Agentic DevOps watchlist

Agentic DevOps Updates

Azure, GitHub, and Azure DevOps announcements from the last 90 days for the agents and platform tools on the watchlist.

Topics tracked
8
Updates
50
Generally available
10
In preview
7
  1. Auto-resolution and analysis updates in Copilot code review

    Latest Copilot Code Review GitHub Changelog

    Update

    Published

    Copilot code review now resolves its own comments once you address them and writes smart commit messages for you when you apply its code suggestions. Comments are automatically resolved when a later commit addresses the underlying feedback.

    Key points

    • Comments are automatically resolved when a later commit addresses the underlying feedback.
    • Feedback that is still outstanding stays open, so nothing gets lost.

    From the announcement

    Copilot code review now resolves its own comments once you address them and writes smart commit messages for you when you apply its code suggestions. Behind the scenes, Copilot now uses a broader set of shell tools to validate the code it reviews, and an ensemble of agents produce a more thorough review within the Lite effort level. Together, these updates make it easier to focus on the feedback that still matters and give Copilot more ways to check its work.

  2. AI Scan for pull request APIs in public preview

    GitHub Advanced Security GitHub Changelog

    Preview

    Published

    You can now manage GitHub code scanning’s AI Scan for pull request enablement with REST API endpoints at the organization and repository levels.

    From the announcement

    You can now manage GitHub code scanning’s AI Scan for pull request enablement with REST API endpoints at the organization and repository levels. This public preview gives teams a programmatic way to roll out AI-powered security detections for pull requests across select repositories without manually configuring each setting in the GitHub UI.

  3. Generally Available: Azure Copilot Troubleshooting Agent

    Azure Monitor Observability Agent Azure Updates

    Generally available

    GA
    Sep 2026
    Published

    Azure Copilot Troubleshooting Agent is now generally available.

    From the announcement

    Azure Copilot Troubleshooting Agent is now generally available. Troubleshooting Agent is a unified, built-in Azure Copilot capability that helps customers investigate and resolve operational issues faster. Available through both Azure Copilot and Support + Troubleshooting in the Azure portal, Troubleshooting Agent enables you to move from issue detection to resolution faster by bringing together troubleshooting insights, operational context, and recommended actions in a single experience. Learn more .

  4. Enterprise managed permissions for GitHub Copilot agent operations

    Copilot Coding Agent GitHub Changelog

    Update

    Published

    If you administer GitHub Copilot Business or GitHub Copilot Enterprise, you can now centrally control which agent operations are blocked, require human approval, or can proceed without a prompt.

    From the announcement

    If you administer GitHub Copilot Business or GitHub Copilot Enterprise, you can now centrally control which agent operations are blocked, require human approval, or can proceed without a prompt. Managed permissions cover shell commands, file reads and edits, and network domains. This gives you fine-grained guardrails for sensitive operations without disabling agent workflows. Managed restrictions can’t be weakened by user or workspace settings, auto-approval, or previously saved approvals. You can also provide specialized policies for different enterprise teams. These controls are generally available in the GitHub Copilot app, GitHub Copilot CLI, and Visual Studio Code sessions that use Agen

  5. GitHub Advanced Security expands trial availability

    GitHub Advanced Security GitHub Changelog

    Update

    Published

    More GitHub Enterprise Cloud customers can now start a self-serve GitHub Advanced Security trial to evaluate GitHub Code Security and GitHub Secret Protection.

    From the announcement

    More GitHub Enterprise Cloud customers can now start a self-serve GitHub Advanced Security trial to evaluate GitHub Code Security and GitHub Secret Protection. Eligibility has expanded from enterprises with up to 100 licenses to enterprises with up to 300 licenses. To set up a GitHub Advanced Security trial, go to the Enterprise “Billing and licensing” page. For details, see self-serve GitHub Advanced Security trials . The post GitHub Advanced Security expands trial availability appeared first on The GitHub Blog .

  6. Block pull requests with exposed secrets from merging

    GitHub Advanced Security GitHub Changelog

    Update

    Published

    Repository rulesets allow you to easily add scalable protections across your repositories. A secret scan has completed for the head commit.

    Key points

    • A secret scan has completed for the head commit
    • No alerts are open for secrets introduced by the pull request’s commits
    • In your repository, organization, or enterprise settings, go to the Repository > Rulesets tab.
    • Create or edit a ruleset targeting the branches you want to protect.
    • Select Require secret scanning alerts are resolved .

    From the announcement

    Repository rulesets allow you to easily add scalable protections across your repositories. Starting today, you can use repository rulesets to block pull requests from merging when the pull request introduces secret scanning alerts.

  7. Remediate Code Quality findings with agentic autofix

    Copilot Coding Agent GitHub Changelog

    Update

    Published

    Agentic autofix is now available to help you burn down findings in your code quality backlog.

    From the announcement

    Agentic autofix is now available to help you burn down findings in your code quality backlog. You can select up to 25 standard findings on a page and assign the whole set to Copilot in one action. Copilot starts fixing them agentically on a branch, validates its own changes, then opens a pull request for you to review and merge. Assign to Copilot replaces Generate fix for individual findings, so you get one consistent flow whether you select one finding or 25. Agentic autofix follows your existing enterprise policy for GitHub Code Quality. There is no separate policy to manage, so if your enterprise allows GitHub Code Quality, users can use bulk remediation too. Assigning findings to Copilot

  8. Enterprise-managed sandbox in Copilot for JetBrains

    Copilot Coding Agent GitHub Changelog

    Update

    Published

    This update brings support for enterprise-managed sandbox policies, cross-file cursor jumps for next edit suggestions, global project context in chat, enterprise policy diagnostics, and a new connection between terminal Copilot CLI sessions and JetBrains IDEs. Background agent prompts : Improved the ask-user card to better.

