November 2025: Three incidents degrade GitHub services
GitHub recorded three incidents in November 2025 that caused degraded performance across its services. Two incidents were resolved within a couple of hours; the third lasted roughly two and a half hours.
Dependabot rate-limited by GHCR
On November 17, from 16:52 to 19:08 UTC, Dependabot ran into a rate limit in GitHub Container Registry (GHCR), preventing roughly 57% of jobs from completing within SLO. Operators reduced the rate at which Dependabot starts jobs and raised the GHCR rate limit, which brought the incident to a close.
Longer-term work includes new monitors and alerts aimed at preventing a recurrence.
Expired TLS certificate breaks Git operations
From 20:30 to 21:34 UTC on November 18, all Git operations failed—SSH and HTTP client interactions plus raw file access—along with dependent products. The cause was an expired TLS certificate used for internal service-to-service communication. Replacing the certificate and restarting affected services restored full functionality.
GitHub has updated alerting to cover the expired certificate and is auditing other certificates in the area to confirm they have similar alerting and automation ahead of expiration. The company is also accelerating efforts to eliminate remaining manually managed certificates so all service-to-service communication is fully automated.
Copilot loses Claude Sonnet 4.5
Between approximately 05:59 and 08:24 UTC on November 28, Copilot users trying to use the Claude Sonnet 4.5 model received an HTTP 400 error stating no model was available until they picked another one. Other models were unaffected. A misconfiguration in an internal service marked Claude Sonnet 4.5 as unavailable; reverting the configuration change resolved the issue. Work is underway to improve cross-service deployment safeguards against similar incidents.



