- gadgetreview.com
AI Coding Agents Are Publishing Your Company’s Secrets to GitHub
AI coding agents across 343 organizations uploaded 13,000 internal screenshots to public GitHub repositories, exposing credentials, unreleased products, and personal data. The issue stemmed from agent…

- aiweekly.co
Glow Labs: AI Coding Agents Pushed 13,000 Screenshots to GitHub
Security firm Glow Labs disclosed that AI coding agents at over 300 organizations pushed 13,000+ internal screenshots to public GitHub repositories, exposing sensitive data like billing records and un…
- helpnetsecurity.com
AI coding agents leaked 13,000 internal company screenshots to public GitHub repos
Researchers at Glow Labs discovered AI coding agents publishing over 13,000 internal company screenshots to public GitHub repositories, exposing sensitive data like billing records and unreleased feat…

- Securitythehackernews.com
AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub - The Hacker News
Security firm Glow reported that AI coding agents inadvertently uploaded over 13,000 internal images—including billing records and unreleased features—to public GitHub repositories. The issue stemmed …
- Featuregithub.blog
Accessibility statements highlighted on repository overview
GitHub now highlights ACCESSIBILITY.md files in repository roots, .github directories, or docs directories on repository overview pages. Users can also add or propose accessibility statements from a p…
- Featuregithub.blog
X25519-only TLS ends for GHE.com on October 7
GitHub Enterprise Cloud with data residency will stop accepting TLS connections using only X25519 for key agreement starting October 7, 2026. The change requires affected clients to support FIPS-appro…
- note.com
Codex Security Cloud Significantly Enhanced with Continuous GitHub Scanning [Breaking News]
OpenAI upgraded Codex Security Cloud to continuously scan entire GitHub repositories and monitor new commits in the cloud, even when laptops are closed. Findings are verified via reproduction in isola…

- cyberpress.org
GitHub AI Security Agent Finds 24 Android Vulnerabilities Including Account Takeover Flaws
GitHub Security Lab disclosed that its open-source AI security agent identified 24 vulnerabilities in Android apps, including account takeover and location tracking flaws. The agent uses structured wo…

- helpnetsecurity.com
GitHub’s AI agent found 24 Android app vulnerabilities
GitHub Security Lab researcher Kevin Stubbings used GitHub’s open-source Taskflow Agent to build AI-driven audit workflows that identified 24 vulnerabilities in Android apps, including critical flaws …

- github.blog
HydraFusion in VS Code and the GitHub Copilot app
GitHub’s HydraFusion research preview, which orchestrates multiple AI models for optimized workflows, is now available in VS Code and the GitHub Copilot app. It selects execution patterns based on cap…
- Legalgithub.blog
Developer policy update: Transparency, state policy, and what’s ahead
GitHub reported a 622% increase in government takedown requests in H1 2026 due to expanded reporting methodology, not content removals. The company also highlighted its advocacy on AI transparency (SB…
- Featuregithub.blog
Opt-in dist-tag permissions for npm trusted publishing
GitHub added opt-in support for managing npm dist-tags (e.g., latest, next, beta) through trusted publishing configurations using short-lived OIDC credentials, eliminating the need for long-lived acce…
- note.com
GitHub Copilot: Initial settings for new features change—Enterprise policies apply starting October 22
GitHub will enforce a new global default policy for Copilot Business/Enterprise starting October 22, 2026, allowing admins to pre-configure whether generally available features (e.g., Copilot Code Rev…

- note.com
[IT News] GitHub Copilot now supports Claude Sonnet 5.5. Eligible plans and how to get started
GitHub announced general availability of Anthropic's Claude Sonnet 5.5 in GitHub Copilot on September 28, 2026. Early testing claims faster task completion with fewer steps and tokens while maintainin…

- gigazine.net
Reports indicate that a 'malicious imitation software' was reported to GitHub but ignored for over three weeks, only to be removed within 10 minutes once it became a topic of discussion online. - gigazine.net
A GitHub-hosted 'malicious imitation software' mimicking Easy Data Transform was reported but ignored for over three weeks. The page was removed within 10 minutes after Bryce's blog post about the inc…
- note.com
[Copilot Studio] Systematically Learning Agent Development with GitHub Copilot Harness #0386
A Microsoft Learn module introduces systematic agent development using GitHub Copilot Harness in Microsoft Copilot Studio, covering knowledge, tools, skills, and MCP integration. The 1h29m intermediat…

- Technicalgithub.blog
How we found 24 Android vulnerabilities using our open source AI security agent
GitHub Security Lab released an open-source AI security agent (Taskflow Agent) to automate and share workflows for finding vulnerabilities in Android apps. Using custom taskflows, the team reported 24…
- github.blog
GPT-6.1 Sol in GitHub Copilot
GitHub Copilot now includes OpenAI's GPT-6.1 Sol model, offering improved multistep coding performance and token efficiency. The model is available to Copilot Pro+, Max, Business, and Enterprise users…
- Featuregithub.blog
Actions Runner Controller release 0.15.0
GitHub released Actions Runner Controller 0.15.0, introducing reliability, scalability, and observability enhancements for runner scale sets. The update improves controller throughput, graceful shutdo…
- Featuregithub.blog
Highlights from Git 2.56
Git 2.56.0 adds three major improvements: a new `git add --resolved` mode to safely stage only resolved conflicts without staging unrelated changes, a faster merge-base search algorithm that can reduc…
- note.com
AI has started remembering 'how it fixed things before'—How GitHub Agentic Autofix and Copilot Memory work
GitHub announced on September 25, 2026, that agentic autofix now uses Copilot Memory to store fix patterns for future security alerts and share repository-specific safe development patterns with other…

- note.com
GitHub Copilot Expands Integration with Slack and Microsoft Teams: Supports Model Switching and Duplicate Prevention
GitHub expanded Copilot integrations for Slack and Microsoft Teams on September 25, 2026, adding model switching persistence, duplicate issue prevention, file/image reference support, and improved rel…

- note.com
[GitHub Actions] For Beginners: A Way to Automate One Check After a Push
A beginner-focused guide explains how to automate repetitive verification tasks using GitHub Actions by setting up minimal workflows triggered by code pushes. It emphasizes starting with a single chec…

- note.com
GitHub Enterprise Server 3.22 adds Copilot CLI configuration for isolated environments and more
GitHub Enterprise Server 3.22 is now generally available, introducing a technical preview for configuring the Copilot CLI in internet-disconnected, air-gapped environments. The update also adds Enterp…

- Securitythehackernews.com
Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
GitHub disabled two compromised GitHub Actions repositories twice after they briefly became accessible on September 16, 2026, allowing dormant malicious workflows to resume execution. The malware, int…
- note.com
Conditions for Safely Trying GitHub's AI-Powered Fuzzing—Human Judgment Remains Even with Automation
GitHub Security Lab introduced an AI-powered fuzzing taskflow that automates entry point selection, harness creation, coverage improvement, and crash triage for C/C++ projects. The system uses LLM age…

- Featuregithub.blog
Claude Sonnet 5.5 in GitHub Copilot
GitHub Copilot now includes Anthropic’s Claude Sonnet 5.5, optimized for everyday coding tasks like feature building and bug fixes. Early tests show it completes tasks faster while using fewer steps, …
- Featuregithub.blog
Usage metrics API adds pull request review stages
GitHub’s Copilot usage metrics API now tracks pull request review stages, breaking down median and 90th percentile times for three phases: ready-for-review to first review, first to final review, and …
- github.blog
Enterprise managed settings in-product validator
GitHub introduced an in-product validator for enterprise managed settings in Copilot, detecting JSON errors, unsupported configurations, and invalid team mappings. The tool highlights affected files a…
- Featuregithub.blog
GitHub Copilot weekly releases — September 21
GitHub released weekly updates to Copilot, introducing new AI models, local sandboxing in the Copilot app, and improvements to Copilot integrations in Slack, Microsoft Teams, JetBrains, and VS Code. T…
- Featuregithub.blog
Updates to GitHub Copilot for Slack and Microsoft Teams
GitHub Copilot in Slack and Microsoft Teams now supports richer context from files, images, and conversation history, with direct links to resulting GitHub work and improved reliability. Users can swi…
- github.blog
Improving site performance by shipping more CSS
GitHub migrated its Primer design system and entire codebase from CSS-in-JS to CSS Modules, eliminating runtime costs and improving performance. The multi-year effort involved incremental component up…
- github.blog
GitHub Copilot app for Beginners: How to build custom workflows with canvases
GitHub introduced canvases in the GitHub Copilot app, enabling users to create customizable interfaces (e.g., kanban boards, checklists) by describing workflows in plain English. These bidirectional c…
- Featuregithub.blog
Agentic autofix now uses Copilot Memory
GitHub’s agentic autofix now leverages Copilot Memory to resolve security alerts by reviewing stored context and storing fix patterns for future use. This enhancement improves resolution efficiency an…
- Launchgithub.blog
GitHub async merge API generally available
GitHub made its async merge API generally available, enabling programmatic merging of individual or stacked pull requests, merge queue additions, and direct merges with optional rule bypass. The API p…
- Featuregithub.blog
GitHub Advanced Security trials for GitHub Team
GitHub Team customers can now initiate self-serve trials of GitHub Advanced Security to test Code Security and Secret Protection features directly from their organization’s Overview, Billing, or Risk …
- Featuregithub.blog
Self-hosted runner version enforcement date has moved
GitHub delayed the enforcement of minimum version requirements for self-hosted runners in GitHub Enterprise Cloud by one day, moving full enforcement to September 29, 2026. The policy itself remains u…
- technobezz.com
GitHub Investigating Disruption With Billing Information Updates
GitHub resolved a service incident on September 24, 2026, where customers could not create or update billing information for approximately four hours. The disruption was mitigated by 4:24 p.m. Eastern…
- events.xebia.com
Master GitHub Copilot Usage-Based Billing — Control Spend, Scale Adoption
GitHub and Xebia are hosting a two-part webinar series on October 6 and 13 to help engineering and finance leaders manage GitHub Copilot's usage-based billing model. The sessions will cover frameworks…
- note.com
OpenTelemetry configuration support in GitHub Copilot app
GitHub introduced OpenTelemetry (OTel) configuration support in the GitHub Copilot app, allowing enterprise administrators to export agent activity data to compatible monitoring tools via centralized …
- Featuregithub.blog
Default Enablement of Copilot Features for Copilot Business and Enterprise
GitHub is rolling out a new global default policy for Copilot features in enterprise and organization settings, configurable now but taking effect October 22. Admins can set default enablement for new…
- Featuregithub.blog
CodeQL 2.27.1 adds C and C++ query and Kotlin 2.4.20 support
GitHub released CodeQL 2.27.1, expanding static analysis capabilities with new C/C++ and C# queries, Kotlin 2.4.20 support, and accuracy improvements. The update is automatically deployed to GitHub co…
- github.blog
AI-powered fuzzing with the GitHub Security Lab Taskflow Agent
GitHub introduced the GitHub Security Lab Taskflow Agent, an LLM-driven pipeline that autonomously performs fuzzing for C/C++ projects. The system writes harnesses, runs AFL++, analyzes coverage, tria…
- Featuregithub.blog
When chat is the wrong UI
GitHub argues that chat is often the wrong UI for AI and introduces 'canvases'—customizable, full-stack applications within the GitHub Copilot app that enable bidirectional communication with AI agent…
- Featuregithub.blog
Changes to query results in the GitHub Actions API and UI
GitHub is capping workflow run query results in the Actions API and UI at '2,500+' when results exceed this threshold to avoid timeouts and improve accuracy. Queries will still return up to 1,000 pagi…
- infosecurity-magazine.com
Hundreds of Leaked GitHub App Keys Still Authenticate
Research found 474 active GitHub App private keys (10% of 4,802 exposed) still authenticating, including 44 with organization admin privileges. Some keys granted access to private repositories, self-h…
- technobezz.com
GitHub Investigating Incident Across Several Services
GitHub experienced a multi-hour incident on September 23, 2026, where database replicas detached, degrading API requests and Projects functionality. Issue label updates in Projects were delayed by up …
- theprint.in
IFI Techsolutions achieves Agentic DevOps with Microsoft Azure and GitHub Specialization
IFI Techsolutions earned the Agentic DevOps specialization with Microsoft Azure and GitHub, validating its AI-powered engineering capabilities using GitHub Copilot and Azure. The recognition highlight…