    Key points

    • Background agent prompts : Improved the ask-user card to better accommodate long questions.
    • Model selection : Refined model picker behavior and BYOK grouping to make model choices easier to scan and select.
    • Subagent models : Added support for selecting the session model used by built-in subagents in the Copilot agent harness.
    • Agent debug logs : Added section copy support so you can share diagnostics and troubleshooting context faster.
    • MCP configuration : Opened MCP configuration in the originating project window for better continuity.
    • Plugin updates : Improved update reminders to make new plugin versions easier to discover.

    From the announcement

    This update brings support for enterprise-managed sandbox policies, cross-file cursor jumps for next edit suggestions, global project context in chat, enterprise policy diagnostics, and a new connection between terminal Copilot CLI sessions and JetBrains IDEs. It also improves model selection, the chat experience, and reliability across MCP servers and agent sessions.

  9. GitHub Copilot weekly releases — August 31

    Copilot Coding Agent GitHub Changelog

    Update

    Published

    This week, GitHub Copilot expands model choice and content protections, while VS Code adds new ways to manage agent sessions and get pull requests merge-ready. Claude Fable 5.1 is available to Copilot Pro+, Max, Business, and Enterprise users.

    Key points

    • Claude Fable 5.1 is available to Copilot Pro+, Max, Business, and Enterprise users.
    • Gemini 3.8 Flash is rolling out to Copilot Pro, Pro+, Max, Business, and Enterprise users.
    • Copilot app and CLI now honor content exclusions, keeping sensitive code out of context across agentic workflows.
    • Agent Merge is now in public preview and gets your pull request ready to merge by resolving review feedback, failed checks, and merge conflicts.
    • Multi-root workspaces are now experimental and bring Copilot and Claude agent sessions to every folder in your workspace.
    • Chat backgrounds are now experimental and let you personalize the Agents window with built-in patterns or your own images.

    From the announcement

    This week, GitHub Copilot expands model choice and content protections, while VS Code adds new ways to manage agent sessions and get pull requests merge-ready.

  10. Copilot code review can now approve pull requests

    Copilot Code Review GitHub Changelog

    Update

    Published

    Copilot now tells you when a pull request is ready to approve, and admins can authorize it to sign off on approval. Enterprise: Admins can leave approvals off for the whole enterprise or let organizations decide.

    Key points

    • Enterprise: Admins can leave approvals off for the whole enterprise or let organizations decide.
    • Organization: Admins can turn approvals on org-wide, let repository admins decide, enable it for specific repositories, or turn it off org-wide.
    • Repository: Admins can turn approvals on or off, and choose which file paths Copilot is allowed to approve.

    From the announcement

    Copilot now tells you when a pull request is ready to approve, and admins can authorize it to sign off on approval. The ability for Copilot to approve is off by default and configurable at the enterprise, organization, and repository level. The approval assessments will now appear as a part of the overview comment in every Copilot review. This feature is available in public preview to GitHub Copilot Pro, Pro+, Max, Business, and Enterprise plans.

  11. Generally Available: Azure Copilot Observability Agent supports Basic and Auxiliary table plans

    Azure Monitor Observability Agent Azure Updates

    Generally available

    GA
    Aug 2026
    Published

    Azure Copilot Observability Agent, an AI-powered operational companion in Azure Monitor, is now covering Log Analytics data in Basic and Auxiliary table plans during interactive analysis and deep investigations.

    From the announcement

    Azure Copilot Observability Agent, an AI-powered operational companion in Azure Monitor, is now covering Log Analytics data in Basic and Auxiliary table plans during interactive analysis and deep investigations. Teams can move high-volume telemetry - including container stdout and stderr , audit trails, and node syslog - to lower-cost table plans while keeping supported data available to the agent alongside metrics, traces, topology, and Azure resource context. This is especially useful for Kubernetes operations, where high-volume telemetry such as ContainerLogV2, AKS audit logs, and control-plane logs can be candidates for the Basic table plan. If eligible tables already use the Basic or Au

  12. GitHub Copilot in VS Code, August 2026 releases

    Copilot Coding Agent GitHub Changelog

    Update

    Published

    This changelog covers VS Code v1.132 through v1.135 , shipped throughout August 2026. Arrange chats side by side: Keep multiple chats visible in horizontal or vertical groups to compare results or follow your agent’s work, with the layout restored when you return to the session.

    Key points

    • Arrange chats side by side: Keep multiple chats visible in horizontal or vertical groups to compare results or follow your agent’s work, with the layout restored when you return to the session.
    • Open a side-conversation: Type to open a side chat that shares the primary chat’s context and prompt cache while it continues running.
    • Navigate the chat conversation: Use the prompt timeline control from the transcript gutter to easily navigate to specific prompts in chat and review the related file changes.
    • Install portable agent plugins: Install agent customizations from plugins that follow the Agent Plugins 1.0 standard across VS Code and other compatible agent clients.
    • Open the Agents window without GitHub sign-in: Enable the experimental setting to open the Agents window without GitHub sign-in when Claude is configured with an API key.
    • Switch model providers in Claude sessions: Choose between models from your Anthropic subscription and Copilot subscription at any time.

