Hacker News new | ask | show | jobs
by vxNsr 1274 days ago
Quoted from the blog post:

> We have partnered with Tencent WeChat to scan for their tokens and help secure our mutual users on all public repositories and private repositories with GitHub Advanced Security.

This is GitHub scanning private repos and telling WeChat about them.

WeChat can already scan public repos.

They are not already screwed if they’re publishing something to a private repo, it might be the wrong way to do it, but it doesn’t mean they’re already screwed.

If you don’t trust GitHub’s private repo security then why are you using it in the first place?

1 comments

Obviously you’re wrong or the article is wrong… I’m gonna lean on you being wrong as the article is coming from GitHub and you’re not GitHub.
For private repos it is opt-in requiring the Advanced Security license: https://docs.github.com/en/get-started/learning-about-github...