5 ms·
But they can still download the source and re-upload it to GitHub. It's really a false sense of control.
by ctrl-j 9y ago
But they can still download the source and re-upload it to GitHub.
It's really a false sense of control.
- moondev 9y agoBut it won't say "forked from..."
- gkya 9y agoAnd how does it matter when it's a private repo?
- moondev 9y agoImagine you run a website, foobar.com. You have foobar.com github org and foobar private repo (and also some public ones). Its the canonical org/repo. ninja123 has a github fork of it and it relays that from the github ui. "forked from foobar/foobar.com". rockstar123 also has a "fork" but it's just code sitting out there at rockstar123/foobar.com. There is no link to the canonical repo. If you fire ninja123 the link is severed. It just allows a way to show active, approved engagement and also to keep track of approved collaborators. What if rockstar123 gets arrested for ICO fraud. Do you want others to see he has an official upstream link to your repo even after you have severed the relationship? What if rockstar123 makes his fork public? It's just messy to keep the link.
- gkya 9y agoI do not want to believe Github allows to make a privately-forked repository public. Other than that, I agree that the link is better removed, but what I don't understand is how that helps with keeping the code itself private, which is what I thought was meant at the root of the thread.
- moondev 9y agoOp is not claiming it keeps it private. It's just used as a tool to signal and track approved, active collaborators to the official upstream. That's beneficial to control.
- abiox 9y ago> I don't understand is how that helps with keeping the code itself private, which is what I thought was meant at the root of the thread. out of curiosity, what made you think that?
- gkya 9y agoI think you're asking about the part after the comma, so here is the part from the comment that started this thread that makes me think so: > Why? Because it's cleaner. It means there are no abandoned copies of my codebase sitting around forever forgotten in random Github accounts. I set up a private repo because I want to control access to my code. That's why a private repo is private. https://news.ycombinator.com/item?id=16600864 https://news.ycombinator.com/item?id=16600864
- bryanrasmussen 9y agoYou have foobar private repo bad actor makes foobar public repo edits readme says public edition of foobar repo. People says ooh that's the one I want!
- moondev 9y agoWhy would they think that? It won't say "forked from foobar/foobar.com" and it won't be under the footer org. That's like me make a random repo and adding a readme that says "official public windows 10 source repo"
- s73v3r_ 9y agoThey could do that no matter what. However, they're not able to have an officially backed association with the original.