TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

GitLab Announcing January 16, 2018 Critical Security Update

21 pointsby teoruizover 7 years ago

4 comments

AdamJacobMullerover 7 years ago
One thing I&#x27;ll say about GitLab (even if I&#x27;m not its biggest fan) their packaging&#x2F;installation&#x2F;upgrade is absolutely top-notch.<p>I&#x27;ve never seen anyone do it better and I&#x27;ve definitely never seen anyone do it with anywhere near such a complicated set of interrelated moving parts.
评论 #16161632 未加载
jlgaddisover 7 years ago
Well, that doesn&#x27;t sound good at all. Think of all those providers (e.g. DigitalOcean) who offer &quot;one-click&quot; installers for applications like GitLab. Now think about the users who never (or rarely, if they&#x27;re lucky) update those machines. I wouldn&#x27;t be surprised if there&#x27;s a lot of compromised VPSes and such running GitLab later this week.<p>And since one of the big reasons for running your own instance is to protect your private stuff -- things like source code, secrets, credentials, API keys -- it seems to me that this has the potential to be pretty wide-reaching and damaging.<p>So, who here gets to be one of the lucky ones that get to work late Tuesday? :)
mesozoicover 7 years ago
Hopefully they backport it to the versions that still have api v3 support. Otherwise the time window for their deprecation of critical functionality and security updates is way too short.
评论 #16161656 未加载
Rjevskiover 7 years ago
Curious to know if this also affects their SaaS offering or if that is already patched.
评论 #16148914 未加载