Hacker Newsnew | past | comments | ask | show | jobs | submit | nightpool's commentslogin

Are you sure? The change says "A malicious template repository could be used to read arbitrary data from the Forgejo host" (emphasis added). Couldn't an attacker create a template repo and then immediately create a new repo from their own template, causing the Forgejo process to execute their template code on the server?

They could, and this is definitely a RCE (a Remote Code Execution) vulnerability. GP confusion stems from the fact, that you (the forgejo user) must execute this attack on "your" instance. But of course the problem is that forgejo user can, in fact, be malicious, and use this vulnerability to escalate their priviliges from user to server.

It can't be done without authenticating first, but there's nothing about RCE that says that it must be sent from unauthenticated connection.


Would be good to label it "authenticated RCE" to make this clear

What does the error message mean by "Your search request"? Why is viewing a single file in a repository considered a search request? That smells like poor caching somewhere

Thanks Mustafa! This was a great article—I'm curious, did you consider the non-technical / organizational costs in keeping the two codebases in sync as a separate factor? Do you foresee more organizational overhead as part of this decision? How are you planning to manage that? E.g. small implementation difference between the iOS and Android app increasing the support burden or bug burden and causing duplicated team effort.

This is not the author. It's very likely Farhan Thawar, head of eng at Shopify

Ah, you're right, my mistake—wasn't reading the username carefully enough

This is a great point that I wish the Shopify article went into in more depth! Would love to hear if they considered this

I believe they have a more in-depth posting that talks about it

https://shopify.engineering/shop-app-migration


The blog post doesn't mention the personnel-related challenges with having two native platform teams working on the app.

The post DOES give more information as to why they looked at switching from React Native to native Platform APIs.

React Native is forcing a major refactor of React Native apps in switching to the React Native "New Architecture" (see https://reactnative.dev/architecture/landing-page).

So if Shopify had to do major refactors of all their React Native apps, maybe they could look at what it would take to go back to native Platform APIs.

from https://shopify.engineering/shop-app-migration

  For the Shop App, this coincided with our next major React Native investment: adopting the New Architecture. That work would have required us to revisit native module integrations, rendering, and the boundaries between shared and platform-specific code. Before committing to this investment, we tested whether coding agents could help us build directly in SwiftUI and Jetpack Compose while keeping product behavior aligned across platforms.

The result of that native platform APIs side project involving six devs converting the app's major user workflows?

- startup time reduced: iOS by 23%, Android by 50%

- crashes - 10x reduction

- app size - iOS increased by 1MB (67MB -> 68MB), Android reduced by 109MB (37.2%)

- build time - Android release build time fell ~75%.

- runtime perf - Android builds could draw at 120fps while scrolling feed and switching screens


> The traffic still has to flow from an india provider to the international leg and back via the domestic provider.

Right, but Cloudflare doesn't have to pay for it in that case. If Cloudflare sends you to their Indian POP, then they have to pay their Indian service provider for traffic. If they send you to their France POP, then they have to pay their French ISP for traffic. The Indian provider cannot claim any of Cloudflare's traffic in that case, because the Indian service provider wouldn't have any relationship with Cloudflare

This is very standard for places with high ISP costs, like South Korea and India. You can see a lot of discussion about it online. I agree with you that Cloudflare should be more transparent if / when they make different routing decision for Free/Pro plans based on bandwidth costs, but I don't think their decision itself is unreasonable at all. Indian bandwidth is very expensive.


You would think Cloudflare would be in a position to do something about it, like they did with several cloud services in their Bandwidth Alliance. It would be a win-win-win for networks to interconnect better in India, it just can't happen stepwise because any individual step is a lose for somebody.

Do you have any sources for this? My understanding is that all of the discussion about prediction market wildfires are completely speculative, nobody has actually started a wildfire for a prediction market payout yet.

I've been in the desert fighting fires for the last 4 months. The news isn't going rampant with the arson stories for reasons (who knows, scaring the public, informing the public, etc).

Open the watchduty app and start looking into how many fires are currently arson suspected/apprehended and how this is the largest national wildfire year we've ever had.

The Dick and Cleetus methheads doing this stuff aren't the brightest and most well informed tech risk takers out there. Most of them will get caught and never get a dime, who the hell knows how why or else they're causing fires, the FBI isn't investigating anyone. They don't tell us WHY an arson occurred. Who knows how many of these apps exist in other markets, etc. The last global wildfire article I saw said either 86 or 96 arsons were arrested. I can't remember if it was France or in Africa.

This is THE strangest wildfire year anyone has had and the news is nowhere.

I'm not the only ex-tech wildland person, plenty of laid off firefighters right now back to their old lives.

https://www.cnn.com/2026/07/17/climate/betting-wildfires-pol...

https://www.theguardian.com/world/2026/aug/14/arrested-suspi...


It used to be out-of-work firefighters doing it for a paycheque. Now I guess they can collect without leaving the couch.

If you win this bet, does the payout come delivered to your door by the police and fire chief?

The chat example here doesn't really seem to work for me—I get 32 FPS consistently no matter what the chat settings are. Maybe a Chrome thing? Or an M3 thing?

Have you interviewed any of these candidates yet? I doubt that you have 500+ real candidates. My experience in the past 12 months of hiring is that you'll have maybe 10 "qualified on paper" candidates, and 490 AI-generated profiles.

Hard to be too mad at the applicants when a similar percentage of the roles might also be fake.

That might be true if you're applying for a megacorp like AWS or something but hard to feel like that's a valid argument when you're applying to a company with 2 open roles.

Small companies I've worked for are "always hiring". They leave job descriptions posted in case they get some miracle applicant.

you only got 10 qualified applicants to a generic software engineer position? i am having hard time beliving that sorry.

Cool, but, uh, this seems really astroturfed? Why are there two anti-Perplexity articles from independent research firms with identical websites on the front-page of HN right now, submitted by the same person? Feels like they should get deleted

(see https://news.ycombinator.com/item?id=49536201)


I don't even know if I disagree with this post, but this seems really astroturfed. Why are there two anti-Perplexity articles from independent research firms with identical websites on the front-page of HN right now, submitted by the same person? Am I going crazy?

(see https://news.ycombinator.com/item?id=49536375, left a comment there also)


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: