"Yesterday (2021-03-28) two malicious commits were pushed to the php-src repo"
In related news, PHP switches to hosting their repositories on GitHub.
@fribbledom I mean as long as I dont need a github account to participate thats ok.
I'm honestly concerned about that monoculture on github.
For example if some country now decides to block US services, you will not be able to contribute to PHP anymore, merely because they depend only on github instead of an independent, self hosted service.
I understand. That's not possible. But I don't see much problems in that when offsetted to the point of maintenance/upkeep they have to do.
You provide a valid problem, but the same could happen to for instance hosted gitlab. Hosting over multiple vendors is an admin nightmare as well. So the only way is to self host. Which could ofcourse also be blocked.
Short summary: I don't think there is a perfect solution that satifies all problems.
Server run by the main developers of the project It is not focused on any particular niche interest - everyone is welcome as long as you follow our code of conduct!