50 Commits
Author SHA1 Message Date
humanacollaborator f2d2d47a2a add onion for nixnet; update status of other nodes 2026-03-22 21:03:36 +01:00
humanacollaborator 906660283e updated versions and statuses 2026-03-17 13:52:38 +01:00
humanacollaborator 2785061d04 added some onions 2026-03-15 15:57:32 +01:00
humanacollaborator 044e5254fd added the first Forgejo instance (a gitea fork used in German schools) 2023-11-23 10:33:03 +01:00
humanacollaborator f8c4c0814c mention github to gitea mirror tool 2023-10-01 11:23:45 +02:00
humanacollaborator 3dec4ead0e MS Copilot violates FOSS licensing & GH suppresses bug reports 2022-12-30 11:05:28 -05:00
humanacollaborator 86e4d0614d add section about the Give-Up Github campaign 2022-12-18 13:37:58 -05:00
humanacollaborator 1b8ac98a17 fix comments 2022-12-17 10:09:00 -05:00
humanacollaborator 3261814490 Add 0xacab.org and fix links 2022-12-17 10:05:20 -05:00
humanacollaborator 8833025817 Graylist openprivacy.ca 2022-10-13 16:39:01 +02:00
humanacollaborator 34aa2b960a fix link 2022-10-13 16:32:18 +02:00
humanacollaborator f5a2b5f951 fix link 2022-10-13 16:30:00 +02:00
humanacollaborator cdc06a748a fix openprivacy.ca 2022-10-13 16:27:40 +02:00
humanacollaborator 188a22efb7 openprivacy.ca actually supports Tor (just uses the flawed onion-location redirect) 2022-10-13 16:24:48 +02:00
humanacollaborator a30d94b122 add slipfox, rm slashdev, note that openprivacy.ca violates the GPL 2022-10-13 11:16:53 +02:00
humanacollaborator 0767e6c970 human rights focused forge open for reg. again 2022-10-02 23:02:09 +02:00
humanacollaborator e18463b365 updated onion for fuwafuwa.moe 2022-10-02 22:54:49 +02:00
humanacollaborator 22a849ed7d added gitea onion instance 2022-09-29 22:17:58 +02:00
humanacollaborator 130b53ab00 Gitlab rolls out more “features” to track users with FLoC. 2022-08-17 19:16:44 +02:00
humanacollaborator b031de5a25 fix table 2022-07-19 08:47:30 +02:00
humanacollaborator 3d036b2add rm label for whitelist 2022-07-17 20:06:53 +02:00
humanacollaborator b723d6f760 git.platypush.tech added to whitelist 2022-07-16 20:35:45 +02:00
humanacollaborator 90e7ea17db mypdns back online but accounts and repos mysteriously gone 2022-07-16 20:23:05 +02:00
humanacollaborator 78d87cbea6 forges using CF DNS properly tagged 2022-07-16 20:13:53 +02:00
humanacollaborator 8753b449e0 forges using CF DNS graylisted 2022-07-16 20:07:43 +02:00
humanacollaborator 24c13f0a34 exozy.me silently deletes repositories without notice 2022-07-15 15:45:43 +02:00
humanacollaborator 45e420686b added warning labels for higher versions of gitea 2022-07-12 07:33:37 +02:00
humanacollaborator eff0719ffa added git.exozy.me, which demonstrates federated issues for the 1st time 2022-07-12 07:20:32 +02:00
humanacollaborator fb2bea2119 Gitlab EE FOSSness uncertain; MS acquired Xandr from AT&T 2022-06-23 08:58:28 +02:00
humanacollaborator e84272797d graylisted forge.chapril.org 2022-04-28 09:31:08 +02:00
humanacollaborator 73c3dc4489 update graylist rationale 2022-04-27 09:51:24 +02:00
humanacollaborator 00fe4c3244 git.passageenseine.fr back up 2022-04-27 09:45:52 +02:00
humanacollaborator 596b21cea9 update warnings 2022-04-27 09:39:22 +02:00
humanacollaborator 9552e3d311 mypdns died; added gitnet.fr 2022-04-27 09:22:41 +02:00
humanacollaborator d200bea337 added git.kescher.at and git.redxen.eu 2022-04-04 11:42:14 +02:00
humanacollaborator c2d6678738 mypdns.org is gitlab ee 2022-03-19 20:57:08 +01:00
humanacollaborator 4fb27dd920 added mypdns.org 2022-03-19 20:16:53 +01:00
humanacollaborator 9bd241330f added git.pofilo.fr 2022-03-01 22:40:53 +01:00
humanacollaborator 9d9f9893dd Sourceforge takes an ethical stance against Cloudflare (yay!) 2021-12-08 09:09:08 +01:00
humanacollaborator b773c7d4db update deCloudflare link 2021-11-30 10:42:11 +01:00
humanacollaborator 2ca628956e Sourcehut deployed an IRC bouncer 2021-11-30 10:24:35 +01:00
humanacollaborator 92110459f0 added updated gitea versions 2021-11-29 22:53:07 +01:00
humanacollaborator 94ddc404d1 added git.eta.st, removed redundancy from gitlab-dot-com.md 2021-11-29 22:19:17 +01:00
humanacollaborator 52c6f6d17b add stux.host 2021-07-21 09:30:59 -04:00
humanacollaborator 21af0dda8e netlandish registration is closed 2021-07-19 19:45:14 -04:00
humanacollaborator c5a2f08c46 Add note stating forge.april.org is for www.april.org members 2021-07-19 19:20:35 -04:00
humanacollaborator 0c8f6d0470 Marked forge.april.org as closed due to not having a registration form. 2021-07-19 19:06:12 -04:00
humanacollaborator 49588fb15d Added forge.april.org to the SQL file and re-generated 2021-07-19 19:03:58 -04:00
humanacollaborator bf399e6753 Merge pull request 'added April.org public forge' (#6) from dachary/humanacollabora:wip-april into master
Reviewed-on: humanacollaborator/humanacollabora#6
2021-07-19 22:55:01 +00:00
dachary 9c74489730 added April.org public forge 2021-07-20 00:09:15 +02:00
5 changed files with 171 additions and 97 deletions
+48 -31
View File
@@ -1,53 +1,71 @@
[//]: # (** DO NOT EDIT this file directly! ** It is auto-generated. Changes should be made to financial_institutions.sql or gen_forge_table.sh instead.)
# Directory of forges
## Whitelist
The following forges have no significant ethical issues:
| *forge* | *registration publicly open* | *software* | *Tor-hostile* | *Cloudflare MitM* | *forced re/hCAPTCHA* | *forced execution of non-free software* | *notes* |
|---|---|---|---|---|---|---|---|
[sloyd.work](https://sloyd.work)|❌|Forgejo 1.19.0-2|n|n|n|n||
[git.nixnet.services](https://git.nixnet.services)([onion](http://qt5vr747phiq55ubqip4hflmpygzl374mum2zbyqdxg6sqbngmzlqhid.onion/))|✅|Forgejo 1.21.11+1|n|n|n|n|formerly git.nixnet.xyz; served from Finland.|
[git.disroot.org](https://git.disroot.org)([onion](http://kgtz2pmmov5jfvn3z4mqryffjnnw6krzrgxxoyaqhqckjrr4pckyhsqd.onion))|✅|Forgejo 14.0.2|n|n|n|n|SSH over Tor works; based in NL; onion down|
[git.platypush.tech](https://git.platypush.tech)|❌|Forgejo 14.0.2|n|n|n|n||
[git.redxen.eu](https://git.redxen.eu)|❌|Forgejo 14.0.2|n|n|n|n||
[git.pofilo.fr](https://git.pofilo.fr)|❌|Forgejo 14.0.3|n|n|n|n|no registration link|
([onion](http://gg6zxtreajiijztyy5g6bt5o6l3qu32nrg7eulyemlhxwwl6enk6ghad.onion))|✅|Gitea|n|n|n|n|Focused on human rights. Goes by the name RightToPrivacy. Dysfunctional for git operations (both SSH and HTTP).|
([onion](http://it7otdanqu7ktntxzm427cba6i53w6wlanlh23v5i3siqmos47pzhvyd.onion))|✅|Gitea|n|n|n|n|graphical CAPTCHA imposed just to sign in! Calls itself “Darktea”|
[git.fsfe.org](https://git.fsfe.org)|✅|Gitea|n|n|n|n|Access intended only for FSFE projects and very small projects; SSH port: 22|
[de.edumat.io](https://de.edumat.io)|✅|Gitea 1.5.2|n|n|n|n|no SSH|
[git.fuwafuwa.moe](https://git.fuwafuwa.moe)([onion](http://git.fuwafuwaqtlkkxwc.onion))|✅|Gitea 1.13.6|n|n|n|n|SSH port: 22; SSH over Tor [broken](http://git.fuwafuwaqtlkkxwc.onion/levena/fuwafuwa/issues/1); HTTPS over Tor works|
[git.slashdev.space](https://git.slashdev.space)||Gitea 1.13.6|n|n|n|n|SSH port: 22; SSH over Tor broken (try HTTPS over Tor)|
[opendev.org](https://opendev.org)||Gitea 1.13.7|n|n|n|n|SSH port: 22|
[dev.sum7.eu](https://dev.sum7.eu)|✅|Gitea 1.14.0[⚠][gitea-bug]|n|n|n|n||
[git.nixnet.services](https://git.nixnet.services)|❌|Gitea 1.14.1[⚠][gitea-bug]|n|n|n|n|formerly git.nixnet.xyz|
