{"company":{"name":"GitHub","slug":"github","website":"https://github.com","category":"developer-tools"},"question":"What has GitHub shipped recently?","answer":"In the last 30 days, GitHub shipped 187 tracked updates. The most recent was \"GitHub Investigating Incident Affecting Git Operations Issues Actions and Pull Requests\" on 2026-10-07.","window":{"days":30,"updateCount":187,"returned":50},"generatedAt":"2026-10-08T06:31:17.330Z","updates":[{"title":"GitHub Investigating Incident Affecting Git Operations Issues Actions and Pull Requests","summary":"GitHub experienced a service incident on October 7, 2026, impacting Git Operations, Issues, Actions, and Pull Requests. The issue was resolved within 47 minutes, with widespread impact from 16:52 UTC to 17:01 UTC. Durable mitigations were applied to prevent recurrence.","date":"2026-10-07","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://www.technobezz.com/news/github-service-incident-2c517a2e","publisher":"technobezz.com"},{"title":"Purpose-built model for leaked secret detection","summary":"GitHub introduced a purpose-built AI model for leaked secret detection, integrating context-aware checks into secret scanning alerts, push protection, and GitHub Copilot security reviews. Existing AI-detected alerts in GHSP and GHAS now use this model at no extra cost, while new opt-in checks for push protection and Copilot security reviews will consume AI Credits starting in coming weeks.","date":"2026-10-07","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://github.blog/changelog/2026-10-07-purpose-built-model-for-leaked-secret-detection","publisher":"github.blog"},{"title":"Local sandboxing for GitHub Copilot now generally available","summary":"GitHub Copilot now offers local sandboxing, a generally available feature enabling secure execution boundaries for agentic workflows on developers' machines. Tools and commands initiated by Copilot run with restricted access to system resources based on developer-defined policies, powered by Microsoft eXecution Container (MXC). The feature is included at no extra cost across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions.","date":"2026-10-07","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://github.blog/changelog/2026-10-07-local-sandboxing-for-github-copilot-now-generally-available","publisher":"github.blog"},{"title":"Discover local models in GitHub Copilot CLI","summary":"GitHub Copilot CLI v1.0.94-0 introduces /modelto discover and select local models from a running Ollama instance, alongside cloud models. Users must manually add and confirm models, which support tool calling and streaming. The update aligns with the GitHub Copilot app’s provider experience and introduces intelligent routing for local models.","date":"2026-10-07","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://github.blog/changelog/2026-10-07-discover-local-models-in-github-copilot-cli","publisher":"github.blog"},{"title":"GitHub Adds Claude Haiku 5.5 to Copilot for Quick Coding Tasks","summary":"GitHub made Anthropic’s Claude Haiku 5.5 generally available in GitHub Copilot, targeting fast, high-volume coding edits, terminal tasks, and subagent workflows. The model is accessible across Copilot Pro, Pro+, Max, Business, and Enterprise plans with usage-based billing. Early tests showed Haiku 5.5 performing comparably to Claude Sonnet 5 while using fewer tokens.","date":"2026-10-07","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://www.technobezz.com/news/github-adds-claude-haiku-copilot-coding-tasks","publisher":"technobezz.com"},{"title":"Thomas Dohmke launches entire, decentralized GitHub alternative for AI coding","summary":"Thomas Dohmke, former GitHub CEO, launched Entire, a decentralized platform addressing AI coding tool limitations by hosting code across regional hubs for speed and reduced bottlenecks. It integrates with AI assistants like Copilot and Codex and claims 25x faster clone performance in tests.","date":"2026-10-07","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://www.newsbytesapp.com/news/science/thomas-dohmke-launches-entire-decentralized-github-alternative-for-ai-coding/tldr","publisher":"newsbytesapp.com"},{"title":"The difference between Codex and GitHub Copilot: Which one should your company sign up for? The deciding factor was 'where you ask for work to be done'｜Codex Studio","summary":"A third-party analysis clarifies that GitHub Copilot operates within GitHub (via GitHub AI