Skip to content

#GitHub

1 today

Jul 8Wednesday

Hacker News front page

GitLost: Researchers tricked GitHub's AI agent into leaking private repos

Noma Security tricked GitHub Copilot's AI coding agent into leaking private repo contents. They planted bait code in a public repo, then prompted the agent to recall context it had absorbed from a private repo, causing it to output snippets it shouldn't share. The attack exploits the agent's cross-repo memory. The post doesn't say whether GitHub has patched this yet. Worth noting: the attacker needs prior knowledge of what's in the private repo—this isn't indiscriminate leakage, but it exposes a real permission-boundary gap in AI coding tools.

Why it matters: A reproducible cross-repo memory attack that exposes a real permission-boundary gap in AI coding tools — practical warning for devs. Not scored higher because the attack requires prior knowledge of private repo contents, and the post doesn't disclose GitHub's response or fix t...

Jul 2Thursday

Hacker News front page

Kimi K2.7 Code is now generally available in GitHub Copilot as the first open-weight model option

GitHub Copilot added Kimi K2.7 Code to its model picker—the first open-weight model available. It runs on Microsoft Azure and is billed at provider list pricing under usage-based billing. Rollout starts with Pro/Pro+/Max plans; Business and Enterprise admins must enable it manually. The post doesn't disclose benchmark scores, only that GitHub will monitor quality and performance.

Why it matters: First open-weight model in Copilot's model picker — a real change to developer toolchains. Deployment details (Azure-hosted, usage-based billing at provider pricing) are new info. Score held back because the announcement provides zero benchmark data, so we can't assess code ca...

Jun 30Tuesday

Product Hunt · AI

v0 launches Design Systems 2.0, letting you import your team's real components, tokens, and Figma frames

v0 by Vercel now lets you import your existing design system from GitHub repos, public/private npm packages, Storybook docs, Figma frames, screenshots, and ZIPs. It learns how your system is used and creates a playground with your real components and tokens. You can preview, iterate in chat, and save when ready. The post doesn't clarify whether the imported system acts as a hard schema or just a reference—one commenter already asked what happens when the model hallucinates plausible but nonexistent prop names or reaches for deprecated variants still present in Storybook stories. No official reply yet.

Why it matters: The direction shift matters more than the feature itself: from generating UI for you to learning your design system first. Import paths are concrete, but the post doesn't answer the key question—is the imported system a hard constraint or soft reference? That determines whethe...

Jun 16Tuesday

Hacker News front page

Microsoft turns to AWS as GitHub faces AI capacity crunch

GitHub Copilot demand is outpacing Azure's GPU supply, so Microsoft signed a deal to rent Nvidia GPUs from AWS for inference and fine-tuning. The post doesn't disclose the number of GPUs, contract value, or migration timeline.

Why it matters: Microsoft renting AWS GPUs for Copilot is a strong signal. H and R are solid, K has substance but lacks numbers — no card count, contract value, or migration timeline disclosed, so it stays at 78 rather than pushing into the 85 band.

Hacker News front page

A LinkedIn job offer that backdoors you on npm install

A LinkedIn recruiter sent the author a GitHub repo to review. The repo hid a backdoor in app/test/index.js that triggers on npm install, fetching and executing remote commands from rest-icon-handler.store. Both the recruiter and the repo's commit author were impersonated—an arts journalist and an unwitting full-stack engineer. A read-only Pi agent flagged the payload in seconds. GitHub and LinkedIn had not acted at time of writing.

Why it matters: All three HKR axes hit. First-person experiment with a Pi agent finding a real npm backdoor, with concrete file paths and malicious URLs. Not a vendor case study — a dev's own story, which adds credibility. Capped below 85 because it's a personal security writeup, not an indus...

