VLLM supply chain attack.
Creator possibly was compromised and likely a security measure.
Affected versions were not pushed IMO, but the owners machine may have been compromised.
A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.
Rules:
Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.
No spam posting.
Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.
Don't duplicate the full text of your blog or github here. Just post the link for folks to click.
Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).
No trolling.
No low-effort posts. This is subjective and will largely be determined by the community member reports.
Resources:
Any issues on the community? Report it using the report flag.
Questions? DM the mods!
VLLM supply chain attack.
Creator possibly was compromised and likely a security measure.
Affected versions were not pushed IMO, but the owners machine may have been compromised.
Honestly as much as people hate the complexity sometimes replicating the repo from Github to Codeberg or other places is great for redundancy. Or maybe use a local repo for all development and releases and push out to public VSC.
Self host your own code repo. Forgejo is adding activitypub and federation features, not sure how far long they are, but someday if enough people start self-hosting we might have a viable decentralized way to collaborate on and contribute to each others' projects.
With AI search engines hosting public repo is very expensive.
Because of the AI-induced scraping traffic? While not perfect, Anubis and similar are coarse-but-effective solutions for self-hosting repos.
And if it it were acceptable to outsource such protection to a CDN (eg Cloudflare) in order to retain firm control over the repo, then that's a choice that's also available. Not everyone agrees that CDNs have a role in self-hosting -- fair enough -- but when a project's very repo and existence can be wiped off the internet, owning a domain name and the affirmative upstream repository is a tractable and intermediate goal, even if it doesn't achieve full independence.
Self hosting is an exercise in harm reduction.
Centralization strikes again