GitHub is investigating unauthorized access to their internal repositories
61–70 of 359 posts
Re: GitHub is investigating unauthorized access to their internal repositories
#62Is it just me or is this happening way more frequently in the last 4 or 5 months? Coincidently around the same time the models got a lot more capable?
Now the market share is all the AI agent users.
Re: GitHub is investigating unauthorized access to their internal repositories
#63Is Twitter/X the right channel to announce a security event like this? I ask because I don’t see anything posted on their official blog or status page. https://github.blog/ https://www.githubstatus.com/
It’s a very popular messaging platform for tech enthusiasts.
Re: GitHub is investigating unauthorized access to their internal repositories
#64Is Twitter/X the right channel to announce a security event like this? I ask because I don’t see anything posted on their official blog or status page. https://github.blog/ https://www.githubstatus.com/
They announced this exclusively on X.com, which ranks barely above Pinterest in terms of usage. That's below Reddit, Snapchat, WeChat, and Instagram, and requires a user account to view profiles and posts. And that's ignoring all the reasons X is a divisive platform with an extreme political bent.
GitHub chose not to announce this on any other social media either (BlueSky, Facebook, TikTok, YouTube, LinkedIn, or Mastodon, as of this posting, and with no emails sent on the matter.)
Re: GitHub is investigating unauthorized access to their internal repositories
#65Re: GitHub is investigating unauthorized access to their internal repositories
#66GitHub: "We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity."
It reminds me of the famous "mistakes were made" Nixon quote. "We are investigating unauthorized access" sounds much better than "we've been hacked"
Re: GitHub is investigating unauthorized access to their internal repositories
#67Re: GitHub is investigating unauthorized access to their internal repositories
#68With this level of availability, would company remain on cloud?
Re: GitHub is investigating unauthorized access to their internal repositories
#69- Use Static analysis for GHA to catch security issues: https://github.com/zizmorcore/zizmor - set locally: pnpm config set minimum-release-age 4320 # 3 days in minutes https://pnpm.io/supply-chain-security for other package managers check: https://gist.github.com/mcollina/b294a6c39ee700d24073c0e5a4e... - add Socket Free Firewall when installing npm packages on CI https://docs.socket.dev/docs/socket-firewall-free#git…
Re: GitHub is investigating unauthorized access to their internal repositories
#70non-twitter link: https://xcancel.com/github/status/2056884788179726685#m
I guess it's hostile to signed in users in a different way.