Cursor began rolling out Origin, its own code-hosting beta, to paid users on August 17. That day, GitHub reported an incident lasting 7 hours and 47 minutes, from 13:28 to 21:15 UTC. At peak, web and API errors reached roughly 20%, and archive/raw-content downloads roughly 50%; authentication and Copilot were affected too. Many services recovered before the incident was fully closed. The launch and outage coincided, but their timing does not establish a causal connection.
That coincidence is worth taking seriously on its own terms. Building on the SpaceX agreement to acquire Cursor, which Cursor says later completed, Origin extends an AI editor into code hosting. Whether SpaceXAI intends to own that entire substrate is my interpretation, not an announced post-acquisition plan.
What Origin Actually Ships#
Origin lives in a new Codebase tab inside the Cursor editor. Teams name a codebase — which becomes part of its URL — then push to it over the command line. From there it’s the machinery you’d expect from a forge: a service layer wrapping Git that handles storage, permissions, checks, and merges. Every repository ships with pull requests — timelines, commits, checks, files changed — reviewable without opening a browser tab.
The more interesting design choice is what runs alongside that machinery. Agents operate in the same surface as the code and pull requests they’re modifying. A developer can ask questions about the file on screen, hand an agent a review comment and have it revise the PR in place, or tell it to push a branch — all inside the editor where the code was written.
Three integrations shipped on day one, and the choices are telling. Vercel spins up a preview deployment for every pull request and ships to production on merge. Depot and Buildkite run continuous integration — critically, both execute existing GitHub Actions workflows unchanged. That compatibility layer is the whole strategy in miniature: Cursor isn’t asking teams to rewrite their build system or rip out their deployment pipeline. It’s asking them to try a second window onto code they already have.
The Smartest Design Choice: GitHub Stays the Source of Truth#
For repos a user explicitly selects to sync, Origin doesn’t ask you to leave GitHub. Connect an organization and choose repositories; Cursor says synced repos preserve GitHub’s read/write access, GitHub remains their source of truth, pushes go there, and PR comments sync in both directions. Origin-native repos are different: Origin itself is their host and source of truth.
This is a wedge, and a well-executed one. Rip-and-replace migration of source control is one of the highest-risk projects an engineering organization can undertake — it touches CI, compliance evidence, audit trails, branch protection, and every integration in the toolchain. Almost no CTO approves that for an early beta product. A selected mirror that leaves GitHub authoritative makes a limited pilot easier, but it still copies code to another host and needs an access and retention review. The technical option to disconnect a repo does not by itself answer what happens to a former mirror. If the review experience proves better, the source of truth eventually follows the attention.
Cursor’s earlier Graphite acquisition brought stacked-review experience into the editor. Origin is a different bet on the review problem discussed in GitHub’s stacked-pull-request preview: how to handle growing PR volume without losing context. Cursor’s answer is to own the platform outright.
Agents Are Changing the Pull Request Queue#
The case for an agent-native forge rests on a claim that’s unusually well supported by evidence: writing code stopped being the constraint, and reviewing and integrating it became one.
Google’s 2025 DORA report says 90% of surveyed technology professionals use AI at work; its analysis links adoption to improved throughput but a negative relationship with delivery stability. That is a correlation, not proof AI causes breakages. Stack Overflow’s 2025 survey reported falling trust in AI accuracy, while GitLab’s survey found 73% of its respondents encountered problems with vibe-coded output.
The volume climbs regardless. GitHub’s Octoverse 2025 counted 43.2 million pull requests merged per month on average, up 23% year over year in its measurement period. Cursor reported that more than 40% of PRs in its own monorepo came from cloud agents; that is an internal vendor figure, not an industry-wide share. A forge built for humans assumes a pull request represents human intent — someone you can ask what they meant. As agent-generated changes increase, the review queue can become a scheduling problem, which is exactly the shift this site has been tracking as autonomous coding agents move from novelty into daily production workflows.
