schmonz.com is a Fediverse instance that uses the ActivityPub protocol. In other words, users at this host can communicate with people that use software like Mastodon, Pleroma, Friendica, etc. all around the world.

This server runs the snac software and there is no automatic sign-up process.

Search results for tag #GitHub

Jared Norman boosted

[?]knoppix » 🌐
@knoppix95@mastodon.social

Microsoft is canceling most Claude Code licenses for developers and steering staff to GitHub Copilot CLI after internal AI coding costs surged. 💸
Uber exhausted its 2026 AI coding budget in four months as rising token use exposed compute costs that can exceed employee pay. ⚙️

🔗 fortune.com/2026/05/22/microso

    Bill Seitz boosted

    [?]Jon Udell » 🌐
    @judell@social.coop

    Things are moving too fast to plan a sequel to Practical Internet Groupware.

    But this got me thinking about it!

    github.com/judell/bram/issues/

      #agile boosted

      [?]Habr » 🤖 🌐
      @habr@zhub.link

      ИИ-агент сам создал тикет, сам же его взял, и сам закрыл. Менеджер ничего не заметил

      Автономные агенты в разработке уже встроены в CI/CD живых команд, закрывают реальные тикеты и пишут код, который идёт в прод. Проблема не в том, что они это делают плохо, а в том, что метрики при этом выглядят слишком отлично. Разобрали, как агенты проходят каждый этап SDLC, что именно идёт не так на каждом из них и почему зелёный дашборд стал наименее надёжным источником правды о состоянии команды.

      habr.com/ru/companies/simpleon

        [?]Deborah Preuss, pcc [she/her/they] » 🌐
        @deborahh@cosocial.ca

        From the linked thread:

        "Just to be clear:

        Microsoft’s was compromised when a Microsoft developer using Microsoft VSCode installed a rogue extension from Microsoft’s VSCode extension library, which is moderated and hosted by Microsoft.!
        m.einverne.info/@HackerNewsBot

          [?]Stefano Marinelli » 🌐
          @stefano@mastodon.bsd.cafe

          So, has been hacked.

          Own Your Data!

            [?]gyptazy » 🌐
            @gyptazy@gyptazy.com

            I hope this doesn't bother you at all...

            Let's move all of our internal code, pipelines, secrets and tokens for external systems to someone. It's free and everyone does - it must be awesome. Welcome to 2026!


              [?]abadidea [she/her] » 🌐
              @0xabad1dea@infosec.exchange

              info on the github breach appears to only be available on xitter 🙄 , I fished it out for you.

              post from github on May 20th, 2026:

We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories.

Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.

Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far.

              Alt...post from github on May 20th, 2026: We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories. Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately. Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far.

                [?]Markus Tacker » 🌐
                @coderbyheart@chaos.social

                TIL: you can use `workflow_run` on actions to run them after another workflow ran ... previously I would invokle the second workflow from the first one. This makes it much more flexible!

                docs.github.com/en/actions/ref

                  [?]Klaus Frank » 🌐
                  @agowa338@chaos.social

                  Can someone explain why everyone is suddenly moving to and not ?

                  I know I'm kinda late to ask this, but why is Codeberg better than GitLab these days? What happened that it become the preferred choice for people moving off of ?

                    [?]Jason Yip » 🌐
                    @jchyip@mastodon.online

                    [?]Jason Yip » 🌐
                    @jchyip@mastodon.online

                    The Pulse: load breaks – why not other vendors? blog.pragmaticengineer.com/the

                      [?]Patrick Drechsler » 🌐
                      @drechsler@floss.social

                      Call me impressed: pages are slightly less annoying to setup than 😎

                        [?]Jason Yip » 🌐
                        @jchyip@mastodon.online

                        Marc Philipp boosted

                        [?]Jendrik Johannes » 🌐
                        @jendrik@mastodon.social

                        Flaky GitHub Pull Request builds are an annoying reality in many projects. Just when you think a change is complete and good to merge, you are greeted with an ❌. To unblock your PR, you need to rerun lengthy test pipeline just because of one rogue test.

                        If you have a Java project on GitHub, TestLens can help you:

                        testlens.app/blog/2027/05/07/r

                        Drop me a message, if you would like to join or beta program.

                        TestLens control buttons in a comment on your GitHub Pull Request. They offer a 'Only rerun the tests that failed or were muted before' checkbox to activate before triggering a rerun through the 'Rerun job' checkbox.

                        Alt...TestLens control buttons in a comment on your GitHub Pull Request. They offer a 'Only rerun the tests that failed or were muted before' checkbox to activate before triggering a rerun through the 'Rerun job' checkbox.

