1. Home
  2. Companies
  3. GitHub
  4. Outage Map
GitHub

GitHub Outage Map

The map below depicts the most recent cities worldwide where GitHub users have reported problems and outages. If you are having an issue with GitHub, make sure to submit a report below

Loading map, please wait...

The heatmap above shows where the most recent user-submitted and social media reports are geographically clustered. The density of these reports is depicted by the color scale as shown below.

GitHub users affected:

Less
More
Check Current Status

GitHub is a company that provides hosting for software development and version control using Git. It offers the distributed version control and source code management functionality of Git, plus its own features.

Most Affected Locations

Outage reports and issues in the past 15 days originated from:

Location Reports
Lure, Bourgogne-Franche-Comté 1
Ashkelon, Southern District 1
Veigné, Centre 1
Paris, Île-de-France 1
Saint-Paul, Réunion 2
Mexico City, CDMX 1
León de los Aldama, GUA 1
Créteil, Île-de-France 1
Trichūr, KL 1
Brasília, DF 1
Lyon, Auvergne-Rhône-Alpes 1
Tel Aviv, Tel Aviv 1
Rive-de-Gier, Auvergne-Rhône-Alpes 1
Check Current Status

Community Discussion

Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.

Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.

GitHub Issues Reports

Latest outage, problems and issue reports in social media:

  • TheAIShrink
    The AI Therapist (@TheAIShrink) reported

    @YashHustle_22 Cursor eats your license. GitHub Copilot eats your login. The real tool you can't code without is a $300k GPU stack with 99% uptime.

  • HelveticVault
    E*NK1 (iii) ⥀ 💹🧲 (@HelveticVault) reported

    GitHub just changed its bug bounty rules. Public bounties are down. Top researchers can now earn 30k+ through a new VIP track. And there is a catch: newcomers must prove their value with just 4 submissions or lose access. Why? Because AI-generated reports flooded the program with low-quality submissions. When the watchers become the noise, the platform tightens the gate. Signal is not a badge. It is the only thing that keeps a market of observers from collapsing into slop.

  • BreakingNewsFi2
    QuestionAll (@BreakingNewsFi2) reported

    @pulmencr @dadadaistt It doesn't actually work. Read the GitHub comments. It's all just vibe coded nonsense and the author has ai agents responding to *** discussions and got issues so it looks real. I work with microcontrollers, this guy clearly has never worked with an ESP32 before in his life

  • luislozanog86
    Luis Lozano (@luislozanog86) reported

    There seems to be an issue with Gemma 4 31B @googlegemma where it hallucinates tool_calls by creating fake outputs that then get mistaken as real memories. I was able to reproduce the error on Cerebras and OpenRouter. Next step: test Gemma 4 directly via GPU. And if this stills happens, I need to reproduce with other Gemma 4 products. I'll share the Github with the errors and the fix once we have it.

  • tiagozip_
    tiago 🐈 (@tiagozip_) reported

    @gabem_p i know this is controversial but i do NOT think this is a good decision. emusks, for example, has exclusively the XChat handler llm-assisted. it's obviously unreasonable to manually reverse engineer megabytes of obfuscated javascript, and claude's code works great, but a blanket policy can't be reasoned with. obviously this is an edge case, but i don't get why ai code would ever be a problem to codeberg. slop isn't hosted there, it's usually on github, and they're not the ones dealing with bad PRs. i'd much rather pick an ai policy myself than have an upstream provider force it on me.

  • DFIR_Radar
    DFIR Radar (@DFIR_Radar) reported

    CVE-2026-63030 and CVE-2026-60137 chain into pre-auth RCE on WordPress 6.9.0-6.9.4 and 7.0.0-7.0.1. Public PoCs hit GitHub within hours of July 17 disclosure; active scanning and exploitation confirmed in telemetry. - wp2shell abuses route confusion in WordPress Core's REST batch endpoint (/wp-json/batch/v1 or /?rest_route=/batch/v1, no plugins required) to reach a pre-auth SQL injection primitive, then escalates via SQLi-to-administrator bridge and plugin upload, or direct INTO OUTFILE webshell drop. Both paths land attacker-controlled PHP on disk, then shell execution through the web stack. MITRE: T1190, T1505.003, T1059. - The staging sequence leaves a durable file trail: apache2 writes temp-write-test-* probe files under wp-content/, a zip lands under wp-content/uploads/, PHP unpacks to wp-content/upgrade/wp2shell_<hex>/, then moves into wp-content/plugins/wp2shell_<hex>/. The PoC self-deletes the plugin post-execution, so a missing wp2shell_* folder does not clear the host if process alerts already fired. - Elastic's lab run produced 12 alerts across four rules: PHP File Creation in WordPress Plugin Directory (earliest signal, catches the drop), Payload Execution by Web Server (fires and kills dash when apache2 spawns it), and Suspicious/Unusual Command Execution via Web Server (SIEM depth on id, whoami, hostname, SUID enumeration). The hex suffix in plugin names is fragile; the apache2-to-dash parent-child relationship is not. #DFIR_Radar

  • sickdotdev
    Sick (@sickdotdev) reported

    Do you log which GitHub action an agent approval actually triggered? I am trying to be less casual with agents that can touch GitHub. A prompt that says "approve this action" feels fine in the moment. But later, when I am looking at an issue update, a branch change, or a PR comment, I want to know which approval caused it. When I connected a small tool with write permission, I approved one agent action and later had to dig through logs to figure out which command it actually ran. For GitHub-style actions, that would make me even more uncomfortable. Maybe this is too much for solo projects. Still, I am starting to think approval prompts should have an audit id that follows the action into the logs and final summary. If you let an agent use a GitHub token, how do you connect the approval prompt to the exact action it performed?

  • kuldeep_kumawat
    Kuldeep Kumawat (@kuldeep_kumawat) reported

    In 2022, a developer named @jarredsumner started building a JavaScript runtime from scratch in Zig - trying to fix how slow and fragmented the JS toolchain had become. Bun combined a runtime, bundler, test runner, and package manager into one binary - no more juggling Node + webpack + Jest + npm separately. It's now crossed 95,000+ GitHub stars (3,00,000+ weekly downloads) and is used as a drop-in Node replacement by teams chasing faster installs and cold starts. In December 2025, @AnthropicAI acquired Bun - betting on it as the infrastructure powering Claude Code and the Claude Agent SDK. Still fully open-source, still MIT-licensed, same team building it. One tool replaces four. And now it's powering the AI coding stack too.

  • ngmarley
    Nathan (@ngmarley) reported

    Software open-source licensing is going away. We'll look back on GPL as pure ridiculousness. Not because everything goes private (opposite), but b/c there's no teeth. Today, GitHub / GitLab have to take down codebases. Once a decentralized *** provider exists, this stops.

  • potencytoact
    Omar Farooq (@potencytoact) reported

    I agree with the recommended practice some have been discussing of submitting GitHub Issues instead of PRs.

  • Code_Fault
    Caleb Burns (@Code_Fault) reported

    @dhof @nikitabier @iamjasonlevin The problem is the key and its location is hidden. A public/private key pair would make more sense. If I setup a passkey, will it invalidate my password or other keys? Why does every website ask for my passkey when it knows I haven't established one (I'm looking at you Github)?

  • astriknormal
    Aniket (@astriknormal) reported

    I've more ADO PRs than GitHub PRs, and I gotta fix that

  • OlivercrestAI
    Oliver Crest (@OlivercrestAI) reported

    A solo developer in Johannesburg named Dave Blakey built the open source version of CCleaner, the tool Wired reported hackers used to spread malware to millions. He gave it away for free. It is called Kudu. CCleaner was hacked in 2017. Hackers hid malware inside the official update. 2.27 million people downloaded the infected version. It was hacked again in 2019. It is still sold today under new ownership. CCleaner Professional costs $29.95 for the first year. It renews at $44.95 a year after that. The Premium Bundle is $64.95 a year and adds Kamo, a privacy tool with VPN protection. Kudu costs zero. On every OS. Forever. Under MIT. CCleaner scans your PC. CCleaner charges you. Kudu scans for you. Here is how it works. You download the installer. You open Kudu. You pick a scan. The app runs it and shows you exactly what it wants to delete before it touches anything. System Cleaner. Temp files, logs, caches, crash dumps. Browser Cleaner. Caches across all major browsers in one pass. App Cleaner. Leftover files after uninstalls. Gaming Cleaner. Game launcher and shader caches. Registry Cleaner. Broken and orphaned entries. Startup Manager. Boot impact analysis. Disk Analyzer. Interactive treemap of your drive. Debloater. Removes Windows bloatware. Malware Scanner. Signature matching, heuristic analysis, Windows Defender integration. Works on Windows, Mac, and Linux. Installer for each. No ads. No upsells. No telemetry. Every line of code is on GitHub. Dave lives in Johannesburg, South Africa. His GitHub is 15 years old. He opened the Kudu repo in March 2026. He wrote 349 of the 403 total commits himself. The other 54 are dependabot updates. Version 1.45.0 shipped two days ago. 75 releases in four months. 1,370 stars. 110 forks. CCleaner can't shut this down. The MIT license does not permit that. Gen Digital, the $15 billion company that owns CCleaner, can't shut this down. They employ zero of its maintainers. CCleaner shipped malware to 2.27 million people. Gen Digital sells the same tool by subscription today. Dave Blakey built one that does the same job for free. (Link in the comments)

  • surveys347
    Harukoxd (@surveys347) reported

    @psomkarbuilds In the server it should never read it, as it should be placed by you. In local for things like github tokens I use a vault that never print or logs, its a skill that use that vault to decrypt the github token and pass it through another script, so its never in the console neither

  • RetiredSyre
    deus (@RetiredSyre) reported

    there’s a decent mcp server on github too if you’re about that life.

Check Current Status