I do believe there is a legal liability here on the person using the tool, but not on GitHub.
GitHub would only need to remove the 'auto-insertion' of the code to get around any liability. Then, it would be on YOU if you chose to copy-paste their provided suggestions into your own code.
This seems like a reasonable way to police. My only issue is if the drones can be 'heard' flying over a location. For example, buzzing over a specific house or business. Neighbors would automatically assume danger or guilt. If they drone, they should stay out of ear-range from anyone on the ground. Nobody should hear surveillance.
Seems like Microsoft is trying to brand a cached proxy for Git...? This would make more sense as a paid service for those that need it. Possibly, a local appliance that a company would host internally. What am I missing...?
The reality is: privacy is no longer possible in a connected world. So, rather than worrying about collection/privacy. Maybe, the best use of our energy is best-spent trying to pass laws that standardize disclosure to the customer and the mandating of an audit process...?
Can someone explain to me why there is no Federal regulation requiring the ISP, and anyone else collecting data on us, to provide full disclosure to the customer whose data is being collected? Also, why are there no laws requiring an audit process on erroneous data?
In America, the credit reporting agencies are required to provide a free detailed report annually and there is a legally-mandated dispute process in place for false/erroneous data. Why don't we have the same protections/process for metadata collection?
Instead of expecting data-collecting companies to police themselves, we must insist on regulation requiring free, full disclosure of all data collected and a legal process to have false/erroneous data collection challenged and removed.
The biggest danger is not that they collect this information, but that there is no AUDIT PROCESS to correct false information.