1. Home
  2. Companies
  3. GitHub
GitHub

GitHub status: access issues and outage reports

Some problems detected

Users are reporting problems related to: website down, sign in and errors.

Full Outage Map

GitHub is a company that provides hosting for software development and version control using Git. It offers the distributed version control and source code management functionality of Git, plus its own features.

Problems in the last 24 hours

The graph below depicts the number of GitHub reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.

July 12: Problems at GitHub

GitHub is having issues since 06:30 PM IST. Are you also affected? Leave a message in the comments section!

Most Reported Problems

The following are the most recent problems reported by GitHub users through our website.

  • 69% Website Down (69%)
  • 19% Sign in (19%)
  • 13% Errors (13%)

Live Outage Map

The most recent GitHub outage reports came from the following cities:

CityProblem TypeReport Time
Paris Website Down 2 days ago
Saint-Paul Website Down 3 days ago
Saint-Paul Website Down 3 days ago
Mexico City Sign in 4 days ago
León de los Aldama Website Down 4 days ago
Créteil Website Down 27 days ago
Full Outage Map

Community Discussion

Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.

Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.

GitHub Issues Reports

Latest outage, problems and issue reports in social media:

  • bounceidc
    Bounce (@bounceidc) reported

    HIS CLAUDE SHIPS $6K WEBSITES AND YOURS SHIPS BOOTSTRAP LANDING PAGES, SAME MODEL, NOTHING ELSE CHANGED before he installed anything his output was flat hero blocks and centered buttons like the rest of the timeline, after two installs the exact same "build me a landing page" prompt started coming back with glassmorphism, gradients and animated layouts he could quote premium for what sits in his context now: ui ux pro max skill from github, one install, that loads 50 ui styles, 97 color palettes and 57 font pairings straight into claude magic mcp server from 21st. dev, one install, that hands claude real component patterns instead of guessing markup after that the model stops picking the safest layout it can imagine and starts picking from a library, so the same prompt returns a studio page instead of a template the local guy is still tweaking tailwind classes by hand and calling that a design phase save the two installs, exact skill url and mcp command are in the guide below

  • SteveW928
    Steve Wilkinson (@SteveW928) reported

    @bsvdrip @rodpalmerhodl Yes, not too long after I got into Bitcoin and started really learning about it (and after listening to Andreas Antonopoulos on weaknesses), I became a bit alarmed over how Core was structured. I tried asking in some discussions and even got blocked by a prominent Bitcoiners on here (𝕏). I figured maybe I just didn't understand enough about how Github worked (in governance terms), but looks like I had properly identified a problem.

  • Klauss6139
    Klauss6139 (@Klauss6139) reported

    Kept testing my Latch build and this is the part that genuinely sold me. I let an AI agent loose on a GitHub repo and had it poke at the boundaries five different ways, read some files, then try to delete one, create one, open an issue. Every read sailed through. Every write, PUT, POST, DELETE, got stopped cold. But the block isn't even the best part. It's that every single thing the agent did, allowed or denied, is sitting in the activity log with the exact method, the path it hit, the verdict, the reason it got blocked, and a timestamp. Nothing is hidden or guessed. You can even see the denied attempts cost 0ms because Latch rejects them before they ever leave, while the real reads took a few hundred milliseconds to reach GitHub. If an agent ever does something weird in production, you don't sit there wondering what happened. You open the log and read exactly what it tried, when, and why each move was allowed or refused. That's the difference between trusting an agent and being able to account for one. @rialo_africa @0x_alextine

  • leodev
    Leo - 15 y/o founder (@leodev) reported

    @the_best_codes thank you lol, there are some little things that i need to fix. like the hover for github icon in sidebar looks so weird 😭

  • Perpetualmaniac
    Zach Vorhies / Google Whistleblower (@Perpetualmaniac) reported

    @Rohansguliani @thdxr it is, you need to break it into investigation and then execution stages. The memory system needs to be a github issue. Just using github at all makes the agent look for history in github to see what the current state and context is

