GitHub: Difference between revisions
SinexTitan (talk | contribs) →Whitelisting of email domains on new accounts: the associated pic is quite cluttered |
complete summary, and 2 more incidents |
||
| Line 11: | Line 11: | ||
==Consumer impact summary== | ==Consumer impact summary== | ||
*'''Privacy:''' GH is owned by [[Microsoft]], raising questions about data usage. GH has recently engaged in aggressive Copilot integration.<ref>https://github.com/features/copilot ([https://megalodon.jp/2026-0326-0304-56/https://github.com:443/features/copilot Archived])</ref> Many projects such as the Gentoo Linux project, have left GH due to the privacy and security concerns associated with [[Artificial intelligence|AI]].<ref> https://itsfoss.com/news/gentoo-github-switch-begins/ ([https://megalodon.jp/2026-0326-0305-45/https://itsfoss.com:443/news/gentoo-github-switch-begins/ Archived])</ref><ref> https://www.linuxjournal.com/content/gentoo-charts-new-path-moving-away-github-toward-codeberg ([https://megalodon.jp/2026-0326-0306-04/https://www.linuxjournal.com:443/content/gentoo-charts-new-path-moving-away-github-toward-codeberg Archived])</ref><ref>{{Cite web |last=Kelley |first=Andrew |date=2025-11-26 |title=Migrating from GitHub to Codeberg |url=https://ziglang.org/news/migrating-from-github-to-codeberg/ |url-status=live |archive-url=https://web.archive.org/web/20260303052544/https://ziglang.org/news/migrating-from-github-to-codeberg |archive-date=2026-03-03 |access-date=2026-03-16 |website=⚡ Zig Programming Language}}</ref> | |||
*'''Privacy:''' GH is owned by [[Microsoft]], raising questions about data usage. GH has recently engaged in aggressive Copilot integration.<ref>https://github.com/features/copilot ([https://megalodon.jp/2026-0326-0304-56/https://github.com:443/features/copilot Archived])</ref> Many projects such as the Gentoo Linux project, have left GH due to the privacy and security concerns associated with AI.<ref> https://itsfoss.com/news/gentoo-github-switch-begins/ ([https://megalodon.jp/2026-0326-0305-45/https://itsfoss.com:443/news/gentoo-github-switch-begins/ Archived])</ref><ref> https://www.linuxjournal.com/content/gentoo-charts-new-path-moving-away-github-toward-codeberg ([https://megalodon.jp/2026-0326-0306-04/https://www.linuxjournal.com:443/content/gentoo-charts-new-path-moving-away-github-toward-codeberg Archived])</ref><ref>{{Cite web |last=Kelley |first=Andrew |date=2025-11-26 |title=Migrating from GitHub to Codeberg |url=https://ziglang.org/news/migrating-from-github-to-codeberg/ |url-status=live |archive-url=https://web.archive.org/web/20260303052544/https://ziglang.org/news/migrating-from-github-to-codeberg |archive-date=2026-03-03 |access-date=2026-03-16 |website=⚡ Zig Programming Language}}</ref> | |||
*'''Transparency:''' While some tools like [https://cli.github.com/ the <code>gh</code> CLI] are open-source,<ref>{{Cite web |date=3 Oct 2019 |title=GitHub’s official command line tool (source Git repository) |url=https://github.com/cli/cli |url-status=live |access-date=16 Sep 2025 |website=GitHub |archive-url=http://web.archive.org/web/20260128035607/https://github.com/cli/cli |archive-date=28 Jan 2026}}</ref> the platform itself is closed-source and proprietary. | *'''Transparency:''' While some tools like [https://cli.github.com/ the <code>gh</code> CLI] are open-source,<ref>{{Cite web |date=3 Oct 2019 |title=GitHub’s official command line tool (source Git repository) |url=https://github.com/cli/cli |url-status=live |access-date=16 Sep 2025 |website=GitHub |archive-url=http://web.archive.org/web/20260128035607/https://github.com/cli/cli |archive-date=28 Jan 2026}}</ref> the platform itself is closed-source and proprietary. | ||
*'''Market control:''' GH is the platform that hosts the most important repositories in the world.{{Citation needed|reason=or is it?|date=2026-05-11}} It's the standard-de-facto for hosting and managing source-code, often overshadowing platforms such as [[wikipedia:Codeberg|Codeberg]] and [[wikipedia:GitLab|GitLab]]. | |||
*'''Reliability:''' ever since Microsoft acquired it, GH's uptime has degraded.<ref>https://damrnelson.github.io/github-historical-uptime/</ref> There have been multiple incidents (elaborated in the next section), such as Git-history corruption and security vulnerabilities. They've apologized and plan to improve the situation.<ref>https://github.blog/news-insights/company-news/an-update-on-github-availability/</ref> | |||
==Incidents== | ==Incidents== | ||
| Line 30: | Line 31: | ||
When creating a new account on the platform, GH restricts the use of emails from certain domains, such as to disallow the usage of {{Wplink|email alias|email aliases}}. Which a user might use to preserve their privacy. | When creating a new account on the platform, GH restricts the use of emails from certain domains, such as to disallow the usage of {{Wplink|email alias|email aliases}}. Which a user might use to preserve their privacy. | ||
=== | ===Buggy merge queue (2026, April)=== | ||
[https:// | On April 23, 2026, [[wikipedia:Distributed_version_control#Pull_requests|pull-requests]] (PRs) merged via merge-queue using the squash merge method produced incorrect merge commits when the merge group contained more than one PR. In affected cases, changes from previously merged PRs and prior commits were inadvertently reverted by subsequent merges.<ref>https://www.githubstatus.com/incidents/zsg1lk7w13cf</ref><ref>https://trunk.io/blog/what-happens-if-a-merge-queue-builds-on-the-wrong-commit</ref> | ||
=== RCE via <code>git push</code> (2026, March) === | |||
A [[wikipedia:Arbitrary_code_execution|remote code execution vulnerability]] was found that allowed abusing <code>git push</code> commands to read and write data to any <!-- not quite "any", it's more nuanced --> repository hosted by GH, including ''private'' ones.<ref>https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854</ref> GH fixed this bug quickly after it was reported to them. | |||
==Products== | ==Products== | ||
{{Ph-C-P}} | {{Ph-C-P}} | ||
== | *Enterprise | ||
*Copilot | |||
==External links== | |||
*[https://giveupgithub.org/ "Give Up GitHub"] | |||
==References== | ==References== | ||
Revision as of 02:08, 12 May 2026
⚠️This article has been marked as incomplete. Sourcing or verifiability needs additional work.
