zlacker

[parent] [thread] 1 comments
1. knallf+(OP)[view] [source] 2025-06-03 19:31:09
It's pretty unlikely someone at Cursor cares about accessing your Spring Boot project on GitHub through your personal access token – because they already have all your code.
replies(1): >>tjhorn+Wi
2. tjhorn+Wi[view] [source] 2025-06-03 21:24:05
>>knallf+(OP)
I don't think that's the threat model here. The concern is regarding potentially sensitive information being sent to a third-party system without being able to audit which information is actually sent or what is done with it.

So, for example, if your local `.env` is inadvertently sent to Cursor and it's persisted on their end (which you can't verify one way or the other), an attacker targeting Cursor's infrastructure could potentially compromise it.

[go to top]