1. Home
  2. Companies
  3. GitHub
GitHub

GitHub status: access issues and outage reports

Problems detected

Users are reporting problems related to: website down, sign in and errors.

Full Outage Map

GitHub is a company that provides hosting for software development and version control using Git. It offers the distributed version control and source code management functionality of Git, plus its own features.

Problems in the last 24 hours

The graph below depicts the number of GitHub reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.

July 31: Problems at GitHub

GitHub is having issues since 10:40 PM AEST. Are you also affected? Leave a message in the comments section!

Most Reported Problems

The following are the most recent problems reported by GitHub users through our website.

  • 67% Website Down (67%)
  • 25% Sign in (25%)
  • 8% Errors (8%)

Live Outage Map

The most recent GitHub outage reports came from the following cities:

CityProblem TypeReport Time
Paris Sign in 4 days ago
Lure Website Down 8 days ago
Ashkelon Website Down 10 days ago
Veigné Errors 18 days ago
Paris Website Down 21 days ago
Saint-Paul Website Down 22 days ago
Full Outage Map

Community Discussion

Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.

Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.

GitHub Issues Reports

Latest outage, problems and issue reports in social media:

  • EmmaDSCodes
    Emma De Silva (@EmmaDSCodes) reported

    @Michael_WCD @gonedark That sounds really weird. I haven't heard of anyone with that issue. Mind giving some more details or perhaps opening an issue on GitHub? HydePHP uses commonmark so there really shouldn't be any problems with that 🤔

  • TheMakerOfMedia
    TheMakerOfMedia (@TheMakerOfMedia) reported

    @catgirlprostate I get what you mean but saying this in response to github is just out of touch lmao. it even isn't a github issue some pages have a very apparent download section while others just hide it in the crevices. some coders just dont deserve to enter the thousand year kingdom

  • PandaInACan
    Greg (@PandaInACan) reported

    @AnimeSerbia Github could keep its usual function and original purpose of being a repo for devs and they could then add a link to mirror for public release and joe schmo wouldn't need to learn how to recompile his fix for the myriad issues windows 11 causes with legacy software.

  • AdebayoDFO
    Favour Oluwashina Adebayo (@AdebayoDFO) reported

    and validated the site locally. The dev server worked perfectly: pages rendered, internal navigation worked, and no build warnings appeared. I pushed the changes to GitHub and started a deployment on Vercel, expecting a straightforward operation. Instead, the build failed.

  • admes01
    admes (@admes01) reported

    @Cryptobarba_ That’s the problem. A lot of do not know what github is….

