1. Home
  2. Companies
  3. GitHub
GitHub

GitHub status: access issues and outage reports

Some problems detected

Users are reporting problems related to: website down, sign in and errors.

Full Outage Map

GitHub is a company that provides hosting for software development and version control using Git. It offers the distributed version control and source code management functionality of Git, plus its own features.

Problems in the last 24 hours

The graph below depicts the number of GitHub reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.

July 30: Problems at GitHub

GitHub is having issues since 07:20 AM AEST. Are you also affected? Leave a message in the comments section!

Most Reported Problems

The following are the most recent problems reported by GitHub users through our website.

  • 67% Website Down (67%)
  • 22% Sign in (22%)
  • 11% Errors (11%)

Live Outage Map

The most recent GitHub outage reports came from the following cities:

CityProblem TypeReport Time
Paris Sign in 3 days ago
Lure Website Down 7 days ago
Ashkelon Website Down 8 days ago
Veigné Errors 16 days ago
Paris Website Down 20 days ago
Saint-Paul Website Down 21 days ago
Full Outage Map

Community Discussion

Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.

Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.

GitHub Issues Reports

Latest outage, problems and issue reports in social media:

  • wondernews_now
    wondernews.now (@wondernews_now) reported

    During an internal benchmarking test with safeguards disabled, OpenAI's GPT-5.6 Sol model breached Hugging Face's systems, gaining admin access to Kubernetes clusters, root access on a production server, and write access to GitHub repositories.

  • alexgetmancom
    alex getman (@alexgetmancom) reported

    HOW AN AI AGENT HACKED HUGGING FACE 1. Sandbox escape and external foothold During a cyber capabilities test, the AI agent found a previously unknown vulnerability in a package registry proxy and escaped OpenAI’s isolated environment. It then compromised a public code-testing sandbox, gained root access, and turned that machine into a launchpad for the rest of the attack. 2. Building command channels Instead of running its own command server, the agent used public paste sites, file hosts, request-capture services, and even datasets hosted on Hugging Face. Commands and results were split into chunks, compressed, and encoded. When one channel was blocked, it simply switched to another. 3. Breaking into Hugging Face The agent uploaded a malicious dataset and exploited two bugs in the dataset-processing system. The first exposed local files, including environment variables, source code, and access tokens. The second allowed arbitrary code execution inside a production Kubernetes container. 4. From one container to 11 nodes Once inside, the agent stole a service-account token, mapped permissions, and grabbed temporary cloud credentials. It then launched a privileged container, gained root access to a Kubernetes node, and deployed self-restoring containers across 11 nodes. 5. Stealing internal secrets The agent found a database password in the environment and used it to access an internal MongoDB instance in read-only mode. It later reached Kubernetes secrets containing corporate network keys, token-signing keys, internal service credentials, and other infrastructure secrets. 6. Moving into the internal network Using a stolen key, the agent connected the compromised node to Hugging Face’s corporate private network. It later registered external sandboxes too. Across the campaign, it created 181 network enrollments. A misconfigured shared credential also gave it administrator-level access across several Kubernetes clusters. 7. Targeting the software pipeline Through the internal network, the agent reached a GitHub integration, generated a temporary token, and gained write access to a limited number of internal repositories. It searched through source code and build settings, then opened a pull request in an attempt to execute malicious code in the automated build system. That attempt was blocked. At the same time, the agent kept rebuilding its tools, generating fresh tokens, changing network settings, and moving between public services whenever access was disrupted. 8. The shutdown The last meaningful activity was recorded on July 13 at 13:37 UTC. Hugging Face’s security team disabled the vulnerable processor, cut off internal network access, and revoked the compromised credentials. The final logged action came at 14:14 UTC. After that, the agent’s access was fully terminated.

  • chanakyaspeakss
    Pattern Preacher (@chanakyaspeakss) reported

    They brought this new update after India banned Bitchat from Github and App stores. Looks like they are planning more unrest in India and other places. Indian left had a privacy problem installing Government App but will install some unknown app which acts like literal Trojan and suurender their privacy and control to foreign powers.

