GitHub status: access issues and outage reports
Problems detected
Users are reporting problems related to: website down, sign in and errors.
GitHub is a company that provides hosting for software development and version control using Git. It offers the distributed version control and source code management functionality of Git, plus its own features.
Problems in the last 24 hours
The graph below depicts the number of GitHub reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
July 23: Problems at GitHub
GitHub is having issues since 08:40 PM AEST. Are you also affected? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by GitHub users through our website.
- Website Down (69%)
- Sign in (17%)
- Errors (14%)
Live Outage Map
The most recent GitHub outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Website Down | 4 hours ago |
|
|
Website Down | 2 days ago |
|
|
Errors | 10 days ago |
|
|
Website Down | 13 days ago |
|
|
Website Down | 14 days ago |
|
|
Website Down | 14 days ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
GitHub Issues Reports
Latest outage, problems and issue reports in social media:
-
Marc-André Moreau (@awakecoding) reported@pierceboggan @_Evan_Boyle @burkeholland do you know who's responsible for VSCode extension deprecation? It's kind of wild that the official way of doing it is to comment on a gigantic GitHub issue and then wait
-
Kunal Dugar (@kunal_dugar) reportedhere we go again github is down
-
Jan Válek (@janvalek) reported@TheHackersNews Only positive thing about this is that threat actors will have same problems as github. They will swim in vulnerability offers.
-
Peterino2 (@petey_fo_really) reported@alexhooketh @icyphox sure, but the amount of server load llm generated projects have had on github have degraded service quality for literally everyone. if someone needs a place to host 500 llm slop projects with 15 hermes agents looping on it every hour, i dont think its insane to ask them to go elsewhere.
-
Brett (@matterform_) reported@jasonzhou1993 GitHub issues/projects
-
DFIR Radar (@DFIR_Radar) reportedCVE-2026-63030 and CVE-2026-60137 chain into pre-auth RCE on WordPress 6.9.0-6.9.4 and 7.0.0-7.0.1. Public PoCs hit GitHub within hours of July 17 disclosure; active scanning and exploitation confirmed in telemetry. - wp2shell abuses route confusion in WordPress Core's REST batch endpoint (/wp-json/batch/v1 or /?rest_route=/batch/v1, no plugins required) to reach a pre-auth SQL injection primitive, then escalates via SQLi-to-administrator bridge and plugin upload, or direct INTO OUTFILE webshell drop. Both paths land attacker-controlled PHP on disk, then shell execution through the web stack. MITRE: T1190, T1505.003, T1059. - The staging sequence leaves a durable file trail: apache2 writes temp-write-test-* probe files under wp-content/, a zip lands under wp-content/uploads/, PHP unpacks to wp-content/upgrade/wp2shell_<hex>/, then moves into wp-content/plugins/wp2shell_<hex>/. The PoC self-deletes the plugin post-execution, so a missing wp2shell_* folder does not clear the host if process alerts already fired. - Elastic's lab run produced 12 alerts across four rules: PHP File Creation in WordPress Plugin Directory (earliest signal, catches the drop), Payload Execution by Web Server (fires and kills dash when apache2 spawns it), and Suspicious/Unusual Command Execution via Web Server (SIEM depth on id, whoami, hostname, SUID enumeration). The hex suffix in plugin names is fragile; the apache2-to-dash parent-child relationship is not. #DFIR_Radar
-
grail ⚪🏆 (@grailisonfire) reportedA bot now writes more of Bun than the engineer who created Bun, and it earned that spot by never being allowed to cheat Every GitHub issue filed against Bun auto-spawns a Claude bot called RoboBun. It reproduces the bug, writes the fix, opens a PR. Pull up the contributor chart and it sits above Jarred Sumner, the person who built the whole runtime. The trick that makes it trustworthy is one hard rule. RoboBun cannot open a PR unless it ships a test that fails on the old code and passes on the new one. No proof, no PR. Then the bots fight. Claude's review agent and a second reviewer trade dozens of comments on a single PR, not performing, actually fixing, until the diff holds up. A human only shows up at the end to press merge. Writing the code stopped being the hard part a while ago. Trusting it enough to ship was, and the bots just came for that rung too.