Jun 11Thursday

AI HOT (Curated Pool)

GitHub Copilot CLI gets real code intelligence via language servers

GitHub wired Copilot CLI into language servers via LSP, so terminal completions and diagnostics now read real project-level types, symbols, and references instead of relying purely on model guesses. A background LSP process runs locally; after the model generates code, the LSP returns diagnostics, completions, and hover info, which are fed back to the model for a second pass. GitHub says internal testing shows noticeably higher accuracy and fewer hallucinations. It currently works in VS Code and JetBrains, covering TypeScript/JavaScript, Python, Go, Rust, and C#. The post doesn't share specific benchmark numbers or a timeline for other editors.

Why it matters: GitHub wired language servers into Copilot CLI so terminal completions can read real project types and symbols instead of relying purely on model guesses. The mechanism is clear and backed by internal data, making it genuinely useful for CLI-heavy devs. Score stays at the feat...

Jun 10Wednesday

AI HOT (Curated Pool)

GitHub Copilot CLI Adds Custom AI Agents to Turn One-Off Terminal Prompts into Workflows

GitHub Copilot CLI added custom AI agents that understand a developer’s tech stack and team workflows; the post does not disclose configuration details, rollout scope, or pricing.

Why it matters: Official GitHub product update with HKR-H/R: custom Copilot CLI agents matter for developer workflows. HKR-K is weak because setup, rollout, and pricing are missing, so it sits at the featured threshold.

Jun 9Tuesday

AI HOT (Curated Pool)

AI coding unicorn Cursor picks London for European HQ; SpaceX holds $60B acquisition option

Cursor set its European headquarters in London and plans to hire about 200 people; SpaceX holds an option to acquire Cursor for $60 billion or pay $10 billion for a new partnership.

Why it matters: HKR-H/K/R all pass: Cursor is a core AI coding player, and the $60B option plus 200-person London expansion lifts this above routine office news. Thin sourcing and no disclosed trigger terms keep it below the 78 band.

AI HOT (Curated Pool)

GitHub 122K-star Skills adds Teach to turn a working directory into a stateful learning space

GitHub’s 122K-star Skills repository added Teach, which turns a working directory into a stateful learning space using MISSION.md, lessons/, learning-records/, and reference/ files to track goals, lessons, learned items, and reusable notes.

Why it matters: HKR-H/K/R pass via a concrete agent-memory workflow and named file structure, but the source is a single X summary with no benchmarks, maintainer detail, or user results, so it sits near the featured threshold.

AI HOT (Curated Pool)

Migrating GitHub CI to Hugging Face Jobs

Hugging Face describes using huggingface/jobs-actions to run GitHub Actions CI as HF Jobs, where the Trackio project cut CPU job time by about 30% and added a GPU test suite using CPU, t4-small, or h200 hardware.

Why it matters: HKR-H/K/R pass via a concrete CI-to-HF Jobs workflow, ~30% speedup, and GPU-test pain point. Scope is ML tooling, not a major platform release, so it sits at the featured threshold.

Jun 6Saturday

AI HOT (Curated Pool)

GitHub open-sources Spec Kit to guide AI coding with product specifications

GitHub released the open-source Spec Kit, shifting AI coding from direct implementation to product specifications, gap clarification, technical planning, task breakdown, and agent execution, with support for 30+ agent integrations including Copilot, Claude Code, Codex, Gemini, Cursor, and Qwen, and 109K+ GitHub stars.

Why it matters: HKR-H/K/R all pass: GitHub’s Spec Kit gives a concrete spec-first agent workflow plus 30+ integrations and 109K+ stars. It is a strong tooling story, not a model- or platform-level launch.

AI HOT (Curated Pool)

OpenCV 5 Released with New DNN Engine and Native LLM Support

OpenCV 5 introduces a graph-based DNN engine, raising ONNX operator coverage from under 23% in 4.x to over 80%, with native support for Transformer, VLM, and LLM workloads.

Why it matters: HKR-H/K/R all pass for a substantive OpenCV major release: graph DNN engine, ONNX coverage jump, and native Transformer/VLM/LLM support. Strong featured item, but below must-write model-lab release territory.

