GitHub Outage Map
The map below depicts the most recent cities worldwide where GitHub users have reported problems and outages. If you are having an issue with GitHub, make sure to submit a report below
The heatmap above shows where the most recent user-submitted and social media reports are geographically clustered. The density of these reports is depicted by the color scale as shown below.
GitHub users affected:
GitHub is a company that provides hosting for software development and version control using Git. It offers the distributed version control and source code management functionality of Git, plus its own features.
Most Affected Locations
Outage reports and issues in the past 15 days originated from:
| Location | Reports |
|---|---|
| Inverness, Scotland | 1 |
| Quito, Pichincha | 2 |
| Junín, Manabí | 1 |
| Guadalajara, JAL | 1 |
| Paris, Île-de-France | 6 |
| São Paulo, SP | 1 |
| Ipauçu, SP | 1 |
| Vigo, Galicia | 1 |
| Tel Aviv, Tel Aviv | 1 |
| Éragny, Île-de-France | 1 |
| Saltillo, COA | 2 |
| Montlhéry, Île-de-France | 1 |
| Aulnay-sous-Bois, Île-de-France | 1 |
| Granada, Andalusia | 1 |
| Vernon, Normandy | 1 |
| Township of Evan, KS | 1 |
| Madrid, Madrid | 1 |
| Bogotá, Bogota D.C. | 1 |
| Lyon, Auvergne-Rhône-Alpes | 1 |
| Lima, Lima | 1 |
| Aix-en-Provence, Provence-Alpes-Côte d'Azur | 1 |
| Trento, Trentino-Alto Adige | 1 |
| Le Chambon-Feugerolles, Auvergne-Rhône-Alpes | 1 |
| Antananarivo, Analamanga | 1 |
| Lure, Bourgogne-Franche-Comté | 1 |
| Ashkelon, Southern District | 1 |
| Veigné, Centre | 1 |
| Saint-Paul, Réunion | 2 |
| Mexico City, CDMX | 1 |
| León de los Aldama, GUA | 1 |
Community Discussion
Tips? Frustrations? Share them here. Useful comments include a description of the problem, city and postal code.
Beware of "support numbers" or "recovery" accounts that might be posted below. Make sure to report and downvote those comments. Avoid posting your personal information.
GitHub Issues Reports
Latest outage, problems and issue reports in social media:
-
pandemonium mode (@0x26_dev) reportedAi has raised the abstraction of the apocalyptic nightmare scenario. Now instead of global power or telecoms infrastructure being hacked it’s GPUs going down. Which means the bad guys aren’t nefarious infiltrators, it’s our own economic systems that are threat actors through unit economics. The zombie apocalypse is now a million vibe coders stuck with software they couldn’t even begin to understand. Bush survival is now understanding the difference between O(1) and O(2ⁿ). *** being distributed is not a bug. It is a feature. And anyone that tells you otherwise is full of ****. Bitcoin being decentralized makes it hard yes. Ethereum being decentralized is a nause, yes. But that exists for a reason. People have died on these hills for a reason. The reason GitHub was a bad idea is because it is centralized. Not because *** is decentralized.
-
Jarod (@not_jarod) reported@elijahmuraoka_ @github ok It does solves the problem of storing your "repo" but there are many things useful on github, like workflows, pr's commits, etc...
-
fantom (@fantom7z) reported@melvindvivas Chatgpt Pro, Claude Plus, Google One Pro, Chatgpt Pro in web make the plan and analyse my github, gemini execute. When gemini does it bad I ask Claude to fix the details
-
Zach Moskow (@zachmoskow) reported@austin_rief Just like cursor launching their GitHub killer the day GitHub went down
-
Rat King Crimson (@Alphiloscorp) reported@burkeholland Or mandate a poor usage pattern. I am presently staring down a likely impossible deadline for the project team that would be vastly assisted by use of the design product's MCP. Problem? We have Copilot for Github, but API keys and 3rd party MCPs are both blocked.
-
Anthony K (@Anthony_K81) reported@VKoukoutis The real smell is using a third-party SaaS as the control plane for ****. Seen too many teams where a GitHub issue becomes a deploy blocker. Do you keep an offline fallback or just accept the coupling?
-
Lone_billo :) (@HazariSoumyadip) reportedI am switching to codeberg not because I don't like github but the **** is happening there :) also I liked their anti ai policy so will be pushing all major projects in codeberg Later will make my own *** server for sure 🙃
-
Burak Topal (@ruzgarburak) reportedthey still couldn't ******* fix the github god save us
-
Vasilis Koukoutis (@VKoukoutis) reported@Anthony_K81 I’d accept some coupling, but I’d want an emergency path that doesn’t depend on the same control plane. Not a full parallel CI/CD stack — that’s probably overkill for most teams. Just enough to ship or roll back a critical production fix when GitHub isn’t available. Curious what fallback you’ve seen work well in practice.