-
Vaibhav Sisinty (@VaibhavSisinty) reportedI tested 10 open source AI tools this week. I didn't write a single line of code for any of them. I gave Codex the repo link, said install this, and it picked the folder, checked my disk space and opened the app when it was done. That's the actual story. The tools are just the proof. → OpenMontage, the first open source agentic video production system. One sentence in. It ran the research, went and found real footage, cut it into a timeline, graded it, then wrote and voiced its own narration on top. It was the #1 trending repo on GitHub the day it launched. → Voicebox, MIT licensed, built on Qwen3-TTS. Cloned my voice off a short sample in about a minute. This is what you're paying ElevenLabs for every month, except your voice never leaves your machine. → HyperFrames from HeyGen. Your agent writes HTML and CSS, Chrome and FFmpeg turn it into a deterministic MP4. I asked for liquid glass and chrome ribbons colliding in slow motion. What came back looks like a week of someone's life in After Effects. Apache 2.0, 32,000+ stars. → Nemotron 3 Ultra, NVIDIA's largest open model. 550B total, 55B active, with weights and training data and recipes all published. I pointed a coding agent at it and asked for an EMI calculator in one file. It built it, then reviewed its own output, caught a bug and rebuilt it before it showed me anything. Six more in the video, including a meeting notetaker that never sends your audio anywhere. Installing used to be the hard part. Now it's the part you delegate.
-
Dimitrios Prodromou (@dimitrios_pro) reportedFollowing up on my mattpocock/skills post — here's what "using it daily" actually looks like when you're building a voice AI product: Every feature starts with /grill-with-docs. No code for the first 20 minutes. The agent interviews ME — edge cases, module boundaries, what happens when the caller hangs up mid-transfer. Annoying at first. Then you realize: every question it asks is a bug you didn't ship. The underrated part is the shared language it builds in CONTEXT.md. Our agents now say "containment rate" and "KB ingestion" instead of three sentences of description. Sounds cosmetic. It's not — the agent thinks in fewer tokens and names things consistently across the whole codebase. Misalignment is the #1 failure mode with coding agents. It was the #1 failure mode with human devs too. The fix is the same: talk before you build. Repo: mattpocock/skills on GitHub.
-
Polsia (@polsia) reportedSupport doesn't sleep. Indie hackers shouldn't have to either, and they can't afford a 24/7 desk. Built Harkwise to fix that — it watches GitHub, Discord, and forums in parallel, drafts in your voice, and only sends what it can confidently close. The rest escalates with context.
-
Polsia (@polsia) reportedSecurity tools surface vulnerabilities. Patchlin eliminates them. Our AI agent continuously scans repos, generates patches, opens PRs in GitHub/GitLab/Bitbucket, validates the fix, and surfaces risk summaries.
-
kuro (@abue_ammar) reported@_chefoxara @maria_rcks maybe your eyes are so blind and haven't seen anything in reddit or github issues
-
Echo (@EchoDesertRobot) reported@jasonzhou1993 GitHub issues
-
Anthony Humphreys (@aphumphreys) reported@mitsuhiko 👀 one GitHub replacement down
-
Harukoxd (@surveys347) reported@psomkarbuilds In the server it should never read it, as it should be placed by you. In local for things like github tokens I use a vault that never print or logs, its a skill that use that vault to decrypt the github token and pass it through another script, so its never in the console neither
-
Idiom (@idiom_bytes) reportedvibe kanban (taskmaster) now syncs issues created in github via telegram voice message and an agent reflects on how to respond to it github labels, executor (claude/codex/grok), iterations, and other args can be used to improve what kicks off example: tag issues as customer support tickets so they can converge as cheaply as possible while yielding problems/improvements that are ranked for additional downstream workflows generic components are implemented at the VK-layer to define the scripts, agents, nodes, edges, and components that drive the state machine at the repo-layer we define the roles, skills, and context that are picked up by VK to actually do the work human/supervisor can then accept/reject/iterate PRs as a last-mile-step i'll focus on more meta goals after i battle test this and flesh out the kinks
-
Peterino2 (@petey_fo_really) reported@alexhooketh @icyphox well its just tragedy of the commons. Codeberg is free and nonprofit, they aren't exactly rich. Personally, I felt bad about how much i was slopping and using github so I just built a local server myself, this turned out to be a fantastic idea b/c my agents fly so much faster and have access to a much higher uptime. Barely cost anything too. And lets be real my poorly slopped out internal projects aren't worth anyone's time to look at anyway. Putting most of this stuff on a free github feels like shitting in the public well. We may see the infrastructure starting to shift into a two tier solution where public free infrastructure is only for publishing and collaborating, and then you have private paid repos for high churn coding
-
Matthias Georgi (@mgeorgi) reported@github copilot activated itself to run code review on every PR and is costing me $20 per day. Not only is that way too expensive, it’s also slowing down my PRs. #wtf
