Discussion
Loading...

Post

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social  ·  activity timestamp 5 days ago

I'm putting together a list of big and small issues that makes us (the curl project) considering switching away from GitHub for security reporting/advisories again:

https://gist.github.com/bagder/ed3268e8745452a53a999d23b7fa1273

*considering* being the operative word, nothing has been decided and I think it's fair to give it some more time first. And some communication to see what can be done, fixed or adjusted.

To be continued.

  • Copy link
  • Flag this post
  • Block
Thibault
Thibault
@thibault@mastodon.online replied  ·  activity timestamp 5 days ago

@bagder Only tangentially related, but are you stil mirroring curl to Codeberg ? Any plans for a migration in case Microsoft decides to double-double-double down on AI-everywhere-as-a-feature ?

  • Copy link
  • Flag this comment
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social replied  ·  activity timestamp 5 days ago

@thibault Yeps, the codeberg mirror is kept in sync: https://codeberg.org/curl/curl-mirror/

Codeberg.org

curl-mirror

A command line tool and library for transferring data with URL syntax, supporting DICT, FILE, FTP, FTPS, GOPHER, GOPHERS, HTTP, HTTPS, IMAP, IMAPS, LDAP, LDAPS, MQTT, POP3, POP3S, RTMP, RTMPS, RTSP, SCP, SFTP, SMB, SMBS, SMTP, SMTPS, TELNET, TFTP, WS and WSS. libcurl offers a myriad of powerful f...
  • Copy link
  • Flag this comment
  • Block
drakeerv
drakeerv
@drakeerv@mastodon.social replied  ·  activity timestamp 5 days ago

@bagder @Codeberg is calling lol

  • Copy link
  • Flag this comment
  • Block
Dźwiedziu
Dźwiedziu
@dzwiedziu@mastodon.social replied  ·  activity timestamp 5 days ago

@bagder
I'm at best a “security aware person”, and yet it seems that half of those are valid reasons to be knee-deep in hell^Wmigration plans.

  • Copy link
  • Flag this comment
  • Block
Dan Brown
Dan Brown
@danb@fosstodon.org replied  ·  activity timestamp 5 days ago

@bagder Related to this, I really wish for a platform, abstract from code hosting solution, which provides a place for open source projects to manage security reports and CVEs, that's not "gamified" for reporters.

I've been moving away from GitHub, but reporting via the Mitre form is slow and cumbersome. I've been searching for something better but not found anything yet!

  • Copy link
  • Flag this comment
  • Block
daniel:// stenberg://
daniel:// stenberg://
@bagder@mastodon.social replied  ·  activity timestamp 5 days ago

@danb maybe one problem is that we all want slightly different things even when we are open source...

  • Copy link
  • Flag this comment
  • Block
Poolitzer
Poolitzer
@poolitzer@mastodon.social replied  ·  activity timestamp 5 days ago

@bagder @danb but I mean how hard can it really be to build a platform customizable for those wishes... xD

  • Copy link
  • Flag this comment
  • Block
Poul-Henning Kamp
Poul-Henning Kamp
@bsdphk@fosstodon.org replied  ·  activity timestamp 5 days ago

@bagder

Reason number N: I bet it will break a lot of github automation :-)

  • Copy link
  • Flag this comment
  • Block
echarlie
echarlie
@notecharlie@social.bigcavemaps.com replied  ·  activity timestamp 5 days ago

@bagder Another reason to add: lack of #IPv6 support.

  • Copy link
  • Flag this comment
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About · Code of conduct · Privacy · Users · Instances
Bonfire social · 1.0.2-alpha.7 no JS en
Automatic federation enabled
Log in
  • Explore
  • About
  • Members
  • Code of Conduct