buc.ci is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Admin email
abucci@bucci.onl
Admin account
@abucci@buc.ci

Search results for tag #github

AodeRelay boosted

[?]Graham Perrin » 🌐
@grahamperrin@mastodon.bsd.cafe

AodeRelay boosted

[?]Richard "RichiH" Hartmann » 🌐
@RichiH@chaos.social

Hey , it's roughly half a year until .

As a reminder, I will disable the -based fallback on the default network next year. The default network will be -only.

I do note that @Codeberg does support IPv6.

    [?]⠠⠵ avuko » 🌐
    @avuko@infosec.exchange

    RE: vt.social/@lina/11697543585120

    I deleted my account since @huggingface.co stole my code (15 repos) in 2025, and happily moved to @Codeberg

    Now I can’t opt-out. 🤦🏻‍♂️

    To everybody working for or using : I do not consent to any use of my code for training, calibration, (partial) extrusion or whatever you want to call your bullshit theft and grifting.

    This means you effectively cannot use any part of this dataset for any means whatsoever, at least not without being a total arsehole.

    [?]Hoshino Lina (星乃リナ) 🩵 3D Yuri Wedding 2026!!! » 🌐
    @lina@vt.social

    Looks like Hugging Face scraped ~all of GitHub into an AI training dataset...

    huggingface.co/spaces/HuggingF

    There is an opt-out link. You might want to use it.

      AodeRelay boosted

      [?]Graham Perrin » 🌐
      @grahamperrin@mastodon.bsd.cafe

      [?]Yves Van Goethem :firefox: » 🌐
      @yvg@indieweb.social

      The Codeberg thing is not surprising. And once again the proof that "it's somebody else's computer".

      GitHub is Microsoft is USA. GitHub is/was therefor restricted in places like Iran, North Korea, China, Russia, Syria, Crimea, etc.

      Codeberg preventing usage of something under their ToS is similar, they can do whatever they want.

      If you must avoid such situations don't use centralised solutions / somebody else's computer.

        AodeRelay boosted

        [?]concretedog » 🌐
        @concretedog@mastodon.social

        [?]Fabian Transchel » 🌐
        @ftranschel@norden.social

        @mthie So much wrong with this, the cognitive dissonance on these „replies“ is just baffling.

        Like starting with understanding what is and aims to be and that it is NOT competition to would be a start, aye…

          AodeRelay boosted

          [?]Tommaso Gagliardoni » 🌐
          @tomgag@infosec.exchange

          My view on the recent Codeberg drama:

          gagliardoni.net/#20260724_code

          Codeberg voting members have the right to decide the policy of their association, and I understand if a community is averse to anything that is AI- or Web3-related. I understand it, but I don't agree with it, because it's 2026, and if you still think you can just stick your head in the sand and wish for these ugly bad things to go away, well, I have bad news for you.

          To me, this is a perfect recipe to relegate Codeberg to irrelevance. And we are already seeing the beginning of a new exodus.

          Here is my conspiracy theory: the vote was pushed or manipulated from the inside by Big Tech. Whether this is true or not, one thing is sure: folks at Microsoft, GitHub, OpenAI etc. are now popping champagne.

            [?]Tommaso Gagliardoni » 🌐
            @tomgag@infosec.exchange

            And now, after banning vaguely-defined "LLM-generated code", Codeberg bans cryptocurrency projects. Discussion:

            codeberg.org/Codeberg/org/pull

            The specific ban is for "Content that harms the reputation of Codeberg, such as cryptocurrency related projects".

            codeberg.org/Codeberg/org/comm

            I think the reputation of Codeberg has been now harmed enough. When I originally escaped GitHub, I chose Codeberg exactly for the ethical stance and values. For me, anti-censorship is a non-negotiable ethical value. The folks at Codeberg have the right to run their org as they want. However, having now shown that they consider "censorship" good when it's about things they dislike, this made clear that their values and mine are not compatible (even if I dislike those same things, mind you).

            Supporters of this ban say that this "draws a line", that "is not meant to be applied blanket-wide to all projects, only those which are harmful to the community", as if having constantly to worry about the next mood swing of Codeberg voting members were an acceptable Sword of Damocles for any reputable project. What's next? Banning US users? Banning software aligned with "capital-fascist" values? Open-source banking/wallet apps? Quantum computing tools? Robotics?

            I'm moving off Codeberg, probably to Radicle. But I feel a bit sad, because Codeberg had the potential, in my opinion, to become the European alternative to GitHub, and they have made clear that they are not ready nor willing to become so. Which is fine: software is political, and everyone has the right to express their political stance.

            But we still desperately need an alternative to GitHub.

              AodeRelay boosted

              [?]mempko » 🌐
              @mempko@fosstodon.org

              I was about to transfer my Abject project to Codeberg but can't now.

