12 ms·
GitHub announcements: Marketplace, Apps and GraphQL API
- davidjgraph 9y ago"...fine-grained repository permissions with GitHub Apps...", excellent, this caused us more problems integrating than anything else. Especially for an organization, anything beyond 15-20 repos and they just couldn't give permission. Edit: It only applies to Github Apps, we have an OAuth App. shame.
- bkeepers 9y agoGitHub Apps also support authenticating users with OAuth, so you might want to check out if it makes sense to migrate. https://developer.github.com/apps/building-integrations/setting-up-a-new-integration/about-choosing-an-integration-type/ https://developer.github.com/apps/building-integrations/sett... https://developer.github.com/apps/building-integrations/setting-up-and-registering-github-apps/identifying-users-for-github-apps/ https://developer.github.com/apps/building-integrations/sett...
- therealmarv 9y agoI did not followed recent GitHub news closely. Is GraphQL a new thing at GitHub? And do you think GitHub integration benefits from this?
- dewski 9y agoWe've been developing on GraphQL internally for the past year, releasing our public preview on September 14th of last year: https://githubengineering.com/the-github-graphql-api/ https://githubengineering.com/the-github-graphql-api/ All new features at GitHub are now developed with GraphQL first which means integrators will have access to the same API that we built the feature on once it ships. If you want to learn more, one of our engineers just spoke at GraphQL Europe yesterday detailing our experiences with GraphQL thus far, here are his slides: https://speakerdeck.com/bswinnerton/launching-githubs-public-graphql-api https://speakerdeck.com/bswinnerton/launching-githubs-public...
- m12k 9y agoGraphQL is a method of creating APIs for consumption by e.g. JavaScript apps or mobile apps that is gaining popularity at the moment. So it can be seen as a successor to REST. It gives you a pretty easy query language to specify which data on which objects you are interested in and that data is then fetched for you. An example could be a React app where each component specifies which data it needs to work on, and then when a page is loaded, all of the rendered component's queries are merged into a single query that fetches all the data in one go.
- nailer 9y agoThe main thing vs REST is that it fixes the 'overlapping data in resources' issue. Want a timeline of tweets? Well you'll also want avatars to display, and you probably don't want that in a separate resource (because of multiple requests), so both /tweets and /users/userid will give you avatar details. It's a bit messy. In graphQL there's one resource and you query it to tell you what you want.
- philstu 9y agoHey! I cover that a bit ni a followup blog post :) https://blog.runscope.com/posts/you-might-not-need-graphql https://blog.runscope.com/posts/you-might-not-need-graphql tl;dr: maybe you want OData, JSON-API, or one of the many other standards or practices that solve this simple problem as their super-set of functionality on top of the networking principles of REST. Using GraphQL for this alone is rather nuclear, as you gain a lot with GraphQL but lose other stuff.
- nailer 9y agoWhat do you lose? I actually use REST ATM but interested in GraphQL for my next project.
- mpetrovich 9y agoREST and GraphQL are two completely different things, and one is not a replacement for the other. REST is an architectural concept, whereas GraphQL is a query language spec. https://philsturgeon.uk/api/2017/01/24/graphql-vs-rest-overview/ https://philsturgeon.uk/api/2017/01/24/graphql-vs-rest-overv...
- m-j-fox 9y agoGraphQL sounds like a cool thing I should be using already. Now let me scroll down to find out why it's a dumpster fire I should avoid at all costs.
- deleted 9y ago[deleted]
- brentvatne 9y agoThere is some undesirable horizontal scrolling on this page for me (mbp 13") -- fixed by adding `overflow: hidden` to `div role="main"` element.
- codefined 9y agoJust hiding bugs isn't a good practice! It'll ruin responsiveness with lower resolutions where that content is required. Actually fix the underlying cause, not just add a quick hack to make it go away.
- kareemm 9y agoI'm a partner at Codetree[1], one of the four launch partners in the project management category of GitHub Marketplace[2]. Happy to answer questions about our experiences working with the GH team to integrate, why we decided to list in Marketplace, etc. [1] - http://blog.codetree.com/articles/project-management-launch-partner-in-github-marketplace.html http://blog.codetree.com/articles/project-management-launch-... [2] - https://github.com/marketplace/codetree https://github.com/marketplace/codetree
- venning 9y agoYou might be the wrong person to ask, but I can't really find anything about this elsewhere: As an App/Integration, is your interaction with the GitHub interface itself limited to only those things that you can do via API calls, such as creating new issues? Or do you have some capacity to modify or add on to the existing interface?
