Lemmy.one
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
cm0002@digipres.cafe to Opensource@programming.dev · 3 days ago

Android syncthing repo gone and Developer profile gone private.

github.com

external-link
message-square
11
fedilink
  • cross-posted to:
  • opensource@lemmy.ml
94
external-link

Android syncthing repo gone and Developer profile gone private.

github.com

cm0002@digipres.cafe to Opensource@programming.dev · 3 days ago
message-square
11
fedilink
  • cross-posted to:
  • opensource@lemmy.ml
Catfriend1 - Overview
github.com
external-link
GitHub is where Catfriend1 builds software.
  • somewa@suppo.fi
    link
    fedilink
    arrow-up
    20
    ·
    3 days ago

    A lot of guesses point to a repository reset: https://forum.syncthing.net/t/does-anyone-know-why-syncthing-fork-is-no-longer-available-on-github/25661

    • Kissaki@programming.dev
      link
      fedilink
      English
      arrow-up
      7
      ·
      2 days ago

      Looks like it’s just random commenters taking random guesses because those have happened before.

      What is a “repository reset”? One commenter writes:

      There was a temporary similar “outage” back in July with rewritten history, apparently something inappropriate was recorded in the repo history they wanted cleaned out. The repo came back after that. I have no idea if this is the same thing, or if they just got tired of maintaining it.

      Seems strange to me. You can prep locally and then force-push. I don’t see why rewriting history would require taking the repository down.

      • orygin@piefed.social
        link
        fedilink
        English
        arrow-up
        4
        ·
        2 days ago

        Plus won’t the forks on GitHub keep the history before the “reset”?
        Afaik, forks on GitHub are basically the same underlying repository, just a branch associated with another user. They won’t be able to really purge anything from these other branches.
        Plus anyone who has a local copy of the repo or an automatic mirror somewhere else, will have the changes available.

      • somewa@suppo.fi
        link
        fedilink
        arrow-up
        4
        ·
        2 days ago

        If he pushed something he shouldn’t have online then taking it offline immediately makes a lot of sense.

        • orygin@piefed.social
          link
          fedilink
          English
          arrow-up
          6
          ·
          edit-2
          2 days ago

          It makes sense, but once it’s pushed there is no way to know if it’s been cloned or kept somewhere else. The only real mitigation is to rotate the keys or password that was leaked.
          If it’s something else you can’t rotate, you’re screwed.

          • onlinepersona@programming.dev
            link
            fedilink
            arrow-up
            5
            ·
            2 days ago

            https://trufflesecurity.com/blog/anyone-can-access-deleted-and-private-repo-data-github

            • somewa@suppo.fi
              link
              fedilink
              arrow-up
              2
              ·
              edit-2
              2 days ago

              The point wasn’t that it’s not accessible but limiting the damage while you still can.

    • whoever loves Digit@piefed.social
      link
      fedilink
      English
      arrow-up
      1
      ·
      3 days ago

      Oh.

Opensource@programming.dev

opensource@programming.dev

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !opensource@programming.dev

A community for discussion about open source software! Ask questions, share knowledge, share news, or post interesting stuff related to it!

Credits

Icon base by Lorc under CC BY 3.0 with modifications to add a gradient

⠀


Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 182 users / day
  • 608 users / week
  • 2.42K users / month
  • 4.97K users / 6 months
  • 9 local subscribers
  • 4.33K subscribers
  • 1.11K Posts
  • 4.02K Comments
  • Modlog
  • mods:
  • Pierre-Yves Lapersonne@programming.dev
  • BE: 0.19.7
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org