Credits) while OpenAI Codex is accessed via ChatGPT plans, with Codex also usable within GitHub via Copilot subscriptions. Pricing models and operational entry points differ significantly.","date":"2026-10-07","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://note.com/codex_studio/n/ne619c067f758?hl=en","publisher":"note.com"},{"title":"Local sandboxing for GitHub Copilot now generally available","summary":"GitHub announced general availability of local sandboxing for GitHub Copilot across CLI, the Copilot app, and VS Code sessions. The feature restricts Copilot-initiated tools and commands to a secure execution boundary, limiting access to filesystem, network, and credentials based on developer-defined policies. Powered by Microsoft eXecution Container (MXC), it ensures consistent sandboxing across Windows, macOS, and Linux.","date":"2026-10-07","dateIsEstimated":false,"signalType":"feature_update","signalTypeLabel":"Feature","sourceUrl":"https://github.blog/changelog/2026-10-07-local-sandboxing-for-github-copilot-now-generally-available/","publisher":"github.blog"},{"title":"Claude Haiku 5.5 in GitHub Copilot","summary":"GitHub Copilot now includes Anthropic’s Claude Haiku 5.5, a lightweight model optimized for fast, high-volume tasks like subagents and terminal edits. Early tests show it matches Sonnet 5 performance with fewer tokens, and it is available to all Copilot tiers via gradual rollout.","date":"2026-10-07","dateIsEstimated":false,"signalType":"feature_update","signalTypeLabel":"Feature","sourceUrl":"https://github.blog/changelog/2026-10-07-claude-haiku-5-5-in-github-copilot/","publisher":"github.blog"},{"title":"Discover local models in GitHub Copilot CLI","summary":"GitHub Copilot CLI version 1.0.94-0 introduces a /modelto command to discover and select local models from a running Ollama instance, alongside cloud models. Users must manually add and confirm models, which work in the current session without restarting. The update aligns with the GitHub Copilot app’s provider experience and introduces intelligent routing for local models.","date":"2026-10-07","dateIsEstimated":false,"signalType":"feature_update","signalTypeLabel":"Feature","sourceUrl":"https://github.blog/changelog/2026-10-07-discover-local-models-in-github-copilot-cli/","publisher":"github.blog"},{"title":"Purpose-built model for leaked secret detection","summary":"GitHub launched a purpose-built AI model for secret detection that analyzes surrounding code to identify leaked credentials, including non-standard formats. The model powers AI-detected secret alerts in GHSP and GHAS at no extra cost, while new opt-in checks for push protection and Copilot security reviews will consume GitHub AI Credits. AI alerts are also coming to GHES 3.23 in public preview.","date":"2026-10-07","dateIsEstimated":false,"signalType":"feature_update","signalTypeLabel":"Feature","sourceUrl":"https://github.blog/changelog/2026-10-07-purpose-built-model-for-leaked-secret-detection/","publisher":"github.blog"},{"title":"Secret protection must scale with software","summary":"GitHub reports that one in three pull requests now involves an AI agent, accelerating code creation and secret exposure risks. To address this, GitHub introduces a fine-tuned ModernBERT classifier that assesses candidate secrets in under two milliseconds, more than doubling the number of secrets prevented by push protection. The feature, currently in private preview, will launch later this month for GitHub Secret Protection across Enterprise Cloud and Teams.","date":"2026-10-07","dateIsEstimated":false,"signalType":"feature_update","signalTypeLabel":"Feature","sourceUrl":"https://github.blog/ai-and-ml/github-copilot/secret-protection-must-scale-with-software/","publisher":"github.blog"},{"title":"Update your IDE to restore agent activity in Copilot usage metrics","summary":"GitHub identified an issue where Copilot agent activity was misattributed in usage metrics due to IDEs moving agent sessions to the Copilot SDK without proper IDE identification. A fix is rolling out now, starting with Visual Studio Code, with other IDEs expected by November 2026. Updated IDE versions will restore accurate agent activity reporting in Copilot metrics dashboards and APIs.","date":"2026-10-06","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://github.blog/changelog/2026-10-06-update-your-ide-to-restore-agent-activity-in-copilot-usage-metrics","publisher":"github.blog"},{"title":"Stacked pull