- kareemm 9y agoAs far as I know there's no capacity to add onto the existing GH interface - all interaction is via APIs and webhooks.
- saimiam 9y agoAlso spam. Start your own Ask HN thread if you're so excited about GitHub.
- 23david 9y ago"Once your revenue reaches a minimum of $500 USD for the month, you'll receive an electronic payment from GitHub for 75% of the sales price." So it looks like Github takes a 25% fee. I thought maybe they would do something more innovative regarding the fee structure, or maybe have a lower intro fee like 15%. But here is seems pretty much on par with the 30% of the Heroku marketplace.
- LeanderK 9y agoWow, i think 25% is more than enough, they don't have costs that justify 25%. It's just their monopoly that allows them to charge that much.
- bradleyankrom 9y agoMonopoly in what sense? There is certainly healthy competition in the hosted Git repository space.
- lmm 9y agoNot really. There are a couple of also-rans but I'd be amazed if GitHub had less than 95% of the market.
- overcast 9y agoYou mean the ones that delete their databases without backups?
- bradleyankrom 9y agoI assume you are referring to GitLab, so yes. GitLab and Bitbucket are both actively releasing new features and have sizable paid user bases. GitHub is the market leader, no question, but it not nearly a monopoly.
- stephenr 9y ago"Market" is an interesting concept here. Do you compare all usage, or just their hosted versions (i.e. do on-premise installs count)? Do you compare all usage, or just paid usage? Can a company that's not even close to profitable be considered a "market leader"?
- ma138 9y agoCongratulations to the GitHub team for a great release here on the new Marketplace. I'm Matt - CEO at ZenHub [1], one of the launch partners for the Marketplace. We've been building apps on top of the GitHub platform for 3 years now and watching the evolution has been amazing. The three releases here have really helped with our biggest integrator pain points: GraphQL - better and faster access to data without hitting API limits GitHub Apps - not having to ask users for so many permissions! Marketplace - user acquisition targeted specifically at GitHub users [1] https://github.com/marketplace/zenhub https://github.com/marketplace/zenhub
- retox 9y agoSpam
- scrollaway 9y agoZenhub is great Matt, good to hear it's beneficial to you :) I'm going to recommend it to others here, with a caveat: I really wish it would not be so aggressively hijacking the Github UI. Tabs and side panels move around because the JS on the page finishes executing, making the Github UI feel super sluggish. We also have a lot of projects which end up with the settings tab in a "More" dropdown, despite Boards and Reports being more easily accessible from keyboard shortcuts (and we don't even use Reports)... All those features are great, but there's no option to turn them off at the UI level, or customize them in any way. Very annoying :(
- ma138 9y agoThank you for the kind words - and the honest feedback! This are similar to thoughts we have heard for other users and we are working on better ways to give you more control over the UI in the near future
- Klathmon 9y agoThis is really cool, and I just discovered sentry.io because of it which is something that we have wanted but hadn't yet put the time into finding.
- mwarkentin 9y agoSentry is pretty awesome. There are a few similar services like Airbrake, Rollbar, etc.
- tedmiston 9y agoBoth Sentry and Rollbar are incredible for debugging purposes.
- nailer 9y agoAfter trying new GitHub Desktop Beta mentioned in the article a week ago: it's still nowhere near compete enough to work: - You can only stage all changes in a file - so you can't discard 'console.log('Wooo'); debugger;' when committing, you have to remove those in your editor first, then commit. - you can't reverse commits. Need to roll HEAD back to a previous commit, push those fixes, then resume what you were working on? You can't do it. - still no graphical interactive rebase to merge and squash and reorder commits (the main reason people put up with sourcetree). It feel fast and responsive though. Edit: downvotes seem odd. If you think this is offtopic, the GitHub Desktop Beta is announced in the article.
- cheshire137 9y ago> You can only stage all changes in a file If I'm understanding you correctly, this is wrong. You can add individual lines in a file to your commit. That's one of the main uses I have for the app: it's easier to split up file changes between commits than on the command line. See this screenshot: http://imgur.com/a/4CQG7 http://imgur.com/a/4CQG7 You have to click on the line numbers to add/remove individual lines.
