In short
GitHub’s plan for “agents” and how AI-driven workflows should work across Microsoft (Teams, Slack, email, GitHub) without forcing people to change how they work; also covers AI skills design, trust/review for agent-written code, and security/operations lessons from GitHub Actions and npm.
Guest
Kyle Daigle, GitHub executive (COO/CMO-style outward-facing role). Background: joined GitHub as a developer; built webhooks, API/platform integrations; led engineering teams through ~2018; launched the first GitHub Actions version around Oct 2018; later moved into business leadership after Microsoft acquisition. He still codes and uses AI to build internal tools and workflows.
Key claims
GitHub is shifting from “mega skills” to micro/atomic skills that can be composed; agents should “look back” (summarize PRs, posts, notes, transcripts) and then “look forward” with tweaks. Internal AI rollout avoids retraining by granting context via CLI and MCP/WorkIQ. Trust for agent PRs remains a social/human problem, not just verification. Security requires containerized execution for Actions and careful npm changes that may break users.
Notable examples
summarizing PRs and marketing messaging from Obsidian notes, Teams/Slack transcripts via MCP; building an AI-assisted revenue-planning slide deck without revealing it was AI-generated; containerization and Azure “Dev Compute” for agent execution; npm acquisition goals: keep npm scaling while improving security posture; invalidating exposed tokens and changing 2FA policies.
Written by AI. May contain mistakes. Listen to the episode to check what was said.
Chapters
Tap a time to open that second in VOKyle's Role and Perspective at GitHub
0:28 to 1:12
Discussion on Kyle's role at GitHub and his approach to product development.
“and passion for developers and how we work with them and how we communicate and, you know, how we bring our products to market.”
The Journey from Developer to COO
1:12 to 2:24
Kyle shares his journey from being a developer to becoming COO and CMO.
“You have lots of stuff planned, and we can sort of touch on that whenever it's appropriate.”
Passion for Coding and People
2:24 to 3:10
Kyle discusses the challenges of balancing coding with managing people.
“And I think as my role expanded, it became my ability to talk to not just developers, but also enterprise customers or business leaders and have this translation layer.”
Re-engaging with Coding through AI
3:10 to 4:00
Kyle talks about how AI has reignited his passion for coding.
“So, I mean, like for me, I think the – I still code.”
Building AI Workflows and Retrospection
4:00 to 5:59
Discussion on using AI to analyze past work and improve future workflows.
“I think what you see there is me like really getting back to coding thanks to AI.”
Internal Communication Strategies at GitHub
5:59 to 7:06
Kyle explains how GitHub manages communication and access to information across teams.
“I find that to be so much more valuable, especially for like non-technical because that retrospection is actually – LMs are very good at that, you know, like finding all the patterns, pulling them out.”
Managing Skills and AI Overload
7:06 to 10:36
Kyle discusses the challenges of managing numerous skills and AI tools within the team.
“I mean, I think, you know, when we started rolling out AI internally beyond engineering, right?”
The Evolution of AI Skills in the Workplace
10:36 to 14:00
Exploration of how AI skills have changed and the importance of tailoring them to different roles.
“Everyone has their thing and they're trying to promote it to the rest of their peers in their org.”
Navigating Developer Concerns Across Professions
14:00 to 18:12
Explore the varied interpretations of AI and its implications across different professions.
“And that, I think, is the interesting matrix problem when we go from a developer set of concerns to all kinds of different professions.”
Leveraging AI for Business Efficiency
18:13 to 21:46
Learn how AI tools enable efficient data handling and creative processes in business.
“We talk about, okay, what is it going to look like for next year?”
Show all 31 chapters
Evolution of Roles in Leadership with AI
21:47 to 26:33
Understand the shifting dynamics of leadership roles in light of AI advancements.
“We can dive into more sort of productivity insights as you go.”
The NPM Acquisition and Its Impact
26:34 to 28:01
Discuss the significance of GitHub's acquisition of NPM and its effects on the ecosystem.
“But like, it is a unique challenge in that every move that we make to make it more secure will break a lot of people.”
GitHub's Security Changes and Community Impact
28:01 to 29:29
Learn about the recent changes to GitHub's security policies and the challenges they pose to developers.
“We're like, you know, anytime that we have a problem with GitHub or we make a change that makes us more secure, there's like a snow day for developers or a really bad fire that they have to go put out.”
The Evolution of Code Publishing and Security
29:30 to 31:38
Explore the historical context of code publishing and the ongoing security challenges faced by developers.
“How we each do that, like especially when we're talking to enterprise customers, it's just like very, very different.”
Maintainer Perspectives on GitHub's Role
31:39 to 33:59
Discover how GitHub interacts with maintainers and the balancing act of security vs. community needs.
“But like how do you balance that sort of role in the industry to keep everything as secure as possible and make sure that you're not going to be compromised as a human because that's usually how it all happens.”
Trust Issues in AI-Powered Development
34:00 to 36:39
Delve into the complexities of trust and verification in AI-assisted coding workflows.
“I hear a lot of people don't know the history of the pull request.”
The Challenge of Trust in Open Source and AI
36:40 to 41:21
Understand the implications of trust in open-source projects, especially with AI involvement.
“Well, I mean, depending on what level of self-driving.”
The State of Stars and Developer Engagement
41:22 to 42:05
Examine the current state of GitHub stars as a measure of project credibility and developer engagement.
“Like how many of these are real or bought or like whatever.”
The New Wave of Developers on GitHub
42:05 to 45:24
Explore how AI is inviting a broader range of people into software development.
Breaking Barriers in Software Development
45:24 to 47:26
Discussing the importance of accessibility in software development for everyone.
“I think the best thing for me as like someone that did not like, you know, traditionally come into software dev way, way, way back.”
The Growth and Challenges at GitHub
47:26 to 49:24
Understanding the rapid growth of GitHub and the challenges that arise with it.
“Sure, there's absolutely, you know, silly problems that shouldn't exist.”
Scaling Issues and Infrastructure Improvements
49:24 to 56:00
Examination of scaling challenges in GitHub's infrastructure and the solutions being implemented.
“Because that'll still happen in that, you know, in that GitHub, you know, tool, that GitHub community.”
Scaling Challenges at GitHub
56:00 to 1:02:10
Learn about the complexities GitHub faces in scaling its infrastructure and services.
“Horizontal isn't working either because, like, we all have some CPU or GPU constraints in the world now.”
The Evolution of GitHub Copilot
1:02:10 to 1:07:30
Discover the development and challenges of GitHub Copilot from its inception to current enhancements.
“So how many original creators of Copilot are there?”
Future of AI in Software Development
1:07:30 to 1:10:03
Explore the potential of AI and coding agents in transforming software development practices.
“And we all codify that in rules and memory and everything else.”
The Future of Software Development with AI
1:10:03 to 1:11:41
Explore how AI could transform decision-making in software development.
“And none of these tools are ultimately doing this.”
Inversion of Control in AI
1:11:42 to 1:13:28
Discuss the implications of AI taking control in software development.
“You know, the extreme of it is AI runs your life, right?”
Understanding OpenClaw's Role
1:13:29 to 1:15:20
Learn about OpenClaw and its impact on software development tools.
“And so I think that OpenClaw has become the personification of like a valuable agent that understands me because it has access to all of my information and it can use a computer.”
Challenges of AI Integration
1:15:21 to 1:17:19
Discuss the complexities of integrating AI into existing systems.
“Like, Microsoft, I think, as I've gotten more and more information, like, there's so much investment into the open source projects themselves.”
Microsoft's Strategy for Developers
1:17:20 to 1:19:34
Understand Microsoft's new approaches for empowering developers.
“What type of compute do we need to run these agents or run these agentic flows?”
Innovations at Microsoft Build
1:19:35 to 1:21:42
Discover exciting new tools and offerings announced at Microsoft Build.
“If you are in the M365 land in any way, check out WorkIQ.”
Transcript
Automatic transcript. May contain errors.0:27Kyle Daigle:Kyle Daigle and passion for developers and how we work with them and how we communicate and, you know, how we bring our products to market. We're also bringing that expertise, you know, to the broader Microsoft ecosystem and helping every developer that uses a Microsoft, you know, product or would like to, to have a sort of similar experience that they've had with, you know, GitHub over the years. So it's a big different role in some ways, but it's also just building on the experience that, you know, I've had at GitHub of just sort of tell the truth, be authentic, show people how to use it, and then let the, you know, products speak for themselves.
1:07Kyle Daigle:Not just doing that with all of Microsoft. Yeah, and we'll be releasing this in conjunction with Build. You have lots of stuff planned, and we can sort of touch on that whenever it's appropriate. I think one of the interesting things is I rarely meet a COO who's also a CMO. I think you're very outward-facing and you're very confident publicly. That's rare. Do you actually view yourself as COO? What is your thing? I think for me, it's been funny. The titles have always felt a little strange to me. I joined GitHub as a developer. I wrote so much of the... Let's bring that up. You wrote the back end?
1:48Kyle Daigle:Yeah, I was going through some old photos when folks were talking about how things were being built or how others would build GitHub. I built webhooks and worked with teams building the API, built the platform layer, anything that integrated with GitHub. Up until really 2018, I was built or ran the engineering teams. And that's kind of where the beginning of my passion always was, was helping people build things, deliver them to their customers. And so being a developer, building for developers was always super unique. And I think as my role expanded, it became my ability to talk to not just developers, but also enterprise customers or business leaders and have this translation layer.
2:39Kyle Daigle:And then through all those years, GitHub has always operated pretty uniquely. Post-pandemic, working remotely was not as novel as it was when GitHub started in 2008. But all that expertise of running remote teams, doing it well, became this sort of bigger role, ultimately turning into the COO role of how do we operate GitHub in the way that GitHub's always operated after the Microsoft acquisition. And kind of so on from there. So, I mean, like for me, I think the – I still code. I love coding. But the problem has always been like people. It's a much harder problem to both support our own employees, harder problem to communicate to developers and enterprise buyers what we're building, why it matters because those are two very different messages.
3:32Kyle Daigle:and so getting to work in the mix of COO, CMO, also just being a dev, I think is what's kept me at GitHub for so long. Yeah, apparently you have, your commits have gone up. What's this? What's going on? Yeah, I mean, Ruiz called me out pretty aggressively. So, I mean, you know, I think, I mean, as you can imagine, right, like you can see my like normal era of being a dev in the 2013, 2014 era and then moving into management and then ultimately the COO role. I think what you see there is me like really getting back to coding thanks to AI. You know, I similar to like attaching problems between, you know, how to market and how to operate a business and how to code.
4:15Kyle Daigle:I find like building agents and workflows that are connecting very disparate problems to be what's driving this. So that's like some of it's writing software. A lot of it is like connecting a ton of different data sources to like help me out. But that is completely me, you know, really, really diving in on the AI side and trying out our tools, trying out everyone's tools. But building for me, building for the non-technical leader, though I'm technical, and how we're able to use these tools more than just the simple call and response, that I think a lot of the non-technical, your employer is like, you have to use AI.
4:59Kyle Daigle:And so everyone uses like ChatGPT or Copilot or Claude or whatever to really get into like, how is this going to help me out? I find that it's not the I need to write a blog post. I need to, you know, those simple examples, helping people find the workflows of like, OK, I need you to go through all the PRs today. I need you to go through everything that we've posted online. I need you to go through what we've did the last, you know, three months, go through all of my Obsidian notes for any mentions of this. then go through my transcripts at work where we use Teams. So like using WorkIQ, go call that MCP server, grab all the transcripts, go through all the Slack, and then build me out the plan of like what this week's messaging actually was.
5:42Kyle Daigle:That's something that was like impossible because for me, I find AI in like what most of this like launch here is, is actually like less building forward. It's actually like a recursive loop backwards. I'm always looking at what had happened first. Like go back through the week and tell me what we did, what worked, what didn't work, you know, and then tell me in the next, you know, three or four days, what would you tweak based on, you know, this sort of like looking backwards and then looking ahead a little bit. I find that to be so much more valuable, especially for like non-technical because that retrospection is actually – LMs are very good at that, you know, like finding all the patterns, pulling them out.
6:23Kyle Daigle:and then applying that retrospection to just a couple of days or just like a short period of time is all a bunch of apps that I've built and launched, like a bunch of internal tools. I use the new GitHub Copilot app, the desktop app with workflows. Every time I crack open my laptop, it's running workflows for me. It's just a ton of different stuff. And of course, it all ends up on GitHub. Of course, that's where stuff is hosted. Man, there's so much to ask you. I was going to leave the how do you run a company with AI thing at the end. I have to ask one, double click one thing. You said like you are looking back at the week, you're understanding what happens.
7:03When you say we, that's 3 ,000 people.
7:06Kyle Daigle:Yeah. Yeah. How? I mean, I think, you know, when we started rolling out AI internally beyond engineering, right? one of the things that I was really, really passionate about is like, we have to do this in a way where no one has to change how they work. I don't want to have to teach you a tool. I don't want to have to teach you something new. And so for us, we tried out a few tools. Most of them don't work because I got to get you on board. You know, I got to teach you how to use it. What we've actually ended up doing is we've built like a set of, you know, skills internally. We have like, we each have our set of skills and we've just been distributing even to the non-technical folks the cli and then effectively we're just giving it access to like read about everything that we're writing so that's for us that's usually github um teams email and slack um so teams for video chat generally speaking teams and slack yeah i mean so we use teams for video communication like but we don't use it for chat we get hub for a long long history right we always talk about chat ops and like everything is built into slack like every command every flow even though you've been acquired for like i don't know eight years now yeah uh yeah i mean we still use the heck yes i mean it's a purpose-built tool for us i think the reality is that moving off of it would be so like bluntly expensive you know simply because all the tooling is uh baked in with that paradigm and they both have their pros and cons like but they don't work the same way like at all.
8:41Kyle Daigle:Yeah, I mean, we still use a bunch of different tools because it's, you know, the purpose-built tools that we need. But the same doesn't go for the rest of Microsoft, presumably. I mean, like, you know, various teams operate in various ways, you know. I think it just matters what you're trying to do. Yeah, yeah. But we do, you know, we do work across kind of every tool that we use, and then by giving everyone access to all of that context in the new WorkIQ MCP cert, which is quite cool if you do live in the M365 world. I can ask it all these backwards-facing questions, and it's incredibly important for our teams that are working remotely.
9:25Kyle Daigle:There's a lot of stuff you miss when you're not in an office, and we are spread out all over the world. So most of that is looking back. And then we post either automatically into GitHub issues or discussions, these sorts of findings or our industry reports, like what's happening this morning, today, yesterday. A little automation gets run. We'll use the app. We might use GitHub Actions with our agentic workflows just to go do that run. And then we push it into GitHub, and we keep having a conversation. So usually for us, it's about that sort of like looking back, looking forward on the non-technical side.
10:03Kyle Daigle:And then, of course, for a lot of those folks, it's also, you know, building an app, pushing it to get a pages or pushing it somewhere to host it, et cetera. But it's just like enabling everyone with that power of it's going to take me a week to figure this out. Instead, we're going, OK, like I built a skill. Let's put it into a repo. We'll all share that skill together. And then we'll use the CLI or now the app just to run it. All right. I think we're going straight into the team management and productivity thing. I think a lot of people are getting various levels of LM psychosis. How do you manage the bloat of skills?
10:39Everyone has their thing and they're trying to promote it to the rest of their peers in their org. And obviously whoever becomes a skill influencer internally becomes an AI leader of all sorts. I assume you have those.
10:50Kyle Daigle:Yeah, I mean, like, I think we have. I assume it's a mess. Yeah, I mean, there's like, I think the reality is there's two pieces. Like, first is I think that we're ending the era of these, like, massive, beautiful, perfect skills that are just, like, not any of those things, you know? Because for a while, right, like, every tweet every day is, like, go download the skills, the perfectly managed thing to do this entire workflow. And I think that like what we found in what I was just with my team this week and we were talking about the skill side and we're really talking about these like incredibly micro skills that are just doing one thing for us very, very well versus a skill that's going to do, like I said, that full report.
11:32Kyle Daigle:That doesn't really exist on our side anymore. You know, it's usually like a single skill that's going to identify the most important marketing information given any MCP server. Like this is the most important thing. Less about stitch a bunch of tools together and have it produce this mega output because then weeks go by, months go by, things change, and you want to tweak your mega skill and you're screwed. You know, you can't do that. And so now we're really just talking about like the Legos we're using and letting the instruction book, you know, be something we're all putting together. Whereas I think a lot of AI skills for a while have been that mega, you know, instruction book style.
12:15Yeah, I've thought a lot about Postel's Law. I don't know if that's a term that means things to folks. It's the idea that you should be liberal in what you accept and strict in what you output. Right. And I think that's like a good framing principle for skills. This is my skills, obviously, on GitHub. I feel like everyone should have, like, you know how some repos in GitHub are special repos? Sure, sure. I feel like we should sort of reify the slash skills and everyone, like, give it some kind of special presentation. Yeah, yeah, yeah. Anyway, so, yeah, this is one of those, like, download anything, transcribe anything, and then you can string together the atomic skills that do one thing well into, like, some kind of orchestration skill that calls other skills.
12:54I assume, does that match?
12:56Kyle Daigle:Yeah, I think so. I think that the the summarize anything totally like I think the for me summarizing something for like you know I do communications and PR and analyst relations and marketing and customer activities and so my summarize everything is very different for each one of those like contexts you know what I mean because if I'm summarizing something for an analyst that's a very different thing than I'm probably how I'm going to summarize something for like a customer meeting or an engagement so that's i think like the difference when we're talking about the um like the tools i might use on saturday you know or the skills i might use on a saturday when it's just for kyle yeah those are kind of like they have an atomic actual tool underneath or maybe skill and then kyle cares about x but i think when we're talking about work and enabling the uh you know the marketers communicators there it's the atomic this is what good summarization is and then And this is what I care about as for marketing, for communications, for whatever.
14:00Kyle Daigle:And that, I think, is the interesting matrix problem when we go from a developer set of concerns to all kinds of different professions. Is that what that word means to me is different than it means to you. It's different than it means to the analyst or the salesperson. And that's where I think the matrix mess is that we're still starting to find. It's not these mega skills, but they're all just slight permutations, but those permutations are really important. It's the difference between someone reading this and going, did AI make this? You know what I mean? Or like this makes total sense and I would expect this when I'm giving a briefing to Gartner or like whatever else.
