GitHub: Private Profiles beta
github.blog
github.blog
I know, I know, I shouldn't be doing that in the first place, but it still sometimes happens, and just being able to keep the profile private is easier than waiting with committing until after work hours.
Not everything I do on GitHub should be broadcasted to my entire workplace
And vice versa. That’s why I’ve to keep two separate accounts - main/personal @firstname and another @shortname-work.
> One person or legal entity may maintain no more than one free Account (if you choose to control a machine account as well, that's fine, but it can only be used for running a machine).
Hmm. Thinking about this I now realize that identity fraud would probably be a lot harder to pin down if things leaned in the direction I'm describing, so perhaps not.
You almost certainly should, and if you’re scolded for it you probably work for parasites. You’re not wrong to hide that activity from them but I hope you’ll find a role where contributing back is valued not chastised.
If you build a software and because of a bug it breaks something, that is fine. If you deliberately change a library to make any software running it crash and you know it is used among other things by software that control nuclear plants or elevators, my guess is it will probably considered a crime in most juridictions. This regardless of the fact said software makers should test their changes.
I was taking a naive view from a theoretical point.
Sounds like your employer needs to reconsider or have the value be explained to them.
I hope you can voice your opinion back. It would be such a dystopia if your employer's attitude become widespread.
I still do it. I have a separate non work github account and I just scp myself the diff and PR it from my personal account in the evening. Fuck 'em.
Because your company may see Open Source Library Y as free as in beer they may not value the vendor relationship with Open Source Library Y. The "cultural" Maintenance Agreement with Open Source "vendors" is that good open source users contribute back to open source those bug fixes they need for workarounds and those features they request for productivity benefits. Compared to the costs of Maintenance Agreements with many large, classic closed source vendors, the cost of a few hours labor on dependencies to products is often quite cheap relatively speaking especially with the "free as in beer" platform/networking effect that other "good" companies following cultural Maintenance Agreement norms contribute as well.
The only real missing ingredient is that because that Maintenance Agreement is cultural more than it is written down in a way that Corporate Lawyers can read it and Actuaries and CPAs can understand it to be an asset and/or liability that impacts the books, it just becomes invisible guilt: either the guilt that you aren't doing your part as a developer with respect to that culturally assumed Maintenance Agreement OR the guilt that you are doing your part but that your company may find out and claim you are wasting their time. But seriously, that vendor relationship even though most of the "assets" are "free as in beer" should be on the books and have its own billing codes for the culturally encouraged "liabilities" of Maintenance Agreements to spend a few hours of developer time here or there for the "greater good", but also the specific good of "making Product X better" because that is an asset directly related to the performance and success of "Product X".
Expanding out further from where I left off:
The "compact" of that cultural Maintenance Agreement further relies on network effects that make it powerful (and cheap as free as in beer as an asset): it isn't assumed that everyone can fix/build every bit of open source, it relies on community effects. It relies on a lot of individuals scratching their own itches becoming a collective force greater than the sum of its parts.
Absolutely, Accounting for that is even harder. It's not a "quid pro quo" that you can directly bill to a specific product. That's even harder for companies to deal with. But plenty of companies have much more complex classic liabilities than that: Marketing efforts, R&D, etc. Again, the "wastefulness" in budgeting for "Open Source Maintenance" both specific and general is a super cheap deal compared to classic R&D budgeting. It's a huge savings compared to classic third party software vendors on a combined "asset portfolio" basic. Companies can budget for it. They can and likely should assume some of that "wastage" on "maintenance costs" as natural overhead of building software. (That's what the cultural narrative of Open Source encourages: that everyone should chip in and assume at least some baseline of community effort, from every user [personal, corporate, whatever].)