                          Jeff Grigg boosted

                          [?]MissConstrue [She/Her (Crone Extraordinaire)] » 🌐
                          @MissConstrue@mefi.social

                          So, is having a rough go of it lately. With significant instability and frequent outages in the last month and platform uptime dropping below 85%.

                          But the most fun trick? Any authenticated user could execute arbitrary commands on GitHub's backend servers with a single git push command - using nothing but a standard git client. (Because their architecture didn’t sterilize semicolons, thus prompt injection.)

                          On GitHub Enterprise Server, the vulnerability grants full server compromise, including access to all hosted repositories and internal secrets.

                          GitHub Enterprise Server customers should upgrade ASAP. Wiz dot io data indicates that 88% of instances were still vulnerable.

                          wiz.io/blog/github-rce-vulnera

                            [?]JdeBP » 🌐
                            @JdeBP@tty0.social

                            Since I was visiting the 'daemontools' account on , I took a look at what the people who mistakenly thought that it was someone actually involved, have done.

                            Not much, fortunately.

                            One wheel reinvention that didn't even look at Bruce Guenter's daemontools-encore.

                            Only one thing worth following up on, in 13 years:

                            github.com/daemontools/daemont

                            The bugfix will be in version 13 when it comes out. As noted, neither @ska's nor my reimplementations have this bug.

                              [?]JdeBP » 🌐
                              @JdeBP@tty0.social

                              For the record, and since we are on the subject of supply-chain attacks:

                              The person behind the 'daemontools' account on GitHub is unidentifiable, and certainly isn't Daniel J. Bernstein, me, @ska, Bruce Guenter, or anyone else well-known in the world.

                              The account has been inactive since 2013. If that account suddenly wakes up, it's not unreasonable to suspect that it has been compromised/become malicious.

                              (M. Guenter is bruceg on and is active there to this week.)

                                Marc Philipp boosted

                                [?]Benedikt Ritter (he/him) » 🌐
                                @britter@chaos.social

                                🚨 New Release of gh-get!

                                gh-get is a GitHub CLI extension that makes cloning and forming repositories eaiser, much like the ghq tool.

                                This release contains better forking behavior, improved logging and the possibility to directly cd into new clones.

                                Full announcement: britter.dev/blog/2026/05/05/gh

                                  [?]sebsauvage » 🌐
                                  @sebsauvage@framapiaf.org


                                  haha merde quelqu'un a fait ce site 😂
                                  dayswithoutgithubincident.com/

                                    [?]R.L. Dane :Debian: :OpenBSD: :FreeBSD: 🍵 :MiraLovesYou: [he/him/my good fellow] » 🌐
                                    @rl_dane@polymaths.social

                                    #VagueTooting

                                    Helpful suggestion:

                                    Instead of:

                                    • Posting error messages from #GitHub
                                    • Complaining about github being down

                                    try:

                                    • Not supporting #FashTech
                                    • Moving to a different service
                                    • Not supporting fashtech
                                    • Self-hosting
                                    • Not supporting fashtech

                                    #kthxbai

                                      Marc Philipp boosted

                                      [?]Benedikt Ritter (he/him) » 🌐
                                      @britter@chaos.social

                                      GitHub recently announced that starting with v2.91.0 GitHub CLI will start sending pseudonymized telemetry data back to GitHub.

                                      github.blog/changelog/2026-04-

                                      Since this is an opt-out feature, most users will have it activated without knowing it. This is unacceptable in my opinion. So I took the liberty of turning this into an opt-in, disabled by default for nixpkgs.

                                      github.com/NixOS/nixpkgs/pull/

                                        [?]dch :flantifa: :flan_hacker: » 🌐
                                        @dch@bsd.network

                                        serious question, has anybody found any info from Microslop about the impact of copyfail on github actions? Are they .. safe .. to use atm?

                                          [?]Jason Yip » 🌐
                                          @jchyip@mastodon.online

                                          [?]Bradley Taunt :runbsd: » 🌐
                                          @bt@mastodon.bsd.cafe

                                          With so many posts popping up about “leaving GitHub” or discussing how poor the experience overall is with that platform, I will share my old post again on moving over to SourceHut :)

                                          “Git Your Freedom Back: A Beginner’s Guide to SourceHut”

                                          btxx.org/posts/beginners-guide

                                            🗳

                                            [?]Buridan's procrastinator ⁂ » 🌐
                                            @quincy@chaos.social

                                            Have you already migrated your projects from ?

