GitHub's plan for Agents — Kyle Daigle, GitHub

Latent Space: The AI Engineer Podcast
2 June 2026 1h 23m
0:00 --:--
Episode Description
I’m excited to work with Microsoft once again as the presenting sponsors of the AI Engineer World’s Fair! We’ll streaming live from MS Build today for a special crossover pod with our friends at No Priors and the one and only Satya Nadella. However we did not hold back with this interview - we asked all the burning questions about uptime and Copilot that we know you have in your minds. Lets go!For almost two decades, GitHub has been the home of software, where both open source and closed flow, t

Summary

Kyle Daigle, COO of GitHub and CMO of Microsoft Developer, discusses how AI agents and micro-skills are transforming developer workflows and internal operations at GitHub. He addresses the unprecedented 14x growth in commits, detailing the scaling challenges and re-architecture efforts for GitHub's infrastructure. The episode also explores the evolution of GitHub Copilot, the concept of ambient AI, and Microsoft's strategic investment in projects like OpenClaw to build new AI operating system components.

Chapters

Kyle Daigle's Expanded RoleKyle Daigle, COO of GitHub, now also serves as CMO of Microsoft Developer, leveraging his developer-centric approach across Microsoft's broader ecosystem.
AI's Impact on Leadership ProductivityKyle explains how AI has enabled him to return to coding and build agents that connect disparate data sources, significantly boosting his productivity and allowing him to manage a large organization more effectively.
Managing AI Skills and WorkflowsThe discussion shifts to the philosophy of using 'micro skills' as modular building blocks for AI workflows, emphasizing flexibility over monolithic 'mega skills' for diverse professional needs.
Golden Age for Developer LeadersKyle argues that AI tools empower former developers in leadership roles to apply their pattern-finding and problem-solving skills, enhancing their effectiveness in both coding and business.
GitHub's History and Open Source SecurityA look back at GitHub's major milestones, including the launch of Actions and the acquisition of NPM, leading into a discussion on open source security challenges and the balance between security and community flexibility.
Codifying Trust in AI DevelopmentThe conversation explores the social problem of trust in pull requests, especially with AI-generated code, and how GitHub aims to provide tools for maintainers to define their own trust heuristics rather than enforcing a single standard.
Scaling GitHub with Exponential GrowthKyle addresses GitHub's recent uptime issues, attributing them to unprecedented 14x growth driven by AI agents, and details the ongoing efforts to re-architect core systems for permissioning, compute, and mono-repo support.
Evolution of GitHub Copilot and Ambient AIThe discussion covers Copilot's journey from code completion to agent-brained harnesses, emphasizing the future of ambient AI that integrates all available context for more intelligent and proactive developer assistance.
Microsoft's Vision for OpenCLO and AI OSKyle explains Microsoft's significant investment in OpenCLO and sandboxing technologies, framing it as building the foundational components for a new AI-powered operating system that supports developers in complex work environments.

Topics

AI agentsDeveloper productivityGitHub CopilotOpen source securityScaling infrastructureAI workflowsOrganizational leadershipTrust in AIAmbient AIOperating systems for AIMonoreposCloud computingData residencySoftware development lifecycle

People

Speaker 1 (host) Kyle Daigle (guest) Satya Nadella (mentioned) Reese (mentioned) Thomas (mentioned) Malte (mentioned) Mitchell Hashimoto (mentioned) Peter (mentioned) Nat Freeman (mentioned) Mario (mentioned) Sugou (mentioned) Sean (mentioned) Jeff Dean (mentioned)
Key Concepts (18)
COO/CMO dual role — Kyle Daigle's unique position combining operational and marketing leadership, applying developer-centric principles across GitHub and Microsoft Developer.
AI-driven coding resurgence — Kyle's return to active coding, building agents and workflows to connect disparate data sources and automate tasks, enabled by AI.
Recursive loop backwards — Using AI to analyze past actions and data, such as PRs, online posts, and personal notes, to inform future strategies and messaging, especially for non-technical leaders.
Micro skills — Small, atomic AI skills designed to perform one specific task very well, preferred over large, complex 'mega skills' for flexibility and maintainability in workflows.
Postel's Law for AI skills — The idea that AI skills should be liberal in what they accept as input but strict in what they output, promoting modularity and clear interfaces for better orchestration.
Codifying trust — The challenge of establishing trust in AI-generated code and automated workflows, which often still relies on human signals and verifiable proofs rather than purely automated verification.
Vouch system — Mitchell Hashimoto's concept for a system where community members can 'vouch' for pull requests or contributors, aiding in trust assessment within open source projects.
Prompt request — Peter's idea for a new type of pull request where agents generate code based on prompts, shifting the interaction paradigm in software development.
Star gamification — The issue of inflated or artificial star counts on GitHub repositories, making it difficult to gauge genuine project popularity or trust due to manipulative tactics.
Gatekeeping developers — The debate around defining who counts as a 'developer' on platforms like GitHub, with Kyle advocating for inclusivity for anyone creating code, regardless of traditional background.
Diagonal scaling — A new challenge in infrastructure scaling where neither purely vertical (more powerful single machines) nor horizontal (more machines) scaling is sufficient, requiring re-architecting core services due to changing workload characteristics.
Permissioning layers — A key pain point in GitHub's scaling, where complex authorization logic stored in legacy databases (like 'MySQL one') causes outages across different deployments.
Mono repo performance — The unique scaling challenges posed by large monorepos, particularly with big underlying blobs, requiring specific infrastructure improvements to maintain performance.
Coding agent brained harnesses — GitHub Copilot's evolution beyond simple code completion to provide SDKs and runtimes for agents that can handle complex tasks across the entire software development lifecycle.
Ambient AI — The vision for AI that proactively understands and integrates all available context from a user's digital life (emails, conversations, documents, code) to provide highly intelligent and personalized assistance.
Inversion of control (AI) — The concept where AI systems become so capable that they start dictating actions to humans, rather than just responding to commands, potentially leading to a shift in human-AI interaction.
OS-level sandboxing for agents — The need for operating systems to provide secure environments for AI agents to access work assets without security risks, a focus of Microsoft's work with OpenCLO.
WorkIQ/FoundryIQ — Microsoft tools that act as 'context engines' to answer questions across all existing work data sources (M365, Slack, GitHub), enabling faster decision-making without requiring users to move to new tools.
References (29)
GitHub company
Microsoft company
Build event
ChatGPT tool
Copilot tool
Claude tool
Obsidian tool
Teams tool
WorkIQ tool
GitHub Copilot app tool
GitHub Actions tool
AgenTic workflows project
GitHub Pages project
NPM project
Semmel company
Dependabot project
Pult Panda company
Azure company
Azure Dev Compute tool
Vitesse tool
PlanetScale company
Supabase company
Waymo company
OpenClaw project
Cursor tool
Fleet tool
Autopilot tool
FoundryIQ tool
Stripe company
Transcript (85 segments)
Speaker 1

Okay. We're here on Cloud Bagel, CEO of GitHub. Welcome.

Yeah. Thanks for having me. You're not just CEO of GitHub.

People know you as that. Yeah. You have a new role.

Yeah. So I have an expanded role now.

Speaker 2

I've been working at GitHub for thirteen years and doing, you know, all things developer, joined as a developer myself. And now, I'm also responsible as the CMO of developer for Microsoft. And so all the kind of learnings and passion for developers and how we work with them and how we communicate and, you know, how we bring our products to market, we're also bringing that expertise, you know, to the broader Microsoft ecosystem and helping every developer that uses a Microsoft product or would like to to have a sort of similar experience that they've had with GitHub over the years.

Speaker 1

not just doing that with, all of Microsoft. Yeah. And, we're we'll be releasing this in conjunction with Build.

You have lots of stuff planned, and we can sort of touch on that whenever it's appropriate. Yeah. I think one of the interesting things is I rarely meet a COO who's also a CMO.

Yeah. Yeah. I think you're a very outward facing and you're very confident publicly.

That's rare. Like, do you actually view yourself as COO? Like, what's Yeah.

I mean What is your thing? I think for me, like, it's been funny.

Speaker 2

like, always felt a little strange to me. I mean, I joined GitHub as a developer, I mean, I wrote so much of the- Let's bring that up. Yeah.

Yeah. You wrote the back end? Yeah.

I was going through some old photos when folks were talking about how things were being built or how there's a build GitHub. I built webhooks and worked with teams building the API, built the platform layer, anything that integrated with GitHub. Up until really 2018, I was built or ran the engineering teams.

And that's kind of where my, like, the beginning of my passion always was, was helping people build things, deliver them to, like, their customers. And so being a developer, building for developers was always super unique. And I think as my role expanded, it became, you know, my ability to talk to not just developers, but also enterprise customers or, you know, business leaders and have this like translation layer.

And then through all those years, GitHub has always operated pretty uniquely. Like, post pandemic working remotely was not as novel as it was when, you know, GitHub, you know, started in 2008. But all that expertise of running remote teams, doing it well, became the sort of bigger role ultimately turning into the COO role of how do we operate GitHub in the way that GitHub's always operated after the Microsoft acquisition.

Yeah. And kinda so on from there. So I mean, like, for me, I think the I've I still code.