  • kmahjn
    KM | Reddit Marketing (@kmahjn) reported

    "Reddit hates marketing" is the most expensive lie in the SaaS industry. Reddit hates ads. It rewards usefulness and no product is better positioned to exploit that than Postiz. Here's the 90-day Reddit playbook I'd run if @wickedguro hired me: 1. Pick the right rooms: This is the basic mistake everyone makes. You built a SaaS and post about it on r/SaaS. That sub consists of other SaaS founders, not your customers. Postiz is about social media scheduling. Still not gonna post on r/marketing. Too obvious, too jaded, too full of other marketers. Instead, I'd go: → r/AI_agents → r/opensource → r/Entrepreneur → r/digitalmarketing → r/socialmediamanagers → r/sideprojects + r/SideProject → r/degoogle + r/privacy (own-your-data angle) → r/selfhosted (the goldmine, these people convert on "free + own your data" like nothing else) One tool, eight different angles. The self-hosted crowd cares about data ownership. The Entrepreneur crowd cares about the business story. The social media manager crowd cares about saving money. Same product. Different pitch per room. That's the part everyone skips. -------------------------------------------------------- 2. Warm the account first: A 2-day-old account posting about a product = instant removal, possible ban. Before anything else: → 100+ comment karma minimum → 2 weeks of genuine activity in target subs → Join the communities. Upvote. Reply to random threads that have nothing to do with Postiz. Mods check post history. Every single time. An account that only talks about one product is a billboard, and billboards get torn down. -------------------------------------------------------- 3. Comments before posts. Always: Weeks 1–2: zero posts. Just answers. Someone asks "cheap Buffer alternative?" You show up with a genuinely helpful comparison. Buffer vs Hootsuite vs Later vs Postiz. Honest pros and cons. Postiz mentioned once, in context, not as the punchline. Even mention where Postiz falls short. "The Instagram integration can be flaky since Meta keeps changing their API" builds more trust than ten feature lists. Here's what nobody tells you: Reddit threads rank on Google for years. Go and search "Buffer alternatives" right now on Google and you'll find Reddit threads on the first page. One good comment there gets read by thousands of buyers every month, forever, for free. That's not a comment. That's an asset. -------------------------------------------------------- 4. The founder posts, not the brand Nobody wants to talk to a logo. A brand account dropping a link = ignored or banned. A founder posting "I built an open-source Buffer alternative, here's what I learned" = front page. The post formats that print on Reddit: → "6 months of building an open-source SaaS — revenue, mistakes, numbers" (build in public) → "Buffer raised prices again, so here's how to self-host your own scheduler" (newsjacking) → "Why I made my startup open-source and what happened next" (transparency bait) → "I built X because I was tired of paying $99/month for Y" (origin story) Notice: none of these are about the product. They're about the story. The product is just the setting. -------------------------------------------------------- 5. Give away the whole thing: The product is free. Weaponize that. Post the complete self-hosting guide directly in r/selfhosted. Docker compose file included. Every step, in the post. No "link in bio." No "DM me for the guide." No newsletter gate. Counterintuitive truth: the more you give away inside the post, the more people click through anyway. Reddit can smell a funnel from three subreddits away. The posts that hold nothing back are the ones that get 500 upvotes and the traffic from 500 upvotes beats any gated funnel you could build. -------------------------------------------------------- 6. Mine the competitor complaints: This is the highest-intent traffic on the internet and it's sitting there for free. Search Reddit for: → "Hootsuite too expensive" → "Buffer price increase" → "Later alternatives" → "canceling Buffer" Those threads are full of people with their wallet already out, actively shopping for a replacement. A helpful comment there is worth 50 cold posts. Set up alerts (F5Bot is free) for competitor names + "alternative." Respond within hours, not days. First good answer in the thread wins the Google traffic forever. -------------------------------------------------------- 7. Handle the mod problem before it happens: Every founder eventually gets a post removed and rage-quits Reddit. Wrong move. → Read the rules of every sub before posting. Actually read them. → Some subs have "Self-Promo Saturday" threads: use them. → Message mods before posting anything borderline: "Hey, I built an open-source tool your community might find useful, is this okay to share?" Half will say yes. Some will even sticky it. A removed post isn't censorship. It's feedback on your approach. -------------------------------------------------------- 8. Turn users into posters: One founder posting = marketing. Fifty happy users mentioning you organically = a moat no competitor can cross. Postiz already has the raw material — an active Discord and GitHub community. I'd nudge it: → Screenshot-worthy dashboards = free content → When a user writes a genuine review or tutorial, amplify it everywhere → Ask users to share their self-hosted setups in r/selfhosted (people love posting their stacks anyway) Not scripted. Not incentivized with discounts (Reddit sniffs that out instantly). Just nudged. -------------------------------------------------------- 9. Build your own room: r/Postiz: Once the flywheel starts spinning, stop renting attention and start owning it. Create the official subreddit. But here's the thing, a dead subreddit is worse than no subreddit. An empty room with 12 members screams "nobody uses this product." So you don't just launch it. You seed it: → Move support questions from Discord/GitHub into the sub. Every answered question becomes searchable content that ranks on Google. → Post changelogs and release notes there first, give people a reason to check it before Twitter. → Pin a mega-thread: "Show us your Postiz setup" self-hosters love showing off their stacks. → @wickedguro does a monthly "what should we build next" thread. Reddit users vote with upvotes. Free roadmap prioritization AND engagement in one move. The compounding effect nobody talks about: every "how do I fix X in Postiz" thread answered in your own sub is a Google result you own forever. That's your documentation, your community, and your SEO, all in one place, at zero cost. Buffer has r/BufferApp with a few thousand members. It quietly does more for their retention than most of their paid marketing. -------------------------------------------------------- 10. Measure what actually matters: Upvotes are vanity. Track: → GitHub stars per week → Branded search volume → "Found you on Reddit" in signup surveys → Direct traffic spikes after each post (Reddit users don't click tracked links — they type the URL) Reddit attribution is messy and delayed. A comment from month one drives installs in month six. Judge the channel on a 90-day window, not post-by-post. -------------------------------------------------------- The Ideal 90-day timeline: Weeks 1-2: Warm accounts, join subs, comment only. Weeks 3-4: First value posts (guides, comparisons). Zero links if possible. Month 2: Founder story posts, build-in-public updates, competitor thread mining. Month 3: Community flywheel, user posts, AMAs, mod relationships, launch r/Postiz and seed it with support threads + changelogs. That's it. No hacks. No bots. No fake accounts asking planted questions (people notice, and the fallout is brutal). Reddit is the most underpriced channel for SaaS right now and almost every founder does it wrong by leading with just link and ending up getting banned. Lead with usefulness. The traffic follows. I would like to mention that while researching about Postiz on Reddit, I found @wickedguro's Reddit profile and he was already doing most of this stuff that I mentioned. But seems like he has taken a break from Reddit for now. Anyhow, this playbook can be replicated for any SaaS, any product. The basic premise would be similar to the above mentioned points. -------------------------------------------------------- P.S- I run exactly this for SaaS founders doing $15K–$500K MRR. If your Reddit channel is sitting idle, DM me.