                                            yes:10
                                            soon:2
                                            not yet because it's always down:2

                                              [?]dch :flantifa: :flan_hacker: » 🌐
                                              @dch@bsd.network

                                              Apparently I have 75 million PRs to review today... gonna be here a while.

                                              you're drunk, take your CoPilot and Go Home.

                                              a snapshot of the Github web UI, with a list of random projects because github is completely borked, with over 75 million PRs to review.

                                              Alt...a snapshot of the Github web UI, with a list of random projects because github is completely borked, with over 75 million PRs to review.

                                                Glyph boosted

                                                [?]Seth Larson » 🌐
                                                @sethmlarson@mastodon.social

                                                RE: mastodon.social/@andrewnez/116

                                                Workflow security continues to be a common cause of compromises of open source projects.

                                                If you're using GitHub Actions and don't want this to happen to your project: use Zizmor and treat the findings seriously, especially insecure triggers and user-controllable template injections.

                                                docs.zizmor.sh

                                                [?]Andrew Nesbitt » 🌐
                                                @andrewnez@mastodon.social

                                                At this point having zizmor scans of every python package is turning out to be quite the crystal ball: stepsecurity.io/blog/elementar

                                                elementary-data in my db: 203 zizmor findings total. 82 template-injection (High), 47 unpinned-uses, 4 dangerous-triggers, 2 github-env, and 1 bot-conditions.

                                                  [?]Oliver Drotbohm » 🌐
                                                  @odrotbohm@chaos.social

                                                  The irony of megabytes of JavaScript force-fed to users in the name of “Nobody wants full page reloads!!!” and then exactly that full page reload being necessary to make the app work properly. FFS… 😣

                                                    [?]Oliver Drotbohm » 🌐
                                                    @odrotbohm@chaos.social

                                                    Today in “Fun with Github UI inconsistencies”:

                                                    – Create a new milestone
                                                    – Follow the “Back to milestones” link
                                                    – New milestone is missing
                                                    – Refresh page
                                                    – The new milestone shows up

                                                    Does anyone even test this stuff? 😔

                                                      [?]🫧 socialcoding.. » 🌐
                                                      @smallcircles@social.coop

                                                      @lattera

                                                      is known to be quite resource hungry.

                                                      Perhaps you can have a look at which is implemented in , and the is very similar to 's.

                                                      forgejo.org

                                                      And is hosted on forgejo, and maintain a downstream fork, optimized for high-scale use, which is also open source.

                                                      codeberg.org

                                                      Some large projects have migrated from GH and GL before, and created migration reports, etc. The other day I was asking if there's a list of those, I am not sure there is.

                                                      CC @forgejo and @Codeberg

                                                        Mark Levison boosted

                                                        [?]Shawn Webb [He/Him] » 🌐
                                                        @lattera@bsd.network

                                                        I'm 100% out of ideas. Our servers cannot handle the load the AI/LLM web scraping bots place on . is turning out to still not be ready for prime-time. I refuse to use beyond being a read-only mirror.

                                                        Self-hosting our code repos is an absolute requirement in order to provide higher levels of OPSEC than what third-party hosted services can provide.

                                                        So, at the hands of our oligarchic overlords, is this the death of HardenedBSD?

                                                        Someone please provide me ideas. I have no idea what to try next and I'm desperate.

                                                        editi[0]: This is solved! I changed my approach and now everything's happy--and so am I! :-)

                                                          [?]Daniel Terhorst-North » 🌐
                                                          @tastapod@mas.to

                                                          ' is down' is the new ' is down'

                                                          xkcd.com/303/

                                                          In other news, today I discovered there is no comic number 404.

                                                            [?]Jesus Michał "Le Sigh" 🏔 (he) » 🌐
                                                            @mgorny@social.treehouse.systems

                                                            Alternate code forges be like:

                                                            1. Let's offer this alternate VCS, so all the haters come to us.
                                                            2. Oh no, there's not much money in git haters. Let's offer git as well.
                                                            3. This alternate VCS is too much effort. Let's discontinue hosting it and tell our users to switch to our git hosting.
                                                            4. Why did all our users to move back to ?

                                                              [?]Michael Simons » 🌐
                                                              @rotnroll666@mastodon.social

                                                              Ok, that gave me enough of an angry energy boost to move my tooling away from to

                                                              codeberg.org/michael-simons/ga

                                                              Wanted to do this for a while.

                                                              Also, now fully Java 26, and because of that, no longer build profiles.

                                                                [?]Jason Yip » 🌐
                                                                @jchyip@mastodon.online

                                                                Back to top - More...