Critical Gitlab vulnerability let attackers take over accounts
bleepingcomputer.com
bleepingcomputer.com
GitLab is actually pretty good: the UI is nice, the feature set is pretty complete and GitLab CI is still one of the best CI solutions that i've used and probably a noticeable step up from Jenkins, or at least the Jenkins instances that i've seen, but self-hosting it and keeping it up to date certainly takes a bit of care, especially if you ever want to have it be publicly available.
That's not to say that Gitea or any other piece of software couldn't have similar vulnerabilities, but rather that GitLab is a pretty large and complex piece of software that's also moving ahead rapidly, so situations like this are inevitable (also things like the EXIF vulnerability a while back https://gitlab.com/gitlab-org/gitlab/-/issues/327121). Perhaps even something as simple as basicauth in front of it can be helpful for cases like this (or just making things available only through a VPN, though that's likely to be too limiting in some cases, e.g. non-enterprise settings).
Edit: Actually, here's a question for the lovely people here: suppose that you want to self-host a platform with a web UI for working more easily with Git repos, something like GitHub, GitLab or other platforms like that, to collaborate on a project with some friends and/or like-minded strangers. What do you, a single person with a VPS and a bit of spare time pick for the most successful outcome? Or is the only viable advice nowadays: "Don't. Just use the cloud."?
It is most certainly a nice project and i'm all for alternatives to Git, but for many people having to give up their current tooling (e.g. IDE integrations, specific tools for graphical graphs, interactive staging of chunks, rebasing etc.) would probably be a non starter, since it's another source control system entirely, instead of a front-end/enhancement of what Git provides (e.g. ticketing, wikis, merge/pull request discussions, CI etc.).
Here's hoping that Fossil has a nice future ahead of it, there is certainly a number of projects that would benefit from it's relative simplicity when compared to Git!
Also their docs are pretty simple to understand: https://fossil-scm.org/home/doc/trunk/www/permutedindex.html
Though personally i really liked the more visual nature of SourceHut's page: https://sourcehut.org/
The darcs FAQ from 2012 reports it as still unfixed:
http://darcs.net/FAQ/Performance#is-the-exponential-merge-pr...
(Yes this was real, and yes we hit it. I liked the patch-centric darcs approach, but that was enough to make us migration to mercurial, then later git.)
It's not for the general mass to say the least. You're better off using other focused products for each components than something that does everything in average ways.
The visual looks like they combined components from 20 years ago.
As soon as you get a Postgres server up and have some flow to keep your infra in source control (ansible+docker-compose/systemd goes a long way; they're a sane starting point for the unopionated mostly because of popularity), setting up new services is pretty straight-forward.
I did use nexus at work but tbh the official docker-registry container and a static webserver have proven sufficient for personal use.
Here's a decent run-down of alternatives for hosting a forge, it all comes down to preference: https://www.paritybit.ca/blog/choosing-a-self-hosted-git-ser...
> Or is the only viable advice nowadays: "Don't. Just use the cloud."?
For the people who really can't or won't self-host, I'd suggest at least looking at smaller providers rather than defaulting to big tech for everything.
It's login-only, there's no other users, so I'm not too worried about security.
For anything public I use GitHub.
Mostly it's the frequency of updates that's a pain, there are enough critical vulnerabilities that you have to stay on top of it.
I am the dog lying on a nail and occasionally whimpering at the moment though.
Maybe I'm bias because I've become accustomed to Gitea, but I really feel like Gitea augments my workflow while GitLab and GitHub are trying to usurp my workflow. I use GitHub, but only for push mirroring when I want to use something like Cloudflare Pages / Functions that do GitOps style managed deployment.
As for an extra layer of auth, I think Cloudflare Access makes a lot of sense for small users. Put everything behind Cloudflare, use split horizon DNS for LAN access, and rely on Cloudflare to pre-auth all users before they can connect via the internet.
How it turned out to be a unicorn, I guess good sales and not by the technical advantage.
nginx['custom_gitlab_server_config'] = "auth_basic 'Restricted';\n auth_basic_user_file /etc/gitlab/.htpasswd;\n location ^~ /.well-known { root /var/www/letsencrypt; auth_basic off;}"
1. Can't be used to login, ever.
2. Can't be used as an actual password.
https://gitlab.com/gitlab-org/gitlab/-/commit/e2fb87ec5d4e23...