HNHacker News
TopNewBestAskShowJobs

mfenniak

566 karma · joined January 25, 2008

[ my public key: https://keybase.io/mfenniak; my proof: https://keybase.io/mfenniak/sigs/eo6JiTXuJQV68__kYj4qCWj-PkplQU5F3clSvlBADHU ]
submissionscomments
mfenniak··on Forgejo <=16.0.3 Critical RCE
Forgejo's security team received disclosure of this issue on September 4th. (source: I am a member of that team)
mfenniak··on Ask HN: Alternatives to GitHub
A basic API to access Actions logs was added in Forgejo v16. `/api/v1/repos/{owner}/{repo}/actions/jobs/{job_id}/logs`
mfenniak··on Codeberg Is Down
You may be violating Codeberg's rules. They are not a service for developmental of closed-source software.

https://docs.codeberg.org/getting-started/faq/#how-about-pri...

mfenniak··on Ask HN: Due to spam on GitHub, what platforms can I move my projects?
Forgejo is lightweight relative to some other options, but it is not resilient to scraping. Scrapers can access, commit-by-commit, each individual file, each file's "git blame", and each commit's repository archive... and they do. Most public Forgejo instances need to rely on a reverse proxy like Anubis or Iocaine in order to prevent server resources from being exhausted by bad actors. Or require sign-in for all access.

https://codeberg.org/forgejo/discussions/issues/320

mfenniak··on My Homelab AI Dev Platform
That's not an API tool. It performs direct database access for administrative functions on the Forgejo server.

But there is a different tool that is an API accessing CLI: https://codeberg.org/forgejo-contrib/forgejo-cli

mfenniak··on Leaving GitHub for Forgejo
The other way around; Forgejo is a fork of Gitea.
mfenniak··on Incident with multple GitHub services
Forgejo 15 was just released last week with repo-specific access tokens. More to come in the future.
mfenniak··on Moving from GitHub to Codeberg, for lazy people
It is kinda incorrect and kinda correct. Codeberg allows you to create private repositories. However, their rules are clear that the intent of private repositories must be in support of Free software projects: https://docs.codeberg.org/getting-started/faq/#how-about-pri..., which for many people is effectively not allowing private repositories.
mfenniak··on Moving from GitHub to Codeberg, for lazy people
Forgejo is committed to using exclusively Free Software for it's own project development. Windows and Mac versions of the Forgejo Runner are built in the project's CI system as a minimal check to ensure platform compatibility, but due to the project's commitment, the project doesn't do integration testing on these platform. And therefore doesn't distribute untested software.

A contributor maintains a tested re-release of Forgejo Runner for Windows: https://github.com/Crown0815/Forgejo-runner-windows-builder

But, pull it down and build it, and it will work.

mfenniak··on GitHub is once again down
As a developer working on Forgejo -- glad you like it!
mfenniak··on GitHub is down again
It probably depends on your scale, but I'd suggest self-hosting a Forgejo instance, if it's within your domain expertise to run a service like that. It's not hard to operate, it will be blazing fast, it provides most of the same capabilities, and you'll be in complete control over the costs and reliability.

A people have replied to you mentioning Codeberg, but that service is intended for Open Source projects, not private commercial work.

mfenniak··on GitHub Actions has a package manager, and it might be the worst
On the plus side, Forgejo Action's implementation is still actively improving, where it seems that for GitHub if it's not AI, it's not being touched.

However, as noted in the article, Forgejo's implementation currently has all the same "package manager" problems.

mfenniak··on Migrating Dillo from GitHub
> * Strange error: "Error: Open(/home/runner/.cache/actcache/bolt.db): timeout"

This will occur if you have a `forgejo-runner daemon` running while you try to use `exec` -- both are trying to open the cache database, and only the first to open it can operate. You could avoid this by changing the cache directory of the daemon by changing `cache.dir` in the config file, or run the two processes as different users.

> It's a bit strange there are two files IMHO.

The `.runner` file isn't a config file, it's a state file -- not intended for user editing. But yes, it's a bit odd.

mfenniak··on Migrating the main Zig repository from GitHub to Codeberg
Although it's not a writeup, most of the problems can be traced through this "moving-to-forgejo" meta-issue: https://codeberg.org/forgejo-contrib/moving-to-forgejo/issue...
mfenniak··on We need a clearer framework for AI-assisted contributions to open source
The Forgejo project has been gently trying to redirect new contributors into fixing bugs before trying to jump into the project to implement big features (https://codeberg.org/forgejo/discussions/issues/337). This allows a new contributor to get into the community, get used to working with the codebase, do something of clear value... but for the project a lot of it is about establishing reputation.

