Hosting code
Repositories live in your own GitHub account; OSCR links them to your papers and keeps its tracing maps.
Where repositories live
Your repositories live in your own GitHub account. OSCR runs no git server and holds no repository: git talks to github.com, with GitHub's own credentials, and GitHub's terms, quotas and limits apply as for any repository of yours (the limits).
- When you create a repository through OSCR, its GitHub App creates it in your account with your authorization, one repository per request. Nothing is written in your name without that authorization.
- A repository you already have is linked, not moved: it stays where it is (the mirror mode, below).
- Your repositories lists the ones OSCR knows in your GitHub account.
What OSCR keeps
- The links between a repository and the DOIs of the papers it belongs to.
- The tracing maps between a paper and its code, each pinned to a commit, and their validation by an author.
- How OSCR follows the repository (created, installed or read only), and when it last saw it.
- Copies of the scripts whose repository's licence allows it, confirmed by the repository's own licence file; the other files are linked at the source, at the commit a map points to.
- An archive by Software Heritage of the commits a map points to, only when an author asks for it (rewriting history says why it matters).
OSCR keeps no git object, no token and no email address. GitHub keeps the repository, its branches, tags, releases, issues and pull requests.
The mirror mode
A repository you already have on GitHub is linked to your papers and stays in your account. How OSCR follows it depends on one choice of yours:
- With OSCR's GitHub App installed on it
- GitHub tells OSCR of each push, and OSCR can write back (a branch, a release, a setting) only with your authorization, one action at a time.
- Public, without the App
- OSCR only reads it: it looks for new commits every night, and never writes to it.
Each repository's page says which in a sentence, and when OSCR last saw it. When the repository has a GitHub Pages site, the page links to it; OSCR never rebuilds it.
The guides
- Limits: file, push and repository sizes on GitHub, tree limits, the push policy, OSCR's own caps, and who pays for what.
- Large files: where data goes before Git LFS, and how to use LFS when it is the right tool.
- Git with GitHub: clone, pull and push straight to github.com, credentials, SSH, tags, remotes, and what git's messages mean.
- Rewriting history: rewriting commits, removing large files or sensitive data, and what it does to tracing maps.
- Tokens for git: GitHub's fine-grained personal access tokens, made on GitHub, and why not the classic ones.
- Importing a repository: moving a repository from another host or version control system to GitHub, keeping its commit ids.
- Leaving: the exit path: what stays yours, and what OSCR keeps.
In short: a file in git stays under 100 MiB, a push under 2 GB, a repository ideally under 1 GB; data goes to release assets, Zenodo or Hugging Face before Git LFS.