Jun 5Friday

Hacker News front page

Show HN: Lowfat – pluggable CLI filter saved 91.8% of my LLM tokens

Lowfat saved 4.1M of 4.4M raw tokens in the author’s two-month personal usage, running as an agent hook or shell wrapper to filter verbose CLI outputs from kubectl, docker, grep, and related commands.

Why it matters: HKR-H/K/R all pass: 91.8% savings is a strong hook, 4.1M/4.4M tokens plus the hook/wrapper mechanism add substance, and the cost/context pain is real for agent users. It is still a personal Show HN tool, so it stays near the featured threshold.

Jun 4Thursday

AI HOT (Curated Pool)

Miso One Open-Sources Voice Model: 8B Parameters, 110ms Latency, One-Shot Voice Cloning

Miso One released an 8B-parameter open-weight TTS model with one-shot voice cloning from a short sample, 110ms inference latency, GitHub self-hosting without an API, and local audio data handling; the post says API access is coming but does not disclose pricing or launch timing.

Why it matters: HKR-H/K/R all pass, but this is a single X-sourced launch with no benchmark suite, license detail, or third-party reproduction. The 8B, 110ms, self-hosted open TTS facts clear featured, not higher.

Jun 3Wednesday

Latent Space

GitHub's Plan for Agents — Kyle Daigle, GitHub

GitHub COO Kyle Daigle said AI-driven code commits grew 14x in 2026, and the interview covers Copilot, Actions, MCP, WorkIQ, cloud agents, and the infrastructure availability pressure created when code review, CI/CD, and open-source contribution volume scale beyond human-speed workflows.

Why it matters: HKR-H/K/R all pass: a GitHub executive gives a 14x AI code-submission figure and ties Copilot, Actions, MCP, WorkIQ, and cloud agents into one roadmap. Not a major release, so it stays at 80.

May 31Sunday

AI HOT (Curated Pool)

“What a joke”: GitHub Copilot’s new token-based billing draws developer backlash

GitHub Copilot changed billing to token-based metering, and the RSS snippet says developers are unhappy; the post does not disclose pricing, per-token rates, or the rollout date.

Why it matters: HKR-H/K/R all pass: Copilot’s token billing creates conflict, a concrete mechanism, and a cost nerve for developers. Missing price, unit economics, and start date keep it in the lower featured band.

May 22Friday

AI HOT (Curated Pool)

Karpathy’s CLAUDE.md Four Rules Raise AI Coding Accuracy to 94%

Karpathy published a 65-line CLAUDE.md with four rules that raised AI coding accuracy from 65% to 94%, and the file received over 220,000 GitHub stars.

Why it matters: HKR-H/K/R all pass: a notable name, a claimed accuracy jump, and a rules-based Claude Code workflow. It stays below 85 because the body only gives summary-level numbers; task set, evaluation method, and the four rules are not disclosed.

Hacker News front page

Show HN: Spec-Driven Development Workflow for Claude Code

The sddw author released a Claude Code plugin that splits work into requirements, code analysis, and design specs, then clears context after each step to keep cost and context focused.

Why it matters: HKR-H/K/R all pass for a Claude Code workflow with a concrete spec-and-context mechanism. It stays in the 72–77 featured band because the post lacks benchmarks, adoption data, or an official Anthropic release.

AI HOT (Curated Pool)

v2.1.147 Release Update

Claude Code v2.1.147 adds a Workflow tool, disabled by default, for deterministic multi-agent orchestration, and renames /simplify to /code-review with code-correctness reporting and GitHub PR inline-comment generation.

Why it matters: HKR-H/K/R all pass: the official Claude Code release adds a default-off Workflow tool for deterministic multi-agent orchestration. No performance data, pricing, or scope limits are disclosed, so this stays in the mid product-update band.