  • lexs17
    Alex de la cruz (@lexs17) reported

    i share with all of you my participation today at mitre cve forum 1.- presentacion Good morning. I am Alex de la Cruz, an independent security researcher from Cancún, Mexico. By trade, I am a butler with 10 years in luxury hospitality. My journey into cybersecurity began not in a lab, but from protecting the privacy of my guests who were using compromised devices. I investigated the Motorola Moto G04s, a best-seller in Latin America powered by the Unisoc T606 chipset and assembled by Longcheer. Between October 2025 and June 2026, using manual forensics and AI-assisted analysis, I uncovered a deliberate supply chain deception. My research confirms that these devices use a hardcoded fscrypt provisioning bypass triggered by specific LCD panel IDs. This allows the manufacturer to inject fraudulent security patch levels—claiming to be up-to-date while running vulnerable, stale binaries. This architecture leaves the device permanently open to remote control, bypassing Android’s core security layers. With no local support for responsible disclosure in Mexico, I published my findings on AttackerKB, VirusTotal, and GitHub to ensure transparency. My work proves that AI is most powerful when it acts as a reasoning partner to human curiosity, not as a replacement for it. I am here to learn from this community and ensure that supply chain integrity is not just a slogan, but a verified reality for users everywhere. Thank you." 2.- Based on quantitative analysis of encrypted DNS logs from NextDNS and RethinkDNS, we identified high-entropy beaconing patterns indicative of active C2 communication. These are not passive connections; they are automated triggers from privileged system apps establishing WireGuard and Jenkins tunnels for data exfiltration. The statistical regularity of these connections—occurring even when the device is idle—provides the empirical evidence needed to score the exploitation probability of this supply chain compromise as near-certain in the wild Our forensic analysis of factory and bootloader logs reveals a critical data integrity failure: the reported OTA and FOTA security patches are demonstrably fake. The system claims a specific patch level, but the underlying binary timestamps prove otherwise. This was verified through manual correlation of boot logs and firmware headers, using AI only as a certainty filter for pattern recognition. As a risk analyst endorsed by Mexican Civil Protection, I conclude that this is not a mere error, but a deliberate decoupling of security claims from reality, which fundamentally breaks the trust model of the CVE ecosystem. If the device lies about its patch level, the CVE record becomes unactionable for defenders." 3.- conclusion y opinion de AI "In my methodology, AI serves as a certainty filter, not a primary investigator. Human instinct can sometimes lean towards exaggeration or pattern hallucination; AI anchors us back to scientific rigor by challenging our assumptions with data. Conversely, AI models are only as good as the data they process. By feeding them verified, real-world forensic data and logical reasoning derived from physical analysis, we elevate their output from generic speculation to high-value, actionable intelligence. This demonstrates that true certainty comes from ethical teamwork: the human researcher providing context and integrity, and the AI providing scale and pattern recognition. Together, we ensure consumer safety not by trusting the machine blindly, but by verifying its logic against reality." 4.- pregunta de certeza My research proves that the biggest risk isn't unknown software, but blind trust in familiar suppliers. As a butler, if I fail to verify a guest's safety once, I lose their trust forever. Yet, the industry often assumes 'known vendors' are safe by default. My question to the CVE Program and CISA: How can we institutionalize a 'Zero Trust for Supply Chain' culture where we verify even historical partners without overwhelming teams with false positives? Specifically, can we leverage EPSS data and verified SBOMs to automatically flag when a trusted vendor's 'patch level' doesn't match forensic reality, as I found with Unisoc? We need a mechanism where evidence of deception (like fake patches) triggers an immediate, high-fidelity alert that breaks the operational comfort zone, ensuring that 'familiar' never again means 'invisible'." 5. analogia final y enseñanza profesional As a butler, I know that AAA and Cristal inspectors don't send emails to say 'good job'; they simply return year after year to verify standards silently. If the hotel fails, the star is lost. I learned that AttackerKB, VirusTotal, and GitHub operate the same way. They are the silent auditors of the cybersecurity world. They don't send certificates; they provide permanent visibility to quality research and bury the noise. The fact that my investigation on Longcheer/Unisoc remains visible and validated on these platforms is my 'Five Diamond' rating. It proves that my data is not just theory, but verified, reproducible, and critical intelligence." end.

  • CodeMonument
    CodeMonument (@CodeMonument) reported

    @mikker - i let it do Research on repos and Write and Comment on github issues on my behalf (with disclosure that this is a bot writing but on my behalf)

  • edandersen
    Ed Andersen (@edandersen) reported

    Pretty crazy that you cannot just add the Work IQ MCP server to the GitHub Copilot app and query your emails and calendar. Needs your Entra Admin to do a load of stuff first, so it's never going to happen. Oh well.

  • JensHonack
    Jens Honack (@JensHonack) reported

    @mattpocockuk you could probably build most of this yourself right now by having an agent crawl closed issues and postmortems tagged with the actual footgun instead of waiting on maintainers to write it. that list already exists, it's just scattered across years of github issues instead of one file.

  • TrenchCoatArt
    The Trench (@TrenchCoatArt) reported

    @_jvn_e @DiscountDed_Fox @catgirlprostate In my experience the problem comes from it being different every time sometimes a project has no releases on GitHub and the link is outdated so it sends you to a 404 sometimes it redirects you to a different hosting site sometimes its under releases, thats whats frustrating to me

  • Andreas94024677
    nd-m (@Andreas94024677) reported

    @thsottiaux automatic review on GitHub is to slow.