14:37Yeah. I think the beauty of it maybe is that you don't have to be that careful about what goes in there. It doesn't have to exactly fit as long as it like roughly is contained in there. i used to complain about plug-in hell basically like when you have a framework and then you have a hundred things that you need to integrate everyone does like the github used to be bloated full of these things and now we don't need them anymore yeah it's not easy skills yeah
15:00Kyle Daigle:and like i think the most magical thing is that just that like i can just also crack it open like yeah you know like yes i could go like you know change the how the plugin is coded or like i could go uh you know do that now with ai but i think there's just something more magical about getting a response back and being like that's not right and then you just crack the skill open you just type english words you know and it's different uh that that building block is just uh i think very unique um once uh once i get everyone to kind of understand how to best uh you know how to best make those changes uh uh you know to get the most power out of them is there you know you you have a your peer group of people like you is there a common framing for something i'm feeling is just true is that uh this is a golden age for former developers who are now in leadership right because you can wield the tools you would know the right words you're maybe not too close to the details sure doesn't matter yeah but like you're more effective than someone who doesn't come from that background i think that like the secret has always been your ability to identify patterns and solve problems and i think that you know for folks that like myself that don't code day-to-day anymore that has made me successful as a developer made me successful as coo now cmo and so now that i have access to get and write code i'm now applying that sort of like pattern finding and problem solving and i know enough still you know about how to then go and say oh i want to make an app and i don't want to you know break into jail or create something that's not going to be able to work or to be deployed scale or whatever uh that ability to apply all that additional business knowledge you know and still code i think is what makes that so interesting to me slightly different than i think some of the other like technical leaders that became business leaders and now are going back to their apps in updating them good for them you know but i think that the more much more interesting thing is well now i have this whole new set of expertise over 10 plus years why not take that and use that as a developer with these ai tools so i definitely think that makes me more powerful but i think that's true for like every dev as well you know most of the dev friends i still have also have some other underlying skill and passion you know there's really talented very you know kind of linear computer science software devs absolutely i just find that the folks that came from a different career went to school for something else went off and did this random thing and then became a software dev or where a dev did a random thing came back.
17:36Kyle Daigle:Learning that extra set of information, learning those extra skills, and now having the power of an AI where I can crank up 15 agents on Saturday, you know, while my kids are doing lacrosse, that's, like, really powerful. And I think it gets me back to that feeling of, like, creation. And it's very hard to, like, replicate that in most other senses. You know, that first time you build an app and you click it and you show someone, like, That's magical. And so being able to do that, not just in code, but across all kinds of different assets, that's huge.
18:13Kyle Daigle:Every year we do our revenue planning. We talk about, okay, what is it going to look like for next year? And, of course, as you imagine, there's slideshows everywhere talking about what are we going to talk about, what's the narrative, et cetera. and so as you said you know i'm like okay well i could probably just like build something to build this and then that way i don't have to go build the whole spreadsheet or i have to pass it to my team so we went through this process and i got all the information and used the skills i mentioned i built like a little app just to make it so i could look at some of the information in a sqlite database more easily and i ultimately built this entire presentation without touching any of it and I was like, okay, I'm just going to present this to our CRO, the CFO, their teams.
18:55Kyle Daigle:Without mentioning, I built it with AI. I built a skill to make it look very much not AI-driven. Not pretty, but just very clearly not AI. Kind of like, don't do anything interesting. Just go, exactly. We did the whole thing through. It used my notes from Obsidian. It used all the context I mentioned before, the plans. And never came up once that it was AI-generated. Never once. exactly it didn't matter and so now i can take that tool and go look i don't want you to go build slideshows yeah they're just helping us share information with each other if this thing can do it with a little bit of crafting from you and then we can look at it together awesome there's no value in all that extra work yeah i think that the ability to like make it look humanly bad and you know like and build a little app to like manipulate the data i think is part of like uh that upside for devs that are now in leadership roles because like the thing that i feel like uh like i said before this that's all a people that's all people problem i know if you've used a co-worker or not to build a slide deck unless you spent a bunch of time to to not do it okay well so like i think there's a certain charm to just being blatantly ai so i think you're like well you're just honest about like there may be mistakes here that i cannot vouch for yep um so you know how much value is is there but anyway like i think actually the real question i want to ask is like there's you were a chief of staff to thomas yeah and in in the pre-ai world that that job would have been a chief of staff job of like can you prep me these slides and all that yeah and now you do it yourself yeah i mean like i still i still have a chief of staff because like the difference is like it's sort of the the discussion every time we you know have some sort of technology uh you know evolution is it's not that the the jobs like the roles don't all go away they just change you know and so yeah i don't have someone spending all their time building out slides for me in presentations because i don't need that anymore but now i need that person that is able to go and find all the different connections between humans in those discussions to help me find out okay i should be meeting with this group and this team and they have an opportunity and i'm going to be in san francisco today i'm going to be in seattle tomorrow those sorts of like um human connection aspects is still incredibly valuable and has always been a big part of that like chief of staff role um but now just like uh you know chiefs of staff are not opening up like letters to process they're doing emails you know what i mean it's the same thing and now they're they're not building out as many of these presentations because they have the ability to have AI take it off.
21:38Kyle Daigle:And share that with me and great. Let's keep moving because it's allowing us to go faster and make better decisions more quickly. Yeah, awesome. We can dive into more sort of productivity insights as you go. I did want to do a little bit of a brief history of Kyle, that could help? Yeah, sure. Because we started here and then you also involved the NPM acquisition. I did want to touch on that. and then more recently I just want to bring up to present day where we're having uptime issues which transparently we've already addressed publicly but we'll discuss in the pod. Sure. Did I miss anything like any other major highlights?
22:13Obviously it's a lot of years to cover.
22:15Kyle Daigle:Yeah, no, I mean like I think one highlight was right before the acquisition closed in 2018 I got to launch the first version of Actions at GitHub Universe. They're that young? Yeah, it was October of 2018, I think. Yeah, yeah. Jesus. Yeah, yeah. I was an engineering leader on that project and got to launch that. And then, yeah, we did acquisitions of NPM, like you said, Semel, Dependabot, Pullpanda, like a whole bunch of things. That was a big— Pullpanda. Right? Abhi is doing well. DX. Doing well on DX. And that was the big shift after the acquisition. I had to join the sort of business side.
23:00I need to hit you on some of these things because you were there. And how often do I get to talk to someone? But actions. Is that the number one source of security issues?
23:11Kyle Daigle:Oh, I mean, I think that the number one source of security issues is probably like the literal code and everyone's like underlying repositories. I would say back further than that is if you remember, like I had in this graph, I didn't say this before, this is ultimately webhooks. Yes. Like Circa, whatever it was. Yeah, hookshot's in there. And so like back then, it says GitHub services. Do you see it says hookshot, hookshot, FE for front end, and then it says GitHub services. GitHub services back in the old days, right? We had a repository that was Ruby code, and you could write any Ruby code in there, and then we would execute that on your behalf as a service.
23:51Kyle Daigle:And then that way, if you were trying to integrate with something, we would run it for you. And, of course, no containers. No, because it was 2014. And so there was some isolation, obviously, but it was mostly the separations on the server level. That's an example as long as the very old version of Pages, which ran on its own containerization infrastructure and not on actions. Which is an all-time great product. Pages powers the internet at this point to some degree. Those were places where clearly there were no issues to my knowledge. Those things where I'm looking at and going, okay, we can't be running arbitrary Ruby code on everyone's behalf.
24:34then containerizing all of that up into uh into actions now where like yeah like the containerization
24:41Kyle Daigle:like is really good the like pinning like most folks aren't pinning it the uh like to a particular shot etc you know like their workflows and so that's a big that's a big place uh of um of you know paying for folks if they're just doing similar to any you know dependency management just v1 or you know newest or latest i think um but uh that journey from that day to like okay we're just gonna run all this arbitrary code and like it'll basically be okay to now no i mean we have like really good containerization we have a new um uh underlying uh agent uh containerization uh service it's like through we're using it under the hood it's through azure they recently announced it the Azure-like dev compute, but it's like very fast, very fast compute to be able to spin up your own cloud agents or whatnot.
25:33Kyle Daigle:We're using it under the hood for some parts of the new Get-A-B-A. Microsoft DevBox? No, no, no. Dev Compute, yeah. Not finding it just yet. Oh, it's in there somewhere. All right, well, we'll cut that out. Sorry. But with dev compute, you can run really, really fast. to spin up really small VMs really quickly. So you're doing a tool call, just do it containerized. So we're using that. So definitely moving that direction to protect us from every piece of code that we're ultimately running. Yeah, I mean, look, that grows into the full SDLC. Code hosting was just the start, and then it's grown beyond that.
26:17Let's talk about NPM, maybe, because I think that's also a very major point in the industry. I do think it was looking for a home. It was kind of struggling as a business. I don't know how you would characterize that whole acquisition.
26:33Kyle Daigle:Yeah, I mean, when we were talking to the team, I think the big thing for the both of us was to find a way to keep NPM, which was basically powering the internet then and way more so now to some degree, you know uh uh running you know like keep it going keep continuing with the scale was having um scaling problems if i recall back at that time they were doing some rewrites uh i mean that's cute compared to now yeah well that's the thing is like you know when i'm talking to folks now like there's you know there's so many more underlying uses of npm than there were you know back when we uh uh we had them join uh joined in with github but that was ultimately the goal it was really like okay we used to have pages we have uh uh like the world's code let's make sure that we can keep npm running well uh uh you know for the world and we put a bunch of time and investment into fixing some of the underlying back-end um uh changes some of which we talked about like some of the manifest work etc and then now like really trying to bring the um you know the security posture of MPM up to speed.
27:45Kyle Daigle:But like, it is a unique challenge in that every move that we make to make it more secure will break a lot of people. And security is paramount. And also, like, we take it very seriously. We're like, you know, anytime that we have a problem with GitHub or we make a change that makes us more secure, there's like a snow day for developers or a really bad fire that they have to go put out. And so we have changed the 2FA policies. We've changed the way the tokens work. When we find tokens that have been exposed or potentially exposed, we invalidate them. I love that feature of GitHub. That creates issues, but that's the thing is we're trying to push the community forward without necessarily doing something that is going to break the contract that's been for 15 years, or some amount of years, on NPM.
28:43Yeah. So now we're talking about open source and publishing. And I think there's something here with what people are calling slop forks, which I think Malta from Vercel is doing. And part of me thinks, well, the way to get past any vulnerabilities is let's just get rid of the concept of NPM. And we only publish source code. And anytime you want to import it you you have your coding agent look at it and then adapt whatever subset you're going to use into your like vendor it but like the ai vendor it and is that realistic i don't know will that solve all the security issues i don't know i mean i don't think it will solve like i so
29:26Kyle Daigle:mitchell was just talking and mitchell hashimoto was just talking about this today and i think that like in some ways it's all you know all things uh old or new again you know like yeah absolutely vendoring everything like you know i do i do remember 2013 2014 we must return that's what i mean it's like we were vendoring everything we were having actual discussions around like or at least i remember we were like should we take this full thing like why is this so big we only need this one file and so i do think there's something true there where having like either taking only what you need or the dependencies just getting incredibly small over time i think will help to some degree but it's not going to solve the fundamental problem i don't think because the vulnerabilities like in an agent looking at them there's time and time again there's a million different ways in which we can convince an agent that this thing is like secure or not and pull it in or we can do you know uh static code analysis or you know runtime testing to say whether the code works or not that is i think the step that needs to continue to be like invested in the question is just on like how much scope should it be this enormous project that i'm pulling down or should it be this piece either way uh you know most companies are running some amount of you know security checking on the on the um uh the packages that they're bringing in or vendoring that i think won't change that's like what you know advanced security does to some degree socket It does some degree, you know, like everyone is doing a piece of that.
Read the full transcript
31:00Kyle Daigle:How we each do that, like especially when we're talking to enterprise customers, it's just like very, very different. Like there's no one wants one single way to do it. And I think that's always been GitHub's unique position in the world. Like I talk a lot to maintainers. I talk a lot to folks about this. It's we rarely start like a process and a practice and like push it onto the community. We usually wait for the sort of like RFC process socially or literally everyone agreeing and then we'll cement something in because otherwise we're GitHub. We don't want to shape the whole thing. We want it to be figured out.
31:40Kyle Daigle:But like how do you balance that sort of role in the industry to keep everything as secure as possible and make sure that you're not going to be compromised as a human because that's usually how it all happens. and not create a process or lock us into a flow that you're not going to like or Mitchell's not going to like or other open source projects aren't going to like. That's always been a tricky balance for us, and I think that's something that we haven't talked about enough. We're not going to be able to fix everything for everyone in a way that everyone is going to like. So help us. Tell us what is working.
32:18Kyle Daigle:When Mitchell was talking about the upvote. I was going to bring out his thing. I forget what it was. Yeah, yeah, yeah. I mean, like, when he's talking to us, I was chatting with him and talking to him about this. And I put it on Twitter and we talked to us over DM. I was like, we're going to keep working. But I think the important thing is I do actually want to hear what isn't working for you. And it's be as specific and clear for your project as is possible. And to every piece of credit over the many years that we've, you know, known each other through the industry, he's always done that. And I appreciate that because there are places that we need to fix up.
32:52Kyle Daigle:and we hear from him and we'll fix up just like we do all other kinds of maintainers. But that process between making those types of improvements and being more secure and creating, I forget what he calls it, it's not the proof process, not the claims process. You know what I'm talking about? He has that like, his projects have a way for you to kind of like... Vouch. Vouch, thank you. Yeah, he has like the vouch system for saying, hey, you should accept my PRs. Yeah, I just built this into GitHub, I don't know. Well, see, but that's the thing is that you say that and he and his community really likes us.
33:27Kyle Daigle:And then I'll go talk to other maintainers and other maintainers globally. And they're like, no, this doesn't work for me. And that is the tension. But also the kind of beauty of GitHub, depending on which way you look at it, is we want to help maintainers. So we create all these tools to let you have more control over how much you take in from AI and PRs. But you can also use this. You know what I mean? You can go use this project. And if it takes off and becomes the kind of mostly standard, then yeah, we probably wouldn't enforce it, but we would add it in because that's the flow that we tend to do.
34:02I hear a lot of people don't know the history of the pull request. Sure. And that's something that GitHub standardized, basically.
34:08Kyle Daigle:Yeah, yeah. It was a very messy process beforehand. And now we have the benefit of it being the process. And now we have to go and figure out the next best process or what adaptations change or what does a pull request look like when 80 % of your PRs are just coming from your agents and not from other devs. Do you like the prompt request idea from Peter? I mean, like, I think that for each, like, each idea, I think, has its merits. Like, I'm not avoiding saying anything good or bad, but I feel like I've seen a version of, you know, we have that, we have, you know, entire, you know, Thomas's, you know, startup, take all the assets of what you've built and put that in.
34:57Kyle Daigle:I think that's got great ideas. like there's all these various permutations of the pr flow but i think the reason why there's not a single answer is ultimately we're trying to codify trust we're trying to say like okay sean reviews this i'm going to trust it because you're sean or you're the senior dev or you're the whatever and right now when we are working in a flow where an agent writes code and another agent reviews code and then kyle goes and looks at it the trust is kind of diffuse uh in most of the tools that we're talking about are talking more about verification flows. We have more assets to look at.
35:31Kyle Daigle:So I can probably say whether this is a good PR or not, but that still doesn't solve, I think the human problem of I'm looking at a PR and I want to know if I can trust it. And we're still, we still tend to use human signals for that, you know, Mitchell approving it or Kyle approving it or whatever. And so I think that's, I think that's why most of these options haven't really solved it is because it's a social problem. Ultimately, it's a human problem to review it and agree. Or you fully trust the tool and you're imbuing that tool with full trust, which I think in some cases that absolutely exists.
36:08So like, you know, in the same way that there will be a tipping point in society when we don't allow humans to drive anymore because machines are measurably better than humans. I'm looking for that tipping point, right? Yeah. Like Mythos is ridiculously expensive. Someday we'll have Mythos on a desktop. I don't know.
36:25Kyle Daigle:uh what does that change the equation uh i think it's more like uh uh i took a waymo here uh and i was on my phone i'm not looking around uh at all uh like there are other uh self-driving uh vehicles that i would not trust while like staring at the road and i think that that trust is something that is a zoogs thing like what i think that is both i think that is both uh you There's Zoox and there's RoboTaxi. That's it. Well, I mean, depending on what level of self-driving. But my point is sort of that I think part of that is I strongly believe that that's a mixture of verifiable proof. Like how many accidents, how much data, and so on.
37:11Kyle Daigle:And the human aspect of how I feel when I'm in this car, what it tells me, etc. And so that's why I think some of our AI tools tend to imbue me with more of that feeling of trust, even if the data says this is 100 % accurate. I feel like it takes more time for us to go, should I trust this or not? And that's in the soft sense of startups with high agency, weekend projects, and open source. And then there's enterprises and regulated industries and everything else. And that is an even harder problem to go solve because even when it is fully verified, not only do you have to have trust from the humans on the team, you probably have to have trust from multinational, multigovernments around the world, you know, regulating agencies.
37:58Kyle Daigle:And so that's where I feel like until we tip over to your point, like on the sort of like human EQ side of it, like I feel OK, like this feels OK, like I've been proven enough. Then the ball will start to roll a lot faster where we'll end up getting to the OK, we can trust this and feel good about it in the most difficult cases. You know, if human trust is the thing that matters, I feel like GitHub as the developer social network could maybe do more there. like vouches one system but like we have star counts and then we have contributor rights and that's it and like i feel like there should be more in that space i don't know if there's any other design decisions i mean i think that like one of the places that we don't really expose right now in this sort of way is um like some degree of like hard trust and support which would like for me is like sponsors is a good example of that it like costs you something you know to prove that i i believe in your project and i like trust you to some degree i want to support you at the very least okay self payments for open source why not i mean like i think that i think that like as we keep moving forward right there's more and more projects where i i'm like adding more and more dollars into sponsors personally because i want to like support them but i also like know of you know i probably never met them in person but like i know of enough of their work that i want to support them i think the thing that i don't love about stars or commit counts or anything else is like ultimately even with all of the various like abuse and de-spamming and deduplication work that we do or anti-abuse you know work that we do these are all like not active social signals they're passive ones that are ultimately gamifiable and you may trust me but another open source maintainer may not and on what heuristic should you be uh trusting me that i think is kind of where some of our thinking is right now what signal from me is most important to you you if you can define that potentially like honestly like in an agentic workflow like that's what we see some of these open source projects do where you have you know github actions and you have like an agentic workflow that's calling ai and you're setting these rules like if kyle has submitted and gotten accepted prs across any given project and has a social handle tied to his account in github and that social account's older than certain amount like really complex measures that matter to you because most open source projects have that heuristic built into their heads if not written down in the contributing guidelines you could take that and then go apply that and then just say oh we're not going to accept this pr building something that is i think malleable to everyone's needs uh uh is a little bit better rather than going hmm this account's too young because what happens the attackers just go and go and create a multitude of accounts and they wait until it ages up needs to have certain amount of stars that's how star inflation happens you have a certain amount of repos with prs they all just create repos and submit prs to each other and then they you know come in and do something nefarious and so uh it's hard like it's hard to find the measure so i think we're we're looking more at how can we provide you tools so you can kind of choose what's best for you and of course we'll give you some standards but the trust vector uh gets down to like i don't know some version of like human digital id like everyone's been talking about like how do i prove that it's me on the internet yeah give me your eyeballs exactly uh i gotta keep moving on on topics but obviously i can go all day on this because i mean i've been involved in github and open source my entire you know professional career um stars yeah very superficial everyone knows it but i think you know time to 100 000 stars is the fastest i've ever seen like now people just reach that in i don't know months yeah uh And then at the same time, like, I don't trust it.
