Agentic DevOps watchlist
Azure, GitHub, and Azure DevOps announcements from the last 90 days for the agents and platform tools on the watchlist.
Copilot code review now resolves its own comments once you address them and writes smart commit messages for you when you apply its code suggestions. Comments are automatically resolved when a later commit addresses the underlying feedback.
Copilot code review now resolves its own comments once you address them and writes smart commit messages for you when you apply its code suggestions. Behind the scenes, Copilot now uses a broader set of shell tools to validate the code it reviews, and an ensemble of agents produce a more thorough review within the Lite effort level. Together, these updates make it easier to focus on the feedback that still matters and give Copilot more ways to check its work.
You can now manage GitHub code scanning’s AI Scan for pull request enablement with REST API endpoints at the organization and repository levels.
You can now manage GitHub code scanning’s AI Scan for pull request enablement with REST API endpoints at the organization and repository levels. This public preview gives teams a programmatic way to roll out AI-powered security detections for pull requests across select repositories without manually configuring each setting in the GitHub UI.
Azure Copilot Troubleshooting Agent is now generally available.
Azure Copilot Troubleshooting Agent is now generally available. Troubleshooting Agent is a unified, built-in Azure Copilot capability that helps customers investigate and resolve operational issues faster. Available through both Azure Copilot and Support + Troubleshooting in the Azure portal, Troubleshooting Agent enables you to move from issue detection to resolution faster by bringing together troubleshooting insights, operational context, and recommended actions in a single experience. Learn more .
If you administer GitHub Copilot Business or GitHub Copilot Enterprise, you can now centrally control which agent operations are blocked, require human approval, or can proceed without a prompt.
If you administer GitHub Copilot Business or GitHub Copilot Enterprise, you can now centrally control which agent operations are blocked, require human approval, or can proceed without a prompt. Managed permissions cover shell commands, file reads and edits, and network domains. This gives you fine-grained guardrails for sensitive operations without disabling agent workflows. Managed restrictions can’t be weakened by user or workspace settings, auto-approval, or previously saved approvals. You can also provide specialized policies for different enterprise teams. These controls are generally available in the GitHub Copilot app, GitHub Copilot CLI, and Visual Studio Code sessions that use Agen
More GitHub Enterprise Cloud customers can now start a self-serve GitHub Advanced Security trial to evaluate GitHub Code Security and GitHub Secret Protection.
More GitHub Enterprise Cloud customers can now start a self-serve GitHub Advanced Security trial to evaluate GitHub Code Security and GitHub Secret Protection. Eligibility has expanded from enterprises with up to 100 licenses to enterprises with up to 300 licenses. To set up a GitHub Advanced Security trial, go to the Enterprise “Billing and licensing” page. For details, see self-serve GitHub Advanced Security trials . The post GitHub Advanced Security expands trial availability appeared first on The GitHub Blog .
Repository rulesets allow you to easily add scalable protections across your repositories. A secret scan has completed for the head commit.
Repository rulesets allow you to easily add scalable protections across your repositories. Starting today, you can use repository rulesets to block pull requests from merging when the pull request introduces secret scanning alerts.
Agentic autofix is now available to help you burn down findings in your code quality backlog.
Agentic autofix is now available to help you burn down findings in your code quality backlog. You can select up to 25 standard findings on a page and assign the whole set to Copilot in one action. Copilot starts fixing them agentically on a branch, validates its own changes, then opens a pull request for you to review and merge. Assign to Copilot replaces Generate fix for individual findings, so you get one consistent flow whether you select one finding or 25. Agentic autofix follows your existing enterprise policy for GitHub Code Quality. There is no separate policy to manage, so if your enterprise allows GitHub Code Quality, users can use bulk remediation too. Assigning findings to Copilot
This update brings support for enterprise-managed sandbox policies, cross-file cursor jumps for next edit suggestions, global project context in chat, enterprise policy diagnostics, and a new connection between terminal Copilot CLI sessions and JetBrains IDEs. Background agent prompts : Improved the ask-user card to better.