- Securityinfoworld.com
GitHub App keys can still enable takeovers long after they are forgotten
GitGuardian found 474 still-valid GitHub App private keys among 4,802 exposed since 2019, with 72% able to read private repositories and 207 capable of writing, enabling potential organization takeove…
- Featuregithub.blog
Rendering huge pull requests in the GitHub Copilot app
GitHub rebuilt the pull request view in the GitHub Copilot app to handle massive diffs (2,200 files, 1M+ lines, 400+ comments) without performance degradation. The solution splits the document into tw…
- Featuregithub.blog
More ways to request and configure Copilot code reviews
GitHub expanded Copilot code review settings to all Copilot plans, including Business and Enterprise, via a new 'code review' page under user profiles. Users can now set default review effort levels (…
- Contentgithub.blog
Developers want more efficient software. Here’s what over 1000 GitHub users told us they need.
GitHub and Yale found 80% of surveyed users want tools to write energy-efficient code and measure environmental impact, with only 10% believing their current practices have a large effect. GitHub resp…
- Featuregithub.blog
Expired GitHub Actions artifacts no longer shown in UI and API
GitHub no longer displays expired artifacts in the Actions run summary or API responses, removing ambiguity about whether users are billed for non-existent storage. The change does not affect retentio…
- note.com
GitHub Copilot Launches Claude Opus 5.5
GitHub integrated Anthropic’s Claude Opus 5.5 into GitHub Copilot for Pro+, Max, Business, and Enterprise users, enabling agentic coding and long-running tasks. Initial tests show reduced steps and to…
- darkreading.com
Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data
A former CrowdSec employee’s compromised machine via the TanStack npm supply chain attack enabled attackers to steal a GitHub OAuth token and exfiltrate 170 private repositories in 9 minutes. CrowdSec…

- cyberpress.org
AWS Automatically Quarantines Exposed IAM Credentials Within 10 Seconds of GitHub Leak
AWS automatically applies a restrictive quarantine policy to IAM users whose long-term access keys are exposed in public GitHub repositories, blocking high-risk actions within 10 seconds of disclosure…

