[fdo] Spam from gitlab.freedesktop.org

darkdragon darkdragon-001 at web.de
Wed Jul 13 00:07:07 UTC 2022


Did you add any commits to any repos (including Gitlab Wiki)?

When cloning the repo (or using the API?), one can read out author and
committer e-mail addresses publicly.

On Wed, Jul 13, 2022, 01:28 LE GARREC Vincent <legarrec.vincent at gmail.com>
wrote:

> Thanks for the answer.
>
> By spam, I mean : "New profiles of this week's girls" from "aqwawhx@@at@@antony-hoste..dot...free...dot...hr"
> (mail obfuscation ;) )
>
> As I said, I have a different mail for each online service so I don't care
> about the spam.
>
> But I think it's important to warn you about a possible breach. If no
> other people complains, the breach came from me ^.^
>
> Le mar. 12 juil. 2022 à 21:28, Lyude Paul <lyude at redhat.com> a écrit :
>
>> Hi! Actually I think you've got the right place :). By "spam" do you just
>> mean Gitlab's slightly over-bearing email notifications?
>>
>> And regarding email addresses being public info: no, gitlab does store
>> email addresses but the only people who can see them are the user in
>> question and gitlab instance admins (so Daniel Stone, Benjamin Tissoires,
>> and some folks from the bard like myself). I hope that answers your
>> question, feel free to respond if you have more!
>>
>> On Fri, 2022-07-08 at 17:15 +0200, LE GARREC Vincent wrote:
>>
>> Dear,
>>
>> Today, it's the second time I received spam from my freedesktop gitlab
>> mailbox. The first time was about 2 months ago (sorry, I didn't keep the
>> mail).
>>
>> I use a different mailbox for each inscription on the web. My unique mail
>> is something like freedesktop-gitlab-with-arobase-at-my-name.fr.
>>
>> Is it possible that my mail from the gitlab inscription may be accessible
>> from the Internet?
>>
>> If not, then I just want to worry about it. I'm not really sure if it's
>> the right place to post.
>>
>> Best regards,
>>
>> Vincent
>>
>>
>> --
>>
>> Cheers,
>> Lyude Paul (she/her)
>> Software Engineer at Red Hat
>>
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.freedesktop.org/archives/freedesktop/attachments/20220713/581bbcc6/attachment.htm>


More information about the freedesktop mailing list