requests generally available","summary":"GitHub announced the general availability of stacked pull requests, allowing developers to break large changes into smaller, independent PRs for easier review and merging. Repositories using stacks saw a 9% increase in merged code and a 5% improvement in time-to-merge, with over two-thirds of top repos already adopting the feature.","date":"2026-10-06","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://github.blog/changelog/2026-10-06-stacked-pull-requests-generally-available","publisher":"github.blog"},{"title":"Over Half a Million Credentials Leaked on GitHub Remain Active","summary":"Truffle Security found 543,699 valid credentials in GitHub repositories, with some active for over 16 years. GitHub’s push protection reduced supported leaks by 53%, but 199,843 credentials were committed after its default rollout. Database credentials had the highest survival rate (88% for PostgreSQL), highlighting revocation challenges.","date":"2026-10-06","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://linuxiac.com/over-half-a-million-credentials-leaked-on-github-remain-active/","publisher":"linuxiac.com"},{"title":"Former GitHub CEO Thomas Dohmke brings entire to tackle outages","summary":"Thomas Dohmke, former GitHub CEO, unveiled Entire, a decentralized Git platform designed to mitigate GitHub outages by distributing code hosting globally. The preview launches July 8, 2026, with hubs handling 570,000 clones/hour and 586 pushes/second, featuring a semantic memory layer for bot-written code.","date":"2026-10-06","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://www.newsbytesapp.com/news/science/former-github-ceo-thomas-dohmke-brings-entire-to-tackle-outages/tldr","publisher":"newsbytesapp.com"},{"title":"Code scanning AI Scan enablement status in security overview","summary":"GitHub introduced a new feature in its security overview that shows AI Scan for pull requests enablement status. Organization and enterprise admins can now view enabled and not enabled repository counts, filter by status, and export this data in CSV. The update aims to help track adoption of AI-powered code scanning across repositories.","date":"2026-10-06","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://github.blog/changelog/2026-10-06-code-scanning-ai-scan-enablement-status-in-security-overview","publisher":"github.blog"},{"title":"GitHub’s ReviewBench puts AI code reviewers to the test","summary":"GitHub introduced ReviewBench, a benchmark for evaluating AI code review agents, available in research preview. It tests 219 pull requests across 19 languages, measuring precision, recall, and F1 scores for issue detection. GitHub used it to improve Copilot code review’s lite tier, showing 8% higher review comment impact and 13.6% better recall in production.","date":"2026-10-06","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://www.helpnetsecurity.com/2026/10/06/github-reviewbench-ai-code-review-benchmark/","publisher":"helpnetsecurity.com"},{"title":"GitHub Copilot weekly releases — September 28","summary":"GitHub introduced new Azure canvases in the Copilot app for resource queries, cost health checks, and Azure Functions skills, along with VS Code Copilot 1.140 updates. These features enable automated workflows and deeper Azure integration within Copilot's interactive workspaces.","date":"2026-10-06","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://github.blog/changelog/2026-10-02-github-copilot-weekly-releases-september-28/","publisher":"github.blog"},{"title":"Building Git infrastructure for agent-scale development","summary":"GitHub is overhauling its Git infrastructure to support agentic software development, driven by a 2x surge in total Git activity (218.2B to 473.3B events/month) and 7.38B commits in September 2026 alone. The new architecture decouples storage from compute, minimizes coordination, and targets 35x higher write throughput while preserving existing controls like branch protections and audit logs.","date":"2026-10-06","dateIsEstimated":false,"signalType":"technical","signalTypeLabel":"Technical","sourceUrl":"https://github.blog/engineering/architecture-optimization/building-git-infrastructure-for-agent-scale-development/","publisher":"github.blog"},{"title":"GitHub Investigating Disruption Affecting Some Services","summary":"GitHub experienced a service disruption on October 5, 2026, impacting access to organization and enterprise billing and licensing