Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> The users can still see all their stars and find the private repo, which makes it not private.

Why seeing a start you made for a previously public repository makes it not private? People remember things too, there's also the webarchive. You should be able to unstar it or keep your star, the only difference is that you don't know if the repository still exists or not.



> the only difference is that you don't know if the repository still exists or not.

If an admin were to private->delete, then all the stars referencing the report would stay and thus the reference to the repo would still be there, on GitHub's servers. There's a difference between GitHub storing things forever and third parties on the internet being a forever archive of visible pages.


But that's an easy fix. If they delete the repo, delete the stars. If they make it private, indicate it is now private in some way.


That's information disclosure; nothing about the repo after it's privated should be known, including name changes and deletion.


It’s unclear to me what the attack vector is for that disclosure.


It was known and there are many sites scraping GH for metadata that will have it anyway


Not whether or not a repo exists after it's set private.


This information is useless. It leaks nothing but name and existence of something once public (that vanished from public view). Most importantly it's not confidential or critical in any way




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: