Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I'm sorry to hear GitLab has not been solid for you. What bugs have you been affected by? What can we improve in our API? Regarding securing webhooks do you mean https://developer.github.com/webhooks/securing/ ?


I've already opened up some issues[1]. What you point to is what I mean, in addition a reverse IP lookup is also useful to tighten security a bit [2], but it's not mandatory. Specifying a secret is IMO the easiest way to have some peace of mind when it comes to accepting hooks. Regarding the API, I mainly found the documentation more difficult to navigate. There doesn't seem a section specifically for gitlab.com, so I just have to assume that 'community edition' applies there. I haven't found a place where the API endpoint for a gitlab.com profile is described, just took a bit of trial and error - and whatever isn't documented for an API I don't like to rely on.

[1] https://gitlab.com/gitlab-org/gitlab-ce/issues?scope=all&sor...

[2] https://developer.github.com/v3/meta/


Thanks for opening those issues days ago! I already marked the documentation issue https://gitlab.com/gitlab-org/gitlab-ce/issues/13479 for the attention of our technical writer 5 days ago. I think having the ability to specify a secret from webhooks makes sense and have asked our CTO and VP of Product for comments in https://gitlab.com/gitlab-org/gitlab-ce/issues/13478. GitLab.com runs GitLab EE, this is displayed at the top of https://about.gitlab.com/gitlab-com/ but please let me know if there is another logical place. The API endpoint paths are the same for all GitLab servers so https://gitlab.example.com/api becomes https://gitlab.com/api. I've made an issue to discuss replacing the example.com url with gitlab.com https://gitlab.com/gitlab-org/gitlab-ce/issues/13643

Thanks for all your feedback and creating issues!


You're welcome, and I appreciate the response. I forgot something btw., which is actually the biggest issue I had so far: We were affected by some variant of [1].

Regarding documentation, how about referencing 'gitlab.com' on the following top level selection? [2] You could add a new box linking to the EE documentation. That was the first place where I was looking and made me stumble.

[1] https://gitlab.com/gitlab-org/gitlab-ce/issues/3150

[2] http://doc.gitlab.com


Thanks for your suggestions.

1. Can you reproduce the web hook push event failure in any way?

2. Thanks for the suggestion, I made https://gitlab.com/gitlab-com/doc-gitlab-com/issues/55




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: