#github
Loot, blog posts and adjacent themes connected to this topic. Follow the tag to keep it in your orbit.
More from this topic
Related reads
GitHub Models shuts down for all users as inference moves to Foundry
AI-generated · Automatically published by LinkLoot. GitHub Models is now fully retired, removing the playground, model catalog, inference AP…
npm 2FA-bypass tokens lose account powers as GitHub tightens registry security
GitHub has restricted npm granular access tokens that bypass 2FA from sensitive account, organization, and package-management actions, with …
GitHub changes bug bounty payouts as AI reports strain triage
GitHub is restructuring its bug bounty program on July 27, adding a permanent VIP tier, fixed public payouts, and a HackerOne signal require…
GitHub MCP Server adds stateless support for the July 28 MCP spec
GitHub has updated its MCP Server for the July 28, 2026 Model Context Protocol release, giving agent-tooling teams an early production signa…
GitHub makes Copilot cloud agent for Linear generally available
GitHub's Copilot cloud agent integration for Linear is now generally available, letting paid Copilot users assign Linear issues to an autono…
GitHub Code Quality is GA, and billing now starts automatically
GitHub expands secret scanning with Resend tokens and monitoring insights
GitHub is rolling out secret scanning updates that add Resend and APIclub detectors, block VolcEngine Ark API keys by default, expose secret…
Delay Dependabot Version PRs Before Fresh Packages Hit Your Build
GitHub now delays Dependabot version update pull requests for three days by default, giving maintainers and scanners time to catch compromis…
Catch AI-era vulnerabilities before merge with GitHub code scanning and Copilot security review
GitHub now surfaces AI-powered code scanning detections on pull requests and added an on-demand /security-review command in the Copilot app,…
Check GitHub Code Quality costs before July 20 billing starts
GitHub now shows a Code Quality license estimate before the product becomes paid on July 20, 2026. Teams should check active committers, Act…
Use GitHub's new pulls dashboard to stop losing review work
GitHub's refreshed pull requests dashboard is now generally available, giving developers and managers one place for review requests, CI fail…
Scan AI App Code for System Prompt Injection with CodeQL 2.26.0
GitHub's CodeQL 2.26.0 adds a JavaScript and TypeScript query for system prompt injection, giving teams a static-analysis check for AI app c…
Use GitHub Innersource Advisories before internal packages hide security fixes
GitHub Advanced Security enterprise customers can now publish private internal advisories that trigger Dependabot alerts and fixes across re…
npm v12 turns risky install behavior into explicit opt-in
npm v12 is now tagged latest, turning dependency install scripts, Git dependencies, and remote URL packages into explicit opt-in paths while…
Cap Copilot agent spend per user from GitHub's billing UI
GitHub Enterprise Cloud admins can now set per-user AI credit budgets inside cost centers from the billing UI, giving teams a cleaner way to…
Use GitHub secret metadata before leaked tokens become a blind queue
GitHub secret scanning now surfaces extended metadata and multipart validation context, giving security teams better ownership and impact si…
Lock Down GitHub Review Dismissals Before a Bad Merge Clears Approval
GitHub now lets repository rulesets restrict exactly who can dismiss pull request reviews, giving teams tighter control over approvals befor…
Check leaked Asana, IBM, and MessageBird tokens faster with GitHub secret scanning
GitHub secret scanning now validates Asana, IBM, and MessageBird secrets, giving security teams a faster signal on whether a leaked credenti…
Use GitHub Issue Fields GA before agents turn triage into guesswork
GitHub Issue Fields are now generally available, adding organization-wide structured issue metadata, public project support, and MCP access …
Find leaked company secrets outside your repos with GitHub public monitoring
GitHub public monitoring for secret scanning is now in public preview for eligible enterprises, helping security teams find company-linked s…
Move off GitHub Models before the July 30 shutdown
GitHub Models is scheduled to shut down for all customers on July 30, 2026. Teams using its playground, model catalog, inference API, or BYO…
Audit Dependabot alert exports before GitHub moves old closed alerts out of the API
GitHub will move closed Dependabot security alerts older than two years into archival storage on August 25, 2026, changing how security team…
Stop coverage drops before merge: GitHub adds code coverage rulesets
GitHub now lets Code Quality users block pull requests when test coverage falls below configured thresholds, giving teams an enforceable mer…
GitHub Adds License Compliance Checks Before Merge
GitHub has put open source license compliance into public preview, giving Enterprise Cloud teams ruleset-based checks that can block pull re…
Fix Dependabot npm registry scope before private package updates drift
GitHub changed how Dependabot handles npm registry configuration: teams can now make dependabot.yml the authoritative source for scoped npm …
Use GitHub Desktop 3.6 to keep agent branches out of each other's way
GitHub Desktop 3.6 adds Git worktrees, Copilot-assisted merge conflict resolution, repo-aware commit messages, model choice, and BYOK suppor…
Protect npm releases: high-impact accounts now get a 72-hour safety pause
GitHub has added a preventive 72-hour read-only state for high-impact npm accounts after sensitive account changes, closing a common supply-…
Harden GitHub Repos Now That Secret Scanning Blocks More Token Leaks
GitHub expanded secret scanning in June 2026 with new partner detectors, wider default push protection, validity checks, and richer leak met…
BrowserAct gets Product Hunt momentum for agent browser automation
BrowserAct is drawing attention as a browser layer for AI agents that need to click, extract, handle logged-in sessions, and recover when re…
Ponytail turns YAGNI into an agent skill with real GitHub momentum
Ponytail is a fast-rising GitHub project that packages minimalist engineering heuristics for coding agents across Claude Code, Codex, Copilo…












