We are investigating unauthorized access to GitHub’s internal repositories. While we currently have no evidence of impact to customer information stored outside of GitHub’s internal repositories (such as our customers’ enterprises, organizations, and repositories), we are closely monitoring our infrastructure for follow-on activity.
If any impact is discovered, we will notify customers via established incident response and notification channels.
• • •
Missing some Tweet in this thread? You can try to
force a refresh
1/ We are sharing additional details regarding our investigation into unauthorized access to GitHub's internal repositories.
Yesterday we detected and contained a compromise of an employee device involving a poisoned VS Code extension. We removed the malicious extension version, isolated the endpoint, and began incident response immediately.
2/ Our current assessment is that the activity involved exfiltration of GitHub-internal repositories only. The attacker’s current claims of ~3,800 repositories are directionally consistent with our investigation so far.
3/ We moved quickly to reduce risk. Critical secrets were rotated yesterday and overnight with the highest-impact credentials prioritized first.
How is generative AI affecting software developers?
A thread 🧵
🌐Generative AI coding tools are trained on large amounts of code across programming languages. They’re trained to process data like humans do—by recognizing patterns, making connections, and drawing inferences with limited guidance.
🔗Generative AI coding tools are powered by large language models (LLMs). Today’s state-of-the-art LLMs are transformers, which makes them adept at connecting tokens, big-picture thinking, and scaling. The results are coding and content suggestions that are contextually relevant.
When we released our first Octoverse report 10 years ago we were celebrating 2.8m people on GitHub. Now we have over 94m. We never could have predicted the impact open source would have on the world.
In 2012, most businesses were only using open source software (OSS) to run their web servers. Big-name projects, such as Kubernetes and Docker hadn't even been released yet.