41:41Right. Like how many of these are real or bought or like whatever. I don't know how to ask this, but like, what can we do about it? Like, you know, is Star is broken? Is Star is fine?
41:51Kyle Daigle:I think that there's kind of two, there's like two pieces. Obviously, like we're constantly like trying to find ways in which like your users are producing spam, which would I would include like be like only doing Star gamification. When we find them, we pluck them out, you know, and we. it's like a whack-a-mole it's 100 like a whack-a-mole now like powered by ai to be helpful but i think more so what i'm seeing is uh a lot of the like fastest time to x you know tends to be because we're now inviting so many more people into like software development on github that like the zeitgeist is just swarming yeah you know it's not just development it's not you and i like you know like however you want to say like what a developer is you know it's not just folks have been coding for a very long time it's folks that maybe started coding or only joined in since the ai era and that was the latest octoverse number i know 80 million was my last member that like a number of developers on github oh we're over 200 million yeah okay well it's easy yeah yeah yeah like over 200 million developers now but but it's not developers right like it's it's people with a github account so like so this is this is the biggest debate that like i would say like everyone loves to have at github at this point from my perspective right i think that there's there's clearly a difference between like professional enterprise developer you know and then developers but i think that i think that the idea that you know uh we should be like i don't know splitting hairs or segmenting developers in the early era of software development is like not worth our not worth the time yeah so like get into gatekeeping 100 like 100 because i mean i wasn't a developer when i started writing code you know i was going to oh no i i made i like cloned the thing like seven years before i learned to code and then i and then i wrote about my learning code journey and people just called me a fraud yeah because i had a github account yeah and i'm like well no i just use github but i don't know i didn't know what i mean i like i remember that like i remember those sets of posts and like that's like that's bullshit so i fight very clearly on the line of like if you create code if you have an idea and you create it into some way of like, I'm going to run it and use the app right now.
44:04Kyle Daigle:You may still use AI in that moment, but that's okay. At some point you're going to do the next thing. You're going to create a big, you're going to have to learn about this database. You're going to fix a bug, whatever. Like we're all on some same journey. And those people are also hearing about the great new agent skill package or a new CLI tool or a new whatever. And those projects are going up because you want to be a part of this moment, just like I wanted to be a part of the Ruby community when Ruby was popping off when I started becoming a developer. And now I can just click the star button.
44:35Kyle Daigle:And so I think that, yes, there's clearly some amount of spamming and gamification that we're working against, but I really think we're just seeing this whole new cohort of folks that are moving from technology to technology because they're not working on a 20-year-old software application. They're working on a side app that they built on the weekend for their friends or for their new idea or whatever yeah uh and that's how you see these enormous charts going up and to the right with uh with stars i think something that's remarkable is the persistence or that like github extends to those folks usually when i see platforms go into a new audience they usually have to like have like a second platform with a different name that like wraps the main platform uh but somehow github has been able to sort of persist and extend and it's friendly and whatever you know so it's nice yeah i like uh that's partially why i think as we've tried to move into like um i don't know more like low codey things you know like we so we you know started working on spark as like a way to like build an app and run it yes i think that the reality is that we anytime we try to like kind of put even a veneer on top of it without like uh like when we put a veneer on top of something we still always show you the code that's kind of like a tenant we're never gonna like hide the code from you ever um because what like yeah it's the whole point you know uh however i think that what we learned with things like spark is that really the value of spark for most devs is like easy runtime and you may have a runtime or a host that you're going to use for that or you just build something and run it but like the package of making that like even more simple isn't really needed like for folks that are trying to build software and not just trying to build like an app, which is like slightly, slightly different, a slightly different goal.
46:23Kyle Daigle:So I want to get you in. I want to get you comfortable. I think the best thing for me as like someone that did not like, you know, traditionally come into software dev way, way, way back. I want anyone to be able to like breach that chasm and not be in the, you know, I don't know. I feel like we're, we're still in an era of like STEM, STEM, STEM. I've got a 12 year old and an eight year old. And it's like, we got to get them in the STEM, you know, over and over uh and i uh i like i do i do the things that good parents do i was like oh we want to do coding yes i want to do coding do coding classes but now they're just not afraid of doing software and that's i think the thing that's honestly kept me at getting for so long anyone should be able to go and build a thing just like i can go change a light switch in my house like i'm not going to go into the breaker box because i'll probably kill myself you know but like i can go change that light switch everyone should be able to go and say this freaking app doesn't do what i want like i want it to work like this yeah and that i think is what's kind of kept us all connected with github through the years and some you know and like during the easiest of times during the hard times because of that opportunity of like we're the home for all developers and we want everyone to be able to have that feeling that we've had of i had an idea i created it and holy shit like you know here it is here it is uh all right i'm gonna try to do more spicy questions great is it an easy time now or a hard time oh i get them yes i mean it's a hard time like i mean like it's a hard time and also like i was just with my team and i said this is also like the best and most exciting time that i think i can remember like at github because best of times worst of times yeah i mean because we've you know like we're talking about octaverse reports and like usually we do an octoberse report once a year and we look at the numbers and we say oh my goodness like i was at universe in october saying this was the fastest year of growth that we've ever had right and now we're doing more in a month than we did in a year last year uh you're talking about prs commits prs kind of like you name it by roughly every measure that we're looking at there's some amount of sort of growth that is much much bigger and that is breaking our system in new ways not old ways like you know web hooks were always notoriously uh unreliable over the years you know whose fault is that like not anymore mine but for a period of time i'm sure you could pull up a tweet that was like it was me i'm sorry uh but like now like that got rewritten at a scale level that is still working and is not having problems today now what we're finding isn't just the like isn't the the simple stuff that folks are on the you know sometimes on twitter or on the internet are like, hey, like, why is this like this?
49:00Kyle Daigle:Sure, there's absolutely, you know, silly problems that shouldn't exist. But now we're talking about like unique novel permission problems that happen only at a scale across all different objects or whatever, that now we have to go rewrite this underlying system. And so it's, there are problems that, yeah, caught us off guard, which I think I said, I mean, like the growth is astronomical. But also, we're making such material progress in that, that I'm excited once we're, you know, once we've kind of like re-imagined the underlying foundation layer or pieces of it at least, what's going to be possible when it's not just all of us and all the new people that are being developers and all of their agents and all the tools like working together.
49:47Kyle Daigle:Because that'll still happen in that, you know, in that GitHub, you know, tool, that GitHub community. but it's a hard it's a hard day anytime we can't give you what you're looking for we have the same problem internally i mean we operate through github.com of course we have backups when things go down and whatnot for our own operations you know but we feel it too you know if it's not working it's not working for us and that's kind of like the promise of dogfooding for github it's always been true we're using the same tool you're using we're not using a super secret version And so we also need it to be great for us, for our customers, of course, for open source.
50:26Kyle Daigle:And now, you know, an exponential growth of agents doing it, too. I wanted to load for audio listeners who maybe haven't seen your tweets, whatever. So one billion commits in 2025. Now it's 275 million per week on pace for 14 billion this year. It goes and remains linear. Is that still the pace? i mean it's uh it's speeding it's still speeding up yeah exactly this was in april all right so basically you have 14x growth right you're on year uh and i think that's a scaling issue i think uh i'm gonna like try to really steel man this thing right people have experienced 14x growth they haven't had your downtime and that's like can we dig into that like why like what's the what broke um what are we doing to fix it like you know just anything for the community to reassure them.
51:18Kyle Daigle:Yeah, I mean, so like I was saying, there's a couple different places that we've seen the growth issues. Some of the growth issues, which is why I was talking about pushing hard on more CPUs is in actions in particular. More tools, more agents, more PRs mean more builds, more builds mean more CPUs. And so we are expanding through not just our data center, but obviously we were talking about moving to Azure and adding an additional cloud compute because we simply need more CPUs. uh not uh not as much gpus like we definitely need gpus too but now cpus are becoming a factor you know uh underneath the hood when it comes to uh like some of the underlying services we've been breaking up over the years our database infrastructure so that way we have more cognitive separation between the various services the place that we continue to have pain is in permissioning.
52:14Kyle Daigle:So right now, many of our permissioning layers sit into a database that we internally call MySQL 1, and old Hubbers will know what I'm talking about. And so we've been pulling things out of MySQL 1 for many, many years. And we use Vitesse and we use other technologies to shard. Famously, PlanetScale was born from this. 100%. Sam, old Hubber and friend, I mean, and so finding these opportunities to break this out and then do that globally. The other thing that I think is interesting in like both a unique opportunity and tricky is we also run everything I just talked about in a like black box container with GitHub Enterprise Server for people that work on on-prem.
52:53Kyle Daigle:So we take everything I just said and we also do it on-prem and we also do all of that and we do it in a data resident setup for customers that need to have their data in a single location. Each of these has the unique characteristic around how we're sort of storing that data in MySQL or in a permissioning setup that's where some of these outages have occurred where you're seeing it more like across the board rather than just like the one piece isn't quite working exactly exactly and so part of it is that i think there's been some other places where agents are much more or more projects appear to be moving towards mono repo versus we were going the other direction for many many years in the industry repos were smaller but there were more of them and now we're seeing the opposite repos are bigger and there's uh not fewer of them per se because there's new growth but like we're just seeing many more big repos big repos uh big mono repos have always had a like a unique performance problem uh like because each one uh is slightly different if particularly if the underlying blobs are incredibly big inside the repos and so we've been a ton of work that you probably most people haven't probably experienced uh unless you're in this case of the monorepo uh but that git uh uh infrastructure layer improvement does help the overall uh system because um many of the improvements that make monorepos work better make all repo infrastructure work better and so like i can kind of keep going like down the line where it's another thing where you know we're moving out of uh uh we're changing how we do um uh like i'll just say like job queuing for lack of a better explanation, like changing the underlying technologies there.
54:32I spent two years being a job queuing guy.
54:34Kyle Daigle:And so it's kind of a little bit of piece by piece. And it's mostly because as it was built, we built everything in a way that assumed, I guess, in some ways that the size of the pipe of work was going to remain the same. There's just going to be more people coming through each of those pipes. But instead now in places where a Git push was generally a certain size, for example, is now like no longer true. Oh, yeah. You know, or like on the average. Same thing with PRs, you know, like PRs, like same thing. And like we've talked about optimizing that and making changes where like and there were like technology choices that did not work there, you know, and it got slow and it didn't.
55:22Kyle Daigle:It was not fast. It did not do what the users wanted. And so we've been like reeling that all out, you know, going, okay, that's just not right. Let's stop putting, you know, good money after bad and do it the right way or the right way now. So it's a lot of things, not quite like when I've experienced scale at GitHub historically, it's almost always two options that we've used. We go vertical scaling, particularly with databases, right? And we go horizontal scaling. Oh, we just have more people using this service. Great. We're going to add more servers and we rack them in our data center. We use it in a cloud.
55:53Kyle Daigle:And now, like, we're sort of in a, like, diagonal where, like, vertical doesn't really work anymore. Horizontal isn't working either because, like, we all have some CPU or GPU constraints in the world now. And now we have to go and, like, crack open services that have been running for 10 or 15 years and go, okay, the rules of this service have, like, legitimately changed. And now we have to rewrite them. None of this is an excuse. This is, like, we have to do the work. we have to make it better i mean actually as an infra guy i'm like this is like one of the most fascinating scaling challenges i've ever seen that's like that's that's the thing that that's the thing that it's hard for like when we weren't talking about it publicly and i was like i came out and i was like hey i just want to explain what's going on part of it comes from a very old github like ethos which is it's our it's our uptime it's down yeah like i know you're a developer so you're you're inclined to uh you know want to understand more what's going on but at the same time like us going hey this service didn't perform the way we expected and now we have to go change it we were we're not trying to hide anything from you and that it's that well that's our problem because you expect us to be up and i think that's like really baked into the core origins of github and so now what we're trying to do as a team is do all that work and just tell talk about it more just share you more technical details write these blogs write the post get the engineers who built it after they finished the work, just tell you, okay, this is what we did.
57:20Kyle Daigle:I think that's the contract that we want to bring back to the community and say, hey, we're still very serious about what we're doing. We haven't been telling you about each piece. So let's do that. And we're going to keep building this and scaling it in a way to support the, if it's not 14, then it's 30 or it's 50 or whatever the next exponential growth is going to be. Yeah. First of all, fantastic answer um i mean i think and i apologize in advance if like any of that is like slightly incorrect just simply because i'm not uh you know uh the i'm like still in the weeds with this but it's not my uh day-to-day but like that's the thing is we're all looking at it to that level yeah you know uh you know and like obviously if people want to help they can join yeah absolutely um so like i think the that is uh good i think people also just want to know like when are when are you through the thick of it right like is there have we identified all the issues is this It's just never-ending.
58:13Like, is Git broken? Like, do we have to change the Git protocol? Like, how much is breaking, right? Like, it's been a while. Yeah, yeah. And so I think people do want to know what's the path back to the reliability that everyone expects out of GitHub.
58:29Kyle Daigle:Yeah, so I mean, like, our availability in recent few weeks has been much better than the three weeks before that or the three weeks before that and so forth. So a lot of these improvements are still very much paying off for us. I think that we're still working on that database piece that I mentioned. And that just is a little bit physics, like a little bit of time to get it fixed up. Because we have to... The answer I had in my head was call YouTube. So YouTube ultimately... Because they also use Vitesse. They also use Vitesse. but the uh uh like whoever was the guy the scaling guy at youtube you know yeah yeah like that's that i believe went to planet scale and it was a part of planet scale too but like oh you mean sugo uh i think so yeah yeah yeah and so uh and so he's at super base now uh the whole postgres drama yeah yeah yeah totally so i mean like some of it's that i think the other piece of it is um uh our our move to get additional compute will alleviate a fair amount of this particularly on the action side because a lot of the underlying um outages is actually related to uh tell you actions is the root of all evil i mean it's all it's it it it has its pros and that it's the core it's the core compute layer for either ci side projects no i don't know i mean like actions i pay a lot for compute right yeah i mean like actions is like definitely a a a piece of the overall business but i would say that like we ultimately also give away so many like minutes you know as part of our entitlements as that but that's what i was saying everyone's using it we talk about it as cicd but the reality is people use it for cicd and various processing and automation exactly and so i mean like part of it is also that like compute piece that uh that is also alleviating some of our availability this is my abuse of actions i've been oh yeah i've been scraping for every day uh and just like i just thank you for your service uh but this is also how i track uh actions on time sure you know sure yes anyway uh so i mean like some of it's going to be that i would say that like each month i expect you know in the next three months you're going to see like fewer and fewer moments where we have an availability problem where things are going to go down and that's not just it stopped it's that we're still experiencing faster growth than ever before.
1:00:57Kyle Daigle:It's just that those underlying improvements that we've been hard at work on are finally paying off. It's just that their improvements take... It's less about these incremental improvements where you make a small change and you get this big output. It's now material change that takes a bit of time, and then you see a step change in our availability. There's a thing we used to do at Amazon. I don't know if it's a thing, but automated software verification or simulation of load testing and all that. I'm just like, at this point, you have a whole map of GitHub and like, well, you can assume whatever growth rates on whatever dimensions that you care about and just run it through the system, right?
1:01:31Like, I feel like there's a way to, I don't know, have a systems model of GitHub and like see what breaks. But obviously I'm not that close to problems.
1:01:39Kyle Daigle:Yeah, but I mean, so yes, totally. And I would say like, that's been the journey and work that's been happening since like, I would say November to now. Because October, right, was the time where we even said like, oh, look at the growth. and then you start to see the chart really, really pick up. It's like, oh, we tested it at N amount of scale and now it's at N cubed maybe in some vectors. And so now we have to go and build it that way and make sure that it can handle all of that scale. Let's talk about Copilot. Yeah. So how many original creators of Copilot are there? Oh, jeez. I count like 12 on LinkedIn.
1:02:20Kyle Daigle:Yeah, I mean, like, I forget, like, all joking aside, I forget the number of people that were on, like, the original, like, GitHub Copilot team. But there was a bigger group. I heard it's Alex. Alex worked on it, Luga worked on it. Like, there's, like, a bunch of people. And then their entire management line. Okay. So, like, you know, enormously successful in its day. I think the last number, I think Mario came to my conference and talked about the$100 million mark. I think most recently three. hundred uh i might be out of date as well there i don't think we shared the dollar amounts yeah all right cool um just like what's the state of copilot uh it's it's obviously as a concept brought into more of microsoft yeah uh but just add github yeah yeah i mean so i think you know one of like one of the challenges is that we had with copilot right is that we came out the gate with code completion and it was you know super great powerful etc etc and then what we initially worked on after that sort of like initial year year and a half was um going after fine-tuning because you know our customers the industry on the whole was really talking about okay well like how do we get more um uh you know more correctness or performance out of this and so we were working on a whole bunch of efforts to do fine-tuning on uh larger and larger co-completions or like next edit suggestions with fine-tuning etc and let me clarify uh is this fine tuning one model or per customer a fine-tuned model both but like but like fine-tuning one model for the overall like uh use and then fine-tuning per customer that wants this as like a service effectively and around that time is when uh you know the next generation of models came and that's around the same time that you know all these other you know ai uh coding tools came to be because the models really, really sped up.
