I've never seen a .gitignore that was justified, ever. It probably shouldn't even exist. I've run into projects often enough with horked build scripts or bad docs about build pre-requisites, where upon failing partway through and necessitating some fix, the build failure leaves the tree in a state where it still won't build successfully even after fixing the thing that caused the original failure. The only fast fix is to rm .gitignore, then look at the output of git-status and rm -rf all the crap that it shows the original build attempt splattered everywhere before re-running the build script for a third attempt. Thanks, .gitignore.
.gitignore is banished in every project I'm in charge of. Everyone is required to manage their personal .git/info/exclude themselves, and any changeset attempting to slip .gitignore into the project will get ipso facto rejected. (Anyone is free to submit a change that adds a file contrib/gitignore if you think you have a set of useful globs relevant to the project that will be a help to others, along with instructions to cp that file to .git/info/exclude, but .gitignore is not making it in.)
Git needs to ship a git-ignore command (or extend git-config) that exclusively works by managing .git/info/exclude for you, including converting "legacy" .gitignore into the less anti-social version.
This is one of the strangest opinions I've seen in awhile. Your complaint seems like it should be pointed at projects not having a working "clean" make target.
Also:
git status --ignored
git clean -ndX # preview what would be removed
git clean -fdX # actually delete the files (warning: destructive)
Or, you could have a build system that does a 100% out-of-tree build into ./build, and then if the build is broken you delete that one directory. You hardly need git to help you with that.
Oh, I can? Cool advice! How do I get the people with bad hygiene that we're talking about to follow it?
(You have lost the plot; your response amounts to explaining how soap and water works to someone who has just described their office mate's tendency not to shower.)
Get a new job? You can't be that "in charge of" a repo if you can't enforce rules this basic. In fact, I don't understand how you can enforce something as (being polite) unusual as banning .gitignore and yet can't enforce build system hygiene.
> I’ve never found the GitHub wiki experience to be particularly ergonomic.
That's because the original sin of GitHub "wikis" is that they weren't (and most of them still aren't) even wikis. There's this perverse thing that happened during the wiki age, where people unable or unwilling to get on board decided to just start calling things "wikis" even though they exemplify the very thing that the wiki was invented as a response to. The reckless debasing of the word then infected adjacent spaces. Sourcehut's "read-only wikis" (wat) aren't even designed to be edited in the browser; on Sourcehut, "Publishing your changes is as easy as committing them and pushing them upstream." Newsflash: That's not a wiki.
Aside from memory safety, which is solved by using a compiler that just doesn't allow unsafe memory operations (so not GCC or Clang upstream), which CVEs specifically would have been ameliorated by a parser written in Rust instead of C?
> Aside from memory safety, which is solved by using a compiler that just doesn't allow unsafe memory operations
I don't see how that's possible without turning the language into something that isn't C, either by adding significant new functionality (e.g. fat pointers) or subtracting enough functionality that it's a much less capable language (e.g. disallowing dynamic memory allocation).
> People don't really sign up for protocols, they download apps.
This is both true and also if followed would fly in the face of what XMPP (and the Mastodon-flavored ActivityPub-powered fediverse of microblogs-and-more) is supposed to be about. And it's also both true and yet people understand what "email" means and how to use it without constantly and consistently running into issues trying to bang out a reply to alice@gmail.example even when the sender's inbox is hosted @yahoo.com—nor do folks spend much time thinking about how and why AT&T's SMSes (for example) are able to make their way to their friend's device even though they use Verizon (to give another example—and if they even know which provider their friend uses at all).
One thing that Jabber (and, later, Mastodon) did wrong was to take the unfortunate stance that it wouldn't be too big of a deal to adopt email-like identifiers without actually being email or implying that Internet-standard email services are available; it was felt that users would just be smart enough to adapt to it. This was a mistake.
The confusion with email, though, can be exploited as useful momentum—something that the network has going for it, instead of a flaw.
