<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>devtake.dev — GitHub</title><description>Articles on devtake.dev covering GitHub.</description><link>https://devtake.dev/</link><language>en-us</language><item><title>Red Hat&apos;s npm namespace and Arch&apos;s AUR were both backdoored within two weeks of each other</title><link>https://devtake.dev/article/npm-registry-supply-chain-wave/</link><guid isPermaLink="true">https://devtake.dev/article/npm-registry-supply-chain-wave/</guid><description>A worm hijacked Red Hat&apos;s npm namespace, a rootkit spread through 1,500 Arch AUR packages, and a SOC 2-certified AI gateway shipped malware. Registries are under fire.</description><pubDate>Sat, 13 Jun 2026 12:45:00 GMT</pubDate><category>security</category><category>security</category><category>supply-chain</category><category>npm</category><category>open-source</category><category>malware</category><author>luca-reinhardt</author></item><item><title>GitHub banned the researcher dropping Windows zero-days. The code was already mirrored everywhere.</title><link>https://devtake.dev/article/github-bans-researcher-windows-zero-day/</link><guid isPermaLink="true">https://devtake.dev/article/github-bans-researcher-windows-zero-day/</guid><description>GitHub wiped Nightmare-Eclipse&apos;s account on May 23 after weeks of unpatched Windows exploits. The ban reopened the oldest fight in security: who decides what research gets hosted?</description><pubDate>Fri, 29 May 2026 06:50:00 GMT</pubDate><category>security</category><category>security</category><category>github</category><category>vulnerability-disclosure</category><category>zero-day</category><category>microsoft</category><category>windows</category><category>supply-chain</category><category>rce</category><author>luca-reinhardt</author></item><item><title>SQLite won&apos;t accept AI-written code, but QEMU just opened the door to it</title><link>https://devtake.dev/article/sqlite-refuses-agentic-code-qemu-opens-door/</link><guid isPermaLink="true">https://devtake.dev/article/sqlite-refuses-agentic-code-qemu-opens-door/</guid><description>Two of the most cautious C projects split on AI contributions in the same week. The real fight is over copyright provenance and who cleans up the slop.</description><pubDate>Fri, 29 May 2026 05:35:00 GMT</pubDate><category>open-source</category><category>open-source</category><category>sqlite</category><category>qemu</category><category>ai-coding</category><category>agentic-coding</category><category>maintainers</category><category>licensing</category><category>llm</category><author>soren-vanek</author></item><item><title>Microsoft is canceling Claude Code for its engineers. They have until June 30 to switch to Copilot CLI.</title><link>https://devtake.dev/article/microsoft-cancels-claude-code-licenses/</link><guid isPermaLink="true">https://devtake.dev/article/microsoft-cancels-claude-code-licenses/</guid><description>Internal Claude Code licenses end June 30, 2026, for Microsoft&apos;s Experiences + Devices group. Engineers move to GitHub Copilot CLI instead.</description><pubDate>Sat, 23 May 2026 10:00:00 GMT</pubDate><category>ai</category><category>microsoft</category><category>anthropic</category><category>claude-code</category><category>github-copilot</category><category>copilot-cli</category><category>ai-assistant</category><category>agentic-coding</category><author>dieter-morelli</author></item><item><title>Karpathy posted four notes about Claude Code. The CLAUDE.md they spawned has 110K GitHub stars.</title><link>https://devtake.dev/article/karpathy-claude-md-github-trending/</link><guid isPermaLink="true">https://devtake.dev/article/karpathy-claude-md-github-trending/</guid><description>Forrest Chang turned Andrej Karpathy&apos;s January coding thread into a 70-line CLAUDE.md. It now has 110,000+ stars and has trended on GitHub for 28 weeks.</description><pubDate>Fri, 22 May 2026 10:30:00 GMT</pubDate><category>ai</category><category>andrej-karpathy</category><category>claude-code</category><category>claude</category><category>ai-agents</category><category>agentic-coding</category><category>ai-assistant</category><category>github</category><category>dev-tools</category><author>dieter-morelli</author></item><item><title>GitHub&apos;s internal repos were breached. The attacker came in through a poisoned VS Code extension.