Skip to content

Private repositories

A private repository is encrypted on your device before anything is stored. Only its members hold the key, and Dash Platform itself refuses an unencrypted issue, pull request, comment or branch name for it.

How sealing works

  1. Each private repository has its own key. Every member gets a copy, encrypted to their identity.
  2. Your browser or the command line encrypts code, branch names, issues, pull requests, comments, reviews and releases before they leave your device.
  3. Dash Platform rejects an unencrypted issue, pull request, comment, review text, branch name or release note for a private repository. The details of events, such as which label was added, are encrypted by Forge's apps.
  4. Storage, whether your own bucket, IPFS or Dash Platform, only ever holds encrypted files.
  5. Members decrypt in their own browser or terminal. There is no Forge server that could read anything.

What stays visible

Encryption hides content, not activity. Anyone can read the public network, so plan for this list to be public.

Only members can read

  • Code, commits and file names
  • Branch and tag names
  • Issue and pull request titles and text
  • Comments, review comments and the files they point at
  • Release names, notes and assets
  • Milestones, and which label or milestone an issue carries
  • The default branch and which branches are protected

Anyone can see

  • That the repository exists, with its name, description, topics and owner
  • Its members, their roles, when each joined, and when its key changed
  • When anything happens and who did it: pushes, issues, pull requests, comments, reviews and edits
  • Whether an issue or pull request is open, closed, merged or a draft, and who is assigned or asked to review
  • Issue and pull request numbers, review verdicts, and the line numbers review comments point at
  • File sizes, and roughly how long each piece of text is
  • Commit ids, so someone who already knows a commit can confirm the repository has it
  • Label names, colours and descriptions, check names, and merge rules such as required approvals

When you remove a member

Removing a member changes the key. Everything written after that uses the new key, which they never receive. What they could read before stays readable to them: nothing can take back a copy they may have kept.

What private repositories can't do

Forks and webhooks are turned off, because both would publish content unencrypted. Merging a pull request needs the dg command line for now.