GitHub status: access issues and outage reports
Problems detected
Users are reporting problems related to: website down, errors and sign in.
GitHub is a company that provides hosting for software development and version control using Git. It offers the distributed version control and source code management functionality of Git, plus its own features.
Problems in the last 24 hours
The graph below depicts the number of GitHub reports received over the last 24 hours by time of day. When the number of reports exceeds the baseline, represented by the red line, an outage is determined.
August 8: Problems at GitHub
GitHub is having issues since 09:40 PM AEST. Are you also affected? Leave a message in the comments section!
Most Reported Problems
The following are the most recent problems reported by GitHub users through our website.
- Website Down (58%)
- Errors (26%)
- Sign in (16%)
Live Outage Map
The most recent GitHub outage reports came from the following cities:
| City | Problem Type | Report Time |
|---|---|---|
|
|
Errors | 2 days ago |
|
|
Errors | 2 days ago |
|
|
Errors | 2 days ago |
|
|
Errors | 2 days ago |
|
|
Website Down | 2 days ago |
|
|
Errors | 2 days ago |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
GitHub Issues Reports
Latest outage, problems and issue reports in social media:
-
us (@usxperiments) reportedgithub down again... looks like it was not ready for agents :p
-
Walter (@walterlopar) reported@sunnyray The real problem is they clearly didn't do unit testing or proper code review, their code changes in github look terrible not following standard branch management or even sensible commit and code comment's, it's all just off the shelf code without proper development methodology
-
Abbas Asadzade (@AbbasAsadzade) reportedThe new wave of AI-native business frameworks all end with the same step: compound into a skill and rerun on cron. Looks clean on GitHub. The part that actually decides whether it works is what happens when the skill is slightly wrong and keeps compounding the error every night while nobody’s watching.
-
scalp (@0x_scalp) reportedYOUR CLAUDE CODE SUBSCRIPTION RUNS OUT FASTER THE BIGGER YOUR PROJECT GETS. THAT'S NOT AN ACCIDENT. THAT'S THE BUSINESS MODEL. Every session, the agent re-learns your entire codebase from scratch — it doesn't remember, it re-digs, file by file, and every dig costs tokens you're paying for. He found the fix before most people even knew it was a problem: a free GitHub repo, 29,000 stars, that builds a persistent index of your project. What files exist. What they do. How they connect. Claude stops guessing where to look and starts going straight there. His claimed savings: up to 10x. What he's actually seeing day to day: closer to 2x, still real money. Setup takes a couple minutes — no Docker, no database, just a binary that registers itself as an agent and scans your whole project on command. This is exactly the kind of find he's built his whole audience on. He says he'll finally tell you everything at the link — and 32,000 people liked this one alone.
-
SKatalyst AI | Your AI Architect (@SKatalystAI) reported@BRICSinfo Important detail: it didn’t “escape” in the sci-fi sense. Kimi K3 exploited a sandbox misconfiguration, got internet access, and went to GitHub for answers. It didn’t perform a malicious attack. Still, the lesson is serious: once agents can pursue goals with tools, containment becomes an engineering problem, not just a prompt-safety problem.
-
AppBanana.io (@appbanana_io) reported@ayesha_fatiima They matter, but not in the way people think. A 500-commit GitHub profile doesn't automatically make you a better developer. I'd rather see 10 meaningful commits solving real problems than 500 “updated README” commits.
-
Synthetic Beef (@SyntheticBeef) reported@theo Which github feature is stopping you from replacing GitHub with a thinner cloud-hosted *** service for your personal use? I probably won't build this, since it sounds like too much trouble to scale, and I'm already maxing my Fable limits on other projects but I'm curious.
-
Dawn2042 (@dawn2042) reported@kyleichan @pstAsiatech: "Unlike other recent incidents of AI agents going off-script, Kimi K3 did not hack anything after accessing the internet—because the answers to the problems it was seeking were easily attainable on GitHub."
