If you haven’t patched your GitLab instance since the start of the year, it could be smart to so asap

https://arstechnica.com/security/2024/05/0-click-gitlab-hijacking-flaw-under-active-exploit-with-thousands-still-unpatched/

Reply to this note

Please Login to reply.

Discussion

Fuck git. Return to emailing tarballs.

Ed scripts. You know it.

Git over Nostr wen?

SSB has had it for years.

(Of course its slow and unreliable given SSB's architecture.)

I don't know ed scripts.

I quite like SVN. Github is basically SVN on top of git. It's retarded.

Git has nothing to do with this though. That’s like saying «fuck car wheels» after a car has crashed😂

Well, why is it so complicated that it enables exploitation of the supply chain?

It isn’t. This was just GitLab failing to implement a GitLab account recovery feature