-
Alexander Talavera Karslake (@AlexTKarslake) reported@EngineerIDE @acolombiadev LOL, I have so many repos on github though... I think almost 50. Some public goodies too, like the absolute best screenshot app for Mac (OSS). I don't want to move away, but the other day I was genuinely blocked for hours regarding a deployment. If I need to fix a critical bug...
-
Mister Salamander (@mr_salamander7) reported@GergelyOrosz I actually prefer GitHub bc I know Microsoft can't be training of my code there bc their platform is down most of the time
-
Dr. Josh C. Simmons (@drjoshcsimmons) reportedIf you are not technical: GitHub is where companies build, test, and deploy. When it goes down, production freezes. That is critical infrastructure owned by a visa factory.
-
The Blueprint Disruptor (@Lemonjello) reportedWill we get through today without a @github or @Railway issue?
-
Synthetic Beef (@SyntheticBeef) reported@SebAaltonen Or you can fix this with better processes. Set your project up with main branch protections on github, To merge a PR the ai must pass the performance benchmarks test suite where it runs your game and immediately jumps to the new content. If this passes the performance benchmark then it does a speedrun of all features. Your game should have debug controls that allow an ai to load the game into any state and configuration it wants. The ai should be told that a feature is not complete until it has registered the x,y,z,y,p,r,gamestate necessary to test the feature with a database whose purpose is to track features and states for performance testing. And if you design all of this as a combination of skills based on the /loop skill that spawn a wakeup timer before they begin, that only kills the timer when the PR is merged, it will loop every ask until it works per your constraints. Ai can and will do everything you ask if you are smart enough to know how to ask.
-
Rituraj (@RituWithAI) reported🚨BREAKING: GitHub's AI security tool just created the vulnerability it was supposed to prevent. And attackers exploited it within five days. Wiz Red Agent found that a GitHub Copilot Autofix patch to Snowflake's snowflake-connector-net repo on June 18, 2026 replaced a safe input pattern with raw string interpolation of a GitHub issue title, opening a shell-injection hole exploited within five days. Read that again. GitHub Copilot Autofix is the AI tool that scans your code, finds security vulnerabilities, and automatically patches them. It's marketed as making your codebase safer. It's built by the company that runs the world's largest code repository. It introduced a shell injection vulnerability into Snowflake's production codebase. Attackers found it. Exploited it. In five days. The security tool was the attack surface. Here's exactly what happened. Snowflake's snowflake-connector-net repo had a vulnerable pattern. Copilot Autofix detected it and generated an automated patch — the kind of one-click fix that millions of developers trust every day because it comes from GitHub's own AI security system. The patch replaced the vulnerable pattern. But in doing so, it introduced raw string interpolation of a GitHub issue title directly into a shell command. Any attacker who could control the title of a GitHub issue could now inject arbitrary shell commands into Snowflake's build pipeline. A conditional gate that checked pull_request.user.login evaluated true on issue events because pull_request was null, letting an unauthenticated attacker through. Unauthenticated. Anyone. No credentials required. The AI generated the fix. The fix was reviewed. The fix was merged. The fix was the vulnerability. Here's why this is more alarming than a standard security breach. When a human developer introduces a security vulnerability, it's a mistake. An oversight. A gap in knowledge or attention. When an AI security tool introduces a vulnerability, it's a systemic failure. Every developer who trusted Copilot Autofix's suggested patches — across every repo it touched — now has to ask: did it help or did it hurt? The entire value proposition of AI security tools is that they're more consistent than humans. They don't get tired. They don't miss things. They catch what developers overlook. Copilot Autofix didn't overlook a vulnerability. It created one. Then approved it. Then merged it into production. Here's the scale of what this means. GitHub Copilot Autofix is used across millions of repositories.Every automated security patch it has ever suggested is now under scrutiny. Not because developers should have caught it — but because the tool that was supposed to catch it was generating the problem. How many other Copilot Autofix patches introduced vulnerabilities that nobody has found yet? How many are sitting in production codebases right now, waiting for an attacker who bothers to look? Here's the brutal irony that nobody is saying out loud. This happened the same week GitHub Copilot switched to token-based billing. Developers are already angry about surprise charges for agentic sessions. Now the tool is also introducing shell injection vulnerabilities into their production code. You're paying more. For a tool that just compromised Snowflake. Here's what you should do right now. If your team uses GitHub Copilot Autofix — audit every automated patch it has merged in the last 90 days. Not just the ones that looked suspicious. All of them. The Snowflake patch looked clean. It passed review. It wasn't clean. The AI that was supposed to make your code safer just made it less safe. And it did it automatically. At scale. Without anyone noticing for five days.