</title><link>https://devtake.dev/article/github-internal-repos-breach-vscode-extension/</link><guid isPermaLink="true">https://devtake.dev/article/github-internal-repos-breach-vscode-extension/</guid><description>GitHub detected the intrusion on May 18 after a malicious VS Code extension compromised an employee&apos;s device. The attacker claims to have exfiltrated 3,800 internal repositories.</description><pubDate>Fri, 22 May 2026 10:15:00 GMT</pubDate><category>security</category><category>security</category><category>github</category><category>vscode</category><category>supply-chain</category><category>credential-theft</category><category>dev-tools</category><author>luca-reinhardt</author></item><item><title>A CISA contractor left GovCloud admin keys on public GitHub. The file was named &apos;Important AWS Tokens.txt&apos;.</title><link>https://devtake.dev/article/cisa-aws-govcloud-keys-github-leak/</link><guid isPermaLink="true">https://devtake.dev/article/cisa-aws-govcloud-keys-github-leak/</guid><description>GitGuardian found a public CISA repo with 844 MB of secrets, including AWS GovCloud admin keys. The repo sat open for six months.</description><pubDate>Thu, 21 May 2026 11:15:00 GMT</pubDate><category>security</category><category>security</category><category>cisa</category><category>github</category><category>supply-chain</category><category>credential-theft</category><category>aws</category><category>gitguardian</category><category>govcloud</category><author>luca-reinhardt</author></item><item><title>Bun&apos;s million-line Rust rewrite is now mainline. 99.8% of tests pass and 13,000 unsafe blocks remain.</title><link>https://devtake.dev/article/bun-rust-rewrite-merged/</link><guid isPermaLink="true">https://devtake.dev/article/bun-rust-rewrite-merged/</guid><description>Jarred Sumner merged the Bun-in-Rust PR on May 14, ending Zig as Bun&apos;s runtime language. Binary shrinks 3-8 MB; one analysis counted 13,000 unsafe blocks.</description><pubDate>Fri, 15 May 2026 09:15:00 GMT</pubDate><category>open-source</category><category>bun</category><category>rust</category><category>zig</category><category>javascript</category><category>runtime</category><category>anthropic</category><category>claude-code</category><category>agentic-coding</category><author>soren-vanek</author></item><item><title>TanStack published its npm supply-chain postmortem. The attack chained three GitHub Actions flaws.</title><link>https://devtake.dev/article/tanstack-npm-supply-chain-postmortem/</link><guid isPermaLink="true">https://devtake.dev/article/tanstack-npm-supply-chain-postmortem/</guid><description>Attackers compromised 42 TanStack packages through a pull_request_target exploit, cache poisoning, and OIDC token theft. An external researcher caught it in 20 minutes.</description><pubDate>Tue, 12 May 2026 10:15:00 GMT</pubDate><category>security</category><category>security</category><category>supply-chain</category><category>npm</category><category>tanstack</category><category>github-actions</category><category>credential-theft</category><category>dev-tools</category><author>luca-reinhardt</author></item><item><title>GitLab is cutting staff and killing its CREDIT values. The CEO calls it &apos;Act 2.&apos;</title><link>https://devtake.dev/article/gitlab-act-2-workforce-reduction/</link><guid isPermaLink="true">https://devtake.dev/article/gitlab-act-2-workforce-reduction/</guid><description>CEO Bill Staples announced a restructuring he frames around agentic AI, retiring GitLab&apos;s six core values for three new operating principles. Exact layoff numbers come June 2.</description><pubDate>Tue, 12 May 2026 10:00:00 GMT</pubDate><category>web</category><category>gitlab</category><category>layoffs</category><category>restructuring</category><category>ai-agents</category><category>dev-tools</category><category>devops</category><category>agentic-coding</category><author>naomi-park</author></item><item><title>RPCS3&apos;s maintainers will ban contributors who submit undisclosed AI pull requests</title><link>https://devtake.dev/article/rpcs3-ai-slop-pull-requests-policy/</link><guid isPermaLink="true">https://devtake.dev/article/rpcs3-ai-slop-pull-requests-policy/</guid><description>The PS3 emulator project posted on X on May 10, citing &apos;AI slop&apos; that has been clogging review. The hard line: ban-on-sight if you don&apos;t disclose.