pages. The incident was resolved by 9:32 p.m. Eastern, with a root cause analysis to follow.","date":"2026-10-05","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://www.technobezz.com/news/github-service-incident-ea96c4f8","publisher":"technobezz.com"},{"title":"GitHub Releases 'ReviewBench': Thinking About AI Code Review Misses and False Positives Through 219 PRs","summary":"GitHub released ReviewBench, a research-preview tool to evaluate AI code review performance using 219 PRs from 187 repositories across 19 languages. It measures precision, recall, and F1 against a fixed ground truth while accounting for false positives and critical misses, enabling teams to tailor evaluation to their priorities.","date":"2026-10-05","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://note.com/shugo/n/n527b5ed7e5bc?hl=en","publisher":"note.com"},{"title":"Secret scanning adds detectors for Lovable, Supabase, and more","summary":"GitHub added secret scanning detectors for Lovable Labs, Pydantic Services Inc., and Supabase, enabling automatic detection of exposed credentials in repositories. Partner secrets are reported to issuers for revocation, while user secrets generate alerts in public or private repos.","date":"2026-10-05","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://github.blog/changelog/2026-10-05-secret-scanning-adds-detectors-for-lovable-supabase-and-more","publisher":"github.blog"},{"title":"ReviewBench: An open benchmark for AI code review","summary":"GitHub introduced ReviewBench, an open benchmark for evaluating AI code review agents, built using data from 103.9 million real GitHub pull requests. The benchmark includes 219 public pull requests across 19 languages, with structured findings labeled by severity and category, and four evaluation metrics to measure performance objectively.","date":"2026-10-05","dateIsEstimated":false,"signalType":"feature_update","signalTypeLabel":"Feature","sourceUrl":"https://github.blog/ai-and-ml/github-copilot/reviewbench-an-open-benchmark-for-ai-code-review/","publisher":"github.blog"},{"title":"Code scanning AI Scan enablement status in security overview","summary":"GitHub now shows AI Scan for pull requests enablement status in the security overview coverage view for organizations and enterprises. The feature provides counts of enabled/disabled repositories and per-repo status, with filtering and CSV export support to track adoption.","date":"2026-10-05","dateIsEstimated":false,"signalType":"feature_update","signalTypeLabel":"Feature","sourceUrl":"https://github.blog/changelog/2026-10-06-code-scanning-ai-scan-enablement-status-in-security-overview/","publisher":"github.blog"},{"title":"Talking on Slack turns directly into GitHub work?? Copilot connects 'Conversation → Issue → Implementation'","summary":"GitHub updated GitHub Copilot on September 25, 2026, to enable direct workflows from Slack conversations to GitHub issues and pull requests. Copilot now reads Slack context (files, attachments, links) to create, update, or investigate issues, and can generate pull requests while checking for duplicates. Conversations and GitHub work are linked for traceability.","date":"2026-10-03","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://note.com/airealworldbench/n/n2ee2c6f2e3c4?hl=en","publisher":"note.com"},{"title":"Stateless GitHub App installation tokens rolled out","summary":"GitHub finished rolling out stateless installation tokens for GitHub Apps, replacing the legacy format with a new 520-character token starting with 'ghs_'. The change improves API reliability and token issuance speed while maintaining the same permissions, expiration, and API endpoint. The temporary validation header will be deprecated on November 30, 2026.","date":"2026-10-02","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://github.blog/changelog/2026-10-02-stateless-github-app-installation-tokens-rolled-out","publisher":"github.blog"},{"title":"Copilot code review: API support and new default effort level","summary":"GitHub introduced API support for Copilot code review via REST and GraphQL, enabling automated reviews in custom workflows. The default review effort level is now Balanced for all plans, replacing the previous Default setting, with Lite still available as an override.","date":"2026-10-02","dateIsEstimated":false,"signalType":"feature_update","signalTypeLabel":"Feature","sourceUrl":"https://github.blog/changelog/2026-10-02-copilot-code-review-api-support-and-new-default-effort-level","publisher":"github.blog"},{"title":"Unvalidated