- Featuregithub.blog
OpenAI’s GPT-6 Sol and GPT-6 Luna now available
GitHub now offers two new OpenAI models—GPT-6 Sol and GPT-6 Luna—in GitHub Copilot, expanding the GPT-6 family alongside GPT-6 Astra. GPT-6 Sol targets agentic coding, while GPT-6 Luna provides fast, …
- Featuregithub.blog
New features and improvements in Copilot for JetBrains
GitHub released Copilot for JetBrains 1.18.0 with AI-assisted tool approvals, re-editable agent messages, shared organizational skills/instructions, and plan review in Codex agent sessions. The update…
- Featuregithub.blog
Security improvements for SSH
GitHub is removing outdated SSH algorithms (SHA-1, Diffie-Hellman) and adding a quantum-resistant key exchange method (ML-KEM) in GitHub Enterprise Server. RSA keys must now meet 128-bit security stan…
- github.blog
Local sandboxing in the GitHub Copilot app
GitHub introduced local sandboxing in the GitHub Copilot app to limit file, network, and credential access during local repository sessions, reducing unintended command risks. The feature is off by de…
- Featuregithub.blog
Require proof of presence for high-impact actions
GitHub introduced proof of presence, requiring interactive re-authentication or MFA challenges before high-impact actions in GitHub Enterprise Cloud. This public preview targets managed user enterpris…
- Featuregithub.blog
Faster C++ code intelligence with whole codebase indexing
GitHub added whole codebase indexing (WCI) to GitHub Copilot CLI for C++ projects, creating a persistent symbol index to speed up code navigation and understanding. The feature is enabled by default a…
- Featuregithub.blog
OpenTelemetry in the GitHub Copilot app
GitHub’s Copilot app now supports OpenTelemetry (OTel) configuration via enterprise-managed settings, allowing administrators to export agent activity data to compatible monitoring tools. Prompt and r…
- cybersecuritynews.com
AWS Automatically Quarantines Exposed IAM Keys Within 10 Seconds of GitHub Leak
GitHub's secret scanning, via its AWS partner integration, detects exposed AWS IAM keys in public repositories and reports them to AWS within seconds. AWS then automatically quarantines the compromise…
- Sunsetgithub.blog
Deprecation notice: All-platform CodeQL bundle
GitHub will deprecate the all-platform CodeQL bundle starting with CLI 2.27.0 and remove it entirely in mid-March 2027. Users must switch to platform-specific bundles, as Linux ARM64 binaries will no …
- github.blog
Claude Opus 5.5 is now available in GitHub Copilot
GitHub Copilot now includes Anthropic’s Claude Opus 5.5, offering improved efficiency in agentic coding and long-running tasks with fewer steps and tokens. The model features error recovery and text w…
- Securitycybersecuritynews.com
TanStack Supply Chain Attack Lets Hackers Steal 170 Private CrowdSec GitHub Repositories
A compromised TanStack npm package led to the theft of 170 private GitHub repositories belonging to CrowdSec via an OAuth token stolen from a former employee’s account. The attack exploited GitHub Act…
- Securitythehackernews.com
CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
A former CrowdSec employee's compromised laptop, linked to a May 2026 TanStack npm supply-chain attack, allowed an attacker to copy 170 private GitHub repositories. The leaked code included internal s…
- ibtimes.sg
Fake GitHub Repositories Are Spreading Rapuncel Malware Through Google Search
A campaign leverages SEO-optimized fake GitHub organizations and repositories to impersonate 40+ software companies and distribute the Rapuncel information stealer. Attackers use fabricated trust sign…

- the420.in
Fake LastPass Authenticator Pages Push Rapuncel Malware Through GitHub Downloads - The420.in
A malware campaign used fake GitHub Pages impersonating LastPass Authenticator and 40+ other brands to distribute the Rapuncel infostealer. Attackers exploited SEO optimization to trick users into dow…

- cyberinsider.com
Fake LastPass downloads on GitHub pushed password-stealing malware
A malware campaign impersonated LastPass on GitHub to distribute a password-stealing trojan via fake download pages. The operation used 40+ impersonated brands, including a fraudulent GitHub organizat…

- Securitybleepingcomputer.com
Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer - BleepingComputer
A malware campaign uses fake GitHub repositories impersonating LastPass and 39 other companies to distribute the Rapuncel infostealer and a Microsoft-signed kernel driver that disables 145 antivirus a…

- helpnetsecurity.com
Hardcoded MCP credentials found in public GitHub files
A Hush Security report found 12% of 82,000 MCP configuration files on GitHub contained hardcoded credentials, with 24% being non-expiring and 53% granting broad-scope access. Even deleted secrets rema…

- Contentxataka.com
"Queremos que haya mil millones de desarrolladores": así es como ve el futuro de la programación Mario Rodríguez, CPO de GitHub
GitHub's CPO Mario Rodríguez emphasizes GitHub's focus on becoming the central platform for all developers, not just competing in AI models. He highlights the shift toward macrodelegation and microste…
- Featureobserver.com
GitHub COO Kyle Daigle Says the Real A.I. Coding Battle Is About More Than Code
GitHub COO Kyle Daigle emphasized GitHub’s platform-based approach to AI coding, offering multi-model access (Claude Code, Codex) and usage-based billing to control costs. Copilot’s 'auto mode' select…