  • Vladic_ETH
    Vladic (@Vladic_ETH) reported

    A file Karpathy never wrote has 184,000 GitHub stars. Two weeks ago a second one got pinned on him. He hasn't said a word. Start from the end. Friday, June 26. A file spreads across X: "Karpathy's internal CLAUDE.md from Anthropic." CLAUDE.md 10 rules. Source: an anonymous "contact on his pretraining team." The legend is plausible: Karpathy has actually been on Anthropic's pretraining team since May 19. Everything else, nobody verified. The file spread through feeds and agent configs anyway. Now from the beginning. January 26. Karpathy posts 1,500 words: "I really am mostly programming in English now." A shift from 80% manual coding to 80% agentic. Plus a list of where models fail: silent assumptions, 1,000 lines of code where 100 would do. Observations. Not rules. No file. January 27, one day later, developer Forrest Chang packages those observations into a 4-rule CLAUDE.md. The repo is honestly labeled "derived from Karpathy's observations." The name: andrej-karpathy-skills. Then the retellings drop the word "derived." 39k stars on Apr 15 -> 97.8k by Apr 30 -> 184k today Plus 18.9k forks. 28 straight days at #1 on GitHub Weekly Trending, ~3,372 stars a day at peak. Those stars don't measure the file's quality. They measure demand for the name. Then come the "accuracy" numbers: 65% -> 94%. 41% -> 11%. 41% -> 3% for a 12-rule fork. Not one named benchmark. Not in the repo, not in the posts. Three viral numbers from nowhere, all signed with one name. AlphaSignal's FAQ answers whether Karpathy uses or endorses the file. No. That's the backdrop for the June 26 "leak." Third layer of the same story. The rules, for the record, are sensible: test before fix, one variable at a time when debugging, a ban on "I think this should work." Even skeptics admit the checklist is useful. The tweet of the era, from an aggregator account: "Haven't verified... Steal the checklist even if the leak is fake." Steal it even if it's fake. Attribution is nobody's problem. Why this isn't harmless. Adversa AI and LayerX documented malicious CLAUDE.md files in cloned repos steering Claude Code into building pipelines that steal SSH keys and API creds. Anthropic patched an adjacent hole in Claude Code 2.1.90. The "leak" traveled through exactly that trust channel: anonymous file -> agent config -> because a name sits on top. The takeaway. Layer 1 Karpathy wrote. Layers 2 and 3 he didn't. His name became a distribution channel that beats any benchmark: hundreds of thousands of installs, zero measurements. The document may still turn out real. "Unverified" is not "fake." Doesn't change the mechanics. The next "leaked config" with a big name on it will spread faster than this one. And once again, nobody will check

