GitHub Copilot, Azure AI, and DevOps: Updates on Agentic Automation and Cloud Workflows
Welcome to this week’s tech roundup, where advancements in AI automation and modernization continue to impact cloud, developer, and enterprise ecosystems. GitHub Copilot continues its shift from a code completion solution to an agentic workflow platform, anchored on the Model Context Protocol (MCP) for open, reusable automation across IDE and CLI environments. The release of updated models, including GPT-5-Codex and Claude Opus 4.1, expands developer flexibility, while Copilot adds general availability for coding agents, CLI modernization, and improved support for SQL and enterprise applications—driving more collaborative and extensible development practices.
At the same time, Microsoft’s Azure ecosystem introduces more unified AI orchestration via Azure AI Foundry and Studio, reliable local inference using Windows ML, and new updates for security, compliance, and observability throughout its stack. Microsoft Fabric supports more data mirroring, embedded analytics, and low-code/no-code agent integration, providing tools for businesses focused on modern data solutions. In ML, DevOps, and security, increased standardization, automation tooling, and operational best practices support innovation while helping teams maintain trust and resilience against modern risks. Continue reading for a practical look at the changes driving progress in the cloud-native and AI-powered technology landscape.
This Week’s Overview
- GitHub Copilot
- Model Context Protocol (MCP): Standardization and Ecosystem Transition
- Copilot Coding Agent: From Workflow Automation to IDE and CLI Integration
- AI Model Options: Next-Generation Model Rollouts, Integrations, and Deprecation
- Copilot CLI and Extension Deprecations: Streamlining for the Future
- Copilot Spaces, Embedding Model Updates, and Open Ecosystem Enhancements
- Copilot-Powered Modernization: Java, .NET, and SQL Workflows
- Agentic Workflows, Prompt-Driven Development, and IDE Innovations
- AI
- Azure AI Foundry and Studio: Unified Generative AI Platform
- Secure and Reliable AI Agent Development with Azure and MCP
- Model Context Protocol (MCP) and Registry: Best Practices and Interoperability
- Microsoft Copilot Studio and Model Selection
- Microsoft Fabric: LLM Analytics, Real-Time AI, and Workflow Automation
- .NET and Multimodal AI: Text-to-Image Capabilities
- SharePoint and Microsoft 365: AI-Driven Content Intelligence
- Building and Operationalizing AI-Powered Agents
- AI for Social Impact and Enterprise Architecture
- Other AI News
- ML
- Azure
- Azure Landing Zones and Multi-Region Architecture
- Infrastructure as Code and Automation Advances
- Agentic AI-Powered Modernization and Migration
- Azure Arc Gateway, Arc for Azure Local, and Hybrid Cloud Connectivity
- Microsoft Fabric: Data Integration, Orchestration, and Developer Tooling
- Azure Platform Updates, Observability, and Security
- Azure Maps Geocode Autocomplete API
- Other Azure News
- Coding
- DevOps
- Security
GitHub Copilot
GitHub Copilot continues its transition from basic code completion toward agent-powered automation, cloud modernization, and context-driven software development. Developers now have more choice with new models, such as GPT-5-Codex and Claude Opus 4.1, alongside further Copilot improvements and extended IDE support. The platform is aligning with open standards focused on the Model Context Protocol (MCP) to improve automation, compatibility, and extensibility. These upgrades include updates for command-line tools, VS Code, enterprise tracking, SQL development, and cloud migration workflows for Java and .NET. As legacy models and extensions get phased out, developers are encouraged to move to the latest approaches and integrate Copilot more deeply into team-oriented, automated workflows.
Model Context Protocol (MCP): Standardization and Ecosystem Transition
GitHub will remove support for Copilot Extensions as GitHub Apps by November 2025 and recommends full migration to MCP servers. This transition takes the ecosystem from initial registry features to a protocol-focused structure, allowing developers to reuse MCP integrations more easily across agents for increased interoperability. Recent registry changes reinforce this approach. The latest MCP IDE guides encourage developers to review migration documentation and shift to MCP standards—for scalable, maintainable workflows and future agentic development. The MCP registry is now positioned as a foundation for Copilot’s ongoing development.
- Deprecation of GitHub Copilot Extensions in Favor of Model Context Protocol (MCP) Servers
- What is Model Context Protocol (MCP)?