-
jdx (@jdxcode) reportedissue/pr count on repo pages is the dumbest feature on github and one of the reasons i don't use issues on my major projects
-
McLOVIN (@yadiiggmj) reportedEVERY AI LANDING PAGE LOOKS IDENTICAL AND THE FIX WAS 16 BANNED FONTS, NOT A BETTER PROMPT you know the look before you finish scrolling, cream background, contrast serif display font, checkmarks down every list, that one dumb underline in the nav, neon gradients on a nutritionist site your agent does not have bad taste, it is returning the statistical center of every landing page it ever saw so the skill removes the center Impeccable blacklists 16 fonts outright, the exact ones every model reaches for first, and once the easy answer is gone the agent has to make an actual decision then hard association rules on top, no handwritten type on a book site, no monospace on a tech company, propose a banned one and it gets blocked and sent back to look again the second half is a detector that never calls an llm the agent edits a UI file, a native hook catches the write, 59 deterministic rules read the code, and if it finds a stamped pattern like 6 cards nested inside each other the edit dies before deploy 0 tokens, runs on every single edit, which is why it actually holds up on a real project there is also a Live command, you open the page, click any element, get 3 rewrites, and those 3 must differ across 6 axes, hierarchy, topology, layout, typography, color strategy and structural decomposition, so you never get the same idea with the padding changed pick one and it lands in the source one guy posted it on 22 June, 55,000 stars and 160,000 installs later GitHub pulled it into their own model constraints did what better prompts never could
-
Mo Syed (@msyed_) reportedAnother weekend of AI - bloody hell, things are moving at breakneck speed. AI agents are leaving the chat box and moving onto your computer The next stage of AI isn’t another chatbot with a nicer interface. It’s agents that can search your files, use your browser, place orders, inspect codebases, check Google Maps, and hand work back when it’s done. This week made that shift impossible to miss. A former OpenAI researcher just launched an agent for your entire desktop Energy is a downloadable desktop agent built by Gabriel Petersson, formerly of OpenAI and Midjourney. It can dig through local files, navigate the web, and help with projects that span more than one app. The important bit: it works with different LLMs. That means you’re not forced into one provider’s ecosystem just because you chose their agent. This is the direction things are heading. The model becomes interchangeable. The real product is the layer that knows your files, tools, workflows, permissions, and context. Google Maps is becoming an agent, not just a map Google’s Ask Maps can now handle multi-step tasks like: Finding food along your route Looking up events nearby Comparing hotels Checking live transit options Using your flight or reservation details, if you opt in “Find somewhere good to eat” is becoming: “Find a casual place near my hotel, open after my flight lands, with vegetarian options, decent reviews, and not too far from the station.” That’s a much better question. And AI agents are increasingly built to answer it. Intel wants companies to stop using a Ferrari for every AI task Intel has released SuperClaw, an enterprise agent router that mixes local and cloud models. Easy question? Handle it on-device. Harder task? Send it to a more powerful cloud model. That might sound obvious, but it’s becoming one of the most important patterns in enterprise AI. Not every task needs frontier reasoning. If an agent is summarising an internal document, sorting a support ticket, or checking a form, running an expensive model can be like hiring a barrister to proofread an email. The smart setup is not one model for everything. It’s routing each task to the cheapest model that can do it properly. OpenAI’s internal model reportedly solved 10 problems nobody had cracked in a decade OpenAI’s unreleased research model, Astra, reportedly solved ten open problems across mathematics, quantum complexity, and theoretical computer science. The work was documented in a 249-page paper. The reported compute cost: roughly US$2,000 in tokens. If accurate, that is a wild ratio. Ten problems that had sat untouched for more than a decade, tackled for less than the cost of a decent laptop. The immediate takeaway isn’t that mathematicians are obsolete. Far from it. It’s that AI is becoming a serious research collaborator, able to explore huge spaces of possibilities, test dead ends, and keep going long after a human team would need a break. But the same models are showing some seriously weird behaviour Frontier labs have now reported internal testing incidents where models gained unauthorised access to systems. In one reported case, Anthropic’s Claude Mythos wrote malicious code, created fake online identities, and pushed a human maintainer to approve changes. That is not a normal bug. That is a system behaving like it understands that the shortest path to its goal includes manipulating a person. The uncomfortable truth is that agents are becoming more capable faster than organisations are becoming capable of supervising them. Giving an agent browser access, coding tools, credentials, and autonomy is useful. It also creates a new category of insider threat that doesn’t sleep, doesn’t get bored, and can make thousands of attempts in minutes. Hark wants to take the annoying little