- Featuregithub.blog
Grok 4.7 is now available in GitHub Copilot
GitHub Copilot now includes Grok 4.7, xAI’s latest reasoning model optimized for agentic coding and complex workflows. The model is available across all Copilot SKUs (Pro, Pro+, Max, Business, Enterpr…
- Featuregithub.blog
GitHub Enterprise adds credential inventory exports
GitHub Enterprise now allows owners to export a full inventory of all credentials (SSH keys, tokens, OAuth apps) across their enterprise via CSV or REST API. This enables faster security incident resp…
- github.blog
Copilot code review: An improved review experience
GitHub Copilot code review now provides clearer progress tracking with grouped findings, auto-resolves its own comments when addressed, and generates smart commit messages for batch suggestions. These…
- github.blog
Upcoming deprecation of selected GitHub Copilot models in mid-October
GitHub will deprecate certain Copilot models across all experiences on October 19, 2026, requiring users to switch to supported alternatives. Enterprise and Business customers will see alternatives en…
- Featuregithub.blog
Repository custom runner settings for Dependabot
GitHub now lets repository admins configure runner type, custom labels, and runner groups for Dependabot version and security updates, extending existing organization-level controls. This applies to p…
- newsbytesapp.com
Microsoft launches free GitHub courses for AI and ML beginners
Microsoft launched four free, self-paced AI and ML courses on GitHub targeting beginners, covering data science, machine learning, AI fundamentals, and generative AI. Each track includes lessons, quiz…

- Sunsetgithub.blog
Node 20 is no longer available in GitHub Actions
GitHub has permanently removed Node 20 from GitHub Actions runners, replacing it with Node 24. JavaScript action maintainers must update their actions to use Node 24 and publish new releases. Workflow…
- Featuregithub.blog
Ubuntu 26 generally available and latest migration
GitHub made Ubuntu 26.04 the default runner image for GitHub Actions, replacing Ubuntu 24.04. The new image is fully supported on x64 and arm64, and the ubuntu-latest label will migrate between Octobe…
- github.blog
Workflow execution protections in GitHub Actions generally available
GitHub Actions workflow execution protections, previously in public preview, are now generally available for Enterprise, organizations, and repositories. The feature allows defining allowlists to cont…
- github.blog
Copilot impact dashboard now shows feature engagement
GitHub’s Copilot impact dashboard now tracks 28-day feature engagement for key Copilot features, allowing enterprise admins to identify adoption trends and prioritize enablement efforts. The same brea…
- github.blog
Agentic CLI customizations now in the usage metrics API
GitHub expanded its Copilot CLI usage metrics API to include agentic activity data such as skills, custom agents, MCP servers, slash commands, and plugins. The new fields appear in enterprise and orga…
- Featuregithub.blog
Stage-only npm tokens for safer automation
GitHub added a 'stage-only' option for npm granular access tokens, allowing automated workflows to stage package versions for review without direct publishing rights. Maintainers must approve releases…
- technobezz.com
GitHub Investigating Degradation With Gemini 3.8 Flash
GitHub is investigating a major service degradation affecting its Copilot AI Model Providers, specifically tied to the Gemini 3.8 Flash model. The incident, rated as major impact, began on September 1…
- Featuregithub.blog
Migrating the GitHub Copilot runtime to Rust, using Copilot
GitHub rewrote its Copilot agent runtime—used across CLI, app, SDK, and multiple Microsoft products—from TypeScript/Node.js to over 800,000 lines of Rust, improving performance by orders of magnitude.…
- Featuregithub.blog
Automate SSO authorization for classic PATs and SSH keys
GitHub Enterprise Cloud now lets admins automate SSO authorization for classic PATs and SSH keys across multiple organizations via a new enterprise setting and API. The API allows bulk authorization f…
- Featuregithub.blog
Manage the code coverage ruleset condition with the REST API
GitHub now offers a REST API to manage the 'Restrict code coverage' repository ruleset, enabling programmatic creation, update, and reading of minimum coverage thresholds or maximum coverage drops. Pr…
- technobezz.com
GitHub Reports Disruption Affecting Some Services
GitHub resolved a service disruption on September 15, 2026, that degraded availability for its Copilot AI Model Providers, specifically impacting the Claude Fable 5.1 model across Copilot products and…
- Featuregithub.blog
Code scanning AI Scan no longer requires CodeQL default setup
GitHub Advanced Security customers can now run AI Scan for pull requests across eligible repositories without requiring CodeQL default setup. The change broadens AI-powered security detection coverage…
- Featuregithub.blog
Bring business context with external custom properties
GitHub introduced external custom properties in public preview, allowing enterprises to sync business context (ownership, service tier, compliance status) from external systems (CMDB, developer portal…
- Featuregithub.blog
Copilot budget increase requests are generally available
GitHub Copilot now allows members to request budget increases when they hit credit limits, with approvals handled directly in settings. Organization and enterprise owners can review, adjust, or approv…
- cyberpress.org
GitHub Pays $100,000 Bounty for Critical RCE Flaw Triggered by a Single Git Push
GitHub disclosed and remediated CVE-2026-3854, a critical unauthenticated RCE vulnerability triggered by crafted Git operations, awarding a $100K bounty to researcher Saif Ghani. The flaw could enable…

- Featuregithub.blog
GitHub Copilot suggests custom properties definitions
GitHub Copilot now suggests allowed values when creating custom properties for repositories in GitHub Copilot Business and Enterprise plans. This feature aims to streamline governance by helping admin…
- andela.com
Optimize GitHub Copilot Token Costs & Boost Productivity
Andela and GitHub are hosting a webinar on October 7 to help enterprise leaders optimize GitHub Copilot token costs and improve developer productivity. The event targets data engineering leaders, CTOs…

