Edit: I hate to remove comments and it may get me banned but due to the hate speech I’m receiving regarding things unrelated to software while trying to sympathize with a frustrated security researcher who got caught up in unnecessary bureaucracy when taken en masse, I’m going to remove these comments for now. This is why we volunteer FOSS engineers have to stay clear of popular projects I guess.
Edit: I hate to remove comments and it may get me banned but due to the hate speech I’m receiving regarding things unrelated to software while trying to sympathize with a frustrated security researcher who got caught up in unnecessary bureaucracy when taken en masse, I’m going to remove these comments for now. This is why we volunteer FOSS engineers have to stay clear of popular projects I guess.
Your comment said Forgejo has a disclosure process. The article says the author went with a carrot disclosure after reading the disclosure process and making a value judgement. Because your comment only mentioned Forgejo having a disclosure process, not an evaluation of the author’s evaluation of the disclosure process, it made you appear as if you had not read the article.
In your response to me calling that out, you offer an analysis. The author is lazy for using carrot disclosure over the defined disclosure process. That’s a valid take. I’m not going to disagree with that.
Yea. But did you read the security.md?
https://codeberg.org/forgejo/governance/src/branch/main/SECURITY-POLICY.md
Use an encrypted email to security@forgejo.org. If you can’t, tell them and they will set one up.
Seems very assholeish to not at least do that.
Edit: I hate to remove comments and it may get me banned but due to the hate speech I’m receiving regarding things unrelated to software while trying to sympathize with a frustrated security researcher who got caught up in unnecessary bureaucracy when taken en masse, I’m going to remove these comments for now. This is why we volunteer FOSS engineers have to stay clear of popular projects I guess.
Edit: I hate to remove comments and it may get me banned but due to the hate speech I’m receiving regarding things unrelated to software while trying to sympathize with a frustrated security researcher who got caught up in unnecessary bureaucracy when taken en masse, I’m going to remove these comments for now. This is why we volunteer FOSS engineers have to stay clear of popular projects I guess.
I don’t think you read the article.
Did you miss this part
Sounds like him being lazy.
Your comment said Forgejo has a disclosure process. The article says the author went with a carrot disclosure after reading the disclosure process and making a value judgement. Because your comment only mentioned Forgejo having a disclosure process, not an evaluation of the author’s evaluation of the disclosure process, it made you appear as if you had not read the article.
In your response to me calling that out, you offer an analysis. The author is lazy for using carrot disclosure over the defined disclosure process. That’s a valid take. I’m not going to disagree with that.