使用 actions/cache 的 GitHub 用户现已可以在 WebUI 上管理 Actions 缓存。
https://github.blog/changelog/2023-04-10-manage-caches-in-your-actions-workflows-from-web-interface/
#GitHub #Actions
https://github.blog/changelog/2023-04-10-manage-caches-in-your-actions-workflows-from-web-interface/
#GitHub #Actions
The GitHub Blog
Manage caches in your Actions workflows from Web Interface
Caching dependencies and other commonly reused files enables developers to speed up their GitHub Actions workflows and make them more efficient. We have now enabled Cache Management from the web interface to enable developers to get more transparency and…
❤12🤔3
一位 GitHub 雇员宣布,GitHub Packages 计划支持 PyPi 源的计划将停止。
https://github.com/github/roadmap/issues/94
linksrc: https://t.me/plltxe/5400
#GitHub #Python
https://github.com/github/roadmap/issues/94
linksrc: https://t.me/plltxe/5400
#GitHub #Python
GitHub
Packages: Python (PyPi) support · Issue #94 · github/roadmap
Summary This is the GA (generally available) release of support for Python packages PyPi supporting the pip client. Intended Outcome GitHub Packages users will have access to a public and private P...
👎37🤔6🎉2
GitHub 移除了原有的 Following 及 For You 时间轴选项,改为混合关注内容及算法推荐内容的统一时间轴 [2]。然而,它并没有受到用户的好评。大量用户表示新的时间轴功能内容缺失、推荐繁杂以致无法使用。
注:GitHub 用户可以在 [3] 查看旧版时间轴。
1. https://github.com/orgs/community/discussions/65343
2. https://github.com/orgs/community/discussions/66188
3. https://github.com/dashboard-feed
#GitHub
注:GitHub 用户可以在 [3] 查看旧版时间轴。
1. https://github.com/orgs/community/discussions/65343
2. https://github.com/orgs/community/discussions/66188
3. https://github.com/dashboard-feed
#GitHub
GitHub
Updates to your GitHub Feed · community · Discussion #65343
Your homepage feed will now have a singular, consolidated feed that aggregates content from your starred repositories and followed users. As part of this update: The content from the “Following” fe...
👎45🤔1🎉1
有用户在 GitHub 论坛提到,GitHub 回复的邮件中要求 GitHub Education 学生包申请者将 GitHub 显示名改为自己的真实姓名;邮件还建议使用设备相机拍照上传学生身份证明文件,因为「图片上传的内容更容易被修改,因而可信度较低」。
https://github.com/orgs/community/discussions/57851
[感谢匿名订户提供的消息。]
#GitHub #Education
https://github.com/orgs/community/discussions/57851
[感谢匿名订户提供的消息。]
#GitHub #Education
GitHub
Student pack requesting full name in github username · community · Discussion #57851
Hi everyone, Hello! Upon applying for the GitHub student package, a few days passed and I received the message that I must change my GitHub username to my real life name, which is something I am re...
👎107👍6🐳6🤨4🤔2
GitHub Sponsors 现已支持持有澳门银行账户的受捐者。
GitHub Sponsors 新增对 35 个地区的支持,其支持的地区总数达到 104 个。
github.blog/~
#GitHub
GitHub Sponsors 新增对 35 个地区的支持,其支持的地区总数达到 104 个。
github.blog/~
#GitHub
🎉23👎2
GitHub 已经移除 subversion 支持。
https://github.blog/changelog/2024-01-08-subversion-has-been-sunset
#GitHub #svn
https://github.blog/changelog/2024-01-08-subversion-has-been-sunset
#GitHub #svn
👍28🤔10🤨5👎2
[旧闻] GitHub 用户 defunkt 称帐号被停用;他是 GitHub 联合创始人并曾 GitHub 担任 CEO。
稍晚些时候其帐号被恢复。
https://twitter.com/defunkt/status/1754610843361362360
#GitHub
稍晚些时候其帐号被恢复。
https://twitter.com/defunkt/status/1754610843361362360
#GitHub
🔥26
GitHub 似乎屏蔽了来自中国 IP 的非登录用户的访问,返回 HTTP 403。
https://github.com/orgs/community/discussions/156515
#GitHub #China
https://github.com/orgs/community/discussions/156515
#GitHub #China
GitHub
Access to this site has been restricted · community · Discussion #156515
Select Topic Area Question Body Starting this morning (April 13, 2025, UTC+8), I am unable to access GitHub without a proxy: My IP information are as follows: IPv4: 58.19.128.79 IPv6: 2408:824e:307...
