lemmy.yachts
  • Communities
  • Create Post
  • Create Community
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
communism@lemmy.ml to Open Source@lemmy.ml · 1 year ago

Anyone can Access Deleted and Private Repository Data on GitHub

trufflesecurity.com

external-link
message-square
16
fedilink
  • cross-posted to:
  • [email protected]
129
external-link

Anyone can Access Deleted and Private Repository Data on GitHub

trufflesecurity.com

communism@lemmy.ml to Open Source@lemmy.ml · 1 year ago
message-square
16
fedilink
  • cross-posted to:
  • [email protected]
Anyone can Access Deleted and Private Repository Data on GitHub ◆ Truffle Security Co.
trufflesecurity.com
external-link
You can access data from deleted forks, deleted repositories and even private repositories on GitHub. And it is available forever. This is known by GitHub, and intentionally designed that way.
alert-triangle
You must log in or # to comment.
  • visor841@lemmy.world
    link
    fedilink
    arrow-up
    29
    arrow-down
    1
    ·
    edit-2
    1 year ago

    While this is still a massive problem, it does require a public fork at some point. So if you have a private repo that has never had a public fork, you should be safe.

  • Lung@lemmy.world
    link
    fedilink
    arrow-up
    9
    arrow-down
    2
    ·
    1 year ago

    Damn that’s a huge problem

  • asudox@lemmy.world
    link
    fedilink
    arrow-up
    6
    ·
    1 year ago

    Im thinking of self hosting Forgejo one day.

    • Deckweiss@lemmy.world
      link
      fedilink
      arrow-up
      5
      arrow-down
      1
      ·
      1 year ago

      I do and it is pretty easy with docker compose.

    • Aatube@kbin.melroy.org
      link
      fedilink
      arrow-up
      0
      ·
      1 year ago

      sourcehut is much better if you can pay

      Edit: Only repo hosters need to pay. Everything else is free.

      • asudox@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        edit-2
        1 year ago

        I want forgejo for its upcoming federation feature tbh.

        • Slotos@feddit.nl
          link
          fedilink
          arrow-up
          0
          ·
          1 year ago

          Considering that git doesn’t need federation, and email is the grandfather of federation, sourcehut has a working version of it this very moment.

          • Aatube@kbin.melroy.org
            link
            fedilink
            arrow-up
            0
            ·
            1 year ago

            Why the downvotes?

            • NekuSoul@lemmy.nekusoul.de
              link
              fedilink
              arrow-up
              1
              ·
              1 year ago

              I’d guess because the same argument could be made for the website you’re on right now. Why use that when we could just use mailing lists instead?

              More specifically: Sure, Git is decentral at its core, but all the tooling that has been built around it, like issue tracking, is not. Suggesting to go back to email, even if some projects still use it, isn’t the way to go forward.

  • youmaynotknow@lemmy.ml
    link
    fedilink
    arrow-up
    6
    ·
    edit-2
    1 year ago

    Just this week I migrated all my repos from github to Gitlab. And only because I can’t host my own gits just yet, but will do it soon enough.

    • 🇦🇺𝕄𝕦𝕟𝕥𝕖𝕕𝕔𝕣𝕠𝕔𝕠𝕕𝕚𝕝𝕖@lemm.ee
      link
      fedilink
      English
      arrow-up
      4
      ·
      1 year ago

      I tried but they demanded a phone number and credit card for “verification” and fuck that.

    • gravitas_deficiency@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      2
      ·
      1 year ago

      Codeberg is great too

      • youmaynotknow@lemmy.ml
        link
        fedilink
        arrow-up
        2
        ·
        1 year ago

        Yeah, I’m just getting started, and for the life of me, haven’t found how to pull the Gitlab repos from it. But I will.

  • Eager Eagle@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    arrow-down
    1
    ·
    1 year ago

    The takeaway is to not use forks if there are changes you want to keep private.

  • nao@sh.itjust.works
    link
    fedilink
    arrow-up
    4
    arrow-down
    2
    ·
    1 year ago

    After reviewing the documentation, it’s clear as day that GitHub designed repositories to work like this.

    Sounds like they wanted to find a problem but it turned out to be a feature.

    • Eager Eagle@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      1 year ago

      a problem that is documented is obviously a feature

Open Source@lemmy.ml

opensource@lemmy.ml

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: [email protected]

All about open source! Feel free to ask questions, and share news, and interesting stuff!

Useful Links

  • Open Source Initiative
  • Free Software Foundation
  • Electronic Frontier Foundation
  • Software Freedom Conservancy
  • It’s FOSS
  • Android FOSS Apps Megathread

Rules

  • Posts must be relevant to the open source ideology
  • No NSFW content
  • No hate speech, bigotry, etc

Related Communities

  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]
  • [email protected]

Community icon from opensource.org, but we are not affiliated with them.

Visibility: Public
globe

This community can be federated to other instances and be posted/commented in by their users.

  • 88 users / day
  • 1.45K users / week
  • 3.37K users / month
  • 10.5K users / 6 months
  • 1 local subscriber
  • 38.8K subscribers
  • 1.65K Posts
  • 13.5K Comments
  • Modlog
  • mods:
  • Evan@lemmy.ml
  • kevincox@lemmy.ml
  • CrypticCoffee@lemmy.ml
  • Lettuce eat lettuce@lemmy.ml
    cake
  • BE: 0.19.7
  • Modlog
  • Instances
  • Docs
  • Code
  • join-lemmy.org