Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

> If one thing can be gotten from that incident is forcing GitHub to create finer OAuth scopes and per repository.

This. Limiting OAuth app access to specific repositories. I really wish this was a thing. For this exact reason I'm creating a new GitHub account for every new integration and share the repo with this account. It's technically against the TOS (they only allow single bot account per user) but there is no other way if you want security.

Maybe GitHub will implement this feature now. My hopes are high.



Aren't OAuth tokens scoped to org? Wouldn't it be easier to create an org per repo? I guess it might get expensive depending on your usage/collaborators.

Edit: nevermind OAuth tokens are not org-scoped, only apps are




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: