19 ms·
Git.io deprecation
- HellsMaddy 4y agoI feel bad, I just recommended a project use git.io short links a few months ago and they took my advice.
- captn3m0 4y agoA dump of the shortlink dataset would be appreciated, even if it was only the links that point to public GitHub repos or gists. Link-rot is annoying, but GitHub could do better here.
- charcircuit 4y agoOr at least just host an immutable endpoint in a subdirectory if you want to repurpose the domain.
- derefr 4y agoThey don't; they want to take down the 99% of git.io links that are pointing to malware / phishing, and they don't want to spend all their time manually culling them.
- charcircuit 4y agoThey could add a giant warning page where you have to copy and paste the link manually. There should still be some way to follow old links.
- dotancohen 4y agoThis would be the proper solution. The service could even just return an HTML page with a hyperlink instead of a 301 redirect.
- tinus_hn 4y agoOr require solving a captcha.
- ro_bit 4y ago> Out of an abundance of caution due to the security of the links redirected with the current git.io infrastructure, we have decided to accelerate the timeline. We will be removing all existing link redirection from git.io on April 29, 2022. What were the security concerns?
- bpeebles 4y agoThe read-only post from January said > Today, git.io is increasingly being used for malicious purposes. So my guess is they observed an increase use of some number of existing git.io URLs (perhaps where the destination URL was squatted on) being actively used for "malicious" things.
- zinekeller 4y ago> perhaps where the destination URL was squatted on ... how? Git.io only redirects to GitHub, isn't it?
- oefrha 4y agoI’m under the impression that gist.githubusercontent.com is a popular malware host and C&C especially before they disabled anonymous gists.
- gurjeet 4y agoPerhaps they are selling the domain, or planning to use it for a new service that allows users to create arbitrary URLs. Both of those scenarios can help an attacker take over old git.io URLs
- jhugo 4y agoIt's basically unimaginable that they would sell the domain. Whatever amount of money they'd get for it wouldn't be worth it given the potential risks to their customers (since it was formerly an URL shortener), and owning git.io is pretty on-brand for GitHub.
- 4y ago
- spondyl 4y agoAnnoyingly, the CodeQL analysis github actions make use of git.io as a short link to relevant documentation inside action comments. Even right now, the action is still using git.io so regardless of this advisory, that seems like something that should be have been fixed some time ago when git.io was initially put into read only mode
- Thorrez 4y agoHow does that work? This page (and the main linked page) seem to say no new links are able to be created: https://github.blog/changelog/2022-01-11-git-io-no-longer-accepts-new-urls/ https://github.blog/changelog/2022-01-11-git-io-no-longer-ac...
- spondyl 4y agoPresumably they were created some time ago and/or Github created them internally. They're hardcoded links that appear as comments in the actions yml file template and have probably existed for quite some time.
- spatulon 4y agoI'll make sure we fix those (I work on CodeQL).
- pabs3 4y agoThat is a very very short deadline.
- deleted 4y ago[deleted]
- upbeat_general 4y agoFor a link redirection service I’d hope the depreciation timeline is measured in years not months.
- forgotmypw17 4y agoA lesson in Internet tenancy we all learn eventually... Either you own your domain, hardware, software, data, and network -- or you're a tenant in someone else's domain, at your landlord's complete mercy. Sometimes it's not a bad deal, especially when it's a small landlord whom you have a connection with, other times it can be a raw deal. You don't have to own all the pieces, but owning your domain name is crucial to avoiding having the rug pulled out from under you like this.
- Jaxkr 4y agoThis made me nostalgic, I remember when vanity URL shorteners were the coolest thing you could have. A new one popped up every few days and every company land grabbed for something custom they could use for social media. Then Twitter updated to make URLs use fewer characters by shortening them on the fly (and showing the original URL to viewers). The URL shortener craze died quickly after.
- vemv 4y agoFeels like a punch in the stomach. git.io has its place in the world, namely for creating code comments to Github immutable permalinks (that is, with SHA markers) that would otherwise surpass a conventional column limit, making linters complain. I probably have created dozens of such comments over the years. Now people following those will find nothing. Folks at github should really reconsider their position. Don't expect loyal consumers to keep their trust when you suck at your very job - namely keeping an immutable historic record.