This update brings support for enterprise-managed sandbox policies, cross-file cursor jumps for next edit suggestions, global project context in chat, enterprise policy diagnostics, and a new connection between terminal Copilot CLI sessions and JetBrains IDEs. It also improves model selection, the chat experience, and reliability across MCP servers and agent sessions.
This week, GitHub Copilot expands model choice and content protections, while VS Code adds new ways to manage agent sessions and get pull requests merge-ready. Claude Fable 5.1 is available to Copilot Pro+, Max, Business, and Enterprise users.
This week, GitHub Copilot expands model choice and content protections, while VS Code adds new ways to manage agent sessions and get pull requests merge-ready.
Copilot now tells you when a pull request is ready to approve, and admins can authorize it to sign off on approval. Enterprise: Admins can leave approvals off for the whole enterprise or let organizations decide.
Copilot now tells you when a pull request is ready to approve, and admins can authorize it to sign off on approval. The ability for Copilot to approve is off by default and configurable at the enterprise, organization, and repository level. The approval assessments will now appear as a part of the overview comment in every Copilot review. This feature is available in public preview to GitHub Copilot Pro, Pro+, Max, Business, and Enterprise plans.
Azure Copilot Observability Agent, an AI-powered operational companion in Azure Monitor, is now covering Log Analytics data in Basic and Auxiliary table plans during interactive analysis and deep investigations.
Azure Copilot Observability Agent, an AI-powered operational companion in Azure Monitor, is now covering Log Analytics data in Basic and Auxiliary table plans during interactive analysis and deep investigations. Teams can move high-volume telemetry - including container stdout and stderr , audit trails, and node syslog - to lower-cost table plans while keeping supported data available to the agent alongside metrics, traces, topology, and Azure resource context. This is especially useful for Kubernetes operations, where high-volume telemetry such as ContainerLogV2, AKS audit logs, and control-plane logs can be candidates for the Basic table plan. If eligible tables already use the Basic or Au
This changelog covers VS Code v1.132 through v1.135 , shipped throughout August 2026. Arrange chats side by side: Keep multiple chats visible in horizontal or vertical groups to compare results or follow your agent’s work, with the layout restored when you return to the session.
This changelog covers VS Code v1.132 through v1.135 , shipped throughout August 2026. These releases make it easier to organize agent sessions, review changes, and navigate long conversations. Agent Host, the integrated browser, and dictation also get updates to support more ways of working in VS Code.
Copilot code review can now review two types of pull requests it didn’t cover before:. Reviews requested automatically on pull requests authored by bots, including Copilot cloud agent.
Copilot code review can now review two types of pull requests it didn’t cover before:
The Azure DevOps plugin is now available for the GitHub Copilot app , allowing you to view and manage Azure DevOps pull requests and work items directly in the Copilot app. View your work items and pull requests from My Work.
The Azure DevOps plugin is now available for the GitHub Copilot app , allowing you to view and manage Azure DevOps pull requests and work items directly in the Copilot app.
We're excited to announce Live Reports, now in Public Preview for Azure SRE Agent.
We're excited to announce Live Reports, now in Public Preview for Azure SRE Agent. Live Reports help operations teams create dynamic operational views directly from SRE Agent conversations and keep them continuously up to date with the latest data from connected environments. Instead of manually rebuilding dashboards or collecting information across multiple tools, teams can use Azure SRE Agent to automatically generate the report and return to it anytime, with fresh data surfaced on a daily, weekly or monthly cadence that you define. Whether you're tracking incidents, service health, operational trends, or recurring investigations, Live Reports provide a consistent, shareable, and always-cu
Azure SRE Agent VNet Integration is now generally available.
