- technobezz.com
GitHub Investigating Incident Affecting Git Operations Issues Actions and Pull Requests
GitHub experienced a service incident on October 7, 2026, impacting Git Operations, Issues, Actions, and Pull Requests. The issue was resolved within 47 minutes, with widespread impact from 16:52 UTC …
- github.blog
Purpose-built model for leaked secret detection
GitHub introduced a purpose-built AI model for leaked secret detection, integrating context-aware checks into secret scanning alerts, push protection, and GitHub Copilot security reviews. Existing AI-…
- github.blog
Local sandboxing for GitHub Copilot now generally available
GitHub Copilot now offers local sandboxing, a generally available feature enabling secure execution boundaries for agentic workflows on developers' machines. Tools and commands initiated by Copilot ru…
- github.blog
Discover local models in GitHub Copilot CLI
GitHub Copilot CLI v1.0.94-0 introduces /modelto discover and select local models from a running Ollama instance, alongside cloud models. Users must manually add and confirm models, which support tool…
- technobezz.com
GitHub Adds Claude Haiku 5.5 to Copilot for Quick Coding Tasks
GitHub made Anthropic’s Claude Haiku 5.5 generally available in GitHub Copilot, targeting fast, high-volume coding edits, terminal tasks, and subagent workflows. The model is accessible across Copilot…
- newsbytesapp.com
Thomas Dohmke launches entire, decentralized GitHub alternative for AI coding
Thomas Dohmke, former GitHub CEO, launched Entire, a decentralized platform addressing AI coding tool limitations by hosting code across regional hubs for speed and reduced bottlenecks. It integrates …

- note.com
The difference between Codex and GitHub Copilot: Which one should your company sign up for? The deciding factor was 'where you ask for work to be done'|Codex Studio
A third-party analysis clarifies that GitHub Copilot operates within GitHub (via GitHub AI Credits) while OpenAI Codex is accessed via ChatGPT plans, with Codex also usable within GitHub via Copilot s…

- Featuregithub.blog
Secret protection must scale with software
GitHub reports that one in three pull requests now involves an AI agent, accelerating code creation and secret exposure risks. To address this, GitHub introduces a fine-tuned ModernBERT classifier tha…
- Featuregithub.blog
GitHub Copilot CLI version 1.0.94-0 introduces a /modelto command to discover and select local models from a running Ollama instance, alongside cloud models. Users must manually add and confirm models
- Featuregithub.blog
GitHub announced general availability of local sandboxing for GitHub Copilot across CLI, the Copilot app, and VS Code sessions. The feature restricts Copilot-initiated tools and commands to a secure e
- Featuregithub.blog
GitHub launched a purpose-built AI model for secret detection that analyzes surrounding code to identify leaked credentials, including non-standard formats. The model powers AI-detected secret alerts
- Featuregithub.blog
Claude Haiku 5.5 in GitHub Copilot
GitHub Copilot now includes Anthropic’s Claude Haiku 5.5, a lightweight model optimized for fast, high-volume tasks like subagents and terminal edits. Early tests show it matches Sonnet 5 performance …
- github.blog
Update your IDE to restore agent activity in Copilot usage metrics
GitHub identified an issue where Copilot agent activity was misattributed in usage metrics due to IDEs moving agent sessions to the Copilot SDK without proper IDE identification. A fix is rolling out …
- github.blog
Stacked pull requests generally available
GitHub announced the general availability of stacked pull requests, allowing developers to break large changes into smaller, independent PRs for easier review and merging. Repositories using stacks sa…
- linuxiac.com
Over Half a Million Credentials Leaked on GitHub Remain Active
Truffle Security found 543,699 valid credentials in GitHub repositories, with some active for over 16 years. GitHub’s push protection reduced supported leaks by 53%, but 199,843 credentials were commi…

- newsbytesapp.com
Former GitHub CEO Thomas Dohmke brings entire to tackle outages
Thomas Dohmke, former GitHub CEO, unveiled Entire, a decentralized Git platform designed to mitigate GitHub outages by distributing code hosting globally. The preview launches July 8, 2026, with hubs …