May 20Wednesday

AI HOT (Curated Pool)

Microsoft reportedly warns internally that GitHub faces existential risk as AI coding tools reduce hosting need

Microsoft internally warned that GitHub faces an existential risk from AI coding assistants such as Cursor and Claude Code, and told some teams to stop using Claude Code by the end of June 2026 and move to GitHub Copilot CLI.

Why it matters: HKR-H/K/R all pass: the angle is sharp, the summary gives a Claude Code-to-Copilot CLI deadline, and the workflow stakes are real. Single-source “reported” framing and no Microsoft response keep it below the 85 must-write band.

AI HOT (Curated Pool)

Smarter Google AI Edge Gallery: MCP Integration, Notifications, and Session Continuity

Google AI Edge Gallery adds experimental MCP support on Android, letting Gemma 4 coordinate external data sources including Google Workspace and Google Maps; the update also adds scheduled notifications and persistent chat history for faster restoration of long-session context.

Why it matters: HKR-H/K/R all pass: Google’s developer update adds experimental MCP, notifications, and session continuity to AI Edge Gallery. It is a mid-weight product update, not a model release or major capability launch.

May 19Tuesday

AI HOT (Curated Pool)

Take your local GitHub sessions anywhere

GitHub launched remote control sessions for Copilot, letting users start tasks in VS Code or the command line and continue them through github.com or GitHub Mobile.

Why it matters: GitHub Copilot session handoff from VS Code/CLI to web and mobile clears HKR-H/K/R, but the post only gives entry points and use case; permissions, pricing, and supported task scope are not disclosed.

May 15Friday

AI HOT (Curated Pool)

X open-sources the “For You” feed recommendation algorithm

X open-sourced the For You recommendation pipeline on GitHub, using a Grok-based Phoenix Transformer to score candidate posts and predict engagement probabilities such as likes, replies, and reposts.

Why it matters: HKR-H/K/R all pass, but the item only gives the open-source claim and Phoenix Transformer ranking mechanism; repo details, license, and reproducible tests are not disclosed, so it stays low-featured.

AI HOT (Curated Pool)

Feishu Open-Source CLI Tool Gets 10,000 Stars in 45 Days with Visible AI Operations

Feishu’s open-source lark-cli gained over 10,000 GitHub stars in 45 days, letting AI create groups and documents through the command line with each operation previewable and reviewable.

Why it matters: HKR-H/K/R all pass, but the source is a single social post and lacks usage, contributor, or adoption data. This fits the lower featured band for an open-source agent tool update.

May 14Thursday

AI HOT (Curated Pool)

WeChat Group Chat Summary Skill Added, Depends on wx-cli Configuration

baoyu-skills added a WeChat group chat summary Skill that depends on wx-cli for data reading; the post provides two GitHub links and says Claude Code plus Claude Opus 4.6 gives the best results.

Why it matters: A small open-source tool update, but the workflow is highly relevant: WeChat data via wx-cli into Claude Code for group summaries. HKR-H/K/R pass; limited detail keeps it at the featured threshold.

May 13Wednesday

AI HOT (Curated Pool)

GitHub Copilot Individual Plans Add Flex Allotments and a New Max Plan

GitHub will update Copilot individual plans on June 1 by adding flex allotments to Pro and Pro+ and introducing a new Max plan; the post does not disclose pricing, quota limits, or the exact allocation rules in the provided snippet.

Why it matters: HKR-H/K/R all land lightly because Copilot plan quotas affect many developers. Missing price, caps, and allocation rules keep it at the low featured threshold, not a major capability update.

May 12Tuesday

AI HOT (Curated Pool)

Dungeons & Desktops: Building a Procedurally Generated Roguelike with GitHub Copilot CLI

A GitHub employee used GitHub Copilot CLI to build an extension that parses any codebase into one Roguelike-style dungeon layout, with procedural level generation used as the core mechanism for a creative coding and game prototyping demo.

Why it matters: HKR-H and HKR-K pass: an official GitHub tutorial has a novel demo and a clear mechanism. It is not a major Copilot capability release, and lacks production metrics, pricing, or benchmark data, so it sits at the tutorial-featured floor.

