social.dk-libre.fr is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.
This server runs the snac software and there is no automatic sign-up process.
I built a small tool for a problem I had in my own setup.
FARM runs Forgejo Actions jobs in disposable Incus VMs:
queued job → FARM → Incus VM → one-job runner → cleanup
Each VM gets one job and is deleted afterwards.
It also supports runner pools, queue-based scaling, idle capacity, lifecycle limits, cleanup and Prometheus metrics.
Sweden is also choosing @forgejo for their digitally sovereign government codeplatform, just like the Dutch code.overheid.nl 🥳🥳
https://github.com/diggsweden/ena-kodsamverkansplattform-poc
This is a nice step towards less dependence on US big tech, aka Github.
In my last days at the @BZKopensource I hope to set up a working group with other EU governments, to work towards a federated network of codeplatforms 🇪🇺
#codeplatform #forgejo #ospo #digitalsovereignty #opensource #foss #govtech
Someone at #gitlab has spent hours and hours on calculating a long list of rate limits. I look at my #forgejo instance and shrug :) https://docs.gitlab.com/user/gitlab_com/rate_limits/
Yo, fellow #Forgejo users: another security update has just been released. I did the update on my instance and encountered no problems. So. Get dem buggies fixed :)
If you have a #forgejo instance, make sure it is updated! Two security fixes came in yesterday, so yeah, get the update done :) (I already didi it yesterday and encountered no problems)
ok, so how is this for spooky.
i maintain an #emacs #forgejo / #codeberg client, fj.el. a while back, a vibe-coder created a way better/faster client for same, called emacs-forgejo. cool design, sqlite, all async... ferrari to my rusty 1970s subaru basically.
recently i saw that they left Codeberg, being a vibe-coder, and the self-hosted version of emacs-forgejo now has a readme that says "Unmaintained. Feel free to fork." i was kinda thinking about this a lot recently. my client sucks, but i love using it, and i love hacking on it. recently i hacked away almost all the awfully slow bits, but there are still a bunch to do. i had gained some humble self-respect in the dog-eat-dog world of... uh, emacs forge clients. one thing i knew i wasn't doing to do was abandonware it.
so anyway, i am pushing fixes like mad coz i am having lots of fun, i'm getting super satisfied with the state of things, solving problems that months ago i bashed my head against for ages and failed to fix. and i'm pushing release tags.
i just now jumped onto Codeberg in the browser, to check out a release tag. the release tags have a description, and the latest 5 or so tags have descriptions that say it was *the vibe-coder* who "released this 6 minutes ago".
Moreover, the username of the non-existent user who is apparently doing my releases, and who never contrubted to my package, highly appropriately, is named "Ghost".
#fjEl, a #Forgejo (#Codeberg) client for #emacs, 0.31 released.
- fj-host/fj-user are defcustoms
- autoload entry points
- fix utf-8 encoding of diffs
- fix parsing of repo/owner from urls
- fix loading forgejo urls in discussion in fj.el
- fix loading PRs from notifications
- fix loading item from notifications with RET
if you appreciate my work on fj.el, consider donating:
https://paypal.me/martianh
or https://liberapay.com/martianh (even a small amount appreciated.)
& thanks a lot to the recent supporters.
#emacs #forgejo (#Codeberg) client #fjEl release 0.38 .
- inhibit modification hooks on tabulated list views (performance)
- asyncify loading of assets in issue/PR views (performance)
- add customize fj-list-repo-langs, making language display optional (performance)
- add request profiling code to ensure no redundant requests (performance)
- fix jump to browser from notifications view
- add customize fj-prefer-browse-url
- fix decoding of unicode chars in diffs
- various other small fixes
- more performance fixes in the pipeline
https://codeberg.org/martianh/fj.el
holler if you run into any issues upon updating.
if you appreciate my work on fj.el, consider donating:
https://liberapay.com/martianh or https://paypal.me/martianh. (even a
small amount appreciated, i'm currently struggling with "underemployment".)
