Browse All Posts (141)
Allison announces an updated enforcement timeline for GitHub Actions self-hosted runner minimum versions on GitHub Enterprise Cloud, including what happens to runners below the required versions and how to avoid workflow disruption.
Kevin Stubbings explains how GitHub Security Lab’s open-source Taskflow Agent uses targeted LLM “taskflows” to audit Android apps, including how to run the workflows in a Codespace and what kinds of findings to expect. He also walks through two disclosed examples and where AI tends to produce false positives or misjudge severity.
Dan Wahlin introduces a free, open source “GitHub Copilot app for Beginners” course that teaches developers how to run and supervise AI coding agents in the Copilot desktop app, keep parallel work isolated with git worktrees, and validate changes with diffs, tests, previews, and PR checks.
Allison announces general availability of Claude Sonnet 5.5 in GitHub Copilot, including where you can select it (IDEs, Copilot CLI, coding agent, and GitHub clients), how it’s billed under usage-based pricing, and how Business/Enterprise admins can control access via model policy settings.
Elijah Newren reviews Git 2.56’s most practical changes for day-to-day workflows and large repo hosting, including safer conflict resolution staging, faster merge-base calculations, and server-friendly path-walk repacks that work with bitmaps and delta islands.
Daniel Roth introduces experimental Blazor AI components in .NET 11 RC1 for building “Agentic UI”: streamed agent output rendered as structured content blocks, tool calls, approvals, and shared state. The post walks through the AgenticUI sample architecture using Microsoft.Extensions.AI, AG-UI, Microsoft Agent Framework, ASP.NET Core, Foundry, and Aspire.
GitHub introduces how the GitHub Copilot app can stay involved after a pull request is opened, automatically fixing CI failures and addressing reviewer comments so changes can move toward merge with less manual back-and-forth.
Microsoft Threat Intelligence breaks down NeedyMantis, a modular post-compromise malware family used in targeted intrusions, covering its loader chain, custom encrypted archives, C2 over HTTPS/WebSockets, and the key indicators and hunting queries defenders can use in Microsoft Defender XDR and Microsoft Sentinel.
John Savill explains Azure Container Apps (ACA) Sandboxes, focusing on how they provide isolated, secure hosting for agent workloads. He covers the MicroVM-based model, egress controls via proxy and rules, lifecycle and pricing considerations, how sandbox groups work, and operational topics like managing instances and logging.
John Savill gives a quick overview of the Azure Container Apps (ACA) Sandboxes capability and how it relates to Microsoft’s own agentic solutions.
Mark Russinovich explains what tends to fail inside large-scale Azure data centers and why “rare” hardware issues become routine at hyperscale, using concrete examples like power units and processor sockets to frame resilience and reliability thinking.
This week in ML, the focus shifted toward running agent workflows closer to the data tier, with SQL-driven agentic RAG and chat completion patterns that bring prompts, tool calls, and logging under existing database security and auditing. We also saw practical guidance on agent isolation and durable memory using Azure AI Foundry with Azure Blob Storage, plus production-oriented debugging considerations when agents run as long-lived services. On the applied side, Microsoft Discovery highlighted a human-in-the-loop, multi-agent approach to wastewater metagenomics that keeps reproducibility and reviewability central. Rounding out the week, platform updates covered the operational plumbing that hybrid analytics and agent-backed pipelines depend on, including gateway improvements and expanded observability for Oracle AI Database@Azure.
Welcome to this week's Azure roundup, where the focus shifted from agent prototypes to agent platforms you can standardize and run. Microsoft Foundry expanded model options (including new GPT-6 SKUs and Claude Opus 5.5), added production primitives like Routines scheduling, hosted long-running execution, and deeper trace-driven evaluation and optimization. In parallel, Azure doubled down on controlling blast radius with Entra-backed identities and security guidance after real-world service principal abuse, while the container stack (AKS and Container Apps Sandboxes) pushed stronger isolation and scaling patterns for AI workloads. We also cover practical platform work: managed connectors in Azure Functions (preview), resilience validation beyond diagrams, experimental Bicep doc generation, and several storage and integration gotchas that can affect day-2 operations.