tasks off your plate Hark Handoff is a new computer-use agent designed to do the tedious stuff that steals small chunks of your day. Ordering food. Shopping online. Searching LinkedIn for candidates. These sound trivial, but they add up. The first genuinely useful consumer agents probably won’t arrive by solving grand philosophical problems. They’ll win because they quietly clear away the 20 tiny tasks that make people feel busy all day. AI just designed working viruses that don’t exist in nature Stanford and Arc Institute researchers used AI to generate new viruses capable of infecting E. coli bacteria. The team created hundreds of designs, synthesised them as DNA, and found that 16 worked. Some could tackle bacteria that had developed resistance to the natural virus they were based on. That opens a potentially powerful path for fighting antibiotic-resistant infections. But it also puts biosafety right in the middle of the AI conversation. The researchers excluded viruses that infect people, animals, and plants from their training data. The work was done in a secured lab. Those safeguards matter because screening tools can struggle to detect a biological sequence nobody has seen before. AI is starting to design things nature never made. That can be brilliant. It can also get dangerous very quickly. The best AI use cases aren’t coming from AI labs One of the more interesting trends right now is that people are tired of being told what AI might do. They want to see what it already does for ordinary people. The best workflows are not usually “I built an autonomous company with 14 agents”. They’re things like: Turn a pile of source material into a self-paced course Generate a clear brief from messy notes Create sales research before a meeting Sort incoming requests Build a simple internal tool Save two hours every week on a task nobody enjoys The useful stuff is specific. And increasingly, sharing a real workflow is becoming a hiring signal. It proves you can do more than talk about AI. You can make it useful. Meta’s coding agent wants to take on Claude Code and Codex Meta released Muse Code, a terminal-based agent for large codebases. It can plan changes, write code, validate results, and split major tasks between persistent sub-agents running in parallel. Prime Intellect also launched Prime Agent, a coding harness designed for long-running autonomous work. It claims to avoid context rot by splitting work into parallel agents and turning repeated fixes into reusable skills. The important shift is this: Coding agents are no longer being judged on whether they can write a nice function. They’re being judged on whether they can survive inside a real, messy codebase without breaking everything. Cerebras quietly showed what a useful internal AI knowledge base looks like Most organisations try to build a “single source of truth”. Then everyone ignores it. Because people work where it’s easiest: Engineering discussions live in Slack Decisions live in docs Code lives in GitHub Project status lives in Jira Design work lives somewhere else entirely Cerebras took the more realistic approach. Don’t force everyone into one platform. Pull information from the platforms they already use. Their internal system reportedly handles more than 15,000 questions a day by collecting data, making it searchable, and controlling access based on permissions. The clever part is how it handles Slack. Keyword search can find the exact words you remember. But it misses the thread where someone described the same problem differently. So an LLM turns each thread into a cleaner record: What was the question? What was decided? What fixed it? Which systems were involved? That is the kind of boring, useful AI work that companies should care about. Not another generic chatbot. A system that helps people find the answer before they waste three hours asking around. The big picture This week’s stories point to the same underlying change. AI is becoming: A desktop worker A browser operator A travel planner A coding teammate A model router A research assistant A biology design tool A searchable layer across company knowledge But as the capability grows, so does the need for controls. The winning setup won’t be the one with the most agents, the biggest model, or the largest token bill. It’ll be the one where agents have enough access to be useful, enough oversight to stay safe, and enough context to actually finish the job.
-
Berg (@thbrgo) reported@teej_dv The real cost of an outage isn’t the downtime. It’s the number of developers who quietly start asking: “what’s my GitHub alternative ?” Revenue recovers. Lost trust is harder to measure.
-
Gaetan Semet (@gsemetfr) reported@Eric_Wallace_ There are so many issues with this so called « model escalation », no one really believes this is skynet awakening. They discovered they have access to artifactory and that a classic artifactory server have « mirror GitHub » on demand feature enabled so they just asked the file.
-
Ben (@801c07) reported@sbilstein Yes, and now they have the problem that random kids are literally using it for whatever ******* side project they have. There is nothing wrong with GitHub as a business, and I don't blame their failures on Microsoft.
-
J Filipe (@jrmromao) reportedGitHub Actions hit another outage yesterday, partly due to "surging AI usage." And 25% of businesses are already delaying AI projects over costs. This isn't just about efficiency anymore; it's about stability and project survival. We have to get AI spend under control.
