I think that’s a very charitable interpretation, and that’s a good attitude in general. In this case though, given that this ended up with all toots and tweets about it, I would suspect notoriety and internet points are at the top of the list of at least some parties here…
Thank fuck that someone found this bug and let them and the rest of us about it so we can protect ourselves. My forgejo instance was already running on my tailnet with no public exposure but had been considering public disclosure of it for some collaborators.
There has been a lot of talk around forgejo as an alternative to github for months now. To now understand that their security posture seems to be, 'like, yaknow, whatever...' is disturbing.
I think both parties can take this opportunity to mature. I understand that Forgejo is a community project, but community projects should have standards or very explicit disclaimers when it comes to security.