If the author and the rest of the Jabber/XMPP community wants the public to "give Jabber/XMPP a shot", then it probably does need (a) a flagship instance (a la mastodon.social) that controls multiple domains (the way that many email providers like Runbox or Fastmail do) and requires the user to pick which one they want their handle to be associated with at signup, in order to introduce email-like decentralization to the userbase as early as possible, and that (b) raises the bar by setting a standard among Jabber/XMPP instances and actually offering email services to that userbase (prior art: Google married (XMPP-based) Gtalk with Gmail in the early days).
While undertaking all of this, an effort to update the XMPP protocol (a la JMAP, but in a backwards-compatible way) while simultaneously reconciling it with legacy email (also in a backwards-compatible way) wouldn't hurt—where "backwards-compatible" here means "to gracefully degrade and provide a fallback" (prior art: Delta Chat).
I'm a former Mozillian and a lifelong Firefox user (continuously since Firefox has existed, at least). I know Firefox is slower. I can feel it and have felt it on every system I've ever owned, and am constantly reminded once every few months or weeks or so when I open up Chrome to check something and am confronted with how much snappier it is—even without an ad blocker, which I don't have installed because I don't actually use Chrome.
I know all this and I use Firefox anyway because I don't care.
What I don't do is go online and comment about how there's no difference when there is clearly a difference. Pretending things are otherwise comes across as some form of denial or delusion.
Pretty much every podcast in the world and all of their listeners are using RSS. WordPress powers something like 30% of the Web, and most of the operators behind those sites are publishing RSS whether they know it or not.
I thought I was more clear than I was being about rss in the context of the conversation about text based news.
How many people consuming text via rss the same way people consume audio via podcasts?
We're talking about text here. We all know how this sentence ends, "You should start a ..." and it isn't rss feed. Everyone used to have a blog and nobody really cared. Now everyone has a podcast and (more) people do. People don't know what an rss feed is.
> We all know how this sentence ends, "You should start a ..." and it isn't rss feed.
I don't know what this means. I'm guessing the correct answer is supposed to be "podcast"? Even so, weird false dichotomy.
That looking at tweets and listening to podcasts is more popular than reading long-form blog posts via RSS has a lot more to do with people's revealed preference for looking at tweets and listening to podcasts versus reading long-form blogs than it has to do with RSS.
(The actual context was delivery of notices by public services through non-Twitter feeds, anyway. Not blogging.)
> People don't know what an rss feed is.
I don't know why you think this is relevant here. It seems that when you're referring to using "RSS", what you mean is for people to care about RSS—in the way that Gemini, Secure Scuttlebutt, etc. have always been about caring about (and almost exclusively using them to talk about) Gemini, Secure Scuttlebutt, etc. than they ever were actually expected to be used organically and non-self-referentially.
The fact is that people (already/still) use RSS today. It hasn't been defeated. And Twitter could turn into an RSS-based feed reader tomorrow that works basically the same as it works today, and then suddenly everyone would be using RSS but no one would drop out because of it. Because people don't know (read: care) what an RSS feed is.
The amount of Codeberg FUD one can encounter on HN is unreal. I'm starting to question whether there's an organized effort behind it.
Both personal and private repos are explicitly permitted in the Codeberg TOS:
> Private repositories[…] allowed for really small & personal stuff like your journal, config files, ideas or notes, but explicitly not as a personal cloud or media storage.
As if there wasn't a massive amount of nuance between "you may keep your dotfiles private but don't upload your photo library". If their rules read this arbitrary, I wouldn't trust them to host any of my stuff, especially considering that you always have to hope they don't change their rules any further.
Assume you did some local LLM stuff in June that worked with a 200MB set of various jpegs and you wanted to keep it private: Is this still legit in September 2026? I wouldn't rely on it.
> , I wouldn't trust them to host any of my stuff, especially considering that you always have to hope they don't change their rules any further.
Yeah, I think this is a win-win for both parties.
You strike me as someone who would "ride along the lines of the terms of service" basically, and you'll see anything not explicitly forbidden as being allowed essentially.