    From the announcement

    This changelog covers VS Code v1.132 through v1.135 , shipped throughout August 2026. These releases make it easier to organize agent sessions, review changes, and navigate long conversations. Agent Host, the integrated browser, and dictation also get updates to support more ways of working in VS Code.

  13. Copilot code review: Resolution reasons and expanded capabilities

    Copilot Code Review GitHub Changelog

    Update

    Published

    Copilot code review can now review two types of pull requests it didn’t cover before:. Reviews requested automatically on pull requests authored by bots, including Copilot cloud agent.

    Key points

    • Reviews requested automatically on pull requests authored by bots, including Copilot cloud agent
    • Very large pull requests

    From the announcement

    Copilot code review can now review two types of pull requests it didn’t cover before:

  14. Azure DevOps in the GitHub Copilot App

    Copilot in Azure DevOps & Boards Azure DevOps Blog

    Update

    Published

    The Azure DevOps plugin is now available for the GitHub Copilot app , allowing you to view and manage Azure DevOps pull requests and work items directly in the Copilot app. View your work items and pull requests from My Work.

    Key points

    • View your work items and pull requests from My Work
    • Open work items and pull requests
    • Edit work items
    • Edit and complete pull requests

    From the announcement

    The Azure DevOps plugin is now available for the GitHub Copilot app , allowing you to view and manage Azure DevOps pull requests and work items directly in the Copilot app.

  15. Public Preview: Introducing Live Reports for Azure SRE Agent

    Azure SRE Agent Azure Updates

    Preview

    Preview
    Aug 2026
    Published

    We're excited to announce Live Reports, now in Public Preview for Azure SRE Agent.

    From the announcement

    We're excited to announce Live Reports, now in Public Preview for Azure SRE Agent. Live Reports help operations teams create dynamic operational views directly from SRE Agent conversations and keep them continuously up to date with the latest data from connected environments. Instead of manually rebuilding dashboards or collecting information across multiple tools, teams can use Azure SRE Agent to automatically generate the report and return to it anytime, with fresh data surfaced on a daily, weekly or monthly cadence that you define. Whether you're tracking incidents, service health, operational trends, or recurring investigations, Live Reports provide a consistent, shareable, and always-cu

  16. Generally Available: Azure SRE Agent VNet Integration

    Azure SRE Agent Azure Updates

    Generally available

    GA
    Aug 2026
    Published

    Azure SRE Agent VNet Integration is now generally available.

    From the announcement

    Azure SRE Agent VNet Integration is now generally available. VNet integration enables Azure SRE Agent to operate within your existing network controls, including Network Security Groups (NSGs), private DNS, and firewall policies, etc. With VNet support, the agent can securely access private resources, including services behind private endpoints, during incident investigation and remediation without requiring changes to your network boundary. This capability helps organizations extend Azure SRE Agent into security-sensitive environments while maintaining existing networking, security, and compliance controls. Learn more .

  17. Generally Available: Azure SRE Agent 30-Day Trial

    Azure SRE Agent Azure Updates

    Generally available

    GA
    Aug 2026
    Published

    New customers can now get started with Azure SRE Agent through a 30-day trial experience. Investigate a root cause: Let the agent work across alerts, logs, metrics, traces, Azure resource state, code, and recent deployments to build a likely root cause and suggest a mitigation.

    Key points

    • Investigate a root cause: Let the agent work across alerts, logs, metrics, traces, Azure resource state, code, and recent deployments to build a likely root cause and suggest a mitigation.
    • Automate alert response: Trigger investigations from Azure Monitor, Datadog, Dynatrace, or PagerDuty and guide the response with your team's existing runbooks and practices.
    • Get ahead of operational risks: Run post-deployment health checks, monitor certificate expiration, detect configuration drift, review costs, or support compliance checks.
    • Close the loop: Have your agent send evidence, root cause, mitigation, and follow-up work to GitHub, ServiceNow, Jira, or Azure DevOps.

    From the announcement

    New customers can now get started with Azure SRE Agent through a 30-day trial experience. During the trial, customers can create SRE Agents and connect them to your operational tools and data sources, and explore capabilities at their own pace without baseline always-on charges. Customers pay only for Azure Agent Units (AAUs) consumed when agents perform work. Here are a few practical ways developers, SREs, and IT operations teams can use the 30-day trial:

  18. Copilot Code Reviews for Azure Repos (public preview)

    Copilot Code Review Copilot in Azure DevOps & Boards Azure DevOps Blog

    Preview

    Published

    Today, we’re announcing the public preview of GitHub Copilot Code Review for Azure Repos, making the feature available to all Azure DevOps customers using the service.

    From the announcement

    Today, we’re announcing the public preview of GitHub Copilot Code Review for Azure Repos, making the feature available to all Azure DevOps customers using the service. There’s no longer a need to sign up for early access. Customers can now enable Copilot Code Review for their Azure Repos repositories and start using it. With the public preview, we’re also introducing several improvements we’ve made over the past couple of months based on what we’ve learned during the technical preview. Before getting started, be sure to read the official documentation for details on how Copilot Code Review works, how to enable it, and what to expect around usage and billing. Let’s take a look at what’s new.

  19. Shared agentic work with GitHub Copilot in Microsoft Teams

    Copilot Coding Agent GitHub Changelog

    Update

    Published

    Turn a Microsoft Teams discussion into a collaborative agent session everyone can see and help direct. Participants with write access can trigger Copilot to make changes, and administrators must enable Copilot cloud agent and cloud sandboxes.