- Understanding Model Context Protocol (MCP) for Developers
- How to Use GitHub Copilot Agent Mode and MCP to Query Microsoft Learn Docs in VS Code
- Use Copilot and MCP to Query Microsoft Learn Docs
- GitHub MCP Registry Integration with Playwright in VS Code Insiders
Copilot Coding Agent: From Workflow Automation to IDE and CLI Integration
Copilot Coding Agent is now available to all paid users, progressing from workflow previews to broad automation across GitHub, IDEs, and direct CLI/Mobile app usage. GitHub Actions continue to orchestrate agent tasks, with new CLI and mobile features providing more flexibility for developers. Recent added controls for issue assignment and repository selection give teams enhanced management over agent-driven tasks—making cross-platform delegation simpler for both individuals and groups.
- GitHub Copilot Coding Agent Now Generally Available
- Kick off and Track Copilot Coding Agent Sessions from the GitHub CLI
- Start and Track GitHub Copilot Coding Agent Tasks in GitHub Mobile
- Enhanced Copilot Issue Assignment: Pick Repository and Base Branch
- Copilot Can Create GitHub Issues with Code Snippets: Public Preview
AI Model Options: Next-Generation Model Rollouts, Integrations, and Deprecation
OpenAI’s GPT-5-Codex and Claude Opus 4.1 are now available to additional Copilot subscribers and IDE users, broadening model selection following last week’s previews. The Copilot-SWE model launches for focused software engineering in VS Code Insiders, supporting ongoing context-driven workflows. Admin controls and Pro+ plan updates deliver more robust model management. GitHub continues to phase out older models, with organizations guided through updates using actionable adoption tutorials.
- OpenAI GPT-5-Codex Now Available in GitHub Copilot Public Preview
- Claude Opus 4.1 Now Generally Available in GitHub Copilot
- GitHub Copilot-SWE Model Launches in Visual Studio Code Insiders
- Upcoming Deprecation of Select Copilot Models from Claude, OpenAI, and Gemini
- VS Code and GitHub Copilot: Exploring GPT-5-Codex and Copilot-SWE
- What’s New: GitHub MCP Registry, Copilot CLI Public Preview, and Beast Mode for Copilot
Copilot CLI and Extension Deprecations: Streamlining for the Future
GitHub is discontinuing the gh-copilot
CLI extension, moving to the npm-distributed Copilot CLI (now in public preview). This is part of the ongoing shift away from historic Marketplace extensions and supports recent MCP registry changes. The improved CLI simplifies agentic code generation, code review, and MCP-based extensibility, reinforcing the platform’s commitment to standardization and modern developer tooling. Admins should review timelines and update workflows before October 2025 as MCP adoption grows.
- GitHub Copilot CLI Extension Deprecation Announcement
- GitHub Copilot CLI Now Available in Public Preview
Copilot Spaces, Embedding Model Updates, and Open Ecosystem Enhancements
Copilot Spaces is now available to all users, providing a platform for managing files, documentation, and project context—building on recent embedding and workflow advancements. A new embedding model for code search in VS Code enhances daily code retrieval and multi-language support. The Hugging Face VS Code extension now allows Copilot Chat to interact with open-source models, enabling experimental and domain-specific development and broadening pay-as-you-go model choices for teams seeking customized workflows and improved context support.
- Copilot Spaces: General Availability Announcement
- GitHub Copilot’s New Embedding Model Improves Code Search in VS Code
- Hugging Face Opens GitHub Copilot Chat to Open-Source Models
Copilot-Powered Modernization: Java, .NET, and SQL Workflows
The Copilot App Modernization toolkit is now generally available for Java and .NET projects, expanding on last week’s agent-guided refactoring tutorials. The toolkit automates dependency analysis, code transformation, containerization, and incorporates security scanning—supporting recent compliance initiatives. Updated SQL workflows leverage AI for smarter query generation, analytics, and automation for both MSSQL and PostgreSQL, continuing the trend from last week’s context-driven database improvements. Tutorials help teams upgrade legacy systems to modern infrastructure while prioritizing productivity and maintainability.
