GitHub Release Notes

Follow

864 release notes curated from 102 sources by the Releasebot Team. Last updated: Sep 12, 2026

Get this feed:

GitHub Products

  • Sep 11, 2026
    • Date parsed from source:
      Sep 11, 2026
    • First seen by Releasebot:
      Sep 12, 2026
    GitHub logo

    Copilot CLI by GitHub

    1.0.84-5

    Copilot CLI adds session and memory import commands, improves shell completions, and refines sandbox, MCP, streaming, and subagent behavior. It also brings better usage reporting, model selection, and remote session controls for a smoother CLI experience.

    Added

    Add session and memory import commands for the semantic JSONL interchange format

    Improved

    Shell completions are generated from the same grammar the CLI parses with, so copilot <TAB> offers root flags alongside subcommands and each subcommand offers only its own options

    Command-line parsing moved from Commander to a Rust grammar; error and help wording changed, copilot login --host now works, and --max-autopilot-continues no longer accepts scientific notation

    Show /sandbox filesystem paths as absolute paths; typing ~/path still expands to your home directory

    Move the /sandbox Filesystem paths into their own list, opened from a Paths row

    Show trust status, tier, and eligibility details for online resource catalogue results

    /usage shows per-model AI Credit consumption in usage breakdowns

    Improve /sandbox guidance and show /sandbox policy in command help

    Fixed

    Subagent launches honor explicit model, reasoning effort, and context tier preferences from applicable global and custom instructions

    A failed command whose EPERM or EACCES diagnostic names a sandbox-blocked path now offers to run outside the sandbox, even when the command line never named that path

    A write blocked by a read-only sandbox path, and a Node or Go network failure blocked by the sandbox, are now recognized as sandbox denials instead of surfacing as raw errors

    Report in-memory MCP servers as memory instead of local in copilot mcp list

    /compact no longer reports an empty model response when a valid summary was returned

    Streaming responses preserve message chunk ordering before final output.

    Retry responses keep the correct streamed message and reasoning after mid-stream model failures

    Workspace .mcp.json servers load correctly after trusting a folder on startup

    When image-heavy requests exceed model limits, user-provided images are prioritized over tool-generated images, newer messages are kept first, and the CLI reports any removals.

    Plugin-contributed agents discovered by the CLI can now be selected and run.

    Fixed same-turn MCP tool-list refresh after received change notifications, including modern subscription-based servers.

    The remote session timeline entry now advertises ctrl+o to show or hide the QR code, matching the key that actually toggles it

    Original source
  • Sep 11, 2026
    • Date parsed from source:
      Sep 11, 2026
    • First seen by Releasebot:
      Sep 11, 2026
    GitHub logo

    GitHub

    Add VS Code Agents to Copilot usage metrics

    GitHub adds generally available VS Code Agents metrics to Copilot usage reports, giving enterprises and organizations new ways to track adoption, activity, session counts, and user engagement in the dedicated VS Code Agents window.

    What’s new

    GitHub Copilot usage metrics reports now include generally available metrics for activity in the dedicated VS Code Agents window, helping you measure adoption and engagement across enterprises and organizations.

    Aggregate enterprise and organization reports for both 1-day and 28-day periods now include:

    • daily_active_vscode_agent_users: An optional count of unique users active in the VS Code Agents window each day.
    • totals_by_vscode_agent: Optional aggregate of session_count and total_user_messages values.

    Enterprise-user and organization-user reports for both 1-day and 28-day periods now include:

    • used_vscode_agent: An optional indicator of whether the user used the VS Code Agents window.
    • totals_by_vscode_agent: Optional per-user session_count and total_user_messages values.

    Why this matters

    These metrics help you understand how many people use the VS Code Agents window and how they engage with it. You can use the aggregate reports to track adoption and activity trends, then use the user-level reports to understand usage across teams.

    Important notes

    These metrics cover the dedicated VS Code Agents window only. They remain separate from editor-window Agent Mode and generic usage rollups.

