- Launchgithub.blog
Claude Sonnet 5 is generally available for GitHub Copilot - The GitHub Blog
GitHub Copilot now supports Anthropic’s Claude Sonnet 5, offering improved coding performance for IDE and CLI workflows. The model is available to Copilot Pro, Pro+, Max, Business, and Enterprise user…
- Featuregithub.blog
How GitHub maintains compliance for open source dependencies - The GitHub Blog
GitHub introduced a new License Compliance feature in GitHub Advanced Security that scans dependencies in pull requests to ensure license policies are met. The tool helps enterprises avoid legal risks…
- Securitythehackernews.com
Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer - The Hacker News
Researchers uncovered hijacked npm and Go packages that deploy a Python-based information stealer using VS Code auto-run tasks. The malware disguises payloads as font files, retrieves encrypted JavaSc…
- Featuregithub.blog
Claude Opus 4.8 (fast mode) is now in preview for GitHub Copilot - The GitHub Blog
GitHub Copilot now offers Claude Opus 4.8 in fast mode, delivering faster token output while maintaining intelligence for interactive coding and agentic workflows. The feature is in preview, billed at…
- startuphub.ai
GitHub Copilot Harness Efficiency - StartupHub.ai
GitHub unveiled its agentic harness for Copilot, demonstrating task completion rates comparable to model-native solutions while consuming fewer tokens across over 20 LLMs. Benchmarks like SWE-bench an…

- Acquisitiontheregister.com
Apple takes over Swift Package Index, vows to remove GitHub dependency - The Register
Apple has taken ownership of the Swift Package Index (SPI), a search engine for open-source Swift packages, and hired its co-creator Dave Verwer. The move aims to accelerate development, including pac…
- Securitythehackernews.com
GitHub Updates actions/checkout to Block Common Pwn Request Attack Patterns - The Hacker News
GitHub is updating its actions/checkout action to block common pwn request attack patterns by default, effective June 18, 2026. The change prevents malicious code execution in pull_request_target work…
- rescana.com
GitHub Actions Enhances CI/CD Security: actions/checkout v7 Blocks Common Pwn Request Attack Patterns - Rescana
GitHub Actions’ actions/checkout v7 now blocks default pwn request patterns in privileged workflows triggered by pull_request_target or workflow_run events, refusing to fetch fork pull request code. T…

- trendhunter.com
Agentic Development Automation - Trend Hunter
GitHub introduced Agentic Workflows, allowing teams to define AI-driven automation for engineering tasks like issue triage, CI failure analysis, and dependency management. The feature embeds reasoning…

- helpnetsecurity.com
Cybercriminals abused GitHub, YouTube and VirusTotal to push crypto-stealing malware - Help Net Security
A coordinated malware campaign used inflated GitHub stars, AI-generated YouTube tutorials, and manipulated VirusTotal reviews to distribute Rust-based clipboard hijackers targeting cryptocurrency wall…

- Partnershipdevops.com
Microsoft Enlists AWS to Help GitHub Handle Explosive Growth in AI Development - DevOps.com
Microsoft is using AWS to supplement GitHub’s infrastructure due to explosive growth in AI-assisted software development, which has strained Azure’s capacity. The move marks a shift from Microsoft’s l…
- varindia.com
Microsoft turns to rival Amazon as AI-driven demand strains GitHub infrastructure - varindia.com
Microsoft is reportedly using Amazon’s cloud infrastructure to manage GitHub’s operations as AI-driven coding tools strain its existing resources. The move reflects a broader industry shift where riva…

- Featuregithub.blog
Copilot-authored pull requests now included in author searches - The GitHub Blog
GitHub now includes pull requests opened by its Copilot cloud agent in author-based searches (e.g., author:@me). The change applies to github.com UI and GitHub Mobile now, with REST and GraphQL API su…
- opensource.googleblog.com
CEL finds a new home at github.com/cel-expr! - blog.google
Google’s Common Expression Language (CEL) repositories have relocated to a new GitHub organization (cel-expr) to centralize development and improve branding, discoverability, and consistency. All lang…

- m.investing.com
Microsoft taps Amazon to ease GitHub AI-driven strains - Business Insider - Investing.com
Microsoft is using Amazon Web Services to supplement GitHub’s infrastructure as AI-driven coding surges strain resources, despite a planned full migration to Azure by 2027. GitHub commits are projecte…
- Technicaltheregister.com
Holy git! Microsoft code-sharing site suffers downtime, despite move to Azure - The Register
GitHub faces persistent service outages despite a 30x capacity expansion to handle AI-assisted coding traffic, now processing 1.4 billion commits monthly. Azure migration and structural changes aim to…
- infosecurity-magazine.com
GitHub to Update npm to Thwart Software Supply Chain Attacks - Infosecurity Magazine
GitHub announced npm v12, introducing breaking security changes to shift from implicit trust to explicit opt-in for dependencies, available from July 2026. The update flips historically permissive def…
- rescana.com
GitHub Enhances npm Security with Mandatory 2FA and Provenance to Combat Supply Chain Attacks - Rescana
GitHub introduced mandatory two-factor authentication (2FA) for maintainers of high-impact npm packages and added cryptographically verifiable package provenance to combat supply-chain attacks. These …

- Sunsetcsoonline.com
GitHub finally pulls the plug on automatic install script execution for npm - csoonline.com
GitHub will change npm’s default behavior in v12 to block automatic execution of preinstall, install, and postinstall scripts unless explicitly allowed, closing a major supply chain attack vector. The…

- Featurethehackernews.com
GitHub to Disable npm Install Scripts by Default to Stop Supply Chain Attacks - The Hacker News
GitHub announced that npm v12 will disable install scripts by default to mitigate supply chain attacks, requiring explicit user approval for script execution during 'npm install'. The change blocks im…
- Featuregithub.blog
GitHub Actions: Minimum version enforcement timeline for self-hosted runners - The GitHub Blog
GitHub will enforce minimum runner versions for self-hosted runners on github.com and GitHub Enterprise Cloud starting July 31, 2026 (Data Residency) and September 25, 2026 (standard). Runners must up…
- Securitydevops.com
GitHub Takes Down 73 Microsoft Repos After Miasma Worm Attack - DevOps.com
GitHub disabled 73 Microsoft-owned repositories within 105 seconds after detecting the Miasma worm, a self-replicating credential-harvesting malware variant. The attack exploited compromised contribut…
- Technicaltechzine.eu
GitHub turns to AWS due to growth in AI development - Techzine Global
Microsoft is leveraging AWS capacity to handle GitHub’s unprecedented growth in AI-generated software development, despite an ongoing migration to Azure. The surge in AI agent activity has strained Gi…

Suivez GitHub en pilote automatique
- · Brief IA hebdomadaire : résumé narratif de ce qui a été livré, chaque lundi 9 h
- · Alertes par e-mail ou Slack, ou discutez avec l'archive depuis votre tableau de bord
- · Ajoutez GitHub + jusqu'à 2 autres concurrents gratuitement, sans carte bancaire