GitHub Agentic Workflows
25 points
1 hour ago
| 6 comments
| github.github.io
| HN
clarkdale
6 minutes ago
[-]
I feel like this solution hallucinated the concept of Workflow Lock File (.lock.yml), which is not available in Github Actions. This is a missing feature that would solve the security risk of changing git tag references when calling to actions like utility@v1
reply
abracos
5 minutes ago
[-]
reply
lemonlime227
22 minutes ago
[-]
Alternative, less phishy link: https://github.com/github/gh-aw

This is on GitHub's official account. For some reason GitHub is deploying this on GitHub pages without a different domain?

reply
hmokiguess
36 seconds ago
[-]
So them using their own product makes it phishy? I don’t get it

It’s not like someone else can or could own this link, could they?

reply
eddythompson80
4 minutes ago
[-]
Why would that be phishy? They own the GitHub org on GitHub, hence github.github.io. I always thought it was a neat recursive/dogfood type thing even if not really that deep. Like when Reddit had /r/reddit.com or twitter having @twitter
reply
embedding-shape
3 minutes ago
[-]
When they launched github.io, they said it was for user-generated content, and official stuff will be on github.com. Seemingly that's changed/they forgot, but users seems to have remembered. Microsoft isn't famous for their consistency, so not unexpected exactly.
reply
ewuhic
6 minutes ago
[-]
Go: check

YAML: check

Markdown: check

Wrong level of abstraction: check

Shit slop which will be irrelevant in less than a year time: check

Manager was not PIP'd: check

reply
microflash
42 minutes ago
[-]
Soon: AgentHub Git Workflows
reply
throwup238
38 minutes ago
[-]
At which point the AI figures out its easier to just switch to jj
reply
TZubiri
25 minutes ago
[-]
Not confirmed that it's by Github, phishy domain.
reply
throwup238
17 minutes ago
[-]
Why is it phishy? Github.io has been the domain they use for all GH pages for a long time with subdomains mapping to GH usernames. It’s standard practice to separate user generated content from the main domain so that it doesn’t poison SEO.
reply
embedding-shape
23 minutes ago
[-]
Very weird of them to not use github.com but instead use the domain they otherwise use for non-github/user content. Phishy indeed, and then people/companies go ahead and blame users for not taking care/checking, yet banks and more continuously deploy stuff in a way to train users to disregard those things.
reply
rendx
21 minutes ago
[-]
Agreed, but looks like it: https://github.com/github/gh-aw
reply