvement, even if somehow considered experimental: https://gitlab.com/gitlab-org/gitlab/-/merge_requests/150254#note_1895251010

geekymalcolm, to random
@geekymalcolm@ioc.exchange avatar

Federal frenzy to patch gaping account takeover hole

https://www.theregister.com/2024/05/02/critical_gitlab_vulnerability/

PrivacyDigest, to security
@PrivacyDigest@mas.to avatar

Maximum-severity flaw allowing account under active exploitation

https://arstechnica.com/?p=2021409

governa, to random
@governa@fosstodon.org avatar

Critical Bug Under Exploit Enables Account Takeover, Warns ⚠️ :gitlab:

https://www.darkreading.com/application-security/critical-gitlab-bug-exploit-account-takeover-cisa

kubikpixel, to email German
@kubikpixel@chaos.social avatar

Die machen Werbung über sich, dass ihre KI toll einsetzbar sei und dann das, eine übliche Schwäche von Profi-Dienste. Nicht im Detail, sondern was es betrifft.

»Account-Übernahme möglich – Kritische Gitlab-Schwachstelle wird aktiv ausgenutzt:
Die Schwachstelle ermöglicht es Angreifern, beliebige Nutzerpasswörter über eine eigene E-Mail-Adresse zurückzusetzen. Tausende von Gitlab-Instanzen sind gefährdet.«

👉 https://www.golem.de/news/account-uebernahme-moeglich-kritische-gitlab-schwachstelle-wird-aktiv-ausgenutzt-2405-184798.html

Linux, to opensource
@Linux@sakurajima.social avatar

⚠️ GitLab Security Flaw (exploit) ⚠️

No matter if you host your own copy of GitLab Software or use GitLab's servers directly, you should enable 2-step Verification - NOW (right now, do not wait). There is a current exploit that allows someone to hijack GitLab Accounts, who are not using 2-step verification.

craftyguy, to cochlearimplants
@craftyguy@freeradical.zone avatar

debugging tests that fail only in is the worst... absolutely has it right by allowing you to SSH into a runner that failed a job.

morenonatural, to github Spanish
@morenonatural@todon.nl avatar

[2208.04259] First Come First Served: The Impact of File Position on
https://arxiv.org/abs/2208.04259

basster, to hamburg German
@basster@norden.social avatar

Heute mal auf der #gitlab #roadshow in #hamburg. Mal schauen, was es Neues gibt.

doctormo, to journalism
@doctormo@floss.social avatar

Hey #journalists if you're going to use an open source project as an example of a hack, can you at least let them know in advance you're about to do something reckless so they can prepare?

K. Thanks! 🙄

This doofus used inkscape and wireshark's live gitlab for a bit of a demo hack: https://www.bleepingcomputer.com/news/security/gitlab-affected-by-github-style-cdn-flaw-allowing-malware-hosting/

#journalism #ethics #oss #foss #floss #gitlab #cdn #infosec

polychromata, to github

@fujowebdev It's nice to see representation of something other than , but given that is maintained by a forprofit, i expect it's only a matter of time before the same shit starts happening (and there /has/ already been one incident). It'd be cool to see like a cameo (or at least an offhand mention) of something like .

InternetIsScary, to fediverse French
@InternetIsScary@mstdn.social avatar

The fediverse is amazing!

I can’t get over how cool it is to view my posts from any server. I’m definitely going to use activitypub for my social media I’m planning on making. I was going to use @Discourse , but considering it’s like where you are only able to self host and each instance of discourse can’t interconnect makes me kinda sad. But activitypub seems like the only way I feel happy in both ways.

@lemmy

welcomewerkstatt, to github German
@welcomewerkstatt@norden.social avatar

Kennt ihr ? Auch wenn ihr kein(e) Programmierer:in seid, dann seid ihr bestimmt schonmal auf , o.Ä. gestoßen. Auch als Designer:in, Maker:in, Texter:in oder einfach nur zum Projektmanagement spielen Git und die dazugehörigen Plattformen heute eine große Rolle. Wir erklären Git/GitHub/GitLab für Nicht-Programmierer in einem dreistündigen Workshop am Sonntag, den 19. Mai. https://www.welcome-werkstatt.de/veranstaltungen/git-fuer-nicht-programmierer

toxi, to github
@toxi@mastodon.thi.ng avatar

"Instead of generating the URL after a comment is posted, GitHub automatically generates the download link after you add the file to an unsaved comment, [...]. This allows threat actors to attach their malware to any repository without them knowing."

