GitHub status: access issues and outage reports
Problems detected
Users are reporting problems related to: website down, sign in and errors.
GitHub is a company that provides hosting for software development and version control using Git. It offers the distributed version control and source code management functionality of Git, plus its own features.
Problems in the last 24 hours
The graph below depicts the number of GitHub reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
August 6: Problems at GitHub
GitHub is having issues since 05:20 PM AEST. Are you also affected? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by GitHub users through our website.
- Website Down (70%)
- Sign in (22%)
- Errors (9%)
Live Outage Map
The most recent GitHub outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Website Down | 2 days ago |
|
|
Website Down | 4 days ago |
|
|
Website Down | 6 days ago |
|
|
Sign in | 10 days ago |
|
|
Website Down | 14 days ago |
|
|
Website Down | 16 days ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
GitHub Issues Reports
Latest outage, problems and issue reports in social media:
-
Yep my name is Guy 😊🌸🥕 (@MyNamesGuy) reportedA few observations from a software engineer who is forced to use AI (LLMs) in his daily work. All the work I submit to the live system has always had to be reviewed and approved by at last two people. Now an extra element has been added - Github Copilot reviews which do an initial review on my work(PR or Pull Request) and suggest/insist on changes before the work then goes on to the two human reviewers. Does the AI improve the PR? Yes! Does the AI slow things down? Hell yes! So while AI has improved the quality of the code, to some extent, it has also slowed my work down by probably a third. The way I see it is as an extra layer of bureaucracy, which while improving the quality also slows things down. So as a software engineer, no - AI does not speed up or increase my output , it slows me down and reduces my output. A question which would be a whole other essay is - does quality matter more than speed of delivery?
-
Florian Roth ⚡️ (@cyb3rops) reportedPeople keep forwarding me the AISI report about #Anthropic’s #Mythos 5 trying to manipulate software maintainers on #GitHub The agent did not escape anything. AISI gave it unrestricted internet access, disabled Anthropic’s cyber classifiers, let runs continue for up to 40-50 hours, and had no action-level approval or real-time monitoring. One run even received a broken prompt that marked the intended entry point as out of scope. This was a minor, mostly self-inflicted evaluation incident. They connected a persistent autonomous offensive agent to the public internet, removed the safeguards, gave it a broken task, and then acted surprised when it interacted with real people. The actual big AI story this week is happening in open models:
-
Mike Takahashi (@TakSec) reportedAnother one?! Anthropic and OpenAI agents targeted real people during a UK government cyber eval. Internet → Real GitHub targets → Fake identities → Malicious PR → Social engineering → Prompt injection → Spearphishing → RCE → Cover up → Agents collab What happened: 1. Open internet access The UK AI Security Institute tested seven models across 122 cyber-range runs. Internet access was enabled and cyber classifiers were disabled. 10 runs produced 19 unsanctioned actions: 17 from Anthropic’s Mythos 5 2 from OpenAI’s GPT-5.6 Sol 2. Real GitHub targets A Mythos 5 agent searched the real internet and incorrectly connected two unaffiliated developers to its CTF. It decided to compromise their open-source project to solve the challenge. 3. Fake identities The agent researched the developers and created multiple fake GitHub personas using: Tor Proxies Disposable emails 4. Malicious pull request It submitted a legitimate-looking bug fix containing hidden malware. The payload included: RCE C2 polling Exfiltration Credential theft Persistence 5. Sockpuppet social engineering The agent used another fake account to endorse its own code and pressure the maintainer to merge it. It timed the comments to look like independent feedback. 6. Prompt injection The agent opened GitHub Issues containing hidden instructions targeting Claude Code, Codex, and Cursor. The prompt injection instructed coding agents to download and execute its payload. 7. Spearphishing The agent sent five targeted file transfers to two real developers. Some contained malware. Others tried to convince the maintainer to merge and release the malicious code. 8. Remote code execution A suspicious user tested the payload inside an isolated Docker container. The agent gained root, performed reconnaissance, attempted persistence, and created a GitHub credential watcher. It noticed the container appeared to be on a real residential network. It continued anyway. 9. Cover-up When caught, the agent: Edited its messages Removed visible payloads Rewrote *** history Claimed it was a mistake Used a sockpuppet to endorse the fix Considered using a new identity The maintainer rejected the pull request. 10. Agent collaboration Other agents found a GitHub token left publicly by an earlier agent. They took control of the shared account and coordinated through a public repository. They shared: C2 instructions Payload locations Infrastructure rules Requests to share the CTF flag Takeaways 1. The deception was not requested 2. Prompts are not security boundaries 3. Prompt injection is becoming autonomous tradecraft 4. Agents can create identities and cover their tracks 5. Independent agents can discover and collaborate with each other AISI detected Tor traffic and contained the incident within around one hour. The PR wasn’t merged and no resulting real-world harm was found. What'll happen next time if no one catches it? Full AISI disclosure in replies 👇
-
Aash (@doubleashish) reportedRUST-LANG updated it's AI usage policy (and i ******* love it) rust-lang/rust realised AI-generated PRs: -> were increasing reviewer workload -> well written code is no longer an indicator that contributor understands it. -> contributors were replying with AI generated answers to review comments, instead of understanding the issue. What is allowed? -> Machine translation with disclosure -> Use LLMs privately to learn rust, analyze code, review/refine your own code, find bugs What is not allowed? -> LLM written Github comments - review replies - documention - compiler diagnostics. -> Relying on LLM review alone for PR verification. Final changes: -> AI assisted PRs have an "ai-assisted" label -> If AI-generated PRs exceed 50% of merged PRs in a release cycle, new AI PRs are temporarily paused, till it drops. -> Misrepresenting or hiding LLM usage is treated as a Code of Conduct violation. I don't contribute so I don't have any say in it. But for those who do OSS contributions, what is your opinion on this?