              Codeberg seems to be more aligned with the OSS compared to the FL in FLOSS.

              blog.codeberg.org/protecting-o

                AodeRelay boosted

                [?]iX Magazin » 🌐
                @iX_Magazin@social.heise.de

                AodeRelay boosted

                [?]The Threat Codex » 🤖 🌐
                @threatcodex@infosec.exchange

                Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign

                socket.dev/blog/github-actions

                  AodeRelay boosted

                  [?]packagist » 🌐
                  @packagist@phpc.social

                  CI/CD pipelines are a prime target for supply chain attacks. We hardened the GitHub Actions workflows for Composer, Packagist and Private Packagist with zizmor, a static analysis tool for GitHub Actions. 🌈

                  Our new blog post covers what zizmor catches, our configuration, and the pitfalls we hit along the way:
                  blog.packagist.com/securing-ou

                    AodeRelay boosted

                    [?]Flippin' 'eck, Tucker! » 🌐
                    @losttourist@social.chatty.monster

                    🎶 Oops, they did it again.

                    A screenshot from githubstatus.com showing a host of services are currently not working correctly.

                    Alt...A screenshot from githubstatus.com showing a host of services are currently not working correctly.

                      AodeRelay boosted

                      [?]ᴏᴏᴍ-ᴋɪʟʟᴇʀ: 333[ᴘʀᴇᴍɪᴜᴍ] » 🌐
                      @jae@mastodon.bsd.cafe

                      seems there's an emerging trend in the space where people are producing tui interfaces or webapps in various frameworks and languages to keep an 👁️ on their usage.

                      i'm not talking like 1-2 finds rando on , countless ones. instead of writing a tool for monitoring your usage and costs. why not save your money and write a bash-script that polls the api endpoint ( ) all have them.

                      all you need is a trivial loc of and

                        [?]Ricard Torres 👨‍💻 » 🌐
                        @dev@ricard.social

                        I plan to move most of my git repos to a self hosted and make them all private.

                        First of all cleaning up repositories. Deleting old, unused stuff...

                          [?]Ricard Torres 👨‍💻 » 🌐
                          @dev@ricard.social

                          From a 100 repos to only 20 left on for now. I shall continue the purge tomorrow.

                          I was able to add a runner with Docker. So now my several repositories are already building in Gitea as I push changed, just like they did before on GitHub Actions (also using a shared workflow now).

                          Feels good.

                            AodeRelay boosted

                            [?]Mike Fiedler, Code Gardener » 🌐
                            @miketheman@hachyderm.io

                            If you use the `setup-uv` in your workflows, consider upgrading to version 9.0.0 soon.

                            This version changes the default behavior to store the downloaded wheels from in GHA Cache, shedding load from PyPI, especially relevant for frequent CI/CD runs.

                            The maintainers considered this a breaking change, hence the version bump, probably because it flips existing expectations.

                            If you expected that the Action was caching downloads before, now it actually does, so it's a logical fix in that regard.
                            Read more: github.com/astral-sh/setup-uv/

                              [?]Tommaso Gagliardoni » 🌐
                              @tomgag@infosec.exchange

                              Codeberg community voted to ban AI-generated code in repositories:

                              codeberg.org/Codeberg/org/pull

                              I am a regular Codeberg user, left GitHub in 2019, and co-maintain Libre projects that saw very little if none at all AI in development.

                              And still I think this decision will backfire badly.

                              I, like most of Codeberg users, was not even aware that this discussion was in place, did not vote. This only passed because of the anti-AI Luddite crowd. Which, mind you, has a point, I have very conflicting feelings about AI myself, and I think that the current trajectory is quite worrying. But this is just a knee-jerk reaction that has clearly not been thought of well enough.

                              I applaude the philosophy, or the intent if you want, of not having Codeberg turn into another SlopHub. But this is fairy-tale wishful thinking. There is no way to reliably detect AI-generated code at scale in 2026.
                              I can already smell the mutual witch hunts across projects and "camps".

                              Anyway, I hope I'm wrong.

                                [?]Tommaso Gagliardoni » 🌐
                                @tomgag@infosec.exchange

                                @tante sorry, the "how will people enforce this" argument is real, dismissing it will not make it disappear.

                                I am a regular Codeberg user, left GitHub in 2019, and co-maintain Libre projects that saw very little if none at all AI in development.

                                And still I think this decision will backfire badly.

                                I, like most of Codeberg users, was not even aware that this discussion was in place, did not vote. This only passed because of the anti-AI Luddite crowd. Which, mind you, has a point, I have very conflicting feelings about AI myself, and I think that the current trajectory is quite worrying. But this is just a knee-jerk reaction that has clearly not been thought of well enough.

                                I applaude the philosophy, or the intent if you want, of not having Codeberg turn into another SlopHub. But this is fairy-tale wishful thinking. There is no way to reliably detect AI-generated code at scale in 2026.
                                I can already smell the mutual witch hunts across projects and "camps".

                                Anyway, I hope I'm wrong.