I love coding. But the problem has always been, like, people. It's a much harder problem to both support our own employees, harder problem to communicate to developers and enterprise buyers what we're building, why it matters, because those are two very different messages.

Speaker 1

I think is what's kept me at GitHub for for so long. Yeah. Apparently, you have your commits have gone up.

Yeah. What's this? What's going on?

Yeah.

Speaker 2

Reese called me out pretty, pretty aggressively. So I mean, you know, I think I mean, as you can imagine, right, like, you can see my, like, normal era of being a dev in the, you know, 2013, 2014 era and then moving into management and then ultimately the COO role. I think what you see there is me, like, getting back to coding, thanks to AI.

You know? I similar to, like, attaching problems between, you know, how to market and how to operate a business and how to code, I find like building agents and workflows that are connecting very disparate problems to be what's driving this. So that's like some of it's writing software.

A lot of it is like connecting a ton of different data sources to like help me out. But that is completely me, you know, really, really diving in on the AI side in trying out our tools, trying out everyone's tools, like but building for me, building for the, like, non technical leader, though I'm technical, you know, and how we're, able to use these tools more than just the simple, like, call and response that I think, you know, a lot of the, like, non technical, your employers, like, you have to get you have to use AI and so everyone uses, like, ChatGPT or Copilot or Claude or whatever. To really get into, like, how is this gonna help me out?

I find that it's not the I need to write a blog post. I need to you know, those simple examples, helping people find the workflows of like, okay, I need you to go through all the PRs today. I need you to go through everything that we've posted online.

I need you to go through what we've did the last, you know, three months. Go through all of my Obsidian notes for any mentions of this, then go through my transcripts at work where we use Teams. So, like, using WorkIQ, go call that MCP server, grab all the transcripts, go through all Slack, and then build me out the plan of like what this week's messaging actually was.

That's something that was like impossible. Because for me, I find AI in like what most of this like launch here is, is actually like less building forward. It's actually, like, a recursive loop backwards.

I'm always looking at what had happened first. Like, go back through the week and tell me what we did, what worked, what didn't work. Mhmm.

You know? And then tell me in the next, you know, three or four days, what would you tweak based on, you know, this sort of like looking backwards and then looking ahead a little bit. I find that to be so much more valuable, especially for like nontechnical because that retrospection is actually very LMs are very good at that, you know, like finding all the patterns, pulling them out, and then applying that retrospection to just a couple of days or just like a short period of time.

It's all a bunch of apps that I've built and launched, like a bunch of, internal tools. I use the new, GitHub Copilot app, the desktop app with workflows. Every time I crack open my laptop, it's running workflows for me.

It's just a ton of different stuff. And of course, it all ends up on it all ends up on GitHub.

Speaker 1

Of course. That's where that's where, stuff is hosted. Man, there's so much to ask you.

I was gonna leave the how do you run a company with AI thing at the end. I have to ask one double click one thing. You said, like, you are looking back at the week, you're you're understanding what happens.

When you say we Yeah. That's 3,000 people. Yeah.

Yeah.

Speaker 2

How? I mean, I think, you know, when we started rolling out AI internally beyond engineering, right, One of the things that I was really, really passionate about is like, we have to do this in a way where no one has to change how they work. I don't wanna have to teach you a tool.

I don't wanna have to teach you something new. And so for us, we tried out a few tools. Most of them don't work because I gotta get on board.

You know, I gotta teach you how to use it. What we've actually ended up doing is we've built like a set of, you know, skills internally. We have like, we each have our set of skills and we've just been distributing even to the nontechnical folks, the CLI.

And then effectively, we're just giving it access to, like, read about everything that we're writing. So that's for us, that's usually GitHub, Teams, email, and Slack. So Teams for a video chat generally speaking.

Teams and Slack? Yep. I mean, so we use Teams for video communication like but we don't use it for chat.

We GitHub for a long long history, right? Always talking about chat ops and like everything is built into Slack. Like every command, every Even though you have been acquired for like, I don't know, eight years now.

Yeah. Yeah. I mean, we still use Slack.

Yeah. I mean, it's a purpose built tool for us. And I think the reality is that moving off of it would be so bluntly expensive, you know, simply because all the tooling is, baked in with that paradigm.

And they both have their pros and cons, like, but they don't work the same way, like, at all. Yeah. I mean, we still use a bunch of different tools because it's, you know, the purpose built tools that, we need.

But the same doesn't go for the rest of Microsoft, presumably. I mean, like the like, you know, various teams, like, operate They make their own Various ways, you know. I think it just matters what you're trying to like, what you're trying to do.

Yeah. Yeah. But we do, you know, we do work across kind of every tool that we use.

And then, by giving everyone access to all of that context and like, the new, like WorkIQ MCP server, which is quite cool if you do live in the m three like world. I can ask it all these backwards facing questions and it's incredibly important for our teams that are working remotely. You know, there's a lot of stuff you miss when you're not in an office and we are spread out all over the world.

So most of that is looking back. And then we post either automatically into GitHub issues or discussions, these sorts of findings or our industry reports. What's happening this morning, today, yesterday?

A little automation gets run. We'll use the app. We might use GitHub Actions, like with our AgenTic workflows just to go do that run.

And then we push it into GitHub and we keep having a conversation. So usually for us, it's about that sort of like looking back, looking forward, on the non technical side. And then, of course, for a lot of those folks, it's also, you know, building an app, pushing it to get to pages or pushing it somewhere to host it, etcetera.

But it's just like enabling everyone with that power of it's gonna take me a week to figure this out. Instead, we're going, okay, like, I built a skill. Let's put it into a repo.

We'll all share that skill together and then we'll use the CLI or now the app Yeah. Just to run it. Alright.

I I think I think we're going straight into, like, the the team management and productivity thing.

Speaker 1

I think a lot of people are getting various levels of LM psychosis. How do you manage the bloat of skills? Like, everyone has their thing and they're, like, trying to promote it to the rest their peers in their org.

Right?

Speaker 2

becomes a skill influencer internally becomes like an AI leader, right, sorts. Yeah. I assume you have those.

Yeah. I mean, like, I think we have That assumes a mess. Yeah.

I mean, there's like I like I think the reality is there's two pieces. Like, first is I think that we're ending the era of these, like, massive, beautiful, perfect skills that are just, like, not any of those things, you know? Because for a while, right, like every every tweet every day is like, go download the skills.

The perfectly managed thing to do this entire workflow. And I think that like what we found in what I was just with my team this week and we were talking about the skill side. And we're really talking about these like incredibly micro skills that are just doing one thing for us very, very well versus a skill that's gonna do, like I said, that full report.

That doesn't really exist on our side anymore. You know? It's usually like how to like a single skill that's going to identify the most important marketing information given any MCP server.

Like, this is the most important thing. Less about stitch a bunch of tools together and have it produce this mega output because then weeks go by, months go by, things change and you wanna tweak Yeah. It's better.

Your mega skill and you're screwed. You know, you can't do that. And so now we're really just talking about, like, the Legos we're using and letting the instruction book, you know, be something we're all putting together.

Whereas I think a lot of AI skills for a while have been that mega, you know, instruction book style. Yeah.

Speaker 1

thought a lot about Postel's Law. I don't know if that's a term that means things to folks. It's the idea that you should be liberal in what you accept is strictly what you output.

Right? And I think that's, like, a good framing principle for skills. This is my skills, obviously, on GitHub.

I feel like everyone should have, like you know how, like, some repos in GitHub are special repos? Sure. Sure.

I feel like we should sort of reify the the slash skills and everyone like give it some kind of special presentation. Yeah. Yeah.

Anyway, so, yeah, this is one of those like download Yep. Download anything, transcribe anything, and then you can string together the atomic skills that do one thing well Mhmm. Mhmm.

Into, like, some kind of orchestration skill that calls other skills. Mhmm. Mhmm.

I assume, does that match?

Speaker 2

Yeah. I I I think so. I think that the the Summarize anything?

Totally. Like, I think the for me, something for, like, you know, I do communications and PR and analyst relations and marketing and customer activities. And so my summarize everything is very different for each one of those, like, contexts.

You know what I mean? Because if I'm summarizing something for an analyst, that's a very different thing than I'm probably how I'm gonna summarize something for, a customer meeting or an engagement. Yeah.

So that's, I think, like, the difference when we're talking about the, like the tools I might use on Saturday, you know, or the skills I might use on a Saturday when it's just for Kyle. Yeah. Those are kind of like they have an atomic actual tool underneath or maybe skill.

And then Kyle cares about x. But I think when we're talking about work and enabling the, you know, the marketers, communicators there, it's the atomic, this is what good summarization is. And then this is what I care about as for marketing, for communications, for whatever.

And that I think is like the interesting matrix problem when we go from like a developer set of concerns to all kinds of different professions, is that what that word means to me is different than it means to you, is different than it means to the, you know, analyst or the salesperson. And that's where I think the matrix mess is that we're starting to, like still starting to find. It's not these mega skills Yeah.

But they're all just slight permutations, but those permutations are really important. It's the difference between someone reading this and going, did AI make this? You know what I mean?

Or, like, this makes total sense, and I I would expect this when I'm giving a briefing to Gartner or, like, whatever else. Yeah. Think I the beauty of it maybe is that you don't have to be that careful about what goes in there.