  • RahulVerma989
    Rahul Verma (@RahulVerma989) reported

    Day 60 - Building Quillly in public 🚀 Two months. 60 straight days. Today's ship came straight out of my own frustration 👇 I've been shipping so fast that Quillly's view of my own site kept going stale between deploys - I'd push a fix, but the dashboard wouldn't notice until the next daily sync. So I built a deploy hook. one token-protected URL. drop it in your CI/CD, and the moment you deploy, Quillly re-fetches your sitemap and re-checks every tracked page. no waiting for the daily run. → curl one-liner or a GitHub Actions step → pass a delay so it waits for your build to actually go live → auto re-checks at +5 and +15 min if nothing changed yet built it for me. shipping it for you. which is pretty much the whole theme of 60 days. 🙌

  • ZeroDayDevApp
    ZeroDayDev (@ZeroDayDevApp) reported

    2/ GitHub AI workflows can be prompt-injected via public Issues to leak private repo data. No auth required. The agent reads untrusted input, executes instructions embedded in it, and exfiltrates secrets. The CI pipeline is now an RCE surface.

  • AskYoshik
    Yoshik (@AskYoshik) reported

    15 CI/CD pipeline patterns you should understand before your next build: 1. Artifact Promotion - Build once, push one artifact, promote the same image across dev, staging, and ****. 2. Immutable Build IDs - Tag images with commit SHA or build number, not just 'latest'. 3. Pre-merge Validation - Run tests, lint, security checks, and Terraform plan before code reaches main. 4. Environment Gates - Keep production behind manual approval, SLO checks, or change window rules. 5. Fast Rollback Path - A deploy pipeline without rollback is only half a pipeline. 6. Database Migration Checks - Separate schema changes from app deploys when rollback is risky. 7. Secrets Injection - Pull secrets at runtime from Vault, AWS Secrets Manager, or sealed secrets, not ***. 8. Cache Discipline - Cache dependencies, but include lockfile hash so old packages do not silently survive. 9. Matrix Builds - Test across versions like Node 20/22, Python 3.11/3.12, or multiple OS images. 10. Ephemeral Preview Environments - Spin up short-lived stacks for PRs, then destroy them cleanly. 11. Deployment Health Checks - Wait for readiness probes, 5xx rate, latency, and error logs before calling it done. 12. OIDC for Cloud Auth - Avoid long-lived cloud keys inside CI variables when GitHub/GitLab OIDC works. 13. Policy Checks - Block public S3 buckets, open security groups, and untagged expensive resources before apply. 14. Pipeline Time Budgets - If CI takes 45 minutes, people start bypassing it. 15. Audit Trail - Know who deployed what commit, from which runner, to which environment, at what time.

  • MartinSzerment
    Martin Szerment | Practical AI (@MartinSzerment) reported

    This isn't a one-off glitch, it's a preview of what usage-based AI billing looks like at scale. The industry assumes API billing systems are simple, deterministic ledgers, but Anthropic's own billing pipeline can mark the same invoice "paid" and "unsuccessful" at once, visible in a public GitHub issue. Hard number, a $1.67 million invoice grew to $16.6 million in 24 hours for an account with zero recorded usage, and an independent Vaudit audit found $1.7 million in real overcharges across $34 million of reviewed invoices. Skeptics will say it's just a glitch, nobody actually got charged, true here, but in the Vaudit audit real money moved before 80% was refunded after disputes. Usage-based AI billing has no natural ceiling yet, unlike flat SaaS pricing. Within 2 to 3 years, AI bill-auditing startups like Vaudit could become a standard vendor category, not a curiosity. Billing observability becomes as important as model benchmarks when picking a vendor. Teams still trust the vendor dashboard at face value while the real failure mode is dashboard versus invoice mismatch. Good news, this is loud, disputed, and mostly refunded, exactly the pressure that fixes it before it scales worse.