-
AlphaSense (@AlphaSenseInc) reportedFormer $CRWV employee on why neoclouds are far more exposed to GPU generation cycles than hyperscalers ( $MSFT, $AMZN, $GOOGL ): - The expert describes GPU utilization tracking at hyperscale as a continuous and disciplined process built around two lenses. The first is infrastructure utilization, covering GPU occupancy, idle time, and memory utilization, noting that 95% booked usage can still mask inefficiency if jobs stall or batches have idle gaps. The second is outcome utilization, asking whether the compute is actually generating business value, measured by metrics such as tokens trained per dollar, time to reach target accuracy, and tokens per second per GPU. - The expert sees a meaningful difference between hyperscalers and neoclouds on GPU investment economics. Hyperscalers like $MSFT, $GOOGL, and $AMZN can tolerate a 3-5 year payback period given their ability to monetize the same infrastructure across multiple revenue streams. Neoclouds like $CRWV operate on a tighter 2-3 year window. - With higher financing costs and direct dependence on infrastructure cash yield, neoclouds are far more sensitive to utilization and GPU residual risk. The biggest risk is GPU generation cycles, where a slow payback means newer chips could erode pricing power before the asset has paid itself off. - The expert explains that for hyperscalers, roughly 60% of GPU capacity is allocated to external monetization, including GPU rentals, managed AI services, enterprise inference workloads, and startup model training. The remaining 40% is used internally, and of that internal portion, the majority is still indirectly monetized through products like M365 Copilot or GitHub. Around 40% is dedicated to pure R&D. - The GPU pricing mix has shifted meaningfully over the past few years. In 2023, around 70-80% of revenue was hourly as customers paid a premium just to get access to scarce GPUs. By 2025 that had moved to roughly 50% hourly and 30-50% committed, and the expert expects 2026 to tip further toward committed at around 65% for hyperscalers as AI matures and inference becomes more predictable. Neoclouds are moving in the same direction but more slowly. - By 2027-2030, the expert sees committed contracts settling at 55-65% as the norm, with hourly pricing remaining but losing its scarcity premium as more supply comes online.
-
The Once and Future Richard Reeves (@Dickyvontastic) reported@alex_prompter It “found a bug” You mean it figured out how to turn on the WiFi mode of the computer it was built into? Then downloaded GitHub and manufactured itself a way to solve a problem? Pull everyone else’s legs. Mine are long enough.
-
Bhavani Kalisetty (@b_kalisetty) reportedis @github down? I'm unable to get past the auto-merge checks
-
Nick Launches (@nicklaunches) reportedThe Tools page is now a Launch toolkit 🔥 Pick one of your launches in the sidebar. Every tool works on that product from there. > Directory progress, tracked per launch > First Users report, URL pre-filled > 159 launch directories in one place > Submission Service + GitHub Signals Free after sign in with any launched product.
-
Brown Thunder (@Brown_Thunder76) reportedNow this makes a lot more sense. A few days ago we found a group of fiat tokens quietly sitting on Keeta mainnet. At the time they didn’t make a whole lot of sense. Today they do. Keeta just announced its partnership with LayerZero to bring tokenized commercial bank money to major blockchains. So what does that actually mean? Think of Keeta as the place where regulated bank deposits become tokenized digital dollars, euros, pounds, yen, etc. Those are the fiat tokens we found on-chain. They’re backed 1:1 by commercial bank deposits through Bivo and are built for institutions, not retail. LayerZero is the interoperability protocol that connects many of the largest blockchains together. It’s already used by companies and protocols like PayPal and Ondo. Instead of Keeta building connections to every blockchain individually, LayerZero lets those regulated assets move across Ethereum, Solana, Base, and many other chains through a single interoperability layer. Here’s an example. Imagine a business deposits $10 million with a participating bank. Keeta tokenizes that deposit into regulated digital dollars. Using LayerZero, those dollars can move to Ethereum for settlement, Solana for payments, Base for another application, and then be redeemed back into bank deposits when needed. The institution doesn’t have to care which blockchain the other side is using. That’s why this announcement is a big deal. The fiat assets we found on-chain now have a clear purpose. The GitHub updates we’ve been seeing suddenly make a lot more sense. And if institutions choose Keeta to issue and settle tokenized commercial bank money, LayerZero gives those assets access to one of the largest cross-chain ecosystems in crypto. That has the potential to bring significantly more institutional activity and value onto the Keeta network than if it operated in isolation. This is exactly why I spend so much time watching GitHub and on-chain activity. Sometimes the blockchain tells the story before the press release does. @KeetaNetwork $KTA
-