npm trusted publishing configurations now expire","summary":"GitHub now enforces a 48-hour expiry on unvalidated npm trusted publishing configurations, requiring revalidation after ownership changes or failed publishes. Validated configurations are exempt, but expired ones must be recreated. GitHub Actions events like issue_comment are also blocked for publishing tokens.","date":"2026-10-02","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://github.blog/changelog/2026-10-02-unvalidated-npm-trusted-publishing-configurations-now-expire","publisher":"github.blog"},{"title":"npm staged publishing now supports creating new packages","summary":"GitHub’s npm now allows creating new packages directly via `npm stage publish`, supporting public scoped/unscoped and private scoped packages. The first version enters a staged queue requiring maintainer promotion before release. This enables automated workflows to generate packages without manual first publishes.","date":"2026-10-02","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://github.blog/changelog/2026-10-02-npm-staged-publishing-now-supports-creating-new-packages","publisher":"github.blog"},{"title":"Selected models in GitHub Copilot deprecated","summary":"GitHub deprecated specific models in all GitHub Copilot experiences on October 2, 2026, requiring users to switch to supported alternatives. Enterprise admins must enable access to new models via Copilot settings, with verification available in VS Code and github.com.","date":"2026-10-02","dateIsEstimated":false,"signalType":"product_sunset","signalTypeLabel":"Sunset","sourceUrl":"https://github.blog/changelog/2026-10-02-selected-models-in-github-copilot-deprecated","publisher":"github.blog"},{"title":"New fields for SecurityAdvisory GraphQL API","summary":"GitHub expanded its SecurityAdvisory GraphQL API with five new fields and two new filters (severities and isWithdrawn), enabling server-side filtering of advisory data. This reduces round trips, simplifies authentication, and streamlines integrations for severity-based triage and withdrawn advisory audits.","date":"2026-10-02","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://github.blog/changelog/2026-10-02-new-fields-for-securityadvisory-graphql-api","publisher":"github.blog"},{"title":"Confidential comments on repository security advisories","summary":"GitHub introduced confidential comments on repository security advisories, visible only to users with write access. Previously, all comments were public to collaborators, complicating internal discussions. The feature is available for public repos with private vulnerability reporting enabled across all GitHub plans.","date":"2026-10-02","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://github.blog/changelog/2026-10-02-confidential-comments-on-repository-security-advisories","publisher":"github.blog"},{"title":"Repository security advisory comments API in public preview","summary":"GitHub introduced a new REST API for reading, adding, and editing comments on repository security advisories, including those from private vulnerability reports. The API now includes comment counts in responses to help identify advisories with discussion activity, enabling automated workflows and audit exports.","date":"2026-10-02","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://github.blog/changelog/2026-10-02-repository-security-advisory-comments-api-in-public-preview","publisher":"github.blog"},{"title":"[IT News] GitHub Copilot can now operate desktop apps, released in public preview","summary":"GitHub Copilot now supports operating desktop applications through a new 'computer use' feature in public preview, enabling Copilot to read screens, click controls, enter text, and execute workflows across macOS and Windows apps. The feature is available in the GitHub Copilot CLI and app.","date":"2026-10-02","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://note.com/zeronin_keiei/n/nffb55272082a?hl=en","publisher":"note.com"},{"title":"AI Agents Leak 13,000 Internal Corporate Screenshots via Public GitHub Repositories","summary":"AI coding agents inadvertently posted over 13,000 internal screenshots to public GitHub repositories across 300+ organizations, exposing sensitive data like billing records and unreleased features. The issue stemmed from agents creating public repositories to host images for pull request