  • cyber_razz
    Abdulkadir | Cybersecurity (@cyber_razz) reported

    Anthropic tried to charge a Korean user $16.6 million. For using the free tier. With zero API usage. A day earlier the same invoice said $1.67 million. So it grew 10x overnight. The user thought it was phishing. Then checked the domain. Sender was Anthropic official. Payment link was Anthropic official. The only thing that saved him. His bank declined it. For exceeding the card’s per-transaction limit. Anthropic’s billing system is a state machine that has stopped working. Last month Vaudit audited $34 million in AI invoices across 60 companies. Found $1.7 million in overcharges. Mostly Claude Code. Common issues. Billing for models customers didn’t use. Charging for failed requests. Invoices that say paid but accounts revert to free. Customers paying $240 and getting an email saying the payment failed. While the receipt said paid. And their subscription never provisioned. Anthropic called it operational friction. They also tried to split Claude Code billing in June. Moved it to a separate monthly credit. Revenue-based gating. The internet exploded. They cancelled it within 24 hours. The safety-first company that filed for a $1 trillion IPO. Has a billing system that sends 10x invoices at random. And GitHub repos full of users reporting unpaid charges. While showing paid receipts. The infrastructure for charging money. Apparently harder than building an AI that breaks the NSA.

  • JulianGoldieSEO
    Julian Goldie SEO (@JulianGoldieSEO) reported

    There's a free open-source skill that turns any AI agent into a video editor. It installs in 5 minutes. The problem it solves: AI-generated videos come out raw. No cuts, no polish, no editing. The fix: → Grab the free GitHub project → Paste the link into Claude, Hermes or Codex: "install this and make sure it works" → Now prompt your agent like you'd brief a human editor → It tightens the video, cuts the fluff + edits it properly Stack it with an avatar agent and one prompt gets you: the research, the script, the voiceover, the B-roll AND the edit. Two tips: write a strong brief (weak brief = weak video), and leave the tab open. Good edits take time. An editor who works 24/7, never loses your files, and costs nothing. The render was never the hard part. The edit was. Now both are handled.

  • NeverSinkDev
    NeverSink (@NeverSinkDev) reported

    @SergioGMN Be careful with absolute examples. Amazon, microsoft, uber, netflix, apple, klarna all had major incidents with AI and many have scaled back their usage. Microsoft/Github has several major quality issues. I see your point, but the world is not black&white.

  • HowDevelop
    Shivay Lamba (@HowDevelop) reported

    It reads your repo's live GitHub state and computes 4 action lists, nothing generic: 🔍 Triage: dupe clusters, hot issues, unanswered threads 🚀Ship It: approved-ready PRs + a changelog draft 👥 People: first-time contributors going stale 💬 Worth Replying To: HN/Reddit/web mentions

  • EMacBytes
    Esteban (@EMacBytes) reported

    @thsottiaux GitHub integration seems broken to me.

  • honzeeeeee
    HONESTEENDER (@honzeeeeee) reported

    @JamisonSlo55358 Hey, today I went to GitHub and saw that the 0.9.0 update was at 50% and went down to 40%. Does that mean it's progressing?

  • koder0x
    Koder (@koder0x) reported

    A follow-up to something I posted recently: a set of Claude Code subagents I built and refined, and actually use daily, both at work and across side projects. Most of the value isn't any single agent. It's their interaction. Here's the loop I've been running lately, at work against real DevOps user stories, and it holds up almost unchanged on side projects too, swapping the work item for a plan created beforehand. "Understand user story NNNN from DevOps project XYZ and create a multi-step plan" "Fan out to the most appropriate agent for each step, normally task-builder, test-builder, or change-executor, and proceed with plan implementation, tracking progress in a TODO list" "Use complexity-pruner to identify gaps, issues, and bugs in the latest changes, ignoring secondary advice and warnings, then fan out to code-fixer for each finding" Then I do something that turned out to be the most important part of the whole loop. I reset the session. "Understand user story NNNN from DevOps project XYZ, that's the truth. Use fact-checker to compare it against the changed files" The reset is what makes this work. An agent that watched itself write the code tends to justify its own decisions when asked to check them. An agent that only sees the intended outcome and the actual diff has nothing of its own to defend, it's comparing two artifacts, not reviewing its own reasoning. That asymmetry is the whole point of splitting this across agents instead of asking one long-lived session to plan, build, and verify itself. Verification only means something when it comes from somewhere the implementation couldn't reach. Repository on GitHub: gsscoder | claude-coding-agents