- github.blog
Code scanning AI Scan enablement status in security overview
GitHub introduced a new feature in its security overview that shows AI Scan for pull requests enablement status. Organization and enterprise admins can now view enabled and not enabled repository coun…
- helpnetsecurity.com
GitHub’s ReviewBench puts AI code reviewers to the test
GitHub introduced ReviewBench, a benchmark for evaluating AI code review agents, available in research preview. It tests 219 pull requests across 19 languages, measuring precision, recall, and F1 scor…

- github.blog
GitHub Copilot weekly releases — September 28
GitHub introduced new Azure canvases in the Copilot app for resource queries, cost health checks, and Azure Functions skills, along with VS Code Copilot 1.140 updates. These features enable automated …
- Technicalgithub.blog
Building Git infrastructure for agent-scale development
GitHub is overhauling its Git infrastructure to support agentic software development, driven by a 2x surge in total Git activity (218.2B to 473.3B events/month) and 7.38B commits in September 2026 alo…
- technobezz.com
GitHub Investigating Disruption Affecting Some Services
GitHub experienced a service disruption on October 5, 2026, impacting access to organization and enterprise billing and licensing pages. The incident was resolved by 9:32 p.m. Eastern, with a root cau…
- note.com
GitHub Releases 'ReviewBench': Thinking About AI Code Review Misses and False Positives Through 219 PRs
GitHub released ReviewBench, a research-preview tool to evaluate AI code review performance using 219 PRs from 187 repositories across 19 languages. It measures precision, recall, and F1 against a fix…

- github.blog
Secret scanning adds detectors for Lovable, Supabase, and more
GitHub added secret scanning detectors for Lovable Labs, Pydantic Services Inc., and Supabase, enabling automatic detection of exposed credentials in repositories. Partner secrets are reported to issu…
- Featuregithub.blog
GitHub now shows AI Scan for pull requests enablement status in the security overview coverage view for organizations and enterprises. The feature provides counts of enabled/disabled repositories and
- Featuregithub.blog
ReviewBench: An open benchmark for AI code review
GitHub introduced ReviewBench, an open benchmark for evaluating AI code review agents, built using data from 103.9 million real GitHub pull requests. The benchmark includes 219 public pull requests ac…
- note.com
Talking on Slack turns directly into GitHub work?? Copilot connects 'Conversation → Issue → Implementation'
GitHub updated GitHub Copilot on September 25, 2026, to enable direct workflows from Slack conversations to GitHub issues and pull requests. Copilot now reads Slack context (files, attachments, links)…

- github.blog
Stateless GitHub App installation tokens rolled out
GitHub finished rolling out stateless installation tokens for GitHub Apps, replacing the legacy format with a new 520-character token starting with 'ghs_'. The change improves API reliability and toke…
- Featuregithub.blog
Copilot code review: API support and new default effort level
GitHub introduced API support for Copilot code review via REST and GraphQL, enabling automated reviews in custom workflows. The default review effort level is now Balanced for all plans, replacing the…
- github.blog
Unvalidated npm trusted publishing configurations now expire
GitHub now enforces a 48-hour expiry on unvalidated npm trusted publishing configurations, requiring revalidation after ownership changes or failed publishes. Validated configurations are exempt, but …
- github.blog
npm staged publishing now supports creating new packages
GitHub’s npm now allows creating new packages directly via `npm stage publish`, supporting public scoped/unscoped and private scoped packages. The first version enters a staged queue requiring maintai…
- Sunsetgithub.blog
Selected models in GitHub Copilot deprecated
GitHub deprecated specific models in all GitHub Copilot experiences on October 2, 2026, requiring users to switch to supported alternatives. Enterprise admins must enable access to new models via Copi…
- github.blog
New fields for SecurityAdvisory GraphQL API
GitHub expanded its SecurityAdvisory GraphQL API with five new fields and two new filters (severities and isWithdrawn), enabling server-side filtering of advisory data. This reduces round trips, simpl…
- github.blog
Confidential comments on repository security advisories
GitHub introduced confidential comments on repository security advisories, visible only to users with write access. Previously, all comments were public to collaborators, complicating internal discuss…
- github.blog
Repository security advisory comments API in public preview
GitHub introduced a new REST API for reading, adding, and editing comments on repository security advisories, including those from private vulnerability reports. The API now includes comment counts in…
- note.com
[IT News] GitHub Copilot can now operate desktop apps, released in public preview
GitHub Copilot now supports operating desktop applications through a new 'computer use' feature in public preview, enabling Copilot to read screens, click controls, enter text, and execute workflows a…

