Hacker News new | past | comments | ask | show | jobs | submit login

I reported a variant of this issue that (to me) was unexpected:

* You add someone to your private repo.

* After some time, you revoke their access.

As long as they keep a fork (which you can't control) they can use this same method to access new commits on the repo and commits from other private forks.

Back in 2018, this was a resolved as won't fix, but it also wasn't documented.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: