humanacollabora/forge_comparison.md

4.4 KiB

Directory of forges

Whitelist

The following forges have no significant ethical issues:

forge registration publicly open software Tor-hostile sensitive info exposed to CloudFlare forced re/hCAPTCHA forced execution of non-free software notes
(🧅) 💀 other/unknown n n n n dead site
codeberg.org 🟢 Gitea n n n n functions without any JavaScript and the JavaScript that exists is all 1st-party (ref)
framagit.org 🟢 Gitlab (CE) n n n n
git.fuwafuwa.moe(🧅) 🟢 Gitea n n n n SSH over Tor broken; HTTPS over Tor works
git.hardenedbsd.org 🟢 Gitlab (CE) n n n n possibly restricted to BSD efforts
git.jami.net 🟢 Gitlab (CE) n n n n possibly restricted to Jami efforts
git.nixnet.services 🔴 Gitea n n n n formerly git.nixnet.xyz
git.sdf.org 🟢 Gitea n n n n SSH over Tor broken but HTTPS over Tor works
git.slashdev.space 🟢 Gitea n n n n SSH over Tor broken (try HTTPS over Tor)
git.teknik.io 🔴 Gitea n n n n
gitlab.freedesktop.org 🟢 Gitlab (CE) n n n n possibly restricted to Freedesktop efforts
gitlab.gnome.org 🟢 Gitlab (CE) n n n n possibly restricted to Gnome efforts
gitlab.torproject.org 🟢 Gitlab (CE) n n n n open registration; repo creation possibly restricted; Google reCAPTCHA is allegedley used, but not at registration time
launchpad.net 🟢 Launchpad n n n n JavaScript is non-free, but it's unknown whether it functions without JavaScript; no wiki
notabug.org(🧅) 🟢 Gogs n n n n based on liberated fork of Gogs; supports Tor (the onion web UI is currently disabled in response to attack but the onion site accepts git connections); supports SSH keys and SSH over Tor to NAB's onion service; no e-voting; NAB doesn't associate PGP keys to users, so PGP signed commits may be unavailable or more manual work needed.
source.puri.sm 🟢 Gitlab (CE) n n n n open registration; not restricted to puri.sm efforts; no CAPTCHA (confirmed March 2021)
source.small-tech.org 🔴 Gitlab (CE) n n n n
sr.ht 🟢 Sourcehut n n n n javascript-free
yerbamate.dev 💀 Gitea n n n n dead site

Blacklist

These forges have severe ethical or trust issues and should be boycotted:

forge registration publicly open software Tor-hostile sensitive info exposed to CloudFlare forced re/hCAPTCHA forced execution of non-free software notes
bitbucket.org 🟢 Bitbucket Server n n n Amazon AWS-hosted; needs non-free javascript that clusterfucks uMatrix; has some relationship with Netlify; access to source code restricted
git.feneas.org 🟢 Gitlab (CE) n n reCAPTCHA impedes registration and imposes non-free s/w
git.openprivacy.ca (exclusive walled garden) other/unknown 👁 n n n Tor users get 404 - suspected botnet; listed as a Cloudflare supporter
gitlab.com (exclusive walled garden) Gitlab (EE) n 🌩 flagship instance running the Enterprise Edition; uses both hCAPTCHA & reCAPTCHA; heavily restricted with discriminatory policies
libregit.org 🔴 Gitea n 🌩 n n reg by invite only