1:04:14Kyle Daigle:And so everyone kind of like will ask like, well, what happened to GitHub Copilot? Like there's all this time. And I would say that we were on an era of going, okay, we want to improve everyone's results. And so let's focus in on fine tuning because that'll give us these better results. And then the models got better. And so then ever since we've been really on this kind of journey to go, okay, of course we have like this great code completion and we've done a ton of investment in the better underlying models that we have, you know, post-terrain, better next set of suggestions with post-terrain language-specific models, all this stuff that kind of like sits in the ether of GitHub Copilot is code completion, but also now have like a single underlying SDK and harness for our coding agent, you know, Copilot ultimately, the new CLI, the new desktop app, cloud agents that use the same SDK.
1:05:07Kyle Daigle:And so there was this moment of, you know, both really, really trying to figure out what our customers want, models Sherlocking us a little bit, then going and saying, okay, what does everyone ultimately need? And what we think is that it's not solely about the code generation. It's really about having the ability to use these, you know, coding agent brained harnesses or runtimes across, not just the coding experience where I'm going to like send a bunch of tasks out or I'm going to use fleet to break up a single task or autopilots and learn to goal, you know, all this stuff. But also, how do I do that for all of my security remediation?
1:05:48Kyle Daigle:How do I do that for every GitHub issue that comes in? Just stick a coding agent on it just to say if it's possible. How do we, you know, go through my repository and see all of my documentation and extract out like, okay, this doesn't actually match. Like that amount of sort of AI coding agent automation, I think, is a big part of what we see when we're looking at, okay, we're still kind of going through a similar but very different flow. It's just all happening at the same time. You know, like there's not really the same, like I'm going to create an issue to track my idea of building this. You're probably just going to go like do it.
1:06:22Kyle Daigle:You're going to say, hey, just build this, right? and there are still tons of open issues and projects etc that are using issues like peter and open claw you know to be able to sick all of his agent on that that kind of infrastructure layer and a really really great coding experience that allows you to handle the sort of multiplexing aspect is what we've built are still building you know with github copilot and so for folks that haven't really used GitHub Copilot since the thing that got them excited about this, which I get. I really encourage you to look at, especially the GitHub Copilot app.
1:07:06Kyle Daigle:That's my new daily driver. Obviously, if you prefer the CLI, also the CLI, be able to use all the models, the bring your own key side of it. We're still improving our own models and using those too. It's just a very, very different experience. But I think that broader sense is of like software development, how coding agents can help throughout, not just writing the code or even verifying it or deploying it, you know, is where we have this unique angle. The other side is the context piece. Oh, God. I mean, like we're still it's like one of those things where I think the, you know, the final thing that will let me ultimately feel complete at GitHub is like when we have this ability for GitHub to act like Kyle wants it to act or Sean or whatever.
1:07:59Kyle Daigle:And we all codify that in rules and memory and everything else. That's an open research problem, right? A hundred percent. A hundred percent. A hundred percent. But if we can even just do it where my team, without me having to codify everything, and as our methods shift on purpose, to be able to have that full experience and all the understanding of what's happening in my dependencies or open source, that feels like a big place for us to be able to continue to provide something really unique and valuable with GitHub Copilot. Yeah. Is there a form factor that we haven't explored? You know, I think like, you know, we did code completion.
1:08:36Yeah. Then we did kind of broadly call it agentic IDE, which cursor famously popularized. And then now it's not all about the sort of agent orchestration, background agent, whatever, whatever. And then there's the security review. I feel like everyone is like just stone agents and everything. The entire SDLC has covered with agents. Are we like at the end of history here, basically? You know, like, you know, is it just refinements from here on out?
1:09:04Kyle Daigle:I mean, I think that we're all still in such this like hyper myopic era of AI where the reality is that for various like boring security and governance reasons, at least for most people's work. Why is my coding agent, even if it's all background agents, background running, not like losing all the context that's available to it across everything that I'm doing outside of coding? Yeah. You know, like I think the most interesting thing to me in AI is actual ambient AI, not insert, you know, assistant name thing or like I've tried just about every pin and tool and whatever. And they don't work the way that I'm looking for them to work because they're just trying to capture and then they are trying to codify and then recall.
1:09:54Kyle Daigle:And I think the thing that I'm looking for is back to the very beginning. I'm looking to be building out the next version of webhooks or like implementing a new feature. And for it to know every spec doc, every email, the conversations that I've had online, everything about how this could be implemented and be able to like use that as part of its decision making. And none of these tools are ultimately doing this. So I think that it's as if like software development where it was a single lane task. It was like it only needs a developer. Once I write the perfect code, we'll be done here. But that's just never been true.
1:10:30Kyle Daigle:It's all the context of the other team members, what the business is doing, what's popular right now. And I think that's this huge opportunity for us to go much broader than really, really excellent coding agents. And that is honestly why I think OpenClaw has been so interesting is that, sure, it's connecting to all the data sources that Kyle the Human cares about. and now my question is like okay how can i take all that and use that every day as a software dev connected together not just have a new way to kick off a coding agent and that's where we're at we're saying okay i'm going to go use this cli under the hood or this sdk but that's not what i'm talking about i'm talking about i'm having a conversation with you it downloads the podcast and it realizes oh kyle sounds like kyle needs this app or this thing or this that level of exactly that level of that level of connectivity i think is where we still have a ton of ways to go in software because then when we have that red thread we want to pull that idea it can not only use the perfect way to write that code but instead all of the sort of taste and judgment calls and uh you know expertise that i've earned or that we've earned as a group uh and use it as part of the actual implementation Yeah.
1:11:44You know, the extreme of it is AI runs your life, right? And I think there's a scary inversion of control in the way that I'm literally doing it in the way that developers mean it in terms of frameworks, like, you know, the Hollywood principle, like, don't call me, I'll call you. Like, at some point, there is an inversion of control where, like, you should stop telling the AI what to do. AI tells you what to do. And, like, that's a little bit scary, but also, like, maybe better.
1:12:09Kyle Daigle:i mean like you know uh nat uh i think nat freeman shared this in a uh uh like a stripe event you know like talking about his open claw was like he connected open cloud to his cameras and it was like watching redirected his uber uh there's a degree of this where i was like i actually would love open claw to tell me to like drink water i don't know that i want it to be uh changing where my car goes but i do think that's kind of what i'm talking about which is it needs to have so much more information at its disposal for it to be helpful to me and i still don't think we're like anywhere near talking about AGI.
1:12:41Kyle Daigle:I'm just talking about every time I have to tell you something I care about that I've ever kind of said, or I've said a dozen times, it should be able to know that codify that or gain access to it. Like the dreaming ideas like are an attempt to kind of do some version of this. But I think there's a much more proactive angle that will help software devs if we can, you know, test that out a bit more. Yeah. Yeah. Well, the other thing about OpenClaw that reminded me is Microsoft has a CVP dedicated to OpenClaw. Why? Because you don't think they should? I don't know. I mean, I think CVP is a high title.
1:13:21Yeah. Why is this so important? Like, you know, Microsoft doesn't even own OpenClaw. Yeah.
1:13:28Kyle Daigle:Yeah, I mean, like, so, you know, we're talking a lot more about this at Microsoft Build this year, too. I think like the main thing is that what OpenClaw has done is it has made this connection for people to have access to the resources that you have access to and be able to do things for you in a way that previously people were trying to codify into their own agents. And so when you think about it, like in the work context, wouldn't it be great to have a claw like object that I could actually run on my work device that or had access to my work assets made worked well on Windows, like what that would look like.
1:14:11Kyle Daigle:And so I think that OpenClaw has become the personification of like a valuable agent that understands me because it has access to all of my information and it can use a computer. And so thus it can, you know, do a lot more than just a task oriented process or like a, you know, a chat tool, et cetera. And that's like a bunch of, you know, the goal of Build, right? Like we're at build this year trying to take a very different approach of, you know, it's unapologetically, you know, aimed at developers. We're trying to show the like bigger investment to not just say, hey, like you said, why do you have a CVP of OpenClaw?
1:14:50Kyle Daigle:Well, because like one of the problems that we have, right, is that our agents, if you install them not on a Mac mini or not on a hosted device, you install them on a personal device or a work device, we need better sandboxing at the OS level. I need to be able to use that claw and not, like, get fired. And so Microsoft is like, okay, great. Let's, like, do that too. And then it's, okay, well, where should I be able to talk to this agent? Should each of us just have a claw available to us at work? Probably. And so there you go. And, you know, continuing to contribute a ton to the open source project too.
1:15:24Kyle Daigle:Like, Microsoft, I think, as I've gotten more and more information, like, there's so much investment into the open source projects themselves. that for whatever reason just i think there's like this uh they don't want to come off like those teams don't want to come off as like taking any credit or getting any recognition but so many of these uh core contributors of teams are full-time just pushing into open source projects uh in like i think that's uh that kind of shows the difference between like well why are we looking so hard at something like claw why are we looking at sandboxing on windows why are we looking at cloud versions of sandboxing why are we looking because ultimately like we need more platform components we don't need everyone to be building the same exact like top line product uh and so if we're building for builders that requires us to give you all these components and tell you what they are and how they work and why you should be interested versus only delivering that single vertical like over and over and over again yeah um i i think like my maybe one way of framing it is that microsoft is the original operating systems company and here's the new operating system for ai yeah yeah i mean like you know i i think that uh we are also in an era where we are like we need to help build that bridge you know like all joking aside like operating systems need to look different than they looked five years ago because it's not just you using them anymore yeah you know uh and that's changed the whole idea it's not okay my claw is going to create a user account it doesn't work like that you know and so just like uh just like all of us we all have to look much much more deeply in the stack all the way down to like the silicon layer in azure to be like okay well what do we need now because the workloads are different it's not just okay we need more inference it's okay well what type of inference do we need?
1:17:20Kyle Daigle:What type of compute do we need to run these agents or run these agentic flows? It's a really interesting kind of like multi-layer problem versus kind of, I would say, you know, software in the last, you know, five or six years, we're all going to our events and we're kind of saying a version of the same thing. SaaS product has new SaaS thing. It's the best SaaS thing ever. It was boring for a while. You know, and so now it's like, oh my goodness, like we're at physics yeah you know we're at physics problems uh and that's exciting yeah i mean we're now trying to make like semi uh room temperature superconductors uh still yep yep uh that's that's that's never going away uh no i think like that that's a really good overview of like everything um i i think have i have we left anything unsaid that you wanted to really get out there that we should cover yeah i mean you know uh i i'm really excited by like for folks you know checking out the announcements that we have at Build.
1:18:17Kyle Daigle:You can go look at them online and take a look. I'm hoping that it's driving a degree of curiosity and interest because there's such this big shift that we're making at Microsoft for developers where if you're a daily driver of a Mac device or a Linux device and you're like, okay, I don't use Windows. I mean, like there's improvements that are being made that I think are going to surprise folks to just be like, oh, that's like they really want to do that. Like not I'm talking for developers. I'm not talking for I play video games on the weekends on my Windows computer. I'm talking like my daily driver, like all the way from that to, OK, well, what is it like to build an agent or build an app and deploy and run it at work in particular?
1:19:05Kyle Daigle:I think that is a big piece of it where I talk all the time with the team, how I build on the weekend should be how I build at work. But if you're working in a Fortune 100 or Fortune 500, you're probably not vibe coding an app and then shipping it to some service. You got to go through security and compliance. How can we move just as fast at work? And that's, I think, something that we have a bunch of different offerings for to give you that same sort of agility and power but in the work context. And then I will tell you, I've mentioned it a couple times, and it's very freaking cool. If you are in the M365 land in any way, check out WorkIQ.
1:19:43Kyle Daigle:Check out FoundryIQ. These little oversimplifying context engines are wild good. And like we've given them to our developers at GitHub, we've given them to employees at GitHub as we've used these tools to be able to just ask questions around everything that you have in your work context. And with Foundry IQ, be able to just do the same exact thing across all your existing stores, like not move to new tools, just connect them in. It's surprisingly powerful. And your boss is still not going to get fired and IT is not going to turn it off because it's leaking all this private information. That is the trick that I think is sometimes getting lost when we're talking about all these great new platforms because I can use them.
1:20:27Kyle Daigle:I'm like, oh, this is super powerful, and I can't use it. And it's not because I'm at work at GitHub. I'm not allowed. It's because I'm not allowed because they can't do all the things that large, complicated companies need. And so whether it be, like I said, just the kind of interesting daily driver curiosity all the way through to, oh, my gosh, like I can go use this at work tomorrow potentially and have that context layer, have that intelligence. It's a huge shift. And so check it out. I'd love to hear – I'm not shy on social. I'd love to hear feedback, like what's working, what's not, but hopefully surprise folks a little bit.
1:21:07what i'm hearing i mean so first of all i think that's that's great pitch what i'm hearing actually is that you should put the work iq people next to the co-pilot people because like the the exact problem context problem that you named yeah they solve enough for you to do your job which is nuts
1:21:23Kyle Daigle:so like the the the thing that we are like that's literally what has been happening the last several months i already forecast you it's like like totally because like you're totally right the The code and the code asset problem is a little bit unique. But otherwise, yeah, we're all working with each other now. It's all just context. Exactly. Amazing. Great. I'm going to be there. I'm going to be doing a couple sessions there. I'm going to be interviewing Satya. I know. When I first started the pod, I had Jeff Dean on. It's like hall of favor. Sure, sure. I want to meet someday. Satya is on there.
1:21:55What should I ask Satya?
1:21:57Kyle Daigle:i mean i think i think that the best question to ask is what he thinks is true in like two or three years from now you know like it seems like such a throwaway question but ultimately uh the way that the way that he is looking at this ai problem in the inference problem token problem and what we're how we're actually going to be working uh i think you can see some of the recent shifts that have been happening inside of microsoft to kind of drive us to a place where it's not four or five six seven eight different things it's not a lack of context everywhere but like why is this uh you know sort of approach in two years going to uh pay off because that i think wow that's a book okay i'll ask it i'll say i'll say i prompted by you but absolutely uh it's a bold question because um you know i think there's a lot of uh doubts to be honest like of course externally and and so like yes i i want like a straight answer from from him on that i think would reassure a lot of people and honestly like give me a lot of food for writing so uh thank you so much for spending your time thank you for doing what you do i think like you you know as a ceo you don't need to be the external face but like because you are authoritative because you have so much background with github and it's so authentic like we on the outside feel it so thank you for that of course appreciate it thank you so much sean
1:23:22you
From the publisher
I’m excited to work with Microsoft once again as the presenting sponsors of the AI Engineer World’s Fair! We’ll streaming live from MS Build today for a special crossover pod with our friends at No Priors and the one and only Satya Nadella. However we did not hold back with this interview - we asked all the burning questions about uptime and Copilot that we know you have in your minds. Lets go!
For almost two decades, GitHub has been the home of software, where both open source and closed flow, through commits, pull requests, reviews, actions, etc.
This ecosystem flourished as open-source maintainers and contributors would continue shipping code for the benefit of the community. However as coding agents began to ship mass quantities of code - growing 1400% in 2026, it marked a new era that was both extremely exciting and challenging for GitHub.
While these agents help more people ship more projects, they also significantly increase the floor of how much code is shipped, how often it is shipped, how many people commit code, and basically orders of magnitude multiples in every dimension of GitHub infrastructure:
Now GitHub inevitably experiences more pressure on their infrastructure which was originally designed around human developers moving at human speed. This has resulted in a very publicly notable uptime story:
So it begs the question of whether current systems around code can absorb what AI produces. Can CI/CD keep up when every idea becomes a build? Can open source maintainers survive floods of AI-generated slop contributions? Can GitHub preserve the human social contract of software while becoming the operating layer for agents?
Which brings us to the perfect person to answer these questions: GitHub COO Kyle Daigle. In this episode, he joins swyx to unpack what happens when AI doesn’t just autocomplete code, but starts changing how companies operate, how open source works, how pull requests get reviewed, and how GitHub itself has to scale.
We go deep on GitHub’s internal AI workflows: micro-skills, WorkIQ, MCP, Slack, Teams, email, Copilot workflows, the new Copilot desktop app, CLI, cloud agents, and how Kyle uses agents to look backwards across company context before deciding what to do next. Kyle also reflects on GitHub’s history building webhooks, APIs, Actions, npm, Dependabot, and Semmle, why the AI era is breaking GitHub in new ways, how Actions became a general-purpose compute layer, and what Copilot becomes after code completion.
Full Video Pod
We discuss:
* Kyle’s expanded role across GitHub
* How AI got Kyle coding again after years in leadership
* Why GitHub rolls out AI through existing workflows instead of forcing new tools
* WorkIQ, MCP, Slack, Teams, email, and GitHub as company context
* Why massive “mega-skills” are giving way to small, atomic micro-skills
* How AI changes summarization, communications, marketing, and analyst work
* Why former developers in leadership may have a unique advantage in the AI era
* Kyle’s “15 agents on Saturday” workflow
* How Kyle built an AI-generated executive presentation for CRO/CFO teams
* Why AI changes the chief of staff role without removing the human work
* GitHub Actions, webhooks, arbitrary code execution, and secure agent compute
* The npm acquisition, supply-chain security, 2FA, and token invalidation
* Slop forks, vendoring, and whether AI agents change dependency management
* What pull requests become when most PRs come from agents
* Prompt requests, vouching, AI review, and trust in open source
* What counts as a “developer” when AI lowers the barrier to building
* GitHub Spark, low-code, and why GitHub refuses to hide the code
* 14x commit growth, Actions load, databases, monorepos, and availability
* Copilot’s evolution from completion to CLI, desktop app, cloud agents, and SDK
* Context, memory, rules, and making GitHub “act like Kyle wants it to act”
* Ambient AI, OpenClaw, enterprise security, and the new operating system for agents
* What swyx should ask Satya Nadella about Microsoft’s AI future
Kyle Daigle
* LinkedIn: https://www.linkedin.com/in/kyledaigle
Timestamps
00:00:00 Introduction
00:03:36 Why AI Got Kyle Coding Again
00:07:04 Running GitHub with AI: WorkIQ, MCP, Slack, Teams, and Skills
00:15:39 The Golden Age for Former Developers in Leadership
00:17:31 15 Agents on Saturday and AI-Generated Executive Work
00:20:20 How AI Changes the Chief of Staff Role
00:21:45 GitHub’s History: Actions, npm, Webhooks, and Open Source
00:28:45 Slop Forks, Vendoring, and AI Dependency Management
00:33:57 Pull Requests, Prompt Requests, and Trust in Agent-Generated Code
00:41:21 GitHub Stars, 200M+ Developers, and the New AI Builder Wave
00:45:15 GitHub Spark, Low-Code, and Why GitHub Still Shows the Code
00:47:38 GitHub’s Hardest Era: 14x Growth, Reliability, and Scale
00:59:21 Actions as the Compute Layer for CI/CD and Automation
01:02:04 The State and Future of GitHub Copilot
01:08:24 Ambient AI, Background Agents, and the Future of the SDLC
01:13:09 OpenClaw, Enterprise Security, and the New OS for Agents
01:18:03 Build Announcements, WorkIQ, FoundryIQ, and Microsoft Context
01:21:41 What Should swyx Ask Satya?
