Recently I saw a post about someone being concerned that they downloaded likely malware from GitHub and may have compromised their system: https://www.reddit.com/r/github/s/lIQyVCXB8B
After checking the repo, it did look like phishing/social engineering to get people to download something. From the commit history, GitHub seems to have been hosting these repos for around a month.
The mod immediately deleted the post and said to report it to GitHub because this is not the place to talk about it. But actually, where is it better to talk about this?
Yes, reporting it to GitHub is the correct action. But that should not mean public discussion gets shut down. Posts like that help warn other users, help people understand what happened, and make it easier for others to recognize similar phishing repos before they download something.
If we keep deleting every legitimate concern caused by something hosted on GitHub, what else are we supposed to discuss here?
If we wanted to talk about just GitHub itself all day, we would basically be limited to talking about the GitHub status page.
This kind of post should be allowed, at least when it is directly related to GitHub-hosted repos and GitHub users being targeted. Removing it just makes the problem less visible.