🎉33👎14🤔8🐳4👍2
层叠 - The Cascading
GitHub 似乎屏蔽了来自中国 IP 的非登录用户的访问,返回 HTTP 403。 https://github.com/orgs/community/discussions/156515 #GitHub #China
GitHub 称这是一个配置错误。中国大陆未登录用户无法访问的问题现应已经恢复。
https://www.githubstatus.com/incidents/jfvgcls9swln
thread: /4699
#GitHub #China
https://www.githubstatus.com/incidents/jfvgcls9swln
thread: /4699
#GitHub #China
Githubstatus
[Retroactive] Access from China temporarily blocked for users that were not logged in
GitHub's Status Page - [Retroactive] Access from China temporarily blocked for users that were not logged in.
🎉32👎8🕊6❤1👍1
Mozilla 迁移 Firefox 主仓库到 GitHub。
- 之前 Mozilla 用于托管 Firefox 官方仓库的 Mercurial 服务,现在从 GitHub 镜像相关仓库。
- 问题讨论和贡献提交依然使用原有的 Bugzilla 和 Phabricator。
1. https://phoronix.com/news/Firefox-On-GitHub
2. https://github.com/mozilla-firefox/firefox
#Firefox #GitHub
- 之前 Mozilla 用于托管 Firefox 官方仓库的 Mercurial 服务,现在从 GitHub 镜像相关仓库。
- 问题讨论和贡献提交依然使用原有的 Bugzilla 和 Phabricator。
1. https://phoronix.com/news/Firefox-On-GitHub
2. https://github.com/mozilla-firefox/firefox
#Firefox #GitHub
Phoronix
Firefox Source Code Now Hosted On GitHub
The Mozilla Firefox source code is now officially available on GitHub as they work to transition from their hg.mozilla.org servers.
👍24🤔12
GitHub 上有用户向大量 repo 发送 OpenHarmony 适配相关的 spam issue。
- 这些 issue 的标题一般为 "Proposal for OpenHarmony Adaptation of [ ... ]" [1] 或「关于 … 的鸿蒙化适配提案」等。
- 包括 wshixjmjr 等部分发布这些 issue 的 GitHub 账号已经被封禁。
https://www.v2ex.com/t/1131883
1. github.com/~
#GitHub #OpenHarmony
- 这些 issue 的标题一般为 "Proposal for OpenHarmony Adaptation of [ ... ]" [1] 或「关于 … 的鸿蒙化适配提案」等。
- 包括 wshixjmjr 等部分发布这些 issue 的 GitHub 账号已经被封禁。
https://www.v2ex.com/t/1131883
1. github.com/~
#GitHub #OpenHarmony
👎73🎉24🤨12⚡3
🔴 Cline 2.3.0 用户可能被安装了 OpenClaw;不需要的话可以卸载。
- 2/17 晚至 2/18 凌晨安装了 Cline 的用户可能受到影响 [1]。
- 研究者利用了 GitHub Actions cache 可以跨分支共享、可以被投毒,以及 cache 的解压并未对路径进行检查的漏洞 [2]。
- 虽然未经用户允许安装,但 OpenClaw 本身并非恶意软件。
1. GHSA-9ppg-jx86-fqw7
2. adnanthekhan.com/~
Fixed-in: 2.4.0
#Cline #OpenClaw #GitHub
- 2/17 晚至 2/18 凌晨安装了 Cline 的用户可能受到影响 [1]。
- 研究者利用了 GitHub Actions cache 可以跨分支共享、可以被投毒,以及 cache 的解压并未对路径进行检查的漏洞 [2]。
- 虽然未经用户允许安装,但 OpenClaw 本身并非恶意软件。
1. GHSA-9ppg-jx86-fqw7
2. adnanthekhan.com/~
Fixed-in: 2.4.0
#Cline #OpenClaw #GitHub
GitHub
Unauthorized npm publish of Cline CLI cline@2.3.0 with modified postinstall script to install openclaw
### Description
On February 17, 2026 at 3:26 AM PT, an unauthorized party used a compromised npm publish token to publish an update to Cline CLI on the NPM registry: cline@2.3.0. The published pac...
