pull down to refresh

Basically, if your GitHub repo was ever public, Copilot likely knows its contents, even if it's now private. Granted, as the article notes in the lead, almost anything that's ever been public can and likely is compromised, but Copilot's making it easy for folks.
If your repo was ever public while it was supposed to be private, you were compromised at that point though - but it's ironic that Microsoft's own tool is compromising Microsoft's own private code on Microsoft's own platforms.
reply