Post #1811506
2026-04-30 15:11 UTC
Replies (4)
-
@siv@mastodon.praxis.red 2026-04-30 15:36
@forgejo@floss.social please link the referenced blog post? Thanks!
-
@forgejo@floss.social 2026-04-30 15:11
We believe these findings can be addressed publicly. The security team will open issues where approaches to implement new defensive measurements will be discussed, we believe there's no single answer and as such appreciate the opinion of other Forgejo contributors on this matter. 2/2
-
@Ember@blobfox.coffee 2026-04-30 20:22
@forgejo@floss.social and all of this could have been avoided if they'd just contacted forgejo in the first place
-
@jzb@hachyderm.io 2026-05-14 13:08
@forgejo@floss.social Could you elaborate on what "internal server credentials" you're talking about? There is some speculation about whether that means a user account on a Forgejo instance or if it means (as I read it) "internal" credentials that are only available if a user has actual server access. But it's ambiguous, which is bad for folks who are trying to understand the actual security implications. A more detailed explanation would be great. Thanks!