Speaker 1

as long as it like roughly is contained in there. I used to complain about plugin hell, basically, like when you have a framework and then you have a 100 things that you need to integrate, everyone do does like the GitHub used to be bloated full of these things. Yeah.

Yeah. And now we don't need them anymore. Yeah.

Yeah. Because now you just use skills. Yeah.

And, like, I think the most magical thing is that just that, like, I can just also crack it open. Like Yeah.

Speaker 2

you know, do that now with AI. But I think there's just something more magical about getting a response back and being like, that's not right. And then you just crack the skill open.

You just type Yeah. English words, you know, and it's different.

Speaker 1

you know, to get the most power out of them. Is there a you know, you you have a your peer group of people like you. Is there a common framing for something I'm feeling is which is true is that, is this a golden age for former developers who are now in leadership?

Right? Yeah. Because you can wield the tools, you would know the right words, You are maybe not too close to the details.

Sure. Doesn't matter. Yeah.

But like, you're more effective than someone who doesn't come from that background.

Speaker 2

your ability to identify patterns and solve problems. And I think that, you know, for folks that like myself that don't code day to day anymore, that has made me successful as a developer, made me successful as COO, now CMO. And so now that I have access to Git and write code, I'm now applying that sort of like pattern finding and problem solving.

And I know enough still, you know, about how to then go and say, oh, I wanna make an app, but I don't wanna, you know, break into jail or create something that's not gonna be able to work or to be deployed scale or whatever. That ability to apply all that additional business knowledge, you know, and still code, I think is what makes that so interesting to me. Slightly different than I think some of the other, like, technical leaders that became business leaders and now are going back to their apps and updating them.

Good for them, you know? But I think the the more much more interesting thing is, well, now I have this whole new set of expertise over ten plus years. Why not take that and use that as a developer with these AI tools?

So I definitely think that makes me more powerful, but I think that's true for, like, every dev as well. You know, most of the dev friends I still have also have some other underlying skill and passion. You know?

There's really talented, very, you know, kind of linear computer science software devs. Absolutely. I just find that the folks that came from a different career, went to school for something else, went off and did this random thing and then became a software dev, or were a dev, did a random thing, came back.

Learning that extra set of information, learning those extra skills, and now having the power of an AI where I can crank up 15 agents on Saturday, you know, while my kids are doing lacrosse, That's like really powerful. And I think it gets me back to that feeling of like creation. And it's very hard to, like replicate that in most other senses.

You know, that first time you build an app and you click it and you show someone, like, that's magical. Yeah. And so being able to do that, not just in code, but across all kinds of different assets, like, that's that's huge.

We were doing we're doing our like, every year we do our revenue planning. You know, we talk about, you know, okay, what is it gonna look like for next year? And of course, as you imagine, there's, slideshows everywhere, you know, talking about what are we gonna talk about, what's the narrative, etcetera.

And so as you said, you know, I'm like, okay, well, I could probably just like build something to build this. And then that way, I don't have to go build the whole spreadsheet or I have to pass it to my team. So we we went through this process, and I got all the information and used the skills I mentioned.

I built, like, a little app just to make it so I could look at some of the information in a SQLite database, more easily. And I ultimately built this entire presentation without touching any of it. And I was like, okay, I'm just gonna present this to our CRO, the CFO, their teams without mentioning I built it with AI.

I, like, built a skill to make it look very much not AI driven. Nice. Just not pretty.

Not pretty. Yeah. But just like very clearly not AI.

Like, kinda like don't do anything interesting. Just go exactly. We did the whole thing through.

It used my notes from Obsidian. It used all the context I mentioned before, the plans, and never came up once it was AI generated. Yeah.

Never once. Yeah. Exactly.

It didn't matter. So now I can take that tool and go, look, I don't want you to go build slideshows. Yeah.

They're just helping us share information with each other. If this thing can do it with a little bit of crafting from you and then we can look at it together, awesome. There's no value in all that extra work.

Yeah. I think that the ability to, like, make it look humanly bad and, you know, like, build a little app to, like, manipulate the data, I think is part of, like, that upside for devs that are now in leadership roles. Because, like, the thing that I feel like, like I said before, this that's all a people that's all people problem.

Speaker 1

to not do it. Think it was so, like, I think there's a certain charm to just being blatantly AI. Sure.

Sure. So I think you're like, Oh, you're just honest about like, there may be mistakes here that I cannot vouch for. So, you know, how much value is there?

But anyway, I think actually the real question I want to ask is like, you were a chief of staff to Thomas. And in in in the pre AI world, that that job would have been a chief of staff job of, like, can you prep me these slides and all that? Yeah.

And now and now you do it yourself. Yeah.

Speaker 2

you know, evolution is it's not that the the jobs, like, the roles don't all go away. They just change, you know. And so, yeah, I don't have someone spending all their time building out slides for me in presentations because I don't need that anymore.

But now I need that person that is able to go and find all the different connections between humans in those discussions to help me find out, okay, I should be meeting with this group and this team, and they have an opportunity, and I'm gonna be in San Francisco today. I'm gonna be in Seattle tomorrow. Those sorts of, like, human connection, aspects is still incredibly valuable and has always been a big part of that, like, chief of staff role.

Mhmm. But now just like, you know, chiefs of staff are not opening up, like, letters to process, they're doing emails. You know what I mean?

It's the same thing. And now they're they're not building out as many of these presentations because they have the, you know, the ability to have a AI take it off of it. And share that with me and great.

Like, let's keep moving because it's allowing us to go faster and make better decisions more more quickly. Yeah. Awesome.

Speaker 1

Well, so we can dive into more sort of, productivity insights as you go. I did want to do a little bit of a brief history of Kotlin GitHub. Yeah, sure.

Because like we started here. Yeah. And then you also involved the NPM acquisition.

I I do wanna touch upon that. Yep. And then more recently, just wanna bring up to present day where we're having uptime issues, which transparently, we've already already addressed publicly, but we'll we'll discuss in the pod.

Sure. Did I miss anything? Like, what any other major highlights?

Obviously, it's it's a lot of years to cover. Yeah. No.

Speaker 2

the I think one highlight was right before the acquisition closed in 2018, I got to launch the first version of Actions, GitHub Universe.

Speaker 1

It was on You're that young? Yeah.

Speaker 2

2018, I think. Yeah. Yeah.

Jesus. Yeah. Yeah.

I got to I was an engineering leader on that project and got to launch that. And then, yeah, we did acquisitions of, you know, MPM, like you said, Semmel, Dependabot, you know, Pult Panda, like a whole bunch of things. Was a Pult big Panda.

Right? Avi is doing well Totally. On was the big shift after the acquisition.

I had to join the sort of business side.

Speaker 1

I need to hit you on on some of these things because you were there. Yeah. Right?

And how how often do I get to talk to someone? But actions, is that the number one source of security issues on GitHub?

Speaker 2

mean, I think that the number one source of, security issues is probably like the the literal code in everyone's, like, underlying repositories. I would say back further than that is, if you remember, like I have shit like in this graph was this is I I didn't say this before. This is ultimately webhooks.

Yes. You can like circa whatever it was. Yeah.

In Yeah. Hookshot's in there. And so like back then, it says GitHub Services.

Do you see it says Hookshot, Hookshot FE for front end and then it says GitHub Services. GitHub Services back in the old days, right? You like we had a repository that was Ruby code and you could write any Ruby code in there and then we would execute that on your behalf as a service.

And then that way, you know, if, if an if you're trying to integrate with something, it didn't you know, we would run it for you. And of course, no containers because No because it was 2014, you know, like Yeah. And so there was some isolation obviously, but it was mostly the separations on the server level.

That's like an example as long as the very old version of Pages, which ran on its own containerization infrastructure and non actions. Which is like all time great product. Only Pages powers the Internet, like, you know, at this point to some degree.

Yeah. Those were places where, like, clearly, there were no, like, you know, like, issues, like, to my knowledge. But it was those things that where I'm looking at and going, okay.

Well, like, we can't be running arbitrary Ruby code, you know, like, on everyone's behalf, Then containerizing all of that up into, into actions now where, like, yeah, like, the containerization, like, is really good. The, like, pinning like, most folks aren't pinning it the, like, to a particular shot, etcetera, know, you like their workflows. And so that's a big pay that's a big place Yeah.

Yeah. Of, of, you know, pain for folks if they're just doing similar to any, you know, dependency management, just v one or, you know, newest or latest, I think. But that journey from that day to like, okay, we're just gonna run all this arbitrary code and like, it'll basically be okay to now.

No. I mean, we have like really good containerization. We have a new underlying agent containerization service.

It's like through we're using it under the hood. It's through Azure. They recently announced it.

The Azure like dev compute, but it's like very fast very fast compute to be able to like spin up your own Cloud Agents, or whatnot. We're using it under the hood, for some parts of the new Microsoft GitHub box? No.

No. No. Dev compute.

Yeah. Not finding it just yet. Oh, it's it's in there somewhere.

Alright. Well, we'll cut that out. Sorry.

But but with, with, like, dev compute, you can work run, really, really fast, spin up really, small VMs really, really quickly. So you're doing a tool called just do it like containerize. Exact exactly.

Yeah. So we're using that. So definitely moving that direction to protect us from every, you know, every, every piece of code that we're ultimately running.

Yeah.

