Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Jens Finkhäuser
Jens Finkhäuser
@jens@social.finkhaeuser.de  ·  activity timestamp 3 hours ago

@andrewnez Consider that gitea contains package registries, and forgejo is the FLOSS fork. It's perfectly possible to build a bunch of these things with a self-hosted forgejo instance.

Which really means that a bunch of things forgejo does should become de facto standards.

There are also things that can be standardized that help here. For example, there are a few competing solutions for platform/language independent package meta information, including dependencies.

Could focus on that, too.

  • Copy link
  • Flag this post
  • Block
slampoud
slampoud
@slampoud@mastodon.cloud replied  ·  activity timestamp 2 hours ago

@andrewnez I was having a conversation with a friend in security the other day who was recalling how, when the CVE fiasco happened recently, everyone noticed EU had what seemed like an alternative they could maybe turn to, but upon closer inspection it was essentially a mirror. we need to do decentralization better, alongside sovereignty, for humanity’s sake

  • Copy link
  • Flag this comment
  • Block
mossman
mossman
@mossman@social.vivaldi.net replied  ·  activity timestamp 2 hours ago

@andrewnez listened to an interesting point on a podcast by Everything Electric this morning. To paraphrase: "96% of the world is *NOT* living in the USA, so can we all please just stop talking about their news and get on with our own lives again?"

  • Copy link
  • Flag this comment
  • Block
IzzyOnDroid ✅
IzzyOnDroid ✅
@IzzyOnDroid@floss.social replied  ·  activity timestamp 3 hours ago

@andrewnez for forges, you might wish to add @Codeberg (Germany, EU). Not sure where Sourcehut sits (is it NL, @sir ?)

So there ARE alternatives. And as already pointed out in another comment by @jens , Forgejo/Gitea can be self-hosted as well. And at least for Forgejo, Federation is upcoming IIRC, to take another hurdle (separate registrations) from self-hosted installs.

But yeah, that list reads horrible, re "sovereignty" 😢

  • Copy link
  • Flag this comment
  • Block
Andrew Nesbitt
Andrew Nesbitt
@andrewnez@mastodon.social replied  ·  activity timestamp 2 hours ago

@IzzyOnDroid codeberg/forgejo/srht don’t have the dependency graph security features that the others have that I was talking about

  • Copy link
  • Flag this comment
  • Block
Jens Finkhäuser
Jens Finkhäuser
@jens@social.finkhaeuser.de replied  ·  activity timestamp 3 hours ago

@andrewnez Consider that gitea contains package registries, and forgejo is the FLOSS fork. It's perfectly possible to build a bunch of these things with a self-hosted forgejo instance.

Which really means that a bunch of things forgejo does should become de facto standards.

There are also things that can be standardized that help here. For example, there are a few competing solutions for platform/language independent package meta information, including dependencies.

Could focus on that, too.

  • Copy link
  • Flag this comment
  • Block
Andrew Nesbitt
Andrew Nesbitt
@andrewnez@mastodon.social replied  ·  activity timestamp 3 hours ago

@jens I’ve been working on that

2 media
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
Sorry, no caption provided by author
  • Copy link
  • Flag this comment
  • Block
Benjamin Geer
Benjamin Geer
@benjamingeer@piaille.fr replied  ·  activity timestamp 4 hours ago

@andrewnez @gvwilson What about the Linux package repositories? Canonical, at least, is UK-based if I’m not mistaken, with subsidiaries in several countries.

  • Copy link
  • Flag this comment
  • Block
Andrew Nesbitt
Andrew Nesbitt
@andrewnez@mastodon.social replied  ·  activity timestamp 4 hours ago

@benjamingeer the Linux distros are much more friendly to being mirrored and standing your own up than many of the language package managers

  • Copy link
  • Flag this comment
  • Block
Marcus Rohrmoser 🌻
Marcus Rohrmoser 🌻
@mro@digitalcourage.social replied  ·  activity timestamp 3 hours ago

@andrewnez @benjamingeer
I am bit bugged as there seem to be no mirrors for e.g. security.ubuntu.com

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.7 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct