<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[For @ifin folks, I started a discussion about this on the Discourse here: https:&#x2F;&#x2F;discourse.ifin.network&#x2F;t&#x2F;carrot-disclosure-forgejo&#x2F;]]></title><description><![CDATA[<p class="quote-inline">RE: <a href="https://infosec.exchange/@jvoisin/116488420408417722" rel="nofollow noopener"><span>https://</span><span>infosec.exchange/@jvoisin/1164</span><span>88420408417722</span></a></p><p>For <span><a href="/user/ifin%40infosec.exchange">@<span>ifin</span></a></span> folks, I started a discussion about this on the Discourse here: <a href="https://discourse.ifin.network/t/carrot-disclosure-forgejo/" rel="nofollow noopener"><span>https://</span><span>discourse.ifin.network/t/carro</span><span>t-disclosure-forgejo/</span></a></p><p>My personal thought is that I appreciate, as a defender, knowing this information about a project having a systematic lack of security.</p>]]></description><link>https://board.circlewithadot.net/topic/facbb593-8e43-4f07-8fe6-e46e05ba817b/for-@ifin-folks-i-started-a-discussion-about-this-on-the-discourse-here-https-discourse.ifin.network-t-carrot-disclosure-forgejo</link><generator>RSS for Node</generator><lastBuildDate>Fri, 01 May 2026 11:16:43 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/facbb593-8e43-4f07-8fe6-e46e05ba817b.rss" rel="self" type="application/rss+xml"/><pubDate>Wed, 29 Apr 2026 17:47:14 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to For @ifin folks, I started a discussion about this on the Discourse here: https:&#x2F;&#x2F;discourse.ifin.network&#x2F;t&#x2F;carrot-disclosure-forgejo&#x2F; on Wed, 29 Apr 2026 18:33:44 GMT]]></title><description><![CDATA[<p><span><a href="/user/cxiao%40infosec.exchange">@<span>cxiao</span></a></span> <span><a href="/user/kouhai%40social.treehouse.systems">@<span>kouhai</span></a></span> <span><a href="/user/ifin%40infosec.exchange">@<span>ifin</span></a></span> oh, so this is not a researcher but a malicious party? Then we should prosecute them!</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/oilheap/statuses/116489428986704995</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/oilheap/statuses/116489428986704995</guid><dc:creator><![CDATA[oilheap@infosec.exchange]]></dc:creator><pubDate>Wed, 29 Apr 2026 18:33:44 GMT</pubDate></item><item><title><![CDATA[Reply to For @ifin folks, I started a discussion about this on the Discourse here: https:&#x2F;&#x2F;discourse.ifin.network&#x2F;t&#x2F;carrot-disclosure-forgejo&#x2F; on Wed, 29 Apr 2026 18:16:26 GMT]]></title><description><![CDATA[<p><span><a href="/user/cxiao%40infosec.exchange">@<span>cxiao</span></a></span> <span><a href="/user/oilheap%40infosec.exchange">@<span>oilheap</span></a></span> <span><a href="/user/ifin%40infosec.exchange">@<span>ifin</span></a></span> one of the objections I’ve seen is “carrot disclosure doesn’t work when you’re punching downwards or sideways”/ “what additional resources can a volunteer-based project apply?”</p><p>(not focusing on the other objections, because I don’t want to retread the productive discussion from earlier)</p>]]></description><link>https://board.circlewithadot.net/post/https://social.treehouse.systems/users/kouhai/statuses/116489360908915026</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.treehouse.systems/users/kouhai/statuses/116489360908915026</guid><dc:creator><![CDATA[kouhai@social.treehouse.systems]]></dc:creator><pubDate>Wed, 29 Apr 2026 18:16:26 GMT</pubDate></item><item><title><![CDATA[Reply to For @ifin folks, I started a discussion about this on the Discourse here: https:&#x2F;&#x2F;discourse.ifin.network&#x2F;t&#x2F;carrot-disclosure-forgejo&#x2F; on Wed, 29 Apr 2026 18:14:19 GMT]]></title><description><![CDATA[<p><span><a href="/user/cxiao%40infosec.exchange" rel="nofollow noopener">@<span>cxiao</span></a></span> <span><a href="/user/kouhai%40social.treehouse.systems" rel="nofollow noopener">@<span>kouhai</span></a></span> I can understand the negative reaction; telling a well-respected and very open source