Speaker 1

grows into the the full SDLC. Yeah. You know, like, code hosting was just the start and, then it's grown grown beyond that.

Let's talk about NPM maybe because I think that's also, like, a very major point in the industry. Like, I I do think, like, it was looking for a home. It was, like, kinda struggling as Right?

I don't know. I don't know how you characterize that, that whole acquisition and, you know, how it Yeah.

Speaker 2

you know, to the team, I think the big thing for the both of us was to find a way to keep NPM, which was basically powering the Internet then and way more so now to some degree, you know, running, you know, like keep it going, keep because you knew it to scale, was having scaling problems if I recall back at that time. They were doing some rewrites. I mean, that's cute compared to now.

Yeah. Well, that's the thing is like, you know, when I'm talking to folks now, like there's, you know, there's so many more underlying uses of NPM than there were, you know, back when we had them join, join in with GitHub. But that was ultimately the goal.

It was really like, okay, we used to have pages. We have, like the world's code. Let's make sure that we can keep NPM running well, you know, for the world.

And we put a bunch of time and investment into fixing some of the underlying back end, changes, some of which we talked about, like some of the manifest work, etcetera. And then now, like, really trying to bring the, you know, the security posture of NPM up to speed. But like, it is a unique challenge in that every move that we make to make it more secure will break a lot of people.

And security is paramount. And also, like, we take it very seriously where like the, you know, anytime that we have a problem with GitHub or we make a change that makes us more secure, there's like a snow day for developers or a really bad fire that they have to go put out. And so we've, like, have changed the 2FA policies.

You know, we've changed the way the tokens work. When we find tokens that have been exposed or potentially exposed, we invalidate them. I love that feature of GitHub.

That creates issues. But like the but that's the thing is we're trying to push the community, forward without necessarily, doing something that is going to break the contract that's been for fifteen years, you know, or close to it or, you know, some amount of years, you know, on NPM.

Speaker 1

Yeah. I think the so now we're talking about open source and publishing. And I think there's something here with what people are calling slot forks, which I think Malte from Vercel is doing.

And part of me thinks like, well, the way to get past any, like, vulnerabilities, we just let's just get rid of the concept of NPM. And we only publish source code. And anytime you want to import it, you you have your coding agent look at it and then adapt whatever subset you're gonna use into your like, vendor it, but like the AI vendor it.

Speaker 2

Is that realistic? I don't know. Is it would that solve all our security issues?

Don't know. I mean, I don't think it will solve like, I so Mitchell was just talking or Mitchell Hashimoto was just talking about this today. I think that, like, in some ways, it's all, you know, all things, old or new again, you know?

Like, yeah, absolutely, vendoring everything. Like, you know, I do I do remember 2013, 2014. Hey, listen.

We must return to That's what I mean. It's like we were vendoring everything. We were having actual discussions around like or at least I remember we were like, should we take this full thing?

Like, why is this so big? We only need this one file. And so I do think there's something true there where having like, either taking only what you need or the dependency is just getting incredibly small over time, I think, will help to some degree.

But it's not gonna solve the fundamental problem, I don't think, because the vulnerabilities, like, in an agent looking at them, there's time and time again, there's a million different ways in which we can convince an agent that this thing is, like, secure or not and pull it in. Or we can do, you know, static code analysis or, you know, runtime testing to say whether the code works or not. That is, I think, the step that needs to continue to be, like, invested in.

The question is just on, like, how much scope? Should it be this enormous project that I'm pulling down or should it be this piece? Either way, you know, most companies are running some amount of, you know, security checking on the on the, the packages that they're bringing in or vendoring.

That, I think, won't change. That's like what, you know, advanced security does to some degree, socket does to some degree, you know, like everyone is doing a piece of that. How we each do that, like, especially when we're talking to enterprise customers, it's just like very, very No like, there's no one wants one single way to do it.

And I think that's always been GitHub's unique position in the world. Like, I talk a lot to maintainers. I talk a lot to folks about this.

It's we're we rarely start, like, a a a process and a practice and, like, push it onto the community. We usually wait for the sort of, like, RFC process socially or literally everyone agreeing, and then we'll cement something in. Because otherwise That fits your role in We're GitHub.

Yeah. We don't wanna shape the whole thing. We want it to be figured out.

But, like, how do you balance that, that, like, sort of, you know, role in the industry to keep everything as secure as possible and make sure that you're, you know, you're not going be compromised as a human because that's usually how it all happens. And not, you know, not create a process or lock us into a flow that, you know, you're not going to like or like Mitchell's not going to like or other open source projects aren't going to like. That's always been a tricky balance for us.

And I think that's something that we haven't talked about enough, you know, is we're not gonna be able to fix everything for everyone in a way that everyone is gonna like. Yeah. So tell help us.

Tell us what is working. When Mitchell was talking about, the Yeah. I'll just bring bring bring out his thing.

Yeah. I forget what it yeah. Yeah.

I mean, like, when he's talking to us, was chatting with him and talking to him about this and I put it on Twitter and we talked to, also over DM. I was like, we're gonna keep working. Like but I think the important thing is keep I do actually want to hear what isn't working for you.

And as be as specific and clear for your project as is possible, into every piece of credit over the many years that we've, you know, known each other through the industry, he's always done that. And I appreciate that because there are places that we need to fix up and we hear from him and we'll fix up just like we do all other kinds of maintainers. But that like that process between, you know, making those types of improvements and being more secure and, like, creating I forget what he calls it.

It's not the the the proof process, not the claims process. You know what I'm talking about? He has that, like he his projects have a way for you to kinda like Vouch.

Vouch. Thank you. Yeah.

Yeah. He has, like, the vouch system for, you know, saying, hey, you should accept my PRs. That's been is a business in GitHub.

I don't know. Well, see, but that's the thing is that you say that and like he and his community really likes us. And then I'll go talk to other maintainers and other maintainers globally and they're like, No.

This doesn't work for me. Yeah. And that is the tension, but also the kind of beauty of GitHub just depending on which way you look at it is we wanna help maintainers.

So we create all these tools to let you have more control over how much you take in, you know, from AI and PRs. But you can also use this. You know what I mean?

You can go use this project. And if it takes off and becomes the kind of mostly standard, then yeah, we probably wouldn't enforce it, but we would add it in because that's the flow that we tend to do, you know? Yeah.

I hear a lot of people don't know the history of the pull request. Sure. And like, you know, like that's how it's something like GitHub standardized basically.

Yeah. Yeah. It was a very messy process, you know, like beforehand and now, you know, we have the benefit of it being the process, And you now we have to go and figure out the next best process or what adaptations change or what does a pull request look like when 80% of your PRs are just coming from your agents and not from other devs, you Do you like the prompt request idea from Peter?

I mean, like, I think that for each, like each idea, I think, has its merits. Like, I'm not avoiding saying anything good or bad, but I feel like I've seen a version of, you know, we have that. We have, you know, an entire, you know, Tom Thomas's, you know, start up.

Take all the assets of what you've built and put that in. I think that's got great ideas. Like, there's all these various permutations of the PR flow.

But I think the reason why there's not a single answer is ultimately we're trying to codify trust. We're trying to say like, okay, if Sean reviews this, I'm gonna trust it because you're Sean or you're the senior dev or you're the whatever. And right now, when we are working in a flow where an agent writes code and another agent reviews code and then Kyle goes and looks at it, the trust is kind of diffuse.

And most of the tools that we're talking about are talking more about verification flows. We have more assets to look at, so I can probably say whether this is a good PR or not. But that still doesn't solve, I think, the human problem of I'm looking at a PR and I wanna know if I can trust it.

And we're still we still tend to use human signals for that, you know? Mitchell approving it or Kyle approving it or whatever. And so I think that's I think that's why most of these, options haven't really solved it is because, it's a social problem.

Ultimately, it's a human problem to review it, and agree. Or you fully trust the tool and you're imbuing that tool with full trust, which I think in some cases that absolutely exists.

Speaker 1

when we don't allow humans to drive anymore because machines are measurably better than humans. I I'm looking for that tipping point. Right?

Yeah. Like, Mythos is ridiculously expensive. Mhmm.

Someday, we'll have Mythos on the desktop. I don't know. Mhmm.

Will will does that change the equation?

Speaker 2

I think it's more like, I took a Waymo here, and I was on my phone and not looking around, at all. Like, there are other, self driving, vehicles that I would not trust while, like, staring at the road. And I think that that trust is something that is Is this a Zugz thing?

Like, what is that? I think that is both. I think that is both.

You know, like There's Zugz in this robot, taxi. That that's it. That's Well, I mean, depending on what level of self driving, you know, but my point is sort of that, I think part of that is, you know, I strongly believe that that's like a mixture of verifiable proof, you know, like how many accidents, how much data and so on.

And the human aspect of how I feel when I'm in this car, what it tells me, etcetera. And so that's why I think some of the, like, some of these, some of our AI tools tend to, imbue me with more of that feeling of trust even if the data says this is 100% accurate. You know, like, I feel like it takes more time for us to go, should I trust this or not?

And that's in the soft sense of like startups with high agency, weekend projects, and open source. And there's enterprises and regulated industries and everything else. And that is an even harder problem to go solve because even when it is fully verified, not only do you have to have trust from the humans on the team, you probably have to have trust from multinational, multi governments around the world, you know, and regulating agencies.