[git.safemobile.org](https://git.safemobile.org)|✅|Gitea 1.14.1[⚠][gitea-bug]|n|n|n|n||
[git.disroot.org](https://git.disroot.org)|✅|Gitea 1.14.2[⚠][gitea-bug]|n|n|n|n|SSH over Tor works; based in NL|
[git.nogafam.es](https://git.nogafam.es)([onion](http://git.hsdtecd4h2b5z732pvkg2yw3746epap4qusgvjjze6nhmfcdpz2suiad.onion/))|✅|Gitea 1.15.0[⚠][gitea-bug]|n|n|n|n|[SSH disabled](https://git.nogafam.es/deCloudflare/deCloudflare/issues/18#issuecomment-75); large repos are [git-inaccessible over Tor](https://git.nogafam.es/deCloudflare/deCloudflare/issues/18#issuecomment-48)|
[try.gitea.io](https://try.gitea.io)|✅|Gitea 1.15.0[⚠][gitea-bug]|n|n|n|n|Intended only for Gitea experimentation; no expectation of future availability|
[opendev.org](https://opendev.org)|✅|Gitea 1.15.6[⚠][gitea-bug]|n|n|n|n|SSH port: 22; apparently became tor-hostile (403 forbidden)|
[git.kescher.at](https://git.kescher.at)|✅|Gitea 1.16.5[⚠][gitea-bug]|n|n|n|n||
[git.veen.world](https://git.veen.world)||Gitea 1.25.3|n|n|n|n||
[forge.april.org](https://forge.april.org)||Gitea 1.25.4|n|n|n|n|French is the primary language; no registration form; access is for [April](https://www.april.org) members -- but perhaps April membership is open to all?|
[git.safemobile.org](https://git.safemobile.org)|✅|Gitea 1.25.5|n|n|n|n|Gives a 403 forbidden error to those trying to reach loudflare/deCloudflare, so possibly anti-privacy politics in play.|
[framagit.org](https://framagit.org)|✅|Gitlab (CE 13.10.2)|n|n|n|n|[may become more restricted](https://framablog.org/2019/09/26/lets-de-frama-tify-the-internet) in mid-2021|
[git.jami.net](https://git.jami.net)|✅|Gitlab (CE)|n|n|n|n|possibly restricted to Jami efforts; acces to help page blocked to non-members so CE/EE unknown|
[gitlab.gnome.org](https://gitlab.gnome.org)|✅|Gitlab (CE)|n|n|n|n|possibly restricted to Gnome efforts|
[gitlab.gnome.org](https://gitlab.gnome.org)|✅|Gitlab (CE)|n|n|n|n|possibly restricted to Gnome efforts; Down for everyone or just Tor users who get a 406 error?|
[gitlab.tails.boum.org](https://gitlab.tails.boum.org)|✅|Gitlab (CE)|n|n|n|n|possibly restricted to Tails efforts but no AUP says otherwise|
[gitlab.torproject.org](https://gitlab.torproject.org)|✅|Gitlab (CE)|n|n|n|n|open registration; repo creation possibly restricted; Google reCAPTCHA is [allegedley](https://lists.gnu.org/archive/html/repo-criteria-discuss/2021-03/msg00000.html) used, but [not at registration time](https://gitlab.onionize.space)|
[source.small-tech.org](https://source.small-tech.org)|❌|Gitlab (CE)|n|n|n|n||
[notabug.org](https://notabug.org)([onion](http://qs3zumwfci4tntnd.onion))|✅|Gogs|n|n|n|n|based on [liberated](https://notabug.org/hp/gogs) fork of Gogs; [supports Tor](https://notabug.org/tor) (the *onion* web UI is currently disabled in response to attack but the onion site accepts git connections); supports SSH keys and SSH over Tor to NAB's onion service; no e-voting; NAB doesn't associate PGP keys to users, so PGP signed commits may be unavailable or more manual work needed.|
[gitlab.torproject.org](https://gitlab.torproject.org)|✅|Gitlab (CE)|n|n|n|n|open registration; repo creation possibly restricted; Google reCAPTCHA is [allegedly](https://lists.gnu.org/archive/html/repo-criteria-discuss/2021-03/msg00000.html) used, but [not at registration time](https://gitlab.onionize.space); its possible to [create an anonymous bug report](https://anonticket.onionize.space)|
[source.small-tech.org](https://source.small-tech.org)|❌|Gitlab (CE)|n|n|n|n|TLS issue→ NET::ERR_CERT_COMMON_NAME_INVALID|
([onion](http://git.dkforestseeaaq2dqz2uflmlsybvnq2irzn4ygyvu53oazyorednviid.onion))|✅|Gogs|n|n|n|n|Registration form reset when disposable address was supplied. Normal email not tested.|
[notabug.org](https://notabug.org)([onion](http://qs3zumwfci4tntnd.onion))|✅|Gogs|n|n|n|n|based on [liberated](https://notabug.org/hp/gogs) fork of Gogs; [supports Tor](https://notabug.org/tor); The web UI is disabled in response to attack git connections are permitted; supports SSH keys and SSH over Tor to NAB's onion service; no e-voting; NAB doesn't associate PGP keys to users, so PGP signed commits may be unavailable or more manual work needed.|
[launchpad.net](https://launchpad.net)|✅|Launchpad|n|n|n|n|It's [unknown](https://wiki.freephile.org/wiki/Comparison_of_git_hosting_options) whether it functions without JavaScript; no wiki|
[gitee.com](https://gitee.com)|✅|OSCHINA|n|n|n|n|based in China; registration over Tor with throwaway email works; no automatic mirror (unlike Gitea); some areas written in simplified chinese|
[code.netlandish.com](https://code.netlandish.com)||Sourcehut|n|n|n|n|Access restricted to staff of the company working on the hosted projects|
[sr.ht](https://sr.ht)|✅|Sourcehut|n|n|n|n|javascript-free; supports patches sent by email|
[gitee.com](https://gitee.com)|✅|OSCHINA|n|n|n|n|based in China; registration over Tor with throwaway email works; no automatic mirror (unlike Gitea); some areas written in simplified chinese; web timeout when last checked|
[code.netlandish.com](https://code.netlandish.com)||Sourcehut|n|n|n|n|Access restricted to staff of the company working on the hosted projects|
[sr.ht](https://sr.ht)|✅|Sourcehut|n|n|n|n|javascript-free; supports patches sent by email; offers an [IRC bouncer](https://sourcehut.org/blog/2021-11-29-announcing-the-chat.sr.ht-public-beta/); recognizes the harm of Cloudflare and takes an [ethical stance against it](https://srht.site/limitations); gratis to contribute to existing projects but non-gratis to start your own project|
[0xacab.org/](https://0xacab.org/)([onion](http://wmj5kiic7b6kjplpbvwadnht2nh2qnkbnqtcv3dyvpqtz7ssbssftxid.onion:44203/))|✅|gitlab|n|n|n|n|registration restricted to those from “friendly” domains|
## Graylist
These forges are not as seriously flawed as the blacklisted ones, but they should still be avoided if possible. Non-Cloudflare sites that use a Cloudflare NS server pose a risk for disruptions because they can trivially and spontaneously flip a switch and route all your traffic through Cloudflare, potentially cutting access to some of your contributors. Dead sites are also graylisted because if they come back online, they are known to be unreliable. Codeberg is graylisted for falsely accusing a repository of illegal conduct and deleting the content of all forks from that project without evidence or redress.
These forges are not as seriously flawed as the blacklisted ones, but they should still be avoided if possible. Non-Cloudflare sites that use a Cloudflare NS server pose a risk for disruptions because they can trivially and spontaneously flip a switch and route all your traffic through Cloudflare, potentially cutting access to some of your contributors. Sites that are dead or previously dead are also graylisted because if they come back online, they are known to be unreliable. Resource deprived instances are graylisted because they may become unstable or unreliable in the future, or if your repo is resource heavy you may be asked to leave. Codeberg is graylisted for falsely accusing a repository of illegal conduct and deleting the content of all forks from that project without evidence or redress.
