Skip to content

Comment on The Go language's first commit (1972)

Comments

So any thoughts on this company, Repography? Their dashboards look really cool, but the only way to give them a go with my own repositories is to authorize their Github app to "Act on my behalf", whatever that means, or to curl some unknown code and pipe that into bash locally on my machine. Neither option is one I'm particularly fond of trying, without additional assurances that this is a legit org. I don't know. I just feel like they could have spent a bit more time convincing me it's safe to do that authorization thing. Likewise, I could have downloaded their script and audited it before running - I just don't have the time to do that right now.

Hi, I'm Arpad, one half of Repography.

There's an entry in our FAQ [1] about this. We only use OAuth to identify your GitHub account and then the GitHub app installation has much better defined permissions.

I'd love to be able to restrict the OAuth scope even further but GitHub doesn't let us. I've heard this concern a couple of times now so I'll have another look. I can hopefully at least improve how it's presented and communicated so it's more reassuring!

[1] https://repography.com/faq

The back button is broken on your website.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.