Earlier quoted context omitted.
I'm no fan of Jira or Confluence but you'll get forgotten wiki articles, for example, no matter what tech you choose. Confluence? Forgotten Git repos? Forgotten Notion? New hotness, still forgotten Google Docs / Office 365 ? Forgotten This is just a difficult problem to solve, especially for organisations growing at speed.
> Git repos? One of these things is not like the other, and anybody who uses a real editor and VCS but still has to deal with confluence or the rest of the above knows it. Child poster below going on about markdown etc is absolutely wrong.
US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
291–300 of 344 posts
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#292Earlier quoted context omitted.
Coming from ClearQuest, Jira was a breathe of fresh air some years ago. We can run projects with several hundred to thousand people with it (the on prem version) without problems and UX is ok IMHO. Maybe it's easy to screw up the config?
It's slow, but so long as you don't do anything “out of the ordinary” (i.e. try to act like the average sort of person who would use Jira), it's decent enough to use. I've personally had no workflow issues, though I could tell there was something deeply wrong with the internals. Then again, if you're only using the “ordinary” features, Jira doesn't have much advantage over any other bug tracker; Gitea can integrate w…
Ohhh found the non power Jira user! Gitea is good enough for your org. Without knowing your requirements this is pretty much a blanket statement. Gitea is nowhere near good enough for a large engineering org.
Example: groovy integration with Jira allows an enterprise to build their own custom workflows. Like integrating with your Vcs to enforce funded work (requiring an open Jira issue in git commits). Features like this, until recently, left them in a league of their own. GitHub Actions has leveled that playing field. Gitlab and gitea can fight it out with bugzilla, but you won’t find them in most engineering orgs.
Another example: building out complex dev roadmaps ahead of time with constraints and relationships. Bridging the gap between dev, product, and project management
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#293Earlier quoted context omitted.
> It’s amazing that this company continues to fall up. There are still not any knowledge base tools that can keep up with Confluence. For Jira the competition is slowly catching up but there are still a large gap for big organizations. That's why they are still here, their product is still superior to the competition. Atlassian get a lot of criticism, that's not always justified
I suspect that a lot of Atlassian's criticism is a reflection of their dominant market position. Outside of smartphones and video game consoles, people generally don't spend much time complaining about products they don't use. For my part, I've spent enough time using both Atlassian products and competitors to find something to hate in all of them. Familiarity breeds contempt.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#294Earlier quoted context omitted.
It's slow, but so long as you don't do anything “out of the ordinary” (i.e. try to act like the average sort of person who would use Jira), it's decent enough to use. I've personally had no workflow issues, though I could tell there was something deeply wrong with the internals. Then again, if you're only using the “ordinary” features, Jira doesn't have much advantage over any other bug tracker; Gitea can integrate w…
> Jira doesn't have much advantage over any other bug tracker Ohhh found the non power Jira user! Gitea is good enough for your org . Without knowing your requirements this is pretty much a blanket statement. Gitea is nowhere near good enough for a large engineering org. Example: groovy integration with Jira allows an enterprise to build their own custom workflows. Like integrating with your Vcs to enforce funded wor…
> but you won’t find them in any worthwile engineering org.
sure.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#295Earlier quoted context omitted.
> Jira doesn't have much advantage over any other bug tracker Ohhh found the non power Jira user! Gitea is good enough for your org . Without knowing your requirements this is pretty much a blanket statement. Gitea is nowhere near good enough for a large engineering org. Example: groovy integration with Jira allows an enterprise to build their own custom workflows. Like integrating with your Vcs to enforce funded wor…
> Not trying to dig on your usage of issue tracking > but you won’t find them in any worthwile engineering org. sure.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#296The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…
If you are serious about the tunnel between the houses can you provide any info or a link for my bubble folder? I’d love to read about that. Googling was not fruitful.
[0] https://www.realestate.com.au/news/the-list-australias-top-t...
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#297Earlier quoted context omitted.
You are missing the point entirely. Any sufficiently complicated product will eventually have major CVEs, as you say. Anyone having hosted Atlassians product know that these products are nothing but garbage fires on the inside, as the commenter above said. Both of these statements are true and not mutually exclusive in any way.
> these products are nothing but garbage fires Would you care to give us alternatives, for example, to the JIRA bug tracker (which I used a lot, slowly :-))
Paper.
An Excel spreadsheet shared on a Windows for Workgroups share drive.
Carrier pigeon.
Quitting software to become a llama herder.
Seriously, though, after over two decades of using different tracking systems I think that the real alternative to stuff like Jira is to not go there. You may think that you need all those bells and whistles, but you really don't. What you actually need is the simplest possible issue tracking system you can get away with. All you really need is a prioritised list of issues, and a list of who is working on which issues now. ‘Kanban’ boards get pretty close.
Minimalism is power.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#298My employer was bit by this on Wednesday. Thankfully we had Crowdstrike on it which blocked any real damage. But it definitely moved our cloud migration from “later this year” to “later this month”. Also, not having confluence for a day exposed just how reliant we were on it for day-to-day activities.
Security is planning to implement here CrowdStrike in the near future... does it run on every single server?
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#299Earlier quoted context omitted.
> these products are nothing but garbage fires Would you care to give us alternatives, for example, to the JIRA bug tracker (which I used a lot, slowly :-))
Is TFS no longer considered a competitor? Feels like it should have been the first mentioned here. Not saying TFS is problem-free, of course.
Re: US Cybercom says mass exploitation of Atlassian Confluence vulnerability ongoing
#300The good thing about the fact that Atlassian offers both on-prem and cloud versions of their offerings is, everyone is now aware of the awful engineering practices that underpin their products. We have to assume that there are problems of a similar nature in their cloud service, which is way more of a problem considering the number of orgs that depend on the JIRA SaaS offering. Maybe the founders could have used some…