5 ms·
I checked out Forgejo shortly after they forked to potentially replace a Gitlab instance. At the time at least, what I found was they seemed to be spending most
by dave78 3y ago
I checked out Forgejo shortly after they forked to potentially replace a Gitlab instance. At the time at least, what I found was they seemed to be spending most of their efforts bickering over a code of conduct and I think they already managed to have a scandal of sorts where they decided to kick someone out for CoC violations. This was before they had even made any real code changes. It really turned me off; I don't want to be dealing with a project that uses a CoC as a weapon. I don't know if the situation has changed or not, but if that kind of thing worries you, then I suggest looking into it before going all-in on Forgejo.
- CaptainFever 3y agoThis is interesting. I run a Forgejo instance but if the project is really more of an Ayo.js (over-interested in governance and office politics, under-interested in coding), I would consider Gitea or Gitlab instead. Do you have a source? I can't find anything about this online.
- wtfwhateven 3y agothere is no source, they made it up
- lolinder 3y agoBe warned that Gitea has its own problems—the trademarks and domain were transferred to a for-profit entity (Gitea Ltd. [0]) and gitea.com is now being operated by a different for-profit entity (CommitGo, Inc.). Given that Gitea Ltd. was created specifically to make money to fund the development of Gitea, it's concerning that they already felt the need to obfuscate the situation further with another company, with no real explanation for why. I think the Forgejo developers were correct that the transfer of the IP did not bode well for the future of the open source project. As for GitLab, I'm concerned by the fact that the company has become weirdly enterprise-y of late. This might not affect the self-hosted version yet, but I wasn't willing to risk it. I ended up going with Forgejo as the option with the least concerning governance structure. [0] https://news.ycombinator.com/item?id=33372471 https://news.ycombinator.com/item?id=33372471
- remram 3y agoMy main problem with GitLab is not only that they have become very enterprise-y, having tons and tons of features to the point that it's impossible to find anything in the left menu. It's that they don't seem very good at it: it seems that every week, another critical security release comes out with a dozen very exploitable CVEs. Makes me feel like they can't write this many features correctly... Going back one month (see https://about.gitlab.com/releases/categories/releases/ https://about.gitlab.com/releases/categories/releases/): Feb 7: CVE-2024-1250 (medium, privilege escalation), CVE-2023-6840 (medium, bypass branch protection), CVE-2023-6386 (medium, ReDoS), CVE-2024-1066 (medium, DOS) Jan 25: CVE-2024-0402 (critical, unprivileged RCE), CVE-2023-6159 (medium, ReDoS), CVE-2023-5933 (medium, CSRF), CVE-2023-5612 (medium, info disclosure), CVE-2024-045 (medium, arbitrary change of ticket assignees) Jan 11: CVE-2023-7028 (critical, arbitrary account takeover without interaction), CVE-2023-4812 (high, bypass MR approval rules), CVE-2023-5356 (high, privilege escalation from Slack/Mattermost integration), CVE-2023-6955 (medium, run commands in Kubernetes cluster from another subgroup), CVE-2023-2030 (low, commit signature validation issue). Note that those are all GitLab issues, not issues with Git or SSH that affect the GitLab application. Running a self-hosted GitLab really keeps you on your toes...
- dave78 3y agoThis was a year or 2 ago - I didn't save specific links. However, if you're interested, you can poke around in https://codeberg.org/forgejo/meta https://codeberg.org/forgejo/meta. Below are two that I just found now that represent the kinds of things I saw at the time that concerned me. There were teams being formed and dissolved and multiple accusations of CoC violations flying around with lengthy, passionate discussions being had on these topics. It gave me a strong vibe of a group of people that was way more concerned with the power and control aspects of a project than the engineering. There's also the behavior that others have linked in comments here about the fact that they have people designated as "enforcers" who edit/remove content and comments they don't like. YMMV. https://codeberg.org/forgejo/meta/issues/176 https://codeberg.org/forgejo/meta/issues/176 https://codeberg.org/forgejo/meta/issues/146 https://codeberg.org/forgejo/meta/issues/146
- WolfeReader 3y agoThis whole HN story is about Forgejo doing a hard fork and focusing on their own code instead of relying on Gitea, so I don't think calling them under-interested in coding is accurate.