| *forge* | *registration publicly open* | *software* | *Tor-hostile* | *Cloudflare MitM* | *forced re/hCAPTCHA* | *forced execution of non-free software* | *notes* |
|---|---|---|---|---|---|---|---|
([onion](http://githidep2hynhdmutuv7n2tei4iie2c7lyqz5fes3r5zzoxe5dshtxyd.onion))|❌||n|n|n|n|**dead site**|
[git.passageenseine.fr](https://git.passageenseine.fr)|❌|Gitea|n|n|n|n|**dead site**|
[gitea.shuishan.net.cn](https://gitea.shuishan.net.cn)|❌|Gitea|n|n|n|n|**dead site**|
[gitnet.fr](https://gitnet.fr)|✅|Gitea|n|n|n|n|Forge is resource deprived. The admin (simonv) had to ask a project to leave his forge for [performance reasons](https://framagit.org/dCF/deCloudflare/-/issues/46)|
[yerbamate.dev](https://yerbamate.dev)|❌|Gitea|n|n|n|n|**dead site**|
[git.teknik.io](https://git.teknik.io)|❌|Gitea 1.9.0|n|n|n|n|**Cloudflare NS server** (they can route all traffic via CF at the flip of a switch)|
[de.edumat.io](https://de.edumat.io)|❌|Gitea 1.5.2|n|n|n|n|**dead site**; no SSH|
[git.teknik.io](https://git.teknik.io)|❌|Gitea 1.9.0|n|n|n|n|**Cloudflare NS server** (they can route all traffic via CF at the flip of a switch); Dying or dead. Message says it will soon be shut down but there already is no web functionality|
[gitea.it](https://gitea.it)|✅|Gitea 1.12.4|n|n|n|n|**Cloudflare NS server** (they can route all traffic via CF at the flip of a switch)|
[git.kiwifarms.net](https://git.kiwifarms.net)||Gitea 1.13.1|n|n|n|n|**Cloudflare NS server** (they can route all traffic via CF at the flip of a switch)|
[codeberg.org](https://codeberg.org)|✅|Gitea 1.14 customized[⚠][gitea-bug]|n|n|n|n|Based in Germany; [censored an anti-Cloudflare project](codeberg.md) in a reckless and destructive manner; functions without any JavaScript and the JavaScript that exists is all 1st-party ([ref](https://github.com/privacytoolsIO/privacytools.io/issues/843#issuecomment-483830547)); devs make [foolish decisions](https://codeberg.org/Codeberg/Community/issues/444) (improving performance by breaking some browsers, when the performance improvement only affects those they broke.)|
[git.sdf.org](https://git.sdf.org)|✅|Gitea 1.14.1[⚠][gitea-bug]|n|n|n|n|git.sdf.org [censored](https://git.sdf.org/deCloudflare/deCloudflare) the deCloudflare project without warning, reason, or recourse. So git.sdf.org apparently unwelcoming of projects driven by privacy, netneutrality, or anti-tech-giant types of activism. Performance is sluggish and the website often times out (perhaps because SDF is also tar-pitting many Tor IPs in defense of attack & it's unclear if this is a temporary measure); SSH over Tor broken but HTTPS over Tor works; some UTF-8 emoticons apparently broke in upgrade from 1.13.1 to 1.14.1.|
[git.kiwifarms.net](https://git.kiwifarms.net)||Gitea 1.13.1|n|n|n|n|**dead site**; **Cloudflare NS server** (they can route all traffic via CF at the flip of a switch)|
[git.fuwafuwa.moe](https://git.fuwafuwa.moe)([onion](http://git.fwfwqtpi2ofmehzdxe3e2htqfmhwfciwivpnsztv7dvpuamhr72ktlqd.onion))|❌|Gitea 1.13.6|n|n|n|n|**dead site**; SSH port: 22; SSH over Tor [broken](http://git.fwfwqtpi2ofmehzdxe3e2htqfmhwfciwivpnsztv7dvpuamhr72ktlqd.onion/levena/fuwafuwa/issues/1); HTTPS over Tor works|
[codeberg.org](https://codeberg.org)|✅|Gitea 1.14 customized[⚠][gitea-bug]|n|n|n|n|Based in Germany; [censored an anti-Cloudflare project](codeberg.md) in a reckless and destructive manner; functions without any JavaScript and the JavaScript that exists is all 1st-party ([ref](https://github.com/privacytools/privacytools.io/issues/843#issuecomment-483830547)); devs make [foolish decisions](https://codeberg.org/Codeberg/Community/issues/444) (improving performance by breaking some browsers, when the performance improvement only affects those they broke.)|
[dev.sum7.eu](https://dev.sum7.eu)|❌|Gitea 1.14.0[⚠][gitea-bug]|n|n|n|n|**dead site**|
[git.sdf.org](https://git.sdf.org)|✅|Gitea 1.14.1[⚠][gitea-bug]|n|n|n|n|git.sdf.org [censored](https://git.sdf.org/deCloudflare/deCloudflare) the deCloudflare project without warning, reason, or recourse. So git.sdf.org apparently unwelcoming of projects driven by privacy, netneutrality, or anti-tech-giant types of activism. Performance is sluggish and the website often times out (perhaps because SDF is also tar-pitting many Tor IPs in defense of attack & its unclear if this is a temporary measure); SSH over Tor broken but HTTPS over Tor works|
[git.passageenseine.fr](https://git.passageenseine.fr)|✅|Gitea 1.14.2[⚠][gitea-bug]|n|n|n|n|Was previously down for a lengthy period thus considered unreliable.|
[git.eta.st](https://git.eta.st)|✅|Gitea 1.15.0[⚠][gitea-bug]|n|n|n|n|**Cloudflare NS server** (they can route all traffic via CF at the flip of a switch)|
[git.slashdev.space](https://git.slashdev.space)|❌|Gitea 1.15.4[⚠][gitea-bug]|n|n|n|n|**dead site**; SSH port: 22; SSH over Tor broken (try HTTPS over Tor)|
[git.nogafam.es](https://git.nogafam.es)([onion](http://git.hsdtecd4h2b5z732pvkg2yw3746epap4qusgvjjze6nhmfcdpz2suiad.onion/))|❌|Gitea 1.15.6[⚠][gitea-bug]|n|n|n|n|**dead site**; [SSH disabled](https://git.nogafam.es/deCloudflare/deCloudflare/issues/18#issuecomment-75); large repos are [git-inaccessible over Tor](https://git.nogafam.es/deCloudflare/deCloudflare/issues/18#issuecomment-48)|
[try.gitea.io](https://try.gitea.io)|✅|Gitea 1.16.0[⚠][gitea-bug]|n|n|n|n|**Cloudflare NS server** (they can route all traffic via CF at the flip of a switch); Intended only for Gitea experimentation; no expectation of future availability|
[forge.chApril.org](https://forge.chApril.org)|✅|Gitea 1.16.6[⚠][gitea-bug]|n|n|n|n|Censorship: spontaneously deletes peoples repos without warning, reason, or recourse. Forge is unsuitable for activism. French UI.|
[git.slipfox.xyz](https://git.slipfox.xyz)|❌|Gitea 1.17.2[⚠][gitea-bug]|n|n|n|n|**dead site**|
[git.exozy.me](https://git.exozy.me)|✅|Gitea 1.18.0[⚠][gitea-bug]|n|n|n|n|silently deletes repos without notice; [supports federated issues](https://social.exozy.me/@ta180m/108631221939677386)|
[git.openprivacy.ca](https://git.openprivacy.ca)([onion](http://gitopcybr57ris5iuivfz62gdwe2qk5pinnt2wplpwzicaybw73stjqd.onion))|✅|Gitea 1.22.1|n|n|n|n|Tor users get 404 - suspected botnet if visiting the clearnet site from a browser that does not act on the “onion-location” header; [listed](https://framagit.org/dCF/deCloudflare/-/blob/master/cloudflare_users/cloudflare_supporter.md) as a Cloudflare supporter for spontaneously deleting the repo of an anti-Cloudflare project without warning.|
[git.shivering-isles.com](https://git.shivering-isles.com)|❌|Gitlab (CE)|n|n|n|n|**Cloudflare NS server** (they can route all traffic via CF at the flip of a switch); Registration is open but broken-- requires 2FA using a device that can QR-scan, and the email verification link is DoA: ![](images/shivering-isles_broken_reg.png) That stale link error triggers even when accessed immediately.|
[git.hardenedbsd.org](https://git.hardenedbsd.org)||Gitlab (EE)|n|n|n|n|**Cloudflare NS server** (they can route all traffic via CF at the flip of a switch); possibly restricted to BSD efforts|
[source.puri.sm](https://source.puri.sm)|✅|Gitlab (EE)|n|n|n|n|open registration but activity is [restricted](https://social.librem.one/@kyle/106030358887310621) to puri.sm efforts; accounts are subject to spontaneous unjustified bans (apparent censorship): ![](images/purism_ban.png); no CAPTCHA (confirmed March 2021); is the JavaScript non-free with the enterprize edition?|
[git.stuxhost.com](https://git.stuxhost.com)||Gitlab (CE)|n|n|n|n|**dead site**; **Cloudflare NS server** (they can route all traffic via CF at the flip of a switch)|
[git.hardenedbsd.org](https://git.hardenedbsd.org)|✅|Gitlab (EE)|n|n|n|?|**Cloudflare NS server** (they can route all traffic via CF at the flip of a switch); possibly restricted to BSD efforts|
[mypdns.org](https://mypdns.org)|✅|Gitlab (EE)|n|n|n|?|Previously down-- sudden death of website without warning to repo admins. Came back online months later but peoples accounts and repos were mysteriously gone; Was home of the deCloudflare and /Right to be Offline/ projects; It was open reg but considered a “private system” whereby the option to create a new repo was not immediately available.|
[source.puri.sm](https://source.puri.sm)|✅|Gitlab (EE)|n|n|n|?|open registration but activity is [restricted](https://social.librem.one/@kyle/106030358887310621) to puri.sm efforts; accounts are subject to spontaneous unjustified bans (apparent censorship): ![](images/purism_ban.png); no CAPTCHA (confirmed March 2021); is the JavaScript non-free with the enterprize edition?|
## Blacklist
@@ -56,18 +74,17 @@ These forges have severe ethical or trust issues and should be boycotted:
| *forge* | *registration publicly open* | *software* | *Tor-hostile* | *Cloudflare MitM* | *forced re/hCAPTCHA* | *forced execution of non-free software* | *notes* |
|---|---|---|---|---|---|---|---|
github.com|❌ (exclusive walled garden)||y|n|n|☣|**access granted or denied based on national origin**; [copious ethical issues](github.md)|
sourceforge.net|❌ (exclusive walled garden)||n|n|n|☣|**access granted or denied based on national origin**; Important site [functionality does not work without non-free JavaScript](https://www.gnu.org/software/repo-criteria-evaluation.html)|
bitbucket.org|✅|Bitbucket Server|n|n|n|☣|**Amazon AWS-hosted**; needs non-free javascript that [clusterfucks uMatrix](https://github.com/privacytoolsIO/privacytools.io/issues/843#issuecomment-483830547); has some relationship with Netlify; access to source code [restricted](https://en.wikipedia.org/wiki/Bitbucket#Bitbucket_Server)|
sourceforge.net|❌ (exclusive walled garden)||n|y|n|☣|**access granted or denied based on national origin**; Important site [functionality does not work without non-free JavaScript](https://www.gnu.org/software/repo-criteria-evaluation.html)|
bitbucket.org|✅|Bitbucket Server|n|n|n|☣|**Amazon AWS-hosted**; needs non-free javascript that [clusterfucks uMatrix](https://github.com/privacytools/privacytools.io/issues/843#issuecomment-483830547); has some relationship with Netlify; access to source code [restricted](https://en.wikipedia.org/wiki/Bitbucket#Bitbucket_Server)|
libregit.org|❌|Gitea|n|y|n|n|reg by invite only|
git.openprivacy.ca|❌ (exclusive walled garden)|Gitea 1.12.4|y|n|n|n|Tor users get 404 - suspected botnet; [listed](https://git.nogafam.es/deCloudflare/deCloudflare/src/branch/master/cloudflare_users/cloudflare_supporter.md) as a Cloudflare supporter|
git.feneas.org|✅|Gitlab (CE)|n|n|⚒|☣|reCAPTCHA impedes registration and imposes non-free s/w|
gitlab.freedesktop.org|✅|Gitlab (CE)|n|n|⚒|☣|possibly restricted to Freedesktop efforts; reg. blocked by reCAPTCHA|
salsa.debian.org|✅|Gitlab (CE)|n|n|⚒|☣|**forced h/reCAPTCHA**; possibly restricted to Debian efforts; serves as an alternative to Debian's email-only bug tracker|
gitlab.com|❌ (exclusive walled garden)|Gitlab (EE)|n|y|⚒|☣|flagship instance running the *Enterprise Edition*; uses both hCAPTCHA & reCAPTCHA; heavily restricted with discriminatory policies; [copious ethical issues](gitlab-dot-com.md)|
⚠ Gitea versions note: Gitea 1.14.0 [breaks][gitea-bug] emoji in some browsers. The developers [believe](https://codeberg.org/Codeberg/Community/issues/444#issuecomment-198199) that by not supplying fonts to the web visitors who need them, they are improving server performance. Of course the server load is only reduced when talking to a browser that does not have the needed fonts. The idiots could also simply arbitrarily deny service to users at random to get a performance increase. Obviously they have misunderstood the point of performance in the first place: availability!