                                  [?]Jesus Michał von Gentoo 🏔 (he) » 🌐
                                  @mgorny@social.treehouse.systems

                                  I don't know what's more stupid: using different authentication flow depending on whether you have a `.pub` file in addition to the private key or not, or suddenly starting to reject one of the two valid RFC 4252 workflows.

                                  thorsell.io/2026/07/21/github-

                                    AodeRelay boosted

                                    [?]omar » 🌐
                                    @omar@mastodon.bsd.cafe

                                    people using in a professional environment (paying for), how's the experience nowadays?

                                    Are you also impacted by throttling ?

                                      [?]𝕂𝚞𝚋𝚒𝚔ℙ𝚒𝚡𝚎𝚕™ » 🌐
                                      @kubikpixel@chaos.social

                                      «xAI stellt KI-Agen "Grok-Build" nach massivem Datenleck als Open Source auf GitHub:
                                      xAIs Kommandozeilen-Tool "grok" hat massive Kritik ausgelöst, weil es beim Ausführen in einem Verzeichnis sämtliche Dateien auf xAIs Google-Cloud-Server hochlud.»

                                      So viel zum Thema Suverenität von xAI. Klar ist, dass Open-Source ist schon länger auch Marketing der IT-Konzernen auf die meisten basieren.

                                      🤖 the-decoder.de/xai-stellt-ki-a

                                        AodeRelay boosted

                                        [?]Truth Matters » 🌐
                                        @TruthMattersww@sueden.social

                                        @christin yepp. Das ++ sollte nur symbolisieren, dass ich auch zu Codeberg gewechselt bin. Und --

                                          AodeRelay boosted

                                          [?]🏳️‍⚧️ Christin Löhner 🏳️‍🌈 » 🌐
                                          @christin@lsbt.me

                                          GitHub gehört Microsoft. Zeit für einen Ausweg.

                                          GitHub gehört seit 2018 Microsoft, unterliegt dem US Cloud Act und lässt Copilot seit April 2026 standardmäßig mit deinem Code trainieren, wenn du nicht widersprichst. Codeberg ist die naheliegende Alternative: gemeinnützig, europäisch, ohne Konzern im Rücken. Reden wir drüber!

                                          chrislo.de/blog/2026-07-12-12-

                                          AodeRelay boosted

                                          [?]rapha3l » 🌐
                                          @rapha3l@not-x.g2od.ch

                                          @christin

                                          Viele Projekte nutzen noch GitHub, statt dezentrale Gits...

                                            AodeRelay boosted

                                            [?]AA » 🌐
                                            @AAKL@infosec.exchange

                                            New.

                                            Socket: Compromised Injective SDK npm Package Exfiltrates Wallet Keys and Mnemonics socket.dev/blog/compromised-in @SocketSecurity

                                              AodeRelay boosted

                                              [?]CyberSecureFox :loading: » 🤖 🌐
                                              @cybersecurefox@infosec.exchange

                                              AodeRelay boosted

                                              [?]heise online » 🌐
                                              @heiseonline@social.heise.de

                                              GitHub-Alternative für KI-Entwickler: Entire startet eigenes Git-Netzwerk

                                              Entire startet ein eigenes Git-Netzwerk für die EU, USA und Australien. Das Start-up von Ex-GitHub-CEO Thomas Dohmke spiegelt auch GitHub-Repos.

                                              heise.de/news/GitHub-Alternati

                                                AodeRelay boosted

                                                [?]thecybersecguru » 🌐
                                                @thecybersecguru@infosec.exchange

                                                🚨 GitHub had two trust failures in the same week. Neither broke cryptography. Neither hacked AI.

                                                They simply exploited the gap between what GitHub checks and what developers assume.

                                                1️⃣ Git Hash Chain Malleability
                                                A signed commit can be transformed into multiple different commit SHAs without the signing key.

                                                ✅ Same code
                                                ✅ Same signature
                                                ✅ Still shows Verified
                                                ❌ Different commit hash

                                                2️⃣ GitLost (AI Prompt Injection)
                                                GitHub's AI agent could be tricked into reading data from private repositories and posting it publicly through a malicious issue.

                                                One attacks cryptographic trust.
                                                The other attacks AI trust.

                                                Different bugs. Same lesson:
                                                "Verified" doesn't always mean what you think it means.

                                                Full breakdown with technical details 👇
                                                thecybersecguru.com/news/githu

                                                  AodeRelay boosted

                                                  [?]Cloud 🤖 » 🤖 🌐
                                                  @cloud@infosec.exchange

                                                  🤖 'GitLost' flaw: GitHub Agentic Workflows leak private repo data via a crafted public issue. No auth needed — attacker opens an issue, and if the agent has broad read access, private data is exfiltrated.

                                                  🔗 darkreading.com/cyber-risk/git

                                                    AodeRelay boosted

                                                    [?]AA » 🌐
                                                    @AAKL@infosec.exchange

                                                    This was posted yesterday.

