5 ms·
I have over 200 open source repos, and 2-3 private once on GitHub. They are private for a reason and it's irresponsible of GitHub to "force" me to make this cho
by watson 10y ago
I have over 200 open source repos, and 2-3 private once on GitHub. They are private for a reason and it's irresponsible of GitHub to "force" me to make this choice in order to participate in the echo-system of 3rd party apps that connect to GitHub. In todays developer world, you need a lot of these 3rd party tools in order to be a productive programmer (granted not this one, but hey).
It's even more irresponsible of this dev WHO WORKS AT GITHUB to take this fact to lightly. Read AND write access to both my public AND private repos is an insane amount of trust to put in another person. I'm sure this person is a stand up individual. But does he/she write secure code? How easy is it to gain access to his database of access tokens?
In this world of Yahoo/Sony/You-name-it hacks that we live in, I'm honestly surprised there haven't been a hack yet where someone got a hold on a whole bunch of access tokens to private repos. You could do A LOT of damage with this. I'll never sign up for a service such as this and the author should be ashamed to even suggest it.
Instead he/she should focus their time on fixing this issue at GitHub instead of making apps like this.
- vhost- 10y agoThis app was made by Reflect not Github. By the way, github has this coming down their development pipeline: https://developer.github.com/early-access/integrations/ https://developer.github.com/early-access/integrations/
- j_s 10y agoecho-system I like it! Kind of a mash-up with echo chamber, which seems equally applicable. In case English is not your favorite language, the word I believe you're looking for is ecosystem.
- watson 10y agoUps, thanks :)
- sakabaro 10y agoMore and more apps require this. It's ridiculous for even code scoring to require total access to a GitHub account.