⚠ Gitea versions note: Gitea 1.13.8 [breaks][gitea-bug] emoji in some browsers. The developers [believe](https://codeberg.org/Codeberg/Community/issues/444#issuecomment-198199) that by not supplying fonts to the web visitors who need them, they are improving server performance. Of course the server load is only reduced when talking to a browser that does not have the needed fonts. The idiots could also simply arbitrarily deny service to users at random to get a performance increase. Obviously they have misunderstood the point of performance in the first place: availability!
The best Gitea version ATM is 1.13.7 which opendev.org runs.
The best Gitea version ATM is 1.13.7 but there are no known instances of this.
[gitea-bug]: https://codeberg.org/Codeberg/Community/issues/444
+47 -9
View File
@@ -1,10 +1,13 @@
[//]: # (to do: vet the links for CF & scrub)
[//]: # (to do: halloween papers)
[//]: # (to do: https://www.businessinsider.com/microsoft-new-employee-review-system-stack-ranking-2023-9)
[0]: https://infosec.exchange/@bojkotiMalbona/104637098084869887
[1]: https://trac.torproject.org/projects/tor/wiki/org/doc/ListOfServicesBlockingTor#ComputingTechnical
[2]: https://user-images.githubusercontent.com/21023035/61580062-10fd6300-aafd-11e9-8bf2-64faddf63760.png
[3]: https://github.com/Eloston/ungoogled-chromium/issues/795#issuecomment-687991721
[4]: https://www.bleepingcomputer.com/news/security/microsofts-github-account-allegedly-hacked-500gb-stolen
[4-cache]: http://web.archive.org/web/20221108044516/www.bleepingcomputer.com/news/security/microsofts-github-account-hacked-private-repositories-stolen/
[5]: https://www.zdnet.com/article/hackers-stole-github-and-gitlab-oauth-tokens-from-git-analytics-firm-waydev
[6]: https://msrc.microsoft.com/create-report
[7]: https://www.bbc.com/news/technology-50232902
@@ -12,12 +15,12 @@
[9]: https://corporate.exxonmobil.com/news/newsroom/news-releases/2019/0222_exxonmobil-to-increase-permian-profitability-through-digital-partnership-with-microsoft
[10]: https://news.microsoft.com/2019/09/17/schlumberger-chevron-and-microsoft-announce-collaboration-to-accelerate-digital-transformation
[11]: https://www.scientificamerican.com/article/exxon-knew-about-climate-change-almost-40-years-ago
[12]: http://web.archivecrfip2lpi.onion/web/publicintegrity.org/federal-politics/republican-lawmakers-posh-hideaway-bankrolled-by-secret-corporate-cash
[12]: http://web.archive.org/web/publicintegrity.org/federal-politics/republican-lawmakers-posh-hideaway-bankrolled-by-secret-corporate-cash
[13]: http://techrights.org/wiki/index.php/Microsoft_and_the_NSA
[14]: http://cal-access.sos.ca.gov/Campaign/Committees/Detail.aspx?id=1401518&view=late1&session=2017
[15]: http://web.archivecrfip2lpi.onion/web/20200318144031/www.theverge.com/2018/6/15/17468292/amazon-microsoft-uber-california-consumer-privacy-act
[15]: http://web.archive.org/web/20200318144031/www.theverge.com/2018/6/15/17468292/amazon-microsoft-uber-california-consumer-privacy-act
[16]: https://web.archive.org/web/20200722105800/tokenpost.com/Central-Bank-of-Sweden-is-testing-digital-currency-5197
[17]: https://github.com/privacytoolsIO/privacytools.io/issues/374#issuecomment-460077544
[17]: https://github.com/privacytools/privacytools.io/issues/374#issuecomment-460077544
[18]: https://www.cnet.com/news/amazon-google-and-microsoft-sued-over-photos-in-facial-recognition-database
[19]: http://gnu.org/philosophy/free-software-even-more-important.html
[20]: http://gnu.org/proprietary/malware-microsoft.html
@@ -26,7 +29,7 @@
[23]: https://www.zdnet.com/article/dutch-government-report-says-microsoft-office-telemetry-collection-breaks-gdpr
[24]: https://gdpr-info.eu/art-5-gdpr
[25]: https://gdpr-info.eu/art-17-gdpr
[26]: https://www.forbes.com/sites/thomasbrewster/2019/08/01/microsoft-slammed-for-investing-in-israeli-facial-recognition-spying-on-palestinians
[26]: http://web.archive.org/web/20231204142210/www.forbes.com/sites/thomasbrewster/2019/08/01/microsoft-slammed-for-investing-in-israeli-facial-recognition-spying-on-palestinians/
[27]: https://edition.cnn.com/2018/06/03/middleeast/razan-al-najjar-gaza-nurse-killed/index.html
[28]: https://www.independent.co.uk/news/world/middle-east/gaza-protests-latest-idf-condemned-edited-video-angel-of-mercy-medic-razan-al-najjar-a8389611.html
[29]: https://companies-that-work-with-ice.com
@@ -49,6 +52,15 @@
[46]: https://github.com/deCloudflare/deCloudflare
[47]: http://crimeflare.eu.org/
[48]: images/github_ban.png
[49]: https://www.iccl.ie/digital-data/iccl-report-on-the-scale-of-real-time-bidding-data-broadcasts-in-the-u-s-and-europe/
[50]: https://github.com/wireapp/kalium#github-packages-authentication
[51]: https://sfconservancy.org/GiveUpGitHub
[52]: https://githubcopilotinvestigation.com
[53]: https://git.veen.world/kevinveenbirkenbach/github-to-gitea-mirror
[54]: https://tuta.com/blog/outlook-falsely-marks-tutanota-emails-as-junk
[hrajab]: https://www.guardian2zotagl6tmjucg3lrhxdk4dw3lhbqnkvvkywawy3oqfoprid.onion/world/2024/feb/10/im-so-scared-please-come-hind-rajab-six-found-dead-in-gaza-12-days-after-cry-for-help
[partners]: https://proton.me/blog/outlook-is-microsofts-new-data-collection-service
[nogithub]: https://nogithub.codeberg.page/
# Direct practical problems with using Microsoft Github
@@ -56,7 +68,9 @@
**withheld** when the bug tracker is inside a restrictive or
politically controversial walled-garden like MS Github or
gitlab.com. This ultimately hinders the quality of software in the
commons.
commons.
1. Github restricts access to some FOSS code by [requiring][50] a
“GitHub Personal Access Token” to download software.
1. Github is Tor-hostile [according to Tor project][1]. GH has
started forcing Tor users through an extra email verification step
that effectively discourages bug reports:
@@ -71,7 +85,7 @@
the user's reputation from the standpoint of a commercial job.
Burner accounts protect users so they can work on multiple
projects, and Microsoft bans that protection.