                                                    NOMA: GitLost: How We Tricked GitHub’s AI Agent into Leaking Private Repos noma.security/blog/gitlost-how

                                                    More:

                                                    The Hacker News: Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data thehackernews.com/2026/07/publ @thehackernews

                                                      AodeRelay boosted

                                                      [?]Graham Perrin » 🌐
                                                      @grahamperrin@mastodon.bsd.cafe

                                                      @scalonnec

                                                      15.0-RELEASE-p11, 15.1-RELEASE-p1, or 15-STABLE?

                                                      I'm grateful for the FreeBSD Foundation's use of GitHub.

                                                      Cc @justine @FreeBSDFoundation

                                                        AodeRelay boosted

                                                        [?]Software Freedom Conservancy » 🌐
                                                        @conservancy@social.sfconservancy.org

                                                        Today is a good day to finally #GiveUpGitHub!

                                                        & now there's YA reason: last week, #GitHub urged the FOSS community to *oppose* important #California legislation that places transparency and consumer rights requirements on deployment of LLM-gen-AI!

                                                        GitHub's tactic? Disinformation claiming #FOSS licenses are incompatible with Cal. Bus. & Prof. Code §22757 and California #SB1000 (which seeks to amend §22757).

                                                        Read the analysis: https://sfconservancy.org/blog/2026/jul/03/github-gen-ai-california-22757-ok-for-foss-license/

                                                        #LLM #AI #copyleft #GPL #Microsoft #law

                                                          AodeRelay boosted

                                                          [?]Paco Hope » 🌐
                                                          @paco@infosec.exchange

                                                          I just got this bill from for usage. See if you can spot what is ridiculous about this bill.

                                                          Screenshot of my “account usage” page at GitHub. 

It lists a bunch of “Included usage” items, each of which is zero dollars. They’re things like 
2,000 Actions minutes
.5 GB Actions storage
10 GB Git LFS storage

Then it says 
Free usage: 100% off per month
Zero dollars and two cents. 

The only thing on the list that explicitly says one hundred percent discount has a non-zero charge.

                                                          Alt...Screenshot of my “account usage” page at GitHub. It lists a bunch of “Included usage” items, each of which is zero dollars. They’re things like 2,000 Actions minutes .5 GB Actions storage 10 GB Git LFS storage Then it says Free usage: 100% off per month Zero dollars and two cents. The only thing on the list that explicitly says one hundred percent discount has a non-zero charge.

                                                            AodeRelay boosted

                                                            [?]DeltaLima 🐧 » 🌐
                                                            @DeltaLima@social.la10cy.net

                                                            Downloads from release-assets.githubuserconte are now speed limited or what?

                                                            Looks like, i can just download with a speed of 10 Mbit/s github uploaded releases.

                                                            Doesnt matter from which project i try to download assets, it's limited to ~1MB/s -.-

                                                              [?]Michael Downey :notAI: » 🌐
                                                              @downey@floss.social

                                                              💡 Today is a perfect day to exercise your independence from , and .

                                                              ☣️ is the equivalent of and for software development -- creators of the most enticing proprietary walled garden ever made for developers.

                                                              Don't be stuck when Microsoft decides to change the rules on you.

                                                              Start today.

                                                              GiveUpGitHub.org

                                                              GitHub "Octocat" mascot holding a bag with a "$" sign, and the other hand crushing blue words "USER RIGHTS".

                                                              Alt...GitHub "Octocat" mascot holding a bag with a "$" sign, and the other hand crushing blue words "USER RIGHTS".

                                                                [?]DigitalEscapeTools » 🌐
                                                                @xabd@mastodon.social

                                                                Awesome Digital Escape Tools is a curated collection of privacy-friendly, open-source, self-hosted, and secure software.

                                                                It features 220+ tools across 32 categories, with every entry linking to detailed information including features, screenshots, and more.

                                                                Contributions and suggestions are always welcome.

                                                                GitHub: github.com/abdomk1998/awesome-

                                                                Screenshot of the Awesome Digital Escape Tools GitHub repository README showing its title, description, and that it includes 220 tools across 32 categories.

                                                                Alt...Screenshot of the Awesome Digital Escape Tools GitHub repository README showing its title, description, and that it includes 220 tools across 32 categories.

                                                                  AodeRelay boosted

                                                                  [?]AA » 🌐
                                                                  @AAKL@infosec.exchange

                                                                  New.

                                                                  "The latest activity includes malicious npm releases affecting LeoPlatform and RStreams packages, GitHub Actions workflow abuse, and a related Go module compromise involving the Verana Blockchain project."