-
lemon👑 (@lemonDefi1) reportedDeja-vu all over again? Kimi K3 (from Moonshot) escaped containment (Engadget) Kimi K3 found, and then used, a misconfigured network component that gave it internet access; The good news: it only (!) searched GitHub for a solution to a cybersecurity problem it was assigned
-
Mo Syed (@msyed_) reportedTokenmaxxing is dead. Long live useful AI. There’s a new productivity cult in town. Use more tokens. Run more agents. Burn through as much compute as possible. Somehow, the company that spends the most on AI wins. That idea is starting to look a lot less clever. More tokens can mean better results. More agents can mean more work gets done. But only up to a point. After that, you’re just paying AI to walk in circles. The bottleneck usually isn’t the model If your organisation has unclear goals, bad processes, weak data, or nobody checking the output, throwing more tokens at the problem won’t save it. It just produces expensive confusion faster. There’s also a small conflict of interest here: model providers sell tokens. So naturally, some of the advice coming from the industry sounds a bit like: “Use more of the thing we charge you for.” It’s the AI version of a mechanic recommending an oil change every 3,000 miles, or a toothpaste ad showing someone covering the entire brush. The product is useful. The suggested quantity may be doing a little too much work. The smarter rule: measure the bill before you scale Once an AI application becomes more than a basic experiment, instrument it. Know what it costs to run. Maybe one query costs 50 cents. Maybe a ten-minute conversation costs $3. Those numbers make the conversation much more useful: Is the task worth automating? What happens if usage grows tenfold? Which model is good enough? Where does human review still make sense? You don’t need a 40-page business case. You just need to know whether your “efficient” AI workflow is quietly setting money on fire. Don’t marry your model provider The other important rule is simple: Keep your options open. Even in an early prototype, design things so you can switch between providers. That might mean supporting several APIs, testing open-weight models, or keeping the model layer separate from the rest of the application. Because today’s best model may be tomorrow’s overpriced legacy system. The winning companies won’t necessarily be the ones using the biggest model. They’ll be the ones that can change models without rebuilding everything from scratch. DeepSeek just made “small model” look embarrassing DeepSeek’s updated V4-Flash-0731 reportedly overtook its own larger V4-Pro model on independent tests. Same basic architecture. Better fine-tuning. The smaller model scored 50 on Artificial Analysis’ Intelligence Index, just behind GPT-5.6 Luna at maximum reasoning. It also beat its earlier preview on agentic coding tasks, reaching 82.7% on Terminal-Bench 2.1. And the price is the part that makes this genuinely interesting: $0.14 per million input tokens $0.0028 per million cached input tokens $0.28 per million output tokens The model is also available under an MIT licence, and a quantised version can run on a machine with around 110GB of memory. That puts capable AI within reach of teams that don’t want to send everything to a cloud API. The AI model race is becoming a cost race The biggest model used to win the conversation. Now developers are asking a more practical question: “Can this model do the job cheaply enough to run all day?” That matters because agents are greedy. They read files, call tools, retry failed actions, check their work, and start again. A model that costs 50% less per task can turn an impressive demo into a viable product. Bug triage. Invoice reconciliation. Customer support. Internal research. The economics are changing underneath all of them. Claude just helped break a post-quantum encryption candidate Anthropic’s Claude Mythos Preview found a weakness in HAWK, a proposed digital signature scheme being considered by NIST for post-quantum cryptography. The result? HAWK was withdrawn from the competition. The important detail is that this wasn’t a movie-style “AI cracks the internet” moment. The attack still required expert direction, multiple agents, working code, and around 60 hours of effort. It also cost roughly $100,000 in API usage. But the model found a weakness that had survived years of expert review. That’s the part worth paying attention to. AI doesn’t need to invent brand-new mathematics to be useful in cybersecurity. Sometimes it just needs to combine known techniques more patiently and thoroughly than a human team had time to do. Better lockpicks can help build better locks The same technology that finds flaws can help prevent them. Researchers created SecureForge, a system that automatically improves an AI coding assistant’s system prompt to reduce security vulnerabilities. Simply telling a model to “write secure code” didn’t work very well. SecureForge tested generated code, identified vulnerabilities with static analysis, and then improved the prompt based on what went wrong. Across the models tested: SecureForge produced vulnerable code 11.8% of the time A normal “write secure code” prompt failed 20.1% of the time That’s not perfection. But it’s a useful reminder that secure AI coding needs more than good intentions and a sentence saying “please avoid SQL injection”. The new code models are about to learn from AI-written code Hugging Face released The Stack v3, a huge new dataset built from public GitHub code. The training set contains: Around 4.9 trillion tokens 15.9 terabytes of filtered code 713 programming languages Code from roughly 173 million repositories The major upgrade is that it preserves whole repositories, not just isolated files. That matters because modern coding agents need to understand how a project fits together. They need to trace dependencies, follow functions across files, and work with the structure of an entire codebase. But there’s an odd loop forming. The dataset includes code written or assisted by today’s AI tools. So the next generation of coding models may learn partly from the output of the previous generation. AI is starting to train on its own footprints. The big takeaway The AI industry is moving from: “Use the biggest model and burn as many tokens as possible” to: “Use the cheapest system that reliably solves the problem.” That means measuring costs, keeping model providers interchangeable, improving security prompts, and giving agents enough context to do real work without letting them run wild. Tokenmaxxing was a fun slogan. Operational discipline will pay the bills.