- beardicus 3y agoi guess if you think enforcing a code of conduct is a "scandal" and a "weapon" then maybe it's not for you? most people don't get hung up on this stuff though.
- llanowarelves 3y agoSome people rightfully want to see what the engineering effort and roadmap is gonna be before becoming invested in it, since there's always a cost. Simple aesthetic changes and codes of conduct / political alignment for contributors are not enough for forks to become full things of their own. Even if they can help (branding, community, etc.). Or hurt (Forgejo is harder to pronounce. And CoC have potential downsides, possibly excluding good people, ironically, over banal minutia and hostile environment around being "not hostile" - like you saying he is "hung up" on it...). Gitea was already a fork of Gogs, so why should contributors use this fork of a fork? These forks (and direct clones) are like little political secessionary/independence movements, both making lofty statements and splitting would-be contributors. Sometimes it works out very well and they become full independent things of their own (GNU stuff), but it's fair to want to get on to see the actual engineering side of things.
- wirrbel 3y agoForgejo forked Gitea IIRC because of problems in the Gitea governance of the Gitea trademark, a limited company was founded by some Gitea contributors, without consent of the larger group of Gitea developers. So I only find it natural that a group of people who split off of Gitea took extra care to set up some kind of governance model. Those who dislike the idea of a code of conduct can of course also contribute to Gitea or Gogs, or fork Forgejo, etc. This is free software after all. With 23 open and 1.381 closed PR forgejo seems like an active project, it's in use at codeberg.org which means it isn't a random fork.
- Spivak 3y agoHN is just anti-CoC overall so any project that actually does something with one other than it being a file sitting in the repo gathering dust earns ire.
- subjectsigma 3y agoThanks, I was leaning towards not switching and staying with Gitea but this solidifies my decision
- lagniappe 3y agoI checked out their issues and learned their moderation team has "enforcers" https://codeberg.org/forgejo/governance/issues/78 https://codeberg.org/forgejo/governance/issues/78
- Kwpolska 3y agoAnd they're silencing constructive criticism by editing comments (removing their content).
- radlad 3y agoWow, those removed comments tell the whole story. (You can click "edited" to see the original message.)
- kstrauser 3y agoOh dear. I like Code of Conducts. I put my pronouns on stuff. I moderate a largely LGBTQ community. I am absolutely, 100% in favor of DEI and making sure people in minority groups feel safe and comfortable contributing to the communities I'm in. And I think those comment edits are a very bad look for the project. I don't know the people involved at all. Maybe the person applying to be a moderator is an angel of a person, and the people opposed to their appointment are awful. I have no idea. But what I saw there was someone raising concerns about a specific person's behavior, and their comments being essentially deleted as ad-hominem attacks. That doesn't sound right to me. The person wasn't saying "you smell funny so I'm ignoring your argument". They were saying "you did some things in a previous role that made me think you're not a good fit for this one". I didn't interpret it as an ad-hominem attack at all. I hope this is a tempest in a teapot that blows over quickly.
- lolinder 3y agoIn a similar vein, I'd put in a word of caution against Gitea. The trademarks and domains were transferred to a for-profit entity (Gitea Ltd) against the protests of the community [0], which is the event that prompted the creation of Forgejo in the first place. Now gitea.com is under the control of a different company (CommitGo, Inc), with no explanation given for why this entity was created [1]. Personally, given a choice between a project that enforces a CoC and a project that keeps creating new for-profit entities to hold the community's IP, I'll take the CoC over the concerning corporate structures. [0] https://news.ycombinator.com/item?id=33372471 https://news.ycombinator.com/item?id=33372471 [1] https://blog.gitea.com/gitea-cloud/ https://blog.gitea.com/gitea-cloud/