This week's AI roundup is about turning agents into production software: more model choice across GitHub Copilot, stronger policies and measurement for teams, and safer execution paths that hold up under real workloads. Copilot leaned further into agent-first workflows (across IDEs, the Copilot app, and chat tools), while adding sandboxing and OpenTelemetry tracing so sessions are easier to control and debug. Microsoft Foundry and the Agent Framework continued the same push with routinized execution, identity-aware design, routing for cost and quality, and concrete guardrails like isolation and network egress policy. We wrap with applied architectures and security research that underline why auditability, least privilege, and evaluation-driven governance now need to be part of the default playbook.
This week in security, the focus shifted from adding more automation to putting tighter boundaries around it, starting with stronger identity and session controls in GitHub and extending into agent governance across Microsoft Foundry. Updates also targeted the places teams tend to forget until something breaks, including SSH hardening, CodeQL packaging changes, and NuGet signing trust policies that can block CI if you do not update proactively. On the threat side, new reporting on compromised service principals and device code token theft reinforced an identity-first reality where attackers can automate destruction and persistence once they have the right tokens. Rounding things out, platform guidance and releases highlighted practical isolation and egress controls (microVM sandboxes, pod sandboxing, confidential containers) plus operational lessons like how Blob immutability can quietly prevent cleanup when you need it most.
This week in DevOps, GitHub Actions made breaking-but-necessary runtime and API changes (Node.js 24 for JavaScript actions, artifact visibility updates, and new query count limits) that will affect pipelines, dashboards, and automation. GitHub also pushed collaboration and security forward with richer PR triage, review-stage metrics, SSH hardening, and proof-of-presence controls for sensitive enterprise actions. On the platform side, Azure sharpened the agent operations story with Foundry governance, Container Apps Sandboxes (microVM isolation with egress control and OTLP export), and AKS updates for isolated and confidential AI workloads. Across it all, the practical theme is treating agents, CI, and security controls like production systems: pin versions, instrument everything, and design for policy and scale.
This week in .NET centers on production readiness: Microsoft rotated its NuGet author-signing certificate (which can break locked-down restores), while agent building guidance moved from demos to deployable systems with AG-UI, memory, isolation, and secret redaction patterns. On the operations side, repeatable dump capture and Visual Studio analysis workflows showed how to diagnose real production hangs like thread pool saturation. We also saw steady momentum in platform hygiene, from .NET 11 preview security hardening (including experimental DBSC) to CodeQL improvements and Azure Functions expanding managed connector triggers in public preview.
GitHub demonstrates how to connect the GitHub Copilot app to Windows Subsystem for Linux (WSL) so you can run Copilot coding agents directly inside an Ubuntu environment, handle parallel feature requests with Git worktrees, preview changes in an in-app browser, and verify diffs without leaving the app.
Microsoft Developer shares a weekly developer-news roundup covering .NET memory dumps for diagnosing failures, the pitfalls of migrating time-related data between PostgreSQL and SQL Server, and how AI agents can use stronger isolation plus durable memory with Microsoft Foundry and Azure Blob Storage.
GitHub shows how maintainers can automate issue triage using GitHub issue intents, including confidence thresholds, reviewing agent reasoning, and auto-applying routine metadata updates while keeping humans in control.
Allison announces an in-product validator for GitHub Copilot enterprise managed settings that helps admins catch configuration issues (like malformed JSON, unsupported settings, and invalid team mappings) so Copilot policies are enforced correctly across the enterprise.
Allison announces an update to GitHub Copilot repository-level usage metrics that breaks pull request review time into distinct stages, helping teams pinpoint where PRs are getting stuck (waiting for first review, review iteration, or post-approval merge delay).
sbaynes introduces run-assert-eval, a VS Code “skill” that threat-models an AI agent, turns discovered risks into measurable eval suites, generates runtime governance policy, and reruns the same evaluation to show whether the mitigation actually reduced failures (without sacrificing helpfulness).