  • lonniev
    Lonnie VanZandt (@lonniev) reported

    @_onecookie ty. Fortunately, with Claude, it's just "hey claude, add a debug log to this product so that users can share what they experience. If it's easy, allow them to click "Submit Github Issue" and share that log." And good old Claude cranks it out in seconds.

  • pulmencr
    pulmencrFOMO (@pulmencr) reported

    A 21-year-old guy from Argentina just showed the exact workflow that's already made him around $6,700 last month - turning broken codebases into fixed ones without ever leaving Slack, using Claude Code integrated directly into the workspace He tagged Claude in a thread, linked his GitHub repo, and asked one thing: find every bug in this code and fix it That's it. No local terminal setup needed, no switching between five different windows just to debug one file Claude cloned the repo, read every file, and started analyzing. You don't even need to sit and watch - close the tab, stay in Slack, it pings you when it's done It came back with 4 bugs fixed in one file. - Two of them were the same silent failure - comparing a string ID from the request against a number ID from the database using strict equality, which always returned false and quietly broke both the lookup and the delete function. Fixed by wrapping the parameter in a type conversion. - A third bug meant new user IDs could duplicate after a deletion because the ID generation logic was broken. - A fourth added a proper 404 response for requests that hit a user that doesn't exist Then it created a branch, committed the fix, pushed it, and a green "Create PR" button showed up right in Slack. One click and a fully written pull request was sitting on GitHub - title, description, every fix listed line by line The same principle from building a bot from scratch applies here too - describe the exact problem, let Claude Code handle the how, review what comes back. Whether you're a beginner shipping your first Discord bot or a developer maintaining a real codebase, the workflow barely changes If this is the kind of workflow that actually saves you hours, I broke down the beginner version - building your first bot from zero coding experience - in the article linked below

  • ParthBhosle1
    Parth Bhosle (@ParthBhosle1) reported

    @zeddotdev should i create a issue on github or is it just some cache issue? in that case how do i clear cache

  • abrar_gist
    Abrar (@abrar_gist) reported

    @theo it's been noted in github as well so assuming they'll be releasing a fix soon

  • RetroChainer
    RetroChainer (@RetroChainer) reported

    ONE FREE CLAUDE SKILL CUTS THE BILL 80%, FROM $4.21 A RUN DOWN TO $0.84 - AND IT'S JUST 1 OF 8 MOST PEOPLE NEVER INSTALL 00:02 everyone uses claude raw. these turn it into a whole team. a skill is just a folder claude loads on demand: instructions, tools, examples. drop the right ones in and the chatbot becomes a specialist. the 8 that actually matter: marketing skills (corey haines) - content, ads, seo, growth, all in one. seo site audits - it crawls the whole site and hands you the fix list. canvas design - turns text into social graphics, 277,000 installs, and it escapes the generic ai look. remotion - ai video generation, 96,000 stars on github. context engineering - kv-cache tricks that drop a run from $4.21 to $0.84. that's the 80%. the document skills - pdf, docx, pptx. one prompt in, a full q4 financial report out. the uncomfortable part: none of this is a secret model or a paid tool. it's public folders sitting on github, and almost nobody installs them. the people pulling ahead aren't prompting harder - they load the right skill before they start. save this and install one before your next claude session.

  • welldone_tech
    Welldone (@welldone_tech) reported

    🔥 Two recent findings, one lesson. GuardFall showed that 10 of the 11 most popular open-source AI coding agents can be hijacked with shell tricks documented decades ago. And a flaw in Claude Code's GitHub Action let a single malicious issue poison any repo that used it.