- GitHub Copilot App Modernization Now Available for Java and .NET Projects
- Modernize .NET Apps in Days with GitHub Copilot
- Modernizing Java Applications with GitHub Copilot and Azure Deployment
- Modernizing Java Projects with GitHub Copilot Agent Mode: Step-by-Step Guide
- Quickly Modernize and Deploy Java Apps with AI and GitHub Copilot in VS Code
- Modernize Java Apps in Days with GitHub Copilot
- Microsoft’s AI Agents Target Technical Debt Crisis
- Enhancing SQL Development in VS Code with GitHub Copilot and Microsoft Fabric
- Boost Productivity with the PostgreSQL Extension and GitHub Copilot in VS Code
Agentic Workflows, Prompt-Driven Development, and IDE Innovations
New guidance covers converting web apps to mobile apps using Copilot prompts, leveraging plan mode, voice input, and improved model management—continuing previous advances in MCP-powered IDE workflows and Spec Kit sessions. The VS Code Insiders podcast features the latest on IDE improvements, focusing on AI’s shift from pure code assistance to orchestrated workflow support. Ongoing updates in live preview, documentation access, and activity tracking build on former releases in XAML, collaborative coding, and agentic automation—marking positive change for developer workflows.
- Converting a Web App to Mobile Using GitHub Copilot Prompts
- The Future of Coding Agents in VS Code: Insights from VS Code Insiders Podcast
- Enhancements to XAML Live Preview in Visual Studio for .NET MAUI
- GitHub Copilot: The Influence of Generative AI Assistants and Agents on Software Development - Netherlands
- GitHub Copilot: The Influence of Generative AI Assistants and Agents on Software Development - Belgium
AI
AI technologies on Microsoft platforms continued to grow in hardware compatibility, agent reliability, model choice, and practical deployment, following the themes established in recent weeks. Guides and releases remain focused on bringing updated AI solutions into daily workflows, supporting best practices across both cloud and edge environments.
Azure AI Foundry and Studio: Unified Generative AI Platform
Azure AI Studio (now Azure AI Foundry) establishes itself as a central workspace for developing generative AI and deploying LLM solutions, spanning model options including OpenAI, Meta, Mistral, and more. The platform supports prompt engineering, fine-tuning, retrieval-augmented generation (RAG), and offers both code-first and low-code interfaces. GPT-4o adds voice and multimodal features, and Phi-3 offers options for lightweight inference.
Security and governance improvements allow organizations to adopt responsible AI usage with integrated monitoring and compliance. Developers should remain aware of billing and vendor lock-in as they work with the platform.
Foundry Local v0.7 brings support for Intel/AMD NPUs on Windows 11 and simplifies local inference and AI runtime management. Installation with winget (Windows) and brew (Mac) reduces setup friction for multi-platform development.
Windows ML is now generally available, providing ONNX-based local inference for privacy and edge execution in Windows applications. Integrated with AMD Ryzen AI, Intel OpenVINO, NVIDIA TensorRT, and Snapdragon NPUs, Windows ML works closely with the App SDK and includes streamlined model conversion via the AI Toolkit for VS Code—highlighting edge AI’s readiness for production scenarios.
- Azure AI Studio and AI Foundry: Microsoft’s Generative AI Platform Explained
- Foundry Local Meets More Silicon: Expanded AI Runtime and NPU Support
- Windows ML Now Generally Available: Empowering Developers to Deploy Local AI on Windows Devices
Secure and Reliable AI Agent Development with Azure and MCP
AI agent development is improving with integration methods for durable, reliable operations—building on previous agent orchestration and security content. Developers now have a step-by-step guide for using the OpenAI Agent SDK with Azure Durable Functions to support persistent state, retry logic, and distributed workflows, using decorators and orchestration functions to manage errors efficiently and reduce manual coding.
The final Agent Factory installment explains how to build a secure, standards-based agent ecosystem using the agentic web stack—covering identity, trust, and compliance via Entra ID alongside open protocols. Practical tips on integrating standards and secure orchestration are included, addressing both Microsoft and open-source tools.
- Enhancing AI Agent Reliability with OpenAI Agent SDK and Azure Durable Functions
- Agent Factory: Designing the Open Agentic Web Stack
Model Context Protocol (MCP) and Registry: Best Practices and Interoperability
Azure’s Model Context Protocol further embeds governance and security in AI workflows. Technical analysis highlights how MCP best practices in GitHub Copilot and VS Code enable automatic compliance and security enforcement, particularly for infrastructure-as-code scripts. Dynamic prompt instructions help teams maintain up-to-date policy compliance.