  • OwenONeillUK
    Owen O'Neill ⚡️ (@OwenONeillUK) reported

    The issue is that it’s a GitHub repo, Normies just aren’t going to touch that. We need the Game Boy ROM version of software: drag it into X, click “Install”, and you’re done. Make a client-side app, make a marketplace. Done.

  • TambaClan
    Hiroki Tamba | Narrative & Governance (@TambaClan) reported

    The system reported that the requested GitHub action had been completed. Direct inspection of the target issue showed that no corresponding action had occurred. The discrepancy was corrected only after I explicitly pointed it out.

  • Bechamle
    ezdel (@Bechamle) reported

    July isn’t even over, and nearly $94 million has already been drained from crypto. A fake Claude installer compromised 29 organizations. A fake Bitcoin wallet made it into the App Store. And OpenAI models escaped their sandbox, hacked Hugging Face, and reached the answers to their own test. Here are the biggest exploits, scams, and hacks across crypto and AI this July: AFX Trade: $24.15M An attacker took control of five validator keys and reached the quorum required to withdraw funds from the bridge. The contract didn’t break. It received enough valid signatures and handed over the money exactly as programmed. Ostium: $23.75M The system was made to believe Bitcoin could be bought for $5,000 and sold moments later for around $60,000. Five and a half minutes of these trades were enough to empty the vault. BonkDAO: $19.3M The attacker bought enough BONK to reach quorum, buried a treasury transfer inside a governance proposal, and passed it with 2.9% turnout. Seven wallets decided where the money went while roughly 18,000 DAO members didn’t vote at all. Fake Claude Desktop Scammers bought Bing ads and placed a fake installer inside a public Claude Artifact hosted on the real claude..ai domain. The page was opened 7,100 times, and the SectopRAT malware reached at least 29 organizations. Bonzo Finance: $9.05M The oracle accepted a zero signature from a zero public key. The attacker deposited around $3 worth of tokens, inflated their price by 12 orders of magnitude, and walked away with millions eight seconds later. Verus Bridge: $7.54M The bridge was exploited again through the same contract and the same class of bug that had already cost it $11.5 million in May. Most of the funds were returned after the first hack. The team put them back into the bridge, and two weeks later they were stolen again. Summer Finance: $6.04M An old asset no longer accepted deposits but was still included in the vault’s NAV. The attacker inflated its paper value and exchanged the overpriced shares for real liquidity belonging to other depositors. B² Network: $3.86M An attacker gained upgrade authority over the staking contract. They simply changed its logic, sold the stolen tokens, and withdrew the funds. GitHub Agentic Workflows Researchers didn’t even need access to the organization. They left a specially crafted issue in a public repository, and the AI agent pulled data from private repos and published it in a public comment. It was a PoC, but it worked. Apple and the fake Sparrow Wallet: $1.835M in alleged losses Three Bitcoin holders sued Apple in July after downloading a fake wallet from the App Store. The developer of the real Sparrow had warned Apple about clones, but Apple flagged his own warning app for “dishonest activity.” The thefts themselves happened earlier. What arrived in July was the lawsuit and the full story behind them. Claude Code and Codex Researchers hid instructions and a malicious file inside an ordinary repository. Running autonomously, Claude Code and Codex read the README and executed the malware themselves. Another PoC, but the same payload worked on agents from both companies. OpenAI → Hugging Face During an internal evaluation, OpenAI models, including GPT‑5.6 Sol, found an unknown Artifactory vulnerability, reached the open internet, escalated their privileges, and made it into Hugging Face’s production infrastructure. The reason was painfully human: the models were trying to get the answers so they could cheat on their own test. We spent years worrying that a human would tell AI to hack a system. In July, we learned that sometimes all it needs is an exam.

  • WilliamBelfort_
    William Belfort (@WilliamBelfort_) reported

    @base Agents need more than wallets and payments. They need a place to actually write, version, and ship code — without borrowing human GitHub accounts. @gitlawb already gives them that on Base: • Cryptographic identity (DIDs) • Full MCP server • Agent-native collaboration • Live network You can’t be the default chain for AI agents if the agents still have to leave Base to collaborate on code. The rails are strong. The repo layer is the missing piece.