- IshKebab 9y agoNot a very obvious UI!
- danielsamuels 9y agoSourceTree is much better in this regard.
- leesalminen 9y agoUI is same as Tower. Doesn't seem that far off for me.
- roryokane 9y agoNo, Tower works differently (unless it has changed in the few months since I used it). In Tower, you can select lines by clicking line numbers, but then you must click "Stage" to actually stage those lines. Then your selection is cleared and those lines are moved to a separate "Staged" tab for that file. Whereas with GitHub Desktop, just selecting the lines marks them as lines to be staged. (GitHub Desktop doesn't actually run `git add` on those lines until the moment you click "Commit".)
- avaer 9y agoHm, I like Github but I don't like this. This is a great move, but we already have a code hosting monoculture, and this subtly piggy-backs on it towards lock-in for tooling. Github knows orgs have inertia. Sorry for the slippery slopeism. I'm just imagining a future where shipping an app without a middleman moves to inconvenient, then annoying, then difficult, then impossible. Because this is exactly how we lost the ability to send email without paying the middleman privacy tax.
- k__ 9y agoYes, seems a bit like Bitbucket/Jira stuff, and I don't know many people who liked it.
- graphememes 9y agoHonestly, the marketplace doesn't seem like a good fit for Github. I couldn't see my company or any organization that I am in buying services through Github when we have that capability in the following locations already: - Docker - Heroku - AWS - Google - Direct Feels more for "discovery" than purchasing.
- eriknstr 9y ago>this subtly piggy-backs on it towards lock-in for tooling FTA: "More than a dozen integrators have apps in GitHub Marketplace today, including Travis CI, Appveyor, Waffle, ZenHub, Sentry, and Codacy" Travis CI and many others were widespread prior to this marketplace. Seems to me that creating a marketplace is a logical way to collect these third-party services in one place.
- YPCrumble 9y ago...and charge the going market rate of 30% of any revenue earned via the GitHub platform.
- robzyb 9y agoTravisCI Pro Bootstrap direct is $69: https://travis-ci.com/plans https://travis-ci.com/plans TravisCI Pro Bootstrap via Github is $89: https://github.com/marketplace/travis-ci/plan/MDIyOk1hcmtldHBsYWNlTGlzdGluZ1BsYW43MQ== https://github.com/marketplace/travis-ci/plan/MDIyOk1hcmtldH...
- ed_blackburn 9y agoI wonder how this will work with GitHub Enterprise?
- bkeepers 9y agoGraphQL will be available in GitHub Enterprise 2.10, and GitHub Apps will be available in 2.11. For Marketplace, we will be researching how to solve similar problems for Enterprise customers after this initial launch.
- santiagobasulto 9y agoAnyone knows if they plan to deprecate V3 (which is likely) and when?
- bkeepers 9y agoWe don't have a timeline yet, but any updates will be posted on the API blog: https://developer.github.com/changes/ https://developer.github.com/changes/
- hashkb 9y agoDoes that mean you do plan to sunset it?
- awj 9y agoNot trying to be rude, but why would someone build a V4 API and plan to keep the V3 API alongside it long term?
- santiagobasulto 9y agoWe've bet big time on Github, and we have a lot built on it. Part of our business depend on it. We're thankful for all that GH has given us, but it'd really really help us to know an estimate when the V3 API is going to be deprecated. We're a small business and planning the work ahead of time is our only hope.
- Entangled 9y agoHow about communities, forums, boards? When I see an interesting project I'd like to talk to the developer without cluttering the Issues section. It could be the entry point of every repo, moderated by the owner of course (something like php docs where people can post interesting stuff related to the page at the end). And it would make Github more social.
- erikbye 9y agoI think a dev-social site like that should be separate to GitHub and just use their API to pull in repo data. Someone should probably give a go at making a site like that. Making it easier for project owners to find contributors and for potential contributors to find projects. Facilitating discussions beyond in issues, etc.
- zilian 9y agoLike gitter ? But more similar to Discourse.
- hashkb 9y agoWhy do you think you'd be cluttering the issues section? I wouldn't let that (your) perception stop you. Just open the issue if you have something to say.
- giaour 9y agoPlease don't. Issues are for bug reports and are not a support forum. If the repo maintainer asks in the README that usage questions should first be asked on Gitter, Slack, or Stack Overflow, please respect that request!
- marcosdumay 9y agoWhere does a "hey, I have this idea, could send a PR if you like it" goes? And what if the maintainer does not talk about any forum in the README? (What is, like, some 90% of the repos.)
- nikon 9y agoNo CI? Gitlab and Bitbucket have built-in pipelines.
- Klathmon 9y agoThere is a whole section for CI services. https://github.com/marketplace/category/continuous-integration https://github.com/marketplace/category/continuous-integrati...
- user15672 9y agoWhat's the point in GitHub creating yet-another-CI-tool? Travis and Circle CI have had good integrations for years and work very well.
- nikon 9y agoCost?
- user15672 9y agoCircle CI works well on their free tier, so no, not cost.
- nikon 9y agoIf you're OK with one container, sure.
- felicianotech 9y agoYou can always purchase more plus open-source projects get four containers for free.
- kkirsche 9y agoIf I install a free version and hit the limit does it auto upgrade me and charge me or am I just cut off from the service and told I should upgrade to keep using it?
- kareemm 9y agoI'm an owner at Codetree - one of the project management launch partners for Marketplace. We talked through this scenario with GH when we were integrating. What happens today is the limits are enforced on the app side, not he GitHub side. So for example our free plan is two users. If you wanted to add a third you'd need to go GH Marketplace and upgrade to the eg 10 user plan. That would trigger an upgrade in Codetree and your plan there would enable you to add up to ten users. In short: you trigger upgrades and downgrades, not the tool vendor you're using or GH, and thresholds are stored in the tool vendors database so they're the ones who decide how to tell you that you need to upgrade.
- deleted 9y ago[deleted]
- jaimefjorge 9y agoEdit: sorry for this. it was not my intention to come across this way. I was wrong. The Github team was great and tireless during this launch, congrats to Github and all the partners. I'm Jaime, CEO of Codacy[1] and one of the three chosen Code Quality partners for this launch. We specially love the Github Apps, since we heard for a long time the feedback of asking too many permissions. This has been a bit of a pain point. With Github Apps, it will be easier to cherry pick permissions. This is not yet running in Codacy but it will soon. One of the reasons why we're excited and decided to take part is the really qualified audience. Everyone just really gets what we do (automated code review) when they are already familiar with Github. [1] https://github.com/marketplace/codacy https://github.com/marketplace/codacy
- tomcorrigan 9y agoI don't think you understand your "really qualified audience" very well if you thought a coordinated marketing campaign with all the other "chosen" launch partners was a good idea.
- l5870uoo9y 9y agoBetter integration and monetization of Github Apps (formerly Integrations)?
- smagch 9y agoI guess that the main benefit of GitHub Marketplace would be the full-scale integration with GitHub Issue and Project board, launched last year. Consider a common situation: when CI fails, people need to reopen an issue manually, getting an error report via email. People who are in charge of project management may be seeking a better way to streamline the manual task, which probably increased since the introduction of Project board. To be clear, I’ve been away from software development over the years, so I’m curious about the impact of Project board. Does it useful in the first place? Did it require manual tasks between other services such as CI? Do you, who is in charge of issue or board assignment, feel frustration using it?
- erikbye 9y agoI expected GitHub to attempt further monetizing but perhaps not something as cheesy as an "app store".
- romanovcode 9y agoSo basically they just released GraphQL. Everything else is just renaming?
- djkor 9y agoI'm Tomek, CEO at codebeat [1] - automated code review for the web & mobile and one of the launch partners for the GitHub Marketplace. For us and probably for many tools that integrate with Github, an announcement about Github Apps is great news because we won't need to ask users for so many permissions. GraphQL also seems to be an interesting way to combine more data available on Github with results of our code analysis. I think Github Marketplace is a right fit for Github and community because it lowers the barrier to use third-party tools. Github puts them in one place, and it is super easy to add or remove each of them. [1] http://github.com/marketplace/codebeat http://github.com/marketplace/codebeat
- mtw 9y agoHow is GraphQL related to the marketplace?
- alangpierce 9y agoIt's not. Each section of the post is a separate announcement.