    Key points

    • For users in an organization or enterprise, make sure an administrator has enabled GitHub Copilot cloud agent and cloud sandboxes. Cloud sandbox policies share the same configuration as cloud agent policies.
    • Install the GitHub app for Microsoft Teams .
    • In Teams, mention and follow the prompts to connect your GitHub account.
    • For public channels, configure a default repository if prompted. Direct messages don’t use a default repository.
    • Mention , followed by your task. You can also use to see available commands.

    From the announcement

    Turn a Microsoft Teams discussion into a collaborative agent session everyone can see and help direct. Mention in a channel, thread, or direct message to start a GitHub Copilot cloud agent session. Anyone in the conversation can ask questions, add context, and help plan or steer the work. Participants with write access to the repository can trigger Copilot to make changes.

  20. Announcing: Azure Copilot introduces direct access to agents

    Copilot Coding Agent Azure Monitor Observability Agent Azure Updates

    Update

    Published

    Starting in August 2026, customers can engage directly with Azure Copilot agents and select the specific agent best suited to their needs.

    Key points

    • Choose the right agent for your goal. Customers can select the specific agent best suited to their needs and get to the right action faster.
    • Agents are enabled by default. Azure Copilot agents are enabled by default for users who have access to Azure Copilot.
    • Admins have granular control. Global administrators can enable or disable individual agents directly from the Azure Copilot Admin Center.

    From the announcement

    Starting in August 2026, customers can engage directly with Azure Copilot agents to move more quickly from questions to action. With this update:

  21. Code scanning adds a mitigated alert dismissal reason

    GitHub Advanced Security GitHub Changelog

    Update

    Published

    You can now dismiss a code scanning alert with the reason Mitigated when a vulnerability remains in the code but external controls, such as a web application firewall or network policy, mitigate its risk.

    From the announcement

    You can now dismiss a code scanning alert with the reason Mitigated when a vulnerability remains in the code but external controls, such as a web application firewall or network policy, mitigate its risk. The new dismissal reason helps you distinguish mitigated vulnerabilities from alerts marked Won’t fix , align dismissals with formal exception and risk-acceptance processes, and reduce the need to track these decisions outside GitHub. For more information, see resolving code scanning alerts . The post Code scanning adds a mitigated alert dismissal reason appeared first on The GitHub Blog .

  22. Separate GitHub Actions path for GitHub Code Quality

    GitHub Advanced Security GitHub Changelog

    Update

    Published

    A dedicated workflow path for code quality CodeQL actions workflows is now generally available. Change Actions usage and billing reports that filter on so they also account for .

    Key points

    • Change Actions usage and billing reports that filter on so they also account for .
    • Update scripts, dashboards, or workflow run filters that identify Code Quality runs by the actor.

    From the announcement

    A dedicated workflow path for code quality CodeQL actions workflows is now generally available. Your workflow run history and your Actions usage reports now tell GitHub Code Quality runs apart from GitHub code scanning runs. Code Quality analysis runs on and shows as the actor, instead of sharing the path and the actor with code scanning.

  23. Copilot code review effort levels are generally available

    Copilot Code Review GitHub Changelog

    Generally available

    Published

    Lite and Balanced effort levels for GitHub Copilot code review are now generally available. Choose Lite for feedback on straightforward changes.

    Key points

    • Choose Lite for feedback on straightforward changes.
    • Choose Balanced when a change warrants deeper analysis from a higher-reasoning model.
    • Set an organization-wide default that repositories inherit while retaining control over individual reviews.

    From the announcement

    Lite and Balanced effort levels for GitHub Copilot code review are now generally available. They let you match the depth of a review to the complexity and risk of a pull request. Not every pull request needs the same scrutiny. Documentation updates and small fixes may only need focused feedback, while complex logic, security-sensitive code, and cross-service changes benefit from deeper analysis. You can now:

  24. Secret scanning coverage updates

    GitHub Advanced Security GitHub Changelog

    Update

    Published

    This release expands secret scanning’s coverage with more secrets blocked by push protection, one new secret scanning partner, and richer metadata on alerts.

    From the announcement

    This release expands secret scanning’s coverage with more secrets blocked by push protection, one new secret scanning partner, and richer metadata on alerts.

  25. Azure DevOps Remote MCP Server is generally available

    Azure DevOps MCP Server Azure DevOps Blog

    Generally available

    Published

    Today, we’re excited to announce the general availability of the Azure DevOps MCP Server The Azure DevOps MCP Server gives AI assistants secure, contextual access to your Azure DevOps projects so they can help you plan, build, and ship software more effectively.

    From the announcement

    Today, we’re excited to announce the general availability of the Azure DevOps MCP Server The Azure DevOps MCP Server gives AI assistants secure, contextual access to your Azure DevOps projects so they can help you plan, build, and ship software more effectively. With the Azure DevOps remote MCP Server , you can get started without installing or hosting anything yourself. Simply connect your AI assistant directly to the Azure DevOps hosted endpoint by using streamable HTTP transport and start working with your projects in minutes.

  26. Customize code scanning default setup at scale

    GitHub Advanced Security GitHub Changelog

    Update

    Published

    You can now apply your own configuration file to code scanning default setup, using the new repository property.