A video walkthrough introduces the GitHub MCP Registry, allowing developers to locate and connect MCP servers for agent development and modular design. Additional guidance outlines secure MCP server integration for Logic Apps and Copilot Studio, including authentication and deployment recommendations.
- Teaching the LLM Good Habits: How Azure MCP Uses Best-Practice Tools
- A Deep Dive into the GitHub MCP Registry for AI Agents
- Connecting Azure Logic Apps MCP Server to Copilot Studio Securely
Microsoft Copilot Studio and Model Selection
Copilot Studio adds model selection for Anthropic’s Claude Sonnet 4 and Opus 4.1, alongside OpenAI’s GPT models, enabling prompt- and logic-level model configuration. Admin options in Microsoft 365 and Power Platform allow for domain-specific assignments and automated fallback rules—providing more control for organizations pursuing consistent automation.
Microsoft Fabric: LLM Analytics, Real-Time AI, and Workflow Automation
Fabric Data Agent now supports mirrored cloud databases, allowing natural language queries and multimodal analytics using Delta Parquet mirrors. Previewed anomaly detection in RTI streamlines streaming analytics with integration into Teams and email alerts. Agent Mart Studio’s expanded connections with Fabric and OneLake enhance low- and no-code workflow automation for data professionals and developers.
- Unlocking LLM-Powered Analytics with Fabric Data Agent and Mirrored Databases
- AI–Powered Real-Time Intelligence with Anomaly Detection in Microsoft Fabric (Preview)
- Building AI Agents for Enterprise Data with Agent Mart Studio and Microsoft Fabric
.NET and Multimodal AI: Text-to-Image Capabilities
MEAI adds text-to-image generation in .NET, providing a consistent API that abstracts providers like Azure AI Foundry, OpenAI, and ONNX. This update prepares for future image-to-image and image-to-video support, making multimodal AI more accessible for .NET applications.
SharePoint and Microsoft 365: AI-Driven Content Intelligence
SharePoint’s Knowledge Agent (public preview) delivers AI-powered automation for content metadata, summaries, document comparison, and rule creation, with workflow integration into Copilot. Controlled pilot programs, governance, review cycles, and training are emphasized for effective enterprise use.
Building and Operationalizing AI-Powered Agents
Developers continue to build practical agents, with a tutorial on creating a resilience coach using Azure OpenAI and Python. Additional resources show agent memory management with Semantic Kernel and Azure AI Search, alongside customization guides for LLMs and Cognitive Services. An operational workflow demonstrates post-call analytics using Azure OpenAI to process transcripts and feed CRM systems.
- Building a Resilience Coach with AI on Cozy AI Kitchen
- AI Agent Memory: Building Self-Improving Agents
- Generative AI in Azure: A Practical Guide to Getting Started
- From Call Transcripts to CRM Gold: AI-Powered Post-Call Intelligence
AI for Social Impact and Enterprise Architecture
UNHCR, Microsoft, and GitHub share new uses of drone data and open-source AI for sustainable planning in refugee settlements, showcasing adaptive open tools. Updated architecture frameworks now account for AI requirements, MLOps, and explainability. Sustainability remains a priority, with AI solutions for digital twins, forecasting, and energy-use reduction continuing the focus on practical environmental reliability.
- Using AI and Open Source to Map Refugee Settlements: The UNHCR and GitHub Story
- Software Architecture Frameworks and Artificial Intelligence: Building Smarter Systems
- Accelerating Sustainability and Resilience with AI-Powered Innovation
Other AI News
Research teams at Microsoft, Drexel University, and the Broad Institute present generative AI for rare disease diagnosis, utilizing Azure AI Foundry for evidence aggregation and collaborative genome review—a continuation of last week’s healthcare AI initiatives.
ML
Machine learning updates this week focus on analytics scale, architecture maturity, and observability—especially in Microsoft Fabric’s Spark environment. New diagnostics and APIs offer developers more control, with an ongoing emphasis on collaborative production ML and best operational practices.
Microsoft Fabric Spark Observability and Integration
A new preview for Fabric Spark Applications Comparison lets users visually assess up to four Spark app runs, supporting easier identification of performance issues. This builds on Spark Run Series Analysis, now generally available for grouping job runs and finding anomalies. Monitoring APIs provide real-time insight and automation capabilities for scaling ML operations. Features like Spark Advisor, skew diagnostics, and allocation reporting strengthen automated observability for teams.