GitHub Earned This Opening#
The supply-side case for an alternative is simpler: GitHub has been unreliable, and its own executives have said so. GitHub acknowledged in March 2026 that it had not met its own availability standards. Its April availability report documented ten incidents causing degraded service that month. After the August 17 outage, GitHub described capacity and retry failures and the work planned to improve reliability. Those first-party reports make the case for reducing single-host dependence without inventing a precise annual outage count. walgit’s S3-native Git server is a different response to that dependence: it experiments with the repository storage layer, not the forge or review experience Origin is selling.
Who Actually Holds Your Code Now#
Here’s the part that deserves a security review rather than a news cycle. Cursor says Origin is rolling out to paid users except enterprise organizations whose admins opt out. That is a default for access to the beta, not for mirroring repositories: users connect GitHub and select what to sync. Platform teams should still check who can enable Origin and which repositories have actually been copied.
Cursor’s privacy policy discusses retention, training choices, and subprocessors for the service, and its Origin documentation describes repository selection and Privacy Mode. Those general terms do not by themselves settle every Origin-specific question about repository retention, residency, or deletion after disconnect. Cursor announced the completed SpaceX acquisition before Origin’s launch; the $60 billion figure in the earlier merger filing was an implied equity valuation, not cash paid. For Origin-native repositories and mirrors users choose to create, the same company can supply both editor and host—and potentially a model used by agents. That concentration raises a governance question without implying that every Cursor repository has been mirrored. That’s a materially different governance question than the one raised by the AI-native editor wars between Cursor and Copilot a year ago, when the stakes were autocomplete quality rather than custody of the repository itself.
There’s also a track record worth weighing before granting Origin repository access. Mindgard reported in July that opening an untrusted Windows project with a planted git.exe could trigger execution without a prompt; it said it first reported the issue in December 2025. Mindgard disputed Cursor’s reliance on Workspace Trust as a sufficient mitigation. The broader lesson is to treat untrusted repositories as executable inputs; the reported flaw is relevant when evaluating an editor integrated with a code host.
What to Settle Before Origin Touches Your Toolchain#
Origin is a beta, not a migration, and evaluated as one it’s a reasonable experiment. Its sync mode gives platform teams a low-risk way to measure whether an agent-native review surface shortens cycle time without touching a single branch protection rule. Three things deserve resolution before anything more authoritative moves:
- The default. Confirm who may enable Origin and explicitly sync repositories. Beta availability is not automatic mirroring.
- The paperwork. Review Cursor’s published privacy and subprocessor terms, then seek Origin-specific answers about repository retention, residency, deletion and access before copying sensitive code.
- The exit. Origin’s GitHub-as-source-of-truth design is precisely what makes it safe to adopt today. It’s also the property most likely to erode as Cursor’s incentives shift toward owning the substrate rather than borrowing it. Ask what egress looks like now, while the mirror is still just a mirror.
My Take#
GitHub’s failure and Cursor’s opportunity are different in kind, and it’s worth not confusing them. Monday’s incident lasted 7 hours and 47 minutes, though most services recovered earlier — availability is an engineering problem, and engineering problems close, even if GitHub has been closing them badly and often lately. The question of who holds your source code, what they may do with it, and who they ultimately answer to carries no such timestamp.
I don’t think Origin’s technical bet is wrong. Once a substantial share of your own pull requests come from agents running unattended in cloud VMs, a review surface designed around the assumption that every PR author is a human you can ask a clarifying question to is already the wrong tool. Cursor bought the right company in Graphite, shipped day-one CI and deployment integrations instead of a bare git host, and chose a sync mode — GitHub stays authoritative for selected mirrors — that may let a CTO say yes to a limited pilot without a six-month security review.
What I can’t get past is the sequencing. A company that spent Monday selling trust launched a new place to host enterprise source code shortly after the acquisition completed, with enrollment open to most paid users but repository selection still required. Its published service terms warrant an Origin-specific security review before a team moves sensitive repositories. Availability problems earn you a status page apology. Custody problems earn you a subpoena. Cursor has built a genuinely good wedge product. Whether its Origin-specific retention and exit answers are sufficient for your repositories is a question each team should settle before syncing them.