    Missing-data behavior is backward compatible — optional fields remain absent or null when corresponding VS Code Agents-window data is unavailable.

    Access is available to enterprise owners and billing managers, organization owners, and anyone with a custom organization or enterprise role granting View Copilot Metrics. The Copilot usage metrics policy must be enabled.

    Visit the Copilot usage metrics API documentation to get started.

    The post Add VS Code Agents to Copilot usage metrics appeared first on The GitHub Blog.

    Original source
  • All of your release notes in one feed

    Join Releasebot and get updates from GitHub and hundreds of other software products.

    Create account
  • Sep 11, 2026
    • Date parsed from source:
      Sep 11, 2026
    • First seen by Releasebot:
      Sep 11, 2026
    GitHub logo

    GitHub

    Auto-resolution and analysis updates in Copilot code review

    GitHub adds smarter Copilot code review with automatic resolution of addressed comments, smart commit messages for applied suggestions, deeper validation with shell tools, and a multi-agent Lite review setup for more thorough feedback and fewer nits.

    Copilot code review now resolves its own comments once you address them and writes smart commit messages for you when you apply its code suggestions. Behind the scenes, Copilot now uses a broader set of shell tools to validate the code it reviews, and an ensemble of agents produce a more thorough review within the Lite effort level. Together, these updates make it easier to focus on the feedback that still matters and give Copilot more ways to check its work.

    Review experience updates

    ✅ Automatic resolution of addressed comments

    When you push a commit that addresses a Copilot code review comment, Copilot now resolves that comment during its rereview. Instead of manually resolving threads that are no longer relevant, you can now rely on the open comments to reflect only the feedback that still needs your attention.

    Comments are automatically resolved when a later commit addresses the underlying feedback.

    Feedback that is still outstanding stays open, so nothing gets lost.

    Smart commit messages on Copilot autofix suggestions

    When you apply a suggestion provided by a Copilot code review comment, instead of auto-filling the standard commit message, Copilot now generates a smart suggestion based on what it’s changing.

    🔧 Analysis updates

    The following changes only improve the quality of reviews you receive and do not affect how you request or receive reviews.

    Deeper analysis with shell tools

    Building on the file-reading tools already used during review, Copilot code review now uses the full set of shell tools from the Copilot SDK, running behind the Copilot agent firewall. This gives the review agent more ways to validate the code under review (e.g., running build commands, running tests, executing targeted scripts, and retrieving information from available tools and APIs).

    Our experiments with this change showed that developers left more positive feedback on Copilot’s comments, and Copilot surfaced more high severity findings and fewer nits.

    Ensemble of agents in Lite reviews

    The Lite effort level now uses an ensemble of agents to produce a review rather than one agent working alone. Each agent contributes its own perspective on the code, and Copilot combines their findings into a single review. This makes Lite reviews more thorough and accurate for the same or often lower cost.

    In our experimentation, the ensemble approach increased the average number of addressed comments per review by 47% for high severity findings, 31% for medium, and 11% for low, while reducing review cost by about 8%.

    The post Auto-resolution and analysis updates in Copilot code review appeared first on The GitHub Blog.

    Original source
  • Sep 10, 2026
    • Date parsed from source:
      Sep 10, 2026
    • First seen by Releasebot:
      Sep 11, 2026
    GitHub logo

    GitHub

    GitHub Copilot weekly releases — September 7

    GitHub releases a Copilot weekly update with Jira integration in the Copilot app, adaptive model orchestration in Copilot CLI, new agent automations and voice mode in VS Code, and expanded enterprise controls for Copilot in JetBrains.

    This week, GitHub Copilot introduces Jira integration in Copilot app and adaptive model orchestration with Project HydraFusion in Copilot CLI. We also introduced new agent automation in Visual Studio Code and expanded enterprise controls for Copilot in JetBrains.

    GitHub Copilot app

    Turn Jira issues into action. Bring Jira issues into a shared canvas, choose what moves forward, and let Copilot carry the context into investigation, implementation, and pull request preparation.

    Download the Copilot app.

