What commitscape keeps, and who can read it
The commitscape command reads repositories on your own machine and sends nothing anywhere unless you ask it to. This page is about the Site: what it stores when you use it.
Public repositories you look up
- What: the repository's Report (its numbers, file paths, the names and GitHub logins of the people who committed, and each commit's subject line), and the facts GitHub shows anyone (description, stars, languages, releases). Never an email address.
- Where: the Report in Cloudflare R2, the rest in a database on our own server. The history is read on our server too, from a clone kept to make the next update quick.
- How long: while people look at it; it is rebuilt when it is more than a day old and someone asks.
- Who can read it: anyone, as they can read the repository on GitHub.
- The Leaderboards: each night our server also reads a budgeted number of the most starred public repositories in each language, as above, and keeps a few numbers from each Report (its Bus Factor, maintainers, this month's commits and people, how old its code is, how fast issues are answered) to rank repositories. Never people.
Shared Reports
- What: a Report your own machine built, locked with AES-256-GCM before it was uploaded. The key exists only in the link
commitscape shareprinted, after the#, which browsers never send to a server. We store the locked bytes, their size, when they expire, and a hash of the Delete Token. - Where: the locked bytes in Cloudflare R2, the rest in our database.
- How long: 4 hours unless you chose otherwise, 12 at most; then it answers "gone" and is removed. The page's Delete button, or
commitscape share --delete, removes it at once. - Who can read it: whoever has the link. We cannot: we never have the key.
Signing in with GitHub
- What: your GitHub account's id, login, name, picture and email address, your sessions, the token GitHub gave the sign-in (encrypted, to ask GitHub which repositories you may see), and which repositories you chose in commitscape's GitHub App, which can only read. For a repository you chose, its Report, as above. The short-lived tokens a Build reads a repository with are never stored.
- Where: our database and R2. A private repository's history is cloned onto our server for its Build, and the clone and everything read from it are deleted when the Build ends; only the Report is kept, which Cloudflare encrypts at rest.
- How long: a chosen repository's Report is deleted after 30 days without a view. Removing the App from a repository on GitHub deletes its Report. "Delete my data" deletes your account, sessions and Reports at once.
- Who can read it: a private repository's Report is shown only to people GitHub says can see the repository, checked again on every view.
Everyone
- To stop abuse, the Site counts how many lookups, Builds and Shared Reports each address starts in an hour (an IPv6 address counts with its neighbours in the same /64). It keeps a hash of the address, never the address, and deletes the count when the hour ends.
- Our server keeps logs of requests, as any host does.
- Errors in the Site are reported to Sentry, without the request's body or cookies. Pages viewed are counted with PostHog, which honours your browser's Do Not Track setting and is never told who you are. No advertising.
The Site's code is open: github.com/pixelactstudio/commitscape.