    From the announcement

    You can now apply your own configuration file to code scanning default setup, using the new repository property. This gives you control over how CodeQL scans your code for security vulnerabilities, whether that’s on one repository or across your whole organization. We recommend using this way to customize your security analysis at scale. You get the granular control of advanced setup without writing or maintaining a GitHub Actions workflow file in every repository.

  27. Copilot code review: Agent skills and MCP now generally available

    Copilot Code Review GitHub Changelog

    Generally available

    Published

    Copilot code review support for agent skills and MCP servers is now generally available for Copilot Pro, Pro+, Business, and Enterprise users. Agent skills let Copilot invoke your team’s internal tools and coding standards during a review, while MCP servers pull external context into reviews.

    Key points

    • Agent skills let Copilot code review invoke your team’s internal tools and coding standards during a review. Add a file under a skill subdirectory in to extend Copilot’s analysis with context and instructions specific to your repository or organization.
    • MCP server connections pull context from third-party platforms your team already uses (e.g., issue trackers, documentation systems, service catalogs) directly into the review. All MCP tool calls performed by Copilot code review will be limited to read-only.
    • Any MCP configurations you’ve already set up for Copilot cloud agent automatically apply to Copilot code review. Note that the GitHub and Playwright MCP will be turned on by default.
    • Attribution on skills and MCP comments : Copilot code review now indicates when a comment was generated using agent skills or MCP context, so you can see your skills and MCP servers in action.
    • MCP servers : Add your MCP configuration under repository settings → Copilot → MCP servers . Store authentication tokens under repository settings → Secrets and variables → Agents . See example MCP configurations to get started.
    • Agent skills : Under , create a skill-specific directory, then add a file to that directory with the context and instructions you want Copilot code review to use. For more details, see the agent skills documentation .

    From the announcement

    Copilot code review support for agent skills and MCP servers is now generally available for all Copilot Pro, Pro+, Business, and Enterprise users. Previously announced in public preview , these capabilities let you bring your team’s tools, standards, and external context directly into every code review.

  28. Manage GitHub Copilot app access with a dedicated policy

    Copilot Coding Agent GitHub Changelog

    Update

    Published

    The GitHub Copilot app now has its own policy, so you can control who has access to it at the enterprise and organization levels. Enabled everywhere gives your developers access to the app.

    Key points

    • Enabled everywhere gives your developers access to the app.
    • Disabled everywhere turns the app off across your enterprise.
    • Let organizations decide passes the choice to each organization’s admin.
    • From your enterprise or organization settings, open the AI Controls tab.
    • Go to the “Copilot Clients” section.
    • Select the Copilot app policy.

    From the announcement

    The GitHub Copilot app now has its own policy, so you can control who has access to it at the enterprise and organization levels. Until now, access to the Copilot app depended on your GitHub Copilot CLI policy being enabled. From several conversations with customers, we understand that many of you want to manage each client independently. Now the Copilot app and the Copilot CLI each have their own policy, giving you the flexibility and control to enable the right clients for your teams. This new policy keeps your developers’ work within the guardrails you already rely on. When using this app, developers drive agent sessions in isolated workspaces and land changes through pull requests. This

  29. GitHub Code Quality is now generally available

    GitHub Advanced Security GitHub Changelog

    Generally available

    Published

    GitHub Code Quality is now generally available on GitHub Enterprise Cloud and GitHub Team. Organization-wide enablement, with org-level dashboards that show maintainability and reliability scores across your repositories.

    Key points

    • Organization-wide enablement, with org-level dashboards that show maintainability and reliability scores across your repositories.
    • Code coverage metrics rendered from your existing test reports (in Cobertura XML format) directly on pull requests.
    • Quality gates through GitHub rulesets, including coverage thresholds, with an evaluate mode for gradual rollout.
    • APIs to manage repository enablement and fetch findings.
    • $10 per active committer, per month. A committer is considered active when they’ve pushed a commit to a repository with Code Quality enabled in the last 90 days. Each active committer is counted only once across your organization no matter how many repositories they contribute to. Bot accounts are not charged.
    • Usage-based billing for AI-powered work , including AI-assisted detection and Copilot Autofix. You don’t need a GitHub Copilot subscription to use them.

    From the announcement

    GitHub Code Quality is now generally available on GitHub Enterprise Cloud and GitHub Team. It solves an emerging challenge for software development: AI accelerates code output, and Code Quality helps teams ship code they trust. Code Quality pairs CodeQL’s deterministic analysis with AI-assisted detection to catch maintainability and reliability issues in your pull requests, and Copilot Autofix suggests fixes for you to review before you merge. In GitHub’s own engineering organization, teams resolve 67.3% of Code Quality findings before merging pull requests.

  30. Repository-level GitHub Copilot usage metrics generally available

    Copilot Coding Agent Copilot Code Review GitHub Changelog

    Generally available

    Published

    The Copilot usage metrics REST API now reports repository-level activity. Pull requests created and merged by Copilot coding agent.

    Key points

    • Pull requests created and merged by Copilot coding agent.
    • Pull requests reviewed by Copilot code review, with suggestion counts broken down by comment type.

    From the announcement

    The Copilot usage metrics REST API now reports repository-level activity. Two new endpoints return a daily, per-repository breakdown of pull request activity for Copilot coding agent and Copilot code review. They do this for both enterprise and organization reports.

  31. GitHub Copilot app now available in the usage metrics API

    Copilot Coding Agent GitHub Changelog

    Update

    Published

    The Copilot usage metrics API now reports the GitHub Copilot app usage in the enterprise and organization 1-day and 28-day reports. : The number of distinct users active in the Copilot app on a given day.

    Key points

    • : The number of distinct users active in the Copilot app on a given day.
    • : A dedicated GitHub Copilot app section reporting , , , and a breakdown (i.e., , , and ).
    • These fields appear in the enterprise and organization 1-day and 28-day reports.
    • The GitHub Copilot app usage is reported in its own section and is kept separate from the generic feature, model, and language totals, as well as from lines-of-code metrics.
    • Enterprises or organizations with no GitHub Copilot app activity report for both and , so existing integrations are unaffected.

    From the announcement

    The Copilot usage metrics API now reports the GitHub Copilot app usage in the enterprise and organization 1-day and 28-day reports. This gives enterprise and organization admins visibility into the app’s activity alongside the IDE, chat, code review, and coding agent metrics they already retrieve.

  32. Copilot code review: Customization and configurability improvements

    Copilot Code Review GitHub Changelog

    Update

    Published

    Copilot code review now utilizes a firewall, custom setup steps, and independent runner configurations. Add a file to your repository to define setup steps specific to Copilot code review.

    Key points

    • Add a file to your repository to define setup steps specific to Copilot code review.
    • If no file exists, Copilot code review will fall back to your existing file if one is present.
    • The firewall is enabled by default for all repositories.
    • To configure this setting in your repository, navigate to your repository settings, then go to Copilot → Internet access .

    From the announcement

    Copilot code review now utilizes a firewall, custom setup steps, and independent runner configurations. It now reads custom instructions from the head branch to allow for easy testing and validation of custom instructions. These changes give administrators and developers more control over how Copilot code review runs in their environment.

  33. Improvements to secret scanning and public monitoring

    GitHub Advanced Security GitHub Changelog

    Update

    Published

    This week, we’re rolling out several improvements to secret scanning and public monitoring:. Resend is now a GitHub secret scanning partner.

    Key points

    • Resend is now a GitHub secret scanning partner.
    • Secret scanning now detects new secret types from APIclub and Resend.
    • Secret scanning now blocks VolcEngine secrets with push protection by default.
    • The webhook now includes a field (i.e., or ) so you can distinguish between specific and generic types.
    • The public monitoring alert list now surfaces insight cards at the top of the page, including a breakdown of associated leaks by attribution, your enterprise member count, and your verified domains.
    • : provider patterns plus your custom patterns.

    From the announcement

    This week, we’re rolling out several improvements to secret scanning and public monitoring:

  34. Code scanning shows AI security detections on pull requests

    GitHub Advanced Security GitHub Changelog

    Update

    Published

    GitHub code scanning now surfaces AI-powered security detections directly on pull requests, expanding vulnerability coverage to languages and frameworks not currently supported by CodeQL. Broader language coverage : AI-powered detections extend code scanning to languages and frameworks beyond those supported by CodeQL’s built-in analysis ,.

    Key points

    • Broader language coverage : AI-powered detections extend code scanning to languages and frameworks beyond those supported by CodeQL’s built-in analysis , reducing blind spots across your codebase.
    • Native pull request integration : Findings appear directly in pull requests, so developers can review and address issues as part of their existing workflow before merging code. Alerts generated using AI will be labeled with so you can easily distinguish them from CodeQL results.
    • Easy to enable : Once allowed at the enterprise level, you can enable AI security detections for any repository or organization that have GitHub code security and CodeQL default setup turned on.

    From the announcement

    GitHub code scanning now surfaces AI-powered security detections directly on pull requests, expanding vulnerability coverage to languages and frameworks not currently supported by CodeQL. These detections help teams identify and address potential issues in parts of the codebase that previously had no native scanning coverage, all before code is merged.

  35. Manage secret scanning custom patterns via REST API

    GitHub Advanced Security GitHub Changelog

    Update

    Published

    Starting today, security teams can create, edit, and manage secret scanning custom patterns with the REST API. list patterns.

    Key points

    • list patterns
    • create patterns
    • update patterns
    • delete patterns

    From the announcement

    Starting today, security teams can create, edit, and manage secret scanning custom patterns with the REST API.

  36. Clearer names for secret scanning detector types

    GitHub Advanced Security GitHub Changelog

    Update

    Published

    To make secret scanning easier to understand, we’re updating the names we use for our detector types to better reflect how each one finds secrets. Provider secrets are issued by a specific service (e.g., an AWS key, a Stripe token).

    Key points

    • Provider secrets are issued by a specific service (e.g., an AWS key, a Stripe token).
    • Generic secrets aren’t tied to any provider (e.g., private keys, connection strings, passwords).
    • Patterns use deterministic detection (i.e., regular expressions combined with additional checks like entropy analysis). Patterns reliably catch secrets with a recognizable structure and include both provider patterns for provider secrets, as well as generic patterns like private keys and connection strings.
    • AI-detected secrets use AI to catch generic secrets that don’t follow a predictable format (e.g., passwords). The model reads the surrounding code to find harder-to-detect unstructured secrets.

    From the announcement

    To make secret scanning easier to understand, we’re updating the names we use for our detector types to better reflect how each one finds secrets. This is a naming change only; detection behavior is exactly the same. Before Now Non-provider patterns Generic patterns Copilot secret scanning AI-detected secrets All existing product documentation links continue to work. We’ve added redirects and updated the terminology across our documentation. There are no changes to webhook events, audit log events, or the REST API. There are two kinds of secrets we detect:

  37. Agentic autofix for code scanning alerts in public preview

    Copilot Coding Agent GitHub Advanced Security GitHub Changelog

    Preview

    Published

    Agentic autofix is now in public preview for all code scanning alerts. Explores relevant files across your codebase.

    Key points

    • Explores relevant files across your codebase.
    • Generates a proposed fix.
    • Validates the fix works by rerunning CodeQL.
    • Iterates if needed, then opens a draft pull request ready for your review.
    • From any code scanning alert, by assigning the alert to Copilot.
    • In the list of security alerts in your repository, by selecting one or more alerts for Copilot to fix together in a single pull request.

    From the announcement

    Agentic autofix is now in public preview for all code scanning alerts. It remediates alerts generated by CodeQL and third-party scanning tools by working across your codebase the way a developer would—it explores relevant files, proposes a fix, and reruns the original analysis to confirm the fix closes the alert before opening a pull request for your review. Agentic autofix is available to organizations with both GitHub Code Security (or GitHub Advanced Security) and a Copilot license with Copilot cloud agent enabled. Editor’s note (July 16, 2026): Clarified that autofix works for all first-party and third-party code scanning alerts.

  38. Public Preview: Manage Azure Chaos Studio from the Azure CLI

    Resiliency Agent Azure Updates

    Preview

    Preview
    Jul 2026
    Published

    You can now create and run Azure Chaos Studio resilience Scenarios directly from the Azure CLI with the new az chaos extension — no more hand-assembling REST calls and JSON files.

    From the announcement

    You can now create and run Azure Chaos Studio resilience Scenarios directly from the Azure CLI with the new az chaos extension — no more hand-assembling REST calls and JSON files. Get started in one step: az chaos setup stands up a workspace, wires up permissions, discovers your resources, and recommends Scenarios (like Zone Down) tailored to what you're running. From there, configure, validate, and run a Scenario in a few clear commands — with built-in --help, tab completion, and table/JSON/TSV output. Install with az extension add --name chaos.

  39. Public Preview: Azure Chaos Studio Workspaces and Scenarios

    Resiliency Agent Azure Updates

    Preview

    Preview
    Jul 2026
    Published

    Azure Chaos Studio now supports Workspaces and Scenarios, a faster, application-centric way to validate how your workloads hold up during real outages. Simulate common outage patterns out of the box, including availability zone failures, DNS and Microsoft Entra ID outages, PostgreSQL and SQL Managed Instance.

    Key points

    • Simulate common outage patterns out of the box, including availability zone failures, DNS and Microsoft Entra ID outages, PostgreSQL and SQL Managed Instance failovers, cache stampedes, and messaging disruptions.
    • Keep tests in sync as your app changes—resources are discovered automatically from the Workspace scope.
    • Control the blast radius with a managed identity governed by Azure RBAC.
    • Generate Scenario reports for game days, retrospectives, and compliance frameworks such as DORA.

    From the announcement

    Azure Chaos Studio now supports Workspaces and Scenarios, a faster, application-centric way to validate how your workloads hold up during real outages. Point a Workspace at your application's scope—a subscription, resource group, or service group—and Chaos Studio discovers the resources inside it and recommends Scenarios: preconfigured tests that reproduce real-world outage patterns. Select a Scenario, and Chaos Studio injects the right faults, in the right order, across every affected resource, then produces a Scenario report showing exactly what happened. With Workspaces and Scenarios, you can:

  40. Secret scanning extended metadata and multipart validation

    GitHub Advanced Security GitHub Changelog

    Update

    Published

    To help you understand ownership and impact of a leaked secret, GitHub secret scanning surfaces enriched metadata for supported secret types.

    From the announcement

    To help you understand ownership and impact of a leaked secret, GitHub secret scanning surfaces enriched metadata for supported secret types. Extended metadata checks are now generally available, including support for multipart validators with supplementary metadata.

  41. Copilot agent session streaming is now in public preview

    Copilot Coding Agent GitHub Changelog

    Preview

    Published

    GitHub Enterprise Cloud customers with enterprise managed users can now access GitHub Copilot agent session data across all Copilot clients, including:. Cloud agents operating on github.com and data resident deployments on ghe.com.

    Key points

    • Cloud agents operating on github.com and data resident deployments on ghe.com
    • GitHub Copilot CLI
    • Visual Studio Code
    • Visual Studio
    • Partner IDEs, such as those provided by JetBrains and Eclipse
    • : Retrieve Copilot usage records for an enterprise.

    From the announcement

    GitHub Enterprise Cloud customers with enterprise managed users can now access GitHub Copilot agent session data across all Copilot clients, including:

  42. Secret scanning public monitoring for enterprises

    GitHub Advanced Security GitHub Changelog

    Update

    Published

    GitHub is committed to empowering the developer community by helping organizations recognize and address the risks of secret leaks wherever they happen.

    From the announcement

    GitHub is committed to empowering the developer community by helping organizations recognize and address the risks of secret leaks wherever they happen. We believe every enterprise should know the moment its secrets leak in public, no matter where it happens on GitHub. That’s why public monitoring is now in public preview for enterprises with GitHub Secret Protection, at no additional cost. Secrets don’t respect boundaries; scanning for them shouldn’t either.

  43. Secret scanning adds validators for Asana, IBM, and MessageBird

    GitHub Advanced Security GitHub Changelog

    Update

    Published

    Secret scanning now runs validity checks on Asana, IBM, and MessageBird secrets so you can tell whether a leaked credential is still active.

    From the announcement

    Secret scanning now runs validity checks on Asana, IBM, and MessageBird secrets so you can tell whether a leaked credential is still active.

  44. Copilot Agent is now available in JetBrains AI Assistant

    Copilot Coding Agent GitHub Changelog

    Update

    Published

    Today, JetBrains and GitHub are announcing a deeper integration between JetBrains AI Assistant and GitHub Copilot.

    From the announcement

    Today, JetBrains and GitHub are announcing a deeper integration between JetBrains AI Assistant and GitHub Copilot. Millions of developers already rely on the GitHub Copilot plugin as their AI pair programmer in JetBrains IDEs, and Copilot has also been available inside JetBrains AI Assistant through the Agent Client Protocol (ACP) . Now we are taking the next step: GitHub Copilot is a first-class option in the AI Assistant agent picker, so you can choose the entry point that best fits your workflow.

  45. Copilot code review: Analysis depth and efficiency updates

    Copilot Code Review GitHub Changelog

    Update

    Published

    Copilot code review now uses the built-in file exploration tools available in the Copilot CLI and SDK, significantly improving review cost efficiency with no change to your existing workflow. attribution in the pull request overview comment : Copilot code review now labels medium analysis depth.

    Key points

    • attribution in the pull request overview comment : Copilot code review now labels medium analysis depth runs in its pull request overview comment so you can quickly confirm which level generated the review.
    • Organization-level default level setting : Organizations can now set a default review level for unconfigured repositories. Repositories under an organization that has configured the default review level will continue to be able to override that default setting if desired.

    From the announcement

    Copilot code review now uses the built-in file exploration tools available in the Copilot CLI and SDK, significantly improving review cost efficiency with no change to your existing workflow. If you’re in the Medium analysis depth public preview, you’ll also see some new updates centered around configurability and visibility of review depth.

  46. GitHub Copilot for Jira is now generally available

    Copilot Coding Agent GitHub Changelog

    Generally available

    Published

    GitHub Copilot for Jira is now generally available. Model selection from within Jira.

    Key points

    • Model selection from within Jira
    • Jira ticket references in pull request titles
    • Confluence context via MCP
    • Custom agents and custom fields
    • Space-level custom guidance
    • Review request notifications in Jira

    From the announcement

    GitHub Copilot for Jira is now generally available. Since launching the public preview in March 2026, we have shipped a series of enhancements based on your feedback, including model selection, Confluence context via MCP, custom agents, custom fields, space-level guidance, and review request notifications in Jira. Today’s release to general availability builds on that foundation with new capabilities designed to give you greater visibility and control over agent sessions.

  47. Secret scanning adds extended metadata for Replicate secrets

    GitHub Advanced Security GitHub Changelog

    Update

    Published

    Secret scanning now includes extended metadata for Replicate secrets, providing richer context for leaked credentials.

    From the announcement

    Secret scanning now includes extended metadata for Replicate secrets, providing richer context for leaked credentials.

  48. GitHub Copilot app support for BYOK

    Copilot Coding Agent GitHub Changelog

    Update

    Published

    The GitHub Copilot app now supports bring your own key (BYOK), so you can run agent sessions against your own model providers, including OpenAI, Azure OpenAI, Microsoft Foundry, Anthropic, LM Studio, Ollama, and any OpenAI-compatible endpoint. Connect the providers you already use: Add Azure OpenAI,.

    Key points

    • Connect the providers you already use: Add Azure OpenAI, Anthropic, self-hosted Ollama, LM Studio, or any OpenAI-compatible gateway, then choose the right model for each session while keeping your existing billing, quotas, regions, and data-handling terms.
    • Mix frontier and local models: Pair a frontier model with a local or self-hosted model. Frontier models handle complexity. Local models handle execution.
    • Keep traffic in your tenant: Route inference through your own cloud account, tenant, or internal gateway for enterprise and regulated environments with stricter data-boundary requirements.

    From the announcement

    The GitHub Copilot app now supports bring your own key (BYOK), so you can run agent sessions against your own model providers, including OpenAI, Azure OpenAI, Microsoft Foundry, Anthropic, LM Studio, Ollama, and any OpenAI-compatible endpoint. Add a provider in Settings → Model Providers with your endpoint and API key, or just a host for LM Studio or Ollama. Once added, your provider’s models appear in the model picker alongside Copilot-hosted models, and you choose which one to use each session. Keys are stored in the local OS keychain and are never read back by the UI. With BYOK you can:

  49. Copilot code review: AGENTS.md support and UI improvements

    Copilot Code Review GitHub Changelog

    Update

    Published

    Copilot code review now supports repository-level files, and it’s easier to request a review from Copilot on draft pull requests with the Request button. Reads from the root of your repository.

    Key points

    • Reads from the root of your repository.
    • Uses relevant instructions from that file when generating review feedback.

    From the announcement

    Copilot code review now supports repository-level files, and it’s easier to request a review from Copilot on draft pull requests with the Request button. These changes are all generally available.

  50. Secret scanning updates – June 2026

    GitHub Advanced Security GitHub Changelog

    Update

    Published

    Since our last pattern update , we’ve expanded secret scanning’s detection coverage with new partners, more patterns blocked by push protection by default, additional validity checks, and richer metadata for leaked secrets.

    From the announcement

    Since our last pattern update , we’ve expanded secret scanning’s detection coverage with new partners, more patterns blocked by push protection by default, additional validity checks, and richer metadata for leaked secrets.