ubergeek77's Lemmy
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
cm0002@digipres.cafe to Opensource@programming.dev · 1 个月前

Android syncthing repo gone and Developer profile gone private.

github.com

external-link
message-square
12
fedilink
  • cross-posted to:
  • [email protected]
96
external-link

Android syncthing repo gone and Developer profile gone private.

github.com

cm0002@digipres.cafe to Opensource@programming.dev · 1 个月前
message-square
12
fedilink
  • cross-posted to:
  • [email protected]
Catfriend1 - Overview
github.com
external-link
GitHub is where Catfriend1 builds software.
alert-triangle
You must log in or # to comment.
  • somewa@suppo.fi
    link
    fedilink
    arrow-up
    23
    ·
    1 个月前

    Any ideas why this happened?

    • whoever loves Digit 🇵🇸🇺🇸🏴‍☠️@piefed.social
      link
      fedilink
      English
      arrow-up
      6
      arrow-down
      2
      ·
      1 个月前

      Coding is “illegal” now, remember?

      • somewa@suppo.fi
        link
        fedilink
        arrow-up
        20
        ·
        1 个月前

        A lot of guesses point to a repository reset: https://forum.syncthing.net/t/does-anyone-know-why-syncthing-fork-is-no-longer-available-on-github/25661

        • Kissaki@programming.dev
          link
          fedilink
          English
          arrow-up
          7
          ·
          1 个月前

          Looks like it’s just random commenters taking random guesses because those have happened before.

          What is a “repository reset”? One commenter writes:

          There was a temporary similar “outage” back in July with rewritten history, apparently something inappropriate was recorded in the repo history they wanted cleaned out. The repo came back after that. I have no idea if this is the same thing, or if they just got tired of maintaining it.

          Seems strange to me. You can prep locally and then force-push. I don’t see why rewriting history would require taking the repository down.

          • somewa@suppo.fi
            link
            fedilink
            arrow-up
            4
            ·
            1 个月前

            If he pushed something he shouldn’t have online then taking it offline immediately makes a lot of sense.

            • orygin@piefed.social
              link
              fedilink
              English
              arrow-up
              6
              ·
              edit-2
              1 个月前

              It makes sense, but once it’s pushed there is no way to know if it’s been cloned or kept somewhere else. The only real mitigation is to rotate the keys or password that was leaked.
              If it’s something else you can’t rotate, you’re screwed.

              • onlinepersona@programming.dev
                link
                fedilink
                arrow-up
                5
                ·
                1 个月前

                https://trufflesecurity.com/blog/anyone-can-access-deleted-and-private-repo-data-github

                • somewa@suppo.fi
                  link
                  fedilink
                  arrow-up
                  2
                  ·
                  edit-2
                  1 个月前

                  The point wasn’t that it’s not accessible but limiting the damage while you still can.

          • orygin@piefed.social
            link
            fedilink
            English
            arrow-up
            4
            ·
            1 个月前

            Plus won’t the forks on GitHub keep the history before the “reset”?
            Afaik, forks on GitHub are basically the same underlying repository, just a branch associated with another user. They won’t be able to really purge anything from these other branches.
            Plus anyone who has a local copy of the repo or an automatic mirror somewhere else, will have the changes available.

            • Kissaki@programming.dev
              link
              fedilink
              English
              arrow-up
              1
              ·
              1 个月前

              Yes, forks remain as they are. Yes, the fork network has a shared data repository on GitHub.

              Consequently, rewritten history will break history compatibility, possibly requiring manual fixups on forks or work based on it.

        • whoever loves Digit 🇵🇸🇺🇸🏴‍☠️@piefed.social
          link
          fedilink
          English
          arrow-up
          1
          ·
          1 个月前

          Oh.

  • Wistful@discuss.tchncs.de
    link
    fedilink
    arrow-up
    15
    ·
    1 个月前

    Oh shit. What do now.

Opensource@programming.dev

opensource@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

A community for discussion about open source software! Ask questions, share knowledge, share news, or post interesting stuff related to it!

Credits

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

⠀


Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 14 users / day
  • 580 users / week
  • 2.18K users / month
  • 5.45K users / 6 months
  • 1 local subscriber
  • 4.59K subscribers
  • 1.14K Posts
  • 4.19K Comments
  • Modlog
  • mods:
  • Pierre-Yves Lapersonne@programming.dev
  • BE: 0.19.7
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org