While Codeberg is a project driven by humans, with human reactions to what's happening. If you're not comfortable with rules not being 100% defined, and requiring a humans value judgement to be had to figure out if the rule is broken or not, I don't think Codeberg is for you.
The rest of us, who are OK with humans making decisions rather than just going by what's written in rules, are fine with this, because we know our private repositories won't be deleted. And if they are, you'll be able to speak with a human to explain, and if your intention is fine and good, they'll be OK with it. But if you try to argue about some "That wasn't explicitly stated", then yeah, they'll probably get tired of you quickly.
Think your participating in your local user group vs some corporate/government forum, the rules will be enforced differently.
Do X in whatever way you want, if you do so knowing it's against the terms of service, you're "riding along the line of the terms of service" for sure if you try to explain away how it is/isn't explicitly forbidden.
No, it was just against every value Codeberg ever stood for, and against the value humanity should stand for. There was no ambiguity ever about this. There is no moral ambiguity that if people develop military FLOSS on codeberg they will be banned, even though it's not in the ToS right now, because that's the right thing to do and the community will reach a consensus that we want to support human communities, not military organisations who destroy them.
The rules say nothing about military AI and currently include selfhosted LLMs as well:
> You must not share projects that mostly consist of code written by "generative AI"-tools (including services such as Claude, OpenAI Codex). Such projects having an unclear copyright status (see requirements § 2 (1) 1 and § 2 (1) 3) and furthermore have little safeguards to ensure that they do not include harmful code (c.f. § 2 (1) 5).
At least stick with the truth before launching with "the right the to do" (which is also a pretty bad rule because it's completely ambiguous.)
I'm fine with ambiguous rules. A non-profit is not a legislative body, though to be fair even actual laws are usually ambiguous and contradictory and that's why we have lawyers and judges and such.
Ambiguous rules with clear objectives is what gives a non-profit the power to be flexible in the way to accomplish common goals. It's based on human trust and is fine by me and others. If you ever were part of a non-profit, you know human trust is an essential component.
Ok, point being? Codeberg is a non-profit community that evolves and figures out where to move, all the time, this is the point of the association itself. Members discuss what to do, then a decision is made, then new rules eventually apply, this is how the project moves forward.
You said people were “riding the line”. They weren’t. Codeberg made up a rule that excluded eligibility for projects they were already hosting. Projects that were not illegal, indecent or dangerous. I can’t think of another time something like that has happened. They can do it, sure, but many had hoped they could be an independent host for all FOSS as GitHub deteriorates. They have disappointed those hopes, and we will have to look to others - like Codefloe - to carry that hope forward.
> Codeberg made up a rule that excluded eligibility for projects they were already hosting
What does "made up" mean? It was a decision by the actual members of the platform, you know, the actual people using it! Nothing "made up" about it.
I think it's pretty clear you don't have an idea of what Codeberg is trying to be, nor do you have any interest in understanding, you just want to push this "Codefloe" platform for some reason. Codeberg make very public what the platform is for and yes, that'll change in the future too, as the world changes.
I'm sorry that phrase offends you so much that you have to resort to personal attacks. Why don't you respond to the actual substance?
The reason I'm supporting Codefloe is written in the comment you are responding to. Codeberg is not interested in hosting all FOSS, and Codefloe is. That is the reason. Its very simple.
It is pretty clear you are not making any effort at all to understand the problem people have with Codeberg's rug pull.
Not one programmer i know does this. Well no actually, one does because his boss makes him but it's so shitty he basically AI-washes his own job. How come on HN every week i come across someone who believes programming is dead and everyone has been brainwashed by Silicon Valley execs into destroying the planet with LLMs?
Honestly it is astonishing to me that there are still people who believe things like this. AI is just a tool. Software development still requires human minds.
There are people who don't understand that and crank out slop. Fuck those people. That isn't what I do.
There are people who don't understand that and won't host my FOSS. Well, I've found someone who will.
