Constance Bello

Rebel technologist

About / Blog (List of tags)


Resources I use:

Posts tagged with "data sovereignty"

GitHub and enshittification

2026-05-14 / updated 2026-06-17 / tags: big tech, data sovereignty, github, microsoft, sidebar updates, ai

The GitHub logo paired with the enshittification icon (a poop emoji with eyes and a censorship bar where its mouth would be).

The open source software ecosystem collectively putting all its eggs in one basket may not have been the best decision.

I'm going to start with a brief timeline of events.
June 29, 2021: GitHub launches Copilot Technical Preview (Wayback Machine link).
June 30, 2022: The Software Freedom Conservancy launches their Give Up GitHub campaign, in response to GitHub and Microsoft's refusal to engage with critiques of their use of publicly available code uploaded to GitHub for training Copilot models regardless of how that code is licensed.
August 11, 2025: GitHub CEO Thomas Dohmke resigns, and Microsoft folds it into its CoreAI group, eliminating GitHub's independence from Microsoft management (paywalled link).
April 28, 2026: GitHub CTO Vlad Fedorov apologizes for serious issues GitHub had on April 23 and April 27 that brought usage to a complete halt twice in one week.
April 28, 2026: The same day, HashiCorp cofounder Mitchell Hashimoto says GitHub is "no longer a place for serious work" in his blog post announcing the migration of the Ghostty project to another hosted git platform. Damningly, the decision to migrate Ghostty was made before the April 27 outage.
May 4, 2026: dayswithoutgithubincident.com is posted to Hacker News. When I first saw it, it showed 0 days since last incident; as of writing, it shows 1. It's also got a neat little "High Score" widget, showing the longest streak of days in 2026 with no incidents (6, from April 2 to April 9).


You might notice a trend here, which is tied together by that word Cory Doctorow coined and I've included in the title of this post[1]. Priorities undoubtedly changed for GitHub once they were acquired by Microsoft back in June 2018, first slowly, then quickly. The AI bubble has needed significant engineering effort to sustain itself, which Redmond was more than happy to allocate when GitHub was all upside; seemingly limitless access to training data for AI coding models, vendor lock-in for thousands upon thousands of widely used open source projects, and a breezy talent pipeline to push engineers from GitHub enthusiasts to Azure DevOps professionals.
So much for "embrace, extend, extinguish"; right now it looks more like GitHub has exploded and everyone else is sprinting away.
The downsides to the world's reliance on Silicon Valley for critical services are making themselves more and more apparent over time. When Karim Khan, a prosecutor at the International Criminal Court, was blocked from accessing Microsoft services following the Trump administration placing sanctions on the ICC, a lot of people all over the world took notice. Digital sovereignty isn't a pie-in-the-sky ideal anymore – for many organizations, it's a base requirement urgently needing to be met.
I recently came across this post entitled "Why I'm leaving GitHub for Forgejo" that makes a lot of salient points related to these topics. I encourage you to read it and come back here when you're done. I'll highlight a specific idea pointed out by the author, Jorijn Schrijvershof, that isn't getting enough airtime:

The reliability story is downstream of the AI story. GitHub is not slowing down on AI features. It is doubling down on them. The outages are what doubling-down looks like in production.

The AI bullshit is wrecking the actual reason people ever came to GitHub in the first place: to come together and make software. These sort of antics were telegraphed in 2018, but decision makers were not listening to pundits in comments sections ranting about how it's time to move off of GitHub. Those network effects are strong, and concerns about espionage, software supply chain attacks, and managerial trust that were voiced in HN comments didn't reach the ears of decision makers. Now that organizations' bottom lines are being hit, whether their attitudes will change remains to be seen, but it seems clear now that to know who will burn you tomorrow, you should investigate who smells smokey today.


Speaking of Cory Doctorow, my initial sidebar had some glaring omissions. These have been rectified, as I have now added:

I could say a lot about Cory Doctorow and how much he's influenced my thinking and action, and I likely will at many points as I get further into this blogging thing.
Addie LaMarr's YouTube channel contains plenty of useful resources for folks wanting to get up to speed on seeing past cybersecurity hype and getting to the real heart of the matter.
Good Work just won a few Webby awards for their disgusting(ly hilarious) videos drilling down into such topics as "why is oil still such a big deal?" and "what does {Meta,Palantir,Oracle} actually do?" Oh, and peptides. Being in New York, a lot of the tech industry happenings I interact with get exported from the Bay Area, so having Dan and co help me recognize that, no, I'm not insane, everything really is that ridiculous is super helpful.
While I've got my sights on Microsoft, maybe next time I could talk about their irresponsible security posture, evidenced by a newly revealed exploit that unlocks any BitLocker drive by copying some files to it. Until then...


Addendum 6/17/2026: It was reported two nights ago that Microsoft is now buying compute from Amazon to keep GitHub afloat. So much for GitHub being a strategic asset to acquire...

  1. For the uninitiated.