top | item 31844184

(no title)

jameslao | 3 years ago

Thanks for taking a look! Yeah, not having admin access is definitely a problem. Using a PAT is an interesting idea that I'll have to think about that from a security and liability perspective.

discuss

order

igetspam|3 years ago

Just today I had to go through the work of auditing a GitHub app, for compliance reasons. Having the source available made that possible. Since your source isn't available, the barrier to entry would be a SOC2 report or you filling out a vendor survey.

Compliance is a PITA but it's a real thing for companies. How are you planning on clearing that hurdle? I wouldn't want to put you through the vendor survey gauntlet and SOC2 is a lot to ask of a solo dev but the aforementioned IT team could likely be persuaded if you did Type 1 at least.