Live data from Hacker News

Forgejo <=16.0.3 Critical RCE

codeberg.org

81–87 of 87 posts

Re: Forgejo <=16.0.3 Critical RCE

#81
post #53

Earlier quoted context omitted.

The amount of time I need to spend maintaining my Forgejo instance this year, even after accounting for this RCE, has been less than the amount of time GitHub has been degraded or unavailable this year.

That doesn't match my experience at all. I had a Foregjo instance on a Raspberry Pi, and maybe it's typical SD card issues, but the number of times that Forgejo has crashed because it locked its own database and couldn't continue and the number of times repos I mirror from GitHub just mysteriously stop syncing is quite probably the same number of times GitHub has been down this year.

Bruh sorry, stop running any RW services off an SD card, it has always been terrible and unfortunately it will remain terrible, you can buy a used SFF with >5x the compute and a sata ssd for the same price as a raspberry pi alternatively put an nvme hat on it

Re: Forgejo <=16.0.3 Critical RCE

#82
post #22

Earlier quoted context omitted.

You can. People on Codeberg use LLMs. They are just against spam of low quality projects generated with LLMs.

That is actually entirely not what they were saying at the time of the vote and its aftermath. At all. Go back and read the threads. On this forum, or on mastodon, or on the vote. It was pretty vociferously ... shall we say ... "principled" It was never stated to be about "low quality" but about use in "large part" or "majority", and when pressed people refused to define what that meant, and in fact got angry and def…

I assume you are implying that LLM generated projects don't mean bad quality. That's true. At same time we all know what this means. Plausibly looking projects that might even work but have little human oversight. There are so many of them It's really difficult to know. I don't want to depend on such code and I bet neither do most programmers. Why? Because by then you might as well vibe the library yourself and be the one who does the oversight.

I might be wrong but I doubt that people on Codeberg are against use of LLMs that make the projects better. Like finding security leaks. What these rules are aimed at are hosting of endless vibe coded projects that are just copy of each other.

Re: Forgejo <=16.0.3 Critical RCE

#83
post #64

Earlier quoted context omitted.

That is actually entirely not what they were saying at the time of the vote and its aftermath. At all. Go back and read the threads. On this forum, or on mastodon, or on the vote. It was pretty vociferously ... shall we say ... "principled" It was never stated to be about "low quality" but about use in "large part" or "majority", and when pressed people refused to define what that meant, and in fact got angry and def…

Do you expect it to be enforced by a machine? Why would you need a precise definition of "majority"?

You don't and that's why everyone gets so angry and annoyed when people try to force precise definitions.

There's no team of lawyers verifying the provenance of all code/projects submitted to codeberg. THe policy is just something they can point to as a general guidelines of what kind of shit they want to support.

Everyone knows exactly what kind of projects they're talking about. The people trying to nitpick definitions are those annoying ass people at the board game night that spend half the time combing through the rule book trying to figure out why whatever they didn't like was against the rules.

Re: Forgejo <=16.0.3 Critical RCE

#84
post #64

Earlier quoted context omitted.

Do you expect it to be enforced by a machine? Why would you need a precise definition of "majority"?

You don't and that's why everyone gets so angry and annoyed when people try to force precise definitions. There's no team of lawyers verifying the provenance of all code/projects submitted to codeberg. THe policy is just something they can point to as a general guidelines of what kind of shit they want to support. Everyone knows exactly what kind of projects they're talking about. The people trying to nitpick definit…

That's why they say they don't need an AI detector and that anyone who complains about the rule is guilty.

Ordinarily that's a bad way to run a rule. But not this time!

Re: Forgejo <=16.0.3 Critical RCE

#85
post #84

Earlier quoted context omitted.

You don't and that's why everyone gets so angry and annoyed when people try to force precise definitions. There's no team of lawyers verifying the provenance of all code/projects submitted to codeberg. THe policy is just something they can point to as a general guidelines of what kind of shit they want to support. Everyone knows exactly what kind of projects they're talking about. The people trying to nitpick definit…

That's why they say they don't need an AI detector and that anyone who complains about the rule is guilty. Ordinarily that's a bad way to run a rule. But not this time!

What the folks involved were actually saying, and what let slip multiple times through all those threads is: Any use of the tool is Wrong(tm). They never meant anything by the "majority" or "vibe-coded" or whatever because they didn't need to or want to; Multiple people let slip in all sorts of forums what the intent was: define a policy ambiguous enough that it could be used for frankly vibe-based exclusion. Defining the terms of exclusion was deliberately avoided because a) if-you-know-you-know b) they wanted to reserve the freedom to sit in judgement.

That's fine for new projects. Their sandbox and they can decide who plays in it. But the people who were using codeberg for months or even years and relying on it, and had to move... deserved better treatment.

Fomr my eyes the questions about what defines "majority" were well-intention-ed queries with the motive of trying to ferret out what the criterion for was in the eyes of the people who proposed the vote. That they refused to answer, and cast aspersions on the people who asked... is both a damning judgement on their personal character but also their community management.

What we have is a community defining an in-group and an out-group. And just like middle school, "you'll just know" if you're in one or the other.,

Good grief. What a bizarre cultish echo chamber. The tools make you dirty. Don't touch the tools.

Re: Forgejo <=16.0.3 Critical RCE

#86
post #82

Earlier quoted context omitted.

That is actually entirely not what they were saying at the time of the vote and its aftermath. At all. Go back and read the threads. On this forum, or on mastodon, or on the vote. It was pretty vociferously ... shall we say ... "principled" It was never stated to be about "low quality" but about use in "large part" or "majority", and when pressed people refused to define what that meant, and in fact got angry and def…

I assume you are implying that LLM generated projects don't mean bad quality. That's true. At same time we all know what this means. Plausibly looking projects that might even work but have little human oversight. There are so many of them It's really difficult to know. I don't want to depend on such code and I bet neither do most programmers. Why? Because by then you might as well vibe the library yourself and be th…

I would encourage you to go back and read what was said at the time. Yes, a significant probably-majority really are against the use of LLMs for anything and the policy was evidently not about a deluge of vibe-slop on the site. Because there was a much simpler answer for that: quotas, specific rules, specific policy, moderation.

Instead a vaguely worded policy was put in around the tools used to write code so that vibe-based judgement could sit and decide without the potential judged having recourse to any appeal. And requests for specificity were not just turned down but mocked. Because the intent was to leave it open so that a process of bullying could be put in place.

Basically, anti-democratic practices masquerading as community/democracy. I used to see this a lot back when I was involved more heavily in left wing activist groups and it was the sign of a declining and degraded community. Sad to see it here.

As for "I assume you are implying that LLM generated projects don't mean bad quality. That's true." I'm specifically saying LLM assisted/generated doesn't mean one way or the other. They're tools.

Re: Forgejo <=16.0.3 Critical RCE

#87
post #55

The opex and security fine costs of moving off managed services like GitHub/GitLab are catching up.

Wouldn't most users considering or using Forgejo also have considered (or used) self-hosted Gitlab which would have the same opex / security costs (and much higher hardware requirements)?

I alluded to business needs, not homelabs. Even-so, GitLab has a helmchart while Forgejo doesn't and is seemingly more secure so idk.
Post reply on HN