And so that's where I feel like until we tip over to your point, like, on the sort of, like, human EQ side of it, like, feel okay. Like, this feels okay. Like Mhmm.

I've been proven enough.

Speaker 1

where we'll end up getting to the, okay, we can trust this and feel good about it in the most difficult of cases. You know, if human trust is the thing that matters, I feel like GitHub as the developer social network could maybe do more there. Like, vouches of one system, but like, we have star counts and then we have contributor rights and that's it.

And like, I feel like there should be more in that space.

Speaker 2

like, some degree of, like, hard trust and support, which would like, me is, like, sponsors is a good example of that. It, costs you something, you know, to prove that I I believe in your project and I, like, trust you to some degree or I wanna support you at the very least. Okay.

Self payments for open source. So we're I mean, like like, I think that I I think that, like, as we keep moving forward, right, there's more and more projects where I I'm, like, adding more and more dollars into sponsors personally because I want to like support them, but I also like know of, you know, I probably never met them in person, but like I know enough of their work that I want to support them. I think the thing that I don't love about stars or commit counts or anything else is like ultimately, even with all of the various, like, abuse and despamming and deduplication work that we do or anti abuse, you know, work that we do, these are all, like, not active social signals.

They're passive ones that are ultimately gamifiable. And you may trust me, but another open source maintainer may not. And on what heuristic should you be, trusting me?

That, I think, is kind of where some of our thinking is right now. What signal from me is most important to you? You if you can define that potentially, like, honestly, like in an agentic workflow, like, that's what we see some of these open source projects do, where you have, you know, GitHub Actions, then you have, like, an agentic workflow that's calling AI, and you're setting these rules.

Like, if Kyle has submitted and gotten accepted PRs across any given project and has a social handle tied to his account in GitHub. And that social account's older than certain amount. Like, really complex measures that matter to you because most open source projects have that heuristic built into their heads if not written down in the contributing guidelines.

You could take that and then go apply that and then just say, oh, we're not going to accept this PR. Building something that is, I think, malleable to everyone's needs is a little bit better rather than going, this account's too young. Because what happens?

The attackers just go and go and create a multitude of accounts and they wait until it ages up. Needs to have certain amount of stars. That's how star inflation happens.

Needs to have certain amount of repos Oh my god. With PRs. They all just create repos and submit PRs to each other.

And then they, you know, come in and do something nefarious. And so, it's hard. Like, it's hard to find the measure.

So I think we're we're looking more at how can we provide you tools so you can kinda choose what's best for you. Of course, we'll give you some standards. But the trust vector, gets down to, like, I don't know, some version of, like, human digital ID like everyone's been talking about.

Like, how do I prove that it's me Give me your eyeballs. On the Internet. Yeah.

Give me your eyeballs. Exactly.

Speaker 1

I I gotta keep moving on on on topics, but obviously, I can go all day on this stuff because, I mean, I've been involved in GitHub and open source my entire, you know, professional career. Stars. Yeah.

Very superficial. Everyone knows it. But I think, you know, time to 100,000 stars is the fastest I've ever seen.

Mhmm. Like, people just reached out in, like Yeah. I don't know, months.

Yeah. And then, like, at the same time, like, I don't trust it. Right?

Like Yeah. How many of these are real or bought or, like, whatever. I don't know how to ask this, but like, what can we do about it?

Like, you know, is STAR's broken? Is STAR's fine? I think that there's kind of two there's like two pieces.

Speaker 2

constantly like trying to find ways in which like your users are, you know, producing spam, which would I would include, like, be, like, only doing star gamification. When we find them, we pluck them out, you know, and we It was like a whack a mole. It's a 100% like a whack a mole now, like powered by AI to be helpful.

But I I think more so, what I'm seeing is, a lot of this, like, fastest time to x, you know, tends to be because we're now inviting so many more people into, like, software development on GitHub Yeah. That, like, the zeitgeist is just swarming. Yeah.

You know? It's It's not just developers. And it's not you and I.

Yeah. Like, you know, like, however you wanna say, like, what a developer is. You know?

It's not just folks that been coding for a very long time. It's folks that have maybe started coding or only joined in since the AI era.

Speaker 1

now What's the latest Octoverse number? I I know 80,000,000 was my last memory that like, a number of developers on GitHub.

Speaker 2

now. Yeah. Okay.

Well, you see? Yeah, yeah, yeah, yeah, yeah. Like over 200,000,000 developers now.

Yeah. It's not developers, right? Like it's people with a GitHub account.

So, like, so this is this is the biggest debate that, like, I would say, like, everyone loves to have at GitHub at this point. From my perspective, right, I think that there's there's clearly a difference between, like, professional enterprise developer, you know, and then developers. But I think that I think that the idea that, you know, we should be, like, I don't know, splitting hairs or segmenting developers in the early era of software development is, like not worth our not worth the time.

Yeah. Like get into gatekeeping like A 100%. Like a 100%.

Because I mean, wasn't a developer when I started writing code, you know? I was going to Oh, I I made I like cloned the thing like seven years before I learned to code. Yeah.

Yeah. And then I and then I wrote about my learning code journey, and people just called me a fraud Yeah. Because I had a GitHub account.

Yeah. And I'm like, well, no. I just used GitHub, but I don't I didn't know what to I mean, I like I remember that.

Like, I remember those sets of posts, and, that's like, that's bullshit. So I fight very clearly on the line of, like, if you create code, if you have an idea and you create it into some way of, like, I'm I'm gonna run it and use the app right now, you may still use AI in that moment, but that's okay. At some point, you're gonna do the next thing.

You're gonna create a big you have to learn about this database. You're gonna fix a bug, whatever. Like, we're all on some same journey, and those people are also hearing about the great new agent skill package or a new CLI tool or a new whatever.

And those projects are going up because you want to be a part of this moment. Just like I wanted to be a part of the Ruby community when Ruby was popping off when I started becoming a developer. And now I can just click the star button.

And so I think that, yes, there's clearly some amount of, like, you know, spamming and gamification that we're working against. But I really think we're just seeing this whole new cohort of folks that are moving from technology to technology because not working on a twenty year old software application. They're working on a side app that they built on the weekend for their friends or for their new idea or whatever.

Yeah. And that's how you see these enormous charts going up into the right with, with stars. I guess something that's remarkable is the persistence or like, GitHub extends to those folks.

Speaker 1

when I see platforms go into a new audience, they usually have to, like, have, like, a second platform with a different name that, like, wraps the main platform. But somehow GitHub has been able to sort of persist and extend and it's friendly and whatever, you know, so it's nice. Yeah.

Speaker 2

I don't know, more like low code y things, you know, like we so we, you know, started working on Spark as like a way to, build an app and run it. Yes. I think that the reality is that we anytime we try to, like, kind of put even a veneer on top of it without, like, like, when we put a veneer on top of something, we still always show you the code.

That's kind of like a tenant. We're never gonna, like, hide the code from you ever, because what? Like Let us yeah.

It's the whole point, you know. However, I think that what we learned with things like Spark is that really the value of Spark for most devs is, like, easy runtime. And you may have a runtime or a host that you're gonna use for that, or you could just build something and run it.

But, like, the package of making that, like, even more simple isn't really needed, like, for folks that are trying to build software Mhmm. And not just trying to build, an app, which is like slightly, slightly different, a slightly different goal. Mhmm.

So I wanna get you in. I wanna get you comfortable. I think the best thing for me as like someone that did not, like, you know, traditionally come into software dev way, way, way back, I want anyone to be able to, like, breach that chasm and not be in the you know?

I don't know. I feel like we're we're still in an era of, like, stem, stem, stem. I've got a 12 year old and an eight year old, and it's like, gotta get them into stem, you know, over and over.

And I I like, I do. I do the things that good parents do. I was like, oh, we wanna do coding?

Yes. I wanna do coding. Do coding classes.

But now they're just not afraid of doing software. And that's, I think, the thing that's honestly kept me agitated for so long. Anyone should be able to go and build a thing just like I can go change a light switch in my house.

Like, I'm not gonna go into the breaker box because I'll probably kill myself, you know? But like, I can go change that light switch. Everyone should be able to go and say, this freaking app doesn't do what I want.

Like, I want it to work like this. Yeah. And that, I think, is what's kind of kept us all connected with GitHub through the years and some you know, and like during the easiest of times or in the hard times because of that opportunity of like, we're the home for all developers.

And we want everyone to be able to have that feeling that we've had of, I had an idea, I created it, and holy shit, like, you know, here it is. Here it is.

Speaker 1

All right. I'm going to try to do more spicy questions. Great.

Is it an easy time now or a hard time?

Speaker 2

Oh, at GitHub? Yes. I mean, it's a hard time.

Speaker 1

Best of times, worst of times. Yeah.

Speaker 2

because we've you know, like, we're talking about Octavus reports and, like, usually, we do an Octavus report once a year and we look at the numbers and we say, oh my goodness. Like, I was at Universe in October saying this is the fastest year of growth that we've ever had. Right?

And now we're doing more in a month than we did in a year last year. You're talking about PRs. Commits.

Yeah. PRs. Yeah.

Kind of like you name it. By roughly every measure that we're looking at, there's some amount of sort of growth that is much, much bigger. And that is breaking our system in new ways, not old ways.