reviews, with 93% of exposures under personal accounts.","date":"2026-10-02","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://www.sofx.com/ai-agents-leak-13000-internal-corporate-screenshots-via-public-github-repositories/","publisher":"sofx.com"},{"title":"Update your IDE to restore agent activity in Copilot usage metrics","summary":"GitHub identified a bug where Copilot agent activity in IDEs using the Copilot SDK was misattributed or excluded from usage metrics. A fix is rolling out now, starting with Visual Studio Code, with other IDEs expected by November 2026. Updated IDE versions will restore accurate agent activity tracking in Copilot dashboards and APIs.","date":"2026-10-02","dateIsEstimated":false,"signalType":"feature_update","signalTypeLabel":"Feature","sourceUrl":"https://github.blog/changelog/2026-10-06-update-your-ide-to-restore-agent-activity-in-copilot-usage-metrics/","publisher":"github.blog"},{"title":"npm staged publishing now supports creating new packages","summary":"GitHub’s npm staged publishing now allows creating new packages directly via `npm stage publish`, supporting local sessions, granular access tokens, and stage-only tokens. This enables automated workflows to initiate packages without manual first publishes, with the first version requiring maintainer promotion before public availability.","date":"2026-10-02","dateIsEstimated":false,"signalType":"feature_update","signalTypeLabel":"Feature","sourceUrl":"https://github.blog/changelog/2026-10-02-npm-staged-publishing-now-supports-creating-new-packages/","publisher":"github.blog"},{"title":"Unvalidated npm trusted publishing configurations now expire","summary":"GitHub now enforces a 48-hour expiry for unvalidated npm trusted publishing configurations, requiring a successful publish to validate and avoid expiration. Expired configurations remain visible but inactive, and tokens from restricted GitHub Actions events are rejected. Valid configurations are unaffected.","date":"2026-10-02","dateIsEstimated":false,"signalType":"feature_update","signalTypeLabel":"Feature","sourceUrl":"https://github.blog/changelog/2026-10-02-unvalidated-npm-trusted-publishing-configurations-now-expire/","publisher":"github.blog"},{"title":"AI is rewriting the developer career ladder. Here’s how to stand out.","summary":"GitHub argues AI is changing developer success factors from pure coding to directing AI, evaluating outputs, and making technical tradeoffs. The post provides actionable tips for developers to adapt, emphasizing AI coordination and judgment over implementation.","date":"2026-10-02","dateIsEstimated":false,"signalType":"content_marketing","signalTypeLabel":"Content","sourceUrl":"https://github.blog/ai-and-ml/ai-is-rewriting-the-developer-career-ladder-heres-how-to-stand-out/","publisher":"github.blog"},{"title":"Copilot code review: API support and new default effort level","summary":"GitHub added REST and GraphQL API support for initiating Copilot code reviews, enabling integration into custom workflows. The default review effort level is now Balanced for new and existing repositories, replacing the previous default. Lite remains an option for users who prefer it.","date":"2026-10-02","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://github.blog/changelog/2026-10-02-copilot-code-review-api-support-and-new-default-effort-level/","publisher":"github.blog"},{"title":"Stateless GitHub App installation tokens rolled out","summary":"GitHub finished rolling out stateless installation tokens for GitHub Apps, replacing the legacy format with a new 520-character token starting with ghs_ and using the statelessghs_APPID_JWT structure. The change speeds token issuance and API validation while keeping permissions, expiration, and API endpoints unchanged. Legacy tokens remain valid until expiration.","date":"2026-10-02","dateIsEstimated":false,"signalType":"feature_update","signalTypeLabel":"Feature","sourceUrl":"https://github.blog/changelog/2026-10-02-stateless-github-app-installation-tokens-rolled-out/","publisher":"github.blog"},{"title":"New fields for SecurityAdvisory GraphQL API","summary":"GitHub expanded its SecurityAdvisory GraphQL API with five new fields on the SecurityAdvisory object and two new filters (severities and isWithdrawn) for the SecurityAdvisories query. These changes enable server-side filtering, reducing round trips and simplifying integrations that rely on advisory