Hacker News new | ask | show | jobs
by yakkityyak 1201 days ago
It looks like it's for accounts that contribute code. Compromised accounts can sneak malicious stuff into dependencies.
1 comments

Maybe I don't understand what "contribute code" means... Do I only "contribute code" if I open a PR on a repo I don't own? Seems like a good option to allow people to enable, but forcing it is an unnecessary overreach.
I interpret it as: your account publishes code bits in any capacity, as opposed to a read-only account that only pulls and participates in social discussions.