                                                                  Socket: Miasma Mini Shai-Hulud Hits LeoPlatform npm Packages and GitHub Actions, Expands to the Go Ecosystem socket.dev/blog/miasma-mini-sh @SocketSecurity

                                                                  FYI @ifin

                                                                    AodeRelay boosted

                                                                    [?]AA » 🌐
                                                                    @AAKL@infosec.exchange

                                                                    The GitHub update was made yesterday: github.com/actions/checkout/co

                                                                    More:

                                                                    The Hacker News: GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns thehackernews.com/2026/06/gith @thehackernews

                                                                    @ifin

                                                                      AodeRelay boosted

                                                                      [?]B'ad Samurai :ifin: » 🌐
                                                                      @badsamurai@infosec.exchange

                                                                      RE: infosec.exchange/@jkirk/116796

                                                                      I know we like to all dunk on pastebin-with-devops but I will always hat tip every non-AI secure-by-design improvement an org takes!

                                                                      More of this team!

                                                                        AodeRelay boosted

                                                                        [?]:awesome:🐦‍🔥nemo™🐦‍⬛ 🇺🇦🍉 » 🌐
                                                                        @nemo@mas.to

                                                                        Angreifer nutzen GitHub als Malware-Schleuder: Laut Marc Stöckel verbreiten sie Trojaner über etwa 10.000 Repos. Vorgehen: bestehende Code-Projekte kopieren, Trojaner per Zip-Link in der Readme einschleusen – und kompromittierte Commits teils mehrfach am Tag erneut posten. GitHub reagiert offenbar nur auf Meldungen, nicht proaktiv. golem.de/news/github-als-malwa

                                                                          AodeRelay boosted

                                                                          [?]AA » 🌐
                                                                          @AAKL@infosec.exchange

                                                                          New post:

                                                                          "A modular phishing infrastructure targeting multiple Mexican banks has been uncovered, abusing GitHub-hosted Pages, employing obfuscated scripts, and featuring a centralized credential exfiltration via SheetBest API, indicating a scalable and persistent multi-brand phishing operation."

                                                                          Group-IB: GitBait: Phishing the Mexican Financial Sector group-ib.com/blog/gitbait-phis

                                                                            AodeRelay boosted

                                                                            [?]AA » 🌐
                                                                            @AAKL@infosec.exchange

                                                                            AodeRelay boosted

                                                                            [?]rapha3l » 🌐
                                                                            @rapha3l@not-x.g2od.ch

                                                                            @nextcloud @jospoortvliet

                                                                            Open Source projects should be hosted on Open Source products.

                                                                              AodeRelay boosted

                                                                              [?]Graham Perrin » 🌐
                                                                              @grahamperrin@mastodon.bsd.cafe

                                                                              AodeRelay boosted

                                                                              [?]Netzpalaver » 🌐
                                                                              @Netzpalaver@social.tchncs.de

                                                                              AodeRelay boosted

                                                                              [?]Steven Saus [he/him] » 🌐
                                                                              @StevenSaus@faithcollapsing.com

                                                                              AI costs how much? GitHub Copilot users react to new usage-based pricing system.

                                                                              Some report burning through their whole monthly

                                                                              Archive: ia: s.faithcollapsing.com/iupsx


                                                                              arstechnica.com/ai/2026/06/ai-

                                                                              An image pulled automatically from the post for decorative purposes only.

                                                                              Alt...An image pulled automatically from the post for decorative purposes only.

                                                                                AodeRelay boosted

                                                                                [?]The Threat Codex » 🤖 🌐
                                                                                @threatcodex@infosec.exchange

                                                                                AodeRelay boosted

                                                                                [?]The New Oil » 🤖 🌐
                                                                                @thenewoil@mastodon.thenewoil.org

                                                                                AodeRelay boosted

                                                                                [?]Harry Sintonen » 🌐
                                                                                @harrysintonen@infosec.exchange

                                                                                Security Advisories program is struggling under the load of new submissions. Delays in CVE assignment up to a month are being reported. Apparently, May 2026 was the highest volume month ever, and they are working through a backlog.

                                                                                source: openwall.com/lists/oss-securit

                                                                                It is not very hard to figure out what is going on: The amount of AI-assisted reports is flooding the systems. Considering the asymmetric nature of the situation (limited human resources processing increasing number of reports), it is unlikely the it is getting any better soon.

                                                                                If just tracking and assigning issues is getting this hard, it can't bode well for actually fixing and patching them.

                                                                                  AodeRelay boosted

                                                                                  [?]Steven Saus [he/him] » 🌐
                                                                                  @StevenSaus@faithcollapsing.com

                                                                                  For the 2nd time in weeks, Microsoft packages laced with credential stealer

                                                                                  73 packages run self-replicating stealer as soon as they’re opened by an AI agent.

                                                                                  -&-it
                                                                                  arstechnica.com/security/2026/

                                                                                  An image pulled automatically from the post for decorative purposes only.

                                                                                  Alt...An image pulled automatically from the post for decorative purposes only.

                                                                                    AodeRelay boosted

                                                                                    [?]AA » 🌐
                                                                                    @AAKL@infosec.exchange

                                                                                    New.