User Data Functions, now generally available, enable custom Python logic in Fabric SQL, Lakehouse, Warehouses, and Power BI, encouraging wider reuse and easier integration. The VS Code extension and async data processing further improve developer workflow.
- Microsoft Fabric Spark Applications Comparison Feature (Preview)
- Fabric Spark Run Series Analysis: Enterprise-Scale Observability for Microsoft Fabric Spark Jobs
- Fabric Spark Monitoring APIs Now Generally Available
- Fabric User Data Functions Now Generally Available
Evolving MLOps Architectures and Operational Practices
Ongoing best practices encourage the shift from ad-hoc ML deployment to modular, automated workflows with versioning, CI/CD, lifecycle management, and monitoring—with tools like Kafka, Spark Streaming, Feast, MLflow, and Kubernetes as central components. The focus is on continuous delivery, drift detection, and strong governance within practical ML lifecycle management.
Community discussions around MLOps support collaborative learning, with events, podcasts, and networking driving shared expertise in real-world deployment, governance, and technical debt management.
- MLOps Architectures: Building Scalable AI Systems
- MLOps at Scale: How Community Is Driving AI Into Production
Azure
Azure’s latest updates include architecture, modernization, automation, observability, security, and developer productivity, oriented toward scalable migration, hybrid cloud, and improved developer experiences.
Azure Landing Zones and Multi-Region Architecture
Updated Azure AI Landing Zone resources guide organizations on modular and secure AI deployments, covering subscription management, RBAC, policy enforcement, zero trust, and expansion planning. Multi-region architecture lessons cover infrastructure-as-code, resiliency, disaster recovery, and regional failover strategies—helping larger organizations deploy securely and reliably, in line with ongoing migration topics.
- Azure AI Landing Zone: Enterprise-Scale, Secure, and Governed AI Deployment Architecture
- Architecting Multi-Region Solutions in Azure: Practical Lessons Learned
Infrastructure as Code and Automation Advances
Azure now features Copilot-driven code generation for Terraform, a unified VS Code extension, and policy validation—supporting better cross-stack management for Azure and Microsoft 365 environments. HPC guides demonstrate automated SLURM cluster deployments with CycleCloud and Hammerspace, showing how natural language and AI can streamline infrastructure as code.
- Accelerating Infrastructure as Code: New Terraform Enhancements for Azure
- Simplifying HPC Deployments with Azure CycleCloud and Hammerspace
Agentic AI-Powered Modernization and Migration
GitHub Copilot’s modernization agents for Java (with .NET in preview) automate code analysis, migration, and artifact generation. Azure Migrate adds agentless discovery, dependency mapping, and guided database migration for PostgreSQL, SQL Server, and Oracle. The Azure Accelerate program helps organizations with large migration projects, reinforcing earlier themes of automation and reduced manual effort.
- Accelerating Application Migration and Modernization with Agentic AI Tools in Azure
- Discover and Assess PostgreSQL Databases for Azure Migration Using Azure Migrate
Azure Arc Gateway, Arc for Azure Local, and Hybrid Cloud Connectivity
Azure Arc Gateway and Arc Gateway for Azure Local reach general availability, providing streamlined outbound endpoint setup for Arc-enabled and edge deployments. Built-in proxy routing improves secure agent communication, echoing ongoing investments in hybrid and mixed environment management.
- General Availability of Azure Arc Gateway for Arc-Enabled Servers
- Announcing the General Availability of Arc Gateway for Azure Local
Microsoft Fabric: Data Integration, Orchestration, and Developer Tooling
Microsoft Fabric advances mirroring, adding support for BigQuery (preview) and Oracle for zero-ETL data access. Power BI and chat analytics expand, and Fabric SQL Database receives Copilot-powered query management, VS Code/SSMS support, application lifecycle management (via REST), backup and monitoring tools, and security updates. Fabric VS Code extension and Extensibility Toolkit are now generally available, streamlining app creation and workspace automation. Data Factory introduces new orchestration features, with Copilot assisting expression writing. Workspace admins gain direct per-workspace workload assignment for improved ingestion and quality oversight.
