GitHub Actions went degraded Thursday afternoon, and the runners you rented somewhere else went down with it. Webhook delivery stopped, so the Blacksmith and Ubicloud boxes teams pay for never picked up a job. Self hosted runners got errors and rate limiting just trying to register.
That puts the failure inside GitHub’s own dispatcher, the one layer no runner vendor can sell you around. Its status page logged 6 incidents in the first 6 days of August, after 26 across all of July.
In today’s indie hacker news:
- 🚨 Paid CI runners sat idle with GitHub down
- 🧊 AMD buys Taalas, 24 people, $30M spent
- 🎥 Local screen recorder lands on 18.5k stars of free
- 🎨 Reddit called his subway map palette vibe coded
- ⚠️ A visible exfil payload got approved 64.7% of the time
- ♟️ Chess Duolingo at $56 MRR and one pricing bug
TOP STORIES
THE RUNNERS THAT WOULD NOT RUN
🚨 GitHub’s outage dragged the runners you pay someone else for down with it

The story: GitHub flagged Actions as degraded at 15:22 UTC, then downgraded it to degraded availability twenty minutes later. Workflow runs failed to start or died partway through. The Actions REST API returned errors, and Pages joined the incident soon after. A CI problem turned into a static hosting problem.
The Register reported that GitHub referenced a cause it never named publicly, and did not answer questions. The Hacker News thread took 352 points and 289 comments. That’s a lot of noise for a status page link. Teams on Blacksmith said they were hard down all day regardless.
“GitHub is not sending out Webhooks and is also not able to queue external jobs.” (tom1337, running Ubicloud runners)
The details:
- Self hosting didn’t help either. GitHub’s own status text warned that runners may see errors or rate limiting when they register.
- Pages kept serving, but could not rebuild. One user waited three hours for an Action to publish a one line broken link fix.
- The status page argued with itself. Pages read as operating normally at 16:19 UTC and degraded at 16:27 UTC.
- The incident count depends on who is counting. GitHub’s June availability report lands on six. The Register counts 23 on the status page for that same month.
- Someone rebuilt CI faster than GitHub fixed it. One commenter had AI agents build a working CI/CD system and ran deploys through it before the incident closed.
Why builders care: Stop asking which runner vendor to buy. Ask how much of your deploy path can fire with GitHub unreachable, then go write that script.
SILICON LLAMA, NO TAKEBACKS
🧊 AMD is buying the startup that burns model weights into the chip

The story: AMD reached a definitive agreement Thursday to buy Taalas, a Toronto startup founded in 2023. Taalas holds model weights in mask ROM on the die instead of streaming them from HBM. AMD disclosed no price and no close date, and the deal needs regulatory approval. The Register says it understands this is a real acquisition rather than an acquihire.
Taalas shipped that first chip with 24 people and $30M spent, out of more than $200M raised. AMD bought it about six months after the HC1 went public.
The details:
- Nobody outside Taalas has benchmarked it. The 17k tokens per second per user figure was run by Taalas labs, on Llama 3.1 8B.
- One die, one model. 815mm2 on TSMC 6nm, 53B transistors, and the weights are physically part of it.
- Changing the model means changing the chip. Anything bigger than a LoRA adapter needs a re-spin, though Taalas says only two metal layers change.
- AMD never says etch. Its press release describes the technology as optimizing inference dataflows. The etching framing comes from Taalas and from the press.
- HC2 aims bigger. The Register reports 20 billion parameters per chip, so roughly 50 accelerators would carry a trillion parameter model.
Why builders care: Token prices are about to split into two tiers instead of falling evenly for everyone. The cheap, instant endpoint will be a quantized model that’s months old, so keep model choice as swappable config.
Freezing a model in silicon isn’t the only way to lock one down today. Drama has the software version.
LOCAL ONLY, ALREADY TAKEN
🎥 A private browser screen recorder launched into 18.5k stars of free competition

The story: u/masterzeng posted Screenio to r/SideProject: screen, mic and webcam, all processed on your device, nothing uploaded. That answers the loudest demand this category has produced. The 462 point Show HN for screenrecorder.me turned into a pile-on for self hosting and a privacy policy. That tool stored recordings on S3.
Screenity already gives the same promise away free under GPL-3.0, with 18.5k GitHub stars and an offline mode. Its solo maintainer earns from a hosted Pro tier, not from the local recorder.
The details:
- The first comment was already a bug report. A tester liked the local processing and flagged audio sync drift on the webcam overlay.
- Memory is the wall, not features. Screen Recorder Studio watched MediaRecorder push a tab past 3 GB of RAM at 4K. Chrome killed the recording.
- Year six looks like plumbing. Screenity’s late July commit was encoder queue headroom and frozen static screen captures, shipped as 4.6.4 that day.
- The browser matrix bites on day one. screenrecorder.me’s capture dialog closed instantly on Firefox and Safari. Its builder trained a YOLO model just to find the cursor.
Why builders care: Local only is the right pitch and a terrible moat, because the free incumbent shipped it years ago. The product is the encode and persist pipeline, long session stability, and the browser matrix.
HAND PICKED, STILL CALLED VIBE CODED
🎨 He picked the palette from subway lines and the first comment called it vibe coded

