Content by allison (940)
Allison announces updates to GitHub Copilot’s impact dashboard and reporting APIs, adding 28-day feature engagement metrics so enterprise and organization admins can see which Copilot experiences are being used regularly and where enablement may be needed.
Allison announces expanded GitHub Copilot CLI reporting in the Copilot usage metrics API, adding agentic activity metrics for skills, custom agents, MCP servers, slash commands, and plugins, plus guidance on how counts are calculated and who can access the reports.
Allison announces that the Ubuntu 26.04 GitHub Actions runner image is now generally available, and explains how the ubuntu-latest label will migrate from Ubuntu 24.04 to 26.04 with a staged rollout window and guidance to avoid broken builds.
Allison announces the general availability of workflow execution protections in GitHub Actions, covering allowlist-based controls for who can trigger workflows and which events can start them, plus new workflow-level targeting, Insights for auditing, and a REST API for managing policies as code.
Allison announces a GitHub Enterprise Cloud update that lets enterprise admins automate SSO authorization for existing classic PATs and SSH keys across multiple SSO-protected organizations using an enterprise-installed GitHub App and a new bulk-authorization REST API.
Allison announces an additive SCIM change in GitHub: user responses now include the standard profileUrl attribute (RFC 7643), making it easier for identity providers and provisioning integrations to map SCIM users to the linked GitHub account without extra lookups.
Allison announces general availability of Copilot budget increase requests, letting members request additional AI credits when they hit their limit and enabling org/enterprise owners and billing managers to approve, adjust, or deny requests directly from GitHub settings under usage-based billing.
Allison announces an update to GitHub code scanning: AI Scan for pull requests can now run even when CodeQL default setup isn’t enabled, expanding where AI-powered vulnerability detections can be applied for GitHub Advanced Security customers.
Allison announces an update to GitHub Advanced Security that lets enterprise admins enforce security configurations across organizations, preventing org and repo admins from overriding enterprise-level settings and helping security and compliance teams apply consistent policies at scale.
Allison announces a public preview feature where GitHub Copilot suggests allowed values while admins define repository custom properties, helping organizations build consistent governance metadata that can be used to scope rulesets across large fleets of repositories.
Allison announces that GitHub has completed the planned shutdown of SHA-1 support in HTTPS for github.com and partner CDNs, with notes on which GitHub Enterprise offerings are affected and where to find the earlier deprecation details.
Allison announces new configuration tiers for GitHub Copilot auto model selection—efficiency, balance, and intelligence—so teams can control how Copilot trades off cost, response quality, and response time per prompt, with billing based on the model selected.
Allison announces a small GitHub profile update: profiles now display the highest tier earned for multi-level achievements, so your Achievements panel reflects your latest progress rather than the first tier you earned.
Allison announces new generally available GitHub Copilot usage metrics that track activity in the dedicated VS Code Agents window, including both aggregate (enterprise/org) and per-user fields for 1-day and 28-day reporting periods.
Allison announces improvements to GitHub Copilot code review, including automatic resolution of addressed review comments, smarter commit message suggestions when applying Copilot fixes, and deeper review analysis using Copilot SDK shell tools plus an ensemble approach for Lite reviews.
Allison summarizes the September 7 weekly GitHub Copilot releases, including Jira integration in the Copilot app, Project HydraFusion model orchestration in Copilot CLI, new agent automations and voice mode updates in VS Code, and expanded enterprise sandbox controls for Copilot in JetBrains.
Allison announces a public preview of a refreshed repository-level pull request listing page on GitHub, focused on making it faster to find and act on PRs with improved filtering, advanced search, and a more compact, information-dense layout.
Allison announces a public preview that adds GitHub REST API endpoints for enabling and managing GitHub code scanning’s AI Scan for pull requests at both the organization and repository level, making it easier to roll out AI-powered security detections across selected repos without manual UI configuration.
Allison announces GitHub Actions cache-mode, a generally available workflow/job setting that lets teams apply least-privilege access to the Actions cache and reduce cache poisoning risk by controlling whether jobs can restore and/or save caches.
Allison announces the deprecation of the MAI-Code-1-Flash model across GitHub Copilot experiences and points Copilot Enterprise admins to the steps needed to enable the replacement model via Copilot model policies and settings.