    GitHub Copilot CLI

    Project HydraFusion is now in /experimental. HydraFusion delivers automated semantic routing between local, cloud, and compound models. You select HydraFusion like any other model, and it chooses a workflow that balances performance, cost, and latency for each task.

    To learn more, read the Project HydraFusion blog post.

    Install Copilot CLI.

    VS Code 1.137 release updates

    Schedule recurring agent tasks to run hourly, daily, or weekly, or run them on demand with automations, now in public preview.

    Voice mode is now in experimental so you can talk to, interrupt, or redirect Copilot while it works on your code.

    New in experimental, review issue and pull request details directly in the Agents window, even when the repository is not open.

    Explore everything that’s new in the full release notes.

    GitHub Copilot in JetBrains

    Now in public preview, enterprise administrators can centrally configure sandbox behavior for GitHub Copilot in JetBrains IDEs. Managed policies can control sandbox enablement, filesystem and network access, proxy settings, developer-tool access, macOS Keychain access, and more.

    Learn more in the previous Copilot in JetBrains changelog.

    The post GitHub Copilot weekly releases — September 7 appeared first on The GitHub Blog.

    Original source
  • Sep 10, 2026
    • Date parsed from source:
      Sep 10, 2026
    • First seen by Releasebot:
      Sep 11, 2026
    GitHub logo

    GitHub

    GitHub Copilot app for Beginners: Using the diff, terminal, and browser

    GitHub now supports review, run, and preview side by side in the GitHub Copilot app, bringing diffs, terminal commands, and browser testing into one place for a smoother AI coding loop.

    Checking agent-generated code usually means hopping between tabs. Learn how to view diffs, run terminal commands, and preview web apps side by side in the GitHub Copilot app.

    When an agent makes a change to your code, you want to review it, run it, and see what changed. Great news: now you can do all three without having to leave the GitHub Copilot app.

    Before, doing those three jobs would mean having to bounce between your editor, terminal window, and web browser. But when these steps live side by side as built-in panels in the Copilot app, checking your agent’s work is simple.

    Let’s walk through each of the panels in the app and how we’ll use them to complete the AI coding loop.

    Using the diff panel to review changes

    The diff panel (a diff is a before and after comparison) shows exactly what lines were added, removed, or changed, with additions highlighted in green and deletions in red.

    This gives you complete clarity, so you can choose what happens. You can accept changes, leave comments, or ask Copilot to make changes. You’re in complete control and make the final decisions.

    Running commands in the terminal panel

    Reading code is good, but running it is even better. You can run commands right inside the session from the Copilot app’s terminal panel. And if it looks intimidating, don’t worry. You’re mostly just running the project’s own commands and reading the results.

    You can run the code by hand or configure it as a script (available through the Run button). Pretend you’re working on a website, here’s an example of how that works:

    • Add the dev server script that opens the client folder and then runs npm run dev.
    • Click Run to start the server for the website.

    You can have multiple terminal windows open at once, so you can switch between them and keep running commands.

    Using the pick & polish tool in the browser panel

    For anything that has a user interface, the browser panel closes the loop. And for our website example: this panel means you can open it and test your new feature as if you were using the site.

    If you want to keep iterating, you can use the Pick & Polish tool to select an element and adjust it with the agent.

    And to see what got fixed, you can run the dev server script again after you’ve made changes.

    Closing the loop of reviewing AI code

    Now you’ve reviewed the diff, started the project in the terminal, reviewed it in the browser, and iterated to get it to a working feature. Once you’ve gotten it where you want, you can accept the change directly from the Copilot app and create a pull request. Completing this loop from one place means there’s no tab hopping, switching apps, or losing your place.

    Having review, run, and preview side by side is what makes agent-made changes feel safe instead of scary, because you can prove that what you’re merging works.

    Take this with you

    These built-in panels answer three important questions you should always ask before you accept an agent’s work.

    • What’s changed?
    • Does it run?
    • And does it actually work?

    Running through this list before accepting agent-generated code will help you understand what changed and whether it functions the way you want, keeping you in control.

