frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Carrot Disclosure: Forgejo

https://dustri.org/b/carrot-disclosure-forgejo.html
46•bo0tzz•1h ago

Comments

dangus•21m ago
The author's attitude is so off-putting. What gives? Did Forgejo hurt you?

The Forgejo disclosure process looked pretty simple and straightforward to me. The bold and all-caps words that bothered the author are just making sure you know how to disclose vulnerabilities safely without leaking zero-day exploits to a wider audience than necessary.

I'm also not impressed with a carrot disclosure that looks like this. Running a python script to compromise a locally hosted instance? Bruh, you have physical hardware and host shell access. That python script could be doing anything including running as root.

Show us the exploit hitting a remote server.

shimman•7m ago
Seriously, this author comes across as an absolute sore loser if this is the PR they are referring too:

https://codeberg.org/forgejo/forgejo/pulls/12283

Someone asking you to write a test for new code and then making this blog in response is just so pathetic.

unethical_ban•21m ago
From a linked PR (related to this RCE?), from a maintainer who closed it:

>Just thinking something not being used is not enough, even if it's a security sensitive topic

Linux kernel seems to disagree. This is a dangerously naive way to think of networked software in the AI age.

---

edit: I got hit with the "posting too fast" block again, so I'll reply to dangus here:

>While a remote host would further prove the claim, the person clearly claims it is RCE, not just CE. It would be quite the pie in the face if the author wrote a python script to take in an IP address but modified system files on the backend to create a stunt.

dangus•2m ago
It would definitely be a bit silly for the author to make a fake carrot disclosure, but I thought of it just because of how reading this article made me feel distrust toward the author. IDK, they just seem like kind of a jerk!

Now, I don't think the PRs with the Forgejo folks show a lot of warm collaborative energy on their side, either, but I can see how soft skills from the author would likely have taken their PRs a lot further in getting what they want.

But the author's whole attitude is that Forejo is such a mess and it's barely worth their time to try and clean it up. Nobody's twisting their arm to contribute to an open source project that they don't even like!

From the perspective of Forgejo maintainers, the author is just some random new contributor barging in and telling them to drop some legacy support that hasn't been discussed in detail yet. And of course, this new contributor hasn't actually followed the security policy to disclose it as a high severity issue to justify the change.

000ooo000•13m ago
Hopefully someone a little more.. pragmatic gets eyes on that linked PR.
preinheimer•6m ago
There’s an old cryptography story.

A cryptographer friend tells the story of an amateur who kept bothering him with the cipher he invented. The cryptographer would break the cipher, the amateur would make a change to “fix” it, and the cryptographer would break it again. This exchange went on a few times until the cryptographer became fed up. When the amateur visited him to hear what the cryptographer thought, the cryptographer put three envelopes face down on the table. “In each of these envelopes is an attack against your cipher. Take one and read it. Don’t come back until you’ve discovered the other two attacks.” The amateur was never heard from again.

https://www.schneier.com/crypto-gram/archives/1998/1015.html

neilv•1m ago
And if you are a dishonest cryptographer, you only need to find one attack to pull this off.

Claude for Creative Work

https://www.anthropic.com/news/claude-for-creative-work
1•elsewhen•4m ago•0 comments

GameNova – Turn text prompts into playable 3D games in 60 seconds

https://www.gamenova.io
1•Taskclan•5m ago•0 comments

Show HN: Niimbot Label Printer desktop app with Pretix integration

https://github.com/ooguz/niimbot-printer
1•m3rcury•7m ago•0 comments

Apple Colour Matching Functions Article by LTTLabs

https://www.lttlabs.com/articles/2026/04/11/apple-studio-display-xdr-display-testing-results
1•HeyMeco•7m ago•0 comments

A Milestone in Formalization: The Sphere Packing Problem in Dimension 8

https://www.alphaxiv.org/abs/2604.23468
1•measurablefunc•8m ago•0 comments

Proxies, Sandboxes and Agent Security

https://www.gouthamve.dev/proxies-sandboxes-and-agent-security/
2•gouthamve•10m ago•0 comments

