Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I reported a similar and even more damaging I my opinion (https://hackerone.com/reports/2240374) and they also dismissed as by design.

Turns out I found out you could even invite external collaborators into your fork and totally bypass enforced SSO.

Even if you block forking into your main repo, the existing forks remains active and still can pull from upstream.

It feels like if you need proper security, you have to go with enterprise



Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: