Live data from Hacker News

GitHub is investigating unauthorized access to their internal repositories

twitter.com

101–110 of 359 posts

Re: GitHub is investigating unauthorized access to their internal repositories

#102
post #91

Earlier quoted context omitted.

[flagged]

Maybe we need a cultural shift then, because if one needs to use a platform like X, nowadays owned and operated by fascists, then there's something deeply wrong with the tech world. It'd probably take a lot of effort to do so, but it'd be absolutely worth it. Besides, even if that wasn't a consideration, only posting the announcement to X is just crazy. As others have said, you'd expect for GitHub to make the announc…

I just spent a few minutes trying to think of a better place, I can't think of one, there is no professional social network, and linkedin doesn't qualify.

Re: GitHub is investigating unauthorized access to their internal repositories

#105
post #67

Is gitea any good?

Self hosted gitea for many years with ~25 devs. Yes, it's essentially a FOSS carbon copy of GitHub. CI/CD is also intercompatible, uses the same syntax and pulls the original GitHub Actions packages. Now with the Forgejo split, I would prefer Forgejo, as it has way more steam behind it with Codeberg and Blender as the big use-cases.

Re: GitHub is investigating unauthorized access to their internal repositories

#106
post #98

Time to move all my code from github. I was hoping they it will get better but it looks like it is getting much worst. Good bye github.

Join the club! I did as soon as the Microsoft acquisition realizing this would be only a matter of time… with more projects (finally) leaving that ecosystem, I might finally be able to delete my last account with Microsoft.

Re: GitHub is investigating unauthorized access to their internal repositories

#107
post #95

Earlier quoted context omitted.

It's normal that a dev has *access* to all the code. But did he clone all the repos into his machine? I doubt it. So, the hacker extracted all the 3800 repos using the employee's machine as a gateway? I doubt it as well, I'm sure they would have detected this huge amount of data much earlier than transferring all of it? > The real question is why github has 3800 internal repos. I guess they mean customer's private re…

> I guess they mean customer's private repos? I don't think so. It is even worse if a random developer has access to customers' private repos.

Good point. Then why in the world would a company have 3,500 repos? Do they create a repo for each employee?

Re: GitHub is investigating unauthorized access to their internal repositories

#108
post #4

Is it just me or is this happening way more frequently in the last 4 or 5 months? Coincidently around the same time the models got a lot more capable?

Also coincides with the time I started seeing Juniors installing "recommended extensions" into GitHub-hosted Visual Studio environments.. because there was a popup that helpfully suggested doing so, based on the programming languages used in the checked out repository.

Re: GitHub is investigating unauthorized access to their internal repositories

#110

Is Twitter/X the right channel to announce a security event like this? I ask because I don’t see anything posted on their official blog or status page. https://github.blog/ https://www.githubstatus.com/

It's been pretty common in the past for tech companies to announce outages and quick updates about them on twitter for decades. I'm sure their status page etc will be updated soon, but it's historically been the fastest way to get things out to the wider audience whilst bypassing the "official mail out" review by marketing etc.
Post reply on HN