Earlier quoted context omitted.
Even if it wasn't forked, it could be cloned. Should that be part of the warning? I wouldn't mind a disclaimer when you delete a repository that any information that repository ever contained is likely to have already been downloaded and stored. Per the comment I added, I'm not sure it would really help that much, but it would not be harmful.
> Should that be part of the warning? It couldn't hurt, but that isn't the misunderstanding I'm worried about. As described in the first example of the article, you can make a fork, commit to it, delete your entire fork , and yet the data will still be accessible via the parent repo, even though no one ever forked or cloned or saw your fork. That is not intuitive at all. You can say "Well just consider any data that…
But isn't that only the third vulnerability, that private forks are implicitly made public?
As I said, I won't defend that decision.