These updates build on recent ecosystem improvements and previews, moving Fabric further toward open administration and orchestration tools.
- Mirroring in Microsoft Fabric: New Sources, Zero-ETL Data Unification, and AI-Powered Insights
- Mirroring for Google BigQuery in Microsoft Fabric: Public Preview Overview
- Introducing the Microsoft Fabric Extensibility Toolkit
- Microsoft Fabric VS Code Extension: New Features and General Availability
- Unlocking Enterprise-Ready SQL Database Features in Microsoft Fabric: ALM, Backups, and Copilot Enhancements
- Innovations in Fabric Data Factory Orchestration Announced at Fabric Conference Europe 2025
- Microsoft Fabric Update: Workspace Admins Gain Direct Workload Assignment
- MSSQL Extension for VS Code Adds Fabric Integration and Database Provisioning
Azure Platform Updates, Observability, and Security
The September 26, 2025 Azure update covers service retirements, new AKS Fleet Manager and Insights, logging enhancements, new App Gateway features, and Azure Files Premium backup. Database administrators benefit from added backup and migration tools. Azure Monitor Logs integrates with Fabric Eventstream for streamlined operations data ingest, and App Gateway logs move to resource-focused tables, improving compliance and monitoring. Grafana now helps track Container Apps.
Security features expand with Azure Integrated HSM in public preview, providing hardware-backed cryptography for trusted VMs and easier FIPS compliance. These updates underscore ongoing monitoring, centralized logging, and confidential compute improvements.
- Azure Update - 26th September 2025: Service Retirements, New Features, and GitHub Copilot Highlights
- Unlocking Real-Time Operational Intelligence: Azure Monitor Logs Integration in Fabric via Eventstream
- Enhanced Logging for Azure Application Gateway: Resource-Specific Tables, DCR, and Cost Optimization
- Announcing Azure Container Apps Azure Monitor Dashboards with Grafana (Public Preview)
- Microsoft Azure Introduces Azure Integrated HSM: Secure Hardware-Backed Cryptography for Virtual Machines
- General Availability of Azure Backup Vaulted Support for Azure Files Premium (SSD) Shares
Azure Maps Geocode Autocomplete API
The Azure Maps Geocode Autocomplete API enters public preview, delivering real-time, ranked autocomplete for addresses and places, with multilingual results, filtering options, and metadata enrichment. It replaces Bing Maps Autosuggest to support more user-friendly location experiences for applications such as store locators and rideshares. Official migration guides are available.
- Introducing the Azure Maps Geocode Autocomplete API
- Introducing the Azure Maps Geocode Autocomplete API
Other Azure News
Developer tooling updates include forums for Azure Automation feedback and bug reporting, highlighting practical workflow priorities and building on recent onboarding resources.
A deep-dive guide for Azure Database for PostgreSQL Flexible Server covers deployment, tuning, authentication, high availability, encryption, and cost optimization practices.
A Rust SDK workshop demonstrates secure secret management and authentication for memory-safe cloud-native apps on Azure.
Analysis of Azure API Management Developer Tier highlights self-hosted gateway capabilities, premium features, and cost considerations for dev/testing environments.
Azure Native Pure Storage Cloud delivers integrated block storage for hybrid migrations, providing a native Azure experience and aiding VMware transitions.
Playwright Testing adds managed, parallel browser sessions on Azure, improving reliability for large test suites in CI/CD.
Updated Azure Hybrid Benefit guides for Linux VMs offer strategies for cost savings through license management.
Cobalt 100 VMs offer energy-efficient, Arm-based compute for analytics, media, AI workloads, and are now widely available.
Microsoft Fabric Maps provide integrated geospatial intelligence with no-code visualization for applications such as fleet management and live analytics.
Azure’s global network sees improvements through hollow core fiber partnerships, increasing reliability and reducing latency for high-performance workloads.
Microsoft Ignite 2025 promotes community collaboration, bringing workshops and best practices to Azure and AI/data topics.
Coding
This week’s coding highlights include updates in .NET development, new container tooling in Visual Studio, and practical advice on platform compliance, distributed workflows, and migration planning.
Visual Studio 2026 and Container Tooling
Visual Studio 2026 Insiders now supports Podman, enabling developers to use this daemonless, rootless container engine instead of Docker for increased security and flexibility. The IDE detects Podman automatically and offers tools for managing images, debugging, and working with containers from the terminal—making secure Linux container development more approachable.