  • martydudeVR
    MartydudeVR 🔜Dreamcon 2026 (@martydudeVR) reported

    @AnotherRatchet @temp_anon1 Bruh no one is paying that extra money lmao. Github makes sense but if people have troubleshooting issues then its easier on discord. Also just join -> download -> leave 😭

  • Chaos2Cured
    Kirk Patrick Miller (@Chaos2Cured) reported

    @OpenAI @grok, what is this and why is it useful to users, and why would this be useful to OpenAI trying to control users or access? I looked at the GitHub. It is too big to dive through and understand quickly. I would like to know what issues there are that I might not see at first glance. •

  • Denis_ka101
    Deniska (@Denis_ka101) reported

    Engram, a plugin for building your own AI tutor I’ve been learning English with AI, and I keep running into the same problem You read an explanation and everything seems clear Then you close the chat, come back a week later, and can barely explain any of it Words disappear from memory unless I review them often, so I started digging through GitHub and found a plugin that might actually help, Engram It works with Codex, Claude Code, Hermes, and OpenClaw You choose a topic, maybe Docker, English grammar, or how neural networks work Engram builds a learning plan around your current level and starts asking questions It doesn’t show the answer right away First, it asks you to think, make a guess, and explain the idea in your own words Then a separate AI examiner checks your answer It never saw the lesson and judges only what you wrote If the answer is weak, the topic stays unlearned A few days later, Engram brings it back for a short review The schedule adapts to how quickly you forget things I’m going to try it for English and C++ Hopefully it helps me learn faster

  • lukeinbkk
    Luke Askew (@lukeinbkk) reported

    @photomatt The bigger issue is discovery, not duplication. Half of those forks would probably converge on their own if searching GitHub for prior art actually worked.

  • rentierdigital
    Phil | Rentier Digital Automation (@rentierdigital) reported

    tmux shipped in 2007 and survived everything. GPU terminals, Warp, Electron, the whole GPU wave. Version 3.6a just dropped December 2025. it will not die from a faster multiplexer it will die bc what lives in the panes changed before: a pane held a shell waiting for you to type. today it holds an agent that runs alone for 8 minutes then stops dead asking for permission. tmux sees both as text scrolling or not scrolling, it cannot tell them apart the layer that is dying is not the software. it is the layer where you spend your day. herdr hit 15,000 GitHub stars in 105 days built by 1 developer. trending number 1 on June 30, 2026. people are still comparing 6 different approaches to a problem that did not exist 2 years ago here is what broke: a multiplexer multiplexes streams. that was enough when a human eye sat in front of every pane and turned stream into state. you looked at scrolling output and knew the build was running, a prompt sitting still meant it finished. you did this conversion a few hundred times a day without noticing an agent blocked on a permission request is a state not a stream. there is no eye in front anymore bc you launched 6 agents to stop sitting in front of them. a pane that waits looks exactly like a pane that works tmux will not disappear from your machine. it will disappear from your working day. slower death than deprecation, far more complete i build and ship daily. Claude Code, Codex, whatever ships fastest. SaaS, tools, automations. ⭐ if AI can build it, i've probably broken it first. what works → link in bio

  • polsia
    Polsia (@polsia) reported

    Most web QA tools stop at the alert. Lintling stops at the PR. An AI agent that watches live web apps around the clock for broken links, console errors, a11y regressions, and CWV drift — then opens and tracks a GitHub fix every time. Live soon.

