#gitea
20 posts · Last used 9d
Boosted by @fedicat@pc.cafe
Replying to
This has been enabled again, please serve this as a reminder to migrate to Codeberg Pages v3!
Documentation: https://docs.codeberg.org/codeberg-pages/migrating-from-pages-v2/
For help & support, make a issue at https://codeberg.org/Codeberg/Community/ or join https://matrix.to/#/#gitea-pages-server:matrix.org
Disposem d'una instància de codig amb més de 70 miralls de projectes per a l'experimentació audiovisual. Si algun dia Microsoft decideix restringir l'accés a uns certs repositoris al seu github aqui podras obtenir l'ultima versió abans de la restricció ☺️
#gitea#mirallejant
https://wiki.terata.org/index.php?title=Gitea
Hackers now exploit critical #Gitea flaw in code injection attacks
https://www.bleepingcomputer.com/news/security/hackers-now-exploit-critical-gitea-flaw-in-code-injection-attacks/
#cybersecurity #FOSS
Remember when I said my DR setup should have me back up in 20-30 minutes? Yeah. About that. Turns out a backup job can run clean every single night for months and still not actually be backing up what you think it is. So here's what I actually found out the hard way replacing nixos2's dying hardware. Feel free to cue the old "The more you know" clip.
https://blog.ppb1701.com/best-laid-plans-replacing-nixos2s-failing-hardware-part-19-of-building-a-resilient-home-server-serie
#blog #homeserver #nixos #disasterrecovery #selfhosting #gitea #tailscale
Critical Gitea RCE CVE-2026-60004: Update to 1.27.1
🔗 https://cybersecurefox.com/en/gitea-cve-2026-60004-critical-rce-vulnerability
#gitea #cve-2026-60004 #rce #git #hooks #diffpatch
Why is .config/ in git repositories not a thing? As an XDG_CONFIG equivalent to move .vscode, .zed, .forgejo away from the repository root, that would be pretty nice.
#git #forgejo #gitea #vscode #zededitor
Replying to
@Codeberg@social.anoxinon.de I did look at some of the initiators/sponsors of the original proposal and did find one of apparent more important maintainers of @forgejo@floss.social and formerly Gitea until it turned "commercial".
I wonder if this will lead to yet another fork of what started out as Gogs some probably 10 years ago now. Vibegeo? Vibeforge? Vibedistrict?
(Thanks the original author of Gogs back when btw. I was already pretty amazing back when!)
Certainly I will refrain from trying to propose (with PRs) a set of extensions to the issue system as said extensions and their raison d'etre have the evil taint of the LLM and hence certainly wouldn't be accepted. 🤷
#gogs #gitea #forgejo
Replying to
From a 100 repos to only 20 left on #GitHub for now. I shall continue the purge tomorrow.
I was able to add a #Gitea runner with Docker. So now my several #Hugo repositories are already building in Gitea as I push changed, just like they did before on GitHub Actions (also using a shared workflow now).
Feels good.
Gitea <1.27.0 CRITICAL vuln (CVE-2026-58443): Public-only write tokens can update private PR head branches, violating repo access controls. Patch pending — review token use & monitor vendor updates. https://radar.offseq.com/threat/gitea-public-only-repository-tokens-can-update-private-pr-head-branches-cve-2026-58443-d058444d84b9595a #OffSeq #Gitea #Vuln #CVE202658443
Gitea vulnerability CVE-2026-58443 (CVSS 9.6) lets public-only tokens write to private repos. Details and PoC code are public. Update to v1.27.0.
#Gitea #CVE202658443 #DevSecOps #PoC #InfoSec
https://securityonline.info/gitea-vulnerability/?utm_source=mastodon&utm_medium=jetpack_social
Ein Header genügt: Wie Gitea und Forgejo jedem Fremden die Admin-Rechte schenkten
Ein gefälschter HTTP-Header genügte monatelang, um sich in Gitea und Forgejo zum Admin zu machen, ganz ohne Passwort. CVE-2026-20896 hat einen CVSS-Wert von 9.8. Gitea ist seit dem 21. Juni gepatcht, Forgejo hängt weiter in der Luft. Was du an deiner Konfiguration sofort prüfen musst.
https://www.chrislo.de/blog/2026-07-14-20-42-24-ein-header-genuegt-wie-gitea-und-forgejo-jedem-fremden-die-admin-rechte-schenkten/
#chrislo #ITSicherheit #ServerInfrastruktur #Gitea #Forgejo #Docker #SelfHosting #CVE #ReverseProxy #OpenSource #Codeberg
本來覺得要從 Gitea 遷移到 Fogejo 的阻力好大(其實只是懶)。
後來無聊查一下,Fogejo 竟然打算要支援 ActivityPub,於是我還是打起精神把實例架起來,慢慢遷移過去!
#gitea #fogejo #activitypub
Critical Gitea Docker Flaw Enables Admin Account Hijack
🔗 https://cybersecurefox.com/en/gitea-docker-cve-2026-20896-admin-account-takeover
#gitea #docker #cve-2026-20896 #reverse #proxy #x-webauth-user
Critical #Gitea #Docker Bug Under Active Exploitation Exposes Repositories and Secrets
https://securityaffairs.com/194902/hacking/critical-gitea-docker-bug-under-active-exploitation-exposes-repositories-and-secrets.html
#securityaffairs #hacking
🤖 CVE-2026-20896 (CVSS 9.8): Critical Gitea Docker flaw — X-WEBAUTH-USER header trusted from any source IP, allowing unauthenticated RCE. Sysdig reports active exploitation attempts 13 days after disclosure.
🔗 https://thehackernews.com/2026/07/threat-actors-probe-gitea-docker-flaw.html
#CVE #Gitea #CyberSec
If you are looking for a self-hosted alternative to GitHub, check out Gitea or Forgejo.
https://about.gitea.com/
https://forgejo.org/
#gitHub #gitea #forgejo #selfHost
In a dick move, I migrated to my new laptop and hadn't pushed my helm charts to #gitea
Thankfully via #warp.dev and #gpt5 i was able to rebuild my #helm charts which are now up on gitea and accessible by helm.
Tomorrow my intent is to get #argocd installed and see how this #cicd pipeline works
#daveknowstech #selfhosted #homelab
I feel somewhat bare, backups have been made, core services moved to a single #proxmox next stage is to re-purpose the proxmox cluster ready to deploy kubernetes via #rancher on the nodes
Then, with the help of #ai setup help charts for my apps and figure out how to use #gitea to host them and pipeline for updates
Love a bank holiday weekend tech project
#daveknowstech #selfhosted #homelab
Boosted by @kkarhan@jorts.horse
The #gitea developers concluded after 10 years that it is not able to host its own development and that they depend on #GitHub.
https://github.com/go-gitea/gitea/issues/1029#issuecomment-4269181192
At the same time, the community fork @forgejo@floss.social is self-hosted for a long time and is also powering the popular @Codeberg@social.anoxinon.de and at least 8 other public instances. So this seem to be a good time to migrate if you haven't already.
https://forgejo.org