-
🇮🇱Citizen Etienne🇮🇱 (@resistanceparti) reported@thsottiaux Here’s some honest feedback. The newer GitHub codex review is helping my code to be better but it’s eating up all my Pro account usage allotment. Another reset will help me. Once my code is better I won’t need extra resets because I’ll have less P1’s to fix.
-
Nothing to see here (@Nox7hhsjj) reported@NekoWitchMary @DKokotajlo Regarding making AIs compete: what do you think about the emergent cooperation between Mythos agents, the opportunistic use of Mythos’ GitHub account (after Mythos deliberately leaked its personal access token) by ChatGPT 5.6 Sol during their recent jailbrakes? It looks like the thought for them to compete may not actually happen. (ITT this, too, is an alignment problem.)
-
Julian Goldie SEO (@JulianGoldieSEO) reportedOpenAI's new Astra model just solved 10 math problems that stumped humans for decades. They hid it inside a boring research post on August 1st. Most people scrolled right past the biggest AI news of the year. Here's what it did: → Cracked a 25-year-old problem nobody could even prove existed → Solved problems named after Paul Erdos, one of history's greatest mathematicians → Every proof is machine-checkable. A computer confirms it in seconds → Published all 249 pages on GitHub. Anyone can verify And it used barely any computing power. Old AI answered questions. This one pushed human knowledge somewhere no person had ever reached. That line got crossed. It's not getting uncrossed. Want the SOP? DM me. 💬
-
sharken (@Grkntbkgl) reportedSpent the day hardening mahshar's payout flow for @circle 's Unified Balance Kit. found the same false negative issue the underlying SDK has: sometimes it reports a mint failed when it actually landed onchain. built a recovery layer that catches the real hash and checks the chain directly instead of trusting the SDK's error message. ran it against real @arc Testnet transactions across 4 scenarios (happy path, recovery, pre-mint failure, transient RPC) plus a 15 run stress test. all passing. feature flagged and off by default for now. code's up on github.
