frontpage.
newsnewestaskshowjobs

Made with ♥ by @iamnishanth

Open Source @Github

fp.

Open in hackernews

Tell HN: GitHub might have been leaking your webhook secrets. Check your emails.

19•ssiddharth•3h ago
Got an email from Github a few minutes back asking me to rotate my webhook secrets, the relevant portions of it below.

We're writing to let you know that between September 2025 and January 2026, webhook secrets for webhooks you are responsible for were inadvertently included in an HTTP header on webhook deliveries. This means that any system receiving webhook payloads during this window could have logged the webhook secret from the request headers. Webhook deliveries are encrypted in transit via TLS, so the header containing the secret was only accessible to the receiving endpoint in a base64-encoded format. We have no evidence to suggest your secrets were intercepted. This issue was fixed on January 26, 2026. Please read on for more information.

User privacy and security are essential for maintaining trust, and we want to remain as transparent as possible about events like these. GitHub itself did not experience a compromise or data breach as a result of this event.

What happened?

On January 26, 2026, GitHub identified a bug in a new version of the webhook delivery platform where webhook secrets were included in an `X-Github-Encoded-Secret` HTTP header sent with webhook payloads. This header was not intended to be part of the delivery and made the webhook secret available to the receiving endpoint in a base64-encoded format. Webhook secrets are used to verify that deliveries are genuinely from GitHub, and should only be known to GitHub and the webhook owner.

The bug was limited to only a subset of webhook deliveries that were feature flagged to use this new version of the webhooks platform. The bug was present between September 11, 2025, and December 10, 2025, and briefly on January 5, 2026. The bug was fixed on January 26, 2026.

What information was involved?

The webhook secret for each affected webhook was included in HTTP request headers during the window that the bug was present. The webhook payload content itself was delivered normally and was not additionally affected. No other credentials or tokens were affected. Webhook deliveries are encrypted in transit via TLS, so the header containing the secret was only accessible to the receiving endpoint.

If the receiving system logged HTTP request headers, the webhook secret may be present in those logs. The webhook secret is used to compute the `X-Hub-Signature-256` HMAC signature on deliveries — if compromised, an attacker who knows the secret could forge webhook payloads to make them appear to come from GitHub.

Comments

esher•3h ago
Got that too. My first reaction: Go to HN to understand what's going on. Where are the comments?
sph•2h ago
> webhook secrets for webhooks you are responsible for were inadvertently included in an HTTP header on webhook deliveries

LOL how does this even happen?

freakynit•2h ago
Same reaction of mine as well. I mean, how do you even fck up this way? ... I dont know why, but, this is giving me vibe-coded vibes.

Developer might have prompted to include some signature (definitely they didn't use this word, or else AI would not have messed this way) to verify the webhooks as being coming from legitimate source, and AI probably went ahead with the secret key itself :)

suralind•2h ago
How come it took them so much time to send this notification? I'm so fed up with their bs.

Sony Boss Urges Theaters to Stop 30 Minutes of Trailers and Ads Before Movies

https://variety.com/2026/film/news/sony-pictures-boss-cinemacon-urges-fewer-ads-trailers-1236720830/
1•randycupertino•46s ago•0 comments

How I made my skills update themselves

https://joost.blog/self-updating-agent-skills/
1•twapi•59s ago•0 comments

Amex Debuts Ace Developer Kit with Registered Agent Protection

https://www.americanexpress.com/en-us/newsroom/articles/innovation/american-express-debuts-agenti...
1•amex_tech•2m ago•0 comments

A simpler, faster way to unlock 1Password

https://1password.com/blog/a-simpler-way-to-unlock-1password
1•doener•2m ago•0 comments

Show HN: Yggdrasil – Scoped architectural rule enforcement for AI-generated code

https://github.com/krzysztofdudek/Yggdrasil
1•chrisdudek•2m ago•0 comments

WCAG Issues That Cause 90% of Ada Lawsuits (+ How to Fix Them)

https://getaccessguard.com/posts/the-10-wcag-issues-that-trigger-90-of-ada-website-lawsuits-and-h...
1•chille87•3m ago•0 comments

How We Use Claude Code and Build with Agents at Fiberplane

https://fiberplane.com/blog/2026-04-10-how-we-use-claude-code-and-build-with-agents-at-fiberplane...
1•miesie•5m ago•1 comments

On the Shoulders of Capitalism [video]

https://www.youtube.com/watch?v=hbryGfM23Ys&list=PL3C6eF-zu5AZF3k0rW1Kwhzo9FFcJeHRk&index=23
1•DesaiAshu•8m ago•0 comments

How to Get Cheaper Lab Equipment

https://chillphysicsenjoyer.substack.com/p/how-to-get-cheaper-lab-equipment
1•crescit_eundo•8m ago•0 comments

New Boutique in Cow Hollow Is Completely Run by AI, Which Manages Human Staff

https://sfist.com/2026/04/14/new-boutique-in-sfs-cow-hollow-is-completely-run-by-ai-which-manages...
1•cdrnsf•11m ago•0 comments

The "AI Vulnerability Storm": Building a "Mythos-ready“ security program [pdf]

https://labs.cloudsecurityalliance.org/wp-content/uploads/2026/04/mythosreadyv9.pdf
1•_tk_•13m ago•0 comments

Show HN: Send physical postcards from your coding harness

https://api.melonpost.com/SKILL.md
1•thevelop•13m ago•1 comments

Which country can claim steak?

https://www.bbc.com/travel/article/20260402-which-country-can-claim-steak
1•Cider9986•14m ago•0 comments

Sindarov Wins Candidates with Round to Spare

https://www.chess.com/news/view/2026-fide-candidates-tournament-round-13
1•FergusArgyll•15m ago•0 comments

Chinese Electrotech Is the Big Winner in the Iran War

https://paulkrugman.substack.com/p/chinese-electrotech-is-the-big-winner
3•dxs•15m ago•0 comments

Who sent you? – The agent identity crisis

https://highflame.com/blogs/who-sent-you-solving-the-agent-identity-crisis
3•jalbrethsen•17m ago•0 comments

Show HN: Monitor AWS activity and security events using CloudTrail

https://github.com/cloudwatcher-dev/cloudwatcher-aws-cloudformation
1•henriklipp•18m ago•0 comments

Court rules X must give privacy researcher access to personal data

https://nltimes.nl/2026/04/14/court-rules-x-must-give-privacy-researcher-access-personal-data-pri...
3•Kiala•18m ago•0 comments

What Would You See Changed in Haskell?

https://blog.haskell.org/what-would-you-see-changed-in-haskell/
3•birdculture•22m ago•0 comments

Why, After All These Years, MZI-Based Transistorlessness Might Finally Be Here

https://write.as/mnggfj7asl07k
1•aniijbod•23m ago•0 comments

Show HN: Sk.illmd.com, a forum for talking about and showing off agent skills

https://skillmd.discourse.group/
2•0gs•24m ago•1 comments

Poking at AttnRes with NanoGPT

https://axu.sh/post/attention-residuals
2•abhiux•24m ago•0 comments

AI is flattening who we uniquely are

https://twitter.com/heyohelen/status/2044126575399186565
1•trovewithin•25m ago•0 comments

Truth Machine: PW Talks with Kevin Hartnett

https://www.publishersweekly.com/pw/by-topic/authors/interviews/article/100085-truth-machine-pw-t...
1•digital55•26m ago•0 comments

Finding unusual machines in network scans

https://xn--mbius-jua.band/blog/nmapview/
2•gebgebgeb•26m ago•0 comments

Nvidia slaps forehead: I know what quantum is missing – it's AI

https://www.theregister.com/2026/04/14/nvidia_ai_quantum_computing/
1•blackcoffeerain•27m ago•0 comments

AI platform that audits websites daily and tracks competitor SEO

https://arlocmo.site
1•decentrowe•27m ago•0 comments

Fake Linux leader using Slack to con devs into giving up their secrets

https://www.theregister.com/2026/04/13/linux_foundation_social_engineering/
1•blackcoffeerain•29m ago•0 comments

The cost of building a workflow editor on React Flow

https://www.workflowbuilder.io/blog/build-vs-buy-workflow-editor-hidden-cost-react-flow
7•maciek996•29m ago•1 comments

Why Amazon Is Buying Starlink Rival Globalstar in $11B Deal

https://www.wsj.com/tech/amazon-to-acquire-globalstar-in-satellite-cellular-connection-push-448d5a16
4•JumpCrisscross•29m ago•0 comments