GitHub is investigating unauthorized access to their internal repositories
81–90 of 359 posts
Re: GitHub is investigating unauthorized access to their internal repositories
#82Earlier quoted context omitted.
It's certainly not the right platform. It'd be one thing if they had any official communication on the matter anywhere else. Maybe they're ashamed and are trying to limit the visibility while only technically issuing an announcement. They announced this exclusively on X.com, which ranks barely above Pinterest in terms of usage. That's below Reddit, Snapchat, WeChat, and Instagram, and requires a user account to view…
[flagged]
Re: GitHub is investigating unauthorized access to their internal repositories
#83Re: GitHub is investigating unauthorized access to their internal repositories
#84This is bad. If they came out announcing this, without a long winded explanation and further details, it's because they're staring at a bottomless pit and they haven't put the lid on it yet. For a Fortune 100, to go out of your way to spook investors is the least desirable approach.
The company that had 40 million Azure servers compromised? This is a drop in the bucket, the investors clearly do not care about this.
https://www.microsoft.com/en-us/security/blog/2026/05/18/sto...
Re: GitHub is investigating unauthorized access to their internal repositories
#85Re: GitHub is investigating unauthorized access to their internal repositories
#86The security issue aside, seeing more companies push announcements like these on X as the only official source is a trend I'm not sure I like. I can understand the rationale, this feels lighter and not something that belongs on status.github.com or the blog. Maybe what's actually missing is an official channel for ephemeral stuff on a domain they own, somewhere between a status page and a tweet? Just sharing an obser…
Social media posts were literally called "status updates" at some point.
Re: GitHub is investigating unauthorized access to their internal repositories
#87Why did one developer have access, even if read-only, to more than 3,800 internal repos?
I think it’s actually non-trivial to determine how many repos you should have read-only access to. I frequently hop through multiple repos that I don’t contribute to, just to understand how the system is architected and what it does at different stages. We even have an internal Claude skill for finding relevant repo for a given problem which relies on personal gh access (via CLI). It _can_ be done more securely but those defaults built over many years will take time to change.
Re: GitHub is investigating unauthorized access to their internal repositories
#88Why did one developer have access, even if read-only, to more than 3,800 internal repos?
The real question is why github has 3800 internal repos.
Re: GitHub is investigating unauthorized access to their internal repositories
#89Earlier quoted context omitted.
It's certainly not the right platform. It'd be one thing if they had any official communication on the matter anywhere else. Maybe they're ashamed and are trying to limit the visibility while only technically issuing an announcement. They announced this exclusively on X.com, which ranks barely above Pinterest in terms of usage. That's below Reddit, Snapchat, WeChat, and Instagram, and requires a user account to view…
[flagged]
The cognitive dissonance is insane here. Indeed, saying things doesn't make them true. Even for you. Facts don't care about your feelings.