1. MS failed to secure Github, which was [breached to the tune of 500gb of private projects][4].
1. MS failed to secure Github, which was [breached to the tune of 500gb of private projects][4-cache].
Then security was breached again in July 2020 when OAuth tokens were
[stolen][5] from both Github and Gitlab.com.
Security incompetence is further showcased by an MS-imposed requirement
@@ -89,10 +103,21 @@
1. Free software projects that rely on non-free software
"[put everyone at the whim of the groups and individuals who produce the tools they depend on][8],"
and it puts free software developers in a position of hypocrisy.
1. MS mechanically suppresses bug reports that contain profanity
*without moderation*. That is, if you say something like “the
fucking server pushed a CAPTCHA” and the profanity is not directed
at any developers, the bug report will still be blocked in an
absolute, irreversable manner without the possibility of human
intervention, instead of quarantining the report for
moderation. This effectively demoralizes the bug reporter who may
opt not to reattempt the report submission; thus ultimately
hindering software quality.
1. MS [violates][52] the copyright of free software projects using AI
in its “Copilot” program.
## Ethical problems with using Microsoft products and services
8. Microsoft harms the **environment** by serving the two most destructive oil companies in the world: [ExxonMobil][9] and [Chevron][10].
11. Microsoft harms the **environment** by serving the two most destructive oil companies in the world: [ExxonMobil][9] and [Chevron][10].
1. (#ExxonKnew) Exxon notoriously [knew][11] about climate change
since 1977. They not only kept it secret from the public, but
they also financed a disinformation campaign.
@@ -103,6 +128,7 @@
membership with ALEC, which doubles as a superPAC and bill mill
that lobbies and writes policy for U.S. republicans.
1. Microsoft is a notorious **privacy** abuser:
1. MS shares your data with [801 3rd-party partners][partners]
1. MS is a PRISM corporation prone to mass surveillance.
1. MS supported CISPA and [collaborates][13] with the NSA.
1. MS [paid][14] $195k to [fight][15] the California Consumer
@@ -118,7 +144,7 @@
1. MS supplies Bing search service which gives high rankings to
[privacy-abusing][17] CloudFlare websites.
1. MS owns and operates Outlook Email and the LinkedIn social
media site, both of which are exclusive walled-gardens that
media site, both of which are exclusive walled gardens that
limit participation to those who have a phone number and the
will to share it with Microsoft.
1. MS supplies hotmail.com email service, which uses vigilante
@@ -138,6 +164,8 @@
365 violates [GDPR article 5][24] ¶ `1.c`,
[GDPR article 17][25], and stores the data outside the EEA (may
also be a GDPR breach).
1. (2022) Microsoft acquired Xandr from AT&T, thus [becoming a
surveillance advertiser][49].
1. Microsoft is detrimental to **human rights** and **democracy**
1. Microsoft [finances AnyVision][26] to produce facial
recognition technology that the Israeli military uses as a
@@ -145,7 +173,7 @@
occupation. Note that Israeli snipers [murdered][27] an unarmed
civilian Palestinian medic (in breach of the Geneva Convention)
then [edited][28] the video to deceive the public for PR damage
control.
control. Also note [what happened][hrajab] to Hind Rajab.
1. Microsoft [supports ICE][29] in a variety of ways in the course
of ICE's implementation of Trump's xenophobic border
policies. Microsoft services an ICE contract worth
@@ -173,3 +201,13 @@
actually wants Windows.
1. MS [hoards][42] software patents and uses them to [fight free software][43].
1. Github [has an F rating][44] by the FSF.
1. MS [got caught][54] directing e-mail from Tuta to the spam boxes of Outlook users. They ignored complaints until it became a public spectacle.
## Remedial actions
The Software Conservancy has a [Give Up Github campaign][51] which
suggests actions you can take to help support this movement.
Developers can join the [no github campaign][nogithub] to request that their software be withheld from Github.
Use [Kevin Veen-Birkenbachs tool][53] to mirror Github repos on Gitea.
+17 -23
View File
@@ -6,22 +6,13 @@
There is Gitlab software, and there are services that use that
software. The software comes in two varieties: "*Community Edition*"
(CE) and "*Enterprise Edition*" (EE). The Community Edition is free
software. These services run Gitlab as their backend:
software. Several forges run Gitlab as their
backend. E.g. framagit.org, git.feneas.org, git.hardenedbsd.org,
git.jami.net, gitlab.com, gitlab.freedesktop.org, gitlab.gnome.org,
gitlab.torproject.org, source.puri.sm, and source.small-tech.org. See
the [full list](forge_comparison.md) if you're interested.
| host | notes |
|---|---|
| framagit.org ||
| git.feneas.org | reCAPTCHA impedes registration |
| git.hardenedbsd.org | possibly restricted to BSD efforts |
| git.jami.net | possibly restricted to Jami efforts |
| gitlab.com (EE) | flagship instance running the *Enterprise Edition*; uses hCAPTCHA; heavily restricted with discriminatory policies (noted below) |
| gitlab.freedesktop.org | possibly restricted to Freedesktop efforts |
| gitlab.gnome.org | possibly restricted to Gnome efforts |
| gitlab.torproject.org (CE) | possibly restricted to the Tor Project (Google reCAPTCHA [is used][GRConTP]) |
| source.puri.sm | open registration; *not* restricted to puri.sm efforts; no CAPTCHA |
| source.small-tech.org | closed registration |
The rest of this article is focused on the gitlab _.com_ ***service***.
This article is only focused on the gitlab _.com_ ***service***.
These are the ethical problems with that specific instance:
1. Sexist treatment toward saleswomen who are [told to wear][sexism]
@@ -55,8 +46,10 @@ These are the ethical problems with that specific instance:
undermines the spirit and intent of [FSF criteria C6][fsfCriteria].
[FSF criteria B1][fsfCriteria] is also unsatisfied due to
deliberate sharing all traffic with CloudFlare.
1. Excessive [tracking][tracking] renders [FSF criteria C4][fsfCriteria]
unsatisfied.
1. Excessive [tracking by Snowplow (possibly FLoC)][snowplow-cache]
renders [FSF criteria C4][fsfCriteria] unsatisfied. The terms of
service were [updated in 2019][tracking-cache] to ensure you agree
to the tracking.
1. Contrary to widespread confused notions about Gitlab being free
software, the gitlab.com *service* does *not* run the Gitlab
Community Edition (GCE). It runs the proprietary "enterprise
@@ -69,7 +62,8 @@ These are the ethical problems with that specific instance:
freedoms. Yet gitlab.com's walled garden is so restricted that Tor
users are not even permitted to clone a project:
![](https://infosec.exchange/system/media_attachments/files/105/764/904/002/819/754/original/38832d4b9ffc75fa.png)
[//]: # (old url→ https://infosec.exchange/system/media_attachments/files/105/764/904/002/819/754/original/38832d4b9ffc75fa.png)
![](https://media.infosec.exchange/infosecmedia/media_attachments/files/105/764/904/002/819/754/original/38832d4b9ffc75fa.png)
consequently [FSF criteria C3][fsfCriteria] is unmet.
@@ -77,7 +71,7 @@ consequently [FSF criteria C3][fsfCriteria] is unmet.
ISP uses CGNAT or if they use Tor. Access is inconvenient in some
cases (e.g. GUI users), while access is outright denied to other
users (e.g. terminal users with non-GUI browsers, browsers without
javascript capability, and users who happen to use a high traffic
JavaScript capability, and users who happen to use a high traffic
exit node). ISPs in Serbia and India often use CGNAT for their
lowest tiers of service while charging an extra fee for IPv4 or
IPv6. This means gitlab.com is effectively discriminating against
@@ -219,7 +213,7 @@ of CAPTCHAs:
they take on more privacy abuse). Tor users are given extra harsh
treatment.
[//]: # (I solved the hCAPTCHA, got a green checkmark, and then it looped back to an empty checkbox and I was forced to solve the hCAPTCHA for a 2nd time. And both times I had to solve 2 windows (4 windows in total [36 images]). After solving the 2nd hCAPTCHA gitlab.com brought me to a 404 error. So after all the hard work I was still blocked.)
[//]: # (I solved the hCAPTCHA, got a green checkmark, and then it looped back to an empty checkbox and I was forced to solve the hCAPTCHA for a 2nd time. And both times I had to solve 2 windows --4 windows in total [36 images]--. After solving the 2nd hCAPTCHA gitlab.com brought me to a 404 error. So after all the hard work I was still blocked.)