- eloisius 4y agoThat sucks and I know it doesn’t help fix your current situation, but I’ve found it useful to include more context and long comments in commit messages than code comments. If your team knows how to use git blame for archeology, the information tends to stay more cogent to the code, while code comments often go stale.
- Gigachad 4y agoIt becomes increasingly undiscoverable. Especially after some lint rule changes and the last change becomes the lint fix. Info going stale seems much worse with commit messages since they can’t even be updated unlike comments.
- jhugo 4y agoThis is largely a problem of GitHub and other code UIs making it awkward to see anything other than the most recent commit in blame view. With `git blame` you can use `-w` to ignore whitespace changes and `-M` to detect moved/copied code; a lot of the time this will help to rapidly find the relevant commit rather than a lint change. You can also use `git log` on a range of lines of a file: `git log -L 15,23:src/main.rs` and if you add `-p` you'll see diffs as well. Comments can go out of date, commit messages (if used properly) provide a genuine timeline of the evolution of the code.
- JohnBooty 4y agoI generally find code comments much more useful than commit messages. They are of course not mutually exclusive and you can (and should) do both. 9 times out of 10, "why are things the way they are now?" is what I'd like to know. Occasionally, of course, I would like to know "why things were the way they were x commits ago" and that's when commit messages come in handy. But that's the minority use case for me.
- chrismorgan 4y agoI will continue my attempt to rescue the word “deprecate” from destruction. > Git.io deprecation > As notified in January, we shared our plans to deprecate the service. This is not deprecation. This is discontinuation. Deprecation is when you say “we recommend not using this, but it’s still working for now”; at time of deprecation, a schedule of when it will cease to work may be provided, or it could be that it will continue to work indefinitely. The announcement in January was the deprecation. What they’re doing now is the final discontinuation.
- BoorishBears 4y agoIf you want to be pedantic you need to also be fully correct. This announcement in itself is a deprecation, just like the last one, that additionally announces a future discontinuation. There is no requirement a deprecated service still works. If something is half broken you can deprecate it for those relying on the half-broken mess and eventually discontinue it (which is what Github is doing)
- Brian_K_White 4y agoSince the service is already read-only, you don't have the option of using it against the recommendation, and so no this is not merely a deprecation.
- BoorishBears 4y agoLike I said, the feature can be half-broken during deprecation. Read-only still lets you use it: http://git.io/iEPt8g http://git.io/iEPt8g The feature can be a stub that prints "no pls" and you're still free to mark it as deprecated (that's more common than one might expect because ABIs are a thing)
- chrismorgan 4y agoTake both notices together and you can see that they’re clearly using the wrong sense of the word deprecate. From the January notice: > Existing URLs will continue to be accessible, but we encourage using one of the many URL shortening services that are available, instead of git.io, as we will be deprecating the tool in the future. Semantically, that was clearly a deprecation of the service: it keeps working, but they discourage its use as it will be discontinued in the future. (It was also notice of shutdown of the write parts of the service.) It is not reasonable to consider today’s notice to be a deprecation (interpreting that as a change in status). > There is no requirement a deprecated service still works. This is flatly wrong. The agreed meaning of the word “deprecate” requires that it still works. See https://en.wikipedia.org/wiki/Deprecation https://en.wikipedia.org/wiki/Deprecation for a good overview of the term’s proper usage and accepted meaning.
