TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

GitLab Announcing January 16, 2018 Critical Security Update

21 点作者 teoruiz超过 7 年前

4 条评论

AdamJacobMuller超过 7 年前
One thing I&#x27;ll say about GitLab (even if I&#x27;m not its biggest fan) their packaging&#x2F;installation&#x2F;upgrade is absolutely top-notch.<p>I&#x27;ve never seen anyone do it better and I&#x27;ve definitely never seen anyone do it with anywhere near such a complicated set of interrelated moving parts.
评论 #16161632 未加载
jlgaddis超过 7 年前
Well, that doesn&#x27;t sound good at all. Think of all those providers (e.g. DigitalOcean) who offer &quot;one-click&quot; installers for applications like GitLab. Now think about the users who never (or rarely, if they&#x27;re lucky) update those machines. I wouldn&#x27;t be surprised if there&#x27;s a lot of compromised VPSes and such running GitLab later this week.<p>And since one of the big reasons for running your own instance is to protect your private stuff -- things like source code, secrets, credentials, API keys -- it seems to me that this has the potential to be pretty wide-reaching and damaging.<p>So, who here gets to be one of the lucky ones that get to work late Tuesday? :)
mesozoic超过 7 年前
Hopefully they backport it to the versions that still have api v3 support. Otherwise the time window for their deprecation of critical functionality and security updates is way too short.
评论 #16161656 未加载
Rjevski超过 7 年前
Curious to know if this also affects their SaaS offering or if that is already patched.
评论 #16148914 未加载