    Try using the GitHub Copilot app >

    Original source
  • Similar to GitHub with recent updates:

  • Sep 10, 2026
    • Date parsed from source:
      Sep 10, 2026
    • First seen by Releasebot:
      Sep 10, 2026
    GitHub logo

    GitHub

    Refreshed repository pull requests page in public preview

    GitHub introduces a refreshed repository pull request listing page in public preview, with smarter filtering, advanced search, a collapsible sidebar, compact presentation mode, and richer context to help users find and act on pull requests faster.

    A refreshed repository-level pull request listing page is now in public preview for all GitHub users. It brings powerful filtering, compact presentation mode, and more.

    Highlights

    The new page makes it easier to find and act on pull requests in a repository, with new filtering and search options to help you find exactly what you’re looking for:

    • Content assist helps you easily find and apply the correct filters.
    • Advanced search supports AND and OR keywords as well as nested searches.
    • Collapsible sidebar gives you quick access to common filters (e.g., “Authored by me” and “Involves me”).
    • Compact presentation mode lets you fit more pull requests on the page.
    • More context including status check counts, stack indicator, and indicators for unread updates.

    Known limitations

    There are some known issues and feature gaps we are working to address:

    • Milestones currently not shown
    • Bulk updates currently not available
    • Emojis in labels do not always appear
    • Saving custom views not currently supported

    We want to hear from you

    Your feedback helps us improve the experience during the public preview. Click the Preview badge at the top of the page, then select Give feedback to let us know what you think and how we can improve the experience.

    If you need to return to the classic experience, click the Preview badge at the top of page, and choose the Switch back option.

    The post Refreshed repository pull requests page in public preview appeared first on The GitHub Blog.

    Original source
  • Sep 10, 2026
    • Date parsed from source:
      Sep 10, 2026
    • First seen by Releasebot:
      Sep 10, 2026
    GitHub logo

    GitHub

    AI Scan for pull request APIs in public preview

    GitHub adds public preview REST APIs for AI Scan for pull requests, letting teams manage organization and repository enablement for code scanning at scale and roll out AI-powered security detections without manual UI setup.

    You can now manage GitHub code scanning’s AI Scan for pull request enablement with REST API endpoints at the organization and repository levels. This public preview gives teams a programmatic way to roll out AI-powered security detections for pull requests across select repositories without manually configuring each setting in the GitHub UI.

    Manage AI Scan for pull requests at scale

    Use the new organization and repository APIs to read and update whether AI Scan for pull requests is enabled. Organization settings control whether pull request scans can run across the organization, and repository settings let you turn scans on or off for individual repositories. Repository settings do not override an organization-level disabled state.

    To view and update the status of AI Scan for selected repositories, users can use the /orgs/{org}/code-scanning/ai-scan and /repos/{owner}/{repo}/code-scanning/ai-scan endpoints.

    This public preview is available on github.com for GitHub Advanced Security customers. GitHub Enterprise Server is not supported for this release. For more information, see AI Scan security detections.

    Join the discussion and leave feedback on the announcement in GitHub Community.

    The post AI Scan for pull request APIs in public preview appeared first on The GitHub Blog.

    Original source
  • Sep 10, 2026
    • Date parsed from source:
      Sep 10, 2026
    • First seen by Releasebot:
      Sep 10, 2026
    GitHub logo

    GitHub

    Control GitHub Actions cache access with cache-mode

    GitHub adds cache-mode for GitHub Actions, bringing least-privilege cache access at the workflow or job level. The generally available feature helps limit restores and saves, reduce cache poisoning risk, and is now available on all GitHub plans.

    You can now use cache-mode to apply least-privilege access to the GitHub Actions cache at the workflow or job level. By granting each workflow or job only the cache access it needs, you can prevent unnecessary restores or saves and help protect trusted workflows from cache poisoning. This capability is now generally available on all plans.

    Choose the access each workflow or job needs:

    • read allows cache restores but prevents cache saves. This is the default for low-trust events such as pull_request_target.
    • write allows cache restores and saves. This is the default for trusted events such as push.
    • write-only allows cache saves but prevents cache restores.
    • none prevents all cache access.