[sexism]: https://web.archive.org/web/20200309145121/https://www.theregister.co.uk/2020/02/06/gitlab_sales_women
[sanctions]: https://en.wikipedia.org/wiki/GitLab#cite_note-30
@@ -241,8 +235,8 @@ of CAPTCHAs:
[glbug]: https://web.archive.org/web/20210306172223/gitlab.com/prism-break/prism-break/-/issues/2146
[GRConTP]: https://lists.gnu.org/archive/html/repo-criteria-discuss/2021-03/msg00000.html
[asAmeans]: https://plato.stanford.edu/entries/persons-means
[snowplow-cache]: https://web.archive.org/web/20220811090954/docs.gitlab.com/ee/development/snowplow
[//]: # (unused links)
[grcNonfree]: # ([recaptcha/api.js](https://www.google.com/recaptcha/api.js))
[signalGRC]: # (https://user-images.githubusercontent.com/18015852/55681364-07713600-5926-11e9-8874-137e4faaf423.png)
[//]: # ([grcNonfree]: [recaptcha/api.js] https://www.google.com/recaptcha/api.js)
[//]: # ([signalGRC]: # https://user-images.githubusercontent.com/18015852/55681364-07713600-5926-11e9-8874-137e4faaf423.png)
+50 -28
View File
@@ -1,6 +1,8 @@
/* Monitor the following for new hosts:
https://gitea.com/gitea/awesome-gitea#organizations
https://wiki.softwareheritage.org/wiki/Suggestion_box:_source_code_to_add (specific repos can be requested here: https://archive.softwareheritage.org/save/#requests)
https://framagit.org/dCF/deCloudflare/-/blob/master/subfiles/cloudflared/gitservices.md
(CF!) https://wiki.p2pfoundation.net/List_of_Community-Hosted_Code_Forge_Instances
*/
create table if not exists forgesTbl
@@ -14,7 +16,7 @@ create table if not exists forgesTbl
cflogin boolean not null default 0,
cfns boolean not null default 0,
antitor boolean not null default 0,
forced_nfsw boolean not null default 0,
forced_nfsw boolean default 0,
aws boolean not null default 0,
nation_discrimination boolean not null default 0,
notes text,
@@ -22,42 +24,58 @@ create table if not exists forgesTbl
/* check(software in ('Bitbucket Server', 'Gitea', 'gitlab_ce', 'gitlab_ee', 'Gogs', 'Launchpad', 'Sourcehut', 'other')) not null default 'other'*/
insert into forgesTbl (url_clrnet, software, notes) values ('https://gitee.com','OSCHINA','based in China; registration over Tor with throwaway email works; no automatic mirror (unlike Gitea); some areas written in simplified chinese');
insert into forgesTbl (url_clrnet, software, notes) values ('https://gitee.com','OSCHINA','based in China; registration over Tor with throwaway email works; no automatic mirror (unlike Gitea); some areas written in simplified chinese; web timeout when last checked');
insert into forgesTbl (url_clrnet, software, forced_nfsw, aws, notes) values ('https://bitbucket.org','Bitbucket Server',1,1,'needs non-free javascript that [clusterfucks uMatrix](https://github.com/privacytoolsIO/privacytools.io/issues/843#issuecomment-483830547); has some relationship with Netlify; access to source code [restricted](https://en.wikipedia.org/wiki/Bitbucket#Bitbucket_Server)');
insert into forgesTbl (url_clrnet, software, forced_nfsw, aws, notes) values ('https://bitbucket.org','Bitbucket Server',1,1,'needs non-free javascript that [clusterfucks uMatrix](https://github.com/privacytools/privacytools.io/issues/843#issuecomment-483830547); has some relationship with Netlify; access to source code [restricted](https://en.wikipedia.org/wiki/Bitbucket#Bitbucket_Server)');
insert into forgesTbl (url_clrnet, url_onion, software, notes) values ('https://notabug.org','http://qs3zumwfci4tntnd.onion','Gogs','based on [liberated](https://notabug.org/hp/gogs) fork of Gogs; [supports Tor](https://notabug.org/tor) (the *onion* web UI is currently disabled in response to attack but the onion site accepts git connections); supports SSH keys and SSH over Tor to NAB''s onion service; no e-voting; NAB doesn''t associate PGP keys to users, so PGP signed commits may be unavailable or more manual work needed.');
insert into forgesTbl (url_clrnet, url_onion, software, notes) values ('https://notabug.org','http://qs3zumwfci4tntnd.onion','Gogs','based on [liberated](https://notabug.org/hp/gogs) fork of Gogs; [supports Tor](https://notabug.org/tor); The web UI is disabled in response to attack git connections are permitted; supports SSH keys and SSH over Tor to NAB''s onion service; no e-voting; NAB doesn''t associate PGP keys to users, so PGP signed commits may be unavailable or more manual work needed.');
insert into forgesTbl (url_clrnet, nation_discrimination, forced_nfsw, notes) values ('https://sourceforge.net',1,1,'Important site [functionality does not work without non-free JavaScript](https://www.gnu.org/software/repo-criteria-evaluation.html)');
insert into forgesTbl (url_onion, software, notes) values ('http://git.dkforestseeaaq2dqz2uflmlsybvnq2irzn4ygyvu53oazyorednviid.onion','Gogs', 'Registration form reset when disposable address was supplied. Normal email not tested.');
insert into forgesTbl (url_clrnet, nation_discrimination, forced_nfsw, cflogin, notes) values ('https://sourceforge.net',1,1,1,'Important site [functionality does not work without non-free JavaScript](https://www.gnu.org/software/repo-criteria-evaluation.html)');
insert into forgesTbl (url_clrnet, antitor, forced_nfsw, nation_discrimination, notes) values ('https://github.com',1,1,1,'[copious ethical issues](github.md)');
insert into forgesTbl (url_clrnet, software, notes) values ('https://launchpad.net','Launchpad','It''s [unknown](https://wiki.freephile.org/wiki/Comparison_of_git_hosting_options) whether it functions without JavaScript; no wiki');
insert into forgesTbl (url_clrnet, software, dead) values ('https://yerbamate.dev','Gitea',1);
insert into forgesTbl (url_clrnet, software, antitor, notes) values ('https://git.openprivacy.ca','Gitea 1.12.4',1,'Tor users get 404 - suspected botnet; [listed](https://git.nogafam.es/deCloudflare/deCloudflare/src/branch/master/cloudflare_users/cloudflare_supporter.md) as a Cloudflare supporter');
insert into forgesTbl (url_clrnet, software, notes) values ('https://sr.ht','Sourcehut', 'javascript-free; supports patches sent by email');
insert into forgesTbl (url_clrnet, software, openpubreg, notes) values ('https://code.netlandish.com','Sourcehut',1,'Access restricted to staff of the company working on the hosted projects');
insert into forgesTbl (url_clrnet, url_onion, software, notes) values ('https://git.openprivacy.ca','http://gitopcybr57ris5iuivfz62gdwe2qk5pinnt2wplpwzicaybw73stjqd.onion','Gitea 1.22.1','Tor users get 404 - suspected botnet if visiting the clearnet site from a browser that does not act on the “onion-location” header; [listed](https://framagit.org/dCF/deCloudflare/-/blob/master/cloudflare_users/cloudflare_supporter.md) as a Cloudflare supporter for spontaneously deleting the repo of an anti-Cloudflare project without warning.');
insert into forgesTbl (url_clrnet, software, notes) values ('https://sr.ht','Sourcehut', 'javascript-free; supports patches sent by email; offers an [IRC bouncer](https://sourcehut.org/blog/2021-11-29-announcing-the-chat.sr.ht-public-beta/); recognizes the harm of Cloudflare and takes an [ethical stance against it](https://srht.site/limitations); gratis to contribute to existing projects but non-gratis to start your own project');
insert into forgesTbl (url_clrnet, software, openpubreg, notes) values ('https://code.netlandish.com','Sourcehut',0,'Access restricted to staff of the company working on the hosted projects');
insert into forgesTbl (url_onion, dead) values ('http://githidep2hynhdmutuv7n2tei4iie2c7lyqz5fes3r5zzoxe5dshtxyd.onion', 1);
/* Gitea */
insert into forgesTbl (url_clrnet, software, notes) values ('https://codeberg.org','Gitea 1.14 customized', 'Based in Germany; [censored an anti-Cloudflare project](codeberg.md) in a reckless and destructive manner; functions without any JavaScript and the JavaScript that exists is all 1st-party ([ref](https://github.com/privacytoolsIO/privacytools.io/issues/843#issuecomment-483830547)); devs make [foolish decisions](https://codeberg.org/Codeberg/Community/issues/444) (improving performance by breaking some browsers, when the performance improvement only affects those they broke.)');
insert into forgesTbl (url_clrnet, software, openpubreg, notes) values ('https://git.nixnet.services','Gitea 1.14.1', 0, 'formerly git.nixnet.xyz');
insert into forgesTbl (url_clrnet, software, openpubreg, cfns) values ('https://git.teknik.io','Gitea 1.09.0',0,1);
insert into forgesTbl (url_clrnet, url_onion, software, notes) values ('https://git.fuwafuwa.moe','http://git.fuwafuwaqtlkkxwc.onion','Gitea 1.13.6','SSH port: 22; SSH over Tor [broken](http://git.fuwafuwaqtlkkxwc.onion/levena/fuwafuwa/issues/1); HTTPS over Tor works');
insert into forgesTbl (url_clrnet, software, notes) values ('https://git.slashdev.space','Gitea 1.13.6','SSH port: 22; SSH over Tor broken (try HTTPS over Tor)');
insert into forgesTbl (url_clrnet, software, notes) values ('https://git.disroot.org','Gitea 1.14.2','SSH over Tor works; based in NL');
