‹ BackHN Continuity

Thread

Gitea 28.0

99 points · 47 comments · porridgeraisin

  1. ThePinion · · focus · HN ↗
    > This release contains security fixes. To give everyone time to upgrade, details will be added to this post in about a week.

    Is this something that has been happening for a while or a new trend due to LLM concerns? I understand the reasoning, it just made me do a double take because I haven't really seen that before.

    1. QuantumNomad_ · · focus · HN ↗
      With Gitea specifically or in general? A lot of different software has silently included security fixes in updates combined with other changes and then later revealed what security fixes were made or stayed quiet about it all together, since long before LLMs could analyze changes.

      Security researchers and malware authors would reverse engineer software updates of proprietary software, and scrutinise source code changes of open source projects to find secretly shipped security fixes.

    2. stackghost · · focus · HN ↗
      Bizarre policy. Any bad guys unaware of the security implications are analyzing the patch diffs as we speak, so this seems nonsensical to me.
      1. IshKebab · · focus · HN ↗
        Yeah maybe it made sense in the past, but not in the age of AI.
    3. techknowlogick · · focus · HN ↗
      (bias note: I am a project lead of Gitea) this approach is based on what peertube has been doing, and is being attempted as an alternative approach to what we've been doing previously due to feedback we've been receiving from the community.
      1. entrope · · focus · HN ↗
        Is not describing the feedback part of the feedback you got? You're kind of playing into Forgejo's narrative about governance.
        1. techknowlogick · · focus · HN ↗
          The feedback was that we gave too many details too soon, and so we solicited feedback from the community and peertube's approach was given as a suggestion for us to try. But to be clear, this decision was discussed and made by the maintainers, including the elected leadership team. I'd say that this is a successful example of governance, as it isn't a unilateral decision, and everyone was involved in making.
    4. e12e · · focus · HN ↗
      That's quite annoying - "security fixes" - but no information if your installation is affected or not? (Eg: in a module that's disabled)?

      Makes work harder for sys admins - little difference for black hats.

      It's still a (<LLM> look at diffs in latest gitea release - find the patched security issues and write poc exploit for cve assessment) I guess?

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.