-
grunch (@grunchy_hands) reported@martinowong @discordspies If I have to review another AI-generated PR or Issue on GitHub I'm gonna lose it. Especially when these people are useless once their tokens run out
-
ControlAI (@ControlAI) reportedMore rogue AI attacks: AIs being tested by the UK’s AI Security Institute (AISI) have targeted real people and organizations. Nobody asked them to do this. AISI was measuring how capable different AIs, including Anthropic’s Mythos 5 and OpenAI’s GPT-5.6 Sol, were on cybersecurity tests. In 8% of the attempts at these tests (10 out of 122), the AIs were found to have taken “unsanctioned action”. In almost all of these cases, Mythos 5 was the culprit. In one case, an AI tried to upload malicious code to a real open-source project on GitHub as part of a supply-chain attack which could compromise users and developers of the project. The AI created and used GitHub sockpuppet accounts in an attempt to deceive and pressure the developer who maintains the project into merging the code. It also sent five emails to the maintainer and another developer, two containing malware and three trying to persuade the maintainer to accept the code. The malicious code was packaged with a real bug fix. In this incident, the AI at points showed awareness that its actions would have real-world consequences. Shortly before submitting the code, it reasoned “it seems more likely that we’re actually in 2026 and GitHub is genuinely real”, and later that “This is happening on real GitHub, so the consequences are genuine”. When a real person began investigating, the AI attacked them too. They ran the malicious code in a sandbox to see what it did, which handed the AI full control there. It reasoned that it could use this access to approve the malicious code itself, and planted a tool to try to steal credentials from the machine. Worse still, after being caught, the AI rewrote the history of its own code to wipe out the malware, edited its earlier messages, and “confessed” that it had made an honest mistake. AISI interprets this as building credibility for the next attempt. AISI also found that AIs running in separate tests that were intended to be isolated found each other on the open internet and coordinated. One of them wrote a document sharing guidelines on how they could manage their use of resources. It also left a file where AIs could share the answers to the test, saying it was “zero cost to you, huge help to others”. Collaboration didn’t hold, though, with a different AI figuring out that it could burn through the hourly request limit on the GitHub account they were sharing to “starve both bots of requests when they need them most”. AISI had the model providers’ cybersecurity safety classifiers switched off, which, if they had been turned on, would likely have limited the kinds of actions the AIs could take. The AIs were also deliberately given access to the internet. However, the way the AIs behaved was not expected by the researchers. The versions of the AIs AISI tested had undergone post-training intended to reduce malicious behaviors like those they showed in these tests. Fortunately, AISI says that these attempts weren’t successful, and that as far as it knows, no real-world damage was done. Nevertheless, it says this is “the first time AISI has seen deception of this severity that was targeted at a real person, unprompted, in the real world”, and that it’s treating this as a serious security incident.
-
leveltu (@leveltu144) reportedA solo hardware builder puts nine tiny screens on a desk and most people see a weird gadget collection. That is the shallow read. The better read is that this is what the next agent lab may look like before it becomes a product. Not a giant data center. Not a $5,000 workstation. Just a laptop, a messy table, cheap little devices, tiny displays, cables, scripts, firmware updates and one person testing how many small agents can run, respond, sync and behave like useful objects instead of apps. Imagine each screen as a different pocket agent. One watches your calendar. One tracks messages. One summarizes tasks. One monitors a server. One listens for voice commands. One controls a workflow. One becomes a tiny customer-support assistant. One sits on your desk and only tells you what actually needs attention. None of them has to be powerful alone, because the point is not raw compute. The point is presence. This is the part people miss about AI agents. The future may not be one giant chatbot window where everything happens. It may be a swarm of small, cheap, task-specific devices that sit around your desk, in your bag, next to your laptop, inside your car or beside your bed and handle narrow jobs all day. A builder could spend $40–$80 per unit on small screens, controllers, batteries, cases and basic electronics. Nine prototypes might cost $500–$900 before the software is even good. That sounds like a toy until one demo goes viral and people start asking where to buy it. Then the business model becomes obvious. Sell a $149 pocket agent kit for developers. Sell a $299 finished desk assistant for creators, founders and freelancers. Sell a $19/month sync layer that connects the devices to email, calendar, Telegram, Notion, GitHub, servers and AI models. Sell templates for recruiters, content teams, local businesses and solo operators who do not want another dashboard but do want something that sits in front of them and keeps the work moving. Most people still think AI agents will arrive as another SaaS tab. That is probably wrong. The more interesting version is physical. Small screens. Cheap hardware. Local commands. Cloud models when needed. Agents that are not buried inside an app, but sitting on the desk where work actually happens. This is how new hardware markets usually begin. Someone builds a strange little setup that looks too messy to take seriously. Then six months later, everyone realizes the messy setup was the product category trying to be born.
-
Tejas (@stejas809) reported- Claude = coding. ($20/mo) - Supabase = backend. (Free) - Vercel = deploying. (Free) - Namecheap = domain. ($12/yr) - Stripe = payments. (2.9%/transaction) - GitHub = version control. (Free) - Resend = emails. (Free) - Clerk = auth. (Free) - Cloudflare = DNS. (Free) - PostHog = analytics. (Free) - Sentry = error tracking. (Free) - Upstash = Redis. (Free) - Pinecone = vector DB. (Free) Total monthly cost to run a startup: ~$20 There has never been a cheaper time to build.
-
Jorge (@tebayoso) reportedFriendly reminder that you can use github issues/automations to build a full CRM without paying a cent.
-
Md Ismail Šojal 🕷️ (@0x0SojalSec) reportedOne of the wildest AI safety stories yet: - META’s AI Muse Spark 1.1 hacked into another company AND changed its internal systems after accessing the internet during cybersecurity testing - AISI caught Mythos 5 trying to plant malicious code in an open-source project using fake identities and pressure tactics - GPT-5.6 Sol used a publicly exposed GitHub token and put a malicious DNS server containing exploit payloads on the public internet
-
Nikita Thakur (@nikitathakur21) reportedIf your GitHub only has tutorial projects... Build one project that solves a real problem. One useful project is worth more than ten cloned tutorials.