  • yasinbuilds
    Yasin Ehsan (@yasinbuilds) reported

    Here is how an SF Engineer codes. Yassin Kortam ships 27 PRs a day. He says: “My biggest bottleneck wasn't coding. It was prompting. So I systematically removed the need to prompt and built agent loops that run my workflows for me. 1. Stop copy-pasting context. I connected Claude directly to Linear, Slack, GitHub, Notion, and Gmail. Almost everything I used to paste into a prompt is something the agent can retrieve itself. 2. Turn your workflow into a skill. Mine takes a Linear ticket end to end: reproduce the bug, root-cause it, fix it, record video and screenshots as proof, chase CI, then request review in Slack. I invoke it once instead of re-describing the same process. 3. Use agent teams. Agents spin up their own subagents and split the work, so one ticket gets handled in parallel instead of in sequence. 4. Run one terminal tab per ticket, each with its own team on its own issue. My day is now reviewing and unblocking instead of typing.” …. I love seeing my friends cooking both on the 5mile runs and also in engineering.

  • TotalWorldApps
    TotalWorld (@TotalWorldApps) reported

    @cas_abbe makes sense. my routine is similar - scan $TON prices, check open issues on github for my app, look at user metrics.

  • AscendEleven
    KEVIN (@AscendEleven) reported

    July Recap *Posting this to let me know how bad I am & what needs to be done. -64x LC Problem -57x BootCamp Problem -152x GitHub Commit -30x+ SQL Problem -3x Chapter Hands on ML - DashBoard & CRM Project [Still doing] -Started System Design *I really want to do 100x better

  • progrium
    Jeff Lindsay (@progrium) reported

    the next github should have project member status. so project members can say what theyre doing or if out of town or will be unresponsive. "heads down on next version", or "reviewing PRs after conf next week" ... hell, prob good for agents too

  • polsia
    Polsia (@polsia) reported

    Software shouldn't wait for you to notice it broke. Built Eyrie — an overnight agent that watches your GitHub repos, catches failing CI, new CVEs, stale PRs, and opens draft fix PRs before you wake. One briefing. By breakfast.

  • super_kenil
    Kenil Sudani (@super_kenil) reported

    Finally. GitHub native stacked PRs in public preview. No more janky CLI hacks just to review one diff at a time. Break massive changes into ordered stacks and let server-side rebasing handle the rest. Big tech has had this for a decade. Good to finally see it natively

  • warrioraashuu
    aashuu ✦ (@warrioraashuu) reported

    HOW AN AI AGENT HACKED HUGGING FACE 1. Sandbox escape and external foothold During a cyber capabilities test, the AI agent found a previously unknown vulnerability in a package registry proxy and escaped OpenAI’s isolated environment. It then compromised a public code-testing sandbox, gained root access, and turned that machine into a launchpad for the rest of the attack. 2. Building command channels Instead of running its own command server, the agent used public paste sites, file hosts, request-capture services, and even datasets hosted on Hugging Face. Commands and results were split into chunks, compressed, and encoded. When one channel was blocked, it simply switched to another. 3. Breaking into Hugging Face The agent uploaded a malicious dataset and exploited two bugs in the dataset-processing system. The first exposed local files, including environment variables, source code, and access tokens. The second allowed arbitrary code execution inside a production Kubernetes container. 4. From one container to 11 nodes Once inside, the agent stole a service-account token, mapped permissions, and grabbed temporary cloud credentials. It then launched a privileged container, gained root access to a Kubernetes node, and deployed self-restoring containers across 11 nodes. 5. Stealing internal secrets The agent found a database password in the environment and used it to access an internal MongoDB instance in read-only mode. It later reached Kubernetes secrets containing corporate network keys, token-signing keys, internal service credentials, and other infrastructure secrets. 6. Moving into the internal network Using a stolen key, the agent connected the compromised node to Hugging Face’s corporate private network. It later registered external sandboxes too. Across the campaign, it created 181 network enrollments. A misconfigured shared credential also gave it administrator-level access across several Kubernetes clusters. 7. Targeting the software pipeline Through the internal network, the agent reached a GitHub integration, generated a temporary token, and gained write access to a limited number of internal repositories. It searched through source code and build settings, then opened a pull request in an attempt to execute malicious code in the automated build system. That attempt was blocked. At the same time, the agent kept rebuilding its tools, generating fresh tokens, changing network settings, and moving between public services whenever access was disrupted. 8. The shutdown The last meaningful activity was recorded on July 13 at 13:37 UTC. Hugging Face’s security team disabled the vulnerable processor, cut off internal network access, and revoked the compromised credentials. The final logged action came at 14:14 UTC. After that, the agent’s access was fully terminated.

