|
|
|
|
|
by gamedever
483 days ago
|
|
And yet, tons of developers install github apps that ask for full permissions to control all repos and can therefore do to same things to every dev usings those services. github should be ashamed this possibility even exists and double ashamed that their permission system and UX is so poorly conceived that it leads apps to ask for all the permissions. IMO, github should spend significant effort so that the default is to present the user with a list of repos they want some github integration to have permissions for and then for each repo, the specific permissions needed. They should be designed that minimal permissions is encouraged. As it is, the path of least resistance for app devs is "give me root" and for users to say "ok, sure" |
|
By design, the gh cli wants write access to everything on github you can access.