& thanks a lot to the recent supporters!
just found out #Jetbrains IDEs can connect to #Forgejo for time tracking (even though it's not mentioned in the manual page)
💡 Tip: PR the #Forgejo package, so it appears on https://delightful.coding.social/delightful-forgejo
Ach wie schön, man kommt aus dem Urlaub zurück und stellt fest, das der gesamte #Github Account gesperrt ist.
Repositories, wie z.B. https://github.com/jedie/django-reversion-compare sind offline und zeigen nur ein 404...
Alles weg, nur 404. (Hab natürlich backups, lokale Klone und automatisierte Klone in einem privaten #Forgejo )
Hab nicht einmal eine EMail bekommen, mit irgendeinem Hinweis.
Made a small PR towards Forgejo to allow its build on NetBSD (I found out that the pkgsrc-wip contributor is already working on packaging it, but was blocked) and illumos - as these are broken at the moment, in 16.x branch: pretty much dumb adding or removal of type case to int64 in one particular module.
Au moins si #Microslop a vraiment fucked.
J'ai le backup de #github de la boite dans le miroir #forgejo popé en sous marin en dans notre futur kubernetes du DC. (570 repos synchronisés il y a 5h)
😅
I am almost done with a #forgejo based workflow that allows me to export a CSV file with my curated data on Schengen notifications on my laptop, `git commit` that to my repo on Codeberg [1] and then the action kicks in and automatically does everything needed to update my DOI entry at Zenodo [2]. My fear is that when I make that action public, it will be picked up by the AI bros who will use it to flood Zenodo with their weird stuff :(
[1] https://codeberg.org/jwildeboer/SchengenData
[2] https://doi.org/10.5281/zenodo.16883949
One of my repositories on my self-hosted forgejo instance is being hit by Anthropic crawlers. They have an infinite loop to download a tar archive of the repository leading to somewhat like 200GB of archives. My backup process struggled to send snapshots remotely on my 6 Mbps upload line. I've made the repository private. And now I'm considering putting Anubis in front of the service.
Je suis en train d'expérimenter #forgejo pour migrer mon infra de dev de gitlab-ce vers cette solution.
La migration des dépôts gît se fait très facilement, mais par contre celles de gitlab-ci vers les actions forgejo c'est bien compliqué...
+ Pas trouvé comment mettre en place des includes depuis un autre dépôt (j'utilise le même workflow paramétré pour tous mes projets)
+ Pas de clonage sans nodejs (what ?)
Interested in hardening your #forgejo installation? We got a Signal group with people looking at how we can secure the service after installation.
- Settings
- Systemd service file
- File permissions
Want to join and think along or learn along?
https://signal.group/#CjQKIIagtwKpq4DcVo_dehkIPpPK6it6KyYFY0onhB32xbK8EhCElOtUV5YosZ3IL_Lc2iid
I want to run #forgejo (public instance) but at the same time worry about its security. These AI times already show the massive number of vulnerabilities discovered. Especially with more people doing #selfhosting and that a software repository may be a hot target, I would like to see what can be done with system hardening. For example a hardening profile: https://linux-audit.com/systemd/hardening-profiles/
Let's make #selfhosted instances more secure! Want to learn, share, and do this together?
https://signal.group/#CjQKIIagtwKpq4DcVo_dehkIPpPK6it6KyYFY0onhB32xbK8EhCElOtUV5YosZ3IL_Lc2iid
@nixCraft thanks!
Popular amongst the shares: <https://www.reddit.com/r/linux/comments/1v00tfs/flathub_announces_migration_away_from_github_to/>
RE: https://social.tchncs.de/@codefloe/116963861098218609
Although I appreciate what Codeberg does, I also recommend CodeFloe. I've been using it for several months now and it has works flawlessly!
It's particularly suited for your non-Open Source software and they don't have an Anti-AI clause.
Bonus for better uptime in my experience.
Oh, that is a very nice project. The other day I learned that #Forgejo will get native Gists support, a feature I suggested to #Codeberg 5 years ago..
https://codeberg.org/Codeberg/Community/issues/382#issuecomment-19747559
Oh, another good page to consult is the delightful #forgejo curated list with a ton of good resources:
For the #ActivityPub and #ForgeFed implementation the #Forgejo contrib organization on #Codeberg has a separate repository and a roadmap they keep up-to-date. See:
https://codeberg.org/forgejo-contrib/federation/src/branch/main/FederationRoadmap.md
@tomootes @jelte @DigitaleOverheid @Gina
To those not aware I would like to point out two relevant @forgejo locations where contributions can be readily made..