Azure SRE Agent VNet Integration is now generally available. VNet integration enables Azure SRE Agent to operate within your existing network controls, including Network Security Groups (NSGs), private DNS, and firewall policies, etc. With VNet support, the agent can securely access private resources, including services behind private endpoints, during incident investigation and remediation without requiring changes to your network boundary. This capability helps organizations extend Azure SRE Agent into security-sensitive environments while maintaining existing networking, security, and compliance controls. Learn more .
New customers can now get started with Azure SRE Agent through a 30-day trial experience. Investigate a root cause: Let the agent work across alerts, logs, metrics, traces, Azure resource state, code, and recent deployments to build a likely root cause and suggest a mitigation.
New customers can now get started with Azure SRE Agent through a 30-day trial experience. During the trial, customers can create SRE Agents and connect them to your operational tools and data sources, and explore capabilities at their own pace without baseline always-on charges. Customers pay only for Azure Agent Units (AAUs) consumed when agents perform work. Here are a few practical ways developers, SREs, and IT operations teams can use the 30-day trial:
Today, we’re announcing the public preview of GitHub Copilot Code Review for Azure Repos, making the feature available to all Azure DevOps customers using the service.
Today, we’re announcing the public preview of GitHub Copilot Code Review for Azure Repos, making the feature available to all Azure DevOps customers using the service. There’s no longer a need to sign up for early access. Customers can now enable Copilot Code Review for their Azure Repos repositories and start using it. With the public preview, we’re also introducing several improvements we’ve made over the past couple of months based on what we’ve learned during the technical preview. Before getting started, be sure to read the official documentation for details on how Copilot Code Review works, how to enable it, and what to expect around usage and billing. Let’s take a look at what’s new.
Starting in August 2026, customers can engage directly with Azure Copilot agents and select the specific agent best suited to their needs.
Starting in August 2026, customers can engage directly with Azure Copilot agents to move more quickly from questions to action. With this update:
You can now dismiss a code scanning alert with the reason Mitigated when a vulnerability remains in the code but external controls, such as a web application firewall or network policy, mitigate its risk.
You can now dismiss a code scanning alert with the reason Mitigated when a vulnerability remains in the code but external controls, such as a web application firewall or network policy, mitigate its risk. The new dismissal reason helps you distinguish mitigated vulnerabilities from alerts marked Won’t fix , align dismissals with formal exception and risk-acceptance processes, and reduce the need to track these decisions outside GitHub. For more information, see resolving code scanning alerts . The post Code scanning adds a mitigated alert dismissal reason appeared first on The GitHub Blog .
A dedicated workflow path for code quality CodeQL actions workflows is now generally available. Change Actions usage and billing reports that filter on so they also account for .
A dedicated workflow path for code quality CodeQL actions workflows is now generally available. Your workflow run history and your Actions usage reports now tell GitHub Code Quality runs apart from GitHub code scanning runs. Code Quality analysis runs on and shows as the actor, instead of sharing the path and the actor with code scanning.
Lite and Balanced effort levels for GitHub Copilot code review are now generally available. Choose Lite for feedback on straightforward changes.
Lite and Balanced effort levels for GitHub Copilot code review are now generally available. They let you match the depth of a review to the complexity and risk of a pull request. Not every pull request needs the same scrutiny. Documentation updates and small fixes may only need focused feedback, while complex logic, security-sensitive code, and cross-service changes benefit from deeper analysis. You can now:
This release expands secret scanning’s coverage with more secrets blocked by push protection, one new secret scanning partner, and richer metadata on alerts.
This release expands secret scanning’s coverage with more secrets blocked by push protection, one new secret scanning partner, and richer metadata on alerts.
Today, we’re excited to announce the general availability of the Azure DevOps MCP Server The Azure DevOps MCP Server gives AI assistants secure, contextual access to your Azure DevOps projects so they can help you plan, build, and ship software more effectively.
