upvote
With Gitea specifically or in general? A lot of different software has silently included security fixes in updates combined with other changes and then later revealed what security fixes were made or stayed quiet about it all together, since long before LLMs could analyze changes.

Security researchers and malware authors would reverse engineer software updates of proprietary software, and scrutinise source code changes of open source projects to find secretly shipped security fixes.

reply
(bias note: I am a project lead of Gitea) this approach is based on what peertube has been doing, and is being attempted as an alternative approach to what we've been doing previously due to feedback we've been receiving from the community.
reply
Bizarre policy. Any bad guys unaware of the security implications are analyzing the patch diffs as we speak, so this seems nonsensical to me.
reply
Yeah maybe it made sense in the past, but not in the age of AI.
reply