The RCA and preventive measures was a pleasant read. I got a lot of respect for companies putting a lot of effort into incident reports like these. Makes them appear very professional rather than just blaming the cloud provider outright.
We just invested a lot migrating 300+ pipelines from Azure DevOps to GitHub Actions. What a bummer timing-wise. Anyone got an alternative to GitHub Actions?
I'd suggest not buying in too hard on any one of these CI systems and just writing shell scripts. Shell scripts are portable, and you can use whatever to trigger them.
The article refers to their GH repo and that was all cherry and sunshine up until just recently, where it is redirected to https://github.com/LobsterTrap/lola.
No mention of it anywhere. "Did it get compromised?" was my initial thought. Still in the fog here.
Windows is just a wonderful box of chocolate that keeps expanding. You never know what you get, all brilliant frontier tech innovations like Edge, Bing, the calculator, vertical taskbar, and now the highly intelligent Copilot, up there fighting with OpenCode, CC and others...!
reply