Today, we’re excited to announce the general availability of the Azure DevOps MCP Server The Azure DevOps MCP Server gives AI assistants secure, contextual access to your Azure DevOps projects so they can help you plan, build, and ship software more effectively. With the Azure DevOps remote MCP Server , you can get started without installing or hosting anything yourself. Simply connect your AI assistant directly to the Azure DevOps hosted endpoint by using streamable HTTP transport and start working with your projects in minutes.
You can now apply your own configuration file to code scanning default setup, using the new repository property.
You can now apply your own configuration file to code scanning default setup, using the new repository property. This gives you control over how CodeQL scans your code for security vulnerabilities, whether that’s on one repository or across your whole organization. We recommend using this way to customize your security analysis at scale. You get the granular control of advanced setup without writing or maintaining a GitHub Actions workflow file in every repository.
Copilot code review support for agent skills and MCP servers is now generally available for Copilot Pro, Pro+, Business, and Enterprise users. Agent skills let Copilot invoke your team’s internal tools and coding standards during a review, while MCP servers pull external context into reviews.
Copilot code review support for agent skills and MCP servers is now generally available for all Copilot Pro, Pro+, Business, and Enterprise users. Previously announced in public preview , these capabilities let you bring your team’s tools, standards, and external context directly into every code review.
The GitHub Copilot app now has its own policy, so you can control who has access to it at the enterprise and organization levels. Enabled everywhere gives your developers access to the app.
The GitHub Copilot app now has its own policy, so you can control who has access to it at the enterprise and organization levels. Until now, access to the Copilot app depended on your GitHub Copilot CLI policy being enabled. From several conversations with customers, we understand that many of you want to manage each client independently. Now the Copilot app and the Copilot CLI each have their own policy, giving you the flexibility and control to enable the right clients for your teams. This new policy keeps your developers’ work within the guardrails you already rely on. When using this app, developers drive agent sessions in isolated workspaces and land changes through pull requests. This
GitHub Code Quality is now generally available on GitHub Enterprise Cloud and GitHub Team. Organization-wide enablement, with org-level dashboards that show maintainability and reliability scores across your repositories.
GitHub Code Quality is now generally available on GitHub Enterprise Cloud and GitHub Team. It solves an emerging challenge for software development: AI accelerates code output, and Code Quality helps teams ship code they trust. Code Quality pairs CodeQL’s deterministic analysis with AI-assisted detection to catch maintainability and reliability issues in your pull requests, and Copilot Autofix suggests fixes for you to review before you merge. In GitHub’s own engineering organization, teams resolve 67.3% of Code Quality findings before merging pull requests.
The Copilot usage metrics REST API now reports repository-level activity. Pull requests created and merged by Copilot coding agent.
The Copilot usage metrics REST API now reports repository-level activity. Two new endpoints return a daily, per-repository breakdown of pull request activity for Copilot coding agent and Copilot code review. They do this for both enterprise and organization reports.
The Copilot usage metrics API now reports the GitHub Copilot app usage in the enterprise and organization 1-day and 28-day reports. : The number of distinct users active in the Copilot app on a given day.
The Copilot usage metrics API now reports the GitHub Copilot app usage in the enterprise and organization 1-day and 28-day reports. This gives enterprise and organization admins visibility into the app’s activity alongside the IDE, chat, code review, and coding agent metrics they already retrieve.
Copilot code review now utilizes a firewall, custom setup steps, and independent runner configurations. Add a file to your repository to define setup steps specific to Copilot code review.
Copilot code review now utilizes a firewall, custom setup steps, and independent runner configurations. It now reads custom instructions from the head branch to allow for easy testing and validation of custom instructions. These changes give administrators and developers more control over how Copilot code review runs in their environment.
This week, we’re rolling out several improvements to secret scanning and public monitoring:. Resend is now a GitHub secret scanning partner.