Bringing things back even more full circle: my company tries to have somewhat regular Community Service Days to give back to the communities the company exists in (and professionally serves day to day). It budgets labor hours towards those efforts (and also promotional budgets for things like t-shirts to pat itself on the back), people sign up to meet those budgets, and things like "helping a homeless shelter" are direct uses of that budgeted time that the company is paying for. My company isn't alone in this practice, and expanding it to charitable "Match" contributions there are a lot of companies paying regular money and/or labor to "general good" charities.
Admittedly, part of those budgets every year come from charitable organization "vendor requests" asking for specific numbers of hours (in many cases) and from Accounting knowing that working with any 501(c)3 makes those hours spent a write-off liability come tax time. That's again where the "cultural" part of Open Source "obligations" meets the practical side that there aren't enough 501(c)3 charitable organization "vendors" to "invoice" companies and also help make the time/labor spent on such "invoices" to be even cheaper than usual labor costs thanks to tax write-offs.
I was sick with COVID, but about one week in, I had an afternoon where I didn't feel completely sick, so I wanted to tinker with some code for an hour. I couldn't commit because I was paranoid that my boss/coworkers would freak out that I coded an hour while I was sick.
Same is true if your coworkers follow you, and you start starring or contributing to repos about interview questions, whiteboard questions, etc. There is a 98% chance nobody would notice or care, but I don't want unnecessary drama because I enjoy using GitHub in my free time.
Contributing to a FLOSS project is equally work-unrelated, but seems like a better way to slack of TBH.
Maybe just keep the Top/Pined repository list since they only show public repositories anyway?
Also, based on my test, even if I set my profile to private, I can still see my activities through GitHub API (say https://api.github.com/users/<UserName>/events). I mean...???
Do you separate work commits from personal/oss/hobby commits?
Do you have different github accounts per employer you've had?
If so... why?
If not... why?
I personally use only 1 profile, but it has occurred to me that this is perhaps unwise and mixing work and pleasure together is a good way to create a diluted and messy situation regarding IP and who owns copyright on something. Not that I delude myself that separate profiles would solve it, only that separate profiles would mitigate a lot of the risk and make it a lot clearer when I'm acting on behalf of my employer vs just as a lay person.
Work and home emails / github / phones / everything are separate, I wouldn't want to ever mix them.
Yes, that means losing some history when changing employers, but that's part of the deal. You work for your employer and while they are tolerant (to various degrees) of engaging with open source, in return they get to retain ownership of that email address and their brand.
In a new company I have a new "hat" on, and while I can see and interact with my previous issues, I'm no longer that person with a new hat on and can only indirectly interact with my other self as if a different person.
Can anybody who uses this feature explain what github profiles are for?
I don’t know that I’d go so far as to explicitly hide that information, mostly because it is so mundane as to have no value to anybody.
Basically whenever I find a package I really like, or I'm skeptical about the profiles the first place I go.
What use is private profiles? Basically nil, but they want to turn GitHub into OnlyFans
I can use myself as an anecdotal example. I use GitHub mainly to store guides and neat tricks for myself, and to sometimes share some excellent code. All my current professional work lives in Azure DevOps, locked away so that you would never know so if I didn’t tell you. I have a NPM package that should be private but is public because we share it with some contractors and nonsense occurred (loooong story that is basically answered by “above my pay grade”). If you found it and looked at my GitHub profile, then you might use it, and you’d experience some breaking changes that you typically wouldn’t with good OSS NPM packages every time we make some major updates to it. Because we don’t really factor external user into our processes.
Usually, people have their stuff spread around, and the GH profile can be a "gateway" to the rest of their information.
In my case, I have a ton of open-source stuff, so my GH profile is a good starting point.
https://github-feed.tandav.me I wish the official GitHub newsfeed to show contribution updates instead of likes. Or even customize what to see in feed.
We're open source (https://robusta.dev) and very involved in the kubernetes ecosystem so GitHub history is extremely relevant when we look at candidates.
We'll hire people with no GitHub activity too, but when it's available it's great
If someone has an old GitHub account but very little activity, I assume they work at a leech company which uses opensource but doesn’t contribute back. I’m less likely to care about the needs of users like that. That said, professional software engineers will usually be more responsive in issue threads when they run into bugs. I’m much more likely to fix a bug if you can give me a good repro!
