I recently authorised a third-party app to connect to my GitHub, but it’s not clear what this means. Apparently I gave it this permission:
Update all user data
Applications act on your behalf to access your data based on the permissions you grant them. Organizations control which applications are allowed to access their private data. Applications you authorize will always have access to public data in your organizations. Read about third-party access.
My GitHub contains commercially sensitive repos owned by me – containing intellectual property that I would not want accessed by anyone. So I am taking on faith that the privatized status of my repos would make it inaccessible to third-parties. Does the above permission jeopardise the privacy of my private repos? Or are private repos always private against third-party apps no matter what permissions they are granted.
I expect my private GitHub repos to be inaccessible to third parties.
Peter Cao is a new contributor to this site. Take care in asking for clarification, commenting, and answering.
Check out our Code of Conduct.