#gogs

𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕kubikpixel@chaos.social
2025-12-12

»Self-hosted Git — Jeder zweite Gogs-Server im Netz ist wohl kompromittiert:
Auch in Deutschland dürften einige Gogs-Instanzen betroffen sein. Angreifer können über eine bisher ungepatchte Lücke Schadcode einschleusen.«

Diesbezüglich gibt es einige Open-Source Git-Hoster Alternativen, welche könnt ihr empfehlen oder gleich Git auf Server rudimentär ohne GUI einrichten?

🧑‍💻 golem.de/news/self-hosted-git-

#git #gogs #selfhosting #opensource #it #github #selfhostedgit #itsicherheit #web #itsec

2025-12-12

Gogs bị phát hiện lỗ hổng RCE Zero-Day (CVE-2025-8110) đang bị khai thác. Wiz Blog cảnh báo nguy cơ an ninh nghiêm trọng. #CVE20258110 #CyberSecurity #LỗHổngZeroDay #Gogs #AnNinhMạng

reddit.com/r/programming/comme

:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉nemo@mas.to
2025-12-12

Alarming: Jeder zweite self-hosted Gogs-Server im Netz ist kompromittiert! 🔒💥 Forscher entdecken schwere Sicherheitslücken in der Git-Software. Zeit für Updates oder Alternativen wie Gitea?

golem.de/news/self-hosted-git-

#Cybersecurity #Gogs #GitServer #InfoSec #Newz

John M. Gamblejgamble@fosstodon.org
2025-12-11

Sites built with Gogs (for self-hosting) are getting clobbered at the moment.

#Git #Gogs #CVE

theregister.com/2025/12/10/gog

Le site de Korbenkorben.info@web.brid.gy
2025-12-11
<p>En 2016, je vous parlais de
<a href="https://korben.info/serveur-git-interface-web-gogs.html">Gogs</a>
, ce petit serveur Git auto-hébergé super léger qui s&rsquo;installe en 10 secondes et c&rsquo;est encore aujourd&rsquo;hui une alternative sympa à GitHub pour ceux qui voulaient garder leur code chez eux. Mais attention, si vous l&rsquo;utilisez, il va falloir agir vite parce que là, c&rsquo;est la catastrophe.</p>
<p>Des chercheurs de Wiz viennent de découvrir que plus de <strong>700 instances Gogs exposées sur Internet</strong> ont été compromises via une faille zero-day baptisée <strong>CVE-2025-8110</strong>. Et le pire, c&rsquo;est que cette faille est activement exploitée depuis juillet 2025 et qu&rsquo;il n&rsquo;existe toujours pas de patch.</p>
<p>L&rsquo;attaque est vicieuse car un attaquant n&rsquo;a besoin que d&rsquo;un compte utilisateur standard pour compromettre votre serveur. Il crée un dépôt, y ajoute un lien symbolique pointant vers un fichier sensible, puis utilise l&rsquo;API PutContents pour écrire à travers ce lien et modifier le fichier <code>.git/config</code>. Ensuite, en bidouillant la directive sshCommand, il peut alors exécuter n&rsquo;importe quelle commande sur votre serveur. Voilà, c&rsquo;est plié !</p>
<p>Cette faille est en fait un contournement d&rsquo;un ancien correctif (CVE-2024-55947). Les développeurs avaient patché le problème mais avaient oublié de gérer le cas des liens symboliques. Et ce n&rsquo;est même pas la première fois q
Ukiah Danger SmithUkiahSmith
2025-10-25

You should be aware of this bug If you have a instance that started out as and you want to upgrade to

codeberg.org/forgejo/forgejo/i

2025-10-20

@luyapapi @LePertti I sync all my laptop/phone/tablet stuff with #nextcloud. It comes with many daily helpers too. Photos with #immich, share them and videos to TV with #jellyfin. Ad block and vpn with #opnsense. Version control at home with #gogs. Home automation with #HomeAssistant...

2025-06-12

I can see tons of #forgejo, #gitea or #gogs #selfhosted git servers out there in the wild. Which is cool. But I don’t see nearly as much about #softserve by the #charmbracelet peeps: github.com/charmbracelet/soft- If you are after something small, and TUI is all you need, don’t miss out on this one! You can check the “demo mode” via `ssh git.charm.sh`. You’re welcome ☺️

Patch Notification Robot 🔔Patchbot_de
2025-06-09

Gogs Authors released version 0.13.3. gogs.io/

Я не зміг знайти можливість пошуку по своєму мастодон-блогу. Чи погано шукав.