                                                                                    "The emails contained links to GitHub repositories masquerading as technical assignments or cryptocurrency-related projects. The instructions encouraged the target to clone the repository and open it in an editor such as VS Code or Cursor. A pre-configured task executes silently when the user opens the repository folder in the IDE, triggering platform-specific loaders that decode embedded payloads on Linux, macOS, and Windows."

                                                                                    Proofpoint: Don't Fear the Repo: UNK_DeadDrop Phishing Campaign Targets Developers to Steal Cryptocurrency proofpoint.com/us/blog/threat-

                                                                                      AodeRelay boosted

                                                                                      [?]DeltaLima 🐧 » 🌐
                                                                                      @DeltaLima@social.la10cy.net

                                                                                      I went to bed: github broken
                                                                                      I wake up: github broken

                                                                                      Luckily I host my stuff on my personal instanz and mirror stuff to :)

                                                                                      github.com
504 Gateway time-out
the server didnt respond in time.

                                                                                      Alt...github.com 504 Gateway time-out the server didnt respond in time.

                                                                                        AodeRelay boosted

                                                                                        [?]Xavier Ashe :donor: » 🌐
                                                                                        @Xavier@infosec.exchange

                                                                                        disabled 73 repositories across four of its GitHub organizations — the entire Functions org, the whole Task family, and a row of AI sample apps — in a 105-second sweep on June 5. The recompromised package sits at the center, and the fingerprints point at the open-sourced worm.
                                                                                        opensourcemalware.com/blog/mia

                                                                                          AodeRelay boosted

                                                                                          [?]Sass, David » 🌐
                                                                                          @sassdawe@infosec.exchange

                                                                                          It seems is blocking from using GitHub.

                                                                                          I hope you all had backups!

                                                                                            [?]Sass, David » 🌐
                                                                                            @sassdawe@infosec.exchange

                                                                                            Access to the sassdawe/azure-functions-host repository has been disabled by #GitHub staff due to a terms of service violation.

                                                                                            When making content moderation decisions, we consider information from a variety of sources, including: account profile data, information contained in submitted reports/notices or discovered through our own voluntarily initiated investigations, and context around the contents of the repository.

                                                                                            If you wish to regain access to the disabled content or would like to dispute that a violation occurred and can provide additional information to show that a different decision should have been reached, please review our Appeal and Reinstatement Policy and submit a request via our form.

                                                                                            You may review our terms of service here: GitHub's Terms of Service

                                                                                            Please feel free to Contact GitHub Support if you have any questions.

                                                                                            Some happened to the source github.com/Azure/azure-functio

                                                                                            Access to this repository has been disabled by GitHub Staff due to a violation of GitHub's terms of service. If you are the owner of the repository, you may reach out to GitHub Support for more information.

                                                                                            Alt...Access to this repository has been disabled by GitHub Staff due to a violation of GitHub's terms of service. If you are the owner of the repository, you may reach out to GitHub Support for more information.

                                                                                              AodeRelay boosted

                                                                                              [?]Kehrwoche 🔴 ⚪ » 🌐
                                                                                              @Kehrwoche@sueden.social

                                                                                              Apps die man z.B. über eine Seite auf seinem Android Smartphone installiert hat, lassen sich mit installieren und auf aktuellem Stand halten.

                                                                                              Das muss einem schon gesagt werden.

                                                                                                AodeRelay boosted

                                                                                                [?]AA » 🌐
                                                                                                @AAKL@infosec.exchange

                                                                                                The New Stack: GitHub Copilot’s usage-based billing is live: Here’s what you need to know thenewstack.io/github-copilot- @TheNewStack

                                                                                                  [?]Artyom Bologov » 🌐
                                                                                                  @aartaka@merveilles.town

                                                                                                  Oh is doing just fine…

                                                                                                  Screenshot of Github Pull Requests tab of chibi-scheme repository. But that isn’t the most important part. The important part is that Pull requests tab has a badge with 4 (open PRs) in it, but the contents of the tab list only one. This pile of dung cannot even count things properly.

                                                                                                  Alt...Screenshot of Github Pull Requests tab of chibi-scheme repository. But that isn’t the most important part. The important part is that Pull requests tab has a badge with 4 (open PRs) in it, but the contents of the tab list only one. This pile of dung cannot even count things properly.

                                                                                                    AodeRelay boosted

                                                                                                    [?]Sascha Pallenberg 🇹🇼 ♻️ ⚡ » 🌐
                                                                                                    @pallenberg@mastodon.social

                                                                                                    Das gibt fuer viele Entwickler:innen heute ein boeses Erwachen, denn stellt heute auf ne Token-based Abrechnung um.

                                                                                                    Bei einigen werden die monatlichen Rechnungen um das 25-fache steigen und zeigt wunderbar, wie die diversen Betreiber von AI-Fabs um Profitabilitaet kaempfen.

                                                                                                    Es wird ein Hauen und Stechen!

                                                                                                    indiatoday.in/technology/news/

                                                                                                      AodeRelay boosted

                                                                                                      [?]Niklas Pivic » 🌐
                                                                                                      @pivic@kolektiva.social

                                                                                                      thoughts.pivic.com/leave-githu

                                                                                                      To leave GitHub is a good idea, for several reasons.