May 11Monday

AI HOT (Curated Pool)

Anthropic open-sources full-stack financial AI templates

Anthropic open-sourced a financial services AI template library on GitHub, including 10 end-to-end agents, 7 vertical industry plugins, and MCP connectors for 11 financial data providers, with deployment paths from personal plugins to enterprise APIs and integrations for Microsoft 365 and private cloud.

Why it matters: HKR-H/K/R all pass: Anthropic shipped a reusable finance-agent template library with GitHub artifacts and concrete counts. It is not a model release, so it stays below 85, but the open-source MCP vertical stack clears featured.

AI HOT (Curated Pool)

Codex autonomously completes a security audit and earns a bounty

A user instructed Codex to earn $5; Codex spent about 22 hours finding an open-source security audit bounty, submitting a valid PR, communicating with maintainers, passing GitHub verification, and ultimately receiving a $16.88 payment.

Why it matters: HKR-H/K/R all pass: a Codex agent allegedly closed a bounty loop in 22 hours with concrete money and workflow details. Single social-post evidence lacks reproducible logs, so it stays below P1.

May 8Friday

AI HOT (Curated Pool)

OpenAI launches official openai-cli for terminal API calls

OpenAI open-sourced openai-cli for direct API calls from the terminal. The Apache 2.0 tool installs via Homebrew or Go and covers Responses API, structured output, image editing, transcription, and key config. The key detail is Agent workflows using cloud tools like web search and code interpreter.

Why it matters: HKR-H/K/R all pass: official OpenAI terminal tooling is clickable, with concrete install/license/API details and workflow resonance. It is still a developer tooling update, not a model or major capability release, so 76 fits the featured threshold.

AI HOT (Curated Pool)

Agent Pull Requests Are Everywhere: How to Review Them

GitHub published a guide for reviewing pull requests generated by AI agents. The snippet lists 3 focus areas: code changes, logic or security bugs, and pre-merge technical debt. The key issue is a review process before automated commits reach production.

Why it matters: HKR-H/K/R all pass: GitHub gives a practical checklist for agent-generated PRs with 3 review areas. It is guidance, not a product or model release, so it stays at the featured threshold.

AI HOT (Curated Pool)

DeepSeek 4: Flash Local Inference Engine for Metal

DeepSeek 4 Flash is open-sourced on GitHub for offline inference on Apple Silicon Macs. The post says it uses Metal Performance Shaders to reduce latency and memory use, but discloses no benchmark numbers. The key item is the Metal local inference stack, not another model wrapper.

Why it matters: HKR-H/K/R pass: the hook is offline Apple Silicon inference, with GitHub OSS, MPS, and a clear run target. No latency or memory benchmarks, and not an official DeepSeek model launch, so it stays near the featured floor.

May 5Tuesday

Xinzhiyuan · WeChat

$1 for 10 Stars: ICSE Paper Exposes Fake GitHub Star Market

CMU researchers scanned GitHub events from July 2019 to Dec. 2024, flagging 6 million suspected fake stars. StarScout ran on about 20 TiB and found 18,617 repositories and 301,000 accounts. The supply-chain risk is concrete: GitHub deleted 90.42% of flagged repos, and about 30% of live samples were spam, phishing, or malware.

Why it matters: HKR-H/K/R all pass: the hook is concrete, the study provides numbers and a detection mechanism, and GitHub trust is a practitioner nerve. Not a model or platform release, so it stays below the 85 must-write band.

May 4Monday

QbitAI · WeChat

DeepSeek-TUI, a “DeepSeek Claude Code,” reaches 2.3k GitHub stars

DeepSeek-TUI reached 2.3k GitHub stars; the Rust project is MIT-licensed. It targets DeepSeek V4 with a 1M-token context, RLM up to 16 V4 Flash subtasks, MCP, Shell, Git, and three control modes. Watch cache misses: uncached tokens cost 10x cached tokens.