    Job-level settings override workflow-level settings. The selected mode is enforced by the cache service and carries through reusable workflows, where a called workflow cannot receive more cache access than its caller granted.

    An explicitly declared cache-mode also overrides the read-only cache default for low-trust events such as pull_request_target. Declaring write or write-only for these events can increase the risk of cache poisoning, so GitHub Actions adds a warning annotation when the declared mode grants write access. Workflows that do not set cache-mode continue to use the existing secure defaults.

    Cache mode is generally available on github.com for all GitHub plans. For configuration details, see the cache-mode workflow syntax documentation.

    Join the discussion within GitHub Community

    The post Control GitHub Actions cache access with cache-mode appeared first on The GitHub Blog.

    Original source
  • Sep 10, 2026
    • Date parsed from source:
      Sep 10, 2026
    • First seen by Releasebot:
      Sep 10, 2026
    GitHub logo

    GitHub

    Xcode 27 runner image now runs on macOS 27

    GitHub adds the Xcode 27 runner image on macOS 27 for validating Apple apps in public preview.

    You can now validate your Apple apps against macOS 27 using the Xcode 27 runner image for GitHub-hosted macOS runners, available in public preview. The image previously ran on macOS 26.

    How you target the image stays the same

    Keep using the following labels in your workflow’s runs-on: value:

    • xcode-27
    • xcode-27-xlarge

    This image runs on arm64 macOS runners only. To view the full list of installed software or report an issue, visit the runner-images repository.

    The post Xcode 27 runner image now runs on macOS 27 appeared first on The GitHub Blog.

    Original source
  • Sep 10, 2026
    • Date parsed from source:
      Sep 10, 2026
    • First seen by Releasebot:
      Sep 10, 2026
    GitHub logo

    Copilot CLI by GitHub

    1.0.84-4

    Copilot CLI adds clearer plugin and assistant management with new instruction, LSP, plugin marketplace, MCP, and skill commands, plus JSON output updates. It also improves sandbox status, startup behavior, and indexed search across Windows and Linux, while removing older mixed-kind plugin flags.

    Added

    Add copilot instruction list and copilot lsp list, replacing copilot plugins list --kind instruction and --kind lsp

    Add --json to copilot plugin list, copilot plugin marketplace list and copilot plugin marketplace browse

    Add enable and disable to copilot plugin, copilot mcp and copilot skill, replacing copilot plugins enable/disable --plugin|--mcp|--skill

    Fixed

    Show when sandboxing is only enabled for the current session in /sandbox status and settings.

    Interactive --yolo startup remains available before authentication when no managed policy evidence is present

    Indexed search shows when enabled, works on Windows ReFS volumes, supports explicit cloud-sync overrides, and keeps refreshing on Linux when native file watches are exhausted.

    Removed

    Replace copilot plugins install --skill [--scope project] with copilot skill add [--project]; the --scope spelling is gone

    Remove the cross-kind --kind, --scope, --mcp and --skill flags from copilot plugins; use copilot mcp and copilot skill

    copilot plugins list --json now emits a flat array of plugins instead of the cross-kind { plugins, errors } object; scripts reading .plugins must be updated

    copilot plugins list is now an alias of copilot plugin list and reports only plugins, no longer MCP servers, skills, instructions or LSP servers

    Original source
  • Sep 10, 2026
    • Date parsed from source:
      Sep 10, 2026
    • First seen by Releasebot:
      Sep 2, 2026
    • Modified by Releasebot:
      Sep 10, 2026
    GitHub logo

    GitHub

    MAI-Code-1-Flash deprecated

    GitHub deprecates MAI-Code-1-Flash across Copilot experiences and points users to MAI-Code-1.1-Flash as the supported alternative. Enterprise admins may need to enable the replacement model in Copilot settings.

    We have deprecated MAI-Code-1-Flash across all GitHub Copilot experiences (including Copilot Chat, inline edits, ask and agent modes, and code completions) today, September 10, 2026.

