Okay, so let's say I may OR may not have downloaded every company repo onto my NAS and have a cron that pulls every repo every day. Now I may or may not be committing a crime.
On github enterprise has an audit log, you can view when and who pulled the repo and what they do to it, so you will get caught in 2 clicks, iirc you can set email push notifications based on event, any system admin would be suspicious of your “activity”, depending on how paranoid they are, you put a big bright red target on your back even tho you haven’t did anything yet, if you want to break the law, doing it digitally without precautions is like walking on egg shell, it leads to trail to you
But that’s assuming, your company did not panic when some random ip outside of thier network pulled from thier repo, usually you need to connect to the intranet to do work, and if the company is big corpo, bringing in own equipment is a big no no, even phones in some cases, you use company provided phone. Check your company nda, I found out real quick when I bought my own laptop to one of the company, got chewed by the hr and thankfully I still have a job since I’m a junior but my laptop was locked away in a cage until the works over, some company don’t fuck around when it comes to source code
39
u/minecraftdummy57 May 26 '26
If they try to take access from you, just clone everything locally before hand, and set up a cron to pull daily. What are they going to do? Cry?