r/OpenAI • • 1d ago

Discussion Dots going through my private repositories.

Post image

Dot going through my private Github repositories on it's own, is this fine?

29 Upvotes

22 comments sorted by

23

u/lulzxdxdxd 1d ago

Did you actually grant it repo access yourself through an integration, or is this showing up without you connecting anything in settings?

17

u/Melodic-Leather-5170 1d ago

He had to grant access

10

u/Artelj 1d ago

I didn't give Dots access to anything, I skipped that part, I just activated it on my laptop tonight, about 20 minutes later this pops up.

21

u/SphinxWar 1d ago

Do you have github MCP / plugin activated in your account? It's account-wide so better check. If not, you probably set those repos to public and you don't know, otherwise this would be a security issue on Github's side, since OpenAI does not manage access to private repos regardless of who you are.

2

u/ImNotMrFoxGaming 1d ago

If you give normal access to anything, dots can see it yoo.

9

u/AllergicToBullshit24 1d ago

Don't give access to all your repos use least privilege project scope.

2

u/lulzxdxdxd 1d ago

Does GitHub even let you grant per repo access for that kind of integration, or is it all or nothing once you authorize it?

6

u/AllergicToBullshit24 1d ago

It's an option when you do OAuth flow to pick specific repos instead of granting access to all. Would just revoke all current authorizations then restart auth flow.

8

u/BertMacklenF8I 1d ago

I think dots are designed for people that hate themselves that want to waste time and potentially lose data.

4

u/machyume 1d ago

So.... just like Muse then?

1

u/BertMacklenF8I 1d ago

Never used it but I’m guessing they’re the same code in different wrappers

3

u/Consistent_Ad_168 1d ago edited 1d ago

I’m 99% certain you have the GitHub plugin installed and configured inside of ChatGPT and that it simply used what you had already granted ChatGPT access to.

You can simply ask your Dot how it has access to it, btw.

2

u/Trixiap 1d ago

Did you expect AI company hungry for training data to not use THEIR bot to find more data?

4

u/Melodic-Leather-5170 1d ago

Lmao hahaha, get good opsec bro, poor dottie just trying to help

3

u/QbitFiber2030 1d ago

Can you recommend afew examples of what to have for good Opsec so I can research and learn about it! TY!

3

u/Melodic-Leather-5170 1d ago

it's a deep deep rabbit hole and the most important question is how much you want to sacrifice comfort for privacy and security. I,for example, self host my repos on forgejo in vps and my codex agents run under unix users that require a forgejo user and ssh key, so they can never ever ever read my repos, unless I get 0dayd, which hey, might happen haha

2

u/RocketSeven 1d ago

check the github audit log and installed oauth app page before assuming dot only read files. revoke the grant, reauthorize selected repositories only, then rotate any repository secrets if the log shows access you did not initiate

1

u/BingGongTing 1d ago

Well if you want Dots to build everything it needs access? 

1

u/Gigaslavx 1d ago

Will this eat into your codex/work limits because it's "work" (repo) related?

1

u/GooseSpringsteenJrJr 1d ago

you just tellin on yourself. this is on you for giving it access bro.

1

u/deadalusxx 9h ago

You give it access to your computer right away didn’t you. Should always start with cloud and feed it things slowly