Security
GitHub permissions
What GitHub access is used for.
GitHub authorization powers personalization.
Public GitHub signals first
The current beta is designed around public repository discovery. Broader organization and private repository access belongs to a future product boundary.
Current beta scope
| Access | Used for |
|---|---|
| Public GitHub profile | Account identity and personalization starting point. |
| Public starred repositories | Taste graph, cold start, and Memory. |
| Public owned repositories | Developer context and language/topic profile. |
| Optional star/save/watch actions | User-directed repo actions depending on app mode. |
OpenStar is independent from GitHub. Users should be able to disconnect GitHub and delete OpenStar account data.
Boundaries
- OpenStar does not require private repository access in the beta. Private repo access should be introduced only with explicit enterprise-grade controls.
- After disconnecting GitHub, OpenStar should stop syncing GitHub signals. Account data deletion is a separate user-controlled action.