    Model

    Deprecation date

    Suggested alternative

    MAI-Code-1-Flash

    2026-09-10

    MAI-Code-1.1-Flash

    Please update your workflows and integrations to use a supported model. Copilot Enterprise administrators may need to enable access to the alternative model through their model policies in Copilot settings. As an administrator, you can verify availability by checking your individual Copilot settings and confirming that the policy is enabled for the specific model. Once enabled, you’ll see the model in the Copilot Chat model selector in VS Code and on github.com. No action is required to remove the deprecated model.

    GitHub Enterprise customers with questions or concerns are encouraged to reach out to their account manager for further assistance.

    Share your feedback

    To learn more about the models available in Copilot, see our documentation on models and get started with Copilot today.

    Join the GitHub Community Discussion to share your feedback.

    The post MAI-Code-1-Flash deprecated appeared first on The GitHub Blog.

    Original source
  • Sep 9, 2026
    • Date parsed from source:
      Sep 9, 2026
    • First seen by Releasebot:
      Sep 10, 2026
    GitHub logo

    GitHub

    npm extends recovery-code security holds to all accounts

    GitHub says npm now adds a temporary 72-hour security hold to all accounts after a successful recovery-code sign-in, pausing publishing and other sensitive writes while sign-in, browsing, and installs still work.

    npm now places a temporary 72-hour security hold on any account after a successful recovery-code sign-in, extending a protection that previously applied only to high-impact accounts. This change applies to all npm accounts.

    During the hold, publishing and other security-sensitive writes, including creating access tokens, are paused. You can still sign in as well as browse and install packages. The hold expires automatically — no action or support request is needed to restore full access.

    This extension builds on the preventive account protection npm introduced for high-impact accounts, further slowing account-takeover attempts and reducing the risk of malicious publishing from a compromised recovery code.

    If you’re unexpectedly blocked from publishing and you didn’t use your recovery code to sign in, contact npm Support right away.

    The post npm extends recovery-code security holds to all accounts appeared first on The GitHub Blog.

    Original source
  • Sep 9, 2026
    • Date parsed from source:
      Sep 9, 2026
    • First seen by Releasebot:
      Sep 10, 2026
    GitHub logo

    GitHub

    CodeQL 2.27.0 adds support for Linux ARM64

    GitHub adds CodeQL 2.27.0 with Linux ARM64 support, a new Rust security query, broader Java, Kotlin, C# and C/C++ coverage, and accuracy improvements across multiple languages. It also expands GitHub code scanning capabilities and includes upcoming deprecation notices.

    CodeQL 2.27.0 is now available on Linux ARM64, adds a new Rust security query, expanded framework coverage for Java/Kotlin and C#, and analysis accuracy improvements across multiple languages. CodeQL is the static analysis engine behind GitHub code scanning, which helps you find and remediate security issues in your code.

    Language and framework support

    CodeQL CLI

    You can now run CodeQL natively on Linux arm64. Download the CodeQL CLI and CodeQL bundle from the linux-arm64 per-platform release assets.

    GitHub code scanning default setup can now use your organization’s private registry configurations to authenticate with container registries or the GitHub API when fetching custom queries or packs. This lets you use custom content from private Git sources and Docker registries.

    C#

    We’ve improved ASP.NET Core MVC controller and action discovery to more closely match runtime behavior. This improves coverage for application parts, endpoint mappings, inherited actions, as well as controller and action exclusions.

    We’ve added taint tracking support for OData action parameter binding. This improves detection coverage for vulnerabilities involving values extracted from ODataActionParameters and entities tracked by Delta.

    In build-mode: none, CodeQL now always attempts to restore projects and solutions using available NuGet feeds. CodeQL also reports explicitly configured feeds that aren’t reachable, making it easier to identify dependencies that may be missing from analysis.

    Java/Kotlin

    We’ve added modeling for the Micronaut framework, including HTTP controllers, WebSocket endpoints, configuration injection, data access, security annotations, and HTTP client sinks.

