|
|
|
|
|
by woodruffw
2 days ago
|
|
GitHub's response time on malicious repositories is often lackluster. However, from conversations with folks at GitHub, my suspicion is that this is because they're being starved for resources, not incompetency or maliciousness. This (IMO) points to a perverse reality: things need to get worse before they can get better. In other words, Microsoft probably needs to feel more pain (in the form of negative revenue pressure) before they take their own platform responsibilities (vis a vis not distributing malware) seriously. We say this play out recently with improvements to GitHub Actions security, I expect we'll see the same here. (Edit: to be absolutely clear, I have first-hand experience that GitHub's security folks work extremely hard, and are often doing the kinds of invisible, thankless "deck-swabbing" work that nobody even thinks about. They're just under-resourced.) |
|
Is this happening? GitHub status page is a Christmas tree for 3 quarters and comically had an incident 10 minutes after the "we're working hard on fixing stability!" blog post published.
The free market has responded by buying GitHub Enterprise to avoid the incidents. So we've effectively rewarded GitHub's lack of serious engineering with more money. Doesn't seem like they have any real pressure to improve.