Transcript
Introduction: Kyle Daigle’s Expanded Role at GitHub and Microsoft
Swyx [00:00:00]: We’re here with Kyle Daigle, COO of GitHub. Welcome.
Kyle [00:00:07]: Hey, thanks for having me.
Swyx [00:00:08]: You’re not just CEO of GitHub. People know you as that. You have a new role.
Kyle [00:00:11]: So I have an expanded role now. I’ve been working at GitHub for thirteen years and doing all things developer. Joined as a developer myself. And now, I’m also responsible as the CMO of Developer for Microsoft. And so all the kind of learnings and passion for developers and how we work with them and how we communicate and how we bring our products to market, we’re also bringing that expertise to the broader Microsoft ecosystem and helping every developer that uses a Microsoft product or would like to have a sort of similar experience that they’ve had with GitHub over the years. So it’s a different role in some ways, but it’s also just building on the experience that I’ve had at GitHub of just sort of tell the truth, be authentic, show people how to use it and then let the products speak for themselves. Now just doing that with, all of Microsoft.
Swyx [00:01:09]: We’ll be releasing this in conjunction with Build. You got lots of stuff planned, and we can sort of touch on that whenever it’s appropriate. I think one of the interesting things is I rarely meet a COO who’s also a CMO. I think you’re a very outward facing and you’re very confident publicly. That’s rare. Do you actually view yourself as COO? What’s What is your thing?
From GitHub Developer to COO/CMO: Building the Platform and Operating GitHub
Kyle [00:01:33]: I think for me, it’s been funny. The titles have always been, a— have always felt a little strange to me. I joined GitHub as a developer? I wrote so much of the
Swyx [00:01:46]: Let’s bring that up. You wrote the back ends?
Kyle [00:01:48]: I was going through, I was going through, some old photos, when folks were talking about how things were being built or how there was a build GitHub. I built, webhooks and worked with teams building the API, built the platform layer. Anything that integrated with GitHub, up until really twenty eighteen, I built or ran the engineering teams. And that’s kind of where my the beginning of my passion always was helping people build things, deliver them to, their customers. And so being a developer, building for developers was always super unique. In a— I think as my role expanded, it became my ability to talk to not just developers, but also enterprise customers or business leaders and have this translation layer. And then through all those years, GitHub has always operated pretty uniquely. Post-pandemic, working remotely was not as novel as it was when GitHub started in two thousand and eight. But all that expertise of running remote teams, doing it well, became this sort of bigger role, ultimately turning into the COO role of how do we operate GitHub in the way that GitHub’s always operated after the Microsoft acquisition. And kind of so on from there. So like for me, I think the— I’ve, I still code. I love coding but the problem has always been, people. It’s a much harder problem to both support our own employees, a harder problem to communicate to developers and enterprise buyers what we’re building why it matters, ‘cause those are two very different messages. And so getting to work in the mix of COO, CMO, also just being a dev, I think is what’s kept me at GitHub for so long.
AI Workflows for Leadership: Commits, Retrospectives, and Context
Swyx [00:03:40]: Apparently, you have— your commits have gone up. What’s this? What’s going on?
Kyle [00:03:45]: Rui’s called me out pretty aggressively. So I think— as you can imagine, right, you can see my normal era of being a dev In the twenty thirteen, twenty fourteen era, and then moving into management, and then ultimately the COO role. I think what you see there is me, really getting back to coding thanks to AI. I— similar to, attaching problems between how to market and how to operate a business and how to code, I find, building agents and workflows that are connecting very disparate problems to be what’s driving this. So that’s, some of it’s writing software. A lot of it is, connecting a ton of a different data sources to, help me out. But that is completely me really diving in on the AI side in trying out our tools, trying out everyone’s tools, But building for me, building for the non-technical leader, though I’m technical and how we’re, able to use these tools more than just the simple, call and response that I think a lot of the non-technical, your employers, you have to get— you have to use AI, and so everyone uses, ChatGPT or Copilot or Claude or whatever. To really get into, how is this going to help me out, it— I find that it’s not the I need to write a blog post, I need to those simple examples. Helping people find the workflows of, “Okay, I need you to go through all the PRs today. I need you to go through everything that we’ve posted online. I need you to go through what we did the last three months. Go through all of my Obsidian notes for any mentions of this then go through my transcripts at work.” We use, Teams, so, using WorkIQ, go call that MCP server, grab all the transcripts, go through all the Slack, and then build me out the plan of, what this week’s messaging actually was. That’s something that was, impossible because for me, I find AI in a what most of this launch here is actually, less building forward. It’s actually, a recursive loop backwards. I’m always looking at what had happened first. Go back through the week and tell me what we did, what worked, what didn’t work? And then tell me in the next three or four days-What would you tweak based on this sort of like looking backwards and then looking ahead a little bit? I find that to be so much more valuable, especially for like non-technical, because that retrospection is actually LLMs are very good at that. Like finding all the patterns, pulling them out, and then applying that retrospection to just a couple of days or just like a short period of time. Is all a bunch of apps that I’ve built and launched a bunch of, internal tools. I use the new, GitHub Copilot app, the desktop app with workflows. Every time I crack open my laptop, it’s running workflows for me. It’s just a ton of different stuff and of course, it all ends up on, it all ends up on GitHub.
Swyx [00:06:47]: Of course. That’s where, that’s where, stuff is hosted. Man, there’s so much to ask you. I was going to leave the how do you run a company with AI thing at the end. I have to ask one— double click one thing. You said, you are looking back at the week. You’re, you’re understanding what happens. When you say we That’s three thousand people. How?
Rolling Out AI Internally: Skills, CLIs, and Company Context
Kyle [00:07:09]: I think when we started rolling out AI internally beyond engineering, right? One of the things that I was really, passionate about is like we have to do this in a way where no one has to change how they work. I don’t want to have to teach you a tool. I don’t want to have to teach you something new. And so for us, we tried out a few tools. Most of them don’t work because I got to get you on board? I got to teach you how to use it. What we’ve actually ended up doing is we’ve built like a set of skills internally. We have we each have our set of skills, and we’ve just been distributing even to the non-technical folks, the CLI. And then effectively, we’re just giving it access to like read about everything that we’re writing. So that’s for us, that’s usually GitHub, Teams, Email, and Slack. So Teams for, video chat, generally speaking.
Swyx [00:08:03]: Teams and Slack?
Kyle [00:08:04]: so we use Teams for video communication, but we don’t use it for chat. W-we— GitHub for a long history, right? We’re always
Swyx [00:08:13]: Also Slack
Kyle [00:08:14]: Talking about ChatOps and like everything is built into Slack. Like every command, every flow.
Swyx [00:08:18]: So even though you have been acquired for I don’t know, eight years now
Kyle [00:08:22]: we still
Swyx [00:08:23]: You still use Slack?
Kyle [00:08:23]: it’s a purpose-built tool for us, and I think the reality is that moving off of it would be so bluntly expensive? Simply because all the tooling is, baked in with that paradigm. And they both have their pros and cons but they don’t work the same way at all. We still use a bunch of different tools Because it’s the purpose-built tools that We need. And then
Swyx [00:08:47]: Well, the same doesn’t go for the rest of Microsoft, presumably.
Kyle [00:08:50]: like the like various teams like operate
Swyx [00:08:53]: They make their own decisions
Kyle [00:08:54]: Various ways. I think it just matters what you’re trying to what you’re trying to do. But we do we do work across kind of every tool that we use, and then by giving everyone access to all of that context and the new WorkIQ MCP server, which is quite cool if you do live in the M365 like world. I can ask it all these backwards-facing questions, and it’s incredibly important for our teams that are working remotely. There’s a lot of stuff you miss when you’re not in an office, and we are spread out all over the world. So most of that is looking back. And then we post, we post either auto-automatically into GitHub issues or discussions, these sorts of like findings or like our industry reports. Like what’s happening this morning, today, yesterday. A little automation gets run. We’ll use the app. We might use GitHub Actions like with, our agentic workflows just to go do that run, and then we push it into GitHub, and w-we keep having a conversation. So usually for us, it’s about that sort of like looking back, looking forward on the non-technical side. And then of course for a lot of those folks, it’s also building an app, pushing it to GitHub pages or pushing it somewhere to host it et cetera. But it’s just like enabling everyone with that power of it’s going to take me a week to figure this out. Instead, we’re going “Okay I built a skill. Let’s put it into a repo. We’ll all share that skill together, and then we’ll use the CLI or now the app-” “just to run it.”
Micro Skills vs. Mega Skills: How GitHub Uses AI at Work
Swyx [00:10:26]: All right. I think, I think we’re going straight into like the team management and productivity thing. I think a lot of people are getting various levels of LLM psychosis. How do you manage the bloat of skills? Like everyone Has their thing, and they’re Like trying to promote it to the rest of their peers in their org, right? And obviously, whoever becomes a skill influencer internally becomes like an AI leader, right? Of sorts. I assume you have those.
Kyle [00:10:50]: like I think we have
Swyx [00:10:52]: And I assume it’s a mess a Yeah.
Kyle [00:10:54]: there’s like I— like I think the reality is there’s two pieces. Like first is I think that we’re ending the era of these like massive, beautiful, perfect skills that are just like not any of those things. ‘cause for a while, right every tweet every day is like go download the skills, the perfectly managed thing to do this entire workflow. And I think that like what we’ve found and what— I was just with my team, this week, and we were talking about the skill side, and we’re really talking about these like incredibly micro skills that are just doing one thing for us very well Versus a skill that’s going to do I said, that full report. That doesn’t really exist on our side anymore. It’s usually how do— like a single skill that’s going to identify the most important marketing information given any MCP server. Like this is the most important thing. Less about stitch a bunch of tools together and have it produce this mega output because then weeks go by, months go by, things change, and you want to tweak
Swyx [00:11:58]: It’s brittle
Kyle [00:11:58]: Your mega skill and you’re screwed? You can’t do that. And so now we’re really just talking about the Legos we’re using and just letting the instruction book be something we’re all putting together. Whereas I think a lot of AI skills for a while have been that mega instruction book style.
Swyx [00:12:15]: I’ve, thought a lot about Postel’s law. I don’t know if that’s a term that is, means things to folks. It’s the idea that you should be liberal in what you accept and strict in what you output, right? And I think that’s like a good framing principle for skills. This is my skills, obviously on GitHub. I feel like everyone should have like how like some repos In GitHub are special repos? I feel like we should sort of reify the slash skills and everyone like give it some kind of special presentation. Anyway, so, yeah, this is one of those like download Download anything, transcribe anything, and then you can string together the atomic skills that do one thing well Into like some kind of orchestration skill that calls other skills. I assume, does that match?
Kyle [00:12:56]: I like I think so. I think that the
Swyx [00:13:00]: Summarize anything.
Kyle [00:13:01]: Like I think the- For me, summarizing something for I do communications and PR and analyst relations and marketing and customer activities, and so my summarize everything is very different for each one of those like Contexts. What ‘Cause if I’m summarizing something for an analyst, that’s a very different thing than, probably how I’m going to summarize something for like a customer meeting or an engagement. So that’s I think like the difference when we’re talking about the like the tools I might use on Saturday or the skills I might use on a Saturday when it’s just for Kyle. Yeah, those are kind of like they have an atomic actual tool underneath or maybe skill, and then Kyle cares about X. But I think when we’re talking about work and enabling the the marketers, communicators there, it’s the atomic, this is what good summarization is, and then this is what I care about as for marketing for communications For whatever. And that I think is like the interesting matrix problem when we go from like a developer set of concerns to all kinds of different professions, is that what that word means to me is different than it means to you is different than it means to the analyst or the salesperson, and that’s where I think the matrix mess is that we’re starting to like still starting to find. It’s about these mega skills but they’re all just slight permutations, but those permutations are really important. It’s the difference between someone reading this and going “Did AI make this?” what Or “This makes total sense, and I would expect this when I’m giving a briefing to Gartner,” or like whatever else.
Swyx [00:14:37]: I think the beauty of it maybe is that you don’t have to be that careful about what goes in there. It doesn’t have to exactly fit as long as it like roughly is contained in there. I used to complain about plugin hell, basically. Like when you have a framework and then you have a hundred things that you need to integrate, everyone does like the GitHub used to be bloated full of these things. And now we don’t need them anymore ‘cause now you just use skills.
Former Developers in Leadership: AI as a Creation Multiplier
Kyle [00:15:00]: And like I think the most magical thing is the just that like I can just also crack it open. Like Like yes, I could go like change the how the plugin is coded, or like I could go do that now with AI, but I think there’s just something more magical about getting a response back and being “That’s not right,” and then you just crack the skill open, you just type English words and it’s different. That building block is just, I think very unique. Once I get everyone to kind of understand how to best how to best make those changes to get the most power out of them.
Swyx [00:15:36]: Is there a— you have a your peer group that Of people like you. Is there a common framing for Something I’m feeling is, which is true, is that is this a golden age for former developers who are now in leadership? Because you can wield the tools, you would know the right words, you’re maybe not too close to the details. Doesn’t matter. But like you’re more effective than someone who doesn’t come from that background.
Kyle [00:15:59]: I think that like the secret has always been your ability to identify patterns and solve problems, and I think that for folks that like myself that don’t code day to day anymore, that has made me successful as a developer, made me successful as a COO and now CMO. And so now that I have access to get and write code, I’m now applying that sort of like pattern finding and problem solving, and I know enough still about how to then go and say, “Oh, I want to make an app, but I don’t want to break into jail or create something that’s not going to be able to work or to be deployed scale or whatever.” that ability to apply all that additional business knowledge and still code I think is what makes that so interesting to me. Slightly different than I think some of the other like technical leaders that became business leaders and now are going back to their apps and updating them. Good for them? But I think the more, much more interesting thing is, well, now I have this whole new set of expertise over ten plus years. Why not take that and use that as a developer with these AI tools? So I definitely think that makes me more powerful, but I think that’s true for like every dev as well. Most of the dev friends I still have also have some other underlying skill and passion. There’s really talented, very kind of linear computer science software devs, absolutely. I just find that the folks that came from a different career, went to school for something else, went off and did this random thing, and then became a software dev, or were a dev, did a random thing, came back. Learning that extra set of information, learning those extra skills, and now having the power of an AI where I can crank up fifteen agents on Saturday while my kids are doing lacrosse, That’s like really powerful. And I think it gets me back to that feeling of like creation, and it’s very hard to replicate that in most other senses? That first time you build an app and you click it and you show someone that’s magical. And so being able to do that not just in code, but across all kinds of different assets that’s, that’s huge. We were doing we’re doing our every year we do our revenue planning. We talk about okay, what is it going to look like for next year? And of course as you imagine, there’s, slideshows everywhere talking about what are we going to talk about, what’s the narrative, et cetera. And so as you said I’m “Okay, well, I could probably just like build something to build this and then that way I don’t have to go build the whole spreadsheet or I have to pass it to my team.” So we went through this process, and I got all the information and used the skills I mentioned. I built like a little app just to make it so I could look at some of the information in a SQLite database, more easily. And I ultimately built this entire presentation without touching any of it and I was “Okay, I’m just going to present this to our CRO, the CFO, their teams,” without mentioning I’d built it with AI. I like built a skill to make it look very much not AI driven. Just not pretty.
AI-Generated Presentations, Human Taste, and the Changing Chief of Staff Role
Swyx [00:19:03]: Like a design. Yeah.
Kyle [00:19:03]: Not pretty. But just like very clearly not AI. Kind of like don’t do anything interesting.
Swyx [00:19:08]: That’s, yeah, that is valuable.
Kyle [00:19:08]: Just go Exactly. We did the whole thing through. It used my notes from Obsidian, it used all the context I mentioned before, the plans, and Never came up once that it was AI generated.
Swyx [00:19:20]: It didn’t matter.
Kyle [00:19:20]: Never once. D It didn’t matter. And so now I take
Swyx [00:19:23]: This is a tool
Kyle [00:19:23]: I can take that tool and go, “Look, I don’t want you to go build slideshows.” They’re just helping us share information with each other. If this thing can do it With a little bit of crafting from you and then we can look at it together, awesome. There’s no value in all that extra work. I think that the ability to, make it look humanly bad and and build a little app to, manipulate the data I think is part of, that upside for devs that are now in leadership roles. Because, the thing that I feel like I said before, this that’s all a people, that’s all a people problem. I know if you’ve used a coworker or not to build a slide deck, unless you spent a bunch of time to not do it.
Swyx [00:20:07]: I know, but like it was so, I think there’s a certain charm to just being blatantly AI. ‘Cause I think that you’re well, you’re just honest about There may be mistakes here that I cannot vouch for. So how much value is there? But anyway I think, actually the real question I want to ask is, there’s a— You were a chief of staff To Thomas. And in the pre-AI world, the that job would’ve been a chief of staff job of like Can you prep me these slides and all that? And now you do it yourself.
Kyle [00:20:35]: I still, I still have a chief of staff. Because, the difference is it’s sort of the discussion every time we have some sort of technology evolution is it’s not that the jobs the roles don’t all go away, they just change? And so yeah, I don’t have someone spending all their time building out slides for me and presentations ‘cause I don’t need that anymore. But now I need that person that is able to go and find all the different connections between humans in those discussions to help me find out, okay, I should be meeting with this group and this team, and they have an opportunity, and I’m going to be in San Francisco today, I’m going to be in Seattle tomorrow. Those sorts of human connection aspects are still incredibly valuable and has always been a big part of that chief of staff role. But now just like chiefs of staff are not opening up, letters to process, they’re doing emails. What It’s the same thing. And now they’re, they’re not building out as many of these presentations because they have the the ability to have a AI take it on for, and share that with me and great. Let’s keep moving ‘cause it’s allowing us to go faster and make better decisions more quickly.
Swyx [00:21:45]: Awesome. Well, so we can dive into more sort of, Productivity insights as you go. I did want to do a little bit of a brief history of colleague and hub. Because, we started here. And then you also involved the NPM acquisition. I did, I do want to touch upon that. And then more recently, I just want to bring up to present day where we’re having uptime issues Which transparently we’ve already Addressed publicly, but we’ll, we’ll discuss in the pod. Did I miss anything? Like what, any other major highlights? Obviously, it’s, it’s a lot of years to cover.
A Brief History of GitHub: Webhooks, Actions, Acquisitions, and Platform Evolution
Kyle [00:22:15]: No the I think one of one highlight was right before the acquisition closed in twenty eighteen, I got to launch the first version of Actions
Swyx [00:22:27]: Oh
Kyle [00:22:27]: At GitHub Universe. So it was O
Swyx [00:22:29]: They’re that young?
Kyle [00:22:30]: It was October of twenty eighteen, I think. Yeah. Yeah.
Swyx [00:22:33]: Gee, Jesus.
Kyle [00:22:34]: I got to I was the engineering leader on that project and got to launch that. And then, yeah, we did acquisitions of NPM you said, Semmle, Dependabot Pul Panda a whole bunch of things. That was a big
Swyx [00:22:47]: Pul Panda.
Kyle [00:22:48]: Abi is doing well.
Swyx [00:22:51]: DX. Holy crap.
Kyle [00:22:52]: Did well on DX. I and like that was a that was the big shift, after the acquisition. I had to join the sort of business side.
Swyx [00:23:00]: So I need to hit you on some of these things ‘cause you were there. Right? And how often do I get to talk to someone who was there? But yeah, Actions. Is that the number one source of security issues on GitHub?
Kyle [00:23:11]: Oh, sh I think that the number one source of, security issues is probably like all, the literal code in everyone’s like underlying repositories. I would say back further than that is, if you remember I had to show in this graph was this is, I’m, didn’t say this before, this is ultimately webhooks.
Swyx [00:23:30]: You yeah.
Kyle [00:23:31]: Like circa whatever it was.
Swyx [00:23:32]: It says Hookshot in there.
Kyle [00:23:32]: I forget. Yeah. Yeah, Hookshot’s in there. And so like back then, it says GitHub Services. Do you see, it says Hookshot FE for front end, and then it says GitHub Services. GitHub Services back in the old days, right? You we had a repository that was Ruby code, and you could write any Ruby code in there, and then we would execute that On your behalf As a service, and then that way if an if you were trying to integrate with something, it didn’t we would run it for you.
Swyx [00:23:57]: And of course no containers ‘cause
Kyle [00:23:58]: No, ‘cause it was
Swyx [00:23:59]: Well, no containers
Kyle [00:24:00]: Twenty fourteen. And so there was some isolation obviously, but it was mostly the separations on the server level. That’s like an example as long as the very old version of Pages, which ran on its own containerization infrastructure, not on Actions.
Swyx [00:24:15]: Which like all-time great product.
Kyle [00:24:16]: Pages powers the internet at this point to some degree. Those were places where like clearly there were no like issues like to my knowledge. But it was those things where I’m looking at and going “Okay, well we can’t be running arbitrary Ruby code,” like on everyone’s behalf. Then containerizing all of that up intoUh into actions now where yeah the containerization, is r-really good. The pinning most folks aren’t pinning it the like to a particular
Swyx [00:24:48]: Images
Kyle [00:24:48]: Sha, et cetera like their workflows, and so that’s a big that’s a big place Of pain for folks if they’re just doing similar to any dependency management, just V1 or newest or latest, I think. But, that journey from that day to “Okay, we’re just going to run all this arbitrary code, and, it’ll basically be okay,” to now, no, we have, really good containerization. We have a new, underlying, ag-agent, containerization, service. It’s like we’re using it under the hood. It’s through Azure. They recently announced it. The Azure, Dev Compute, but it’s, very fast, very fast compute to be able to, spin up your own cloud agents, or whatnot. We’re using it under the hood for some parts of the new,
Swyx [00:25:36]: Microsoft Dev Box?
Kyle [00:25:37]: No. Dev Compute, yeah.
Swyx [00:25:41]: Hmm. Not finding it just yet.
Kyle [00:25:44]: Oh, it’s, it’s in there somewhere.
Swyx [00:25:46]: All right. Well, we’ll cut that out.
Kyle [00:25:47]: Sorry. But with, Dev Compute, you can, run, really fast, spin up really, small VMs really quickly, so you’re doing a tool call
Swyx [00:25:58]: Same concept
Kyle [00:25:58]: Just do it containerize exact-exactly. So we’re using that so definitely moving that direction to protect us from every every piece of code that we’re ultimately running.
Swyx [00:26:07]: look, that grows into the full SDLC? Code hosting was just the start and and then it’s grown beyond that. Let’s talk about NPM may-maybe ‘cause I think that’s also, a very major point in the industry. I do think, it was looking for a home. It was, kind of struggling as a business, right? I don’t know, I don’t know how you would characterize that whole acquisition and how it
NPM, Package Security, and Keeping the Internet Running
Kyle [00:26:33]: like when we were talking to the team, I think the big thing for the both of us was to find a way to keep NPM, which was basically powering the internet then and way more so now to some degree running. Keep it going keep continuing to scale. It was having scaling problems, if I recall, back at that time. They were doing some rewrites. It
Swyx [00:27:00]: that’s cute compared to now.
Kyle [00:27:01]: Well, that’s the thing is like when I’m talking to folks now, there’s there’s so many more underlying uses of NPM than there were back when we had them join in with GitHub. But that was ultimately the goal. It was really okay, we used to have pages. We have, the world’s code. Let’s make sure that we can keep NPM running well for the world. And we put a bunch of time and investment into fixing some of the underlying backend, changes, some of which we talked about some of the manifest work, et cetera. And then now, really trying to bring the the security posture of NPM up to speed. But, it is a unique challenge in that every move that we make to make it more secure will break a lot of people. And security is paramount. And also, we take it very seriously. We’re, the any time that we have a problem with GitHub or we make a change that makes us more secure but hurts, there’s, a snow day for developers or a really bad fire that they have to go put out. And so we’ve, have changed the 2FA policies. We’ve changed the way the tokens work. When we find tokens that have been exposed or potentially, exposed, we invalidate them, and
Swyx [00:28:22]: I love that feature in GitHub. Yeah, it’s great
Kyle [00:28:23]: That creates issues, but, the but that’s the thing is we’re trying to push the community, forward without necessarily, doing something that is going to break the contract that’s been for 15 years or close to it or some amount of years on NPM.
Slop Forks, Vendoring, and the Future of Open Source Supply Chains
Swyx [00:28:43]: I think the— So now we’re talking about, open source and publishing. And I think there’s something here with what people are calling slop forks, which, I think Malta from Vercel is doing. And, part of me thinks, well, the way to get past any vulnerabilities, we just, let’s just get rid of the concept of NPM. And we only publish source code. And anytime you want to import it you have your coding agent look at it and then adapt whatever subset you’re going to use into your vendor it. But, the AI vendor it. Is that realistic? I don’t know. Is it— Will that solve all our security issues? I don’t know.
Kyle [00:29:24]: I don’t think it’ll solve I so Mitchell was just talking Mitchell Hashimoto Was just talking about this today, and I think that I-in some ways, it’s all all things, old or new again? Yeah, absolutely vendoring everything. Like I do I do remember twenty thirteen, twenty fourteen.
Swyx [00:29:42]: This is Yeah. Let’s, we must return to
Kyle [00:29:43]: That’s what is We were vendoring everything. We were having actual discussions around, or at least I remember we were “Should we take this full thing?” “Why is this so big? We only need this one file.” And so I do think there’s something true there where having either taking only what you need or the dependencies just getting incredibly small over time, I think will help to some degree, but it’s not going to solve the fundamental problem, I don’t think, because the vulnerabilities in an agent looking at them, there’s time and time again, there’s a million different ways in which we can convince an agent that this thing is, secure or not and pull it in. Or we can do static code analysis or runtime testing to say whether the code works or not. That is, I think, the step that needs to continue to be, invested in. The question is just on, how much scope. Should it be this enormous project that I’m pulling down, or should it be this piece? Either most companies are running some amount of security checking on the on the packages that they’re bringing in or vendoring. That I think won’t change. That’s like what advanced security does to some degree, Socket does some degree. Like everyone is doing a piece of that. How we each do that like especially when we’re talking to enterprise customers, is just like very different. No there’s no one wants one single way to do it. And I think that’s always been GitHub’s, unique position in the world. I talk a lot to maintainers, I talk a lot to folks about this. It’s we’re— we rarely start like a process and a practice and like push it onto the community. We usually wait for the sort of like RFC process socially or literally, everyone agreeing, and then we’ll cement something in. Because otherwise we’re
Maintainers, RFCs, Vouching, and the Social Layer of Trust
Swyx [00:31:35]: That fits your role in the ecosystem, yeah
Kyle [00:31:36]: We’re GitHub. Yeah, we don’t want to shape the whole thing. We want it to be figured out. But like how do you balance that like sort of Role in the industry to keep everything as secure as is possible and make sure that you’re you’re not going to be compromised as a human, ‘cause that’s usually how it all happens. And Not not create a process or lock us into a flow that you’re not going to or like Mitchell’s not going to or other open source projects aren’t going to like. That’s always been a tricky balance for us, and I think that’s something that we haven’t talked about enough is we’re not going to be able to fix everything for everyone in a way that everyone is going to like. So tell, help us, tell us what is working. When Mitchell was talking about, the Upvote, the up
Swyx [00:32:22]: I was going to bring up his thing. Yeah.
Kyle [00:32:23]: I forget what it Yeah. When he’s talking to us, I was chatting with him and talking to him about this and I put it on Twitter and we talked to, also over DM, was “We’re going to keep working.” but I think the important thing is I do actually want to hear what isn’t working for you. And as, be as specific and clear for your project as is possible. And to every piece of credit over the many years that we’ve known each other through the industry, he’s always done that and I appreciate that ‘cause there are places that we need to fix up, and we hear from him, and we’ll fix up just like we do all other kinds of maintainers. But that that process between making those types of improvements and being more secure and like creating, I forget what he calls it’s not the proof process, not the claims process. Do what I’m talking about? He has that he his projects have a way for you to kind of like,
Swyx [00:33:13]: Vouch
Kyle [00:33:13]: Vouch. Thank you. Yeah. He has like the vouch system for saying, “Hey, you should accept my PRs.” That’s been
Swyx [00:33:20]: I just built this into GitHub. I don’t know.
Kyle [00:33:22]: Well, see, but that’s the thing is that you say that and like he and his community really likes this and then I’ll go talk to other maintainers and other maintainers, globally, and they’re “No, this doesn’t work for me.” And that is the tension, but also the kind of beauty of GitHub, depending on which way you look at it is we want to help maintainers, so we create all these tools to let you have more control over how much you take in from AI and PRs. But you can also use this. What You can go use this project, and if it takes off and becomes the kind of mostly standard, then yeah, we probably wouldn’t enforce it but we would add it in because that’s the flow that we tend to do?
Swyx [00:34:02]: I hear a lot of people don’t know the history of the pull request. And like like that’s how, that’s something that GitHub standardized basically.
Kyle [00:34:08]: Yeah. It was a very messy process Like beforehand, and now the we have the benefit of it being the process? And now we have to go and Figure out the next best process or what adaptations change, or what does a pull request look like when eighty percent of your PRs are just coming from your agents and not From other devs?
Swyx [00:34:31]: Do you like the prompt request idea from Peter?
Kyle [00:34:34]: like I think that for each like each idea I think has its merits. I’m not, I’m not avoiding saying anything good or bad, but I feel like I’ve seen a version of we have that we have entire Thomas’ store. Take all the assets of what you’ve built and put that in. I think that’s got great ideas. There’s all these various permutations of the PR flow, but I think the reason why there’s not a single answer is ultimately we’re trying to codify trust. We’re trying to say “Okay, if Sean reviews this I’m going to trust it because you’re Sean or you’re the senior dev or you’re the whatever.” And right now, when we are working in a flow where an agent writes code and another agent reviews code and then Kyle goes and looks at it the trust is kind of diffuse. And most of the tools that we’re talking about are talking more about verification flows. We have more assets to look at, so I can probably say whether this is a good PR or not. But that still doesn’t solve, I think, the human problem of I’m looking at a PR and I want to know if I can trust it. And we’re still, we still tend to use human signals for that? Mitchell approving it or Kyle approving it or whatever. And so I think that’s, I think that’s why most of these options haven’t really solved it is because, it’s a social problem ultimately. It’s a it’s a human problem to review it and agree. Or you fully trust the tool and you’re imbuing that tool with full trust Which I think in some cases that absolutely exists.
AI-Generated PRs, Trust, and the Waymo Analogy
Swyx [00:36:08]: And so like in the same way that there will be a tipping point in society when we don’t allow humans to drive anymore Because machines are measurably better than Than humans. I’m looking for that tipping point, right? Like Mythos is ridiculously expensive. Someday we’ll have Mythos on a desktop. I don’t know. Will, does that change the equation?
Kyle [00:36:30]: I think it’s more I took a Waymo here, and I was on my phone and not looking around at all. There are other, self-driving, vehicles that I would not trust while, staring at the road. And I think that trust is something that is
Swyx [00:36:48]: Is this a Zoox thing? What is it
Kyle [00:36:50]: I think that is both. I think that is both. Like
Swyx [00:36:53]: There’s Zoox in this robo taxi. That’s it. It’s
Kyle [00:36:56]: Well, depending on what level Of self-driving. But, my point is sort of that I think part of that is I strongly believe that’s, a mixture of verifiable proof. Like how many accidents, how much data, and so on, and the human aspect of how I feel when I’m in this car, what it tells me, et cetera. And so that’s why I think some of the like Some of these some of our AI tools tend to, imbue me with more of that feeling of trust, even if the data says this is 100% accurate. I feel like it takes more time for us to go, “Should I trust this or not?” And that’s in the soft sense of, startups with high agency, weekend projects, and open source. And then there’s enterprises and regulated industries and everything else, and that is an even harder problem to go solve because even when it is fully verified, not only do you have to have trust from the humans on the team, you probably have to have trust from multinational,
Swyx [00:37:55]: Oh my God
Kyle [00:37:55]: Multi governments around the world and regulating agencies. And so that’s where I feel like until we tip over to your point on the sort of like human EQ side of it. I feel okay this feels okay I’ve been proven enough. Then the ball will start to roll a lot faster, where we’ll end up getting to the “Okay, we can trust this,” and feel good about it in the Most difficult of cases.
Reputation, Sponsors, Stars, and Bot Activity on GitHub
Swyx [00:38:18]: If human trust is the thing that matters, I feel like GitHub as the developer social network could maybe do more there. Like vouchers are one system But, we have star counts, and then we have Contributor rights, and that’s it. And I feel like there should be more in that space. I don’t know if there’s any other design decisions there.
Kyle [00:38:37]: I think that one of the places that we don’t really expose right now in this sort of way is, some degree of like hard trust and support, which would like for me is like sponsors is a good example of that.
Swyx [00:38:49]: Ah.
Kyle [00:38:49]: It like costs you something. To prove that I believe in your project and I trust you To some degree or I want to support you at the very least.
Swyx [00:38:56]: Solve payments for open source. Why not?
Kyle [00:38:58]: I think that I think that like as we keep moving forward, right, there’s more and more projects where I’m, adding more and more dollars into sponsors personally because I want to like support them, but I also like know of I’ve probably never met them in person, but, I know of enough of their work that I want to support them. I think the thing that I don’t love about stars or commit counts or anything else is ultimately, even with all of the various, abuse and de-spamming and deduplication work that we do or anti-abuse work that we do, these are all, not active social signals. They’re passive ones that are ultimately gamifiable. And you may trust me, but another open source maintainer may not. And on what heuristic should you be, trusting me? That I think, is kind of where some of our thinking is right now. What signal from me is most important to you? You— If you can define that potentially, honestly in an agentic workflow that’s what we see some of these open source projects do, where you have GitHub actions, and then you have like an agentic workflow that’s calling AI, and you’re setting these rules. Like if Kyle has submitted and gotten accepted PRs across any given project and has a social handle tied to his account in GitHub, and that social account’s older than a certain amount. Really complex measures that matter to you ‘cause most open source projects have that heuristic built into their heads, if not written down in the contributing guidelines. You could take that and then go apply that and then just say, “Oh, we’re not going to accept this PR.” Building something that is, I think, malleable to everyone’s needs, is a little bit better, rather than going “Hmm, this account’s too young.” Because what happens? The attackers just go and go and create a multitude of accounts, and they wait Until it ages up. Needs to have a certain amount of stars. That’s how star inflation happens. Need to have a certain amount of repos
Swyx [00:40:46]: Oh my God. Yeah
Kyle [00:40:47]: With PRs. They all just create repos and submit PRs to each other, and then they come in and do something nefarious. And so, it’s hard. It’s hard to find the measure. So I think we’re, we’re looking more at how can we provide you tools so you can kind of choose what’s best for you. And of course, we’ll give you some standards. But the trust vector, gets down to I don’t know, some version of like human digital ID like everyone’s been talking about. Like how do I prove that it’s me
Swyx [00:41:13]: Give me your eyeballs
Kyle [00:41:14]: On the internet. Give me your eyeballs. Exactly.
Swyx [00:41:18]: The I got to keep moving on Topics, but obviously I can go all day on this stuff because, I’ve been involved in GitHub and open source My entire professional career. Stars. Very superficial. Everyone knows it. But I think time to one hundred thousand stars is the fastest I’ve ever seen. Like people just reached that in I don’t know, months. And then like at the same time I don’t trust it right? Like how many of these are real or bot or like whatever. I don’t know how to ask this but like what can we do about it? Like
Kyle [00:41:49]: Just
Swyx [00:41:49]: Is stars broken? Is stars fine?
Kyle [00:41:51]: I think that there’s kind of two, there’s like two pieces. Obviously we’re constantly like trying to find ways in which like your users are producing spam, which would, I would include like be like only doing star gamification. When we find them, we pluck ‘em out and we,
Swyx [00:42:08]: But it’s like a Whac-A-Mole
Kyle [00:42:10]: It’s a hundred percent like a Whac-A-Mole
Swyx [00:42:11]: There’s no way
Kyle [00:42:11]: Now, powered by AI to be helpful. But I think more so what I’m seeing is, a lot of the like fastest time to X tends to be because we’re now inviting so many more people into like software development on GitHub That like the zeitgeist is just swarming? And it’s
Swyx [00:42:32]: It’s not just developers anymore
Kyle [00:42:33]: And it’s not you and I. Like like however you want to say like what a developer is it’s not just folks who have been coding for a very long time. It’s folks that have maybe started coding or only joined in since the AI era. And now
Swyx [00:42:44]: what’s the latest Octoverse number? I know eighty million was my lastRem- member that a number of developers on GitHub
Kyle [00:42:50]: Oh, we’re over 200 million now.
Swyx [00:42:53]: Okay. Well, so you see?
Kyle [00:42:55]: Like over 200 million developers now.
Swyx [00:42:56]: But it’s not developers, right? It’s, it’s people with a GitHub account.
What Counts as a Developer in the AI Era?
Kyle [00:43:00]: So, so this is, this is the biggest debate that I would say, everyone loves to have at GitHub at this point. From my perspective, right, I think that there’s, there’s clearly a difference between, professional enterprise developer and then developers. But I think that I think that the idea that we should be I don’t know, splitting hairs or segmenting developers in the early era of software development is, not worth our not worth the time. So
Swyx [00:43:29]: When you get into gatekeeping
Kyle [00:43:31]: 100%
Swyx [00:43:31]: What is a developer?
Kyle [00:43:31]: 100%. ‘Cause I wasn’t a developer when I started writing code? I was going to
Swyx [00:43:36]: Oh, no. I made— I cloned a thing, seven years before I learned to code. And then I and then I wrote about my learning to code journey, and people Just called me a fraud ‘cause I had a GitHub account. And I’m “Well, no, I just use GitHub, but I don’t know-” “I didn’t know what I was doing.”
Kyle [00:43:49]: I I remember that. I remember those sets of posts, and like that’s, that’s b******t. So I fight very clearly on the line of, if you create code, if you have an idea and you create it into some way of, I’m, I’m going to run it and use the app right now, you may still use AI in that moment, but that’s okay. At some point you’re going to do the next thing. You’re going to create a big— You’re going to have to learn about this database. You’re going to fix a bug, whatever. We’re all on some same journey, and those people are also hearing about the great new agent skill package or a new CLI tool or a new whatever. And those projects are going up because you want to be a part of this moment, just like I wanted to be a part of the Ruby community when Ruby was popping off when I started becoming a developer, and now I can just click the star button. And so I think that yes, there’s clearly some amount of like spamming and game gamification that we’re working against, but I really think we’re just seeing this whole new cohort of folks that are moving from technology to technology because they’re not working on a 20-year-old software application. They’re working on a side app that they built on the weekend for their friends or for their new idea or whatever. And that’s how you see these enormous charts going up and to the right with With stars.
Swyx [00:44:59]: I think something that’s remarkable is the persistence or, that GitHub extends to those folks. Usually when I see platforms go into a new audience, they usually have to, have like a second platform with a different name that wraps the main platform. But somehow GitHub has been able to sort of persist and extend, and it’s friendly and whatever? So it’s, it’s nice.
Spark, Low-Code, and Always Showing the Code
Kyle [00:45:19]: I that’s partially why I think as we’ve tried to move into I don’t know, more like low-code-y things. We so we started working on Spark as like a way to, build an app and run it. I think that the reality is that we anytime we try to, kind of put even a veneer on top of it without when we put a veneer on top of something, we still always show you the code. That’s kind of like a tenant. We’re never going to, hide the code from you ever, because what
Swyx [00:45:52]: Why would you?
Kyle [00:45:52]: That’s, yeah, that’s the whole point? However, I think that what we learned with things like Spark is that really the value of Spark for most devs is, easy runtime. And you may have a runtime or a host that you’re going to use for that or you just build something and run it but, the package of making that even more simple isn’t really needed for folks that are trying to build software and not just trying to build, an app, which is, slightly different, a slightly different goal. So I want to get you in, I want to get you comfortable. I think the best thing for me as, someone that did not traditionally come into software dev way back, I want anyone to be able to breach that chasm and not be in the I don’t know, I feel like we’re, we’re still in an era of, STEM. I’ve got a 12-year-old and an eight-year-old, and it’s “We got to get ‘em into STEM,”? Over and over. And I like I do, I do the things that good parents do. I was “Oh, you want to do coding?” “Yes, I want to do coding.” Do coding classes. But now they’re just not afraid of doing software. And that’s, I think, the thing that’s honestly kept me at GitHub for so long. Anyone should be able to go and build a thing, just like I can go change a light switch in my house. I’m not going to go into the breaker box ‘cause I’ll probably kill myself? But, I can go change that light switch. Everyone should be able to go and say, “This fricking app doesn’t do what I want. I want it to work like this.” And that I think, is what’s kind of kept us all connected with GitHub through the years and some and during the easiest of times or in the hard times because of that opportunity of, we’re the home for all developers, and we want everyone to be able to have that feeling that we’ve had of, had an idea, I created it and holy s**t here it is.
Swyx [00:47:37]: Here it is. All right, I’m going to try to do more spicy questions.
GitHub’s Hardest Scaling Moment: Growth, Agents, and Uptime
Kyle [00:47:42]: Great.
Swyx [00:47:42]: Is it an easy time now or a hard time?
Kyle [00:47:45]: Oh at GitHub? It’s a hard time. Like, it’s a hard time and also, I was just with my team and I said, “This is also, the best and most exciting time that I think I can remember at GitHub.” Because
Swyx [00:47:57]: Best of times, worst of times. It’s never one
Kyle [00:47:59]: ‘cause we’ve we were talking about Octoverse reports and, usually we do an Octoverse report once a year, and we look at the numbers, and we say, “Oh my goodness.” I was at Universe in October saying, “This was the fastest year of growth that we’ve ever had,” right? And now we’re doing more in a month than we did in a year last year.
Swyx [00:48:20]: You’re talking about PRs.
Kyle [00:48:21]: Commits.
Swyx [00:48:21]: Commits, yeah.
Kyle [00:48:22]: PRs. Kind of like you name it by roughly every measure that we’re looking at, there’s some amount of sort of growth that is much bigger, and that is breaking our system in new ways, not old ways. Like webhooks were always notoriously, unreliable over the years?
Swyx [00:48:38]: Whose fault is that?
Kyle [00:48:39]: not anymore mine, but for a period of time, I’m sure you could pull up a tweet that was “It was me. I’m sorry.” but, now, that got rewritten at a scale level that is still working and is not having problems today. Now what we’re finding isn’t just the isn’t the-The simple stuff that folks are on the sometimes on Twitter or on the internet are “Hey, why is this like this?” Sure. There’s absolutely silly problems that we shouldn’t exist. But now we’re talking about, unique, novel permission problems that happen only at a scale across all different objects or whatever, that now we have to go rewrite this underlying system. And so it’s, there are problems that yeah, caught us off guard, which I think I said. Like the growth is astronomical, but also we’re making such material progress in that I’m excited once we’re once we’ve kind of like reimagined the underlying foundation layer, or pieces of it at least, what’s going to be possible when it’s not just all of us and all the new people that are being developers and all of their agents and all the tools like working together. Because that’ll still happen in that in that GitHub tool, that GitHub community. But it’s a it’s a hard day anytime we can’t give you what you’re looking for. We have the same problem internally. We operate through github. Com. Of course, we have backups when things go down and whatnot for our own operations but we feel it too. If it’s not working it’s not working for us, and that’s kind of like the promise of dogfooding for GitHub. It’s always been true. We’re using the same tool you’re using. We’re not using a super secret version. We and so we also need it to be great for us for our customers of course for open source. And now an exponential growth of agents, Doing it too.
Swyx [00:50:32]: I wanted to load for audio listeners who maybe haven’t seen your tweets, whatever. So one billion commits in twenty-five. Now it’s two hundred and seventy-five million per week on pace for fourteen billion this year, if growth remains linear. Is that still the pace? I don’t know. It’s been a
Kyle [00:50:48]: it’s, it’s speeding
Swyx [00:50:50]: Roughly.
Kyle [00:50:50]: It’s still speeding up.
Swyx [00:50:51]: It’s, it’s April, so yeah.
Kyle [00:50:51]: Exactly. This was in April.
Swyx [00:50:53]: All right. So basically you have fourteen x growth, right? Year on year on year. And I think that’s a scaling issue. I think, I’m going to like try to really steel man this thing. People have experienced fourteen x growth. They haven’t had your downtime. And that’s like— C-can we go dig into that? Why? Like what’s the— what broke? What are we doing to fix it? Like just anything for the community to reassure them.
Why GitHub Reliability Is Breaking in New Ways
Kyle [00:51:18]: so there’s a Like I was saying, there’s a couple different places that we’ve seen the growth issues. Some of the growth issues, which is why we’re t— I was talking about pushing hard on more CPUs is in actions in particular. More tools, more agents, more PRs mean more builds, more builds mean more CPUs. And so we are expanding through not just our data center, but obviously we were talking about moving to Azure and moving to, adding an additional cloud compute because we simply need more CPUs. Not as much GPUs. We definitely need GPUs too, but now CPUs are becoming a factor.
Swyx [00:51:53]: It’s very CPU heavy.
Kyle [00:51:54]: Underneath the hood when it comes to some of the underlying services, we’ve been breaking up over the years our database infrastructure, so that way we have, more cognitive separation between our the various services. The place that we continue to have pain is in, permissioning. And so right now m-many of our permissioning layers sit into a database that we like internally call MySQL One, and old Hubbers will know what I’m talking about. And so we’ve been pulling things out of MySQL One for many years, because like and we use we use Vitess and we use other technologies to shard and we do it as one big
Swyx [00:52:31]: Famous thing, PlanetScale was born from this and
Kyle [00:52:32]: A hundred percent. Sam Old Hubber and friend. And so finding these opportunities to like break this out and then do that globally. The other thing that I think is interesting and both a unique opportunity and tricky is we also run everything I just talked about in a black box container with GitHub Enterprise Server for people that work on-prem. So we take everything I just said, and we also do it on-prem, and we also do all of that and we do it in a data residence setup for customers that need to have their data in a single location. Each of these has the unique characteristic around how we’re sort of storing that data in MySQL or in a permissioning setup. That’s where some of these outages have oc-occurred, where you’re seeing it more like across the board rather than just like the one piece
Swyx [00:53:17]: Filling the database
Kyle [00:53:17]: Isn’t quite working. Exactly. And so part of it is that. I think there’s been some other places where agents are much more or more projects appear to be moving towards monorepo versus we were going the other direction for many years in the industry. Repos were smaller, but there were more of them, and now we’re seeing the opposite. Repos are bigger, and there’s, not fewer of them per se ‘cause there’s new growth, but, we’re just seeing many more big repos. Big repos, big monorepos have always had, a unique performance problem. Because each one, is slightly different if, particularly if the underlying blobs are incredibly big Inside the repos. And so we’ve done a ton of work that you pro— like most people haven’t probably experienced, unless you’re in this case of the monorepo. But that Git, infrastructure layer improvement does help the overall, system because, many of the improvements that make monorepos work better make all repo infrastructure work better. And so, I could kind of keep going down the line where it’s another thing where we’re moving out of, We’re changing how we do j I’ll just say job queuing for lack of a better, explanation changing the underlying technologies there.
Swyx [00:54:32]: I spent two years being a job queuing guy, so.
Kyle [00:54:34]: And so it’s kind of a little bit of a little bit of piece by piece, and it’s mostly because as we were— as it was built, we built everything in a way that assumed, I guess in some ways that the size of the pipe of work was going to remain the same. There’s just going to be more people coming through each of those pipes. But instead now in places whereA git push was, generally a certain size for example, is now, no longer true.
Swyx [00:55:03]: Oh, yeah.
Kyle [00:55:03]: Or
Swyx [00:55:05]: I push a thousand
Kyle [00:55:06]: On the average. 100%
Swyx [00:55:06]: A thousand line commits like daily
Kyle [00:55:07]: Same thing with PRs. Like PRs same thing. And like we’ve talked about optimizing that and making changes where, and there were technology choices that did not work there? And it got slow, and it didn’t It was not fast. It did not do what the users wanted. And so we’ve been reeling that all out and going “Okay, that’s just not right. Let’s stop putting good money after bad and do it the do it the right way or the right way now.” So there’s It’s a it’s a lot of things, not quite when I’ve experienced scale at GitHub historically, it’s almost always two options that we’ve used. We go vertical scaling, particularly with databases, right? And we go horizontal scaling. Oh, we just have more people using this service. Great. We’re going to add more servers, and we rack them in our data center, or we use it in a cloud. And now we’re sort of in a like diagonal, where like vertical doesn’t really work anymore. Horizontal isn’t work either because we’re all We all have some CPU or GPU constraints in the world now, and now we have to go in and like crack open services that have been running for 10 or 15 years and go, “Okay, the rules of this service have legitimately changed, and now we have to rewrite them.” None of this is an excuse. This is like we’re We have to do the work. We have to make it better.
Swyx [00:56:22]: actually as an infra guy, I’m “This is like one of the most fascinating scaling challenges I’ve ever seen.”
Kyle [00:56:26]: That’s that’s, that’s the thing that’s the thing that it’s hard for Like when we weren’t talking about it publicly, and I was like I came out, and I was “Hey, I just want to explain what’s going on.” Part of it comes from a very old GitHub ethos, which is it’s our it’s our uptime. It’s down. W What I know you’re a developer, so you’re, you’re inclined to want to understand more what’s going on. But at the same time us going “Hey, this service didn’t, perform the way we expected, and now we have to go change it,” we weren’t We’re not trying to hide anything from you in that. It’s that well, that’s our problem because you expect us to be up, and I think that’s really baked into the core, origins of GitHub. And so now what we’re trying to do as a team is do all that work and just tell Talk about it more and just share you more technical details, write these blogs, write the posts, get the engineers who built it after they finish the work, just tell you “Okay, this is what we did.” I think that’s the contract that we want to bring back to the community and say, “Hey, we’re still very serious about what we’re doing. We haven’t been telling you about each piece. So let’s do that and we’re going to keep building this and scaling it in a way to support the If it’s not 14, then it’s 30 or it’s 50 or whatever the next exponential growth is going to be.”
Swyx [00:57:40]: First of all, fantastic answer. I think
Kyle [00:57:44]: And I apologize in advance if like any of that
Swyx [00:57:47]: I think it’s all nice
Kyle [00:57:47]: Is slightly incorrect just simply because
Swyx [00:57:49]: No
Kyle [00:57:49]: I’m not the I’m still in the weeds with this but it’s not my day-to-day. But like that’s the thing is we’re all looking at it to that level.
Swyx [00:57:58]: And obviously, if people want to help, they can join.
Kyle [00:58:00]: Absolutely
Swyx [00:58:01]: So like I think the that is, good. I think people also would just want to know when are, when are you through the thick of it right? Like is there Have we identified all the issues? Is this just never-ending? Is Git broken? Do we have to change the Git, protocol? Like what how much is breaking, right? It’s been a while. And so I think people do want to know What’s the path back to the reliability that everyone expects out of GitHub.
The Reliability Roadmap: Databases, Compute, and Load Testing
Kyle [00:58:30]: So like our availability in like recent few weeks has been much better than the three weeks before that or the three weeks before that and so forth. And so a lot of these improvements are still very much paying off for us. I think that we’re still working on that that database piece that I mentioned, and that just is a little bit physics a little bit of time to get it to get it fixed up. Because we have to the w
Swyx [00:58:59]: My the answer I had in my head Was call YouTube.
Kyle [00:59:03]: So YouTube ultimately is
Swyx [00:59:04]: ‘Cause they also use Vitess.
Kyle [00:59:05]: They also use Vitess. But the,
Swyx [00:59:09]: Like whoever was the guy, the scaling guy at YouTube?
Kyle [00:59:11]: Like that’s That I believe went to PlanetScale, and was a part of PlanetScale too. But like
Swyx [00:59:16]: Oh, you mean Sugo?
Kyle [00:59:17]: I think so. Yeah. And so, and so like
Swyx [00:59:19]: He’s at Superbase now.
Kyle [00:59:20]: Ah.
Swyx [00:59:21]: There’s a whole Postgres drama Thing there, right?
Kyle [00:59:25]: So like some of it’s that. I think the other piece of it is, our move to get additional compute will alleviate a fair amount of this particularly on the action side ‘cause a lot of the underlying, outages is actually related to,
Swyx [00:59:39]: I’ll tell you actions is the it’s the root of all evil.
Kyle [00:59:42]: it’s all It has its pros
Swyx [00:59:47]: Some extent
Kyle [00:59:47]: In that it’s the core It’s the core compute layer for either CI, side projects, et cetera.
Swyx [00:59:52]: Is the main money maker? Like is
Kyle [00:59:54]: Actions?
Swyx [00:59:55]: No? I don’t know.
Kyle [00:59:56]: like Actions
Swyx [00:59:57]: I pay a lot for compute, right?
Kyle [00:59:58]: like Actions is definitely a piece of the overall business, but I would say that like we ultimately also
Swyx [01:00:06]: Storage
Kyle [01:00:07]: Give away so many like minutes as part of our entitlements as that. But that’s what I was saying. Everyone’s using it. We talk about it as CI/CD, but the reality is people use it for CI/CD and
Swyx [01:00:17]: Automation
Kyle [01:00:17]: Various processing and automation, exactly. And so like part of it is also that like compute piece that is also alleviating some of our availability.
Swyx [01:00:26]: This is my abuse of, actions. I have been
Kyle [01:00:29]: Oh, yeah
Swyx [01:00:29]: I have been scraping for every day, and just like I just tell people to
Kyle [01:00:34]: Thank you for your service
Swyx [01:00:35]: Go dog because I But this is also how I track, actions all time. So anyway,
Kyle [01:00:41]: So like some of it’s going to be that. I would say that like each month I expect in the next three months, you’re going to see fewer and fewer moments where we have an availability problem Where things are going to go down, and that’s not just it’s stopped. It’s that we’re still experiencing faster growth than ever before. It’s just that those underlying improvements that we’ve been hard at work on, are finally paying off. It’s just that the improvements take-It’s less about, these incremental improvements where you make a small change, and you get this big output. It’s now material change That takes a bit of time, and then you see a step change in our availability.
Swyx [01:01:14]: There’s a thing we used to do at Amazon, I don’t know if this is, a thing, but, if automated software verification or simulation of load testing and all that. I’m, I’m just like at this point, you have a whole map of GitHub. And, while you can assume whatever growth rates on whatever dimensions that you care about and just run it through a system, right? I feel like there’s a way to, I don’t know, have a systems model of GitHub and, see what breaks. But obviously, I’m pro— I’m not that close to the problem, so.
Kyle [01:01:39]: But yeah, so yes, totally. And I would say, that’s been the journey and work that’s been happening since, I would say November to now. Because October, right, was the time where we even said, “Oh, look at the growth,” and, and then you start to see the chart
Swyx [01:01:53]: It doesn’t
Kyle [01:01:53]: Really pick up. And it’s oh, we tested it at N amount of scale, and now it’s at, N cubed maybe like in some in some vectors. And so now we have to go and build it that way and make sure that it can handle all of that scale.
Swyx [01:02:08]: Let’s talk Copilot. So how many original creators of Copilot are there?
The State of Copilot: From Code Completion to Agents
Kyle [01:02:15]: Oh, geez.
Swyx [01:02:18]: ‘Cause I count like twelve authenticated.
Kyle [01:02:19]: We haven’t— Yeah, I forget, all joking aside, I forget the number of people that were on, the original, GitHub Copilot team. But, there was a bigger group.
Swyx [01:02:30]: I heard it’s, it’s Alex. It there’s, there’s, a three people
Kyle [01:02:32]: Alex worked on it. Udo worked on it. There’s a a bunch of people that were on the team.
Swyx [01:02:35]: And then their entire management line. Okay. So enormously successful at its in its in its day. I think the last number, I think Mario Came to my conference, and talked about the hundred million dollar mark. I think most recently three hundred. I might be out of date as well there.
Kyle [01:02:53]: I don’t think we shared the dollar amounts.
Swyx [01:02:54]: All right, cool. Just, what’s the state of Copilot? It’s, it’s obviously as a concept brought into More of Microsoft. But just at GitHub.
Kyle [01:03:03]: so I think One of, one of the challenges is, that we had with Copilot, right, is that we came out the gate with code completion, and it was super great, powerful, et cetera. And then what we initially worked on after that sort of, initial year and a half, was, going after fine-tuning because our customers, the industry on the whole was really talking about, okay, well, how do we get more more correctness or performance out of this? And so we were working on a whole bunch of efforts to do fine-tuning on, larger and larger code completions or, next edit suggestions with fine-tuning, et cetera.
Swyx [01:03:43]: And let me clarify. Is this fine-tuning one model or per customer a fine-tuned model for
Kyle [01:03:48]: Per cust— Well, both. But, but, fine-tuning one model for the overall, use, and then fine-tuning per customer that wants this as, a service effectively. And around that time is when the next generation of models came, and that’s around the same time that all these other AI, coding tools came to be because the models really sped up. And so everyone kind of, will ask, “Well, what happened to GitHub Copilot?” there’s all this time, and I would say that we were on an era of going okay, we want to improve everyone’s results, and so let’s focus in on fine-tuning because that’ll give us these better results. And then the models got better. And so then ever since, we’ve been really on this kind of journey to go, okay of course, we have, this great code completion, and we’ve done a ton of investment in the better underlying models that we have post-trained better, next set of suggestions with post-training language specific models. All this stuff that kind of, sits in the ether of GitHub Copilot is code completion, but also have now ha— now have, a single underlying, SDK and harness for our coding agent Copilot ultimately. The new CLI, the new desktop app, cloud agents that use the same SDK. And so there was this moment of both, really trying to figure out what our customers want, models, Sherlocking us a little bit, then going and saying, “Okay, what does everyone ultimately need?” And what we think is that it’s not solely about the code generation. It’s really about having the ability to use these coding agent brained, harnesses or run times across, not just the coding experience where I’m going to, send a bunch of tasks out, or I’m going to use Fleet to break up a single task or autopilot similar to Goal all this stuff. But also how do I do that for all of my security remediation? How do I do that for every GitHub issue that comes in, just stick a coding agent on it just to see if it’s possible? How do go through my repository and see all of my documentation and extract out okay, this doesn’t actually match? That amount of sort of AI coding agent automation, I think is a big part of what we see when we’re looking at, okay, we’re still kind of going through a similar but very different flow. It’s just all happening at the same time. There’s not really the same, I’m going to create an issue to track my idea of building this. You’re probably just going to go, do it.
Swyx [01:06:22]: Just do it.
Kyle [01:06:22]: You’re going to say, “Hey, just build this,” right? And, there are still tons of, open issues and projects, et cetera, that are using issues like Peter and OpenClaw to be able to sic all of his agent on that. That kind of infrastructure layer and a really great coding experience that allows you to handle the sort of multiplexing, aspect is what we’ve built, are still building with GitHub Copilot. And so for folks that haven’t really used GitHub Copilot sinceThe thing that got them excited about this Which I I get. I really encourage you to, look at especially the GitHub, Copilot app. That’s my new daily driver. I obviously, if you prefer the CLI, also the CLI, be able to use all the models, the bring your own key side of it. We’re still improving our own models and using those too. And, it’s just like a very different experience, but I think that broader sense is of like software development and how coding agents can help throughout, not just Writing the code, or even verifying it or deploying it is is where we have this unique, angle. The other side is the context piece. Like
Copilot’s Future: Context, Taste, and Personal Developer Workflows
Swyx [01:07:44]: Oh, God
Kyle [01:07:44]: we’re still It’s like one of those things where I think the the final thing that will let me ultimately, feel complete at GitHub is, when we have this ability for GitHub to act like Kyle wants it to act Or Shawn or whatever. And we all codify that in rules and in memory and everything else, but
Swyx [01:08:03]: Well, that’s an open research problem, right? Like it’s
Kyle [01:08:05]: A hundred percent. A hundred percent
Swyx [01:08:07]: AGI when you get it. Yeah.
Kyle [01:08:07]: A hundred percent. But, if we can even just do it where my team, Without me having to codify everything, and as our methods shift on purpose to be able to have that full experience and all the understanding of what’s happening in my dependencies or open source, that feels like a big place for us to be able to continue to provide something really unique and valuable with GitHub Copilot.
Swyx [01:08:29]: Is there a form factor that we haven’t explored? I think like we did code completion Then we did kind of let’s broadly call it agentic IDE Which Cursor Famously popularized, and then now it’s, now it’s all about the sort of agent orchestration Background agent, whatever. And then there’s the security review. I feel like everyone’s like just throwing agents at everything. The entire SDLC has Just, covered with agents. Are we like at the end of history here, basically? Like is it just refinements from here on out?
Kyle [01:09:04]: I think that we’re all still in such this hypermyopic era of AI Where the reality is that for various, boring security and governance reasons at least for most people’s work, why is my coding agent, even if it’s all background agents, background running not, losing all the context that’s available to it across everything that I’m doing outside of coding? I think the most interesting thing to me in AI is actual ambient AI, not insert assistant name thing or, I’ve tried just about every pin in tool and whatever, and they don’t work the way that I’m looking for them to work because they are just trying to capture, and then they are trying to codify and then recall. And I think the thing that I’m looking for, back to the very beginning, I’m looking to be building out the next version of webhooks or, implementing a new feature, and it for it to know every spec doc, every email, the conversations that I’ve had online, everything about how this could be implemented and be able to, use that as part of its decision-making and none of these tools are ultimately doing this. So I think that it’s as if, software development work was a single lane task, was like it only needs a developer. Once I once I write the perfect code, we’ll be done here, but that’s just never been true. It’s all the context of the other team members, what the business is doing what’s popular right now, and I think that’s this huge opportunity for us to go much broader than really excellent coding agents? And that is honestly why I think OpenClaw has been so interesting is that sure, it’s connecting to all the data, sources that Kyle the human cares about, and now my question’s “Okay, how can I take all that and use that every day as a software dev connected together, not just have a new way to kick off a coding agent?” And that’s where we’re at. We’re saying, “Okay, I’m going to go use this CLI under the hood or this SDK,” but that’s not what I’m talking about. I’m talking about I’m having a conversation with you it downloads the podcast, and it realizes, “Oh, Kyle, sounds like Kyle needs this app or this thing or this “ That level of
Swyx [01:11:16]: Just recommends it.
Kyle [01:11:16]: That level of, that level of connectivity I think is where we still have a ton of ways to go in software because then when we have that red thread we want to pull, that idea, it can not only use the perfect way to write that code, but instead all of the sort of taste and judgment calls and expertise that I’ve earned or that we’ve earned as a group and use it as part of the actual implementation.
Swyx [01:11:42]: The extreme of it is AI runs your life, right? And I think there’s a scary inversion of control in the way that I literally doing it in the way that developers mean it in terms of frameworks Like the Hollywood principle, “Don’t call me, I’ll call you.” Like there at some point there is an inversion of control where, you should you stop telling what the AI, the AI what to do. AI tells you what to do. And, that’s a little bit scary, but also, maybe better.
Kyle [01:12:10]: like Nat, I think Nat Friedman shared this in a like a Stripe event like talking about his OpenClaw was, he connected OpenClaw to his cameras, and it was, watching him.
Swyx [01:12:20]: It redirected his Uber. And it,
Kyle [01:12:23]: there’s a degree of this where I was I actually would love OpenClaw to tell me to Drink water. I don’t know that I want it to be, Changing where my car goes, but I do think that’s kind of what I’m talking about, which is it needs to have so much more information at its disposal for it to be helpful to me, and I still don’t think we’re, anywhere near talking about AGI. I’m just talking about every time I have to tell you something I care about that I’ve ever kind of said or I’ve said a dozen times, it should be able to know that codify that or gain access to it. Like the dreaming ideas, are an attempt to kind of do some version of this but I think there’s a much more proactive angle that will help software devs if we can test that out a bit more.
OpenClaw, Ambient AI, and Inverting Control
Swyx [01:13:05]: Yeah. Well, the other thing about OpenClaw that reminded me Is Microsoft has a CVP Dedicated to OpenClaw. Why?
Kyle [01:13:16]: Because you don’t think they should?
Swyx [01:13:17]: I don’t, I don’t know. I think CVP is a high title. What, why is this so important? Like Microsoft Doesn’t even own OpenClaw. What’s, what’s the
Kyle [01:13:29]: so I— we’re talking a lot more about this at, Microsoft Build this year too. I think, the main thing is that what OpenClaw has done is it has made this connection for people to have access to the resources that you have access to and be able to do things for you in a way that previously people were trying to codify into their own agents. And so when you think about it like in the work context, wouldn’t it be great to have a Claw-like object that I could actually run on my work device that or had access to my work assets, made— worked well on Windows what that would look like. And so I think that OpenClaw has become the personification of, a valuable agent that understands me because it has access to all of my information, and it can use a computer. And so thus it can do a lot more than, just a task-oriented process or like a a chat tool, et cetera. And that’s like a bunch of the goal of Build, right? We’re at Build this year trying to take a very different approach of it’s unapologetically aimed at developers. We’re trying to show the bigger investment to not just say, “Hey,” like you said, “Why do you have a CVP of OpenClaw?” Well, because, one of the problems that we have, right, is that our agents, if you install them not on a Mac Mini or not on a hosted device, you install them on a personal device or a work device, we need better sandboxing at the OS level. I need to be able to use that Claw and not, get fired. And so Microsoft is “Okay, great, let’s, do that too.” And then it’s, okay, well, where should I be able to talk to this agent? Should each of us just have a Claw available to us at work? Probably. And so there you go. And continuing to contribute a ton to the open source project too. Microsoft, I think as I’ve gotten more and more, information there’s so much investment into the open source, projects themselves that for whatever reason just I think there’s like this they don’t want to come off those teams don’t want to come off as like taking any credit or getting any recognition. But so many of these core contributors or teams are full-time just pushing into open source projects. And, I think that’s, that kind of shows the difference between, well, why are we looking so hard at something like Claw? Why are we looking at sandboxing on Windows? Why are we looking at cloud versions of sandboxing? Why are we looking— Because ultimately, we need more platform components. We don’t need everyone to be building the same exact, top-line product. And so if we’re building for builders, that requires us to give you all these components and tell you what they are and how they work and why you should be interested versus only delivering that single vertical over and over and over again.
Microsoft, Windows Sandboxing, and Platform Components for Agents
Swyx [01:16:23]: I think, my maybe one way of framing it Is that Microsoft is the original operating systems company. And here is the new operating system for AI.
Kyle [01:16:35]: like I think that we are also in an era where we are— we need to help build that bridge? All joking aside operating systems need to look different than they looked five years ago because it’s not just you using them anymore. And that’s changed the whole idea. It’s not, “Okay, my Claw is going to create a user account.” Doesn’t work like that? And so just just like all of us, we all have to look much more deeply in the stack, all the way down to, the silicon layer in Azure to be “Okay, well, What do we need now?” ‘Cause the workloads are different. It’s not just, “Okay, we need more inference.” It’s, “Okay, well, what type of inference do we need? What type of compute do we need to run these agents or run these agentic flows?” it’s a really interesting kind of like multi-layer problem, versus kind of, I would say software in the last five or six years were all going to our events, and we’re kind of saying a version of the same thing. SaaS product has new SaaS thing. It’s the best SaaS thing ever.
Swyx [01:17:42]: It was boring for a while.
Kyle [01:17:43]: And so now it’s like Oh my goodness, we’re at physics.
Swyx [01:17:47]: It’s great.
Kyle [01:17:48]: We’re at physics problems. And that’s exciting.
Swyx [01:17:50]: We’re— we’re now trying to make, semicondu- room temperature superconductors. Still. That’s, that’s, that’s never going away. No, I think, that’s a really good overview of, everything. I think, have I have we left anything unsaid that you wanted to really get out there that we should cover?
Build Announcements, Enterprise Adoption, and AI at Work
Kyle [01:18:07]: I’m really excited by for folks checking out, checking out the announcements that we have at Build go you can go look at them online, take a look. I think that I’m hoping that it’s driving, a degree of curiosity and interest because there’s such this big shift that we’re making at Microsoft for developers, where if you’re a daily driver of a Mac device or a Linux device, and you’re “Okay, I don’t use Windows,” there’s improvements that are being made that I think are going to surprise folks to just be “Oh, that’s in— they really want to do that?” not, And I’m talking for developers. I’m not talking for I play video games on the weekends on my Windows computer. I’m talking my daily driver. Like-All the way from that to, okay, well, what is it like to build an agent or build an app and deploy it and run it at work in particular? I think that is a big piece of it where I talk all the time with the team how I build on the weekend should be how I build at work. But if you’re working at a Fortune one hundred or a Fortune five hundred, you’re probably not vibe coding an app and then shipping it to some service. You got to go through security and compliance. How can we move just as fast at work? And that’s, I think, something that we have a bunch of different offerings for to give you that same sort of agility and power, but in the work context. And then I will tell you I’ve mentioned it a couple times, and, it’s very freaking cool. If you are in the M365 land in any way, check out WorkIQ, check out FoundryIQ. These little, oversimplifying it context engines are wild good. And, we’ve given them to our developers at GitHub, we’ve given them to employees at GitHub as we’ve used these tools to be able to just ask questions around everything that you have in your work context. And with FoundryIQ, be able to just do the same exact thing across all your existing stores. What— Not move to new tools, just connect them in. It’s surprisingly powerful, and you your boss is still not going to get fired, and IT is not going to turn it off because it’s leaking all this private information. That is the trick that I think, is sometimes getting lost when we’re talking about all these all these great new platforms. ‘Cause I can use them, I’m “Oh, this is super powerful. Oh, and I can’t I can’t use it.” and it’s Not because I’m at work at GitHub. It’s be
Swyx [01:20:34]: ‘Cause I’m not allowed, yeah
Kyle [01:20:35]: It’s ‘cause I’m not allowed, because they can’t do all the things that large, complicated companies need. And so, whether it be I said, just the kind of interesting daily driver curiosity all the way through to, “Oh, my gosh,” “I can go use this at work tomorrow potentially,” and have that context layer, have that intelligence, it’s a huge, it’s a huge shift. And so check it out. I’d love to hear— I’m, I’m not shy on social. I’d love to hear feedback. What’s working what’s not. But hopefully surprise folks a little bit.
Swyx [01:21:07]: What I’m hearing— so first of all, I think that’s, that’s a great pitch. What I’m hearing, actually, is that you should put the WorkIQ people next to the Copilot people. ‘Cause, the exact prob- context problem that you named They solve enough for you to do your job, which is nuts.
Kyle [01:21:23]: So, the thing that we are lit— that’s literally what has been Happening the last several months.
Swyx [01:21:29]: I already forecast you were going there.
Kyle [01:21:30]: It’s totally ‘cause, you’re totally right. The code, the code and the code asset problem is a little bit unique. But otherwise
Swyx [01:21:36]: That’s it
Kyle [01:21:37]: We’re all working
Swyx [01:21:37]: It’s context
Kyle [01:21:37]: With each other now. It’s all just context, exactly.
Swyx [01:21:40]: Amazing. Great. I’m going to be there. I’m going to be doing
Kyle [01:21:43]: Great
Swyx [01:21:43]: A couple sessions there. I’m going to be interviewing Satya.
Kyle [01:21:46]: I know.
WorkIQ, Copilot Context, and What to Ask Satya
Swyx [01:21:47]: When I first started the pod, though, I had, Jeff Dean on. Jeff like It’s like hall of fame of People I want to meet someday. Satya’s on there. So, what should I ask Satya?
Kyle [01:21:57]: I think, I think that the best question to ask is what he thinks is true in, two or three years from now. It seems like such a throwaway question. But ultimately, the way that the way that he is looking at this AI problem in, inference problem, token problem, and what we’re how we’re actually going to be working I think you can see some of the recent shifts that have been happening inside of Microsoft to kind of drive us to a place where it’s not four, five, six, seven, eight different things. It’s not a lack of context everywhere. But, why is this sort of approach in two years going to, pay off? Because that I think
Swyx [01:22:41]: Wow, that’s a bold Okay. I’ll ask it. I’ll say you I’ll say I prompted by you but
Kyle [01:22:45]: Absolutely
Swyx [01:22:45]: It’s a bold question because there, I think there’s a lot of, doubts to be honest, Externally. And so, yes, I want, a straight answer from him on that I think would reassure a lot of people, and honestly, give me a lot of food for writing. So, thank you so much for spending your time. Thank you for doing what you do. I think as a CEO, you don’t need to be the external face. But, because you are authoritative, ‘cause you have so much background with GitHub, and it’s so authentic, we on the outside feel it. So thank you for that.
Kyle [01:23:16]: Of course. Appreciate it. Thank you so much, Sean.
This is a public episode. If you'd like to discuss this with other subscribers or get access to bonus episodes, visit www.latent.space/subscribe




