social.heise.de ist einer von vielen unabhängigen Mastodon-Servern, mit dem du dich im Fediverse beteiligen kannst.
Der Mastodon-Server von und für Heise Medien und insb. die Nachrichten von heise online.

Serverstatistik:

38
aktive Profile

#gitlab

2 Beiträge2 Beteiligte0 Beiträge heute

#gitlab Securityfix 7.10.1, 17.9.3, 17.8.6

Cross-site Scripting (XSS) through merge-request error messages

Cross-site Scripting (XSS) through improper rendering of certain file types

Admin Privileges Persists After Role is Revoked

External user can access internal projects

and so on ...

#opensource #adminlife #git

about.gitlab.com/releases/2025

GitLabGitLab Patch Release: 17.10.1, 17.9.3, 17.8.6Learn more about GitLab Patch Release: 17.10.1, 17.9.3, 17.8.6 for GitLab Community Edition (CE) and Enterprise Edition (EE).

Empfehlungen für einen #Gitlab Provider für ein Projekt im universitären Umfeld? 4-5 Repos, 1-2 Entwickler, Issues, CI/CD, alles Mainstream, nichts Grosses...der Betrieb sollte halbwegs professionell sein...aber auch bezahlbar...Tipps?

Deux vulnérabilités (CVE-2025-25291, CVE-2025-25292) permettent de contourner l’authentification SAML (SSO) sur GitHub et GitLab via une attaque par « signature wrapping ».
Un attaquant disposant d'une signature valide pourrait ainsi se connecter sous l’identité d’un autre utilisateur. La prudence est de mise, surtout qu’un gang spécialisé dans les ransomwares a récemment ciblé ces plateformes. L’exploitation active est à ce jour inconnue.

📌 GitLab recommande fortement la mise à jour vers 17.9.2 :
👇
about.gitlab.com/releases/2025

📌 GitHub – Sign in as anyone (détails techniques) :
👇
github.blog/security/sign-in-a

#Cyberveille
#vulnerabilite
#GitHub
#GitLab
#SAML
#CVE_2025_25291
#CVE_2025_25292

GitLabGitLab Critical Patch Release: 17.9.2, 17.8.5, 17.7.7Learn more about GitLab Critical Patch Release: 17.9.2, 17.8.5, 17.7.7 for GitLab Community Edition (CE) and Enterprise Edition (EE).

Beware, #devops geekery lies ahead! Look away unless you're into that sort of thing.

I decided to give the #terraform backend feature of #gitlab a try over the weekend though I'm using it for OpenTofu. Generally I use the storage at Dreamhost for backend state since it behaves like an s3 bucket, though more recently I've started using the object storage at Linode since I get it for free with my job.

The actual integration was pretty easy though not having used http for backend state before it took a couple of commits to get it working. Looking at the documentation it's dead simple if you use one of the pre-built Terraform or OpenTofu Gitlab templates but I have a centralized template I use for my pipelines and I opted to build Tofu support into that instead of using the Gitlab-provided one.

The lack of support for Terraform Workspaces will likely keep me from using it heavily, but I do see a great use case for leveraging this backend state for bootstrapping a new cloud environment. Normally when I'm setting up a greenfield Cloud account I have to bootstrap the backend state by running with local state and then migrating it into the object solution once it's setup. The benefit of this would be that I could have remote backend state the entire time and not need to migrate.

Overall it's pretty good. I think if support were added at some point down the road for Workspaces, that might make me look at shifting to using this instead of object storage. If you don't have access to an object storage though then this was perfectly fine and it being accessible even with a free Gitlab plan is pretty nice.

GitLab CFO, Brian Robins, says they are “aligned with the goals of DOGE, because the company’s software tools aim to help people do more with less. What the Department of Government Efficiency is trying to do is what GitLab does.”

archive.is/okSlz

You either support fascism or you don’t. It’s binary. There’s no gray area or “aligning.”

Considering GitLab? Don’t. Use @Codeberg.

(Hat tip @aphyr)

#Code#Dev#Development

Hey peeps, if you're still using #GitLab and #GitHub and you're twitching a bit because they're fellating fascists, I want to point to the sign that says you can self-host @forgejo - a project which is also working on decentralisation and federation.

Failing that, @Codeberg also exists, are a European non-profit that also supports the development of Forgejo.

Hope that helps 😀

I bet most of you #Markdown enthusiasts didn't know you can paste #LibreOffice #spreadsheets as Markdown tables in #GitLab.

Pretty cool, right?
Now, imagine if we could also do that in #GNOME's Markdown editor, Apostrophe (or even, any GNOME text editor that recognizes Markdown for syntax highlighting…) :blobaww:

Ponies-on-rainbows feature request here: gitlab.gnome.org/World/apostro

GitLabAbility to paste spreadsheets / tables contents as markdown tables (#598) · Tickets · World / Apostrophe · GitLabThe parser in GitLab's MarkDown editor can actually do this:

Achievement unlocked: loaded a GNOME #GitLab link that was pasted in a chatroom and triggered @cadey's "Anubis" anti-LLM-scraper protection catgirl with my genuine Firefox browser, and had to watch my CPU burn for a minute :blobmiou:

I regret to inform you that we have now entered the DEFCON 1 stage of the struggle against the LLMs "AI" #enshittification bubble 🫠

What I don't quite understand is why the GitLab instance would put up this challenge to already logged-in users 🤔