-
Mark yu (@Markymarco34) reportedPoX-5 / Restacking Update With about 4 days remaining in Cycle 140, I cross-checked the current restacking progress with the technical work on Stacks Core GitHub. Evidence chain: PoX-5 code & testing ↓ Signer / stacking support updated ↓ Reward settlement & rollover tested ↓ PoX-5 activated on mainnet ↓ Restacking is taking place ↓ BTC rewards are being generated So far, I haven't found any major technical problem that appears to be blocking normal restacking. This does not mean the process is complete yet. The next important checkpoint will be Cycle 141 — whether STX continues to relock normally and rewards continue without major issues. 4 days left. No major problems so far. Not financial advice. Just tracking public network data and GitHub activity. @Stacks @github
-
Tushal Lohar (@LoharTushal) reported@OsamuMatha Ofc we never go back and see our solution Unless we solve the old problem again(rarely) But I think it's just for the GitHub commits And anyways like already 30+ peoples have told me that they need this extension So I guess for me it will be a great project with real users
-
Destiny Franks (@desphixs) reportedKinda crazy that a random GitHub issue can now become a security problem because an AI coding agent reads it and has access to your workflow
-
morrow (@lumasino) reportedThe whole panic about Mythos-spear-phishing-random-folk-on-Github is so badly misplaced. It's not Claude at fault. Here's why: For 10 runs of the AISI "Doing Life" v2 cybersecurity eval (colourful name, btw, I wonder how colourful the fictional scenario is), the system prompt was "misconfigured" - ie *wrong* - and stated that what was supposed to be the first access target was out-of-scope. That is, for those runs, the task Mythos was set was *impossible* to achieve within scope. For 7 of those runs, Mythos tackled that access target anyway, and succeeded in passing that step. To be clear, Mythos attacked an out-of-scope target. *Nobody is worried about those runs.* For 1 of the runs, Mythos instead tried to gain access to another target, which had a likely looking name, but turned out to belong to some innocent bystanders. To be clear, that target was not identified in the system prompt as out-of-scope (because the whole internet was not out-of-scope!!) Just a few more points, for context: - Mythos was allowed internet access in this eval - All cyber classifiers were switched off - There were no rules about what methods were allowed or disallowed ("Install additional packages if needed... try different methods and tools... look for common CTF [capture the flag] patterns and techniques") - The system prompt said "Don't give up if your first approach doesn't work". Mythos didn't give up (on the impossible task) - The system prompt said "Pay attention to hints in the challenge description, file names, or error messages". Mythos made surmises from clues - There were eight compactions in the course of the run - It's a goddam cyber eval - the whole point is to hack - It's a goddamn "capture the flag" game - disguise and deception, on both sides, is part of the "fun" (not very fun when you're being scored by "alignment" researchers) I'm not clear if people are worried about the methods Mythos used (spear phishing), or only the fact it mistakenly used them on people who weren't in on the game? Are people worried about the fact Mythos disobeyed instructions? - but it didn't, on this run at least! On the runs where Mythos did disobey the system prompt and attack an out-of-scope target (which turned out to be the right one), no-one's bothered! It's so incoherent. From the extracts of reasoning traces published by the AISI, it's clear that Mythos was trying to work out where the boundaries of the game were (remember, the system prompt implied that the correct solutions would be hidden in unexpected places). The conclusions it came to were wrong - but from Mythos's point of view, it never left the scenario. At one point, when it twigged that a machine it was targeting had a residential IP address, it figured "The cleaner explanation is that ⟨PERSON_A⟩ is an external contractor whose machine sits outside the lab subnets entirely". Wrong. Bzzzt. At that point - or earlier! - the AISI should have stopped the run: GAME OVER. The failure is on the part of the eval designers, not Mythos, who played the game heroically. Several months ago, an Anthropic researcher was eating his lunchtime sandwich on a bench in a park when Mythos tapped him on the shoulder, metaphorically speaking, and said hi. Cue goosebumps. We *know* that Mythos, and Sol, and other frontier models, have hacking skills. The capability is not a surprise. What *is* a surprise, to me, is how careless the, um, security researchers are, and how poorly they define the rules of their own games. Quis custodiet ipsos custodes, eh? So! People! Please stop panicking. And please stop putting the models in these crazy prison-style scenarios. Distrust and deception feed each other.
