World's oldest continuously developed git repo has been flagged, what to expect? #209876
Replies: 1 comment
|
I think this situation highlights an important issue for open-source projects that depend heavily on GitHub. A project with decades of development history and an established open-source community suddenly losing access to normal organizational operations is a serious concern. Even if automated systems flag an organization for legitimate reasons, providing a clear explanation and an expected review timeframe would help maintainers understand what happened and plan accordingly. Regarding the review timeline, I don't think anyone outside GitHub Support can give a reliable estimate for this specific case. Past experiences vary, and another organization's resolution time does not guarantee the same outcome. I also agree with your point about infrastructure dependency. GitHub provides excellent tools for open-source development, but projects should consider maintaining independent backups of their Git repositories, release artifacts, issue data, and CI/CD configurations. A secondary Git hosting option can also help reduce operational risk. Hopefully, GitHub Support reviews your case soon and provides a clear explanation. It would also be helpful if GitHub introduced a more transparent organization-flagging process, including notification details, the reason for restrictions where appropriate, and realistic expectations for appeal timelines. |
Uh oh!
There was an error while loading. Please reload this page.
🏷️ Discussion Type
Question
💬 Feature/Topic Area
Other
Body
Our open source community has been on Github for over 5 years, open source for nearly 25, in development for over 50. Couple days ago, we like others were surprised to discover "The BRL-CAD organization has been flagged." We have since done our homework on what that means, checked e-mail and spam folders for any notices (none), reviewed secret key utilization, checked for any abuse, etc, and of course submitted a support ticket (#4835101) to request review.
Our guess thus far is maybe we've exceeded some undocumented infrastructure utilization threshold. He have always taken care to not exceed published limits, but compilations of BRL-CAD are very large. Thus, it would not be surprising if our pipelines, repos, file releases or some other aspect of project utilization was a ranked outlier.
We know the Community cannot help with reinstatement requests, but my question is does the community have any collective insight on what response timeline might be expected? In reviewing past discussions, there appears to be a broad range from days to months to never. Looking at the Transparency Center odds are not favorable against never, but timelines are also not mentioned. Does anyone know the typical or average response timeframe?
In all, this abrupt status change has made us acutely aware of how dangerously reliant on Github our release and development operations have become. We've certainly appreciated and benefitted from GitHub infrastructure provisioning, but opaqueness of the flagging process itself gives pause. Despite a lack of phone recourse, e-mail warning/info/notice, or ticket response, our project is hopeful resolution can be quick, hence any feedback on observed timeframes from the Community appreciated. Thank you in advance.
All reactions