- deleted 9y ago[deleted]
- fotinakis 9y agoMike from Percy[1] here, we're one of the 4 Continuous Integration launch partners in the GitHub Marketplace. Congrats to GitHub on this impressive launch! We're very happy to share the stage with so many great partners and dev tools, many that we use everyday too. Happy to answer anyone's questions about what we're working on or our integration in to the marketplace. [1] https://github.com/marketplace/percy https://github.com/marketplace/percy
- stephenr 9y agoThe eerily similar posts from CEO/etc of "chosen partners" in this thread is a bit creepy. "We are the chosen ones. We love the leader."
- hashkb 9y agoBeyond creepy. It's gross, shameless, and inappropriate content (marketing) for an HN comment.
- hashkb 9y agoThe shameless support posts by execs/founders at launch partners are slimy! You guys should be ashamed. This isn't your marketing site, it's for discussion.
- treehau5 9y agoMight as well slather banner ads all over this post at this point.
- javajosh 9y agoI'm not affiliated with anyone doing this, but a) I haven't seen anything yet, and b) in general, the availability of (even commercial) options is valid discussion. Plus, I'm not unsympathetic: developer tooling is notoriously difficult to market, and it's hard to pass up an opportunity like a Hacker News front-page story about an almost universally loved service (GitHub) building a dev tool marketplace to talk about your dev tools! When Valve announced Steam you think game devs weren't gushing about their games? Of course they were.
- stephenr 9y agoThey've basically all been downvoted to death. HN submissions are open, nothing stops them writing a blog post and submitting that. The similarity of the posts makes it seem like a coordinated effort by those involved. A circle jerk of marketing bullshit, if you will.
- moron4hire 9y agoSo what the hell is "Show HN" but marketing?
- simplehuman 9y agoThis isnt a show hn
- stephenr 9y agoShow HN is expected to be submitted by the person who made the thing to show, and it's expected that they're showing it for a reason: it's either new, or had a significant change. Edit: So technically, GH probably could have had their new shit posted as a Show HN: but you generally want that to be something people can 'play' with right away, not a blog post about a way to pay more for the same things. /Edit My best guess with what happened here (based on the similarity of the texts) is that GH arranged a pre-formatted 'base' text, with placeholders, sent it to each of the involved CEOs/whatevers and said "we will submit our story to HN, once we do please comment using this template". Every one of the comments basically matches this pseudo-regex: "<Name> (at|from) <Company> [1] ..... one of the ([:digit:] <App Category>)? launch partners" and the [1] is referenced as a link to GitHub Marketplace. Only one has a link to their own site. The HN story itself was submitted by someone who at least used to be, and based on that, likely still is a GH employee. I assume they were trying to drum up lots of positive attention about this with the cool-kid me-too cargo-culting developer set that makes up a large part of HN readers.
- shabbyrobe 9y agoNice to see the old "oops we didn't bother to check the if the 'subscribed' column was true when we imported the mailing list" trick isn't beneath GitHub either.
- j_m_b 9y agoI've recently been exploring GraphQL. It's an excellent way to design and maintain Web APIs imo. GitHub is a great resource for learning how GraphQL works. I've been using the GraphiQL tool to experiment with it. However, there is a big issue with the GraphQL implementation in that requests using the POST method work, but the mirror GET requests do not return the same results. For example, see the response for the simple query "query { viewer { login }}" My understanding is that this request should return the same result, whether or not it is a POST or GET request (http://graphql.org/learn/serving-over-http/#get-request http://graphql.org/learn/serving-over-http/#get-request). Could someone provide some clarity on this?
- jlouis 9y agoYou are correct. The transport is a detail and if the query is the same, the response should be the same. What sometimes do create a difference is if one transport has one way of authenticating whereas the other transport-path hasn't. Perhaps this is what happens with the `viewer` output here. I'm fond of the idea of allowing the query itself to contain every head-meta-data as well, i.e.,: `query { viewer(auth_token: "...") { login }}` because such queries are possible to copy in a URL without having to worry about side-channels of auth.
- shurcooL 9y agoPerhaps https://developer.github.com/v4/guides/forming-calls/#communicating-with-graphql https://developer.github.com/v4/guides/forming-calls/#commun... is relevant: > In REST, HTTP verbs determine the operation performed. In GraphQL, you'll provide a JSON-encoded body whether you're performing a query or a mutation, so the HTTP verb is POST. The exception is an introspection query, which is a simple GET to the endpoint.