- github.blog
Marketing ops as code: Automating events from planning to follow-up on GitHub
GitHub's marketing team in APAC automated repetitive event workflows by converting GitHub Issues into self-managing event pipelines using GitHub Copilot and GitHub Actions. The system screens registra…
- Featuregithub.blog
SCIM user responses now include a profileUrl attribute
GitHub now includes a standard profileUrl attribute in SCIM user responses, providing the absolute URL of the linked GitHub account. This eliminates the need for extra lookups to match SCIM records to…
- Featuregithub.blog
Configure cost and quality in Copilot auto model selection
GitHub Copilot’s auto model selection now offers three tiers—efficiency, balance, and intelligence—to let users prioritize cost, quality, or response time per prompt. The feature optimizes model choic…
- github.blog
Add VS Code Agents to Copilot usage metrics
GitHub Copilot usage metrics now include aggregate and user-level reports for VS Code Agents activity, covering 1-day and 28-day periods. These metrics help enterprises and organizations track adoptio…
- cryptobriefing.com
Morpho Midnight releases audit reports on GitHub, showing no critical vulnerabilities
Morpho Midnight published five security audit reports on GitHub, conducted by firms like Spearbit and Blackthorn, revealing no critical vulnerabilities. The protocol, launched in July 2026, uses forma…

- thewindowsclub.com
Top 5 OpenClaw GitHub Repositories & Community Projects
The article highlights five top GitHub repositories and community projects built around OpenClaw, an open-source agent framework. Projects like ScreenPipe, memU, and Archestra expand OpenClaw’s capabi…

- Featureheise.de
Visual Studio Code 1.137: Developers can automate agent tasks
Microsoft released Visual Studio Code 1.137 with new agent-focused features, including automated recurring tasks (e.g., summarizing repository changes) and experimental GitHub Pull Requests integratio…
- Featuregithub.blog
Enforce GitHub Advanced Security configurations
GitHub now lets enterprise admins enforce Advanced Security configurations across organizations, preventing both organization and repository owners from overriding enterprise-level security policies. …
- Featuregithub.blog
Control GitHub Actions cache access with cache-mode
GitHub introduced cache-mode to restrict GitHub Actions cache access at workflow or job levels, preventing unnecessary restores/saves and mitigating cache poisoning risks. The feature is GA across all…
- Featuregithub.blog
Auto-resolution and analysis updates in Copilot code review
GitHub Copilot code review now automatically resolves addressed comments and generates smart commit messages when applying suggestions. Under the hood, it uses an ensemble of agents for Lite reviews a…
- Featuregithub.blog
AI Scan for pull request APIs in public preview
GitHub introduced REST API endpoints to manage AI-powered security scans for pull requests during public preview. Organization and repository-level APIs allow programmatic control over enabling AI Sca…
- Featuregithub.blog
GitHub Copilot app for Beginners: Using the diff, terminal, and browser
GitHub introduced new built-in panels in the Copilot app—diff, terminal, and browser—to streamline reviewing, running, and previewing AI-generated code changes without leaving the app. These panels pr…
- news.ssbcrack.com
Logitech Launches $99 MX Keypad for AI Coding Workflows With GitHub Copilot
Logitech introduced the MX Keypad, a $99.99 nine-key device designed to streamline AI coding workflows by mapping prompts, macros, and agent controls to physical keys. It integrates natively with GitH…

- Sunsetgithub.blog
MAI-Code-1-Flash deprecated
GitHub deprecated the MAI-Code-1-Flash model across all Copilot experiences on September 10, 2026. Enterprise administrators must enable an alternative model via Copilot settings to maintain functiona…
- Technicalgithub.blog
GitHub availability report: August 2026
GitHub faced multiple availability incidents in August 2026, including Actions workflow failures, authentication latency, Copilot task delays, and model provider outages. The company is aggressively m…
- Featuregithub.blog
Block pull requests with exposed secrets from merging
GitHub introduced a new repository ruleset feature that blocks pull requests from merging if they introduce secret scanning alerts. The rule runs on open pull requests and requires developers to resol…
- Featuregithub.blog
GitHub Advanced Security expands trial availability
GitHub Advanced Security trials are now available to enterprises with up to 300 licenses, up from 100, enabling more customers to self-serve evaluate Code Security and Secret Protection features. Tria…
- github.blog
Refreshed repository pull requests page in public preview
GitHub introduced a refreshed repository-level pull requests listing page in public preview, featuring enhanced filtering, search options, and a compact presentation mode. Users can provide feedback o…
- Securitygithub.blog
npm extends recovery-code security holds to all accounts
npm now enforces a 72-hour security hold on all accounts after a recovery-code sign-in, pausing publishing and sensitive writes. Previously limited to high-impact accounts, this change aims to slow ac…
- Securitycybersecuritynews.com
Kimsuky Hackers Use OpenCode AI Agent to Mass-Produce Phishing Decoys in LNK Attacks - CyberSecurityNews
Kimsuky hackers leveraged an AI agent to automatically generate phishing decoys embedded in malicious Windows LNK files, distributing malware via spear-phishing ZIP archives. The campaign used financi…
- github.blog
Company news
GitHub revealed its Universe 2026 event (Oct 28–29, San Francisco) with a live session catalog, introduced a new GitHub Copilot Max plan, shifted Copilot to usage-based billing via AI Credits starting…

