Hacker News new | ask | show | jobs
by Pathogen-David 1275 days ago
For public repositories only though. For private repos it's optional, and when enabled the repo admins get an alert to handle it themselves without it going to the vendor.