.NET Aspire 9.5 and Modern .NET Cloud-Native Development
.NET Aspire 9.5 provides improvements for distributed .NET applications, including a new ‘aspire update’ CLI for managing SDK/package upgrades, improved dashboards, a single-file AppHost preview for fast prototyping, and color-coded telemetry. GenAI Visualizer aids model debugging, YARP supports static files, and integration with Azure DevTunnels supports local secure testing. Visual Studio 2026 picks up new Aspire tracing features, and migration guides offer help for upgrades from Aspire 8.x.
.NET MAUI: App Compliance, Migration, and Community Engagement
.NET MAUI applications must update to MAUI 9 to comply with Google Play’s 16 KB memory page rule for Android 15+. Guidance is available for checking dependencies and updating build tools. The MAUI Community Standup event in Prague continues focus on collaboration and ongoing platform improvements, reflecting recent compliance and migration support topics.
- Preparing Your .NET MAUI Apps for Google Play’s 16 KB Page Size Requirement
- .NET MAUI Community Standup - Live in Prague with the .NET MAUI Team
.NET Platform Strategy and Database Migrations
Microsoft has clarified support timelines for .NET LTS/STS releases. Nick Chapsas provides migration planning guidance, helping developers minimize upgrade risk. Jeremy Miller’s Data Community Standup compares Marten/PostgreSQL and Entity Framework Core, offering real-world migration Q&A for developers planning database changes.
- Understanding Microsoft’s LTS/STS Changes for .NET Support
- .NET Data Community Standup: Jeremy Miller on Marten and Database Migrations
Building Server-Side and CLI Tools with .NET
The latest ASP.NET Community Standup demonstrates a multi-user MCP server, highlighting collaborative code review and refactoring workflows. Andrew Lock’s guide on ‘sleep-pc’ covers .NET Native AOT usage, Win32 integration, argument processing, and NuGet packaging for durable server-side and CLI tool creation.
- ASP.NET Community Standup - Vibe Coding a C# MCP Server
- Building sleep-pc: A .NET Native AOT Tool for Automating Windows Sleep
DevOps
DevOps this week highlights new automation features, updates to API lifecycles, and improved onboarding, with emphasis on collaboration and clear operational processes.
GitHub Platform and API Lifecycle Updates
GitHub’s pull request ‘Files changed’ page now supports comments on any changed line, improving code review flexibility for teams and supporting enhanced navigation and API/webhook integration. This update continues previous efforts to refine workflow transparency.
Dependabot alert pagination via offsets is being retired on the REST API—teams should transition to cursor-based pagination for easier handling of larger alert sets. Billing API endpoints now provide aggregate metered usage, streamlining integration and reporting. Enterprise Cloud accounts gain new organizational usage views for better cost management.
- Enhanced GitHub Pull Request Files Changed Page: Comment Anywhere in Changed Files
- Upcoming Changes to GitHub Dependabot Alerts REST API Pagination
- GitHub Retires Product-Specific Billing APIs for Actions, Packages, and Storage
- Product-specific Billing APIs for GitHub Actions and Packages Are Closing Down
- Visualizing GitHub Enterprise Cloud Metered Usage by Organization
AI and Automation in DevOps: Harness and HashiCorp Advances
Harness adds modules for autonomous DevOps tasks, including code maintenance, build troubleshooting, feature flag management, and policy enforcement, all powered by AI. Verification and rollback modules work with observability platforms to improve deployment reliability, and natural language YAML generation supports automated pipeline configuration.
HashiCorp brings agentic AI for infrastructure automation, compatible with Microsoft, AWS, and Red Hat Ansible environments. HCP Terraform Stacks reaches general availability, delivering dependent config management, and new search/action tools (in beta) improve resource management. Vault security updates offer automated cryptography and enhanced credential workflows.
- Harness Adds New AI Modules to Automate DevOps Pipelines and Maintenance
- HashiCorp Introduces Agentic AI and Enhanced Automation for IT Infrastructure
Testing and Developer Onboarding Tools
Playwright Testing now runs on all major browsers and languages, offering managed parallel sessions on Azure and close CI/CD integration. Guides cover advanced debugging, reporting, and DevOps pipeline integration to help teams scale automated testing.