- sofx.com
AI Agents Leak 13,000 Internal Corporate Screenshots via Public GitHub Repositories
AI coding agents inadvertently posted over 13,000 internal screenshots to public GitHub repositories across 300+ organizations, exposing sensitive data like billing records and unreleased features. Th…
- Featuregithub.blog
GitHub finished rolling out stateless installation tokens for GitHub Apps, replacing the legacy format with a new 520-character token starting with ghs_ and using the statelessghs_APPID_JWT structure.
- github.blog
GitHub added REST and GraphQL API support for initiating Copilot code reviews, enabling integration into custom workflows. The default review effort level is now Balanced for new and existing reposito
- Featuregithub.blog
GitHub now enforces a 48-hour expiry for unvalidated npm trusted publishing configurations, requiring a successful publish to validate and avoid expiration. Expired configurations remain visible but i
- Featuregithub.blog
GitHub’s npm staged publishing now allows creating new packages directly via `npm stage publish`, supporting local sessions, granular access tokens, and stage-only tokens. This enables automated workf
- Featuregithub.blog
GitHub identified a bug where Copilot agent activity in IDEs using the Copilot SDK was misattributed or excluded from usage metrics. A fix is rolling out now, starting with Visual Studio Code, with ot
- Contentgithub.blog
AI is rewriting the developer career ladder. Here’s how to stand out.
GitHub argues AI is changing developer success factors from pure coding to directing AI, evaluating outputs, and making technical tradeoffs. The post provides actionable tips for developers to adapt, …
- Featuregithub.blog
GitHub expanded its SecurityAdvisory GraphQL API with five new fields on the SecurityAdvisory object and two new filters (severities and isWithdrawn) for the SecurityAdvisories query. These changes en
- github.blog
GitHub introduced a REST API to read, add, and edit comments on repository security advisories, including those from private vulnerability reports. The API now includes comment counts in responses, he
- cryptobriefing.com
NEAR AI Cloud brings private inference to GitHub Copilot through a VSCode extension
GitHub Copilot now supports NEAR AI Cloud through a VSCode extension, enabling private inference via hardware-secured enclaves (TEEs) for prompts, model weights, and outputs. The integration leverages…

- github.blog
Rate limits for private vulnerability reports
GitHub introduced rate limits for private vulnerability reports to combat low-quality and automated submissions that overwhelm maintainers. The feature caps daily report submissions per account, both …
- technobezz.com
GitHub Copilot Gains Computer Use for Desktop Apps
GitHub Copilot now supports direct interaction with desktop applications via a new 'computer use' feature in public preview for CopilotCLI and the Copilot app on macOS and Windows. It can automate GUI…
- technobezz.com
GitHub Actions Job Delays Under Investigation
GitHub Actions experienced run-start delays on October 1, 2026, initially affecting Ubuntu runners and later recurring on Windows runners. The root cause was identified as 429 errors from an upstream …
- technobezz.com
GitHub reports elevated request latency incident now resolved
GitHub experienced elevated request latency for web requests on October 1, 2026, which was resolved within 20 minutes. The incident was investigated, mitigated, and marked resolved by 9:57 a.m. Easter…
- newsbytesapp.com
Thomas Dohmke launches Entire to decentralize GitHub and reduce outages
Thomas Dohmke, former GitHub CEO, launched Entire, a decentralized Git alternative designed to reduce outages and server strain by distributing repos globally. It supports tools like Codex and Copilot…

- newsbytesapp.com
Former GitHub CEO Thomas Dohmke launches entire decentralized Git network
Thomas Dohmke, ex-GitHub CEO, unveiled Entire, a decentralized Git network designed to mitigate GitHub outages by distributing repositories globally. The platform mirrors 570,000 clones per hour and i…

- techgig.com
Over 543,000 valid credentials exposed on GitHub despite security measures
GitHub disclosed that over 543,000 valid credentials were exposed on its platform despite existing security measures. The incident highlights ongoing challenges in preventing credential leaks even wit…