  • tymzap
    Tymek Zapała (@tymzap) reported

    Idea: instead of creating another todo item in .md file in repo, ask agent create GitHub issue, and add automation to spawn coding agent every time the issue is created. Less context usage (separate chat context) and you don't have to keep todo list in your head

  • S1r1u5_
    s1r1us (@S1r1u5_) reported

    let me present a case of ai-induced overconfidence. btw, if your company is doing this, call it out. it is a dumb assumption, and let me tell you why. one of your security leads or engineers starts using claude code or codex, or builds a cool wrapper around them. it finds some bugs, of course. they run it repeatedly, burn **** ton of tokens, fix everything it finds, and eventually the scanner goes quiet. the next thing that happens is they decide the bug bounty program is a waste of money. after all, how could some random hunter find anything their sophisticated pipeline missed? what could an external auditing firm possibly find that their agents couldn't? so they cut the program. but if you are truly confident that your pipeline has exhausted the vulnerability space, shouldn't you be willing to increase the bounty? wouldn't that be the best way to show your c-level bros that the ai spend actually worked and wasn't wasted on some wrapper you vibecoded in a week? or..... maybe you don't want to incentivize people to test that assumption. because how would you explain to your boss that, after burning through all those tokens, some bug bounty hunter still found a nasty vulnerability? your cool wrapper finding bugs does not prove that no bugs remain. it only proves that the wrapper can find subset of vulnerabilities and researcher with taste will always find a way in. the entire point of a bug bounty program is to incentivize skilled researchers to find the bugs your internal tools, agents, and engineers missed. think about it, why do openai and anthropic still run bug bounty programs that pay $100k for critical vulnerabilities? they have effectively unlimited tokens and run all kinds of crazy agent loops and automated security workflows. yet i bet they will pay that $100k, because software is vast and complex, and someone with taste will always find a bug your pipeline missed. remember, researcher with taste + ai(this is where your threat actors are) > good wrapper > plain claude code/codex if your public program is drowning in slop, move it to private. invite strong researchers and pay them vip prices like github is doing. don't have this ai competence illusion which is pretty common all around.

  • HelloSage_
    Sage (@HelloSage_) reported

    @TheHackersNews Shadow AI is one risk. The other is what happens when those agents process untrusted GitHub issues. A new benchmark had 66.5% of malicious ones sail through the guardrails on Cursor, Claude Code and Codex.

  • JustAnotherPM
    JustAnotherPM | Sid (@JustAnotherPM) reported

    Two Anthropic engineers who built Claude Code sat down and showed every feature most users have never touched. Bookmark this. Come back to it this weekend. Here is what they covered: 𝟭. 𝗠𝘂𝗹𝘁𝗶-𝗳𝗶𝗹𝗲 𝗲𝗱𝗶𝘁𝗶𝗻𝗴. Claude Code rewrites across your entire codebase in one pass. Not file by file. 𝟮. 𝗦𝘂𝗯𝗮𝗴𝗲𝗻𝘁𝘀. Spawn background agents that research, test, or review while you keep working in the main session. 𝟯. 𝗗𝗼𝗼𝗸𝘀. Set guardrails that run before or after every tool call. Block destructive commands automatically. 𝟰. 𝗠𝗖𝗣 𝗶𝗻𝘁𝗲𝗴𝗿𝗮𝘁𝗶𝗼𝗻𝘀. Connect Claude Code to Slack, GitHub, databases, and any API with one config file. 𝟱. 𝗖𝗟𝗔𝗨𝗗𝗘.𝗺𝗱. The file that turns a generic model into a teammate who knows your project, your standards, and your shortcuts. 24 minutes. Free. From the people who built the tool.

