Reply by email functionality disabled in Gitlab
Nate Graham
nate at kde.org
Tue Sep 15 19:32:12 BST 2026
Now horrible; thanks for taking care of it! I can confirm that emails
and email-based hookscripts are once again processing as fast as they
normally do from my perspective.
Personally, I find losing the "reply by email" functionality loss to be
acceptable. It results in lengthy quoted text in Gitlab comments which
are annoying to mentally filter out, and I won't miss those. :D
Nate
On 9/15/26 12:03 PM, Ben Cooksley wrote:
> Hi all,
>
> This is just a heads up that due to a recent wave of abuse centered
> around the Service Desk function in Gitlab, i've had to disable incoming
> email functionality on invent.kde.org <http://invent.kde.org> this
> morning. As a consequence, you will no longer be able to reply to emails
> from Gitlab and have that reply appear on the issue / merge request in
> question.
>
> This has been needed because abusive actors have discovered that the
> Service Desk function in Gitlab can be (ab)used to send emails to people
> using a configurable per-project template.
>
> This has happened a couple of times now in isolated instances, but a
> more concentrated wave happened today (with over 4,100 issues being
> created, with multiple people per issue being opened, so probably ~10k
> spam emails being sent using invent.kde.org <http://invent.kde.org>).
> These attacks appear to be a phishing campaign targeting Vinted (a
> second hand sales platform) on essentially all occasions this has happened.
>
> This was also why email delivery earlier today was running slow -
> because every single message going out of invent.kde.org <http://
> invent.kde.org> is subject to spam checks (and unfortunately the nature
> of this being a fairly small but targeted campaign means SpamAssassin
> unfortunately was unable to block this).
>
> Please let me know if there are any issues with this.
>
> Thanks,
> Ben
More information about the kde-devel
mailing list