<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>devtake.dev — #github</title><description>Articles tagged github on devtake.dev.</description><link>https://devtake.dev/</link><language>en-us</language><item><title>VS Code&apos;s webview sandbox leaks GitHub tokens that read and write every private repo</title><link>https://devtake.dev/article/vscode-zero-day-github-token-theft/</link><guid isPermaLink="true">https://devtake.dev/article/vscode-zero-day-github-token-theft/</guid><description>A disclosed VS Code zero-day lets one click on a malicious github.dev notebook steal a GitHub OAuth token with full read-write access to every private repo.</description><pubDate>Wed, 03 Jun 2026 13:15:00 GMT</pubDate><category>security</category><category>security</category><category>github</category><category>credential-theft</category><category>dev-tools</category><category>rce</category><category>supply-chain</category><category>oauth</category><author>luca-reinhardt</author></item><item><title>Microsoft is shipping Linux&apos;s core commands on Windows, built in Rust</title><link>https://devtake.dev/article/microsoft-coreutils-windows-rust/</link><guid isPermaLink="true">https://devtake.dev/article/microsoft-coreutils-windows-rust/</guid><description>Microsoft&apos;s Coreutils for Windows brings native ls, cp, and grep to Windows, built on the Rust uutils project. Here&apos;s what it is and why the Rust rewrite matters.</description><pubDate>Wed, 03 Jun 2026 12:45:00 GMT</pubDate><category>open-source</category><category>open-source</category><category>rust</category><category>dev-tools</category><category>github</category><category>linux</category><author>soren-vanek</author></item><item><title>GitHub banned the researcher dropping Windows zero-days. The code was already mirrored everywhere.</title><link>https://devtake.dev/article/github-bans-researcher-windows-zero-day/</link><guid isPermaLink="true">https://devtake.dev/article/github-bans-researcher-windows-zero-day/</guid><description>GitHub wiped Nightmare-Eclipse&apos;s account on May 23 after weeks of unpatched Windows exploits. The ban reopened the oldest fight in security: who decides what research gets hosted?</description><pubDate>Fri, 29 May 2026 06:50:00 GMT</pubDate><category>security</category><category>security</category><category>github</category><category>vulnerability-disclosure</category><category>zero-day</category><category>microsoft</category><category>windows</category><category>supply-chain</category><category>rce</category><author>luca-reinhardt</author></item><item><title>Microsoft just open-sourced 86-DOS. Tim Paterson&apos;s 45-year-old listings are now on GitHub under MIT.</title><link>https://devtake.dev/article/microsoft-dos-historical-source-open-sourced/</link><guid isPermaLink="true">https://devtake.dev/article/microsoft-dos-historical-source-open-sourced/</guid><description>Yufeng Gao and Rich Cini scanned Tim Paterson&apos;s 1981 assembler printouts. Microsoft pushed them to DOS-History/Paterson-Listings on April 28, the 45th anniversary.</description><pubDate>Mon, 25 May 2026 12:30:00 GMT</pubDate><category>open-source</category><category>microsoft</category><category>ms-dos</category><category>86-dos</category><category>open-source</category><category>computer-history</category><category>github</category><category>mit-license</category><category>tim-paterson</category><author>soren-vanek</author></item><item><title>Karpathy posted four notes about Claude Code. The CLAUDE.md they spawned has 110K GitHub stars.</title><link>https://devtake.dev/article/karpathy-claude-md-github-trending/</link><guid isPermaLink="true">https://devtake.dev/article/karpathy-claude-md-github-trending/</guid><description>Forrest Chang turned Andrej Karpathy&apos;s January coding thread into a 70-line CLAUDE.md. It now has 110,000+ stars and has trended on GitHub for 28 weeks.</description><pubDate>Fri, 22 May 2026 10:30:00 GMT</pubDate><category>ai</category><category>andrej-karpathy</category><category>claude-code</category><category>claude</category><category>ai-agents</category><category>agentic-coding</category><category>ai-assistant</category><category>github</category><category>dev-tools</category><author>dieter-morelli</author></item><item><title>GitHub&apos;s internal repos were breached. The attacker came in through a poisoned VS Code extension.</title><link>https://devtake.dev/article/github-internal-repos-breach-vscode-extension/</link><guid isPermaLink="true">https://devtake.dev/article/github-internal-repos-breach-vscode-extension/</guid><description>GitHub detected the intrusion on May 18 after a malicious VS Code extension compromised an employee&apos;s device. The attacker claims to have exfiltrated 3,800 internal repositories.</description><pubDate>Fri, 22 May 2026 10:15:00 GMT</pubDate><category>security</category><category>security</category><category>github</category><category>vscode</category><category>supply-chain</category><category>credential-theft</category><category>dev-tools</category><author>luca-reinhardt</author></item><item><title>A CISA contractor left GovCloud admin keys on public GitHub. The file was named &apos;Important AWS Tokens.txt&apos;.</title><link>https://devtake.dev/article/cisa-aws-govcloud-keys-github-leak/</link><guid isPermaLink="true">https://devtake.dev/article/cisa-aws-govcloud-keys-github-leak/</guid><description>GitGuardian found a public CISA repo with 844 MB of secrets, including AWS GovCloud admin keys. The repo sat open for six months.</description><pubDate>Thu, 21 May 2026 11:15:00 GMT</pubDate><category>security</category><category>security</category><category>cisa</category><category>github</category><category>supply-chain</category><category>credential-theft</category><category>aws</category><category>gitguardian</category><category>govcloud</category><author>luca-reinhardt</author></item><item><title>RPCS3&apos;s maintainers will ban contributors who submit undisclosed AI pull requests</title><link>https://devtake.dev/article/rpcs3-ai-slop-pull-requests-policy/</link><guid isPermaLink="true">https://devtake.dev/article/rpcs3-ai-slop-pull-requests-policy/</guid><description>The PS3 emulator project posted on X on May 10, citing &apos;AI slop&apos; that has been clogging review. The hard line: ban-on-sight if you don&apos;t disclose.</description><pubDate>Mon, 11 May 2026 10:15:00 GMT</pubDate><category>open-source</category><category>open-source</category><category>rpcs3</category><category>emulator</category><category>github</category><category>ai-coding</category><category>ai-slop</category><category>playstation-3</category><category>contributors</category><author>soren-vanek</author></item><item><title>GitHub Copilot&apos;s Claude Opus multiplier jumps to 27x on June 1. Monthly plans dodge the hike.</title><link>https://devtake.dev/article/github-copilot-multiplier-hike-june-2026/</link><guid isPermaLink="true">https://devtake.dev/article/github-copilot-multiplier-hike-june-2026/</guid><description>GitHub&apos;s new model multiplier table for Copilot Pro and Pro+ annual plans lands June 1. Opus 4.6 goes 3 to 27. Sonnet 4.6 goes 1 to 9.</description><pubDate>Mon, 04 May 2026 10:45:00 GMT</pubDate><category>ai</category><category>github-copilot</category><category>github</category><category>ai-agents</category><category>pricing</category><category>microsoft</category><category>anthropic</category><category>claude-opus</category><category>dev-tools</category><author>dieter-morelli</author></item><item><title>Microsoft open-sourced the earliest known DOS code, transcribed from a stack of Tim Paterson&apos;s printouts.</title><link>https://devtake.dev/article/microsoft-dos-source-code-open-sourced/</link><guid isPermaLink="true">https://devtake.dev/article/microsoft-dos-source-code-open-sourced/</guid><description>MIT-licensed at GitHub on April 28, the 86-DOS 1.00 kernel and PC-DOS development snapshots were OCR&apos;d from 45-year-old assembler listings.</description><pubDate>Sun, 03 May 2026 12:45:00 GMT</pubDate><category>open-source</category><category>microsoft</category><category>dos</category><category>86-dos</category><category>open-source</category><category>retrocomputing</category><category>mit-license</category><category>github</category><category>tim-paterson</category><author>soren-vanek</author></item><item><title>Mitchell Hashimoto is pulling Ghostty off GitHub. The reason is daily outages.</title><link>https://devtake.dev/article/ghostty-leaving-github-mitchell-hashimoto/</link><guid isPermaLink="true">https://devtake.dev/article/ghostty-leaving-github-mitchell-hashimoto/</guid><description>Ghostty&apos;s creator has tracked GitHub outages every workday for months. After 18 years on the platform, he&apos;s moving the project. A read-only mirror stays.</description><pubDate>Wed, 29 Apr 2026 09:25:00 GMT</pubDate><category>open-source</category><category>ghostty</category><category>github</category><category>open-source</category><category>dev-tools</category><category>mitchell-hashimoto</category><category>terminal</category><category>hashicorp</category><author>soren-vanek</author></item><item><title>Wiz found an RCE in GitHub&apos;s git-push pipeline. The patch shipped in six hours.</title><link>https://devtake.dev/article/github-rce-cve-2026-3854-wiz/</link><guid isPermaLink="true">https://devtake.dev/article/github-rce-cve-2026-3854-wiz/</guid><description>CVE-2026-3854 is a CVSS 8.7 RCE in GitHub&apos;s git-push pipeline. github.com fixed it within hours. 88% of Enterprise Server installs were still vulnerable at disclosure.</description><pubDate>Wed, 29 Apr 2026 09:05:00 GMT</pubDate><category>security</category><category>github</category><category>security</category><category>cve-2026-3854</category><category>rce</category><category>supply-chain</category><category>wiz</category><category>github-actions</category><category>dev-tools</category><author>luca-reinhardt</author></item><item><title>GitHub Copilot kills premium requests on June 1. Token billing arrives, fallback models do not.</title><link>https://devtake.dev/article/github-copilot-usage-based-billing/</link><guid isPermaLink="true">https://devtake.dev/article/github-copilot-usage-based-billing/</guid><description>On June 1 every Copilot plan switches to GitHub AI Credits priced per token. Code completions stay free. Fallback models and credit rollover do not.</description><pubDate>Tue, 28 Apr 2026 11:00:00 GMT</pubDate><category>ai</category><category>github-copilot</category><category>github</category><category>ai-agents</category><category>pricing</category><category>microsoft</category><category>anthropic</category><category>claude-opus</category><category>dev-tools</category><author>dieter-morelli</author></item><item><title>Inside GitHub&apos;s fake star economy: 6 million bought stars and how to spot them</title><link>https://devtake.dev/article/github-fake-star-economy/</link><guid isPermaLink="true">https://devtake.dev/article/github-fake-star-economy/</guid><description>A Carnegie Mellon study counted 6 million suspected fake stars across 18,617 GitHub repos. Here&apos;s what the StarScout research actually found and how to read a star count now.</description><pubDate>Mon, 20 Apr 2026 16:00:00 GMT</pubDate><category>open-source</category><category>github</category><category>fake-stars</category><category>starscout</category><category>open-source</category><category>software-research</category><category>icse-2026</category><category>supply-chain</category><category>ai-repos</category><author>soren-vanek</author></item><item><title>A $5,000 open-source radar that sees 20 km, built by one engineer in Morocco</title><link>https://devtake.dev/article/aeris-10-open-source-radar-github/</link><guid isPermaLink="true">https://devtake.dev/article/aeris-10-open-source-radar-github/</guid><description>Nawfal Motii&apos;s Aeris-10 phased-array radar beats $250,000 commercial systems at 3% of the cost. Hardware, firmware, and FPGA bitstream are all on GitHub.</description><pubDate>Fri, 17 Apr 2026 13:00:00 GMT</pubDate><category>hardware</category><category>open-hardware</category><category>radar</category><category>github</category><category>fpga</category><category>phased-array</category><category>maker</category><category>cern-ohl</category><author>hiro-tanaka</author></item></channel></rss>