My Login Shell in Assembly

https://isene.org/2026/04/Bare.html
1•birdculture•11m ago•0 comments

VibeBench: Measuring 1k Engineers' Opinions of New Models

https://vibebench.standardagents.ai/
4•jpschroeder•14m ago•2 comments

From spaghetti to main bus: refactoring an AI agent orchestrator with Elm

https://blog.mariohayashi.com/p/the-factory-must-grow-part-ii-from
1•mhay•16m ago•0 comments

Show HN: 49Agents – 2D Canvas IDE for Orchestrating Agents, Repos, Issues

https://github.com/49Agents/49Agents
1•alpadurza•17m ago•0 comments

For SF's public defenders, resistance is the new black

https://sfstandard.com/2026/04/27/public-defenders-wear-all-black-protest/
1•iancmceachern•18m ago•0 comments

The lamps you're not allowed to have. Exploring the Dubai lamps (2021) [video]

https://www.youtube.com/watch?v=klaJqofCsu4
2•bb88•19m ago•0 comments

Joby flies first point-to-point air taxi flight tests in New York

https://www.reuters.com/business/aerospace-defense/joby-flies-first-point-to-point-air-taxi-fligh...
1•canucker2016•19m ago•0 comments

An open-source platform to auto-update agent skills and discover fresh sources

https://www.loooop.dev/
1•kl01•23m ago•0 comments

Redmine

https://www.redmine.org/
1•tamnd•24m ago•0 comments

A persistent Unix-like ESP8266 system with more that 70 console commands

https://github.com/hery-torrado/KernelESP
2•herytorrado•29m ago•1 comments

Client side search and recommendation with TurboQuant

https://h3manth.com/ai/cinematch/
1•init0•31m ago•0 comments

There's a Good Reason You Can't Concentrate

https://www.nytimes.com/2026/03/27/opinion/technology-mental-fitness-cognitive.html
1•philip1209•32m ago•0 comments

The Secret Group Chats Fueling MAGA's Messaging Machine

https://slate.com/technology/2026/04/trump-ballroom-ashley-st-clair-maga.html
3•JojoFatsani•32m ago•0 comments

Victory in FOIA Against Twelve South for PlugBug 120W Electrical Info

https://archive.org/details/pb120-us
1•birdculture•35m ago•0 comments

What Are OPEC+'s Fiscal Breakeven Oil Prices Telling Us?

https://economics.bmo.com/en/publications/detail/141134d9-5322-4b04-bf49-2c3e6088115a/
1•JumpCrisscross•37m ago•0 comments

Canada govt plans crypto ATM ban to stop scammers from defrauding Canadians

https://www.cbc.ca/news/canada/toronto/canada-crypto-atm-ban-scammers-9.7180642
3•canucker2016•42m ago•1 comments

The Revealing Summary Reversal in LULAC

https://www.stevevladeck.com/p/223-the-revealing-summary-reversal
2•hn_acker•44m ago•1 comments

Claude-multiprofile: run multiple Claude accounts side by side on macOS

https://github.com/jmdarre-v/claude-multiprofile
3•jmd7•45m ago•0 comments

Asimov, an open source tsla humanoid

https://github.com/asimovinc/asimov-v1
3•ElasticBottle•47m ago•0 comments

SubmitYourWork – Submit your startup to directories from one place

https://github.com/Sketchjar/submityourwork
2•gcsydney•48m ago•0 comments

Couples Wanted to Have Children. Rising Costs Are Stopping Them

https://www.nytimes.com/2026/04/26/business/children-rising-costs.html
2•lando2319•51m ago•2 comments

Ask HN: Can we just call them "Harness Gloves"?..and an App Store model?

2•lowoxidizer•51m ago•0 comments

The 3-character kernel patch that tamed the OOM killer for Postgres

https://www.ubicloud.com/blog/postgresql-and-the-oom-killer-why-we-use-strict-memory-overcommit
3•mustpax•51m ago•0 comments

Super Zsnes: GPU Powered SNES Emulation

https://www.youtube.com/watch?v=r5twUkvYFpA
4•kjeetgill•52m ago•0 comments