GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by Gordon Messmer (gordonmessmer@fosstodon.org)

  1. Embed this notice
    Gordon Messmer (gordonmessmer@fosstodon.org)'s status on Tuesday, 09-Apr-2024 16:25:34 JST Gordon Messmer Gordon Messmer
    • John Wyatt 🐧
    • Matthew Miller
    • Björn
    • Mattias Bengtsson

    @sageofredondo @thaodan @mattiasb @mattdm Do you have a link to that statement? It's not clear what you mean...

    GitLab is Open Core, and as far as I know it always has been. In their words, "GitLab CE .. is open source and GitLab EE .. is closed source" The EE product has a lot of essential security features, and they are not open to community contributions that would add them to CE.

    https://about.gitlab.com/blog/2016/07/20/gitlab-is-open-core-github-is-closed-source/

    In conversation about a year ago from fosstodon.org permalink
  2. Embed this notice
    Gordon Messmer (gordonmessmer@fosstodon.org)'s status on Tuesday, 09-Apr-2024 16:24:11 JST Gordon Messmer Gordon Messmer
    in reply to
    • malte
    • AndresFreundTec

    @malte @AndresFreundTec There's still a lot of data out there already in xz format, so merely dropping the software would mean that that data becomes unreadable. Dropping it may be an option, but I'm not sure it's the best option.

    In conversation about a year ago from fosstodon.org permalink
  3. Embed this notice
    Gordon Messmer (gordonmessmer@fosstodon.org)'s status on Tuesday, 09-Apr-2024 16:24:07 JST Gordon Messmer Gordon Messmer
    in reply to
    • AndresFreundTec

    @AndresFreundTec Thank you so much for finding this!

    The questions at the top of my mind now are: who will fork and continue maintenance of xz? How will we determine that we can trust them? And how will we apply those lessons throughout the larger ecosystem?

    In conversation about a year ago from fosstodon.org permalink
  4. Embed this notice
    Gordon Messmer (gordonmessmer@fosstodon.org)'s status on Tuesday, 09-Apr-2024 16:23:24 JST Gordon Messmer Gordon Messmer
    in reply to
    • Matthew Miller

    @mattdm I feel like I don't often see Fedora folk criticize GitLab, but yeah... I agree. I am quite sad that Red Hat doesn't see more value in developing and offering Pagure to customers for private, on-site Git management.

    In conversation about a year ago from fosstodon.org permalink
  5. Embed this notice
    Gordon Messmer (gordonmessmer@fosstodon.org)'s status on Saturday, 30-Mar-2024 12:57:19 JST Gordon Messmer Gordon Messmer

    The least surprising thing about the xz vulnerability is that it happened to a widely used project after a maintainer hand-off. We've seen exactly the same thing repeatedly in npm, pypi, browser extensions, and other code marketplaces.

    Humans don't last forever. Hand-off is inevitable. And I've long held that because that is true, the size of the group of maintainers is an important security characteristic.

    Small projects create big risks.

    Sustainability is a security concern.

    In conversation about a year ago from fosstodon.org permalink
  6. Embed this notice
    Gordon Messmer (gordonmessmer@fosstodon.org)'s status on Saturday, 01-Jul-2023 02:49:07 JST Gordon Messmer Gordon Messmer
    in reply to
    • Miguel de Icaza ᯅ🍉
    • Matthew Miller
    • Max Steenbergen

    @Migueldeicaza @mattdm @maxsteenbergen

    "people want ... the one that is certified"

    I want to remark on that point specifically. There is not one line of "certification" in RHEL. As a developer, I cannot write certification.

    Certification is part of the support contract that Red Hat provides, not a part of the software. The thing that people want is Red Hat's support.

    In conversation Saturday, 01-Jul-2023 02:49:07 JST from fosstodon.org permalink

User actions

    Gordon Messmer

    Gordon Messmer

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          140903
          Member since
          30 Jun 2023
          Notices
          6
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.