I recently started to notice random custom repositories have gotten added to my HACS instance. These are for integrations that are not actually installed on my HA instance, and which I know I did not manually add to the custom repositories myself. Has anyone else seen this happen, or have suggestions for what to do?
I noticed a few a couple of days ago and deleted those, when I checked today, more custom repositories had been added, but no integrations actually installed from those.
I already changed the password for my HA user and new repositories were added after that change.
My only remote access to my HA instance is via VPN and Nabu Casa. Previously, I did have my own port forwarding and SSL in place, but I have shut those access avenues down.
I’m not sure how to proceed - I don’t want to over react, but I also don’t want to take unnecessary risks. I’m thinking about starting from scratch with HACS, using a new token etc.
Seeing a good 50 or so listed under custom repositories here too. I assumed that was normal, and they were added whenever HACS updated it’s repo list? (Given that every time I pop in to HACS the top of the integrations screen tells me to review all the new repositories that have been added)
Yes, but it’s the fact that when you go to the 3 dots at the top right, and choose custom repositories - which by it’s name you would assume is where you manually add repositories that are not included in HACS - but it is full of loads of repositories that I definitely never added.
All the new ones that were added without my consent were for new integrations or cards that showed up recently. Maybe you dismissed these before the issue was introduced?
I’m running the latest version of HA OS, and I can confirm that after a restart, the custom repositories in HACS are back to showing just the repositories I added myself. Curious about the cause of this one.