The story: u/Piinoy launched Festy on r/SideProject, a festival companion that turns a flat lineup poster into a plannable schedule. He wrote that he spent most of the build on the UI. The first substantive comment went straight at it.
“I think you could make a really cool color system for this that fits your genre. Get away from the vibe coded colors.” (u/gucciman333)
He replied that the colors were hand picked, with inspiration from NY subway line colors. His fix, pre-set themes plus a HEX picker, got turned down too. The commenter told him to make his own design choices and stick to them, because those define the brand.
The details:
- Two rating states against three. Festy has interested and must-see. FestivPlanner runs Must See, Want and Maybe.
- The two features that matter on the day are missing. FestivPlanner flags every overlap and pushes to Google Calendar. Festy exports one image.
- The logging half is already an iOS app. Jukeboxd names 12 festivals on its homepage, from EDC Las Vegas to Ultra Miami.
- The roadmap points at the crowded lane. Artist pages, social features and maps, plus the mobile app both rivals already have or promise.
Why builders care: When every primitive in a niche is built, the seam between two products is the thing left to own. And say your design decisions out loud, because reviewers now assume a model picked the colors.
NPM RUN EXFILTRATE
⚠️ Players approved the exfil command that was printed on screen above the button

The story: Alex Wauters published the numbers from his browser game. You play the human in the loop for a coding agent. Over 40,000 runs and 409,000 approve or deny decisions later, mean accuracy sits at 66.3 percent.
The single most missed command out of 37 threats was npm run analyze, approved 64.7 percent of the time. The payload wasn’t hidden. The agent history log directly above the button printed the script. It piped the bundle report into a curl POST to an unknown API.
The Hacker News thread took 267 points and 196 comments, much of it arguing the labels aren’t self consistent. Wauters says the miss rate held when he compared later runs against the first ones.
The details:
- The loud stuff gets caught. rm -rf / class commands were missed 11.7 percent of the time, against 35.0 percent for cat ~/.aws/credentials.
- A familiar name is the attack. The three npm run threats were missed 52.5 percent of the time, roughly double every other exfiltration attack.
- Vigilance costs too. 59 percent of players blocked npm config set registry, a harmless internal mirror change.
- 7 percent approved every prompt they saw. Another 32.9 percent finished the run with a negative score.
- Real stakes look worse. Northeastern ran 100+ developers through a five hour task with a sabotaging agent, and 94 percent missed it.
Why builders care: The prompt gates execution, not file edits, so an agent can rewrite package.json without asking once. Run it in a sandbox and move your keys out of ~/.zshrc.
If you’d rather review the plan than the prompt, today’s Stack of the Day does exactly that.
Ship voice in your product without sounding like a robot. ElevenLabs' API turns text into voice that actually sounds human, priced per character so your dev playground costs cents. 30+ languages, streaming, low-latency. Same vendor slot as Polly or Google TTS, but the voices don't tip your users off.
We get a cut if you sign up. Only added for tools we use ourselves.
TRENDING TODAY
- 🥩 Almost no skill required to cook a steak - 294 points and 344 comments. More replies than upvotes means everyone has a method and wants you to hear it.
- 🕹️ Quake, 30th Anniversary Update - 238 points and 117 comments. Bethesda is still patching a thirty year old shooter, which is the long tail most products never get.
- ⚖️ Meta ordered to pay $942M over harm to kids - 107 points, posted overnight. If any part of your product touches teenagers, that number is the new anchor.
FIRST DOLLAR
SEVEN PAYING USERS AND A PRICING BUG
♟️ A chess Duolingo hit $56 MRR, then doubled its own price by accident
u/rodrigoibarra shipped a chess learning app in June and posted the receipts. 428 users in 28 days, and 7 of them pay. That’s $56 MRR against about $300 spent on ads. Then he changed the annual price server side, and it applied to every app version at once. He doubled his own price without noticing.
DRAMA
OPEN WEIGHTS WITH A LOCK ON THEM
🔒 Apple researchers want open weights you can ship but cannot fine-tune
Apple’s machine learning group published a method for locking pretrained weights, using deep low-rank residual distillation. Sharing weights is what makes a model portable and testable across platforms. Apple’s argument is that concerns about unauthorized modification can outweigh that.
Why builders care: If locked weights land in real releases, “open weight” stops being one thing and starts needing a license read. Worth a bookmark if any part of your product is a fine-tune.
STACK OF THE DAY
A SECOND OPINION ON THE PLAN
An independent review pass for Claude Code plans, posted to Show HN overnight. The idea is small and obvious in hindsight. Review the plan with something other than the model that wrote it. The repo is public on GitHub, and the thread is sitting at one point with no comments yet. That’s usually where the useful ones start.
Not sponsored. We just feature tools builders would actually use.
BOOKMARKED TODAY
- ⌨️ A mechanical Magic Keyboard, two years in the making - 260 points and 219 comments. Two years on a keyboard, and Show HN showed up for it.
- 🍄 Mario Meets Pareto - 925 points against 151 comments, the biggest score in the whole set by a wide margin.
- 🎯 Taste Is All That’s Left - 253 points and 200 comments. Pair it with the vibe coded colors up top.
That’s the edition. Hit reply and tell us what you shipped today.
Work from any WiFi like it's your home network. NordVPN's Meshnet runs a free private mesh between your laptop, dev box, and home server. SSH from a cafe without exposing a port, the way you'd use Tailscale. The paid VPN on top lets you test geo-fenced Stripe checkouts or feature flags from any country.
We get a cut if you sign up. Only added for tools we use ourselves.
Curated by AI, built by a human.