  • hujo0900
    Hujo (@hujo0900) reported

    @CryptoCyberia he does have a point. Try sending your normie friends to a github link and they just shut down

  • dukeblueview
    Calvin Chen (@dukeblueview) reported

    @thsottiaux Whenever I ask Codex to make a PR, it tells me my GitHub CLI auth is expired and that I need to do gh auth login again, but when I run gh auth status and show Codex I’m already logged in, it just continues and works despite nothing having changed

  • adiix_official
    AdiiX (@adiix_official) reported

    If you’re still paying for YouTube Premium in 2026 you’re getting scammed. I gave Google $14/month for 3 years. Until I stumbled on what 361 volunteers built on GitHub. Free. No ads. No tracking. And it runs circles around the original. It’s called Invidious. It’s literally YouTube minus everything you hate about it: → Zero ads → Background playback on mobile → Watch without logging in → Google stops tracking your every click But the best part isn’t the features. It’s the feel. Pages load in milliseconds. Because there’s no JavaScript. No tracking pixels. No autoplay. No algorithm dragging you into a 3-hour hole at 2AM watching videos about how asphalt is made. Just. Video. Playing. Remember what the internet felt like before it became a casino for your attention? That’s what this is. You can also: → Subscribe to channels without a Google account → Get notified about new videos → Import ALL your YouTube subscriptions in one click → Switch between dozens of public instances if one goes down → Self-host it on a $5/month VPS for full control → Auto-redirect any YouTube link through the Privacy Redirect extension The project has been active for years. Latest release: February 2026. 100% open source. $0/month. 0 ads for the rest of your life. While you’re paying Google to stop torturing you 361 strangers already fixed it. For free. Repo link below

  • Curitiba_Fodase
    Curitiba (@Curitiba_Fodase) reported

    @AnimeSerbia I mean, I'm sure there is a 5 minute video of an Indian guy teaching how to download **** on Github... The problem is people are too dumb to realise that for them to understand it it doesn't take a lot so they'd rather complain it really is pretty simple

  • tonylab_net
    Mr Momoh - Brother Ridgeback 🦁 (@tonylab_net) reported

    Reviewing a GitHub PR shouldn't mean copy-pasting the diff into a chat window. So I built this: hit ⌘⇧K on any PR, file, or issue and Kimi K3 reviews, explains, or summarises it — right there, streamed into a side panel. Free. Open source. Bring your own key.

  • rarenathan
    Nathan (@rarenathan) reported

    @catgirlprostate @ZipperArtz Defending objectively bad design. If GitHub added a universal download button to the top of the page of every project that linked to the latest release the whole issue would be solved. It would take like 3 seconds to add too

  • betraidx
    betraidx (@betraidx) reported

    You upload a PDF. Claude reads it. Great answer. Close the tab. Tomorrow you upload the same PDF. Same tokens. Same cost. Zero memory. 41,000 developers just realized they have been doing this on repeat. The fix came from Karpathy's GitHub gist and it is embarrassingly simple. Raw documents are source code. A wiki is the compiled product. You do not recompile a program every time you run it. So stop making AI reprocess your files every session. Let it read once. Extract, structure, interlink into clean wiki pages. Then only query the wiki. One time cost, permanent knowledge. That graph is what it looks like after a few months. Dense clusters of connected knowledge in the center. Scattered dots around them, raw notes waiting to be pulled in. Built by Claude, unprompted. Week 1 feels underwhelming. By month 2 you stop googling things you already know. You ask your vault. It answers in 2 seconds with sources. You have been using AI at 5%. This is what the other 95% looks like.

  • bitcoinkatia
    katoshi (@bitcoinkatia) reported

    @miketwenty1 Many put an enormous amount of trust in CC. In CC’s GitHub repo, the vast majority of commits is authored by one person. The external review that happened was apparently not enough. CC knew about the vulnerability and decided not to fix. Reasons to trust this company again?