Hacker Newsnew | past | comments | ask | show | jobs | submit | latchkey's commentslogin

If everyone moves off GH, it'll just go back to normal again?

People keep wanting to replace GitHub, but with what?

If GH is getting RCE's this late in the game who wants to take the chance something else won't?


A "reasonable" answer is probably a primary self-hosted Forgejo instance as the canonical forge, while using GitHub as a mirror solely to take advantage of its free CI, while that lasts, while hosting secrets with a dedicated secret-hosting provider (I don't know what the provider du jour for this is these days).

> solely to take advantage of its free CI, while that lasts

Eh, if you want to be able to continue working, deploy and what not as normal during weekdays, I'd suggest also moving to Forgejo Actions if you're moving anyways. Not 100% compatible, but more or less the same, and even paying the same but with dedicated hardware you'd get way faster runners.


For companies with resources for infrastructure, sure.

For OSS, the unlimited free minutes of multiplatform CI offered by GitHub are literally impossible to replace. Maintaining runners yourself to do the same things would be somewhere between a part- and full-time job.


> For OSS, the unlimited free minutes of multiplatform CI offered by GitHub are literally impossible to replace.

Yeah, how you think the ecosystem got by before GitHub even had actions? Y'all don't remember Travis CI et al anymore?

There are more CI services than what Microsoft offers the world, sometimes it's worth looking around a bit.


> https://docs.codeberg.org/ci/

"Codeberg is a non-profit, community-led effort that provides services to free and open-source projects, such as Git hosting (using Forgejo), Pages, CI/CD and a Weblate instance."

Never say impossible.

Github is still "new" to a lot of us. OSS existed well before it, and will continue to exist well after.


If Codeberg starts offering Mac and Windows runners alongside their Linux ones for free (or at an achievable price point) for a modest OSS project I'll certainly look at it very closely. If all I needed was a Linux runner, I'd probably be on there already.

And yes, if we make OSS just about hosting the code, things are much simpler. If you're a piece of desktop software though, and you have users, they'll typically (and reasonably) want auditable signed binaries on all the platforms you support, which requires multiplatform CI.


Replace a whole 24/7 team of devops people with myself?

As much as I'd like to believe that I'm worthy, I'm not.


It's the devops team can manage a measly 87% uptime [1] you're talking about, you can do a lot better on your homeserver.

[1]: https://mrshu.github.io/github-statuses/


If the primary forge's only job is to host the actual Git infrastructure (the code, the MRs, the issues, maybe a wiki), it's a lot more simple than GitHub, and probably more within the scope of what people can reasonably administer themselves.

I hosted the first "java.apache.org". I was an early employee at CollabNet, and in the first discussions around starting subversion. I worked on Cloud Foundry.

This stuff isn't easy and I'm more than happy letting someone else do it at the expense of some downtime.


24/7 devops team for a forgejo instance? Come on mate...

24/7 devops team for github? Come on mate...

Is running a small forgejo instance for a team the same as running GitHub?

Will I have to patch machines, keep packages updated, deal with SSL certs, maintain action runner infra, deal with billing for the machines, add monitoring, alerts, logging, etc

No, I don't want to be in the business of running my own Github clone. That's what I pay Github for.

Why do you pay salary to employees to buy food when you can just run a farm next to the office and save money by operating the farm and giving the employees food directly? You'd save money by not having to pay as high of salaries, and farms don't even need 24/7 devops teams.


Don't you think the farm example was a bit too extreme for it to make sense? A tech company probably does not have expertise in farming but devOps is something they already know how to do and can easily manage it in-house. Also how fast do you think farms produce food that you can drip feed it to employees constantly

We moved from github to a self-hosted forgejo instance about 6 months ago, works like a charm. Still can't belive how snappy forgejo is / laggy github has become


I am personally now drawing a clear delineation between projects for my internal consumption (e.g. ansible scripts) and projects that have potential use for the general populace. For the prior, I now host a private Forgejo instance. For the latter, I'll put it on GitHub but mirror it to my Forgejo instance.

