3 years ago
Sat Mar 11, 2023 7:49pm PST
Ask HN: How can the Vercel GitHub App create a repository without my permission?
Hello!

I'm a bit surprised! How is it possible for the Vercel GitHub App to create a new repository on my GitHub account, even though I only gave it permission to access one of my existing repositories?

Also, I found out that the GitHub App doesn't have access to an API that can create new repositories on a personal account.

Even though the Vercel GitHub App acts on my behalf, it didn't ask for permission to access the 'repo' scope when requesting a personal access token.

comments:
add comment
loading comments...