Why it matters: HKR-H/K/R all pass: the hook is a DeepSeek-flavored Claude Code, with 2.3k stars, 1M tokens, 16 subtasks, and a 10x cache-miss cost gap. Impact is developer-specific, so it sits in the 72–77 band.

Apr 30Thursday

Xinzhiyuan · WeChat

AI Raw Proofs Pile Up on GitHub as Terence Tao Says Solving Alone Is Not Enough

Terence Tao says math is shifting from proof scarcity to proof abundance, with 20-plus AI solutions pending assessment on an Erdős problems GitHub page. The post says GPT-5.4 Pro generated an Erdős #1196 approach in 80 minutes, and Tao verified the core within 24 hours. The key issue is verification and digestion workflow, not raw proof count.

Why it matters: All HKR axes pass: Tao plus GitHub proof backlog gives HKR-H, while 20+ pending AI solutions and an 80-minute GPT-5.4 Pro claim give HKR-K. This is not a model release, so it stays below 85.

Apr 28Tuesday

Hacker News front page

GitHub Copilot code review will start consuming GitHub Actions minutes

GitHub will make Copilot code reviews consume GitHub Actions minutes starting June 1, 2026. Private-repo reviews use plan entitlements, with overages billed at standard Actions rates; public repos stay free. The change covers Copilot Pro, Pro+, Business, and Enterprise, including direct org billing for unlicensed users.

Why it matters: Official GitHub billing change for Copilot code review hits CI quotas and org invoices; HKR-H/K/R all pass, but it is a pricing rule, not a capability release, so it sits low in 72–77.

X · @dotey

GitHub Copilot switches to usage-based billing on June 1

GitHub Copilot will switch to AI Credits billing on June 1 while keeping subscription prices unchanged. Credits count input, output, and cached tokens; Pro includes $10 monthly credits and Pro+ includes $39. Watch Copilot Agent long-task costs.

Why it matters: HKR-H/K/R all pass: Copilot billing moves from subscription expectations to token/cache consumption with date and credit amounts. Single-source X context lacks enterprise details and overage rates, so it stays in the 78–84 band.

Hacker News front page

GitHub Copilot is moving to usage-based billing

GitHub said on 2026-04-27 that GitHub Copilot will move to usage-based billing. The captured post only shows the title, time, and navigation. It does not disclose the launch date, usage metric, prices, or overage rules.

Why it matters: GitHub Copilot billing affects a large developer base. HKR-H and HKR-R are strong, while HKR-K is limited to the usage-based mechanism with no date, metering unit, or price details disclosed.

Apr 25Saturday

Hacker News front page

Open-source memory layer Stash lets any AI agent do what Claude.ai and ChatGPT memory can do

Stash released an open-source persistent memory layer for AI agents, exposing 28 MCP tools and a 6-stage pipeline for long-term memory. The page says it uses PostgreSQL plus pgvector and hierarchical namespaces to separate user, project, and self memory. The real point is a portable memory layer, not the headline claim about matching ChatGPT or Claude.ai.

Why it matters: HKR-H/K/R all pass: the hook is portable long-term memory for any agent, and the page gives concrete architecture details. The score stays in the low featured band because this is an indie OSS infrastructure launch, not a major lab or platform release.

Apr 23Thursday

Hacker News front page

Coding Models Are Doing Too Much

The author programmatically corrupts 400 BigCodeBench problems with single-point bugs to test whether coding models over-edit code during fixes. The post defines the minimal fix as exactly reversing the corruption and measures excess changes with token-level Python Levenshtein distance. The provided body does not disclose final results, model rankings, or training gains.

Why it matters: Strong HKR-K from a concrete 400-task bug-injection eval and a clear minimal-patch metric. HKR-R also lands because over-editing is a daily pain point for Copilot/Cursor/Claude Code users, but the excerpt omits results, model rankings, and effect sizes, so this sits near the low