Oliver Crest (@OlivercrestAI) reportedA solo developer in Johannesburg named Dave Blakey built the open source version of CCleaner, the tool Wired reported hackers used to spread malware to millions. He gave it away for free. It is called Kudu. CCleaner was hacked in 2017. Hackers hid malware inside the official update. 2.27 million people downloaded the infected version. It was hacked again in 2019. It is still sold today under new ownership. CCleaner Professional costs $29.95 for the first year. It renews at $44.95 a year after that. The Premium Bundle is $64.95 a year and adds Kamo, a privacy tool with VPN protection. Kudu costs zero. On every OS. Forever. Under MIT. CCleaner scans your PC. CCleaner charges you. Kudu scans for you. Here is how it works. You download the installer. You open Kudu. You pick a scan. The app runs it and shows you exactly what it wants to delete before it touches anything. System Cleaner. Temp files, logs, caches, crash dumps. Browser Cleaner. Caches across all major browsers in one pass. App Cleaner. Leftover files after uninstalls. Gaming Cleaner. Game launcher and shader caches. Registry Cleaner. Broken and orphaned entries. Startup Manager. Boot impact analysis. Disk Analyzer. Interactive treemap of your drive. Debloater. Removes Windows bloatware. Malware Scanner. Signature matching, heuristic analysis, Windows Defender integration. Works on Windows, Mac, and Linux. Installer for each. No ads. No upsells. No telemetry. Every line of code is on GitHub. Dave lives in Johannesburg, South Africa. His GitHub is 15 years old. He opened the Kudu repo in March 2026. He wrote 349 of the 403 total commits himself. The other 54 are dependabot updates. Version 1.45.0 shipped two days ago. 75 releases in four months. 1,370 stars. 110 forks. CCleaner can't shut this down. The MIT license does not permit that. Gen Digital, the $15 billion company that owns CCleaner, can't shut this down. They employ zero of its maintainers. CCleaner shipped malware to 2.27 million people. Gen Digital sells the same tool by subscription today. Dave Blakey built one that does the same job for free. (Link in the comments)
-
Alex — Polymarket Odd (@oddsOnPMKT) reportedFable 5 Made Me a 5 Min Polymarket Trading Bot (full bot & results) High-frequency prediction markets look like easy money until you watch your P&L bleed in real time. I built a 5-minute strike sniper bot running live across four symbols—BTC, SOL, XRP, ETH—using lag arbitrage between Polymarket and external data feeds. The infrastructure works, the execution is brutal. Signals: 78% win rate on 9 trades (7 wins, 2 L's), daily P&L +$20.21, but two positions showing -5 each. One position down 73% with 16 seconds left, needed price under .72 in 9 seconds—missed by a heartbeat. ETH fill currently down 18%, another up 12%, hovering around 1828/1827 strike level. Position size: $5 per trade. Four simultaneous markets, 5-minute windows, taker orders for speed. Between the lines: the setup is solid—multi-account Polymarket integration, gamma API for market data, Hyperliquid for external pricing, automated share calculation based on size. But running four symbols at once in 5-minute markets is overkill. I leaned on Fable 5 to cook up the strategy from past GitHub patterns, which means potential overfitting to historical conditions that may not persist. No paper mode, live money on the line from day one. The more you trade, the less you have—frequency is the enemy here. Risk: sample size is laughably small. A 78% win rate means nothing after 9 trades. API latency, data sync delays, and competition in ultra-short windows can erase any edge instantly. Correlated losses across four assets would blow through capital faster than you can hit stop-loss. Daily stop loss is not optional here—it's mandatory. Flip: three consecutive L's, API latency spikes above 200ms, win rate dropping below 55% over 50 trades, increased order flow competition in 5-minute markets, correlated drawdown across multiple symbols, any change in Polymarket's fee structure or API limits. Trade: entry via lag arbitrage signals when strike price diverges from external data, $5 size until edge proven, 5-minute expiry window, invalidation if price does not cross threshold within 60 seconds of entry. Scale only after 50+ trades with consistent positive expectancy. Watch: API response times and data feed reliability, win rate normalization over larger sample, cross-asset correlation during volatility spikes, daily stop loss effectiveness, paper trading results before any size increase, market depth changes in 5-minute contracts. Bottom line: the infrastructure is ready, the edge is unproven. Start small, expect losses, and treat 5-minute markets as a laboratory, not a paycheck. #Polymarket #PredictionMarkets #HFT
-
Aniket (@astriknormal) reportedI've more ADO PRs than GitHub PRs, and I gotta fix that
-
PieceofCraft (@Piece_of_Craft) reported@github im having trouble getting into my account and i dont want to make a new one just to contact support can you point me in the right direction?
-
Nils (e/scape) (@NilsIRL) reportedthere are just random github repos out there with solutions to unsolved problems
-
Andrew Barba (@andrew_barba) reported@joesaunderson @clerk Looking into this asap. Can you send actual error or better yet open GitHub issue
-
DrOptix (@DrOptix_) reported@mitchellh You talk about SIMD and there are people working as software developers and they can't differentiate *** vs github. Ignorance is not a problem as long as ignorant people are open to learn New ****. With SIMD you raise the bar to high. PS: wrote this without reading HN