insert into forgesTbl (url_clrnet, software, notes) values ('https://codeberg.org','Gitea 1.14 customized', 'Based in Germany; [censored an anti-Cloudflare project](codeberg.md) in a reckless and destructive manner; functions without any JavaScript and the JavaScript that exists is all 1st-party ([ref](https://github.com/privacytools/privacytools.io/issues/843#issuecomment-483830547)); devs make [foolish decisions](https://codeberg.org/Codeberg/Community/issues/444) (improving performance by breaking some browsers, when the performance improvement only affects those they broke.)');
insert into forgesTbl (url_clrnet, url_onion, software, notes) values ('https://git.nixnet.services','http://qt5vr747phiq55ubqip4hflmpygzl374mum2zbyqdxg6sqbngmzlqhid.onion/','Forgejo 1.21.11+1', 'formerly git.nixnet.xyz; served from Finland.');
insert into forgesTbl (url_clrnet, software, notes, openpubreg, cfns) values ('https://git.teknik.io','Gitea 1.09.0','Dying or dead. Message says it will soon be shut down but there already is no web functionality',0,1);
insert into forgesTbl (url_clrnet, url_onion, software, notes, dead) values ('https://git.fuwafuwa.moe','http://git.fwfwqtpi2ofmehzdxe3e2htqfmhwfciwivpnsztv7dvpuamhr72ktlqd.onion','Gitea 1.13.6','SSH port: 22; SSH over Tor [broken](http://git.fwfwqtpi2ofmehzdxe3e2htqfmhwfciwivpnsztv7dvpuamhr72ktlqd.onion/levena/fuwafuwa/issues/1); HTTPS over Tor works', 1);
insert into forgesTbl (url_clrnet, software, notes, dead) values ('https://git.slashdev.space','Gitea 1.15.4','SSH port: 22; SSH over Tor broken (try HTTPS over Tor)',1);
insert into forgesTbl (url_clrnet, url_onion, software, notes) values ('https://git.disroot.org','http://kgtz2pmmov5jfvn3z4mqryffjnnw6krzrgxxoyaqhqckjrr4pckyhsqd.onion','Forgejo 14.0.2','SSH over Tor works; based in NL; onion down');
insert into forgesTbl (url_clrnet, software, openpubreg, cflogin, notes) values ('https://libregit.org','Gitea',0,1,'reg by invite only');
insert into forgesTbl (url_clrnet, software, notes) values ('https://git.sdf.org','Gitea 1.14.1','git.sdf.org [censored](https://git.sdf.org/deCloudflare/deCloudflare) the deCloudflare project without warning, reason, or recourse. So git.sdf.org apparently unwelcoming of projects driven by privacy, netneutrality, or anti-tech-giant types of activism. Performance is sluggish and the website often times out (perhaps because SDF is also tar-pitting many Tor IPs in defense of attack & it''s unclear if this is a temporary measure); SSH over Tor broken but HTTPS over Tor works; some UTF-8 emoticons apparently broke in upgrade from 1.13.1 to 1.14.1.');
insert into forgesTbl (url_clrnet, software, notes) values ('https://git.sdf.org','Gitea 1.14.1','git.sdf.org [censored](https://git.sdf.org/deCloudflare/deCloudflare) the deCloudflare project without warning, reason, or recourse. So git.sdf.org apparently unwelcoming of projects driven by privacy, netneutrality, or anti-tech-giant types of activism. Performance is sluggish and the website often times out (perhaps because SDF is also tar-pitting many Tor IPs in defense of attack & its unclear if this is a temporary measure); SSH over Tor broken but HTTPS over Tor works');
insert into forgesTbl (url_clrnet, software, notes) values ('https://forge.chApril.org','Gitea 1.16.6','Censorship: spontaneously deletes peoples repos without warning, reason, or recourse. Forge is unsuitable for activism. French UI.'); /* dCF censored */
insert into forgesTbl (url_clrnet, software, cfns) values ('https://gitea.it','Gitea 1.12.4',1);
insert into forgesTbl (url_clrnet, software, notes) values ('https://de.edumat.io','Gitea 1.05.2','no SSH');
insert into forgesTbl (url_clrnet, software, cfns) values ('https://git.kiwifarms.net','Gitea 1.13.1',1);
insert into forgesTbl (url_clrnet, software) values ('https://git.safemobile.org','Gitea 1.14.1');
insert into forgesTbl (url_clrnet, url_onion, software, notes) values ('https://git.nogafam.es','http://git.hsdtecd4h2b5z732pvkg2yw3746epap4qusgvjjze6nhmfcdpz2suiad.onion/','Gitea 1.15.0','[SSH disabled](https://git.nogafam.es/deCloudflare/deCloudflare/issues/18#issuecomment-75); large repos are [git-inaccessible over Tor](https://git.nogafam.es/deCloudflare/deCloudflare/issues/18#issuecomment-48)');
insert into forgesTbl (url_clrnet, software) values ('https://dev.sum7.eu','Gitea 1.14.0');
insert into forgesTbl (url_clrnet, software, dead, notes) values ('https://de.edumat.io','Gitea 1.05.2',1,'no SSH');
insert into forgesTbl (url_clrnet, software, cfns, dead) values ('https://git.kiwifarms.net','Gitea 1.13.1',1,1);
insert into forgesTbl (url_clrnet, software, notes) values ('https://git.safemobile.org','Gitea 1.25.5','Gives a 403 forbidden error to those trying to reach loudflare/deCloudflare, so possibly anti-privacy politics in play.');
insert into forgesTbl (url_clrnet, url_onion, software, notes, dead) values ('https://git.nogafam.es','http://git.hsdtecd4h2b5z732pvkg2yw3746epap4qusgvjjze6nhmfcdpz2suiad.onion/','Gitea 1.15.6','[SSH disabled](https://git.nogafam.es/deCloudflare/deCloudflare/issues/18#issuecomment-75); large repos are [git-inaccessible over Tor](https://git.nogafam.es/deCloudflare/deCloudflare/issues/18#issuecomment-48)', 1);
insert into forgesTbl (url_clrnet, software, dead) values ('https://dev.sum7.eu','Gitea 1.14.0',1);
insert into forgesTbl (url_clrnet, software, notes) values ('https://git.fsfe.org','Gitea','Access intended only for FSFE projects and very small projects; SSH port: 22');
insert into forgesTbl (url_clrnet, software, notes) values ('https://opendev.org','Gitea 1.13.7','SSH port: 22');
insert into forgesTbl (url_clrnet, software, dead) values ('https://git.passageenseine.fr','Gitea',1);
insert into forgesTbl (url_clrnet, software, notes) values ('https://opendev.org','Gitea 1.15.6','SSH port: 22; apparently became tor-hostile (403 forbidden)');
insert into forgesTbl (url_clrnet, software, dead, notes) values ('https://git.passageenseine.fr','Gitea 1.14.2',0,'Was previously down for a lengthy period thus considered unreliable.');
insert into forgesTbl (url_clrnet, software, dead) values ('https://gitea.shuishan.net.cn','Gitea',1);
insert into forgesTbl (url_clrnet, software, notes) values ('https://try.gitea.io','Gitea 1.15.0','Intended only for Gitea experimentation; no expectation of future availability');
insert into forgesTbl (url_clrnet, software, notes, cfns) values ('https://try.gitea.io','Gitea 1.16.0','Intended only for Gitea experimentation; no expectation of future availability',1);
insert into forgesTbl (url_clrnet, software, openpubreg, notes) values ('https://git.pofilo.fr','Forgejo 14.0.3',0,'no registration link');
insert into forgesTbl (url_clrnet, software, openpubreg, notes) values ('https://forge.april.org','Gitea 1.25.4',0,'French is the primary language; no registration form; access is for [April](https://www.april.org) members -- but perhaps April membership is open to all?');
insert into forgesTbl (url_clrnet, software, cfns) values ('https://git.eta.st','Gitea 1.15.0',1);
insert into forgesTbl (url_clrnet, software) values ('https://git.kescher.at','Gitea 1.16.5');
insert into forgesTbl (url_clrnet, software, openpubreg) values ('https://git.redxen.eu','Forgejo 14.0.2',0);
insert into forgesTbl (url_clrnet, software, notes) values ('https://gitnet.fr','Gitea','Forge is resource deprived. The admin (simonv) had to ask a project to leave his forge for [performance reasons](https://framagit.org/dCF/deCloudflare/-/issues/46)');
insert into forgesTbl (url_clrnet, software, notes) values ('https://git.exozy.me','Gitea 1.18.0','silently deletes repos without notice; [supports federated issues](https://social.exozy.me/@ta180m/108631221939677386)'); /* dCF censored */
insert into forgesTbl (url_clrnet, software, openpubreg) values ('https://git.platypush.tech','Forgejo 14.0.2',0);
insert into forgesTbl (url_onion, software, notes) values ('http://gg6zxtreajiijztyy5g6bt5o6l3qu32nrg7eulyemlhxwwl6enk6ghad.onion','Gitea','Focused on human rights. Goes by the name RightToPrivacy. Dysfunctional for git operations (both SSH and HTTP).');
insert into forgesTbl (url_clrnet, software, dead) values ('https://git.slipfox.xyz','Gitea 1.17.2',1);
insert into forgesTbl (url_clrnet, software, openpubreg) values ('https://git.veen.world','Gitea 1.25.3',0);
insert into forgesTbl (url_clrnet, software, openpubreg) values ('https://sloyd.work','Forgejo 1.19.0-2',0);
insert into forgesTbl (url_onion, software, notes) values ('http://it7otdanqu7ktntxzm427cba6i53w6wlanlh23v5i3siqmos47pzhvyd.onion','Gitea','graphical CAPTCHA imposed just to sign in! Calls itself “Darktea”');
/*
Bug: the record for de.edumat.io sorts unfavorably. We need a natural sort but that's not part of Sqlite. A collation function is needed:
@@ -81,14 +99,18 @@ insert into forgesTbl (url_clrnet, software, cflogin, hrecaptcha, notes) values
insert into forgesTbl (url_clrnet, software, hrecaptcha, notes) values ('https://salsa.debian.org','gitlab_ce','unavoidable','possibly restricted to Debian efforts; serves as an alternative to Debian''s email-only bug tracker');
insert into forgesTbl (url_clrnet, software, hrecaptcha, notes) values ('https://gitlab.freedesktop.org','gitlab_ce','unavoidable','possibly restricted to Freedesktop efforts; reg. blocked by reCAPTCHA');
insert into forgesTbl (url_clrnet, software, notes) values ('https://gitlab.tails.boum.org','gitlab_ce','possibly restricted to Tails efforts but no AUP says otherwise');