I was pleasantly shocked that Forgejo is literally a single binary with a relatively easy config. All my internal services reference my Forgejo instance so, if I need to bail on GitHub, it's low friction for me.


Self hosted gitlab behind a VPN.

The all-in-docker image and a couple of gitlab runners is all small to medium sized teams need. (Don't overcomplicate it with the kubernetes version unless you really need it)



GitLab ?

Me and my friends call it CveLab because there was a time where there was a critical security update every week or multiple times a week.

The people who suggest gitlab, haven't used it. But I guess I could be tempted to try again...

https://status.gitlab.com/pages/history/5b36dc6502d06804c083...


If you could only choose from github, gitlab and atlassan then I suppose.. But really anything newer that stays in existance has to be focused on quality from early enough to not be defined by path dependence problems and bad choices like those 3.

Given that github is imploding under a lot of load, everyone leaving github for something else, actually makes github better.

Ah, you assumed I meant SaaS GitLab. I meant the self-hosted version. I would never host our source code on a remote service.

Why not?

Because I don't trust someone else to not train or steal our source code, or, even legally, introduce some silly cause after we are invested/locked into their infra, that allows them to do whatever with our property.

And on equal footing, I trust our security more than theirs. Case in point.


just git

.... git?

replace it with git.

if you want a whole ui you can use something like forgejo which has far fewer features likely leading to less issues.


You probably meant Forgejo. Codeberg is a Forgejo instance exclusive for FOSS projects.

i want what github offers.

Enjoy your experience, there will certainly be no end to it.

I've had my account since 2008. ¯\_(ツ)_/¯

updated: changed the date to 2008.

my account shows 2001, but that's probably from projects I moved over... proof: https://github.com/lookfirst


GitHub launched in 2008, so that seems unlikely?

Just be careful your patronage doesn't lead to a sunk cost fallacy---a middle manager might just be betting on it

I have no ingrained loyalty, I just haven't found something better.

i just deleted my account of 2008. github sucks

You mention rocm-smi in your blog post, but you don't actually support AMD gpus?

AMD support is on the roadmap, but we mentioned it for now to highlight that AMD calculates their utilization metric the same way -- it's not just NVIDIA.

I like having control over my backups.

I've been working on improving an open source menubar that wraps restic. Right now it is a bit rough around the edges, but my plan is to have a simple onboarding experience for various backend services like B2.

Over the weekend, I added a "Smart backups" feature that uses all the same directories that the backblaze menubar app and timemachine excludes. This was the primary missing feature for me. It even generates and backups your Brewfile...

https://github.com/lookfirst/ResticScheduler


I wanted to buy a domain that was under GoDaddy's control.

We agreed on a price.

I sent the money (not cheap).

Weeks went by and then they emailed me to say that the person they thought owned the domain didn't actually own it.

Mind you, this is a domain that was hosted on their service.

The broker started to ignore me, since his job was done.

It took about 4-5 months and a huge amount of harassment at multiple support levels to get my money back.

Net negative for the internet.


> I know this is a nice factoid that does not need to be true. When I was 13 I did believed it, so now days I try to not spread this factoid.

I took it as sarcasm.


Correct.

I'll add this to Orange Juice soon too.

You should just submit a PR to OJ.

https://github.com/OrangeJuiceExtension/OrangeJuice/issues/3


Awesome!

If one other person uses it, it is good enough for me.

If you use it and want more features, post in the issue queue or respond to one of my comments -- I'll get it.

The engine that makes the requests and does the logic is agnostic and probably is portable copy and paste into your project. The one thing I have are all the tests and red team adversary agents that do very well to surface bugs.


This place sucks, don't come here.

https://x.com/HotAisle/status/2046792071521157600 (taken tonight)


I mean it’s just a sunset on some sand. You can get that all the way from Chile to Alaska, not a big deal.

This is a massive speed up and entirely open source!


Consider applying for YC's Summer 2026 batch! Applications are open till May 4

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: