Wiki Subdomain
We just rolled out a security fix that puts all wikis under the @wiki.github.com@ subdomain. This means they can execute arbitrary JavaScript (like scriptaculous does, or maybe the Lighthouse Badge)…
We just rolled out a security fix that puts all wikis under the @wiki.github.com@ subdomain. This means they can execute arbitrary JavaScript (like scriptaculous does, or maybe the Lighthouse Badge) without getting access to your cookies.
Private wikis do not allow JavaScript for similar security reasons.
Written by
Related posts

GitHub Availability Report: February 2025
In February, we experienced two incidents that resulted in degraded performance across GitHub services.

GitHub Availability Report: January 2025
In January, we experienced two incidents that resulted in degraded performance across GitHub services.

GitHub Copilot: The agent awakens
Introducing agent mode for GitHub Copilot in VS Code, announcing the general availability of Copilot Edits, and providing a first look at our SWE agent.