On February 17, 2026 at 3:26 AM PT, an unauthorized party used a compromised npm publish token to publish an update to Cline CLI on the NPM registry: cline@2.3.0. The published pac...
🤯46💩11😁3👾2👎1
GitHub Copilot 宣布 4/24 起默认将使用用户输入进行训练;用户可以 opt-out。
- 涉及 Copilot Free/Pro/Pro+ 用户。
- opt-out 的位置在设置页 [1]。
github.blog/~
1. https://github.com/settings/copilot/features#copilot-telemetry-policy
#GitHub #GenAI
- 涉及 Copilot Free/Pro/Pro+ 用户。
- opt-out 的位置在设置页 [1]。
github.blog/~
1. https://github.com/settings/copilot/features#copilot-telemetry-policy
#GitHub #GenAI
The GitHub Blog
Updates to GitHub Copilot interaction data usage policy
From April 24 onward, interaction data from Copilot Free, Pro, and Pro+ users will be used to train and improve our AI models unless they opt out.
🖕26😁4😇4👍1👎1
🔴 npm 包 axios 1.14.1 & 0.30.4 被投毒。
安装了被骇包的设备可能会访问
stepsecurity.io/~
seealso: HackerNews:47582220
linksrc: https://t.me/CE_Observe/42851
#GitHub #SupplyChain
安装了被骇包的设备可能会访问
hxxp://sfrclak.com:8000 并执行 payload。stepsecurity.io/~
seealso: HackerNews:47582220
linksrc: https://t.me/CE_Observe/42851
#GitHub #SupplyChain
www.stepsecurity.io
axios Compromised on npm - Malicious Versions Drop Remote Access Trojan - StepSecurity
Hijacked maintainer account used to publish poisoned axios releases including 1.14.1 and 0.30.4. The attacker injected a hidden dependency that drops a cross platform RAT. We are actively investigating and will update this post with a full technical analysis.
😱8
GitHub 的 Stacked PR 功能开始 private preview。
在 https://gh.io/stacksbeta 可申请加入 waitlist。
https://github.github.com/gh-stack/
linksrc: blog.gslin.org/~
#GitHub
在 https://gh.io/stacksbeta 可申请加入 waitlist。
https://github.github.com/gh-stack/
linksrc: blog.gslin.org/~
#GitHub
GitHub Docs
Stacked pull requests - GitHub Docs
Use stacked pull requests to break large code changes into a chain of smaller, dependent pull requests you can review and merge independently.
GitHub 内部代码库被窃;原因是职员使用了带毒 VS Code 插件。
https://x.com/github/status/2056949168208552080
[感谢一位匿名订户提供消息。]
#GitHub
https://x.com/github/status/2056949168208552080
[感谢一位匿名订户提供消息。]
#GitHub
X (formerly Twitter)
GitHub (@github) on X
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories.
Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious…
Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious…
🌚17😁9
GitHub 出现数个发送质疑刷星相关 issue 的 spam 账号;现已被封禁。
内文似乎为 LLM 生成。
gh:didilili/ai-agents-from-zero#40
linksrc: https://t.me/zrj96/36133
#GitHub
内文似乎为 LLM 生成。
gh:didilili/ai-agents-from-zero#40
linksrc: https://t.me/zrj96/36133
#GitHub
GitHub
关于今日 Issue 区遭受恶意bot攻击的事件说明与共同举报倡议 · Issue #40 · didilili/ai-agents-from-zero
事件分析 今晚 2026-05-31 23:11 至 23:41,本仓库集中出现一批内容高度相似,与项目建设无关的 Issue 和评论,主要围绕 “Star 异常” 等主题对仓库进行攻击。 一开始我以为只是普通用户质疑,但继续查看账号行为后发现,这并不是用户的正常反馈,而是一组bot机器人账户对多个 GitHub 仓库进行批量攻击刷屏的行为。 主要涉及的攻击的bot账户如下: https:/...
🤬20