top 21 comments

sorted by: hot top controversial new old
[–] 78 points 3 years ago (1 child)

Thanks for releasing it so quickly!

This "sunaruas" sounds like a cool guy 😛

  • source
  • hideshow 2 child comments
  • [–] 37 points 3 years ago (1 child)

    Glad to see Lemmy is responding quick to exploits. Does Lemmy have a plan to prevent any other exploits that may be lying around such as a routine security audit?

  • source
  • hideshow 2 child comments
  • [–] [S] 70 points 3 years ago (1 child)

    All the code is open source, everyone is welcome to look through it for potential problems and report/fix them. we dont have any money to pay for a professional audit. Maybe there are some organizations which would do audits of open source projects for free, might be worth searching for.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 25 points 3 years ago (2 children)

    We use sonarqube for code analysis that is pretty nice and has a community edition. It isn't a bullet proof solution, but it is pretty convenient for maintainers and reviewers of PRs. The only thing missing from the enterprise edition are useless flashy dashboards to show to people who don't understand computers

  • source
  • parent
  • hideshow 4 child comments
  • [–] 10 points 3 years ago (3 children)

    I do have a Sonarqube server somewhere around. Is it considered an annoying behavior to scan an open source project and open issues for others to fix?

  • source
  • parent
  • hideshow 6 child comments
  • [–] [S] 23 points 3 years ago (1 child)

    That depends, it would be annoying if you open lots of issues for minor, unimportant issues. But if you find a few major problems its good to report them. Of course its always ideal if you submit fixes as well, because there are never enough devs.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 17 points 3 years ago (1 child)

    Given that the exploit was literally yesterday, you guys are damn fast!

  • source
  • hideshow 2 child comments
  • [–] 9 points 3 years ago

    Thanks for the prompt fixes

  • source
  • [–] 5 points 3 years ago

    Thank you for reacting so quickly!

  • source
  • [–] 5 points 3 years ago

    and docker images for arm64 are ready as well :)

  • source
  • [–] 3 points 3 years ago
    [–] 1 point 3 years ago

    is it me or front is broken?

  • source
  • [–] 1 point 3 years ago

    Thanks for the quick update on this!

  • source
  • [–] 1 point 3 years ago

    Hey one quick question.. the Ansible playbook doesn't look like it's been updated to 0.18.2 or at least the instructions don't state how to pull it. Any chance this could get fixed/clarified in the release notes?

  • source
  • load more comments
    view more: next ›