The delightful #forgejo curated list, where #FOSS contributions can be added via a PR or by creating a new issue in the repo's issue tracker:
https://delightful.coding.social/delightful-forgejo/
And the forgejo-contrib organization, where among others the #ActivityPub based forge federation project is taking shape:
https://codeberg.org/forgejo-contrib/federation/
Related to the latter, I'd also like to give attention to the #ForgeFed ActivityPub protocol extension, which is really promising but needs an impetus from the community to bring the specifications to a higher level of maturity, and get good reference implementations to help open standard adoption:
RE: https://fosstodon.org/@Gina/116934380891580389
At the Dutch government we're building a shared code platform based on Forgejo (code.overheid.nl). In my opinion it holds a very big promise because it enables different gov organizations to cooperate. I would also love to have a marketplace to exchange Forgejo actions and by doing this spreading knowledge. So much to build/ think of 🧭
For now we have a very enthusiastic community and it's good to be part of this. The trick will be how to co-operate as we improve the platform.
🫧 Social coding commons boostedRE: https://social.overheid.nl/@codeplatform/116930559753703237
Yesterday we had our second #Codeplatform community meet-up! 🚀
It's been three months since @BZKopensource , @developer and friends launched a gov-wide @forgejo server to move away from Github/Gitlab.
Our community added and prioritized issues to build a roadmap. We'll be funding + developing features around federation, accessibility and security that we will upstream. The top issue (gov-wide SSO) will be fixed next week 🔥
@bo @johan @tomootes @marlenabcn @manfredzielinski @DigitaleOverheid
@badrihippo @praveen @athulvis @double_a_runi @mostlyharmless @guusdk @fossunited @ravi @libreinator @sflcin @untrusem To wind down, we had a panel discussion raising an important point. It is common for FOSS Clubs to rely on proprietary software like #GitHub and #Figma, without it registering that these are nonfree. Panellists exchanged notes about how to raise awareness and minimise their dependence on proprietary software, at least for club-related activities
It was noted that groups like the Free Software Community of India (#FSCI) are already running some alternatives, such as meet.fsci.in for video calls. Raising awareness of existing alternatives to proprietary web platforms, like #Codeberg (powered by #Forgejo) and #Penpot is an important step in this process
Je découvre encore #Forgejo.
Je souhaiterais que tous mes dépôts n'apparaissent pas au même endroit, mais soient, heu… « triés » dans des sous-dossiers, dans l'interface web. Ni sur la page d'accueil, ni sur ma page utilisateur.
Je ne trouve pas comment faire.
Ça se fait ?
Si oui, comment ? 🤔
🇸🇪 boostedYou Can Now Search this Blog
It's approaching 40 seconds #forgejo activity page load time. Would be really great if one could deactivate the activity page somehow, but I don't see a config for this? 🤔
#forgejo q:
So I have my own selfhosted instance now. I don't want others to host their repo's on my instance tbh BUT I do want others to have the ability to create PR's and such... What's the correct way of setting that up then?
A new version of #Forgejo is out 15.0.3
The earlier CVE-2026-27771 is a Gitea bug, and Forgejo was looped into the reporting. However, Packages under a public owner are visible to unauthenticated users by design. If you are publicly hosting, please make sure you understand the permissions model. (see below)
During that CVE stuff, a real authz bypass (any authenticated user could write to public repos they don't own) was fixed in 15.0.1 in May. So jump to 15.0.3 to get all the current security fixes.
Noodling out how to check the permissions (tell me if I'm wrong!!)
curl -s -o /dev/null -w "%{http_code}\n" \
https://<your-forgejo-host>/v2/<owner>/<image>/manifests/<tag>
- 401/404 the access control is enforcing, you're fine.
- 200 with a manifest, you are exposed. Fix it with REQUIRE_SIGNIN_VIEW=true