- mgdlbp 4y agoThe problems with url shorteners https://news.ycombinator.com/item?id=545565 https://news.ycombinator.com/item?id=545565 – 2009-04 (56 comments) URL Shorteners – the herpes of the web https://news.ycombinator.com/item?id=570041 https://news.ycombinator.com/item?id=570041 – 2009-04 (17 comments) Url Shorteners: Destroying the Web Since 2002 https://news.ycombinator.com/item?id=660087 https://news.ycombinator.com/item?id=660087 – 2009-06 (57 comments) URL Shorteners are evil, here's one to prove it. https://news.ycombinator.com/item?id=904941 https://news.ycombinator.com/item?id=904941 – 2009-10 (57 comments) – ironically dead Link shorteners hurt the user experience and destroy the Web https://news.ycombinator.com/item?id=7803290 https://news.ycombinator.com/item?id=7803290 – 2014-05 (89 comments) – dead The URL shortener situation is out of control https://news.ycombinator.com/item?id=7836626 https://news.ycombinator.com/item?id=7836626 – 2014-06 (78 comments) URL shorteners set ad tracking cookies https://news.ycombinator.com/item?id=25624112 https://news.ycombinator.com/item?id=25624112 – 2021-01 (207 comments) Link shorteners: the long and short of why you shouldn’t use them https://news.ycombinator.com/item?id=27462261 https://news.ycombinator.com/item?id=27462261 – 2021-06 (145 comments)
- rectang 4y agoEventually, all domains expire. It's not just url shorteners. You can't count on anything on the web lasting. You can't count on anything disappearing either. When you want the web to be ephemeral, "the internet never forgets". When you want the web to be permanent, the site you remember will be abandoned and lost.
- jraph 4y agoYes, and everybody dies one day. But you don't need to double the problem by making a link rely on two domains and shortening its life. What's more, if you have the complete original URL, you might be able to use an archive service that might have taken a snapshot, or at least try to guess what was behind the link by looking at it. Shortened URLs are usually inscrutable.
- tobr 4y ago
- johndough 4y agoAnd just like that, several hundred scientific papers which used git.io links become incorrect https://scholar.google.com/scholar?hl=en&q=git.io https://scholar.google.com/scholar?hl=en&q=git.io Changing the content of papers after they have been published is usually impossible or at least extremely difficult, depending on the publisher.
- asvitkine 4y agoI wonder if anyone is working on an archive?
- xucheng 4y agoIt is unlikely because it is very difficult and maybe illegal to scrape research papers. See https://en.wikipedia.org/wiki/Aaron_Swartz https://en.wikipedia.org/wiki/Aaron_Swartz for example.
- johtso 4y agoIf anyone is it would probably be the people over at ArchiveTeam / URLTeam: https://wiki.archiveteam.org/ https://wiki.archiveteam.org/ https://wiki.archiveteam.org/index.php/URLTeam https://wiki.archiveteam.org/index.php/URLTeam
- oefrha 4y agoGlad I made the decision to use my own 5-character domain for URL shortening years ago. Anyone can write a simple URL shortening service in less than half an hour, and you gain flexibility and peace of mind with that little bit of effort. Still, losing all git.io links hurt. I’m certain I have a few old projects with issue explanations, download links, etc. based on git.io. This is handled so poorly it’s ridiculous.
- hayleox 4y agoGuess I'll finally have to bookmark play2048.co, if git.io/2048 is gonna stop working.
- 0x0000000 4y agoDiscussion from the January announcement: https://news.ycombinator.com/item?id=30024993 https://news.ycombinator.com/item?id=30024993 - 56 comments
- noway421 4y agoAs an owner of http://git.io/way http://git.io/way and https://git.io/no https://git.io/no it's a good thing I noticed this on hackernews front page. Otherwise I would've never known! Just changed all of my git.io links where I could find them. I wish they would send out emails for this, but as I remember git.io is an anonymous service.
- dataflow 4y agoWhile I'm a little annoyed by this (it seemed unlikely to me that GitHub would shut it down, so I actually used it), I can live with it. The "was only lightly documented" comment is pretty unnecessary and just adds insult to injury though. What's that supposed to mean? It feels like such an "it's kinda your fault for putting too much faith in us" insinuation. GitHub literally blogged about the feature [1], did they expect people not to use it because it wasn't "heavily" documented? Should their users ignore their blogs from now on, because apparently it's an irresponsible thing to take their blogs at face value? Oh, and I don't think they've sent anyone any notifications about this, like the repo owners. Not sure how people are supposed to find out; are all users expected to stay up to date with GitHub's blog... which GitHub is telling them not to trust? [1] https://github.blog/2011-11-10-git-io-github-url-shortener/ https://github.blog/2011-11-10-git-io-github-url-shortener/
- math-dev 4y agoAll good points
- larusso 4y agoI’m in general not a fan of sunset ting services which are part of greater infrastructure. The demise of jcenter for instance is still hunting me because of cache misses etc. And I had the same thoughts about the documentation comment. For me this means that GitHub has put itself in the long lines of service companies who have no issues with pulling the plugs (because this is mostly the cheapest solution) of services they don’t want to maintain for whatever reason.