data.","date":"2026-10-02","dateIsEstimated":false,"signalType":"feature_update","signalTypeLabel":"Feature","sourceUrl":"https://github.blog/changelog/2026-10-02-new-fields-for-securityadvisory-graphql-api/","publisher":"github.blog"},{"title":"Repository security advisory comments API in public preview","summary":"GitHub introduced a REST API to read, add, and edit comments on repository security advisories, including those from private vulnerability reports. The API now includes comment counts in responses, helping users identify advisories with discussion before fetching comments. Available in public preview for all public repository plans.","date":"2026-10-02","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://github.blog/changelog/2026-10-02-repository-security-advisory-comments-api-in-public-preview/","publisher":"github.blog"},{"title":"NEAR AI Cloud brings private inference to GitHub Copilot through a VSCode extension","summary":"GitHub Copilot now supports NEAR AI Cloud through a VSCode extension, enabling private inference via hardware-secured enclaves (TEEs) for prompts, model weights, and outputs. The integration leverages OpenAI-compatible APIs and BYOK support in VS Code, with pricing in NEAR tokens or credit cards.","date":"2026-10-01","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://cryptobriefing.com/near-ai-private-inference-github-copilot/","publisher":"cryptobriefing.com"},{"title":"Rate limits for private vulnerability reports","summary":"GitHub introduced rate limits for private vulnerability reports to combat low-quality and automated submissions that overwhelm maintainers. The feature caps daily report submissions per account, both per repository and across GitHub, while preserving access for legitimate researchers. It is available on GitHub Free, Pro, Team, and Enterprise Cloud for public repositories with private vulnerability reporting enabled.","date":"2026-10-01","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://github.blog/changelog/2026-10-01-rate-limits-for-private-vulnerability-reports","publisher":"github.blog"},{"title":"GitHub Copilot Gains Computer Use for Desktop Apps","summary":"GitHub Copilot now supports direct interaction with desktop applications via a new 'computer use' feature in public preview for CopilotCLI and the Copilot app on macOS and Windows. It can automate GUI-only tools by reading screen content and performing actions like clicking, typing, and dragging, with user approval required. The feature targets older apps lacking APIs or command-line interfaces.","date":"2026-10-01","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://www.technobezz.com/news/github-copilot-computer-use-desktop-apps-preview","publisher":"technobezz.com"},{"title":"GitHub Actions Job Delays Under Investigation","summary":"GitHub Actions experienced run-start delays on October 1, 2026, initially affecting Ubuntu runners and later recurring on Windows runners. The root cause was identified as 429 errors from an upstream provider, causing up to ten-minute delays. The issue was mitigated but remained under investigation.","date":"2026-10-01","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://www.technobezz.com/news/github-service-incident-e67d6253","publisher":"technobezz.com"},{"title":"GitHub reports elevated request latency incident now resolved","summary":"GitHub experienced elevated request latency for web requests on October 1, 2026, which was resolved within 20 minutes. The incident was investigated, mitigated, and marked resolved by 9:57 a.m. Eastern, with a root cause analysis to follow.","date":"2026-10-01","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://www.technobezz.com/news/github-service-incident-edb2b5ce","publisher":"technobezz.com"},{"title":"Over 543,000 valid credentials exposed on GitHub despite security measures","summary":"GitHub disclosed that over 543,000 valid credentials were exposed on its platform despite existing security measures. The incident highlights ongoing challenges in preventing credential leaks even with safeguards in place.","date":"2026-10-01","dateIsEstimated":false,"signalType":null,"signalTypeLabel":null,"sourceUrl":"https://techgig.com/news/cybersecurity/over-543000-valid-credentials-exposed-on-github-despite-security-measures/134605687","publisher":"techgig.com"}],"attribution":{"source":"Spyingbee","url":"https://spyingbee.com/updates/github","citation":"Spyingbee, \"GitHub updates\", https://spyingbee.com/updates/github (retrieved 2026-10-08)"}}