> This release contains security fixes. To give everyone time to upgrade, details will be added to this post in about a week.
Is this something that has been happening for a while or a new trend due to LLM concerns? I understand the reasoning, it just made me do a double take because I haven't really seen that before.
QuantumNomad_•16m ago
With Gitea specifically or in general? A lot of different software has silently included security fixes in updates combined with other changes and then later revealed what security fixes were made or stayed quiet about it all together, since long before LLMs could analyze changes.
Security researchers and malware authors would reverse engineer software updates of proprietary software, and scrutinise source code changes of open source projects to find secretly shipped security fixes.
stackghost•16m ago
Bizarre policy. Any bad guys unaware of the security implications are analyzing the patch diffs as we speak, so this seems nonsensical to me.
IshKebab•14m ago
Yeah maybe it made sense in the past, but not in the age of AI.
MitPitt•36m ago
they skipped 26 major versions, ai is truly amazing
layer8•35m ago
> Gitea drops the historical 1. prefix from its version numbers, so this release is 28.0.0 rather than 1.28.0.
wasting_time•33m ago
For anyone curious why they should choose one over the other:
Thanks! Currently going through this decision process myself.
GrayShade•25m ago
I suggest browsing through the release notes of the last 4-5 versions to see what you like more.
tjoff•13m ago
I'd argue project values, license and health are way more important.
nightpool•9m ago
Unfortunately, seems like this is Forgejo's best suggestion on how to compare the two: https://i.imgur.com/j1665QR.png. Not sure that page helps much if you're not already bought in to a free-software-absolutist mindset
godbox•18m ago
Holy shit. They went from 1.27.3 to 28.0.0. These guys are hauling ass
LoganDark•17m ago
They're even ahead of Apple. macOS 27? Nah, how about Gitea 28?
ThePinion•38m ago
Is this something that has been happening for a while or a new trend due to LLM concerns? I understand the reasoning, it just made me do a double take because I haven't really seen that before.
QuantumNomad_•16m ago
Security researchers and malware authors would reverse engineer software updates of proprietary software, and scrutinise source code changes of open source projects to find secretly shipped security fixes.
stackghost•16m ago
IshKebab•14m ago