- ThrashBeard 4y agoThe way I understood "was only lightly documented" was they were blaming themselves like "we didn't put much work into it and didn't document it very well".
- hjkl0 4y agoAs someone without a leg in this race, I found the added context of “lightly documented” useful. It does help tell the story
- rjmunro 4y ago"https://git.io/ https://git.io/" seems to occur about 200,000 times in source code: https://github.com/search?q=%22https%3A%2F%2Fgit.io%22&type=code https://github.com/search?q=%22https%3A%2F%2Fgit.io%22&type=... It would be good to write a script to fetch all of those and log their destinations to a CSV file and put that online somewhere. You could even make PRs to all of those projects replacing links with un-shortened versions. I hope github will replace the redirects with a holding page linking where they used to redirect to, rather than just delete them. That way people can report the broken links to the original site and still get to the destination they were intending.
- soco 4y agoGiven how often I get the "this is not the page you're looking for" I can safely assume they won't care this time either.
- deleted 4y ago[deleted]
- snthd 4y agohttps://wiki.archiveteam.org/index.php?title=URLTeam https://wiki.archiveteam.org/index.php?title=URLTeam
- romantomjak 4y agoThis is why you should never use url shorteners for publicly addressable content. Using url shorteners contributes to ‘link rot’ and after the domain expires or the service reaches its end of life the link is broken and cannot be resolved anymore. imo, it’s fine for linking to ephemeral content such as submission forms or anything that will not make sense after a certain time. Do not use it for articles and other content, because it will make the resource inaccessible after the service is no longer operational.
- jacobmischka 4y agoOff topic, but I have really grown to despise the phrase "out of an abundance of caution". It's grown so popular during the pandemic when people exercise the absolute bare minimum amount of caution.
- smegsicle 4y agoas if 'can't be too careful' is an excuse to forgo discernment
- henvic 4y agoWhy don't them just start returning the redirection link as a text (so if you want to follow, you must copy & paste), and call it a day?
- donohoe 4y agoGreat - but seems like very short notice. Just 4 days? Maybe 4 weeks. We're going to see a lot of broken links across the web.
- bsuvc 4y agoThis is not a developer-friendly decision. Why can't they leave it working for existing URLs at least? A quick search shows 704,000 code results containing git.io. https://github.com/search?q=git.io&type=code https://github.com/search?q=git.io&type=code Edit: actually it is more than 704k, much more it seems.
- pc86 4y agoThey mention security but don't expand on that, I wish they would have.
- computerfriend 4y agoGitHub has been quite thoughtful about its deprecation timelines before, e.g. with long notice periods and brownouts. They're handling this quite badly. Personally I don't see why they would care that it is used to shorten links to malicious redirects or whatever. But given that they do, the easy fix is to drop the github.io domain but keep the github.com domain. And in the interest of letting people update their URLs, returning the redirect URL as a response body instead of a 302.
- beliu 4y agoHere is a list of open source projects that should update their git.io URLs, ranked in order of popularity: https://sourcegraph.com/search?q=context:global+https://git.io+count:10000&patternType=literal https://sourcegraph.com/search?q=context:global+https://git....
- beliu 4y agoSourcegraph CTO here. Does anyone know someone at GitHub or Microsoft we could get in touch with to take over maintenance of git.io? There are hundreds of thousands of references in open source, blog posts, and academic papers that will 404 if git.io is taken down. Sourcegraph would be happy to take over maintenance to preserve these links.
- untitaker_ 4y agoPlaying the ball back: I was trying to export all git.io links through your sourcegraph code search, but the CSV export doesn't work for those purposes (it times out). Is there a chance you can publish this dataset now such that crawling git.io is easier? EDIT: https://twitter.com/untitaker/status/1519034010978160641 https://twitter.com/untitaker/status/1519034010978160641