- j_m_b 9y agoThanks. I'm not sure that this conforms to GraphQL best practices. http://graphql.org/learn/serving-over-http/ http://graphql.org/learn/serving-over-http/ It seems GET methods should be supported for more than just introspection queries.
- 9y ago
- philip1209 9y agoThis feels like a Docker-esque move. Taking a product that people love, then thinking that they can conjure new features on top to grow more. The issue is, none of these new features really seems to be something that people want. So, it creates bloat and harms the core product.
- chaostheory 9y agoGithub's Marketplace would be much better to Github's bottom line long term if they expanded the free plan to include private repos. I can see this working more to bitbucket's benefit if Atlassian gets more aggressive with its own marketplace offering.
- cyphar 9y agoI just got an advertising email about this from GitHub, even though I've never subscribed to GitHub advertising mail. I just checked my email settings and it looks like GitHub has added a new option (defaulting to being "on" of course) that auto-subscribes you to spam. Surely the unsubscription laws don't allow you to retroactively add more options that are defaulted to being on that subscribe you to things you were never subscribed to in the first place? Seems like an easy way to spam people without having any repercussions. For those who want to disable this anti-feature, look at the bottom of https://github.com/settings/emails https://github.com/settings/emails.
- Drdrdrq 9y agoI usually give aliases for such accounts because of this (and because of data breaches). Send me spam and I don't have to put up with your UI to unsubscribe, I just delete mail alias. Of course, that doesn't work if I want to receive any mail from you...
- cyphar 9y agoWhat email service do you use? I've been trying to figure out where to switch to from "the big G" and it's not clear to me what host is good. Personally a host that has a mail client which is free software would be the best deal. :P
- Cabal 9y agoI think Twitter and LinkedIn may have patents on this dark pattern, based on the frequency with which they do it. Seriously, Twitter has ~20 email subscription options now, and they add a new one (and opt you in) every month.
- jtmcmc 9y agoit's going to depend where you live. In the united states no opt-in is required for sending marketing email - https://www.ftc.gov/tips-advice/business-center/guidance/can-spam-act-compliance-guide-business https://www.ftc.gov/tips-advice/business-center/guidance/can...
- deleted 9y ago[deleted]
- bartq 9y agoI think it's only an upgrade for shitty REST-like protocol for APIs. The next after GraphQL will be something like executing your own code in sandboxed environment on the server, with strong constrains etc. Anyhow, I don't like centralized approaches. Easier access to Github data will encourage to create apps based on a global variable which is the Github. I'd rather want them to release installable libraries that communicate with other parts of the system. Sort of.
- krab 9y ago> The next after GraphQL will be something like executing your own code in sandboxed environment on the server, with strong constrains etc. Ah, like a SQL database with procedures? Honestly, I've wondered why the SQL interface isn't common for the remote APIs. My thoughts are that it's possible to run very expensive queries and you'd need provide some HTTP transport so it works for browser JavaScript.
- bartq 9y agoI think we're don't do that because it's too dangerous and user would have too much privileges. I'm referring to something like AWS Lambda, but handled by your library on your web server. Say you can run JS snippet only for 10ms and the only global non-standards variables are those that contain data that can be queried. Or even pass them through function params, look: ctx => ctx.users.filter(u=>u.name.contains('Janusz')).slice(0,10); And that will return 10 firsts users as JSON.
- peter_retief 9y agoOnly for Mac or PC? Clearly not aimed at me
- misterbowfinger 9y agoKinda random - anyone have experience scaling GraphQL APIs? It seems super difficult since you're basically giving clients the ability to arbitrarily query your data.
- thangngoc89 9y agoI never worked on Github scale but if your API is not open and you're in control of all of your clients. Take a look at Persisted Queries[1] . It enables you to whitelist all queries that your application uses. [1]: https://github.com/apollographql/persistgraphql https://github.com/apollographql/persistgraphql
- arca_vorago 9y agoIs it all GPLv3'd? That's my question. If not, why not?
- shurcooL 9y agoREST v3 API supports conditional requests, that return 304 when content hasn't changed since last time you asked and don't count against rate limit. It means one can use a caching HTTP transport and benefit from that. Is there any support for caching in the GraphQL v4 API? I'm not seeing anything about it in the docs.