This week, we’re rolling out several improvements to secret scanning and public monitoring:
GitHub code scanning now surfaces AI-powered security detections directly on pull requests, expanding vulnerability coverage to languages and frameworks not currently supported by CodeQL. Broader language coverage : AI-powered detections extend code scanning to languages and frameworks beyond those supported by CodeQL’s built-in analysis ,.
GitHub code scanning now surfaces AI-powered security detections directly on pull requests, expanding vulnerability coverage to languages and frameworks not currently supported by CodeQL. These detections help teams identify and address potential issues in parts of the codebase that previously had no native scanning coverage, all before code is merged.
Starting today, security teams can create, edit, and manage secret scanning custom patterns with the REST API. list patterns.
Starting today, security teams can create, edit, and manage secret scanning custom patterns with the REST API.
To make secret scanning easier to understand, we’re updating the names we use for our detector types to better reflect how each one finds secrets. Provider secrets are issued by a specific service (e.g., an AWS key, a Stripe token).
To make secret scanning easier to understand, we’re updating the names we use for our detector types to better reflect how each one finds secrets. This is a naming change only; detection behavior is exactly the same. Before Now Non-provider patterns Generic patterns Copilot secret scanning AI-detected secrets All existing product documentation links continue to work. We’ve added redirects and updated the terminology across our documentation. There are no changes to webhook events, audit log events, or the REST API. There are two kinds of secrets we detect:
Agentic autofix is now in public preview for all code scanning alerts. Explores relevant files across your codebase.
Agentic autofix is now in public preview for all code scanning alerts. It remediates alerts generated by CodeQL and third-party scanning tools by working across your codebase the way a developer would—it explores relevant files, proposes a fix, and reruns the original analysis to confirm the fix closes the alert before opening a pull request for your review. Agentic autofix is available to organizations with both GitHub Code Security (or GitHub Advanced Security) and a Copilot license with Copilot cloud agent enabled. Editor’s note (July 16, 2026): Clarified that autofix works for all first-party and third-party code scanning alerts.
You can now create and run Azure Chaos Studio resilience Scenarios directly from the Azure CLI with the new az chaos extension — no more hand-assembling REST calls and JSON files.
You can now create and run Azure Chaos Studio resilience Scenarios directly from the Azure CLI with the new az chaos extension — no more hand-assembling REST calls and JSON files. Get started in one step: az chaos setup stands up a workspace, wires up permissions, discovers your resources, and recommends Scenarios (like Zone Down) tailored to what you're running. From there, configure, validate, and run a Scenario in a few clear commands — with built-in --help, tab completion, and table/JSON/TSV output. Install with az extension add --name chaos.
Azure Chaos Studio now supports Workspaces and Scenarios, a faster, application-centric way to validate how your workloads hold up during real outages. Simulate common outage patterns out of the box, including availability zone failures, DNS and Microsoft Entra ID outages, PostgreSQL and SQL Managed Instance.
Azure Chaos Studio now supports Workspaces and Scenarios, a faster, application-centric way to validate how your workloads hold up during real outages. Point a Workspace at your application's scope—a subscription, resource group, or service group—and Chaos Studio discovers the resources inside it and recommends Scenarios: preconfigured tests that reproduce real-world outage patterns. Select a Scenario, and Chaos Studio injects the right faults, in the right order, across every affected resource, then produces a Scenario report showing exactly what happened. With Workspaces and Scenarios, you can:
To help you understand ownership and impact of a leaked secret, GitHub secret scanning surfaces enriched metadata for supported secret types.
To help you understand ownership and impact of a leaked secret, GitHub secret scanning surfaces enriched metadata for supported secret types. Extended metadata checks are now generally available, including support for multipart validators with supplementary metadata.
GitHub Enterprise Cloud customers with enterprise managed users can now access GitHub Copilot agent session data across all Copilot clients, including:. Cloud agents operating on github.com and data resident deployments on ghe.com.
