[HN Gopher] GitHub UX has operational security risks
___________________________________________________________________
GitHub UX has operational security risks
Author : davydog187
Score : 27 points
Date : 2024-07-04 17:52 UTC (5 hours ago)
(HTM) web link (twitter.com)
(TXT) w3m dump (twitter.com)
| lijok wrote:
| It does show people in your org first, but you have to search by
| username, not full name.
| rad_gruchalski wrote:
| And that is a problem. Do you know gh usernames or everyone in
| your org? I sure know most names of the people in my org but no
| clue about their handles... I most often depend on gh
| suggestions.
| bitfilped wrote:
| I know people in my org by their handles better than their
| names haha, guess it just depends on the culture of the place
| you're at.
| wrs wrote:
| I agree this is a real problem. If the repo is in an
| organization, I would like to have to check a box like "include
| outside users".
| fjni wrote:
| Github ux is an unmitigated disaster from an operational security
| perspective. In their defense, it did start out as an open-source
| tool. The fact that enterprises adopted it so blindly despite
| this is pretty interesting.
| okanat wrote:
| It really didn't start out as an open-souce tool. Github was
| founded for selling private repo access for Git and got popular
| in the FOSS community since they provided free storage.
| brobdingnag_pp wrote:
| Accidentally @tagging people in private PRs is always fun too!
___________________________________________________________________
(page generated 2024-07-04 23:01 UTC)