this post was submitted on 29 Apr 2026
70 points (90.7% liked)

Selfhosted

60970 readers
748 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

Detailed Rules Post

  1. Be civil.

  2. No spam.

  3. Posts are to be related to self-hosting.

  4. Don't duplicate the full text of your blog or readme if you're providing a link.

  5. Submission headline should match the article title.

  6. No trolling.

  7. Promotion posts require active participation, with an account that is at least 30 days old. F/LOSS without a paywall has exceptions, with requirements. See the rules link for details. Tags [CBH] or [AIP] are required, see the links in Rule 8 for details.

  8. AI-related discussions and AI-involved promotional posts have additional requirements for tagging, as noted in Rule 7 and the AI & Promotional Post Expanded Rules post, and find example disclosures here.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 3 years ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
[–] non_burglar@lemmy.world -1 points 2 months ago* (last edited 2 months ago) (2 children)

I understand what you're saying, but Forgejo has an outdated and made-up-from-thin-air policy. From their security.md:

  • You MUST disclose vulns to the author (why are we dictating instead of inviting participation)
  • emails about vulns MUST be encrypted (I don't even understand this one, this gives really strong "we don't know how email works" vibes)

And it just goes on, like someone from 2003 wrote that policy.

Now, I'm going to agree with you that it's a bit of a dick move to do the carrot dangle thing, but some vendors/devs just don't respond without the pressure. And forgejo has been forced by github supporters to implement a security policy after trying to ignore it.

It seems that the author has some ongoing interactions with forgejo, and it would be great if these were disclosed in the article, but forgejo seems to need a kick in the pants, especially over an RCE, the forbidden sev 10 of vulns.

[–] AbidanYre@lemmy.world 2 points 2 months ago

emails about vulns MUST be encrypted (I don't even understand this one, this gives really strong "we don't know how email works" vibes)

PGP/GPG has existed for decades as a way to encrypt email.

[–] warm@kbin.earth 2 points 2 months ago

If you replaced Forgejo with GitHub then I would understand, but Forgejo isn't a massive organization with hundreds of hired employees, it's run by people in their spare time with the option of donations.

Anyone can help contribute, instead of doing that, this guy decided to try and get some clout by being an asshole because he is butthurt about some other interaction. If this guy went about it the proper way and then still got no answer or fix after months, then I would understand more, but he didn't.