I don't think the fear is that they'll steal code you'll end putting publicly on GitHub, but everything else. I guess there is some fear that it won't just analyze and process what you currently have open, but might scrape your computer for more data and so on.
I personally don't believe ByteDance would be stupid enough to even attempt exfiltrating files from developers machines, which typically are better protected than the average user computer, just trying to see the perspective of others with a more charitable reading :)
Honestly, if they built a real scripting engine into OpenTofu, I'd be overjoyed. As it stands though, the declarative code (HCL) isn't the ugliest.
Come to the webinar tmrw, not quite a scripting engine but multilang no-custom-provider custom function support
https://www.linkedin.com/posts/opentofuorg_native-lua-more-i...
Apologies for the LI link I’m a startup CEO
Yes, indeed. But it seems the problem more was something with Google's algorithm, I swear a month ago this here [1] wasn't on the first page when searching for "terraform private provider registry".
That also answered the second question.
Deleted Comment