<description>&lt;p&gt;This episode of &lt;strong&gt;Ship It Weekly&lt;/strong&gt; is about the developer toolchain becoming part of production. Brian covers GitHub’s critical git push RCE, AI-assisted reverse engineering, prompt injection against AI agents in GitHub workflows, Elementary’s malicious CLI release, GitHub’s merge queue regression, Cal.com going closed source, and Copilot moving toward usage-based billing. Plus: MinIO’s repo archive, Ghostty leaving GitHub, Docker Hardened Images, and Azure DevOps security updates.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;Links&lt;/strong&gt;&lt;/p&gt;&lt;p&gt;GitHub git push RCE &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://github.blog/security/securing-the-git-push-pipeline-responding-to-a-critical-remote-code-execution-vulnerability/"&gt;https://github.blog/security/securing-the-git-push-pipeline-responding-to-a-critical-remote-code-execution-vulnerability/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;AI-assisted reverse engineering &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://www.darkreading.com/application-security/reverse-engineering-ai-unearths-high-severity-github-bug"&gt;https://www.darkreading.com/application-security/reverse-engineering-ai-unearths-high-severity-github-bug&lt;/a&gt;&lt;/p&gt;&lt;p&gt;AI agents + GitHub Actions prompt injection &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://www.theregister.com/2026/04/15/claude_gemini_copilot_agents_hijacked/"&gt;https://www.theregister.com/2026/04/15/claude_gemini_copilot_agents_hijacked/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Elementary malicious CLI release &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://www.elementary-data.com/post/security-incident-report-malicious-release-of-elementary-oss-python-cli-v0-23-3"&gt;https://www.elementary-data.com/post/security-incident-report-malicious-release-of-elementary-oss-python-cli-v0-23-3&lt;/a&gt;&lt;/p&gt;&lt;p&gt;GitHub merge queue regression &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://github.blog/news-insights/company-news/an-update-on-github-availability/"&gt;https://github.blog/news-insights/company-news/an-update-on-github-availability/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a target="_blank" rel="noopener noreferrer nofollow" href="http://Cal.com"&gt;Cal.com&lt;/a&gt; going closed source &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://cal.com/blog/cal-com-goes-closed-source-why"&gt;https://cal.com/blog/cal-com-goes-closed-source-why&lt;/a&gt;&lt;/p&gt;&lt;p&gt;GitHub Copilot billing &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://github.blog/news-insights/company-news/github-copilot-is-moving-to-usage-based-billing/"&gt;https://github.blog/news-insights/company-news/github-copilot-is-moving-to-usage-based-billing/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;MinIO archived repo &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://github.com/minio/minio"&gt;https://github.com/minio/minio&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Ghostty leaving GitHub &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://mitchellh.com/writing/ghostty-leaving-github"&gt;https://mitchellh.com/writing/ghostty-leaving-github&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Docker Hardened Images &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://www.docker.com/blog/why-we-chose-the-harder-path-docker-hardened-images-one-year-later/"&gt;https://www.docker.com/blog/why-we-chose-the-harder-path-docker-hardened-images-one-year-later/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;Azure DevOps security updates &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://devblogs.microsoft.com/devops/one-click-security-scanning-and-org-wide-alert-triage-come-to-advanced-security/"&gt;https://devblogs.microsoft.com/devops/one-click-security-scanning-and-org-wide-alert-triage-come-to-advanced-security/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;On Call Brief &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://oncallbrief.com/"&gt;https://oncallbrief.com/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;More episodes &lt;a target="_blank" rel="noopener noreferrer nofollow" href="https://shipitweekly.fm/"&gt;https://shipitweekly.fm/&lt;/a&gt;&lt;/p&gt;</description>

Ship It Weekly - DevOps, SRE, Platform and Cloud Engineering News

Teller's Tech - DevOps, SRE and Cloud Podcast

GitHub RCE, AI Agent Prompt Injection, and the New Reality: Your Developer Toolchain Is Production Now

MAY 1, 202625 MIN
Ship It Weekly - DevOps, SRE, Platform and Cloud Engineering News

GitHub RCE, AI Agent Prompt Injection, and the New Reality: Your Developer Toolchain Is Production Now

MAY 1, 202625 MIN

Description

<p>This episode of <strong>Ship It Weekly</strong> is about the developer toolchain becoming part of production. Brian covers GitHub’s critical git push RCE, AI-assisted reverse engineering, prompt injection against AI agents in GitHub workflows, Elementary’s malicious CLI release, GitHub’s merge queue regression, Cal.com going closed source, and Copilot moving toward usage-based billing. Plus: MinIO’s repo archive, Ghostty leaving GitHub, Docker Hardened Images, and Azure DevOps security updates.</p><p><strong>Links</strong></p><p>GitHub git push RCE <a target="_blank" rel="noopener noreferrer nofollow" href="https://github.blog/security/securing-the-git-push-pipeline-responding-to-a-critical-remote-code-execution-vulnerability/">https://github.blog/security/securing-the-git-push-pipeline-responding-to-a-critical-remote-code-execution-vulnerability/</a></p><p>AI-assisted reverse engineering <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.darkreading.com/application-security/reverse-engineering-ai-unearths-high-severity-github-bug">https://www.darkreading.com/application-security/reverse-engineering-ai-unearths-high-severity-github-bug</a></p><p>AI agents + GitHub Actions prompt injection <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.theregister.com/2026/04/15/claude_gemini_copilot_agents_hijacked/">https://www.theregister.com/2026/04/15/claude_gemini_copilot_agents_hijacked/</a></p><p>Elementary malicious CLI release <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.elementary-data.com/post/security-incident-report-malicious-release-of-elementary-oss-python-cli-v0-23-3">https://www.elementary-data.com/post/security-incident-report-malicious-release-of-elementary-oss-python-cli-v0-23-3</a></p><p>GitHub merge queue regression <a target="_blank" rel="noopener noreferrer nofollow" href="https://github.blog/news-insights/company-news/an-update-on-github-availability/">https://github.blog/news-insights/company-news/an-update-on-github-availability/</a></p><p><a target="_blank" rel="noopener noreferrer nofollow" href="http://Cal.com">Cal.com</a> going closed source <a target="_blank" rel="noopener noreferrer nofollow" href="https://cal.com/blog/cal-com-goes-closed-source-why">https://cal.com/blog/cal-com-goes-closed-source-why</a></p><p>GitHub Copilot billing <a target="_blank" rel="noopener noreferrer nofollow" href="https://github.blog/news-insights/company-news/github-copilot-is-moving-to-usage-based-billing/">https://github.blog/news-insights/company-news/github-copilot-is-moving-to-usage-based-billing/</a></p><p>MinIO archived repo <a target="_blank" rel="noopener noreferrer nofollow" href="https://github.com/minio/minio">https://github.com/minio/minio</a></p><p>Ghostty leaving GitHub <a target="_blank" rel="noopener noreferrer nofollow" href="https://mitchellh.com/writing/ghostty-leaving-github">https://mitchellh.com/writing/ghostty-leaving-github</a></p><p>Docker Hardened Images <a target="_blank" rel="noopener noreferrer nofollow" href="https://www.docker.com/blog/why-we-chose-the-harder-path-docker-hardened-images-one-year-later/">https://www.docker.com/blog/why-we-chose-the-harder-path-docker-hardened-images-one-year-later/</a></p><p>Azure DevOps security updates <a target="_blank" rel="noopener noreferrer nofollow" href="https://devblogs.microsoft.com/devops/one-click-security-scanning-and-org-wide-alert-triage-come-to-advanced-security/">https://devblogs.microsoft.com/devops/one-click-security-scanning-and-org-wide-alert-triage-come-to-advanced-security/</a></p><p>On Call Brief <a target="_blank" rel="noopener noreferrer nofollow" href="https://oncallbrief.com/">https://oncallbrief.com/</a></p><p>More episodes <a target="_blank" rel="noopener noreferrer nofollow" href="https://shipitweekly.fm/">https://shipitweekly.fm/</a></p>