Skip to content
Z Zendikt
Vendor trust scorecard

GitHub vendor trust score

Trust scoring is the “is this vendor a fair counterparty” question, deliberately separated from product quality. Six dimensions, dated, sourced where events warrant it.

8.3
/10
strong
Verdict

GitHub carries a strong vendor trust profile across the six dimensions we score. Few material concerns at renewal or procurement.

Vendor Trust Score

Is GitHub a trustworthy vendor?

8.3/10
High trust
Pricing transparency
Published rates; no hidden fees
8.5
Contract fairness
Reasonable terms; no auto-renew traps
8.0
Incident response
How they handle outages and breaches
8.0
Post-acquisition behavior
Customer treatment after M&A or PE
8.5
Executive stability
Leadership churn over 24 months
9.0
Roadmap honesty
Public commitments held
8.0
Trust signal log
  • 2018-06-04
    Microsoft acquires GitHub for $7.5B
    Initially controversial in OSS communities; outcomes broadly viewed as positive by 2024 with sustained investment and product expansion.
  • 2022-11-03
    GitHub Copilot Lawsuit filed (DOE plaintiffs)
    Class action alleging Copilot reproduces licensed code without attribution. Ongoing through 2025-2026; raises IP indemnity questions for enterprise buyers.
  • 2024-04-22
    Codespaces pricing changes blindsided buyers
    Compute and storage billing changes in 2024 surprised teams with large Codespaces footprints; multiple Reddit and HN threads.
  • 2024-10-15
    Copilot Workspace and Agent Mode launched
    Agentic features GA; closes the gap with Cursor and Claude Code on multi-step task completion.
Vendor Trust is scored independently of product quality. A great product from an unfair vendor still earns a low trust score.

How to read this score

  • Trust is separate from product quality. A vendor can ship great software and treat customers badly — or vice versa. We score the two independently.
  • 8.0+/10: strong. Few concerns at renewal or procurement.
  • 6.5–7.9: mixed. Negotiate hard on the lowest dimensions; monitor across the contract term.
  • 5.0–6.4: cautious. Add explicit mitigation language to the master agreement.
  • Below 5.0: concerning. Treat this as a contracted-risk evaluation, not a product-fit evaluation.
  • Updates: we re-verify scoring quarterly. Material trust events (acquisitions, breaches, leadership change, hostile contract terms) get logged on the timeline above.

Related editorial

Last updated 2026-05-10. Scoring methodology: editorial standards. Disagree? Tell us.