    Query changes

    C/C++

    We’ve added PostgreSQL libpq query-execution and prepared-statement functions as SQL injection sinks. Queries such as cpp/sql-injection can now identify vulnerabilities involving PQexec, PQexecParams, PQprepare, PQsendQuery, PQsendQueryParams, and PQsendPrepare.

    GitHub Actions

    We’ve improved how CodeQL evaluates checks of author-association fields from event payloads. CodeQL now treats these checks as protection only when the event payload provides the relevant field. This may produce additional alerts for workflows that rely on ineffective checks.

    Rust

    We’ve added the rust/command-line-injection query to detect uncontrolled command lines.

    We’ve updated the rust/hard-coded-cryptographic-value query to reduce duplicate results with very similar source locations.

    The rust/unused-variable query no longer reports variables in functions that contain the standard todo!() or unimplemented!() macros.

    Upcoming Deprecations

    Language support for Java 9 and 10 has been deprecated and will be removed in January 2027. Java 7 and 8 will continue to be supported.

    The generic multi-platform codeql.zip CLI distribution will be removed in a future release. Download the per-platform .zip for your platform instead. The CLI now emits a warning when it is run from an all-platforms distribution; set CODEQL_ALLOW_ALL_PLATFORMS_DIST=true to suppress it.

    For full details, see the CodeQL 2.27.0 changelog. GitHub automatically deploys every new CodeQL version to users of GitHub code scanning on github.com. A future GitHub Enterprise Server (GHES) release will also include the new functionality in CodeQL 2.27.0. If you use an older version of GHES, you can manually upgrade your CodeQL version.

    The post CodeQL 2.27.0 adds support for Linux ARM64 appeared first on The GitHub Blog.

    Original source
  • Sep 9, 2026
    • Date parsed from source:
      Sep 9, 2026
    • First seen by Releasebot:
      Sep 9, 2026
    GitHub logo

    GitHub

    Enterprise managed permissions for GitHub Copilot agent operations

    GitHub adds enterprise managed permissions for GitHub Copilot agents, letting admins centrally block, approve, or allow shell commands, file access, edits, and network domains. The new guardrails are generally available across Copilot app, CLI, and supported VS Code sessions.

    If you administer GitHub Copilot Business or GitHub Copilot Enterprise, you can now centrally control which agent operations are blocked, require human approval, or can proceed without a prompt.

    Managed permissions cover shell commands, file reads and edits, and network domains. This gives you fine-grained guardrails for sensitive operations without disabling agent workflows. Managed restrictions can’t be weakened by user or workspace settings, auto-approval, or previously saved approvals. You can also provide specialized policies for different enterprise teams.

    These controls are generally available in the GitHub Copilot app, GitHub Copilot CLI, and Visual Studio Code sessions that use Agent Host.

    Learn more about enterprise managed permissions.

    Share feedback and implementation questions in the GitHub Community discussion.

    The post Enterprise managed permissions for GitHub Copilot agent operations appeared first on The GitHub Blog.

    Original source
  • Sep 9, 2026
    • Date parsed from source:
      Sep 9, 2026
    • First seen by Releasebot:
      Sep 9, 2026
    GitHub logo

    GitHub

    GitHub Advanced Security expands trial availability

    GitHub expands self-serve GitHub Advanced Security trials for more Enterprise Cloud customers.

    More GitHub Enterprise Cloud customers can now start a self-serve GitHub Advanced Security trial to evaluate GitHub Code Security and GitHub Secret Protection. Eligibility has expanded from enterprises with up to 100 licenses to enterprises with up to 300 licenses.

    To set up a GitHub Advanced Security trial, go to the Enterprise “Billing and licensing” page. For details, see self-serve GitHub Advanced Security trials.

    The post GitHub Advanced Security expands trial availability appeared first on The GitHub Blog.

    Original source
Releasebot

Curated by the Releasebot team

Releasebot is an aggregator of official release notes from hundreds of software vendors and thousands of sources.

Our editorial process involves the manual review and audit of release notes procured with the help of automated systems.