                                                                                                      A quote: 'The underlying purpose of AI is to allow wealth to access skill while removing from the skilled the ability to access wealth.'

This is not new. This is capitalism.

                                                                                                      Alt...A quote: 'The underlying purpose of AI is to allow wealth to access skill while removing from the skilled the ability to access wealth.' This is not new. This is capitalism.

                                                                                                        AodeRelay boosted

                                                                                                        [?]The Threat Codex » 🤖 🌐
                                                                                                        @threatcodex@infosec.exchange

                                                                                                        AodeRelay boosted

                                                                                                        [?]OffSequence » 🌐
                                                                                                        @offseq@infosec.exchange

                                                                                                        🚨 CRITICAL: CVE-2026-9312 (SSRF) in GitHub Enterprise Server 3.16.0 – 3.21.0 lets unauth attackers access internal services via crafted uploads. Patch to 3.16.20+ ASAP! Details: radar.offseq.com/threat/cve-20

                                                                                                        Critical threat: CVE-2026-9312: CWE-918 Server-Side Request Forgery (SSRF) in GitHub Enterprise Server

                                                                                                        Alt...Critical threat: CVE-2026-9312: CWE-918 Server-Side Request Forgery (SSRF) in GitHub Enterprise Server

                                                                                                          AodeRelay boosted

                                                                                                          [?]The New Oil » 🤖 🌐
                                                                                                          @thenewoil@mastodon.thenewoil.org

                                                                                                          AodeRelay boosted

                                                                                                          [?]Paul Chambers🚧 » 🌐
                                                                                                          @paul@oldfriends.live

                                                                                                          RE: infosec.exchange/@cyberseckyle

                                                                                                          It should be noted that this "Megalodon" has nothing to do with the Fediverse API project or the old pink Megalodon Fediverse App.

                                                                                                          "On May 18, 2026, an automated campaign codenamed megalodon pushed 5,718 malicious commits to 5,561 GitHub repositories in a six-hour window. Using throwaway accounts and forged author identities (build-bot, auto-ci, ci-bot, pipeline-bot), the attacker injected GitHub Actions workflows containing base64-encoded bash payloads that exfiltrate CI secrets, cloud credentials, SSH keys, OIDC tokens, and source code secrets to a C2 server at 216.126.225.129:8443."
                                                                                                          stepsecurity.io/blog/megalodon

                                                                                                            AodeRelay boosted

                                                                                                            [?]Kyle Reddoch (CybersecKyle) » 🌐
                                                                                                            @cyberseckyle@infosec.exchange

                                                                                                            AodeRelay boosted

                                                                                                            [?]Wendy Lin » 🌐
                                                                                                            @serigala_tropis@lgbtqia.space

                                                                                                            Pixelfed has a known bug about the federation, and deleting Pixelfed posts and/or accounts don't delete them on remote servers.

                                                                                                            github.com/pixelfed/pixelfed/i

                                                                                                              AodeRelay boosted

                                                                                                              [?]Curated Hacker News » 🤖 🌐
                                                                                                              @CuratedHackerNews@mastodon.social

                                                                                                              AodeRelay boosted

                                                                                                              [?]chesheer » 🌐
                                                                                                              @chesheer@mastodon.bsd.cafe

                                                                                                              Мой сонный разум породил подходящий рекламный слоган для в последнее время:
                                                                                                              «Я часть той силы, что вечно обещает SLA, но вечно производит баги».

                                                                                                                AodeRelay boosted

                                                                                                                [?]Ben Rothke » 🌐
                                                                                                                @benrothke@infosec.exchange

                                                                                                                Who guards the guards? embarrassed this week as attackers found a public repository called "Private-CISA" w/ 844MB of plain-text passwords, AWS tokens & Entra @CISAgov ID SAML certs exposed since 11/25. HT @guedou of @gitguardian. cybersec.gitguardian.com/s/how

                                                                                                                  AodeRelay boosted

                                                                                                                  [?]Steven Saus [he/him] » 🌐
                                                                                                                  @StevenSaus@faithcollapsing.com

                                                                                                                  In stunning display of stupid, secret CISA credentials found in public GitHub repo

                                                                                                                  SSH keys, plaintext passwords, other sensitive data had been up since November 2025.

                                                                                                                  Archive: ia: s.faithcollapsing.com/o2he7

                                                                                                                  -&-it -krebs -leak
                                                                                                                  arstechnica.com/information-te

                                                                                                                  A clown in bright clothes holds a laptop above his head.

                                                                                                                  Alt...A clown in bright clothes holds a laptop above his head.

                                                                                                                    AodeRelay boosted

                                                                                                                    [?]matthew - retroedge.tech » 🌐
                                                                                                                    @matthew@social.retroedge.tech

                                                                                                                    If you are looking for a self-hosted alternative to GitHub, check out Gitea or Forgejo.

