Since yesterday a lot of users in Europe found their workflows failing due to Github seemingly randomly throwing HTTP/401 on git clone/git pull when interacting with public repos without authentication.

It was now confirmed by staff member that this indeed is intentional and no further steps are planned at this point.

top 50 comments

sorted by: hot top controversial new old
[–] [S] 125 points 1 month ago (16 children)
  • [–] 25 points 1 month ago (14 children)

    The word is “scrapers,” as in to scrape.

  • source
  • parent
  • hideshow 14 child comments
  • load more comments (10 replies)
  • [–] 77 points 1 month ago

    did microsoft just lock up a good chunk of open source behind a (stochastic (for now)) login wall?

    this feels like it should violate the gpl, but i bet it doesn't. truly devious.

  • source
  • [–] 60 points 1 month ago (17 children)

    Public GitHub repositories remain public and can still be accessed without a GitHub account, including repositories owned by paying customers. However, a subset of unauthenticated clone or fetch requests may now be asked to authenticate as part of GitHub’s protections against abusive traffic. If you receive a 401, update your application or script to use GitHub credentials.

    Uh okay.

  • source
  • hideshow 17 child comments
  • [–] 37 points 1 month ago (16 children)

    I wonder why people still keep up with this bullshit and not switch to some better public Git hosting provider.

  • source
  • parent
  • hideshow 16 child comments
  • [–] [S] 9 points 1 month ago (14 children)

    Could you suggest an alternative?

    I know Codeberg exists, but they had reliability problems recently IIRC?

    sr.ht and Gitlab are paid products.

    Technically one can self-host a forge, but my attempts at setting up CI were unsuccessful (IMO that's way more complicated that setting up the forge itself).

  • source
  • parent
  • hideshow 14 child comments
  • [–] 13 points 1 month ago (2 children)

    you can self host gitlab too, and its free. yes, you CAN buy a license, but you can run it free forever. you can also use their SaaS free forever too.

    at least right now, I think it's the best alternative, though I completely understand people wanting to favor OSS.

    disclaimer: I have contributed code to gitlab, but I am NOT an employee.

  • source
  • parent
  • hideshow 2 child comments
  • [–] 8 points 4 weeks ago (1 child)

    Their SaaS is pretty good but of course you are running the same chain trust. You're betting that gitlab doesn't enshittify within the next 5 years which is hardly a guarantee.

    Self-hosting gitlab is very resource-intense and complex from what I tried, though I did only try it two or three times.

    I did set up forgejo which was way easier and less heavy but I haven't tested it much so who knows.

  • source
  • parent
  • hideshow 1 child comment
  • load more comments (1 reply)
  • [–] 4 points 1 month ago

    Yes, they had reliability problems because so many fucking people are suddenly switching to them because they're so much better overall and not evil. Those are the kind of reliability problems that it is genuinely nice to see someone having. Having a little bit of a bumpy road when scaling due to significant rapid adoption is normal. So what?

    Imagine not wanting to use Linux because it recently had a bunch of security flaws. And it did. But again, so what? Does that mean Linux has always been insecure? Well for those things it was. But is it still insecure? Maybe, who knows, nothing is perfect. Are you going to refuse to use it because you're not sure? Why? Past performance is not an indicator of future success.

    If some minor reliability issues are your foremost concern to the point that the other things codeberg provides for free are not valuable to you because of it, I question the depth of your priorities.

    That said, it is much healthier and better for people to self-host or use smaller less centralized providers if possible. I do not wish Codeberg to become a victim of their own success, and a healthy ecosystem is a diverse one. But it is not for everyone, and if all you need is a minimal fuss alternative to Github, Codeberg is right there.

  • source
  • parent
  • [–] 5 points 4 weeks ago* (last edited 4 weeks ago)

    Can you help me find a solution that:

    1. I don’t have to self host
    2. Provides SSO
    3. Provides local and remote build agents and actions
    4. Allows me to store private proprietary code
    5. Supports static IPs for runners

    Number 4 rules out Codeberg. The only other one that really supports that level is Azure DevOps, and well….