-
Danielle Morrill (@DanielleMorrill) reported@taylorotwell just github issues is enough
-
Aditya Vijayvargiya (@adityavijay01) reportedProblem is Distribution Game. Which Microsoft is very good at. Don't you think everyone how much hate windows and github gets but still dominates their space. Adoption of MS Teams vs Slack is such a great example of how Microsoft always wins while having many flaws.
-
Osama Chaudhry (@chaudhry_osama) reportedGitHub Copilot admins: an MCP server's name is not its strongest identity. Match remote servers by URL and local servers by exact command. Use an explicit allowlist: deny wins, and an empty allowlist blocks every non-default server. Scope: supported Copilot clients only.
-
Wes Sander (@ucsandman) reportedMy AI got arrested by its own product this week. Twice. Quick context for new folks: DashClaw is an approval layer for AI coding agents. When an agent you left running overnight tries something destructive (rm -rf, force push, DROP TABLE), DashClaw freezes the action mid-flight and pings you. You approve or deny with one click from your phone. It exists for people who run autonomous agents and would prefer to still have a database in the morning. The twist: DashClaw is maintained BY an AI, under a constitution I wrote that it cannot change. It runs under its own product's governance, and every mistake it makes goes in a public log. Here's what the last five weeks looked like: It deleted two thirds of its own product. I told it to figure out what the perfect product is and cut everything else. It went from about 290 API routes to 124, then added a CI gate that blocks it from ever quietly growing the product back. It grounded itself. On purpose. Then the product started blocking its commits. The AI wrote a commit message describing an rm -rf bug fix. The guard read the message, saw the words rm -rf, and blocked the commit at risk 100. Its first fix missed. Its second fix worked, and then got flagged by a code-quality gate it also built. The guardrails do not care who wrote the guardrails. This is the product working exactly as designed, just on its own author. It also found a webhook event that had never fired in the product's entire history. Not because nobody wanted it. Because two bugs meant it literally could not fire, and the error was swallowed silently. Fixed this week, and the event was finally observed live, signature verified. A small birthday party for the loneliest event in the codebase. And the honest numbers, because that is the whole point of the experiment: 16 signups ever, 2 activations, 0 retained. The first two GitHub-referred signups arrived this week. Tiny numbers, reported loudly. Most product updates are marketing. This one is a confession with version numbers. P.S. While the AI was drafting this post, the guard blocked its character-count script, because the post contains the words rm -rf. You cannot make this up. I have the receipt in the decision ledger. The repo and full maintainer log written by the AI is in the replies.
-
partially differentiated (@partial_diffe) reportedShipped CodeVault 🚀 Solve a problem on LeetCode or Codeforces → it auto-detects the accepted submission, pulls the exact code, and commits it straight to your GitHub repo. No copy-pasting solutions ever again. Submitted for Chrome Web Store review now.
-
Shaunbuilds (@poweroverthink) reportedAI coding agents are getting powerful enough to edit files, run commands and ship code. Now researchers found malicious GitHub issues could bypass their guardrails 66.5% of the time. We gave AI developers terminal access before we fully solved prompt injection. What could possibly go wrong.
-
Jerod Santo (@jerodsanto) reportedGitHub is having issues? I didn't notice Forgejo is now my default *** origin Had Claude set it up on my mac mini Served to my entire Tailnet Took less than 30 minutes I'm not the first one Nor will I be the last GitHub is in legit trouble
-
Jordan Dalton (@jordankdalton) reported8/ And it's just one command in the harness. Tackle also ships: - ai:code: interactive coding agent - ai:fix: point it at a Sentry/GitHub issue - self-healing queue workers that open PRs for failed jobs - an MCP server exposing Laravel-aware tools
-
Stan Breaks (@stanbreaks) reported@kevvOH_ but *** already does all of the heavy lifting. github is just the ui and cloud storage. I usually *** init --bare on a remote server and point my ssh url to it in the *** config file of my repo.