I wish they had an actual feature comparison list. I've been trying to find anyone who can give me a list of non-trivial differences between the two; so far it's always either FUD about Gitea's governance and security structure or ForgeFed. The former has made me rather wary of the project[0] and the latter has been stagnate for years and I'm no longer convinced anything will come from it. Otherwise it's just silence.
Personally I thought Forgejo was doing better work on their actions runner for a while from casual changelog browsing but Gitea's been putting a lot of work into theirs. Otherwise it mostly still looks like a soft-fork in practice to me.
[0] Not that I'm thrilled with Gitea's semi-open-core setup and company but they make it seem like they're kicking puppies and dangling features over non-enterprise users head before snatching them away.
Unfortunately, seems like this is Forgejo's best suggestion on how to compare the two: https://i.imgur.com/j1665QR.png. Not sure that page helps much if you're not already bought in to a free-software-absolutist mindset
> This release contains security fixes. To give everyone time to upgrade, details will be added to this post in about a week.
Is this something that has been happening for a while or a new trend due to LLM concerns? I understand the reasoning, it just made me do a double take because I haven't really seen that before.
With Gitea specifically or in general? A lot of different software has silently included security fixes in updates combined with other changes and then later revealed what security fixes were made or stayed quiet about it all together, since long before LLMs could analyze changes.
Security researchers and malware authors would reverse engineer software updates of proprietary software, and scrutinise source code changes of open source projects to find secretly shipped security fixes.
(bias note: I am a project lead of Gitea) this approach is based on what peertube has been doing, and is being attempted as an alternative approach to what we've been doing previously due to feedback we've been receiving from the community.
https://forgejo.org/compare-to-gitea/
Personally I thought Forgejo was doing better work on their actions runner for a while from casual changelog browsing but Gitea's been putting a lot of work into theirs. Otherwise it mostly still looks like a soft-fork in practice to me.
[0] Not that I'm thrilled with Gitea's semi-open-core setup and company but they make it seem like they're kicking puppies and dangling features over non-enterprise users head before snatching them away.
Is this something that has been happening for a while or a new trend due to LLM concerns? I understand the reasoning, it just made me do a double take because I haven't really seen that before.
Security researchers and malware authors would reverse engineer software updates of proprietary software, and scrutinise source code changes of open source projects to find secretly shipped security fixes.