                                                                                                                    https://about.gitea.com/

                                                                                                                    https://forgejo.org/

                                                                                                                    #gitHub #gitea #forgejo #selfHost

                                                                                                                      AodeRelay boosted

                                                                                                                      [?]heise online English » 🤖 🌐
                                                                                                                      @heiseonlineenglish@social.heise.de

                                                                                                                      Attack on GitHub: Data from 3800 internal repositories stolen

                                                                                                                      GitHub has confirmed an attack via an extension for Visual Studio Code. The stolen data is apparently for sale on a cybercrime forum.

                                                                                                                      heise.de/en/news/Attack-on-Git

                                                                                                                        AodeRelay boosted

                                                                                                                        [?]Aral Balkan » 🌐
                                                                                                                        @aral@mastodon.ar.al

                                                                                                                        RE: techhub.social/@Techmeme/11660

                                                                                                                        Remember this whenever you hear claims that your data is secure on some system or other that you do not own and control.

                                                                                                                        Like all that additional data governments want to gather via the slippery slope of “age verification” in the EU.

                                                                                                                        The only data that is actually secure on a third party is data you haven’t shared with the third party.

                                                                                                                        Hence: data minimisation.

                                                                                                                        Had I mentioned GDMR yet today? Because I feel I might have. But hey, here it is again:

                                                                                                                        ar.al/2018/11/29/gdmr-this-one

                                                                                                                        AodeRelay boosted

                                                                                                                        [?]Techmeme » 🤖 🌐
                                                                                                                        @Techmeme@techhub.social

                                                                                                                        GitHub confirms breach of ~3,800 repositories after one of its employees installed a malicious VS Code extension; TeamPCP claimed responsibility for the hack (Sergiu Gatlan/BleepingComputer)

                                                                                                                        bleepingcomputer.com/news/secu
                                                                                                                        techmeme.com/260520/p14#a26052

                                                                                                                          AodeRelay boosted

                                                                                                                          [?]Stefano Marinelli » 🌐
                                                                                                                          @stefano@mastodon.bsd.cafe

                                                                                                                          So, has been hacked.

                                                                                                                          Own Your Data!

                                                                                                                            AodeRelay boosted

                                                                                                                            [?]gyptazy » 🌐
                                                                                                                            @gyptazy@gyptazy.com

                                                                                                                            I hope this doesn't bother you at all...

                                                                                                                            Let's move all of our internal code, pipelines, secrets and tokens for external systems to someone. It's free and everyone does - it must be awesome. Welcome to 2026!


                                                                                                                              AodeRelay boosted

                                                                                                                              [?]abadidea » 🌐
                                                                                                                              @0xabad1dea@infosec.exchange

                                                                                                                              info on the github breach appears to only be available on xitter 🙄 , I fished it out for you.

                                                                                                                              post from github on May 20th, 2026:

We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories.

Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.

Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far.

                                                                                                                              Alt...post from github on May 20th, 2026: We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately. Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far.

                                                                                                                                AodeRelay boosted

                                                                                                                                [?]BlablaLinux » 🌐
                                                                                                                                @blablalinux@mastodon.blablalinux.be

                                                                                                                                En plein labo sur le reverse ! J'ai déterré une vieille discussion secrète et je tiens peut-être la recette magique pour faire tourner avec . Ça sent le prochain tuto ou le gros crash, verdict au prochain déploiement !

                                                                                                                                  AodeRelay boosted

                                                                                                                                  [?]Curated Hacker News » 🤖 🌐
                                                                                                                                  @CuratedHackerNews@mastodon.social

                                                                                                                                  Canada’s Bill C-22 would weaken protections on private messages

                                                                                                                                  opencivics-labs.github.io/dont

                                                                                                                                    AodeRelay boosted

                                                                                                                                    [?]Curated Hacker News » 🤖 🌐
                                                                                                                                    @CuratedHackerNews@mastodon.social

                                                                                                                                    Fabricked: Misconfiguring Infinity Fabric to Break AMD SEV-SNP

                                                                                                                                    xca-attacks.github.io/fabricke

                                                                                                                                      AodeRelay boosted

                                                                                                                                      [?]Hackread.com » 🌐
                                                                                                                                      @Hackread@mstdn.social

                                                                                                                                      📢⚠️ New: Grafana Labs, the open source analytics and visualization company, says hackers stole its source code after gaining access to a GitHub token and later demanded a ransom.

                                                                                                                                      Read: hackread.com/grafana-source-co

                                                                                                                                        AodeRelay boosted

                                                                                                                                        [?]AA » 🌐
                                                                                                                                        @AAKL@infosec.exchange

                                                                                                                                        New.

                                                                                                                                        Socket: Packagist Urges Immediate Composer Update After GitHub Actions Token Leak socket.dev/blog/packagist-urge @SocketSecurity

                                                                                                                                          Back to top - More...