I always wondered if these attachments would stay around and if so for how long. Seems to be permanent, though (at least until this is going to be fixed)...

https://www.bleepingcomputer.com/news/security/gitlab-affected-by-github-style-cdn-flaw-allowing-malware-hosting/

#GitHub #GitLab #Malware #Infosec

abcdw, to github
@abcdw@fosstodon.org avatar

The nice thing about sourcehut: API is exposed to me to the full extent and I can easily integrate things how I want.

https://man.sr.ht/lists.sr.ht/api.md
https://man.sr.ht/todo.sr.ht/api.md

arda, to github
@arda@micro.arda.pw avatar

GitLab C̶o̶p̶i̶l̶o̶t̶ 😆 Duo chat is now generally available:

https://about.gitlab.com/gitlab-duo/

gregorni, to GNOME
@gregorni@fosstodon.org avatar

New custom emoji on the GNOME GitLab!

#GNOME #GitLab #Emoji

falken, to ai
@falken@qoto.org avatar

In today's "LLM is the future" rebuttal, this exchange from

"
Q: Is 23 less then twenty five ?
A: No, 23 is not less than 25.
"

and (nous hermes 2 mistral DPO) which is somehow even worse

"
Q: Is 23 less then twenty five ?
A: No, 23 is not less than 25. In fact, it is greater by 2 units (25 - 23 = 2).
"

falken,
@falken@qoto.org avatar

@jaifroid whatever shit #gitlab uses. IDK. Go use it yourself?

xahteiwi, to random
@xahteiwi@mastodon.social avatar

Opinion: people who staunchly prefer working with Gerrit, and consider anything else inferior, really love working with git-review. And if git-review were not Gerrit specific they would be just as happy with, say, GitLab.

The process that the git-review/Gerrit combo automates/enforces (one commit per change, automatically generated topic branches, change IDs with cross-project uniqueness) could also work just fine by hooking up git-review with the GitLab API.

Discuss.

phryk, to random
@phryk@mastodon.social avatar

A friend got frustrated with gitlab today because the @efoundation gitlab denies registrations from their personal mailserver, probably
caused by this thing:

https://about.gitlab.com/blog/2021/08/19/introducing-spamcheck-data-driven-anti-abuse/

I could reproduce the issue (see screenshot) and then we stumbled onto this:

https://about.gitlab.com/

Some money quotes:

"GitLab is the most comprehensive AI-powered DevSecOps Platform."

"See how Lockheed Martin saves time, money, and tech muscle with GitLab"

phryk,
@phryk@mastodon.social avatar

For context: Lockheed Martin is one of the biggest US arms manufacturers, building things like fighter jets and ballistic missiles.

I think it's fair to say that by now should be seen as just as morally bankrupt as Microsoft .

BoydStephenSmithJr, to haskell
@BoydStephenSmithJr@hachyderm.io avatar

I opened two merge requests on a project (hosted on ) that I don't "own". I think that's enough for the day. 😀

J12t, to firefox
@J12t@social.coop avatar

Today, between and , I'm getting an endless loop of some silly attempt to verify that I am human. So it says at least, I don't think it can, but maybe it is recognizing that and that keeps it looping :-) Safari works.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • anitta
  • Durango
  • magazineikmin
  • InstantRegret
  • hgfsjryuu7
  • vwfavf
  • Youngstown
  • slotface
  • thenastyranch
  • ngwrru68w68
  • rosin
  • kavyap
  • PowerRangers
  • DreamBathrooms
  • cisconetworking
  • khanakhh
  • mdbf
  • tacticalgear
  • ethstaker
  • modclub
  • osvaldo12
  • everett
  • tester
  • cubers
  • GTA5RPClips
  • normalnudes
  • Leos
  • provamag3
  • All magazines