#gogs #git

2025-03-31

From last week's ADMIN Update newsletter: Thomas Reuß shows you how to migrate your Git repositories to Gitea
admin-magazine.com/Archive/202
#Gitea #GitHub #repository #VersionControl #Gogs #fork

Listing 1: Classic Migration command line
2025-03-18

@DG1JAN Das ist ja eine gute Frage. Anscheinend ist Codeberg der einzige solche Dienst, den ich auch finden konnte. In der Vergangenheit habe ich #Gogs selbst gehostet und überlege, ob ich das wieder tun soll.

github.com/gogs/gogs

2025-02-15

@Dokza @Blort I don't know how #forgejo compares to #gogs, but the latter was very easy to set up. The UI is a perfect mimic of GitHub. #selfhosting

2025-02-03

@simonmic It took 10y to get my friends off of #whatsapp and most are probably not keen on installing yet another messenger. But #simplex surely looks very intriguing.

Same with #radicle now that they've nailed the protocols. I've moved from #gogs / #gitea / #forgejo to plain ssh 2y ago, maintenance had become too much of a burden. It's been great for me but unsurprisingly collaboration has gone down to zero. Maybe this can provide some middle ground? Will definitely try it out this year

Cesare Forellicdf1982@iosdev.space
2025-01-28

I've been using #bitbucket for 10 years and I don't feel great about the 1 GB limit suddenly set to the sum of all repositories.

While I could just rely on my beloved #Gogs local git server, I would prefer to move to #Github, but the lack of transparency/commitment over AI training on private repositories on the free plans worries me (github.com/orgs/community/disc).

Any suggestions (beside paying, I know I know, but I'd rather not)? Just Gogs it is? toot.rainbow-100.com/objects/1

2025-01-21

i mirrored this "frustration project" to GitHub ... and realised i haven't been maintaining it (just using it)

github.com/g-pechorin/shugits/

#mercurial #forgejo #gitea #gogs #scala

🇵🇸🇱🇧🇻🇪🇰🇪🇳🇨(🧆🏳️)Popolon🐷ᠫᠣᠫᠣᠯᠣᠨ🐎抱抱龙🐉بوبولون🤖🦧Popolon@snac2.popolon.org
2025-01-08
I also installed several private instances of #Forgejo, including one for my own needs, looks promising, but at current time, their runner (needed for CI/CD), that I still need to setup, is marked as "alpha release, should not be considered secure enough to deploy in production". For information and found some other interesting related documentation, Forgejo is a fork by Codeberg.org of #Gitea that is itself a fork of #GOGS.

Already installed some #Gilab instances+runners, some Gitea/Forgejo servers without runners, need to learn its whole setup (runners+act+) and how to make test recipes, only tried some made by other ones on opensource project. Learnt and tested the basis of LXC deployment/management last week on #ArchLinux. Still few problems about IPv4 assignment in cross-architecture deployment (maybe a LXC-net bug?), IPv6 and lxc-attach for direct,local connexion to container works fine. #LXC would be far lighter than docker for tests.

LXC already has some #RISCV and #ARM pre-made templates image in default repository that works well in x86_64 server environment, that's probably not a big work to create and add new "templates". Forgejo can support LXC containers.

$ /usr/share/lxc/templates/lxc-download -l | grep riscv
alpine 3.20 riscv64 default 20250107_13:00
alpine 3.21 riscv64 default 20250107_13:00
alpine edge riscv64 default 20250107_13:03
debian trixie riscv64 default 20250108_05:24
ubuntu focal riscv64 default 20250108_09:58
ubuntu jammy riscv64 default 20250108_08:42
ubuntu noble riscv64 default 20250108_07:42
ubuntu oracular riscv64 default 20250108_08:18

2025-01-03

Seriously though if anyone out there has ever tried GOGs, please let me know how it compares to Forgejo and Gitea.

#gogs #forgejo #gitea #fosstodon

Client Info

Server: https://mastodon.social
Version: 2025.07
Repository: https://github.com/cyevgeniy/lmst