Will the contributor respond to code-review feedback? Will they follow-up on work? Will they work within the code-of-conduct and learn the contributor guidelines? All great things to figure out on small bugs, rather than after the contributor has done significant feature work.

mfenniak··on Forgejo v13.0 Is Available
If you're running a public Forgejo instance and upgrading to v13, please take note of the post-release recommendation to run the `avatar-strip-exif` command to enhance user privacy.

https://forgejo.org/2025-10-release-v13-0/#avatar-image-priv...

mfenniak··on Forgejo v13.0 Is Available
If you're running a Forgejo instance and upgrading to v13 today (or soon), note the post-release recommendation to run the `avatar-strip-exif` command to enhance user privacy.

https://forgejo.org/2025-10-release-v13-0/#avatar-image-priv...

mfenniak··on I ditched Docker for Podman
People having trouble getting this configured is a common issue for self-hosting Forgejo Runner. As a Forgejo contributor, I'm currently polishing up new documentation to try to support people with configuring this; here's the draft page: https://forgejo.codeberg.page/@docs_pull_1421/docs/next/admi...

(Should live at https://forgejo.org/docs/v12.0/admin/actions/docker-access/ once it is finished up, if anyone runs into the comment after the draft is gone.)

mfenniak··on Claude Code Checkpoints
I don't think jujutsu woild help with this use case -- jujutsu will not save everything because it is not running constantly on your repo. It snapshots the working tree only when you run a `jj` command. Ineffective if an agent is doing work.
mfenniak··on What is going on right now?
Not really.

If a program is built with strong software architecture, then a lot of it will fit that definition. As an analogy, electricity in your home is delivered by electrical outlets that are standardized -- you can have high confidence that when you buy a new electrical appliance, it can plug into those outlets and work. But someone had to design that standard and apply it universally to the outlets and the appliances. Software architecture within a program is about creating those standards on how things work and applying them universally. If you do this well, then yes, you can have a lot of code that is testable and verifiable.

But you'll always have side-effects. Programs do things -- they create files, they open network connections, they communicate with other programs, they display things on the screen. Some of those side-effects create "state" -- once a file is created, it's still present. These things are much harder to test because they're not just a function with an input and an output -- their behavior changes between the first run and the second run.

mfenniak··on Fedora Moves Towards Forgejo
"was previously known as gitea" is slightly confusing wording since it makes it sound like the project was renamed, which isn't the case. Gitea is still an active project known as Gitea. Forgejo is a fork of Gitea.
mfenniak··on Building a robust frontend using progressive enhancement
Great idea, more capacity for LLMs!

/s

mfenniak··on Show HN: Container Desktop – Podman Desktop Companion
There are two approaches to using compose w/ podman:

Replace docker-compose with podman-compose -- somewhat limited capabilities, but works in a lot of cases.

Use docker-compose against podman w/ podman's system service, which provides a docker compatible API endpoint (https://docs.podman.io/en/v5.2.1/markdown/podman-system-serv...). This basically has full docker-compose capabilities, but, you do need run the socket service as a specific user account which end up running all the pods.

mfenniak··on my-new-rust-binary-search
I believe this is reference to Go's approach, where code can be written in a linear straightforward fashion with normal function calls, but, if they are syscalls then they become async automatically.

I don't think it's appropriate for the level of coding that Rust is targeting... But... It would be nice.

mfenniak··on Malaysia started mandating ISPs to redirect DNS queries to local servers
DoH uses HTTPS; it solves redirects because you can use a trusted server, and not have the request intercepted and the response spoofed.
mfenniak··on Google Sheets ported its calculation worker from JavaScript to WasmGC
Since Excel 2010 that limit is 1,048,576.
mfenniak··on How to find the AWS account ID of any S3 bucket
Be aware that AWS Config is not free. https://aws.amazon.com/config/pricing/
mfenniak··on The Decomposition of Rotten Tomatoes
I like that idea quite a bit. I wonder if there's an algorithm that doesn't get completely screwed up by circles... since it is subjective, A > B > C > A is a valid input and shouldn't cause a complete algorithmic failure.
mfenniak··on What is a merge queue, and does your team need one?
They're super annoying if you have flaky tests. If the tests are such that you can automate retrying and get to a reasonably low false-positive rate, it can be usable.
mfenniak··on GitHub merge queue is generally available
The branch protection rules that you apply are both used to determine if you can add a PR to the merge queue, and if the merged commit passes the merge queue checks and is OK. This isn't documented, but based upon experience using the beta.
Page 1 of 5Next →