Private saved views for repository issues and “Relates to” issue relationship is generally available
Allison announces two GitHub Issues updates: private saved views on repository issues pages, and general availability of the “Relates to” issue relationship across GitHub’s APIs, webhooks, timeline events, and search.
Mark Russinovich recounts a 2014 incident where a developer’s code nearly caused a worldwide Azure outage, and explains the safe deployment policy that came out of it as part of a broader discussion on Azure resilience.
Matt Kazanowsky describes an Azure reference architecture that turns assembly videos into illustrated manufacturing work instructions using multimodal GenAI. It breaks down the end-to-end pipeline (ingestion, transcription, human review gates, step extraction, frame selection, and document generation) and calls out practical security controls for storage, identity, networking, and AI safety.
Tyler Leonhardt explains how to use different model “harnesses” in VS Code with GitHub Copilot, including Claude and Codex, and how bring-your-own-key (BYOK) changes the ways you can access models from your editor.
Tommi Gustafsson and Janne Gustafsson join the .NET MAUI Community Standup to explain how they built GnollHack, a cross-platform roguelike, using .NET MAUI to target Android, iOS, and Windows, and to share practical lessons from modernizing a classic NetHack-based codebase for mobile-friendly gameplay.
Allison explains a change to GitHub Actions workflow run queries in the API and UI: result counts are now capped at “2,500+” to avoid timeouts returning misleading totals, while pagination still returns up to 1,000 items per query.
Kayla Cinnamon explains how to use canvases in the GitHub Copilot app to generate a custom, shared UI (like a kanban board or release checklist) from a plain-English description, then iteratively refine it while the agent updates the same live surface.
Allison announces that GitHub’s agentic autofix can now use Copilot Memory to pull repository-specific context when resolving security alerts, and to store fix patterns as reusable memories for future fixes and other Copilot features.
Daniel Roth announces the new AG-UI .NET SDK and shows how to expose and consume interoperable agent endpoints from .NET using Microsoft.Extensions.AI. The post explains the AG-UI event model, includes an ASP.NET Core quickstart for streaming Server-Sent Events, and outlines how Microsoft Agent Framework now builds on the shared AGUI.* packages.
Microsoft Developer demonstrates how to use Azure AI Foundry’s model router so a single deployment can dynamically route requests to different models, balancing cost and quality while keeping the agent integration to a minimal code change.
Allison summarizes the September 21 weekly GitHub Copilot releases, including new model options, a local sandboxing preview in the Copilot app, and feature updates across Slack/Teams, JetBrains IDEs, and VS Code—especially around agent sessions, remote development, and observability.
Allison outlines updates to GitHub Copilot’s Slack and Microsoft Teams integrations, focusing on richer conversation context, better traceability when creating GitHub work, and more control over model selection and repository defaults. The post also summarizes reliability fixes and explains preview availability for Copilot Business and Enterprise.
goupadhy announces the September 2026 on-premises data gateway release (v3000.334), highlighting a new Soft Delete recovery window, security dependency updates (including Log4j 2.26.1 and a fix for CVE-2026-18401), and compatibility alignment with the September 2026 Power BI Desktop query runtime.
John Savill runs through the Azure Weekly Update for 25 September 2026, covering a grab bag of platform changes across compute, serverless, containers, PostgreSQL, and Azure AI Foundry, plus several GitHub Copilot and model availability updates and a retirement notice.
Microsoft Security Research, Yossi Weizman and Tushar Mudi detail Storm-3168 (JADEPUFFER) activity in Azure, showing how compromised service principals were used for reconnaissance, rapid resource deletion, and credential access. The post breaks down the observed sequence and provides concrete mitigations using Defender for Cloud, RBAC hardening, secret rotation, and recovery protections.
GitHub introduces Canvas in the GitHub Copilot app, showing how developers can describe a workspace UI in plain language and have Copilot generate interactive tools like dashboards and issue trackers without writing UI code.