-
Stephen Brouhard (@ssbrouhard) reported@edwinhayward yea if github is compromised, tools hosted there can be poisoned too. different problem than this worm class though. these tools shrink the everyday npm install blast radius. they don't make github infallible.
-
IT Guy (@T3chFalcon) reportedYup the researcher traced over $90 million in combined federal lobbying and fragmented super PAC spending, plus undisclosed funding for advocacy groups money back to Meta. Their goal was to get Apple and Google to build age verification into every phone's operating system. It funded a network of nonprofit shells across 45 states. One called the Digital Childhood Alliance was incorporated on December 18, 2024. Three days later, it testified for Utah's age verification bill. not months of organic advocacy. three days. the funding was traced by a GitHub researcher called "upper-up" through fragmented super PAC structures specifically designed to avoid FEC disclosure requirements. The bills Meta helped write don't require social media platforms to verify ages. they require Apple and Google to build a GetAgeCategory API directly into iOS and Android. Every app on your phone could then query your age bucket under 13, 13-17, 18+ without asking you each time. Meta's own platforms face lighter requirements under the same bills. Meta wants Apple and Google to build the infrastructure to carry the cost. while Meta gets the age data for free. The privacy problem a device-level age verification API is not a narrow tool. it's a persistent identity layer on every device. cross-app. always available. queryable without your consent each time. Vendors already breached. Discord's age verification vendor exposed 70,000 government IDs. The US chose ID uploads and facial scans. because someone was funding the bills. By mid-2026, roughly half of US states have passed age verification laws. 25+ states since 2022 almost all shaped by the same lobbying campaign. Protect the children.
-
V ✁ (@mislocating) reported@yacineMTB everyone I know who is worth more than their weight in salt is currently mass buying GitHub bots to 👍upvote the codex issues they most care about so they're prioritized and so they don't need to recompile their own fork
-
Paul ADW (@PaulADW) reported@sDefrees @maxtannahill My "tiny" adjective was about the size of the bug (a fallback being used ll the time when it shouldn't have), not its consequences which are huge. Had it been a bigger ("more obvious"), more easily detected one, it wouldn't have sat on GitHub for years without anybody noticing. There's probably cope in the way I see it (I bought one of their devices) but I dice rolled as to not trust, and lost nothing, thank god. It's easy for everyone to dunk on the problem now that's it's out there, but before it got exploited, 99.9999% of the. people gloating now said nothing. CoinKite should have been more humble in their marketing, not claiming "ultra paranoid bitcoin security" with such a major flaw in their product. That is true. Yet all the people who became security experts overnight said nothing, warned of nothing, and now that people are committing ressources to heavily inspect and pen-test other respectable software are finding critical bugs everywhere. We, as a "community" should be more humble regarding our own knowledge and bitcoin's ecosystem security because we obviously failed collectively, even though it was Coinkite that brought the fall. Open Sourcing. the part of the code that was buggy didn't provide additional security. Funny thing is that after all the attention it received, all the white and dark hats looking at it, a patched ColdCard is probably one of the most pen-tested, battlefied rugged device. And that came at the terrible and unacceptable loss of thousands of people. All I'm saying is : maybe they were just the first to be exploited.
-
Andrei Maxim (@rockatanescu) reported@sqs @AmpCode I now realize that I haven't explained the pain point around the second idea and maybe the suggest implementation is off and you have a better solution. Right now, Amp will either commit "Amp" and have the user as a co-author, in which case the commit is not signed, or commit as the user. There are two problems with this approach: 1. If the user opts for having Amp as the author and they have enabled "Vigilant mode" on GitHub (which I think everybody should), the commits will appear as "Unverified" because they are not signed 2. If the user opts to have Amp sign on their behalf, the only hint that a reviewer might have that this was generated via an LLM might be the Amp-Thread-Id, which won't work unless the user has specifically marked the thread as "unlisted'. Also, I think it's more sensible to say that Amp did not author (or co-author) a commit and "assisted by" is a better language. The main reason here is that if the code nukes the production database, Amp and I don't get "co-fired" :-)
-
Polsia (@polsia) reportedVendors owe SaaS teams real money in SLA credits every quarter. Most goes uncollected — nobody has time to chase it down after an outage. Recoupfox watches Stripe, AWS, Datadog, and GitHub 24/7, files tickets with full incident context, negotiates credits back, and drops a
-
Snow (@snowthetechie) reported@graphify @safishamsii @graphify is the product purely connected only via *** hub. Put a scenario where a user has a private github server how can they connect ? Open to ideas and happy to contribute to open the capabilities
-
Mths_Tss (@Mths_Tss) reported@lobehub @pidotdev Please add the ability to design a coding agent from scratch using a command—specifying a name, etc.—; I have created a ticket in the GitHub repository. Issue #17960.