„ and if your intention is fine and good, they'll be OK with it“
That doesn’t work because „fine and good“ doesn’t mean the same thing to Codeberg voters/admins and to a large part of the hacke news population. Notably, Codeberg is morally opposed to AI.
> That doesn’t work because „fine and good“ doesn’t mean the same thing to Codeberg voters/admins and to a large part of the hacke news population.
Why on earth would Codeberg give even the slighest fucks about what the "hacker news population" finds "fine and good"? Makes absolutely zero sense.
Codeberg made those things against the Terms of Service because paying members who use the platform voted for exactly that. This is how Codeberg works, the members of the platform decides how it works.
You changed the topic. The topic is not what Codeberg should care about. The topic was trust in the humans behind Codeberg to not delete private repositories on a whim. Codeberg community is free to care about whatever it sees fit. That doesn't protect them from criticism.
Do I trust humans behind Codeberg to behave sensibly? No.
Would more precise terms of service that explain what Codeberg community thinks is ok help with such trust? Yes.
Should the humans behind Codeberg care what I think? Maybe? Presumably they do care about reaching _some_ users, otherwise why have the service public at all?
What a weird take coming from a pro-Codeberg perspective considering that many their users I are proudly #actuallyautistic people who would prefer strict rules to follow in order to feel secure.
> The rest of us, who are OK with humans making decisions rather than just going by what's written in rules [...]
Better speak for yourself and not infer from your own views to others. With bad intention this could be interpreted as if I was incapable of dealing with human decisions when all I stated is that I mistrust people who rugpull me.
"Use it for your personal notes, your side project or any other[sic] you want to keep private".
(That's even ignoring that I was addressing the claim that you actually made, which is different from the one you're making now; you're moving the goalposts.)
That language is not in the terms of service. The word "side" does not appear on that page.
The terms of service state:
> Private repositories are only allowed for things required for FLOSS projects, like storing secrets, team-internal discussions or hiding projects from the public until they're ready for usage and/or contribution. They are also allowed for really small & personal stuff like your journal, config files, ideas or notes, but explicitly not as a personal cloud or media storage.
The TOS Section 1:
> Our service is open for all projects covered by a licence for free and open source software, free and open source hardware, or free cultural works as defined by § 2 (1) 1.
So the "FUD" I am spreading is literally the headline of the legal terms of service. There is an organization behind the spread of this information, and it is Codeberg e.V.
You have made two concrete claims about Codeberg that are verifiably untrue:
"Codeberg does not permit personal repos"
"A private git repo with my own code, is not permitted"
Codeberg's policy explicitly permits personal repos, including private code repos. Both of your claims are false. There is no getting around this, no matter how much you try to move the goalposts or the other forms of conversational misdirection you're trying to pull off here.
You have made two concrete claims about Codeberg that are verifiably untrue:
"Codeberg does not permit personal repos"
"A private git repo with my own code, is not permitted"
Codeberg's policy explicitly permits personal repos, including private code repos. Both of your claims are false. There is no getting around this, no matter how much you try to move the goalposts or the other forms of conversational misdirection you're trying to pull off here.
> At best, registering an OAuth client is 5 minutes of clicking around a developer portal. But you never know.[…] DCR automates the client registration problem. Instead of requiring a human to manually get an OAuth client, your app dynamically provisions one, and then immediately starts the OAuth flow to this app it had never heard of before.
In the remoteStorage protocol, providers have been instructed to ignore client_id in lieu of identifying the connecting app by its origin.
.gitignore is banished in every project I'm in charge of. Everyone is required to manage their personal .git/info/exclude themselves, and any changeset attempting to slip .gitignore into the project will get ipso facto rejected. (Anyone is free to submit a change that adds a file contrib/gitignore if you think you have a set of useful globs relevant to the project that will be a help to others, along with instructions to cp that file to .git/info/exclude, but .gitignore is not making it in.)
Git needs to ship a git-ignore command (or extend git-config) that exclusively works by managing .git/info/exclude for you, including converting "legacy" .gitignore into the less anti-social version.
reply