project “you have serious issues but I’m not going to tell you what they actually are” without any attempt to actually flag the issues to them is… not great? it’s not like this is a company that can bring in someone to audit the code, it’s an open source project that would love to fix the issues but is resource constrained by virtue of being an open source project </p><p>it’s an inherently aggressive approach to disclosure and it doesn’t come off as “helpful” nearly as much as “condescending”, and while that’s one thing to direct at a corporation…</p>]]></description><link>https://board.circlewithadot.net/post/https://unstable.systems/users/demize/statuses/116489352577702955</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://unstable.systems/users/demize/statuses/116489352577702955</guid><dc:creator><![CDATA[demize@unstable.systems]]></dc:creator><pubDate>Wed, 29 Apr 2026 18:14:19 GMT</pubDate></item><item><title><![CDATA[Reply to For @ifin folks, I started a discussion about this on the Discourse here: https:&#x2F;&#x2F;discourse.ifin.network&#x2F;t&#x2F;carrot-disclosure-forgejo&#x2F; on Wed, 29 Apr 2026 18:05:29 GMT]]></title><description><![CDATA[<p><span><a href="/user/kouhai%40social.treehouse.systems" rel="nofollow noopener">@<span>kouhai</span></a></span> <span><a href="/user/oilheap%40infosec.exchange">@<span>oilheap</span></a></span> <span><a href="/user/ifin%40infosec.exchange">@<span>ifin</span></a></span> TY! I'm a little surprised by the extreme negative reactions to this TBH. From the perspective of being a Forgejo or other OSS maintainer it sucks to see this. But at the end of the day attackers don't care and aren't going to tell you in this way, or any way, that you have serious issues</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/cxiao/statuses/116489317849431583</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/cxiao/statuses/116489317849431583</guid><dc:creator><![CDATA[cxiao@infosec.exchange]]></dc:creator><pubDate>Wed, 29 Apr 2026 18:05:29 GMT</pubDate></item><item><title><![CDATA[Reply to For @ifin folks, I started a discussion about this on the Discourse here: https:&#x2F;&#x2F;discourse.ifin.network&#x2F;t&#x2F;carrot-disclosure-forgejo&#x2F; on Wed, 29 Apr 2026 18:02:16 GMT]]></title><description><![CDATA[<p><span><a href="/user/oilheap%40infosec.exchange">@<span>oilheap</span></a></span> <span><a href="/user/cxiao%40infosec.exchange">@<span>cxiao</span></a></span> <span><a href="/user/ifin%40infosec.exchange">@<span>ifin</span></a></span> for what it’s worth, we (treehouse staff and community) had a productive discussion with the author on discord; hopefully further updates will trickle out over the next days</p>]]></description><link>https://board.circlewithadot.net/post/https://social.treehouse.systems/users/kouhai/statuses/116489305250447594</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://social.treehouse.systems/users/kouhai/statuses/116489305250447594</guid><dc:creator><![CDATA[kouhai@social.treehouse.systems]]></dc:creator><pubDate>Wed, 29 Apr 2026 18:02:16 GMT</pubDate></item><item><title><![CDATA[Reply to For @ifin folks, I started a discussion about this on the Discourse here: https:&#x2F;&#x2F;discourse.ifin.network&#x2F;t&#x2F;carrot-disclosure-forgejo&#x2F; on Wed, 29 Apr 2026 17:57:27 GMT]]></title><description><![CDATA[<p><span><a href="/user/cxiao%40infosec.exchange">@<span>cxiao</span></a></span> <span><a href="/user/ifin%40infosec.exchange">@<span>ifin</span></a></span> "carrot disclosure" wtf. This is not the most stupid thing I've seen this week, but it's up there. This helps nobody and only inflates the ego of the researcher. The fact that they considered "sellability" of these issues already gives enough insight.</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/oilheap/statuses/116489286312458649</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/oilheap/statuses/116489286312458649</guid><dc:creator><![CDATA[oilheap@infosec.exchange]]></dc:creator><pubDate>Wed, 29 Apr 2026 17:57:27 GMT</pubDate></item></channel></rss>