GitHub Enterprise Cloud customers with enterprise managed users can now access GitHub Copilot agent session data across all Copilot clients, including:
GitHub is committed to empowering the developer community by helping organizations recognize and address the risks of secret leaks wherever they happen.
GitHub is committed to empowering the developer community by helping organizations recognize and address the risks of secret leaks wherever they happen. We believe every enterprise should know the moment its secrets leak in public, no matter where it happens on GitHub. That’s why public monitoring is now in public preview for enterprises with GitHub Secret Protection, at no additional cost. Secrets don’t respect boundaries; scanning for them shouldn’t either.
Secret scanning now runs validity checks on Asana, IBM, and MessageBird secrets so you can tell whether a leaked credential is still active.
Secret scanning now runs validity checks on Asana, IBM, and MessageBird secrets so you can tell whether a leaked credential is still active.
Today, JetBrains and GitHub are announcing a deeper integration between JetBrains AI Assistant and GitHub Copilot.
Today, JetBrains and GitHub are announcing a deeper integration between JetBrains AI Assistant and GitHub Copilot. Millions of developers already rely on the GitHub Copilot plugin as their AI pair programmer in JetBrains IDEs, and Copilot has also been available inside JetBrains AI Assistant through the Agent Client Protocol (ACP) . Now we are taking the next step: GitHub Copilot is a first-class option in the AI Assistant agent picker, so you can choose the entry point that best fits your workflow.
Copilot code review now uses the built-in file exploration tools available in the Copilot CLI and SDK, significantly improving review cost efficiency with no change to your existing workflow. attribution in the pull request overview comment : Copilot code review now labels medium analysis depth.
Copilot code review now uses the built-in file exploration tools available in the Copilot CLI and SDK, significantly improving review cost efficiency with no change to your existing workflow. If you’re in the Medium analysis depth public preview, you’ll also see some new updates centered around configurability and visibility of review depth.
GitHub Copilot for Jira is now generally available. Model selection from within Jira.
GitHub Copilot for Jira is now generally available. Since launching the public preview in March 2026, we have shipped a series of enhancements based on your feedback, including model selection, Confluence context via MCP, custom agents, custom fields, space-level guidance, and review request notifications in Jira. Today’s release to general availability builds on that foundation with new capabilities designed to give you greater visibility and control over agent sessions.
Secret scanning now includes extended metadata for Replicate secrets, providing richer context for leaked credentials.
Secret scanning now includes extended metadata for Replicate secrets, providing richer context for leaked credentials.
The GitHub Copilot app now supports bring your own key (BYOK), so you can run agent sessions against your own model providers, including OpenAI, Azure OpenAI, Microsoft Foundry, Anthropic, LM Studio, Ollama, and any OpenAI-compatible endpoint. Connect the providers you already use: Add Azure OpenAI,.
The GitHub Copilot app now supports bring your own key (BYOK), so you can run agent sessions against your own model providers, including OpenAI, Azure OpenAI, Microsoft Foundry, Anthropic, LM Studio, Ollama, and any OpenAI-compatible endpoint. Add a provider in Settings → Model Providers with your endpoint and API key, or just a host for LM Studio or Ollama. Once added, your provider’s models appear in the model picker alongside Copilot-hosted models, and you choose which one to use each session. Keys are stored in the local OS keychain and are never read back by the UI. With BYOK you can:
Copilot code review now supports repository-level files, and it’s easier to request a review from Copilot on draft pull requests with the Request button. Reads from the root of your repository.
Copilot code review now supports repository-level files, and it’s easier to request a review from Copilot on draft pull requests with the Request button. These changes are all generally available.
Since our last pattern update , we’ve expanded secret scanning’s detection coverage with new partners, more patterns blocked by push protection by default, additional validity checks, and richer metadata for leaked secrets.
Since our last pattern update , we’ve expanded secret scanning’s detection coverage with new partners, more patterns blocked by push protection by default, additional validity checks, and richer metadata for leaked secrets.
No updates match your filters.