Like, you know, webhooks were always notoriously, unreliable over the years. You know? Whose fault is that?

Like, not anymore mine, but for a period of time, I'm sure you could pull up a tweet that was like, it was me. I'm sorry. But, like, now, like, that got rewritten at a scale level that is still working and is not having problems today.

Now what we're finding isn't just the, like isn't the the the simple stuff that folks are on the, you know, sometimes on Twitter or on the Internet are like, hey, like, why is this like this? Sure. There's absolutely, you know, silly problems that shouldn't exist.

But now we're talking about, like, unique novel permission problems that happen only at a scale across all different objects or whatever, that now we have to go rewrite this underlying system. And so it's there are problems that, yeah, caught us off guard, which I think I said. I mean, like the growth is astronomical.

But also, we're making such material progress in that that I'm excited once we're, you know, once we've kind of like re reimagine the underlying foundation layer or pieces of it at least. What's going to be possible when it's not just all of us and all the new people that are being developers and all of their agents and all the tools, like, working together. Because that'll still happen in that, you know, in that GitHub, you know, tool, that GitHub community.

But it's a hard it's a hard day. Anytime we can't give you what you're looking for, we have the same problem internally. I mean, we operate through GitHub dot com.

Of course, we have backups when things go down and whatnot for our own operations, you know, but we feel it too. You If it's not working, it's not working for us. And that's kind of like the promise of dogfooding for GitHub.

It's always been true. We're using the same tool you're using. We're not using a super secret version.

Speaker 1

Yeah. Doing it too. I wanted to load, for for audio listeners who who maybe haven't seen your tweets, whatever.

So 1,000,000,000 commits in 2025. Now it's 275,000,000 per week on pace for 14,000,000,000 this year. It goes to remains linear.

Speaker 2

pace? Yeah. It's I mean, it's speeding roughly.

Still speeding up. Exactly.

Speaker 1

This was in April. All right. So basically you have 14x growth, right?

Year on year. And I think that's a scaling issue. I think I'm going to like try to really steel man this thing, right?

People have experienced 14x growth. They haven't had your downtime. Mhmm.

And that's like can we go dig into that? Like, why? Like, what's the what broke?

What are we doing to fix it? Like, you know, just anything for the community to reassure them. Yeah.

Speaker 2

the the growth issues. Some of the growth issues, which is why we're I was talking about, you know, pushing hard on more CPUs as in actions in particular. More tools, more agents, more PRs mean more builds.

More builds need more CPUs. And so we are expanding through not just our data center, but obviously, we are talking about moving to Azure and moving to, like, adding an additional cloud compute because we simply need more CPUs, Not, not as much GPUs. Like, we definitely need GPUs too, but now CPUs are becoming a factor, you know.

Underneath the hood when it comes to, like some of the underlying services, we've been breaking up over the years our database infrastructure. So that way we have more cognitive separation between the various services. The place that we continue to have pain is in, permissioning.

So right now, many of our permissioning layers sit into a database that we, like, internally call MySQL one, and old hovers will know what I'm talking about. And so, like, we've been pulling things out of MySQL one for many, many years because like and we use, you know, we we use Vitesse and we use other technologies to shardly do like one of scale was born from this. A 100%.

Yeah. Sam, you know, you old harboring friend. I mean, like and so finding these opportunities to, like, break this out and then do that globally.

The other thing that I think is interesting in, like, both a unique opportunity and tricky is we also run everything I just talked about in a, like, a black box container with GitHub Enterprise Server for people that work on on prem. And so we take everything I just said, and we also do it on prem. And we also do all of that, and we do it in a data resident setup, for customers that need to have their data in a single location.

Each of these has the unique characteristic around how we're sort of storing that data, in MySQL or in a permissioning setup. That's where some of these outages have occurred where you're seeing it more like across the board rather than just like the one who isn't quite working. Exactly.

Exactly. And so part of it is that. I think there's been some other places where agents are much more or more projects appear to be moving towards mono repo versus we were going the other direction for many, many years in the industry.

Repos were smaller, but there were more of them. And now we're seeing the opposite. Repos are bigger and there's, not fewer of them per se because there's new growth, but, like, we're just seeing many more big repos.

Big repos, big mono repos have always had, like, a unique performance problem. Mhmm. Like, because each one, is slightly different if particularly if the underlying blobs are incredibly big inside the repos.

And so we've been a ton of work that you like, most people haven't probably experienced, unless you're in this case of the mono repo. But that Git infrastructure layer improvement does help the overall, system because, many of the improvements that make mono repos work better make all repo infrastructure work better. And so, like, I could kinda keep going, like, down the line where it's another thing where, you know, we're moving out of, we're changing how we do, like, I'll just say, like, job queuing for lack of a better, like, explanation, like changing the underlying technologies there.

I've spent two years being a job queuing guy. And so, like, it's kind of a little bit of, like, a little bit of piece by piece, and it's mostly because as we were as it was built, we built everything in a way that assumed, I guess, in some ways that the size of the pipe of work was going to remain the same. There's just gonna be more people coming through each of those pipes.

But instead now, in places where a git push was generally a certain size, for example, is now, like, no longer true. Oh, yeah. You know, or, like I pushed thousand the average.

100% commits. Same thing with PRs. You know, like PRs, like, same thing.

And, like, we've, like, talked about optimizing that and making changes where, like and there were, like, technology choices that did not work there, you know, and it got slow, and it didn't it was not fast. It did not do what the users wanted. And so we've been, like, reeling that all out, you know, and going, okay.

That's just not right. Let's stop putting, you know, good money after bad and do it the do it the right way or the right way now. So there's it's a it's a lot of things, not quite like when I've experienced scale at GitHub historically, it's almost always two options that we've used.

We go vertical scaling, particularly with databases. Right? And we go horizontal scaling.

Oh, we just have more people using this service? Great. We're gonna add more servers and we rack them in our data center or we use it in a a cloud.

And now, like, we're sort of in a, like, diagonal where, like, vertical doesn't really work anymore. Horizontal isn't work either because, like, we're all we all have some CPU or GPU constraints in the world now. And now we have to go and, like, crack open services that have been running for ten or fifteen years and go, okay, the rules of this service have, like, legitimately changed, and now we have to rewrite them.

None of this is an excuse. This is like we're we have to do the work. We have to make it better.

I mean, actually, as an infra guy, I'm like, that's this is like one of the most fascinating scaling challenges I've ever seen. That's like that's that's the thing that that's the thing that it's hard for like, when we weren't talking about it publicly and I was like I came out and I was like, hey. I just wanna explain what's going on.

Part of it comes from a very old GitHub like ethos, which is it's our it's our uptime. It's down. Yeah.

What like, I know you're a developer, so you're you're inclined to, you know, want to understand more what's going on. But at the same time, like, us going, hey, this service didn't perform the way we expected, and now we have to go change it. We were we're not trying to hide anything from you in that.

It's that, well, that's our problem because you expect us to be up. And I think that's, like, really baked into the core, origins of GitHub. And so now what we're trying to do as a team is do all that work and just tell talk about it more, just share you more technical details.

Write these blogs. Write the post. Get the engineers who built it after they finished the work.

Just tell you, okay. This is what we did. I think that's the contract that we wanna bring back to the community and say, hey.

We're still very serious about what we're doing. We haven't been telling you about each piece. So let's do that, and we're gonna keep, you know, building this and scaling it in a way to support the if it's not 14, then it's 30 or it's 50 or whatever the next, you know, exponential growth is gonna be.

Yeah.

Speaker 1

First of all, fantastic answer.

Speaker 2

I mean, I think And I apologize in advance if any of that is slightly incorrect just simply because I'm still in the weeds with this, but it's not my day to day. But that's the thing is we're all looking at it to that level. Yeah.

Speaker 1

Know? And like, obviously if people want to help, they can join. Yeah, absolutely.

So like, I think that is good. I think people also just want to know, like, you through the thick of it, right? Like, have we identified all the issues?

Is this just never ending? Like, Git broken? Like, do we have to change the Git protocol?

Like, how much is breaking, right? Like, it's been a while. Yeah.

Yeah. And so I think people do want to know what's the path back to the the the reliability that everyone expects out of GitHub. Yeah.

Speaker 2

our availability in in recent, like, few weeks has been much better than the three weeks before that or the three weeks before that and so forth. So a lot of these improvements are still very much paying off for us. Yeah.

Speaker 1

the way My my my, the the answer I had in my head was call YouTube.

Speaker 2

So YouTube ultimately They also use Vitesse. They also use Vitesse. But but the, Like whoever was the guy, the scaling guy at YouTube.

You know what saying? Yeah. Yeah.

Like that's that I believe went to PlanetScale and it was a part of PlanetScale too. Like Oh, you mean Sugou? I think so.

Yeah. Yeah. And so, and so He's at Supabase now.

Speaker 1

There's a whole

Speaker 2

Postgres drama. Yeah. Totally.

So I mean, like some of it's that.

Speaker 1

Tell you, actions. This is the root of all evil.

Speaker 2

its pros and that it's the core it's the core compute layer for either CI, side projects such as

Speaker 1

No.

Speaker 2

I don't know. I mean, like, actions I pay a lot for for compute. Right?

