• mrbn@lemmy.ca
    link
    fedilink
    arrow-up
    13
    arrow-down
    15
    ·
    21 hours ago

    Kind of a nothing burger.

    These repositories, belonging to more than 16,000 organizations, were originally posted to GitHub as public, but were later set to private, often after the developers responsible realized they contained authentication credentials allowing unauthorized access or other types of confidential data. Even months later, however, the private pages remain available in their entirety through Copilot.

    The repo was listed as public and archived. It’s not clear from the article but I suspect that the “private” information is just a copy of what was made public and not the information added after it was made private.

    • xmunk@sh.itjust.works
      link
      fedilink
      arrow-up
      32
      arrow-down
      2
      ·
      21 hours ago

      When a code repository is shut down on github the expectation is that it’s removed. We’re all aware that the internet will never forget that API key you accidentally committed once but the expectation was always that it wouldn’t be github itself doing the remembering and openly sharing it with others.

        • grue@lemmy.world
          link
          fedilink
          English
          arrow-up
          19
          arrow-down
          5
          ·
          16 hours ago

          “According to the article it was Microsoft and not Microsoft.”

          Do you see now how silly you sound?

          • rijom@lemmy.ml
            link
            fedilink
            arrow-up
            3
            ·
            5 hours ago

            From an ownership perspective, sure. But it’s still different from the implication that github is leaking currently private repositories.