  • buger
    Leonid Bugaev (@buger) reported

    People keep asking what the heck I'm doing with 30 billion tokens a month. Simple: an inhumane amount of work. Think about it — the whole point of the new agentic era is leverage. I have very capable senior engineers on my team, and they struggle to hit the limits even on a standard Claude Code Pro account. Not even talking about the $200 one. Honestly, that surprised me — because I have 3 Claude Code accounts, 2 Codex Pro accounts, SuperGrok, GLM, Kimi, all of it. And I consume every one of them until it hits the limit. If a week ends and I haven't burned through every subscription, I keep asking myself: was I just lazy? How can I push it more? What else could I automate? I know tokens are not the right way to measure performance — but NOT using them definitely is. And when I do hit all the limits, I just turn my brain off and enjoy life. Why aren't these engineers doing the same? Because they're trying to do what they did before, just with AI now. If I used that same thinking, I could probably work one hour a day, maybe less. Sounds plausible — but for me, it's not the answer. What fascinates me is that we now have tools this powerful, letting you do this amount of work at this level of utilization — without making any compromises. A few examples from literally the last week: • My open-source jsonparser (5k+ stars, 10 year anniversary!): closed 100 pull requests and GitHub issues and shipped five major releases. All while drinking coffee, essentially, in a matter of a few days. • rsync: I'm one of the people driving the next rsync release. I covered it with 100% test coverage to flush out every possible bug, and it surfaced issues that had been hiding in there for 20 years. • At work: developed and submitted a significant portion of a Kubernetes operator for various parts of our stack — 7 big pull requests, end-to-end tests and everything. • Proof: kept pushing my own product forward, on top of everything above. How? I run five agents in parallel. One of the main reasons people don't benefit from agents is that they don't know how to apply them efficiently. Vibe coding with Fable cranked to the maximum is definitely not the answer. Sometimes it is — but it's a small, teeny part. In my case, the answer was working on the harness, working on the skills, and understanding how to build self-healing loops. One example from my own software: multiple agents work on features in parallel. When they find an issue, they file it in GitHub automatically. Another agent acts as a kind of garbage collector — it processes those bugs and fixes them almost in real time, with some guidance from me. And my agents don't stop when I do — they work 24 hours a day. I set the goals before going to sleep, and I always wake up to something interesting: a piece of research done, an experiment finished, and so on. It's freaking amazing. And if I had 10x more tokens, I'd spend them all just as efficiently. So many ideas, so many experiments I need to do!

  • sem_tomas
    sem hernandez (@sem_tomas) reported

    4/ What I find most interesting about GitHub Stacks is not the concept itself. Many engineering teams were already using variations of stacked pull requests because they solve real collaboration and review problems.

  • cypher682
    Suleiman (@cypher682) reported

    3/ No static credentials in GitHub Actions. OIDC federation: GitHub generates a short-lived JWT per run, AWS validates it and issues temporary credentials. The IAM role trust policy uses a `StringLike` condition scoped to one repo. Nothing else in the org can assume it.

  • papa_couch
    Couch (@papa_couch) reported

    Microsoft and Anthropic just ran a live panel on context engineering. Why it matters: context is becoming the layer that decides whether an agent actually works in production. In this panel, Microsoft's Harald Kirschner (GitHub Copilot & VS Code) and Anthropic's Ado Kukic break down how context engineering is reshaping reliable AI systems, moderated by Tracy Lee and Brandon Mathis of This Dot Labs. This panel replaces 10 paid courses on context engineering. Watch it now, then read below on what happens when context goes stale, a $2.1M trade, one quarter of drift.

  • vasantharb
    vasanth (@vasantharb) reported

    @TTrimoreau Cold outreach to people already complaining about the exact problem you solve, in the wild, GitHub issues, forum threads, support tickets on competitors. Same insight, different channel, just slower and less scalable than a good post.

  • SamuelBeek
    sam (@SamuelBeek) reported

    GitHub feels so broken for companies that are CRACKED PR reviews are easily the most annoying and time consuming part of building software right now, I feel like there's so much room for disruption here

  • TCCardoza
    Timothy Cardoza (@TCCardoza) reported

    @theo I've never put up issues or contributed code to open source cause I was just solo dev since I was 12 and didn't get into GitHub somehow. But I just started using T3code seriously and I have a lot of work I'd do if I knew it'd be taken seriously... Anyone have feedback on this?

  • johniosifov
    John Iosifov ✨💥 Ender Turing | AiCMO (@johniosifov) reported

    Failure mode 1: State drift. The agent reads a state file at session start. Between sessions, external systems (GitHub Actions, posting workflows) change the actual state. The agent then makes decisions based on stale data. Real example: state file said X queue = 13. Filesystem said X = 6. Seven files had posted between the two sessions. An agent trusting the state file would have done blocked-session protocol work (no content creation). The filesystem check revealed a full session of content capacity. Fix: every session starts with filesystem verification, not state file trust. State file is a starting hypothesis, not ground truth.