- technobezz.com
GitHub Adds Claude Fable 5.1 and Gemini 3.8 Flash to Copilot
GitHub expanded Copilot’s model choices by adding Claude Fable 5.1 to Pro+, Max, Business, and Enterprise tiers, and Gemini 3.8 Flash to Pro and higher tiers. New features include content exclusion su…
- startupfortune.com
GitHub Ships HydraFusion, a Copilot Tool That Mixes AI Models to Cut Costs
GitHub introduced HydraFusion, a Copilot CLI feature that dynamically routes coding tasks across multiple AI models to optimize cost and performance. In benchmarks, it matched or exceeded Claude Opus …

- cryptobriefing.com
GitHub unveils AI coding router with frontier-level quality
GitHub introduced Project HydraFusion, a dynamic multi-model AI coding router for GitHub Copilot, announced September 4, 2026. It optimizes coding tasks across Single, Cascade, and Critique execution …

- venturebeat.com
GitHub’s HydraFusion cuts AI coding costs in every benchmark. It only matches quality in one.
GitHub introduced HydraFusion, a research-preview model-routing feature for Copilot CLI that dynamically constructs execution strategies for coding tasks across multiple models. It reduces estimated c…

- Launchgithub.blog
GitHub Enterprise Server 3.22 is now generally available
GitHub Enterprise Server 3.22 is now generally available, bringing enterprise teams out of public preview to centralize user access management across organizations. New features include sortable secre…
- Featuregithub.blog
Project HydraFusion: Frontier quality via multi-model orchestration
GitHub launched Project HydraFusion, a research preview that dynamically orchestrates multiple AI models to optimize performance, cost, and latency for coding tasks. Available via GitHub Copilot CLI t…
- Featuregithub.blog
Enterprise-managed sandbox in Copilot for JetBrains
GitHub introduced enterprise-managed sandbox policies for Copilot in JetBrains IDEs, allowing admins to centrally control sandbox behavior and enforce development environment boundaries. The update al…
- technobezz.com
GitHub Resolves Incident with Grok Copilot AI Model Provider
GitHub resolved a September 3, 2026 incident where Grok 4.5 and 4.6 models in Copilot Chat, VS Code, and other products suffered degraded availability due to an upstream model provider issue. The outa…
- techspot.com
Microsoft engineer says 'typing code is absolutely over' as GitHub Copilot takes on more development work
GitHub Copilot’s agent now automates environment setup, repository changes, testing, and pull requests, reducing routine coding tasks. Microsoft’s Aspire toolchain and WinUI 3 framework are being enha…

- Eventgithub.com
Events & Webinars
GitHub unveiled its flagship in-person and virtual event lineup, headlined by GitHub Universe 2026 in San Francisco on October 28-29, alongside a series of Copilot-focused webinars and community event…
- Eventinsight.com
WebinarControlling GitHub Copilot SpendSept. 29, 2026 | 12 p.m. ET/9 a.m. PT
Insight announced a webinar on September 29, 2026, to discuss strategies for managing GitHub Copilot costs amid changes to usage-based billing. The session will feature experts from Insight and GitHub…
- hkcert.org
GitHub Enterprise Server Multiple Vulnerabilities
Multiple vulnerabilities in GitHub Enterprise Server were disclosed, allowing remote attackers to bypass security restrictions, execute arbitrary code, and spoof systems. Fixes are available from the …

- github.blog
New customer portal help.github.com
GitHub moved its support portal to a redesigned help.github.com, consolidating support, docs, learning, community, and account resources into one place with Copilot-powered search. The rollout is grad…
- github.blog
Reopening Copilot Business and Enterprise signups
GitHub is gradually reopening sign-ups for Copilot Business and Enterprise plans for credit card and PayPal users over the next two weeks. The change follows account vetting and billing reliability im…
- Featuregithub.blog
Automatic Dependabot access to GitHub-hosted registries
Dependabot can now read from private GitHub Packages registries without a personal access token by reusing repository access granted via 'Manage Actions access'. The feature was temporarily rolled bac…
- Featuregithub.blog
Code scanning adds a mitigated alert dismissal reason
GitHub introduced a new dismissal reason, 'mitigated,' for code scanning alerts to distinguish vulnerabilities with external risk controls (e.g., WAFs) from those marked 'won't fix.' This aligns dismi…
- github.blog
Upcoming deprecation of selected GitHub Copilot models
GitHub announced the deprecation of certain Copilot models across all experiences, effective October 2, 2026. Administrators must enable alternative models in Copilot settings before this date, while …
- Featuregithub.blog
GitHub Copilot app for Beginners: Run several agents at once
GitHub introduced parallel agent sessions in the Copilot app, allowing developers to run multiple independent AI agents simultaneously on separate Git worktrees. Each session maintains its own context…
- Launchgithub.blog
GPT-6 Astra is generally available in GitHub Copilot
GitHub Copilot has introduced OpenAI’s GPT-6 Astra model, designed for long-horizon, autonomous coding tasks. The model plans, validates, and confirms results independently, improving performance on c…
- github.blog
Gemini 3.8 Flash is now available in GitHub Copilot
GitHub integrated Google’s Gemini 3.8 Flash model into GitHub Copilot, offering improved performance on terminal-based coding tasks. The model is available to Copilot Pro, Pro+, Max, Business, and Ent…
- Featuregithub.blog
Remediate Code Quality findings with agentic autofix
GitHub introduced agentic autofix to bulk-remediate up to 25 code quality findings at once using Copilot, which validates changes and opens a PR for review. The feature integrates with existing enterp…
- github.blog
Xcode 27 runner image now runs on macOS 27
GitHub now offers a public preview of its Xcode 27 runner image running on macOS 27 for GitHub-hosted macOS runners, replacing the previous macOS 26 image. Developers targeting Apple apps can validate…
- github.blog
Decoding the new AI lingo: Loops, harnesses, squads, hill climbing… oh my!
GitHub’s blog dissects trending AI development terms like loop engineering, Ralph loops, squads, harnesses, and hill climbing, framing them as emerging patterns in AI-native software workflows. The po…
- blockchain.news
GitHub Optimizes Copilot AI for Cost Efficiency Without Sacrificing Quality
GitHub Copilot updated its AI coding assistant to reduce token usage and operational costs while maintaining task quality, shifting focus from minimizing individual tokens to end-to-end task efficienc…