  • source
  • parent
  • [–] 27 points 1 month ago

    Our aim is to make public repositories accessible without authentication as much as possible. However,...

    It's new reddit then. I was still using Github as a shitty backup for my projects, but an alternative may be required faster than expected.

  • source
  • [–] 24 points 4 weeks ago* (2 children)

    Holy crap this is huge!

    Open source is no longer open source on github.

  • source
  • hideshow 2 child comments
  • load more comments (2 replies)
    [–] 19 points 4 weeks ago (13 children)

    This might be a problem for many projects. Rust, comes to mind, that pulls everything from Github and is 100% dependent on it. Same as Go. They pull everything from Github.

    It might make sense for them to use something like radicle, a distributed git. Many people can easily pick what they want to distribute. Scripts can be written that make the local node only host the projects you depend on. That would naturally make popular projects more available.

  • source
  • hideshow 13 child comments
  • load more comments (3 replies)
    [–] 19 points 1 month ago* (2 children)

    I deleted my repos on github and moved to a mix of codeberg and selfhosted forgejo.

    But I do occasionally fork/clone/reupload random projects from github to github so they have to spend money on storage and the scrapers.

  • source
  • hideshow 2 child comments
  • [–] 16 points 4 weeks ago

    Embrace. Extend. Extinguish.

  • source
  • [–] 16 points 1 month ago (1 child)

    Time to leave github! Boycott is the only language companies understand!

  • source
  • hideshow 1 child comment
  • [–] 5 points 4 weeks ago

    Done a long time ago. It would be great if others at least had official mirrors. A mirrors.txt with a list of links in the repo would be very helpful and could be a start.

    But I'm afraid people will either just stay or start hosting on the cursor git forge.

  • source
  • parent
  • [–] 7 points 4 weeks ago (4 children)

    AI bot problem is real and there is no good solution to it. Look, I very much dislike GitHub for various reasons BUT currently there is no good way to throttle AI bots that literally trash web. They are like that geeky classmate who can never hold his liquors: it's nice having them around for some answers, but they ramble a lot and shit/puke in random places of the house making it unlivable.

  • source
  • hideshow 4 child comments
  • [–] 7 points 4 weeks ago (1 child)

    BUT currently there is no good way to throttle AI bots that literally trash web.

    Sure is. There are plenty of protocols resilient to DDOS.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 4 points 4 weeks ago

    DDOS is most effective on expensive endpoints. A git clone isn't exactly cheap. Fetching is especially expensive if you vary the revisions you fetch.

    Does GitHub have an alternative here? A Git-compatible protocol with anonymous access that is DDoS-resilient?

  • source
  • parent
  • load more comments (1 reply)
    [–] 7 points 1 month ago (2 children)

    I believe that it is some fuckup and they don't know where exactly problem is and while they are looking for a way to fix it they've created plausible lie. When they'll fix it or believe that it's fixed there would be a public announcement like 'we heard the community and reversed our decision' and users will be happy. There is a serious need for github mirror, they are becoming less and less stable every year.

  • source
  • hideshow 2 child comments
  • [–] [S] 13 points 1 month ago

    I'm 100% sure this is damage control on their part, they refused to acknowledge the incident and are looking for their way out.

    What users found in this thread is

    • problem is limited to EU
    • problem is limited to subset of git builds (gix version x TLS lib x TLS lib version in place)
    • problem goes away if you switch back to HTTP/1.1 for some reason

    If these are LLM scrapper mitigation steps then apparently fighting LLM scrappers is 7D chess game or something 🤷

  • source
  • parent
  • [–] 5 points 4 weeks ago (1 child)

    First time ever seeing color in a post title

  • source
  • hideshow 1 child comment
  • [–] 4 points 4 weeks ago (2 children)

    Our aim is to make public repositories accessible without authentication as much as possible. However, like much of the Internet, we continue to see significant increases in the volume of robot traffic recently which has increased the need for verification, for example CAPTCHAs.

    As I expected, it's about combating (excessive) bot traffic.

  • source
  • hideshow 2 child comments
  • load more comments
    view more: next ›