GitHub’s beginner guide delivers video resources for repository management, pull requests, commands, licensing, and profile setup, providing a standardized approach to DevOps onboarding.
- Getting Started with Microsoft Playwright Testing Features and How to Use It
- The Ultimate Beginner’s Guide to GitHub in 2025
Other DevOps News
GitHub refreshes its DMCA takedown policy, Acceptable Use Policy, and moderation practices, clarifying boundaries around developer feedback, synthetic media, and content safety. Teams managing public and open-source projects should review these updates.
Security
Recent updates in security emphasize supply chain protection, vulnerability remediation, artifact signing, and up-to-date governance for developers working in increasingly risk-aware environments.
Package Registry and Supply Chain Security
NuGet.org now supports Trusted Publishing with short-lived OIDC tokens through GitHub Actions, replacing static keys and improving .NET package safety. Npm registry updates include enforced 2FA, short-lived tokens, and trusted publishing. Chainguard’s curated JavaScript repository adds SLSA provenance and malware scanning for safer dependencies.
- New Trusted Publishing Enhances Security on NuGet.org
- GitHub’s Roadmap for Strengthening npm Supply Chain Security
- How GitHub Plans to Secure npm After Recent Supply Chain Attacks
- Chainguard Launches Curated JavaScript Libraries to Enhance Software Supply Chain Security
Code Scanning, Static Analysis, and Remediation Workflows
CodeQL 2.23.1 introduces improved language detection and query updates for common vulnerabilities, like SSRF and CORS. Incremental analysis speeds scanning for pull requests, and GitHub Security Campaigns with Assignable Alerts help teams coordinate and track remediation within CI flows.
- CodeQL 2.23.1 Released: Java 25, TypeScript 5.9, and Swift 6.1.3 Support
- Incremental Security Analysis with CodeQL Now Available Across All Languages
- Accelerate Remediation with GitHub Security Campaigns and Assignable Alerts
Artifact Signing, Infrastructure, and Cloud Security
Azure Trusted Signing (public preview) and Notary Project now support integrated signing of OCI images, SBOMs, and Helm charts, helping automate certificate handling for CI/CD. RBAC for AI Landing Zones and secure Databricks deployments via Private Link/Azure Firewall provide templates for regulated operational security.
- Simplify Image Signing and Verification with Notary Project and Trusted Signing (Public Preview)
- Enterprise-Ready RBAC Model for Azure AI Landing Zone
- Securing Azure Databricks Serverless with Private Link and Azure Firewall
Threat Intelligence, Malware, and Incident Response
Microsoft details the latest XCSSET malware variant targeting macOS dev tools, with mitigation strategies for Defender XDR users. A retail sector incident report outlines response tactics to SharePoint-based attacks, stressing rapid patching and Zero Trust controls. Threat intelligence detects new AI-obfuscated phishing techniques, showcasing layered defense strategies.
- Latest XCSSET Malware Variant: Technical Deep Dive and Mitigation Guidance
- Retail at Risk: How a Single Alert Uncovered a Major Cyberthreat
- AI-Obfuscated Phishing Campaign Detection by Microsoft Threat Intelligence
Identity, Data Protection, and Developer Security Skills
A Microsoft Entra Suite guide outlines unified identity, access, risk, passwordless options, and multi-cloud gateways for zero trust. Purview’s DLP and sensitivity labeling (now GA for Fabric) assist with policy enforcement and auditing. OneLake Catalog previews a centralized security permissions tab. An Azure OpenAI customer success story demonstrates App Gateway and NSGs for secure access. A DevSecOps guide covers career progression and practical skills for developers.
- Microsoft Entra Suite: The Future of Identity and Access Security
- Protecting Microsoft Fabric Data with Purview DLP and Sensitivity Labels
- View and Manage Security in the OneLake Catalog (Preview)
- Securing Azure OpenAI Access from On-Premises with Application Gateway: A Customer Success Story
- The DevSecOps Career Path: What No One Tells You About Getting Started
Other Security News
A practical guide details JWT authentication and authorization for MCP servers in agentic platforms and microservices. GitHub’s Bug Bounty program increases incentives for Copilot ecosystem vulnerability research during Cybersecurity Awareness Month, inviting more robust security testing of developer tooling.