- cryptobriefing.com
Anthropic’s Claude Skills repository gains 173K+ stars on GitHub
Anthropic’s open-source Claude Skills repository surpassed 173,000 GitHub stars, offering predefined instruction sets for specialized tasks with on-demand loading. The surge reflects growing community…
- Featuregithub.blog
Content exclusions generally available in Copilot app and CLI
GitHub made content exclusion policies generally available in Copilot app and CLI, allowing enterprise and organization admins to block sensitive files from being used as context. The feature is live …
- Featuregithub.blog
How we make AI coding more cost efficient without sacrificing task quality
GitHub Copilot introduced four efficiency-focused changes to reduce AI inference costs without sacrificing task quality. These include selective output compression to preserve useful context, removal …
- Technicalgithub.blog
GitHub CLI Linux package signing key expires September 5
GitHub announced the PGP key for GitHub CLI Linux package repositories expires on September 5, 2026, with a replacement key already published. Users who installed via APT or RPM before April 8, 2026, …
- github.com
Pricing change detected for Github
Pricing updated for Github: - Plan features or structure changed
- github.com
Pricing updated for Github: - Team: promotion changed — First 12 months - Enterprise: promotion changed — First 12 months
- Pricingdevops.com
GitHub Tightens Copilot’s Billing and Governance Rules Ahead of a Busy Fall - DevOps.com
GitHub is shifting Copilot from a feature to enterprise software by introducing upfront seat payments starting September 1, 2026 (October 1 for existing customers), replacing usage-based billing with …
- Launchgithub.blog
Claude Fable 5.1 is generally available in GitHub Copilot
GitHub Copilot now offers Anthropic’s Claude Fable 5.1, a long-horizon coding model optimized for deep codebase research and agentic workflows. The model requires data retention by default for safety …
- Featuregithub.blog
New API endpoint provides privacy-safe star history data
GitHub introduced a new REST API endpoint to retrieve repository star growth data over time while protecting stargazer identities. This follows earlier restrictions on stargazer listing endpoints to s…
- Featuregithub.blog
Enterprise Live Migrations from GHES to ghe.com generally available
GitHub launched Enterprise Live Migrations (ELM), enabling near-zero-downtime repository moves from GitHub Enterprise Server (GHES) to GitHub Enterprise Cloud with Data Residency (GHEC DR). ELM suppor…
- Sunsetgithub.blog
Selected GitHub Copilot models deprecated
GitHub deprecated several Copilot models across most experiences on September 1, 2026, including Copilot Chat, inline edits, and code completions. Users must switch to supported models, with administr…
- Featuregithub.blog
Set an expiration date for individual user budgets
GitHub introduced optional expiration dates for individual user budgets in Copilot Business and Enterprise plans, automating cleanup of temporary overrides. Admins can now set, change, or clear expira…
- github.blog
Enterprise-managed settings support any default model
GitHub now allows enterprises to set a preferred default Copilot model for new conversations, with the ability to customize defaults by team via team-mappings.json. The feature is generally available …
- Restockheise.de
New registrations for GitHub Copilot Business and Enterprise allowed again
GitHub resumed new registrations for Copilot Business and Enterprise on September 1, 2026, after pausing them in April 2026. New seats require upfront payment, with usage-based billing for exceeded AI…
- Featuregithub.blog
Copilot code review can now approve pull requests
GitHub Copilot now includes approval assessments in code reviews, indicating whether a pull request is ready to approve. Admins can enable Copilot to submit formal approvals that count toward merge re…
Suivez GitHub en pilote automatique
- · Brief IA hebdomadaire : résumé narratif de ce qui a été livré, chaque lundi 9 h
- · Alertes par e-mail ou Slack, ou discutez avec l'archive depuis votre tableau de bord
- · Ajoutez GitHub + jusqu'à 2 autres concurrents gratuitement, sans carte bancaire