Skip to main content

Repository Sharing Guidance

Use this guidance when deciding whether the final project repository can be public.

Public Repository

A public repository is appropriate when:

  • data are public and permitted for redistribution, or raw data are not committed
  • outputs do not reveal private, identifiable, restricted, or culturally sensitive information
  • data source terms allow public sharing
  • the README explains where data came from and how to rerun the project

Public repositories are useful for portfolios, but publication is never more important than privacy, stewardship, or data-use rules.

Private Repository

Use a private repository when:

  • the data source is restricted
  • the dataset includes sensitive or potentially identifiable records
  • a data steward has not approved public sharing
  • the group is unsure whether public release is allowed

For a private repository, grant course staff access and submit the private GitHub repository link on Canvas. The project still needs reproducibility instructions for course staff.

Record the chosen route in repository-access-note.md using the field list in the Final Portfolio brief. The note lets the grader verify the submitted link and artifact paths without guessing; it does not require a justification for keeping the repository private.

Safe Publishing Check

Before making a repository public, confirm:

  • no restricted raw data are committed
  • no credentials, tokens, or private URLs are committed
  • no individual-level sensitive examples appear in outputs
  • figures and tables are aggregate or otherwise safe to share
  • README states the data source and sharing limits