244
submitted 11 months ago by nutomic@lemmy.ml to c/announcements@lemmy.ml
top 22 comments
sorted by: hot top controversial new old
[-] sunaurus@lemm.ee 77 points 11 months ago

Thanks for releasing it so quickly!

This "sunaruas" sounds like a cool guy 😛

[-] machinaeZER0@lemm.ee 9 points 11 months ago

Somebody should give that guy a raise!

[-] startlefrenzy@lemmy.world 37 points 11 months ago

Glad to see Lemmy is responding quick to exploits. Does Lemmy have a plan to prevent any other exploits that may be lying around such as a routine security audit?

[-] nutomic@lemmy.ml 69 points 11 months ago

All the code is open source, everyone is welcome to look through it for potential problems and report/fix them. we dont have any money to pay for a professional audit. Maybe there are some organizations which would do audits of open source projects for free, might be worth searching for.

[-] Zeth0s@lemmy.world 25 points 11 months ago

We use sonarqube for code analysis that is pretty nice and has a community edition. It isn't a bullet proof solution, but it is pretty convenient for maintainers and reviewers of PRs. The only thing missing from the enterprise edition are useless flashy dashboards to show to people who don't understand computers

[-] lowleveldata@programming.dev 10 points 11 months ago

I do have a Sonarqube server somewhere around. Is it considered an annoying behavior to scan an open source project and open issues for others to fix?

[-] nutomic@lemmy.ml 23 points 11 months ago

That depends, it would be annoying if you open lots of issues for minor, unimportant issues. But if you find a few major problems its good to report them. Of course its always ideal if you submit fixes as well, because there are never enough devs.

[-] lowleveldata@programming.dev 7 points 11 months ago

I'm way too lazy to code when I'm off work

[-] JoeKrogan@lemmy.world 3 points 11 months ago

I think its better to detect something early even if there is not a fix as it at least can be triaged and others can fix it if the original reporter is unable to devote the time or whatever

[-] Zeth0s@lemmy.world 2 points 11 months ago

Better ask the lead developers... :)

[-] mrmanager@lemmy.today 2 points 11 months ago
[-] Zeth0s@lemmy.world 1 points 11 months ago

No, you are right... Time to hire 3 PMOs per developer to copy and paste random numbers in well formatted tables on outlook, and send it around in the mailing list with CIO and directors.

And publicly shame developers if some meaningless number goes down

/s

[-] lvxferre@lemmy.ml 17 points 11 months ago

Given that the exploit was literally yesterday, you guys are damn fast!

[-] shellshock@reason.rocks 3 points 11 months ago* (last edited 11 months ago)

Yeah this was a fast turnaround, they did a great job. Autocorrect messed me up

[-] lckdscl@whiskers.bim.boats 9 points 11 months ago

Thanks for the prompt fixes

[-] ulu_mulu@lemmy.world 5 points 11 months ago

Thank you for reacting so quickly!

[-] ravermeister@lemmy.rimkus.it 5 points 11 months ago

and docker images for arm64 are ready as well :)

[-] gabriele97@lemmy.g97.top 3 points 11 months ago
[-] DonDino@mujico.org 1 points 11 months ago

is it me or front is broken?

[-] entropy@not.alazy.dev 1 points 11 months ago

Thanks for the quick update on this!

[-] nick@nickbuilds.net 1 points 11 months ago

Hey one quick question.. the Ansible playbook doesn't look like it's been updated to 0.18.2 or at least the instructions don't state how to pull it. Any chance this could get fixed/clarified in the release notes?

[-] nutomic@lemmy.ml 1 points 11 months ago

Its updated: https://github.com/LemmyNet/lemmy-ansible/blob/main/VERSION

You need to run git pull in the repo and then rerun ansible.

load more comments
view more: next ›
this post was submitted on 11 Jul 2023
244 points (100.0% liked)

Announcements

22776 readers
1 users here now

Official announcements from the Lemmy project. Subscribe to this community or add it to your RSS reader in order to be notified about new releases and important updates.

You can also find major news on join-lemmy.org

founded 5 years ago
MODERATORS