</description><pubDate>Mon, 11 May 2026 10:15:00 GMT</pubDate><category>open-source</category><category>open-source</category><category>rpcs3</category><category>emulator</category><category>github</category><category>ai-coding</category><category>ai-slop</category><category>playstation-3</category><category>contributors</category><author>soren-vanek</author></item><item><title>VS Code shipped &apos;Co-Authored-by Copilot&apos; on every commit by default. Microsoft is reverting it.</title><link>https://devtake.dev/article/vscode-ai-coauthor-default-pr-310226/</link><guid isPermaLink="true">https://devtake.dev/article/vscode-ai-coauthor-default-pr-310226/</guid><description>A two-line PR flipped the AI co-author flag from off to all in April. Hand-typed commits started getting Copilot attribution. The maintainer apologized and promised a fix in 1.119.</description><pubDate>Tue, 05 May 2026 09:15:00 GMT</pubDate><category>web</category><category>github-copilot</category><category>vscode</category><category>microsoft</category><category>dev-tools</category><category>ai-coauthor</category><category>git</category><category>javascript</category><category>ai-assistant</category><author>luca-reinhardt</author></item><item><title>GitHub Copilot&apos;s Claude Opus multiplier jumps to 27x on June 1. Monthly plans dodge the hike.</title><link>https://devtake.dev/article/github-copilot-multiplier-hike-june-2026/</link><guid isPermaLink="true">https://devtake.dev/article/github-copilot-multiplier-hike-june-2026/</guid><description>GitHub&apos;s new model multiplier table for Copilot Pro and Pro+ annual plans lands June 1. Opus 4.6 goes 3 to 27. Sonnet 4.6 goes 1 to 9.</description><pubDate>Mon, 04 May 2026 10:45:00 GMT</pubDate><category>ai</category><category>github-copilot</category><category>github</category><category>ai-agents</category><category>pricing</category><category>microsoft</category><category>anthropic</category><category>claude-opus</category><category>dev-tools</category><author>dieter-morelli</author></item><item><title>Zed 1.0 ships its agentic editor. The Atom team&apos;s Rust rewrite finally has a stable label.</title><link>https://devtake.dev/article/zed-1-0-rust-editor-launch/</link><guid isPermaLink="true">https://devtake.dev/article/zed-1-0-rust-editor-launch/</guid><description>Zed Industries shipped 1.0 on April 29 after five years of Rust and GPU work. Free forever for humans, with $10/month hosted AI and an open Agent Client Protocol.</description><pubDate>Thu, 30 Apr 2026 09:30:00 GMT</pubDate><category>open-source</category><category>zed</category><category>rust</category><category>dev-tools</category><category>agentic-coding</category><category>open-source</category><category>cursor</category><category>code-editors</category><category>ai-assistant</category><author>soren-vanek</author></item><item><title>Mitchell Hashimoto is pulling Ghostty off GitHub. The reason is daily outages.</title><link>https://devtake.dev/article/ghostty-leaving-github-mitchell-hashimoto/</link><guid isPermaLink="true">https://devtake.dev/article/ghostty-leaving-github-mitchell-hashimoto/</guid><description>Ghostty&apos;s creator has tracked GitHub outages every workday for months. After 18 years on the platform, he&apos;s moving the project. A read-only mirror stays.</description><pubDate>Wed, 29 Apr 2026 09:25:00 GMT</pubDate><category>open-source</category><category>ghostty</category><category>github</category><category>open-source</category><category>dev-tools</category><category>mitchell-hashimoto</category><category>terminal</category><category>hashicorp</category><author>soren-vanek</author></item><item><title>Wiz found an RCE in GitHub&apos;s git-push pipeline. The patch shipped in six hours.</title><link>https://devtake.dev/article/github-rce-cve-2026-3854-wiz/</link><guid isPermaLink="true">https://devtake.dev/article/github-rce-cve-2026-3854-wiz/</guid><description>CVE-2026-3854 is a CVSS 8.7 RCE in GitHub&apos;s git-push pipeline. github.com fixed it within hours. 88% of Enterprise Server installs were still vulnerable at disclosure.</description><pubDate>Wed, 29 Apr 2026 09:05:00 GMT</pubDate><category>security</category><category>github</category><category>security</category><category>cve-2026-3854</category><category>rce</category><category>supply-chain</category><category>wiz</category><category>github-actions</category><category>dev-tools</category><author>luca-reinhardt</author></item><item><title>GitHub Copilot kills premium requests on June 1. Token billing arrives, fallback models do not.</title><link>https://devtake.dev/article/github-copilot-usage-based-billing/</link><guid isPermaLink="true">https://devtake.dev/article/github-copilot-usage-based-billing/</guid><description>On June 1 every Copilot plan switches to GitHub AI Credits priced per token. Code completions stay free. Fallback models and credit rollover do not.</description><pubDate>Tue, 28 Apr 2026 11:00:00 GMT</pubDate><category>ai</category><category>github-copilot</category><category>github</category><category>ai-agents</category><category>pricing</category><category>microsoft</category><category>anthropic</category><category>claude-opus</category><category>dev-tools</category><author>dieter-morelli</author></item><item><title>GitHub Copilot paused new signups and kicked Opus out of Pro. Here&apos;s what actually changed.</title><link>https://devtake.dev/article/github-copilot-pro-plan-changes/</link><guid isPermaLink="true">https://devtake.dev/article/github-copilot-pro-plan-changes/</guid><description>GitHub froze Copilot Pro/Pro+/Student signups on April 20 and moved Claude Opus 4.7 behind the $39 Pro+ tier. Agent workflows broke the old math.</description><pubDate>Wed, 22 Apr 2026 11:30:00 GMT</pubDate><category>ai</category><category>github-copilot</category><category>anthropic</category><category>microsoft</category><category>claude-opus</category><category>ai-agents</category><category>pricing</category><category>dev-tools</category><author>dieter-morelli</author></item><item><title>protobuf.js RCE: a 52M/week npm package was one bad type name from code execution</title><link>https://devtake.dev/article/protobuf-javascript-rce-cve/</link><guid isPermaLink="true">https://devtake.dev/article/protobuf-javascript-rce-cve/</guid><description>GHSA-xq3m-2v4x-88gg hits protobuf.js ≤8.0.0 / ≤7.5.4. Attacker-controlled schemas executed arbitrary JS on decode. One-line fix patched it.</description><pubDate>Tue, 21 Apr 2026 12:00:00 GMT</pubDate><category>security</category><category>npm</category><category>protobuf</category><category>javascript</category><category>supply-chain</category><category>rce</category><category>endor-labs</category><category>grpc</category><author>luca-reinhardt</author></item><item><title>Inside GitHub&apos;s fake star economy: 6 million bought stars and how to spot them</title><link>https://devtake.dev/article/github-fake-star-economy/</link><guid isPermaLink="true">https://devtake.dev/article/github-fake-star-economy/</guid><description>A Carnegie Mellon study counted 6 million suspected fake stars across 18,617 GitHub repos. Here&apos;s what the StarScout research actually found and how to read a star count now.</description><pubDate>Mon, 20 Apr 2026 16:00:00 GMT</pubDate><category>open-source</category><category>github</category><category>fake-stars</category><category>starscout</category><category>open-source</category><category>software-research</category><category>icse-2026</category><category>supply-chain</category><category>ai-repos</category><author>soren-vanek</author></item><item><title>Ruby Central admits &apos;real financial jeopardy&apos; seven months after the RubyGems takeover</title><link>https://devtake.dev/article/ruby-central-rubygems-financial-crisis/</link><guid isPermaLink="true">https://devtake.dev/article/ruby-central-rubygems-financial-crisis/</guid><description>Ruby Central cut its executive director, CFO, and PR firm, and shifted to a volunteer working board. The April 16 letter closes the arc from September&apos;s RubyGems walkout.</description><pubDate>Mon, 20 Apr 2026 12:00:00 GMT</pubDate><category>open-source</category><category>ruby</category><category>rubygems</category><category>ruby-central</category><category>bundler</category><category>gem-cooperative</category><category>shopify</category><category>open-source-governance</category><author>soren-vanek</author></item><item><title>Trivy got hijacked: 75 of 76 version tags rewrote to drop a CI secret-stealer</title><link>https://devtake.dev/article/trivy-supply-chain-attack-compromise/</link><guid isPermaLink="true">https://devtake.dev/article/trivy-supply-chain-attack-compromise/</guid><description>Attackers force-pushed 75 of 76 trivy-action tags to a malicious commit. Pinning by tag turned a trusted scanner into an infostealer for CI pipelines.</description><pubDate>Sat, 18 Apr 2026 08:30:00 GMT</pubDate><category>security</category><category>supply-chain</category><category>trivy</category><category>aqua-security</category><category>github-actions</category><category>cicd</category><category>devsecops</category><category>teampcp</category><author>luca-reinhardt</author></item></channel></rss>