insert into forgesTbl (url_clrnet, software, notes) values ('https://gitlab.gnome.org','gitlab_ce','possibly restricted to Gnome efforts');
insert into forgesTbl (url_clrnet, software, hrecaptcha, notes) values ('https://gitlab.torproject.org','gitlab_ce','non-essential tasks','open registration; repo creation possibly restricted; Google reCAPTCHA is [allegedley](https://lists.gnu.org/archive/html/repo-criteria-discuss/2021-03/msg00000.html) used, but [not at registration time](https://gitlab.onionize.space)');
insert into forgesTbl (url_clrnet, software, notes) values ('https://gitlab.gnome.org','gitlab_ce','possibly restricted to Gnome efforts; Down for everyone or just Tor users who get a 406 error?');
insert into forgesTbl (url_clrnet, software, notes) values ('https://mypdns.org','gitlab_ee','Previously down-- sudden death of website without warning to repo admins. Came back online months later but peoples accounts and repos were mysteriously gone; Was home of the deCloudflare and /Right to be Offline/ projects; It was open reg but considered a “private system” whereby the option to create a new repo was not immediately available.');
insert into forgesTbl (url_clrnet, software, hrecaptcha, notes) values ('https://gitlab.torproject.org','gitlab_ce','non-essential tasks','open registration; repo creation possibly restricted; Google reCAPTCHA is [allegedly](https://lists.gnu.org/archive/html/repo-criteria-discuss/2021-03/msg00000.html) used, but [not at registration time](https://gitlab.onionize.space); its possible to [create an anonymous bug report](https://anonticket.onionize.space)');
insert into forgesTbl (url_clrnet, software, notes) values ('https://source.puri.sm','gitlab_ee','open registration but activity is [restricted](https://social.librem.one/@kyle/106030358887310621) to puri.sm efforts; accounts are subject to spontaneous unjustified bans (apparent censorship): ![](images/purism_ban.png); no CAPTCHA (confirmed March 2021); is the JavaScript non-free with the enterprize edition?');
insert into forgesTbl (url_clrnet, software, openpubreg) values ('https://source.small-tech.org','gitlab_ce',0);
insert into forgesTbl (url_clrnet, software, notes, openpubreg) values ('https://source.small-tech.org','gitlab_ce','TLS issue→ NET::ERR_CERT_COMMON_NAME_INVALID',0);
insert into forgesTbl (url_clrnet, software, openpubreg, cfns, notes) values ('https://git.shivering-isles.com','gitlab_ce',0,1,'Registration is open but broken-- requires 2FA using a device that can QR-scan, and the email verification link is DoA: ![](images/shivering-isles_broken_reg.png) That stale link error triggers even when accessed immediately.');
insert into forgesTbl (url_clrnet, software, cfns, dead) values ('https://git.stuxhost.com','gitlab_ce',1,1);
insert into forgesTbl (url_clrnet, url_onion, software, notes) values ('https://0xacab.org/','http://wmj5kiic7b6kjplpbvwadnht2nh2qnkbnqtcv3dyvpqtz7ssbssftxid.onion:44203/','gitlab','registration restricted to those from “friendly” domains');
update forgesTbl set forced_nfsw = null where software = 'gitlab_ee';
update forgesTbl set forced_nfsw = 1 where hrecaptcha = 'unavoidable';
update forgesTbl set lst_kind = 'gray' where lst_kind = 'white' and (aws or cfns or dead or nation_discrimination or (notes is not null and (notes like '%google_cloud_hosted%' or notes like '%censor%')));
update forgesTbl set lst_kind = 'gray' where lst_kind = 'white' and (aws or cfns or dead or nation_discrimination or (notes is not null and (notes like '%google_cloud_hosted%' or notes like '%censor%' or notes like '%spontaneous%' or notes like '%silently%' or notes like '%previously_down%' or notes like '%resource_deprived%')));
update forgesTbl set lst_kind = 'black' where cflogin or antitor or forced_nfsw;
update forgesTbl set notes = '**Cloudflare NS server** (they can route all traffic via CF at the flip of a switch)'||case when notes is null then '' else '; '||notes end where cfns;
update forgesTbl set notes = '**Amazon AWS-hosted**'||case when notes is null then '' else '; '||notes end where aws;
@@ -96,4 +118,4 @@ update forgesTbl set notes = '**dead site**'||case when notes is null then '' el
update forgesTbl set notes = '**forced h/reCAPTCHA**'||case when notes is null then '' else '; '||notes end where hrecaptcha = 'unavoidable' and notes not like '%captcha%';
update forgesTbl set notes = '**access granted or denied based on national origin**'||case when notes is null then '' else '; '||notes end where nation_discrimination;
update forgesTbl set software = 'Gitlab (CE)' where software = 'gitlab_ce';
update forgesTbl set software = software||'[⚠][gitea-bug]' where software like 'gitea_1.14%' or software like 'gitea_1.15%';
update forgesTbl set software = software||'[⚠][gitea-bug]' where software like 'gitea_1.14%' or software like 'gitea_1.15%' or software like 'gitea_1.16%' or software like 'gitea_1.17%' or software like 'gitea_1.18%';
+9 -6
View File
@@ -53,7 +53,7 @@ intro()
printf %s\\n 'The following forges have no significant ethical issues:'
;;
gray)
printf %s\\n 'These forges are not as seriously flawed as the blacklisted ones, but they should still be avoided if possible. Non-Cloudflare sites that use a Cloudflare NS server pose a risk for disruptions because they can trivially and spontaneously flip a switch and route all your traffic through Cloudflare, potentially cutting access to some of your contributors. Dead sites are also graylisted because if they come back online, they are known to be unreliable. Codeberg is graylisted for falsely accusing a repository of illegal conduct and deleting the content of all forks from that project without evidence or redress.'
printf %s\\n 'These forges are not as seriously flawed as the blacklisted ones, but they should still be avoided if possible. Non-Cloudflare sites that use a Cloudflare NS server pose a risk for disruptions because they can trivially and spontaneously flip a switch and route all your traffic through Cloudflare, potentially cutting access to some of your contributors. Sites that are dead or previously dead are also graylisted because if they come back online, they are known to be unreliable. Resource deprived instances are graylisted because they may become unstable or unreliable in the future, or if your repo is resource heavy you may be asked to leave. Codeberg is graylisted for falsely accusing a repository of illegal conduct and deleting the content of all forks from that project without evidence or redress.'
;;
black)
printf %s\\n 'These forges have severe ethical or trust issues and should be boycotted:'
@@ -130,8 +130,11 @@ table_md()
else
name_clause="case when url_clrnet is null then '' else replace(url_clrnet,'https://','[')||']('||url_clrnet||')' end"
fi
printf %s "## ${lst^}list
if [[ "$lst" != white ]]
then
printf %s\\n "## ${lst^}list"
fi
printf %s "
$(intro $lst)"'
| *forge* | *registration publicly open* | *software* | *Tor-hostile* | *Cloudflare MitM* | *forced re/hCAPTCHA* | *forced execution of non-free software* | *notes* |
@@ -143,7 +146,7 @@ $(intro $lst)"'
case when antitor then '${sym[eye]}' else 'n' end,
case when cflogin then '${sym[cloud_lightening]}' else 'n' end,
case when hrecaptcha = 'unavoidable' then '${sym[hammerpick]}' else 'n' end,
case when forced_nfsw then '${sym[biohaz]}' else 'n' end,
case when forced_nfsw then '${sym[biohaz]}' when forced_nfsw is null then '?' else 'n' end,
case when notes is null then '|' else notes||'|' end
from forgesTbl where lst_kind = '$lst'
order by software,url_clrnet collate nocase;"
@@ -162,9 +165,9 @@ case "$1" in
*)
printf '%s\n\n' '[//]: # (** DO NOT EDIT this file directly! ** It is auto-generated. Changes should be made to financial_institutions.sql or '"${0##*/}"' instead.)'
table_md
printf '\n%s\n' '⚠ Gitea versions note: Gitea 1.14.0 [breaks][gitea-bug] emoji in some browsers. The developers [believe](https://codeberg.org/Codeberg/Community/issues/444#issuecomment-198199) that by not supplying fonts to the web visitors who need them, they are improving server performance. Of course the server load is only reduced when talking to a browser that does not have the needed fonts. The idiots could also simply arbitrarily deny service to users at random to get a performance increase. Obviously they have misunderstood the point of performance in the first place: availability!
printf '\n%s\n' '⚠ Gitea versions note: Gitea 1.13.8 [breaks][gitea-bug] emoji in some browsers. The developers [believe](https://codeberg.org/Codeberg/Community/issues/444#issuecomment-198199) that by not supplying fonts to the web visitors who need them, they are improving server performance. Of course the server load is only reduced when talking to a browser that does not have the needed fonts. The idiots could also simply arbitrarily deny service to users at random to get a performance increase. Obviously they have misunderstood the point of performance in the first place: availability!
The best Gitea version ATM is 1.13.7 which opendev.org runs.
The best Gitea version ATM is 1.13.7 but there are no known instances of this.
[gitea-bug]: https://codeberg.org/Codeberg/Community/issues/444'
;;