Yeah. Yeah. I mean, like, actions is, like, definitely a a a piece of the overall business, but I would say that, like, we ultimately also give away so many, like, minutes, you know, as part of our entitlements as that.

But that's what I was saying. Everyone's using it. We we talk about it as CICD, but the reality is people use it for CICD and various processing and automation.

Exactly. And so, I mean, like, part of it is also that, like, compute piece that, that is also alleviating some of our availability. This is my abuse of, actions.

Speaker 1

I've been scraping for every day and just like, I just Thank you for your service. But this is also how I track actions on time. Sure.

You know? Sure. Yes.

Anyway.

Speaker 2

So I mean, like, some of it's gonna be that. I would say that, like, each month I expect, you know, in the next three months, you're gonna see, like, fewer and fewer moments where we have an availability problem, where things are gonna go down. And that's not just it stopped.

It's that we're still experiencing faster growth than ever before. It's just that those underlying improvements that we've been hard at work on are finally paying off. It's just that their improvements take it's less about, like, these incremental improvements where you make a small change and you get this big output.

It's now material change that takes a bit of time, and then you see a step change in our availability.

Speaker 1

or simulation of load testing and all that, like, I'm I'm just like, at this point, you have a whole map of GitHub. Mhmm.

Speaker 2

assume whatever growth rates on whatever dimensions that you care about and just run it through the system. Right? Like, I feel like there's a way to, I don't know, have a systems model of GitHub and, like, see what breaks.

But, obviously, I'm I'm not that close to problems. Yeah. But I mean yeah.

So, yes, totally. And I would say, like, that's been the journey and work that's been happening since, like, I would say November to now. Yeah.

Because October, right, was the time where we even said, like, oh, look at the growth and, like and then you start to see the chart, like, really, really pick up. It's like, oh, we tested it at, you know, n amount of scale and now it's at, like, n cubed maybe, you know, like in some, in some, vectors. And so now we have to go and build it, you know, that way and make sure that it can handle all of that scale.

Speaker 1

Let's talk Copilot. Yeah. So how many original creators of Copilot are there?

Speaker 2

Oh, geez.

Speaker 1

It's okay. I count like 12. Yeah.

Speaker 2

I mean, like, I forget, like, all joking aside, I forget the number of people that were on like the original like, GitHub Copilot team. But, there was a heard bigger it's There's Alex working on it. Google worked on it.

Like, there's a, like, a bunch of people. And then their entire management line. Okay.

Speaker 1

So so, like, you know, enormously successful at its in in its in its day. I think the last number, I think Mario Mhmm. Came to my conference, and talked about the $100,000,000 mark.

Mhmm. I think most recently 300. I might be out of date as well there.

I don't think we shared the dollar amounts. Alright. Cool.

Just like, what's the state of Copilot? It's it's obviously as a concept brought into more of Microsoft. Yeah.

But just add GitHub. Yeah. Yeah.

Speaker 2

one of, like, one of the challenges is that we had with Copilot, right, is that we came out the gate with code completion. It was, you know, super great, powerful, etcetera. And then what we initially worked on after that sort of like initial year, year and a half was going after fine tuning.

Because, you know, our customers, the industry on the whole was really talking about, okay, well, like, how do we get more, you know, more correctness or performance out of this? And so we were working on a whole bunch of efforts to do fine tuning on, larger and larger co completions or, like, next edit suggestions with fine tuning, etcetera. And let me clarify.

Yeah. Is this fine tuning one model or per customer a fine tuned model? Per cus both.

But like but like fine tuning one model for the overall, like, use and then fine tuning per customer that wants this as like a service effectively. And around that time is when, you know, the next generation of models came And that's around the same time that, you know, all of these other, you know, AI, coding tools came to be because the models really, really sped up. And so everyone kinda like will ask, well, like, what happened to GitHub Copilot?

Like, there's all this time. And I would say that we were on an era of going, okay, we wanna improve everyone's results, and so let's focus in on fine tuning because that'll give us these better results. And then the models got better.

And so then, ever since, we've been really on this kind of journey to go, okay, of course, we have, like, this great code completion and we've done a ton of investment in the better underlying models that we have, you know, post train, better next set of suggestions of post training, language specific models, all this stuff that kinda, like, sits in the ether of GitHub Copilot is code completion, but also have now have now have, like, a single underlying, SDK and harness for our, our coding agent, you know, Copilot ultimately. The new CLI, the new desktop app, cloud agents that use the same SDK. And so there was this moment of, you know, both, really, really trying to figure out what our customers want, models, surelocking us a little bit, then going and saying, okay, what does everyone ultimately need?

And what we think is that it's not solely about the code generation. It's really about having the ability to use these, you know, coding agent brained harnesses or runtimes across not just the coding experience where I'm gonna like send a bunch of tasks out or I'm gonna use Fleet to to break up a single task or autopilot similar to goal, you know, all this stuff. But also, how do I do that for all of my security remediation?

How do I do that for every GitHub issue that comes in? Just stick a coding agent on it just to say if it's possible. How do you, you know, go through my repository and see all of my documentation and extract out, okay, this doesn't actually match.

Like, that amount of sort of AI coding agent automation, I think, is a big part of what we see when we're looking at, okay, we're still kinda going through a similar but very different flow. It's just all happening at the same time. You know, like, there's not really the same, like, I'm gonna create an issue to track my idea of building this.

You're probably just gonna go, like, do it. You're gonna say, hey, just build this. Right?

And there are still tons of open issues and projects, etcetera, that are using issues like Peter in OpenClaw, you know, to be able to sick all of his agent on that. That kind of infrastructure layer and a really, really great coding experience that allows you to handle the sort of multiplexing aspect is what we've built or still building, you know, with GitHub Copilot. And so for folks that, you know, haven't really used GitHub Copilot since the thing that got them excited about this, you know, which I like I get.

I really encourage you to like look at especially the GitHub Copilot app. Like, that's my new daily driver. I obviously, like, you prefer the CLI, also the CLI, be able to use all the models, the bring your own key side of it.

Like, we are still improving our own models and using those too. And it's just like a very, very different experience. But I think that broader sense is of, like, software development and how coding agents can help throughout, not just writing the code or even verifying it or deploying it, you know, is, like, was where we have this unique angle.

The other side is the context piece. Like Oh, god. I mean, like, we're still it's like one of those things where I think the, you know, the final thing that will let me ultimately feel complete at GitHub is like when we have this ability for GitHub to act like Kyle wants it to act or Sean or whatever.

Speaker 1

and everything else. But That's an open research problem. Right?

A 100%. A 100%.

Speaker 2

A 100%.

Speaker 1

with GitHub Copilot. Yeah. Is there a form factor that we haven't explored?

You know, I think like, you know, we did code completion. Yeah. Then we did kind of broadly called it agentic IDE Mhmm.

Which Cursor Yeah. Yeah. Famously popularized.

And then now it's now it's all about the sort of agent orchestration, background agent, whatever whatever. And then there's the security review. Yeah.

I feel like everyone's, just throwing agents at everything. The entire SDLC has just covered with agents. Are we at the end of history here basically?

Speaker 2

Is it just refinements from here on out? I mean, I think that we're all still in such this like hyper myopic era of AI where the reality is that for various like boring security and governance reasons, at least for most people's work, why is my coding agent, even if it's all background agents, background running, not like losing all the context that's available to it across everything that I'm doing outside of coding? Yeah.

You know? Like, I I think the most interesting thing to me in AI is actual ambient AI, not insert, you know, assistant name thing or, like, I've tried just about every pin in tool and whatever, and they don't work the way that I'm looking for them to work because they're just trying to capture and then they are trying to codify and then recall. And I think the thing that I'm looking for is back to the very beginning.

I'm looking to be building out the next version of webhooks or, like, implementing a new feature. And it for it to know every spec doc, every email, the conversations that I've had online, everything about how this could be implemented and be able to, like, use that as part of its decision making. And none of these tools are ultimately doing this.

So I think that it's as if, like, software development work was a single lane task. It was like, it only needs a developer. Once I once I write the perfect code, we'll be done here.

But that's just never been true. It's all the context of the other team members, what the business is doing, what's popular right now. And I think that's this huge opportunity for us to go much broader than really, really excellent coding agents, you know?

And that is honestly why I think OpenCLO has been so interesting is that, sure, it's connecting to all the data sources that Kyle the human cares about. And now my question is like, okay, how can I take all that and use that every day as a software dev connected together, not just have a new way to kick off a coding agent? And that's where we're at.

We're saying, okay, I'm gonna go use this CLI under the hood or this SDK, but that's not what I'm talking about. I'm talking about I'm having a conversation with you. It downloads the podcast and it realizes, oh, Kyle sounds like Kyle needs this app or this thing or this that level of exactly.

That level of that level of connectivity, I think, is where we still have a ton of ways to go in software because then when we have that red thread we wanna pull that idea, it can not only use the perfect way to write that code, but instead, all of the sort of taste and judgment calls and, you know, expertise that I've earned or that we've earned as a group and use it as part of the actual implementation.

Speaker 1

Yeah. You know, the extreme of it is AI runs your life. Right?

And I think there's a scary inversion of control in the way that I literally doing it in the way that developers mean it in terms of frameworks, like, you know, the the Hollywood principle, like, don't call me. I'll call you. Yeah.

