GitHub · juillet 2026
26 mises à jour · juillet 2026
En juillet 2026, GitHub a publié 26 mises à jour suivies. En hausse de 13% par rapport à juin 2026. Le thème dominant : feature updates (7). À retenir : « Tame Dependabot: Group your updates, slow the cadence, keep security fast » (29 juil. 2026).
Parcourir d'autres mois de GitHub
GitHub’s engineering team revealed how they optimized case-folding for Blackbird, their code search engine, by removing early-exit branches in ASCII processing. This change boosted performance from 3 …
GitHub will now pause potentially malicious Actions workflow runs in public repositories until an authorized collaborator approves them. The safeguard, announced July 28, 2026, targets attacks using c…
On July 14, 2026, attackers compromised the @asyncapi npm organization by abusing GitHub Actions workflows to publish five backdoored packages with valid cryptographic provenance. The attack executed …

GitHub demonstrated how Microsoft’s GCToolkit reduced Dependabot noise by grouping updates into monthly batches and slowing cadence from daily to monthly, cutting review and CI cycles. The change invo…
GitHub introduced a 3-day cooldown in Dependabot for version updates to reduce exposure to poisoned packages, while security updates remain immediate. The default balances attack window reduction with…
GitHub introduced stacked pull requests in public preview, allowing teams to break large changes into ordered, reviewable layers. Each pull request can be reviewed independently, with the entire stack…
India’s Ministry of Home Affairs directed GitHub to remove repositories for Bitchat, a decentralized Bluetooth mesh messaging app, citing unauthorized access and national security concerns under the I…

GitHub Copilot now supports Anthropic’s Claude Opus 5, optimized for complex, multi-step coding tasks like autonomous changes and regression verification. The model includes enhanced cyber-content saf…
Block, led by Jack Dorsey, launched Buzz, an AI-first workplace collaboration platform combining messaging, project management, and software development. Buzz integrates AI agents directly into team w…
GitHub Sponsors reached $100 million in contributions, driven by accelerated corporate sponsorships that now support over 70,000 open-source maintainers globally. The milestone reflects growing corpor…
)
A GitHub code file by AMD’s VP of AI Software listed Anthropic as a top-priority customer, matching Meta’s status. Anthropic is hiring ROCm engineers and evaluating AMD’s software stack ahead of AMD’s…

OpenCode, an MIT-licensed terminal-based coding agent, surged to the top of LogRocket’s July 2026 AI dev tool rankings with 160,000 GitHub stars and 7.5M monthly active developers. Its rise was cataly…

A financially motivated Russian-speaking threat actor is impersonating 292 brands on GitHub to distribute a smash-and-grab infostealer malware disguised as legitimate software downloads. The campaign,…

South Korean police reported a leak of GitHub Personal Access Tokens (PATs), enabling attackers to access private repositories and steal sensitive data like API keys and database passwords. The leak c…

Researchers demonstrated a multi-turn workflow exploit that bypasses GitHub Copilot’s safety guardrails by framing harmful objectives as benchmark-improvement tasks. All four tested backends (Claude S…

GitHub Copilot now supports OpenAI’s GPT-5.6 family with three variants—Sol, Terra, and Luna—each optimized for different coding tasks. The models are available across most Copilot SKUs, with Enterpri…
Researchers uncovered sustained campaigns using GitHub’s public APIs and ghost accounts to profile enterprise software environments, blending into normal developer activity. Attackers map organization…

GitHub Copilot now generates high-level overviews of unfamiliar repositories, summarizing purpose, technologies, and contribution guidelines. If a repository lacks a README, Copilot can create one. Th…
Kaspersky’s analysis of 130,000 CI/CD pipelines in 30,000 GitHub repositories revealed over 250,000 security misconfigurations, with only 10% of repos free of alerts. High-risk flaws were found in 200…

GitHub launched public monitoring for secret scanning, scanning all public content on github.com in real time to detect leaked secrets tied to enterprises via GitHub's identity layer. Available at no …
.png)
GitHub teased a concept allowing users to obtain physical CD-ROM copies of public repositories, framing it as a nod to 'physical ownership' of digital assets. The move blends satire with a critique of…

Entire hired Karthik Rameshkumar, former GitHub APAC Field CTO, as its first Field CTO for India to lead developer adoption and AI-native infrastructure initiatives. The move underscores Entire’s push…

Arctic Wolf’s SecOps team discovered a malicious GitHub page impersonating their brand to distribute an information-stealing malware called 'BoryptGrab Stealer.' The attack chain involved a trojanized…
GitHub introduced a new License Compliance feature in public preview for its Advanced Security customers, enabling automated scanning of open-source dependencies in pull requests to flag non-compliant…

GitHub Copilot now offers Kimi K2.7 Code, an open-weight model, as a selectable option in the Copilot model picker. The model is available in Copilot Pro, Pro+, and Max plans, with rollout beginning i…
GitHub introduced public monitoring for enterprises to detect leaked secrets in real time across all public content on github.com, attributing findings to the correct enterprise via verified domains a…
Suivez GitHub en pilote automatique