I kindly suggest you not lump in users/employees with the behaviors of their employers. Any company that i might work for might indeed be "leeches" as you noted, but that does not mean the user/associate/employee is one also. It might also be the case that said employee actually only works for such an employer as a necessity...you know for earning a living, but not really share the morals/ethics of the employer. Some employers require proprietary controls on their source code, hence preventing employees from using publicly availablr repos on github. Now, if i were to get "graded" on my low activity on github for personal projects, then i get your point...but to automatically lump in both employee and employer into one actor's ethics, seems not right.
You’re getting financial benefit from my donated effort. I don’t mind - I wouldn’t opensource my work if this bothered me enough. But GitHub issues opened by leeches have a certain entitled tang to them - “Hey could you donate more of your time so I can make more profit? I won’t pay you. Maybe you should be thanking me for finding problems in your work and pointing them out to you. Get to it!”
The reason you don’t contribute doesn’t matter. You’re profiting from my volunteer work and asking me to volunteer more so you can profit more.
Justify leeching to yourself how you like. But you won’t get respect from me until you contribute back.
And, yes, if you work at an immoral company, that is also absolutely on your hands.
If you disable Issues, I suggest also briefly explaining why you did that in the README to ensure you don’t get do-nothing Pull Requests asking how you’d like bug reports submitted.
I can respond with things like: "Oh, that problem? Yeah there's already code to work around it - here's what you need to do." Or: "You want that feature? I can see why thats valuable to you. I'm sorry but I'm never going to accept a PR from a stranger adding that. I don't need that feature for my workflow, and its complex, so the payoff isn't there for me to maintain the code. Fork my code, or implement that feature in an external library."
I'd much rather turn down a feature request in an issue tracker than turn down work in a PR, after someone has done all the work already for something I'm not going to merge. That feels bad for everyone.
If you write a good issue and take part in the discussion, that signals that you aren't taking my work for granted. Work with me to make a good repro case, and I'll work with you to fix the bug you're running in to.
I always look at profiles.
I spent a bunch of time, customizing mine: https://github.com/chrismarshallny
in the new feed i see every release update from 800+ repositories i starred
would be nice if there was a way to exclude releases from the feed, because it actually discourages me from reading the things i care about (like what my friends star and updates to repositories i'm watching)
here’s my GitHub discussion so you get an idea how it looks like: https://github.com/github/feedback/discussions/13318
the register also has covered this: https://www.theregister.com/2022/03/23/github_for_you/
Try and give people permissions in an org between a regular user and a super admin, even on Enterprise Cloud you don't get much granularity
... I guess we could set a de facto standard and create a "resume" repository. Though, it would be better if it were a standard feature and searchable too.
I feel like this isn't widely known
---
Well I guess they did say Beta...
I turned this on immediately and now get HTTP 500 errors on every page on GitHub while logged in. Clear cache and login again does not solve.
Oh dear.
Thankfully their support portal does still work. For anyone as unlucky as me:
Edit: Spoke a little soon, my profile page is also 500 when logged out.
On the one hand I actually want the credit for all the open source I've done. On the other I don't want my boss to see if I'm contributing to some open source repo when we have a looming deadline. I would appreciate fine grained control
* Hide activity newer than a certain date. The reason this would be super useful is that it's okay / good for me to contribute to OS during work hours but I don't want the question of "Is now the best time to be doing this?"
* Hide activity on certain repos temporarily
* Hide activity to certain users temporarily
People just use stars in completely different ways such that the information that someone starred something ends up being basically pointless. E.g. people star stuff just because they want to look at them later and having a public link to these profiles isn't really reflecting their relationship with them. I know multiple users (myself included) who were pretty surprised when they first learned that this is all visible.
Of course instead of hiding the stars it might be better to add a private similar feature instead...
Anyway the whole "sharing the development experience" features in GitHub are IMO mostly weird. I'm using GitHub to develop open source software, not because I'm looking for another social network.
We star because we like the code, the idea, the execution and the maybe the impact of the project. And it's encouragement. You star a project you pushing it forward. This is the human experience. We are not machines worshiping code. We care about what others think and this is why github is different.
> Of course instead of hiding the stars it might be better to add a private similar feature instead.
Agreed. Hiding means giving more space to anonymous users do we want that?
> I'm using GitHub to develop open source software.
Same. And i am not coding for myself i also need other to be part of what i am building and that's supposed to be part of the mission. Increase interactively. Instead this feature does the opposite.
I use stars as bookmarks, no more than that.
Hint: This is the culture I need github to promote. Giving back to the community.
GitHub has always been a social coding platform
i remember what happened when VK allowed people to make their profiles private
everyone just made their VK profile private and now you can't see beyond a person's name and avatar
which sucks, because it makes VK look like a ghost town
edit: why am i getting downvoted?
I personally love this feature and have been waiting forever for it. Default to privacy over social features.
if make your whole profile private this would exclude you from the network
As someone who's been subject to harassment based on info on the github profiles, this couldn't have come soon enough. Prior to this my only other option was deleting my account but if I did that the name would have been instantly re-registered by the harassers and used to impersonate me for harassment purposes.
So who is this feature for? Those who have no interest in the social aspects of Github and want to use it privately. I'm sure that's going to be a minority.
Or people who don't want to use GitHub in the first place (esp. because of its less than appealing position on privacy), but they don't have a choice because it's the Facebook of the tech world and seemingly everyone else insists on it in order to get anything done.
https://github.blog/2020-12-17-no-cookie-for-you/
https://docs.github.com/en/account-and-profile/setting-up-an...
In this instance we don't think it will hurt the social coding experience of open source and in fact might encourage folks who would otherwise be put off. But we are testing this particular feature and will keep iterating on it depending how things go and what the feedback is.
Namely, I'd like to be able to stop myself (the org owner) from inadvertently creating a public repo, or at least make it much more difficult to make that mistake.
I can do this for other users in my account (of which I have none), but not for myself as the org owner. I live in fear of clicking the wrong pixel one day and pushing private customer code to a "not meant to be public" repo.
Don't overstate it. Out of all the big social networks, GitHub's handling of user privacy is the worst by far. It took 1 1/2 decades to give a switch to toggle off the default behavior of "provide a public index of my activity across the site to anyone, even though I never asked for this (and was never asked if it was okay, either)". To really spell it out, what this means is that for its entire existence, GitHub has offered even worse privacy controls for what a user chooses to share about themselves than Facebook. For the longest time—until now—the only way to get around this was to regularly delete and then recreate your account (which is still an imperfect solution, not to mention labor intensive) or to disengage completely. Given the way that GitHub has positioned itself, it being even harder to avoid than Facebook has had a hugely deleterious effect on privacy for those who actually care about it.
This should have been table stakes 10 years ago.
So they may not be electing in to the community you are describing.
Or they may have a different idea I’d what GitHub should be than the company did at the start or how you’ve described it.
Forcing public profiles may also a wee bit too close to zuck’s view if the world.
if i'm a member of private org does it count my contributions too? and if i'm no longer a member of the org are my contributions still counted to my profile?
the scenario is the following: somebody invites me to their org to do some work on their private repo, then after the work is done they remove me from the org
what i expect in this case is that my contributions are still counted as long as the repository is on GitHub, even when i'm no longer a member of the org
it's a very minor feature but a very nice one for contractors like me who want to show some progress!
What jumps to the eye right now is that second option checked, as if that's the new feature.
Thank you Microsoft? Eugh nope. Still weird.
> Follow and Sponsor buttons.
Thanks, but no.[0]
How does this affect you? It's just another option for people who want to use it.