4 ms·
This looks really cool and is something I would love to check out, but the permissions of the actual app seem pretty high. For us, our code is stored in a priva
by x0ner 11y ago
This looks really cool and is something I would love to check out, but the permissions of the actual app seem pretty high. For us, our code is stored in a private repository with no plan for any public release. Permissions for Zube are asking to not only read the private repository code, but also have write access to them as well. There's also requests to read/write web service hooks, deploy keys and pull requests. Is this a byproduct of Github's design or does the app really need all of these permissions to function properly?
- jenniferDewalt 11y agoWe totally understand your concerns and we take security very seriously. In order to manage GitHub issues, GitHub currently requires the repo scope. If there was a more restrictive scope just for GitHub Issues, Zube would use that one instead, but there isn't. Zube requires the same permissions as many other applications, the same permissions as Slack, for example. On our side, Zube only accesses data related to your GitHub issues and never touches your code at all. All of the calls Zube makes to the GitHub API are whitelisted (on our end) to ensure that Zube only accesses the data it needs. For extra security, we also encrypt your auth token before storing it. It’s also important to note that your auth token is specific to Zube and at any time you can revoke your token on GItHub.