Allison announces that the GitHub Actions Xcode 27 runner image now runs on macOS 27 (public preview), enabling Apple app validation against the latest macOS version while keeping the same workflow runner labels.
Allison announces a new npm security protection: after signing in with a recovery code, any npm account is placed under a 72-hour security hold that blocks publishing and other sensitive write actions while still allowing sign-in and package installs.
Allison announces CodeQL 2.27.0, highlighting native Linux ARM64 support, improvements to GitHub code scanning default setup, and multiple query and framework-modeling updates that improve vulnerability detection across C#, Java/Kotlin, C/C++, and Rust projects.
Allison announces generally available enterprise managed permissions for GitHub Copilot agent operations, letting admins centrally decide which actions are blocked, require human approval, or run without prompting across supported Copilot clients.
Allison announces expanded self-serve trial eligibility for GitHub Advanced Security on GitHub Enterprise Cloud, allowing more enterprises to evaluate GitHub Code Security and GitHub Secret Protection before purchasing.
Allison announces a new GitHub repository ruleset option that can block pull requests from merging when they introduce unresolved secret scanning alerts, adding an extra enforcement layer beyond push protection.
Allison announces agentic autofix for GitHub Code Quality, letting teams select up to 25 findings and assign them to GitHub Copilot in one action. Copilot applies fixes on a branch, validates the changes, and opens a pull request for review, with usage governed by existing enterprise policy and AI credits.
Allison announces updates to GitHub Copilot for JetBrains, including enterprise-managed sandbox policies, cross-file cursor jumps for next edit suggestions, global project context in chat, and enterprise policy diagnostics. The release also adds a preview integration that connects Copilot CLI terminal sessions to IDE context and improves reliability across MCP and agent sessions.
Allison announces GitHub Enterprise Server (GHES) 3.22 general availability, highlighting updates for enterprise administration and collaboration, including Copilot CLI support for disconnected environments, enterprise teams, improvements to repository rulesets and required reviewers, and UI enhancements for issues and pull requests.
Allison’s weekly Copilot changelog highlights new model options (Claude Fable 5.1 and Gemini 3.8 Flash), stronger content protection via honored content exclusions in Copilot app/CLI, and VS Code 1.136 updates aimed at managing agent sessions and getting pull requests ready to merge.
Allison announces general availability of OpenAI’s GPT-6 Astra in GitHub Copilot, highlighting its strength on long-horizon, agentic coding tasks, how it’s billed under usage-based pricing, and where developers and admins can enable and select the model across supported IDEs and clients.
Allison announces a redesigned GitHub support portal now hosted at help.github.com, bringing support, documentation, learning, community, and account resources into a single entry point with Copilot-powered search.
Allison announces a new GitHub REST API endpoint that lets you track repository star growth over time while keeping stargazer identities private, aimed at helping maintainers and tool builders update integrations affected by earlier access restrictions.
Allison announces generally available updates to npm trusted publishing, including multiple OIDC configurations per package, staged approvals that wait for malware scanning to finish, and improved version history visibility for maintainers on npmjs.com.
Allison summarizes three GitHub Actions improvements: a new REST API to track runner version deprecation timelines, a least-privilege `vulnerability-alerts` permission for `GITHUB_TOKEN` to read Dependabot alerts, and new `job` context properties that help reusable workflows identify their source at runtime.
Allison announces the deprecation of several AI models used across GitHub Copilot experiences on October 2, 2026, and outlines the replacement models plus the admin steps needed to enable them via Copilot model policies.
Allison announces a required PGP signing key update for the GitHub CLI (gh) Linux APT and RPM repositories ahead of the September 5, 2026 key expiration, with guidance on who needs to update their setup and which installation methods are unaffected.
Allison announces that Gemini 3.8 Flash is now available as a selectable model in GitHub Copilot, including where it can be used (IDEs, CLI, and cloud agent), who gets access across Copilot plans, and how admins can control enablement via model policy.
Allison announces that GitHub is gradually reopening sign-ups for Copilot Business and Copilot Enterprise paid by credit card or PayPal, alongside billing and account-vetting changes that affect how seats are activated, charged, and how overage usage may require additional payment.
Allison summarizes what’s new in CodeQL 2.26.4 for GitHub code scanning, including language support updates and query accuracy improvements that affect security detections across C#, Java/Kotlin, and GitHub Actions workflows.