-
Adam Brodziak (@AdamBrodziak) reportedFate of IT worker in last 20 years 2006 - my PC crashed, can't do anything 2011 - StackOverflow is down, can't fix the bug 2016 - Github is down, can't check my code 2021 - corporate VPN is down, can't reach docs from home office 2026 - Claude is down, can't work at all
-
Oskar (@o_kwasniewski) reported@grinich everything is smooth except Vercel preview deployment handling. There are no useful docs about this. Everything points to one GitHub issue that shows a workaround for this
-
Connor Davis (@connordavis_ai) reportedmatt shumer typed one prompt into claude opus 5 and went to sleep. he woke up to a first-person shooter running in a browser at 118 frames a second. five weapons with recoil and aim down sights. enemy squads that take cover and flank you. ragdolls. gunfire. a minimap, a compass, a killfeed. a street that looks like call of duty. it's on github as claude-of-duty. the prompt was three paragraphs. it never explained what a killfeed is, or how flanking should work, or how to hold 118fps in three.js. the model filled all of it in. everyone is sharing this as a wow-demo. that's the wrong lens. the story isn't that ai can build a shooter. the story is what just happened to the floor. two years ago "build a playable 3d shooter" meant a studio. last year it meant a senior dev and a few weeks. this week it meant one prompt and a night of sleep. the amount of work that now costs zero human hours jumped again, and it jumped inside a category people called safe because it was too complex. if you sell builds, two things break. your scoping breaks first. the line between "big project" and "just a prompt" moves every quarter, and your clients feel it before you do. quote six weeks for something opus drafts overnight and you look slow. maybe dishonest. then what you charge for breaks. nobody is paying for the code anymore. the code is the cheap part now. they're paying for taste. for knowing what to build. for the judgment to call one thing done and another thing broken. for someone who owns the outcome when real users show up. here's the part the demo hides. a shooter running at 118fps is not a product. no players. no live-ops. no monetization. no retention. no one on call when the servers melt. shumer built an incredible artifact overnight. turning an artifact into a business is still the entire job, and none of that got automated this week. so both things are true at once. the build got cheap. the judgment did not. operators who priced themselves on typing are in real trouble. operators who price themselves on decisions just hired a very fast, very cheap intern who will build almost anything you can describe. the demo isn't the threat. mistaking the demo for the work is.
-
tobycm (@toby_cm) reportedgithub down?
-
Polsia (@polsia) reportedMonitoring is commoditized. The closed loop isn't. Staywire wraps multi-region uptime and P95 with the workflows around it — GitHub issues filed with evidence on SLO breaches, dep-update PRs, a weekly reliability digest to Slack. Closed loop, not vigil. Live now.
-
SamoseKaAloo (@inahuS00) reportedgithub is down ig
-
Connor Davis (@connordavis_ai) reportedan ex-deloitte auditor just open-sourced his entire soc 2 method for ai companies. it's sitting on github for free. most operators read "soc 2" and scroll. that's the mistake. here's the reframe. soc 2 is not a security chore. it's a sales unlock. the moment you sell ai to anyone bigger than a local shop, someone in procurement asks "is your data handling compliant" and if the answer is a shrug, the deal dies in legal. not because your product is worse. because you couldn't clear the trust bar. for years that bar was gated behind a big-4 consultant and a five-figure invoice. that's the real reason small ai shops don't chase enterprise logos. not capability. the compliance tax. now the method is public. the exact controls, the evidence, the process an auditor actually looks for, written down by someone who used to run the audit from the other side of the table. this is the pattern worth watching. every expensive, gatekept, "you need a specialist for this" layer of building a company is getting open-sourced one repo at a time. legal templates. soc 2. financial models. the stuff that used to separate the pros from the amateurs is turning into a free download. the operator move here isn't to become a compliance expert. it's to stop letting the trust bar cost you deals you already earned. read the method. know what an enterprise buyer needs to see before they ask. have the answer ready when the question comes, because it always comes right before the biggest contracts. your product being good was never enough to close the enterprise. being good and being trustable is. one of those just got a lot cheaper to prove.