Yeah. Like, there at some point, there's an inversion of control where, like, you you should you stop telling what the AI the AI what to do. Mhmm.

AI tells you what to do. Mhmm. And, like, that's a little bit scary, but also, like, maybe better.

Speaker 2

I mean, like, you know, Nat, I think Nat Freeman shared this in a, like a Stripe event, you know, like talking about his Open Claw was like, he connected Open Claw to his cameras and it was like watching He redirected his Uber. And it's There's a degree of this where I was like, I actually would love Open Claw to tell me to like drink water. I don't know that I want it to be, changing where my car goes.

But I do think that's kind of what I'm talking about, which is it needs to have so much more information at its disposal for it to be helpful to me. And I still don't think we're like anywhere near talking about AGI. I'm just talking about every time I have to tell you something I care about that I've ever kind of said or I've said a dozen times, it should be able to know that, codify that, or gain access to it.

Like, the dreaming ideas, like, are an attempt to kind of do some version of this.

Speaker 1

if if we can, you know, test that out a bit more. Yeah. Yeah.

Well, the other thing about OpenCLR that reminded me Yeah. Is Microsoft has a CVP Yeah. Dedicated to OpenCLR.

Yeah. Why? Because you don't think they should?

I don't know. I mean, I I I think CVP is a high title. Yeah.

Yeah. What why is this so important? Like, you know, Microsoft doesn't own OpenClaw.

Yeah.

Speaker 2

Like, what's what's the So, you know, we're talking a lot more about this at, Microsoft Build this year too. I think, like, the main thing is that what OpenClaw has done is it has made this connection for people to have access to the resources that you have access to and be able to do things for you in a way that previously people were trying to codify into their own agents. And so when you think about it, like, in the work context, wouldn't it be great to have a claw like object that I could actually run on my work device that or had access to my work assets made worked well on Windows, like, what that would look like.

And so I think that OpenCLO has become a personification of, like, a valuable agent that understands me because it has access to all of my information, and it can use a computer. And so thus, it can, you know, do a lot more than, just a task oriented process or like a, you know, a chat tool, etcetera. And that's like a bunch of, you know, the the goal of Build.

Right? Like, we're at Build this year trying to take a very different approach of, you know, it's unapologetically, you know, aimed at developers. We're trying to show the, like, bigger investment to not just say, hey.

Like you said, why do you have a CVP of OpenClaw? Well, because, like, one of the problems that we have, right, is that our agents, if you install them not on a Mac mini or not on a hosted device, you install them on a a personal device or a work device, we need better sandboxing at the OS level. I need to be able to use that claw and not, like, get fired.

And so Microsoft is like, okay. Great. Let's, like, do that too.

And then it's okay. Well, where should I be able to talk to this? Each of us just have a claw available to us at work?

Probably. Yeah. And so there you go.

Continuing to contribute a ton to the open source project too. Microsoft, I think, as I've gotten more and more information, there's so much investment into the open source projects themselves that for whatever reason, I think there's like this they don't wanna come off like, those teams don't wanna come off as, like, taking any credit or getting any recognition. But so many of these core contributors of teams are full time just pushing into open source projects.

Yeah. And, like, I think that's that kinda shows the difference between, like, well, why are we looking so hard at something like Claw? Why are we looking at sandboxing on Windows?

Why are we looking at cloud versions of sandboxing? Why are we looking? Because ultimately, like, we need more platform components.

We don't need everyone to be building the same exact, like, top line product.

Speaker 1

only delivering that single vertical, like, over and over and over again. Yeah. I I think, like, my maybe one way of framing it is that Microsoft is the original operating systems company.

Mhmm. Mhmm. And here's the new operating system for AI.

Yeah. Yeah. Yeah.

Speaker 2

are also in an era where we are like, we need to help build that bridge, You know? Like, all joking aside, like, operating systems need to look different than they looked five years ago because it's not just you using them anymore. Yeah.

You know? And that's changed the whole idea. It's not, okay, my claw is gonna create a user account.

Doesn't work like that. And so just like all of us, we all have to look much, much more deeply in the stack all the way down to the silicon layer in Azure to be like, okay, well, what do we need now? Because the workloads are different.

It's not just, okay, we need more inference. It's, okay, well, what type of inference do we need? What type of compute do we need to run these agents or run these agentic flows?

It's a really interesting kind of like multi, multilayer problem, versus kind of, I would say, you know, software in the last, you know, five or six years. We're all going to our events and we're kind of saying a version of the same thing. SaaS product has new SaaS thing.

Yes. It's the best SaaS thing ever. It was boring for a while.

You know? And so now it's like, oh my goodness, like we're at physics. Yeah.

Know, we're at physics problems. And that's exciting. Yeah.

Speaker 1

temperature superconductors Yeah. Still. Yep.

Yep. That's that's, that's never going away. No, I think like that that's a really good overview of like everything.

I I think have I have we left anything unsaid that you wanted to really get out there that we should cover? Yeah.

Speaker 2

I I'm really excited by like for folks, you know, checking out, checking out the announcements that we have a build. Like go, you know, you can go look at them online and take a look. I think that I'm hoping that it's driving, like, a degree of curiosity and interest because there's such this big shift that we're making at Microsoft, for developers where if you're a daily driver of, like, you know, a Mac device or a Linux device, you're like, okay.

I don't use Windows. I mean, like, there's improvements that are being made that I think are gonna surprise folks to just be like, oh, that's in like, they really wanna do that? Like, not, and I'm talking for developers.

I'm not talking for I play video games on the weekends on my Windows computer. I'm talking like my daily driver. Like, all the way from that to, okay, well, what is it like to build an agent or build an app and deploy it and run it at work in particular?

I think that is a big piece of it where I talk all the time, with the team. How I build on the weekend should be how I build at work. But if you're working in a Fortune one hundred or Fortune 500, you're probably not vibe coding an app and then shipping it to some service.

You gotta go through security and compliance. How can we move just as fast at work? And that's, I think, something that, we have a bunch of different offerings for to give you that same sort of agility and power, but in the work context.

And then I will tell you, like, I've mentioned it a couple times and it's very freaking cool. Like, if you are in the M 365 land in any way, check out WorkIQ, check out FoundryIQ. These little, like, oversimplifying context engines are wild good.

And, like, we've given them to our developers at GitHub. We've given them to employees at GitHub as we've used these tools to be able to just ask questions around everything that you have in your work context. And with Foundry IQ, be able to just do the same exact thing across all your existing stores, like, what not not move to new tools, just connect them in.

It's surprisingly powerful. And you your boss is still not gonna get fired and IT's not gonna turn it off because it's leaking all this private information. Yeah.

That is the trick that I think, is sometimes getting lost when we're talking about all these, all these great new platforms because I can use them. I'm like, oh, this is super powerful. Oh, and I can't like, I can't use it.

Like it's not because I'm at work at GitHub. It's I'm not allowed. Yeah.

It's because I'm not allowed because they can't do all the things that large complicated companies need. And so whether it be, like I said, just the kind of interesting daily driver curiosity all the way through to, oh my gosh, I can go use this at work tomorrow potentially and have that context layer, have that intelligence, it's a huge shift. And so, you know, check it out.

I'd love to hear I'm like, I'm not shy on social.

Speaker 1

but hopefully surprise folks a little bit. What I'm hearing I mean, so first of all, think that's that's great pitch. What I'm hearing actually is that you should put the WorkIQ people next to the Copilot people because like the the exact context problem that you named Yeah.

They solve enough for you to do your job, which is nuts.

Speaker 2

the thing that we are lit like, that's literally what has been happening the last several months. I already forecasted you were gonna It's like, look, totally because like, you're totally right. The code the code and the code asset problem is a little bit unique.

But otherwise, yeah, we're all working with each other now. It's all just context. Exactly.

Yeah. Amazing.

Speaker 1

Great. I'm going be there. I'm going to be doing a couple sessions there.

I'm going be interviewing Satya. I know. When I first started the pod, though, I had, like, Jeff Dean on Jeff like, Yeah.

It's, like, hall of fame of, like Sure. Sure. I wanna meet someday.

Satya's on there. So, like, what should I ask Satya?

Speaker 2

I mean, I think I think that the best question to ask is what he thinks is true in, like, two or three years from now. You know, like, seems like such a throwaway question. K.

But ultimately, the way that the way that he is looking at this AI problem, inference problem, token problem, and what we're how we're actually gonna be working. I think you can see some of the recent shifts that have been happening inside of Microsoft to kind of drive us to a place where it's not four, five, six, seven, eight different things. It's not a lack of context everywhere.

Speaker 1

pay off? Because that I think Wow. That's a bold okay.

I'll ask it. I'll say I'll say I prompted by you. But Absolutely.

It's a bold question because, you know, I think there's a lot of doubts, to be honest, like Of course. Externally. And and so, like, yes, I I I want, like, a straight answer from from him on that, think, would reassure a lot of people.

And, honestly, like, give me a lot of food for writing. Yeah. Yeah.

So thank you so much for spending your time. Of course. Thank you for doing what you do.

I think, like, you you know, as a COO, you don't need to be the external face, but like, because you are authoritative, because you you have so much background with GitHub and it's so authentic, like we on the outside feel it. So thank you for that. Of course.

Appreciate it. Thank you so much, Sean.

Shared via Hopper