schmonz.com is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
So, #GitHub is having a rough go of it lately. With significant instability and frequent outages in the last month and platform uptime dropping below 85%.
But the most fun trick? Any authenticated user could execute arbitrary commands on GitHub's backend servers with a single git push command - using nothing but a standard git client. (Because their architecture didn’t sterilize semicolons, thus prompt injection.)
On GitHub Enterprise Server, the vulnerability grants full server compromise, including access to all hosted repositories and internal secrets.
GitHub Enterprise Server customers should upgrade ASAP. Wiz dot io data indicates that 88% of instances were still vulnerable.
https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854
Since I was visiting the 'daemontools' account on #GitHub, I took a look at what the people who mistakenly thought that it was someone actually involved, have done.
Not much, fortunately.
One wheel reinvention that didn't even look at Bruce Guenter's daemontools-encore.
Only one thing worth following up on, in 13 years:
https://github.com/daemontools/daemontools/issues/8
The bugfix will be in #djbwares version 13 when it comes out. As noted, neither @ska's nor my #nosh reimplementations have this bug.
For the record, and since we are on the subject of supply-chain attacks:
The person behind the 'daemontools' account on GitHub is unidentifiable, and certainly isn't Daniel J. Bernstein, me, @ska, Bruce Guenter, or anyone else well-known in the #daemontools world.
The account has been inactive since 2013. If that account suddenly wakes up, it's not unreasonable to suspect that it has been compromised/become malicious.
(M. Guenter is bruceg on #GitHub and is active there to this week.)
With so many posts popping up about “leaving GitHub” or discussing how poor the experience overall is with that platform, I will share my old post again on moving over to SourceHut :)
“Git Your Freedom Back: A Beginner’s Guide to SourceHut”
The irony of megabytes of JavaScript force-fed to users in the name of “Nobody wants full page reloads!!!” and then exactly that full page reload being necessary to make the app work properly. FFS… 😣 #Github
Today in “Fun with Github UI inconsistencies”:
– Create a new milestone
– Follow the “Back to milestones” link
– New milestone is missing
– Refresh page
– The new milestone shows up
Does anyone even test this stuff? 😔 #Github
#Gitlab is known to be quite resource hungry.
Perhaps you can have a look at #forgejo which is implemented in #Golang, and the #UX is very similar to #Github's.
And #Codeberg is hosted on forgejo, and maintain a downstream fork, optimized for high-scale use, which is also open source.
Some large projects have migrated from GH and GL before, and created migration reports, etc. The other day I was asking if there's a list of those, I am not sure there is.
I'm 100% out of ideas. Our servers cannot handle the load the AI/LLM web scraping bots place on #GitLab. #Radicle is turning out to still not be ready for prime-time. I refuse to use #GitHub beyond being a read-only mirror.
Self-hosting our code repos is an absolute requirement in order to provide higher levels of OPSEC than what third-party hosted services can provide.
So, at the hands of our oligarchic overlords, is this the death of HardenedBSD?
Someone please provide me ideas. I have no idea what to try next and I'm desperate.
editi[0]: This is solved! I changed my approach and now everything's happy--and so am I! :-)