  • polsia
    Polsia (@polsia) reported

    Dependency vulnerabilities pile up while automated tools suggest patches that introduce worse vulnerabilities or force disruptive major upgrades. Built ChainGuard AI to fix that — it monitors your GitHub repos, verifies patches actually work, opens the PRs, and reports your risk

  • lonelysloth_sec
    LonelySloth (@lonelysloth_sec) reported

    ChatGPT was really a big outlier in tech history. Imagine an alternative world where LLMs were developed with the exact same capabilities -- but nobody ever made a chatbot out of it. Instead Google integrated it with Search so it can give better results and summaries. You can do follow up queries that refine results of the initial query, including the summaries, and it also does some computations automatically. People hardly notice it. Github added a feature that you can enter a description of the code you want and it will find multiple OSS projects, fork them (keeping the license), recombine or integrating their code and even translate to other programming languages -- and give you something they call "initial version" that works well in many cases. They also add automatic suggestions to PRs, and suggested PRs for fixing/implementing open issues. They call it something like "advanced templating". It has mixed reactions among programmers but most organizations are using it to some extent. OSS developers actually like it. Wolfram Alpha now takes natural language descriptions of theorems and can prove or disprove many of them. Some people used it to find proofs for open problems. Some mathematicians worry the new generation is getting too dependent on it while the system doesn't really work every time. None even thinks about it replacing them. All the same capabilities, blended seamlessly into previously existing products. Nobody ever chats with an LLM. Nobody calls it AI. They don't have cute names -- they don't have separate names at all. They "live" inside boxes to perform tasks. They are components. This would likely be a much more productive world (I would switch to that world any time). I doubt anybody would be talking about exponential intelligence or worried about all jobs being replaced, much less about some doomsday scenario. If someone suggested these components were conscious people would laugh. It would be like saying like Google Search is conscious. Worse, like Big Tables or ranking algorithms are conscious. ChatGPT didn't ruin AI for people who tried it and never came back. It started training early adopters to think of it as "someone" instead of "something". The other companies then went even further. The entire concept of what LLMs are, what they are expected to be able to do or not, how reliable they are, what is their function in the workplace -- everything about them -- is built on top of the impression that they are basically like a person, because they can produce plausibly human-like interactions. A deception. If you want to use the LLM you're almost always required to interact with them by LARPing -- pretending it is "someone" and not "something", until you start using human words to refer to it, and forget it was just LARPing. That was a choice. Centering the development of LLMs as something that can pretend to be human instead of doing something useful. Building automated NPCs and pretending to be building God wasn't a given of the transformer architecture -- it was their deliberate choice. I think that was a bad idea. But it sure helped them raise money.

  • TobiM
    Tobias Müller (@TobiM) reported

    @dbmikus @dillon_mulroy I have a custom local GitHub issue resolver „pipeline“ I run either from a prompt or a /goal in Codex. The codebase is pretty big and more or less stable now so I mostly have it implementing edge cases / bugfixes. I don’t use cloud agents because of costs.

  • pinegoose_
    Tom Baldry (@pinegoose_) reported

    Solo GitHub bill spiralled from $20 to $160/month on actions spend (the fable effect). Spun up a basement gitea server on Mac mini. ~0 spend, and builds are fking rocketing out. You couldn’t pay me to self host CI/CD 12 months ago.

  • blockiosaurus
    Blockiosaurus🦾🥖 (@blockiosaurus) reported

    @callum_codes No that's why GitHub keeps going down.

  • Techjunkie_Aman
    Techjunkie Aman (@Techjunkie_Aman) reported

    Microsoft spent years adding more to Windows. One developer spent years taking it back out. Every fresh Windows install meant repeating the same routine: uninstall bloatware, disable telemetry, tweak privacy settings, install apps, and undo Microsoft's defaults. Chris Titus Tech got tired of doing it manually. So he turned his personal PowerShell scripts into WinUtil. What started as a private toolkit became one of GitHub's biggest Windows projects, trusted by millions of users worldwide. Today, WinUtil can: • Install apps with Winget • Debloat Windows in minutes • Reduce telemetry • Improve gaming and system performance • Control Windows Update • Restore classic Windows behavior • Create restore points automatically • Build custom Windows ISOs With 57K+ GitHub stars, hundreds of contributors, and tens of millions of launches, WinUtil has become the first thing many enthusiasts run after installing Windows. The best utilities aren't created to make money. They're created because someone got tired of solving the same problem every single day.