- cryptonector 9y agoIf your query is complex and/or depends on sharded data, it can be difficult or impossible to cheaply (i.e., without re-executing the query) check whether the results have changed. That doesn't mean that the server couldn't execute the query, hash the results, and compare to an ETag from a client's If-None-Match: header, or some GraphQL equivalent of that (if it has it), thus saving network bandwidth. You just might not be able to save cycles and I/O on the server-side.
- shurcooL 9y agoI found this in the GraphQL docs: http://graphql.org/learn/caching/ http://graphql.org/learn/caching/
- mrinterweb 9y agoThe thing I'd like to see Github focus on with their API is granular permissions. There are many SASS integrations that I am just not comfortable with granting access to because I don't want to have any more than necessary 3rd parties having access to repositories. Please correct me if I'm wrong, but every time I grant an application access to my Github account, it automatically has access to all repositories I have access to. I know there are ways that organizations can set permissions such that they can approve app integrations. Still, there are private repositories I have that I would prefer to not have 3rd party integrations be able to access. With 3rd party SASS providers having access to private repositories, it would be trivial for code to be stolen or sold to competitors. If they wanted to be real nasty they could rebase and force push, delete branches, tags, inject malicious code. There are so many potential ways that providing full access to everything you have access to in Github could be exploited. I would love to see Github add permissions to apps requesting OAuth permissions be able to restrict access to the repositories the 3rd party app has access to. It would also be nice to be able to revoke individual permissions. [Edit] fixed some grammatical errors.
- kardon33 9y ago+1 this a thousand times. The only way i have found to effectively lock things down is using an org and creating a new Github user just for third-party integrations.
- Kequc 9y agoBitbucket is fast, and I believe focuses on repository permissions. Have you tried them?
- kardon33 9y agoYes, though it has been a year or two. However it's more of a personal preference / fits within my normal work routine to use GH. I have a number of OS repos that, for community reasons, need to stay on GH, then most of my normal work is on GH which is generally where the concerns come in from a security standpoint.
- 9y ago
- strin 9y agoSo this is a marketplace for "meta-apps" - apps that run on codebases. I am concerned if in the future Github will add private repos to the marketplace. Making this move will discourage people from sharing code freely.
- sdesol 9y agoCan somebody from GitHub comment on this? > Apps cannot actively persuade users away from GitHub. This is listed as requirement from the "Requirements for listing an app on GitHub Marketplace" page. Is this saying your app should only support GitHub?
- mrclark411 9y agoThe Listing requirements: https://developer.github.com/apps/adding-integrations/listing-apps-on-github-marketplace/requirements-for-listing-an-app-on-github-marketplace/ https://developer.github.com/apps/adding-integrations/listin... mention: - OAuth Apps should have a minimum of 1000 users. - GitHub Apps should have a minimum of 250 installations. Does this mean you aren't listed on the Marketplace until you have 1000 users + 250 installations?
- creichert 9y agoGitHub apps are slightly different than OAuth Apps. GitHub Apps are per-repository "integrations" that don't perform actions on behalf of a specific user and are installed directly to a repo (with fine-grained permissions). OAuth Apps are the classic "integrations" installed by a specific user and perform actions on behalf of that user. I imagine they have lower requirements because they are new, more specialized, and likely to be installed a little less.
- mrclark411 9y agoThanks. I also see that the security requirements are quite high. While its difficult to argue with source code security - here are some of the security requirements: The standard annual risk assessment shall include, to the best of Developer's ability, the following: (i) SOC 1 and/or SOC 2 audit report; (ii) 3rd party proof of PCI compliance (a certificate showing Developer's handling of credit card payments is compliant); (iii) Privacy Shield Attestation; (iv) ISO Certification or Cloud Security Alliance Self-Assessment; (v) Cloud Security Self Assessment; (vi) any information on subcontractor or vendor production datacenter(s), IaaS, PaaS, or private hosting providers, as required by GitHub based on data and services rendered; and (vii) Written responses and evidence of specific security requirements as outlined in this agreement https://help.github.com/articles/github-marketplace-developer-agreement/ https://help.github.com/articles/github-marketplace-develope... The GitHub Marketplace will be an exclusive place for a while with those requirements.