/plushcap/analysis/bandwidth/bandwidth-is-your-private-github-organization-really-private

Is your private GitHub organization really private?

What's this blog post about?

Private GitHub organizations may not be as secure as expected due to the lack of third-party access policies, which allows applications to act on behalf of users with granted permissions. This can potentially include access to private repositories. GitHub does not have resource-specific scopes, so granting an application permission to manage issues requires giving them access to all resources. Organizations should check their configurations and implement access restrictions to protect proprietary code from bad actors.

Company
Bandwidth

Date published
June 9, 2015

Author(s)
Bandwidth Dan Goslen

Word count
579

Hacker News points
None found.

Language
English


By Matt Makai. 2021-2024.