GitHub header

Incident with Codespaces and API Requests

Incident Report for GitHub

Resolved

On December 26, 2023, GitHub received a report through our Bug Bounty Program demonstrating a vulnerability which, if exploited, allowed access to credentials within a production container. We fixed this vulnerability on GitHub.com the same day and began rotating all potentially exposed credentials. Through this process we found some flaws in how we rotate certain credentials and are working on improving our credential rotation process. More detail can be found on our blog: https://github.blog/2024-01-16-rotating-credentials-for-github-com-and-new-ghes-patches/
Posted Dec 27, 2023 - 03:06 UTC

Update

Codespaces is operating normally.
Posted Dec 27, 2023 - 03:06 UTC

Investigating

We are investigating reports of degraded performance for Codespaces and API Requests
Posted Dec 27, 2023 - 02:51 UTC
This incident affected: API Requests and Codespaces.