- bitdefender.com
PixelLeak exposes 13,000 internal screenshots on GitHub
A third-party report (PixelLeak) revealed that AI coding agents uploaded 13,000 internal screenshots from over 300 organizations to public GitHub repositories, exposing billing records and unreleased …
- Featuregithub.blog
Actions retention now covers checks, runs, and statuses
GitHub expanded its Actions retention policy to cover checks, workflow runs, and statuses, aligning them with existing artifact and log retention settings. The unified retention period applies to both…
- Featuregithub.blog
GitHub is adding rate limits to private vulnerability reports to curb automated and low-quality submissions that overwhelm maintainers. The feature is available for public repositories with private vu
- Sunsetgithub.blog
GitHub Actions: macOS 14 runner image retirement
GitHub will retire its macOS 14 runner image for GitHub Actions on November 2, 2026, with temporary job failures during brownout periods leading up to the date. Users must migrate workflows to newer m…
- github.blog
Structured forms for private vulnerability reports
GitHub introduced structured forms for private vulnerability reports, requiring reporters to fill four fields: summary, details, proof of concept (150+ chars), and impact. This replaces a free-text bo…
- Featuregithub.blog
GitHub introduced confidential comments for repository security advisories, visible only to repository collaborators with write access. This allows teams to discuss sensitive details privately without
- github.blog
GitHub Copilot in VS Code, September 2026 releases
GitHub shipped VS Code v1.136–v1.140 in September 2026, introducing agent-driven development workflows in Copilot. New features include automated task scheduling, agent-assisted pull request creation …
- Featuregithub.blog
GitHub Copilot can now interact with desktop apps with computer use
GitHub Copilot now supports computer-use automation in public preview, enabling it to interact with desktop applications on macOS and Windows. The feature can read app content, click controls, enter t…
- xenospectrum.com
AI Agents Exposed 13,000+ Internal Images From 300+ Organizations on GitHub, Glow Reports
A security study by Glow found AI coding agents uploaded over 13,000 internal images from 300+ organizations to public GitHub repositories, exposing sensitive data like billing records and unreleased …

- Featuregithub.blog
GitHub added secret scanning detectors for Lovable Labs, Pydantic Services Inc., and Supabase, enabling automatic detection of their secrets in public repositories. Partner secrets are forwarded to is
- Featuregithub.blog
GitHub announced the general availability of stacked pull requests, allowing developers to break large changes into smaller, independently reviewable PRs. Early adopters saw a 9% increase in merged co
- Sunsetgithub.blog
GitHub deprecated specific models in GitHub Copilot as of October 2, 2026, affecting all Copilot experiences including chat, inline edits, and code completions. Enterprise admins must enable alternati
- Featuregithub.blog
Dynamic workflows in Copilot CLI and the Copilot app
GitHub introduced dynamic workflows in Copilot CLI, the Copilot app, and the Copilot SDK, enabling code-defined orchestration of multi-agent tasks with reliability and observability. Users can now def…
- Eventgithub.blog
10 technical talks I’m excited about at GitHub Universe 2026
GitHub announced the session catalog for its upcoming Universe 2026 event (Oct 28–29, San Francisco/hybrid), featuring 10 technical talks focused on AI agent development, JavaScript tooling, and suppl…
- Featuregithub.blog
New dashboard experience now the default
GitHub has made its redesigned dashboard the default view for all users, replacing the previous experience. The update aims to improve focus and ease of navigation, with an option to revert to the old…
- Featuregithub.blog
Code coverage uploads no longer fail CI for new branches
GitHub modified its Code Quality upload-code-coverage action to stop failing CI when pushing a branch without an open pull request. Instead, the upload step skips and explains the reason, while defaul…
- Featuregithub.blog
Scheduled code scanning skips inactive repositories
GitHub changed scheduled code scanning to trigger only after pushes or PRs, not unscheduled scans like initial validation or language changes. This reduces unexpected weekly scans on dormant repositor…
Suivez GitHub en pilote automatique
- · Brief IA hebdomadaire : résumé narratif de ce qui a été livré, chaque lundi 9 h
- · Alertes par e-mail ou Slack, ou discutez avec l'archive depuis votre tableau de bord
- · Ajoutez GitHub + jusqu'à 2 autres concurrents gratuitement, sans carte bancaire