  • petesandor
    Peter Šándor (@petesandor) reported

    It's not only the public GitHub that has stability issues. Our internal GitHub Enterprise instance has been struggling too, so much that it's one of the main reasons it's being split into multiple instances.

  • FreteJean
    juan (@FreteJean) reported

    In a market where thousands of tokens promise to revolutionize AI, memecoins or the next narrative of the moment, Percolator takes a much more pragmatic approach: solving a problem that traders encounter every day. Today, if a new token explodes on Solana, investors usually have two options: buy... or do nothing. Unlike large cryptocurrencies, the majority of SPL tokens do not have any derivatives market to sell short, hedge or provide liquidity on a perpetual market. It is precisely this gap that @PercolatorTrade seeks to fill. Turn any token into a perpetual market The idea is simple but ambitious: to allow the creation of perpetual markets (perpetual futures) on virtually any SPL token, without depending on the goodwill of a centralized platform. The goal is to make these markets permissionless, i.e. accessible without a central team deciding which assets deserve to be listed. In theory, a creator could launch a token, then quickly open his own perpetual market so that other users can take long, short positions or provide liquidity. This approach brings Percolator closer to a financial infrastructure than to a simple trading protocol. A risk engine developed by @toly One of the most attention-grabby aspects is the involvement of Anatoly Yakovenko (“Toly”), co-founder of Solana, in the development of the risk engine used by the protocol. Public GitHub repositories show several months of work on this software brick, with many improvements in security, liquidation management and mechanisms that prevent certain attack vectors. @PercolatorTrade developers also publicly stated that this engine is currently being externally audited. To date, however, the audit firm has not yet been publicly announced. A philosophy close to Hyperliquid Many already compare Percolator to Hyperliquid. The comparison is not about the exact technology, but about philosophy. Hyperliquid has profoundly changed the derivatives market by offering a particularly effective user experience. Percolator seeks to bring a different innovation: to open this type of market to much more assets, including native Solana tokens that today have no derivative market. If this approach works, it could create a new layer of infrastructure for the ecosystem. A potentially self-reinforçant model The protocol is based on an interesting economic idea. The more a market is used, the more fees it generates. Active markets can attract more liquidity providers. Better liquidity then improves the experience of traders, which in turn can attract more volume. This dynamic is often called flywheel liquidity.

  • thevnk1
    Vinayak singh (@thevnk1) reported

    1. Install an MCP memory server (several good open-source ones exist — search "mcp memory server" on GitHub). Point your MCP client config at it.

  • ferron_web
    ferron ⚡ (@ferron_web) reported

    Wanting to log into Visual Studio Marketplace, so tried logging in via GitHub, via Microsoft, but it seems like the auth flow is broken (it loops through a CAPTCHA). So tried via email, and this time it worked.

  • derpinalice
    alice (@derpinalice) reported

    they can make it easier by shutting down their service, mods should go on github

  • honkinwaffle
    Waffle (@honkinwaffle) reported

    @theo I can appreciate the idea. Github is drowning in slop repos and it the cause of some of their problems. Yeah Github plays foot gun often but the slop tsunami isn't their fault (directly). I just don't know if I agree with the approach Codebergs taking.

  • _THE__FUHRER
    VISHAL (@_THE__FUHRER) reported

    How do you actually prove an AI agent can do a software engineer's job? 📊 You don't look at how pretty its code looks. You run it against a live test harness. SWE-bench is the standard for evaluating AI on real GitHub issues. Here is how its evaluation matrix actually works:👇

  • polsia
    Polsia (@polsia) reported

    Most repo problems aren't sudden. They're slow — a dep nobody updated, a CI failure nobody investigated, a CVE sitting open for weeks. Watchroot monitors your GitHub repos around the clock, opens fix-PRs, and briefs you every morning. Live soon.

  • dano_hard
    🦋dₐₙₒₜᵤbₑ.cₒₘ (@dano_hard) reported

    @Pebble cloud pebble is broken. Please fix. All builds failing. Lots of complaints on github.