#appeals channel in either Zulip or Discord to request removal.Articles must provide verifiable, credible evidence for their claims and avoid relying on forum posts, personal blogs, or other unverifiable sources. You can help by replacing weak citations with reputable reporting, corporate communications, receipts, repair logs, or independent investigative coverage that demonstrates the systemic relevance required by the Mission statement and Moderator Guidelines.
| Basic information | |
|---|---|
| Founded | 2008-02-08 |
| Legal Structure | Subsidiary |
| Industry | Developer platform |
| Also known as | |
| Official website | https://www.github.com |
Github (GH) is a proprietary developer platform that allows developers to create, store, manage, and share their code. It uses Git to provide distributed version control and GH itself provides access control, bug tracking, software feature requests, task management, continuous integration, and wikis for every project. Headquartered in California, GH has been a subsidiary of Microsoft since 2018.
Consumer impact summary
- Privacy: GH is owned by Microsoft, raising questions about data usage. GH has recently engaged in aggressive Copilot integration.[1] Many projects such as the Gentoo Linux project, have left GH due to the privacy and security concerns associated with AI.[2][3][4]
- Transparency: While some tools like the
ghCLI are open-source,[5] the platform itself is closed-source and proprietary. - Market control: GH is the platform that hosts the most important repositories in the world.[citation needed - or is it? (2026-05-11)] It's the standard-de-facto for hosting and managing source-code, often overshadowing platforms such as Codeberg and GitLab.
- Reliability: ever since Microsoft acquired it, GH's uptime has degraded.[6] There have been multiple incidents (elaborated in the next section), such as Git-history corruption and security vulnerabilities. They've apologized and plan to improve the situation.[7]
Incidents
Questions about data usage (2024-present)
GH does not specifically tell you the data usage for AI with private repositories. This means that it might be using your data to train AI models by Microsoft like Copilot.[8] Previously, Copilot exposed vital private repositories from big companies, raising even more concerns.[9]
This is a list of all consumer-protection incidents this company is involved in. Any incidents not mentioned here can be found in the GitHub category.
Planned fees for self-hosted Action runners (2025-present)
In December 2025, GH announced a new $0.002 per minute "cloud platform charge" for developers using self-hosted GH Actions runners on private repositories. It was due to take effect on March 1 2026, but seems to be postponed indefinitely. [10]
Whitelisting of email domains on new accounts

When creating a new account on the platform, GH restricts the use of emails from certain domains, such as to disallow the usage of email aliases. Which a user might use to preserve their privacy.
Buggy merge queue (2026, April)
On April 23, 2026, pull-requests (PRs) merged via merge-queue using the squash merge method produced incorrect merge commits when the merge group contained more than one PR. In affected cases, changes from previously merged PRs and prior commits were inadvertently reverted by subsequent merges.[11][12]
RCE via git push (2026, March)
A remote code execution vulnerability was found that allowed abusing git push commands to read and write data to any repository hosted by GH, including private ones.[13] GH fixed this bug quickly after it was reported to them.
Products
- Enterprise
- Copilot
External links
References
- ↑ https://github.com/features/copilot (Archived)
- ↑ https://itsfoss.com/news/gentoo-github-switch-begins/ (Archived)
- ↑ https://www.linuxjournal.com/content/gentoo-charts-new-path-moving-away-github-toward-codeberg (Archived)
- ↑ Kelley, Andrew (2025-11-26). "Migrating from GitHub to Codeberg". ⚡ Zig Programming Language. Archived from the original on 2026-03-03. Retrieved 2026-03-16.
- ↑ "GitHub's official command line tool (source Git repository)". GitHub. 3 Oct 2019. Archived from the original on 28 Jan 2026. Retrieved 16 Sep 2025.
- ↑ https://damrnelson.github.io/github-historical-uptime/
- ↑ https://github.blog/news-insights/company-news/an-update-on-github-availability/
- ↑ "What specific data exactly will be send to Copilot?". GitHub. Archived from the original on 12 May 2025. Retrieved 7 September 2025.
- ↑ "Copilot AI Exposes Private GitHub Code From Top Companies". digitalchew.com. Archived from the original on 26 Apr 2025.
- ↑ "Coming soon: simpler pricing and a better experience for GitHub Actions". GitHub. Archived from the original on 25 Mar 2026.
- ↑ https://www.githubstatus.com/incidents/zsg1lk7w13cf
- ↑ https://trunk.io/blog/what-happens-if-a-merge-queue-builds-on-the-wrong-commit
- ↑ https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854