Catalog / Developer platform

GitHub changelog

GitHub last published on 10 Oct 2026, yesterday.

Product changes across repositories, Actions, Packages and the API.

SubscribeGitHub as markdown, for pasting into a model
Collected
148 releases back to 20 Aug 2026
Source
github.blog
Project
github.com
Feed
RSS

Read on 28 of the 30 days on record, last today. Collection status

Version history

2026148 releases
New controls and chat improvements in Copilot for JetBrains

This update brings more control over default models and MCP server in GitHub Copilot for JetBrains. It also makes diagnostics easier to address, improves chat navigation and account controls, and strengthens reliability across agent session

addedfixedchanged
GitHub Copilot weekly releases — October 5

This week’s updates make Copilot easier to use across accounts and environments, with more control over what agents can access and how you manage their work. GitHub Copilot Claude Haiku 5.5 is available to Copilot Pro, Pro+, Max, Business,

addedchanged
CodeQL 2.27.2 improves C++, Go, Rust, and JavaScript analysis

CodeQL 2.27.2 is now available, adding a C++ regular-expression parser and analysis improvements across several languages. CodeQL is the static analysis engine behind GitHub code scanning, which helps you find and remediate security issues

breakingsecurityadded
Triage role users or higher can now archive pull requests

Users with the triage role or higher in a repository can now archive and unarchive pull requests. Previously, archiving was limited to repository administrators, requiring trusted triagers to hand routine moderation work to someone with hig

addedchanged
Screen readers can navigate timelines as lists

Screen readers can now navigate issue and pull request timelines as a list. When you move through a timeline, assistive technology can announce the list structure, item count, current position, and how to move between events. This makes it

addedchanged
Draft pull requests count toward pull request limits

Maintainers are seeing more low-quality contributions in their repositories and need better ways to manage them. You can now configure pull request limits to also include draft pull requests. Previously, draft pull requests didn’t count tow

Claude Haiku 5.5 in GitHub Copilot

Claude Haiku 5.5, Anthropic’s newest lightweight model, is now generally available in GitHub Copilot. It is designed for fast, high-volume work like subagents, quick edits, and terminal tasks. In early testing, Haiku 5.5 matched Claude Sonn

added
Purpose-built model for leaked secret detection

Secret protection should keep pace with the way you build software, whether you write code yourself or work with an AI agent. With our new purpose-built model, we’re bringing context-aware detection into more developer workflows to help you

securityaddedfixed
Local sandboxing for GitHub Copilot now generally available

Local sandboxing for GitHub Copilot is now generally available in GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host. Local sandboxes give developers a secure execution boundary for agentic workflows on their

Discover local models in GitHub Copilot CLI

GitHub Copilot CLI makes it easier to choose a local model without leaving your existing workflow. Starting in CLI version 1.0.94-0, use /model to discover supported models from a running local Ollama instance, alongside your configured mod

addedchanged
Update your IDE to restore agent activity in Copilot usage metrics

If your Copilot usage metrics have shown agent activity or agent lines of code falling while Copilot usage kept growing, we’ve found the cause, and a fix is rolling out to each IDE. Several IDEs recently moved Copilot agent sessions to the

addedfixedchanged
Stacked pull requests generally available

GitHub stacked pull requests are now generally available. Break large changes into smaller, focused pull requests that you can review independently and merge together. Since the feature went into public preview, repositories using stacks ha

addedremoved
Code scanning AI Scan enablement status in security overview

Organization and enterprise administrators can now see AI Scan for pull requests enablement status in the security overview coverage view. The code scanning summary shows enabled and not enabled repository counts, while repository rows show

security
Secret scanning adds detectors for Lovable, Supabase, and more

Secret scanning now detects new secret types from Lovable Labs, Pydantic Services Inc., and Supabase. New secret scanning partner The following provider joined the secret scanning partnership program. When one of their secrets is found in a

added
Stateless GitHub App installation tokens rolled out

The staged rollout of the stateless GitHub App installation token format, which began on April 27, 2026, is complete. By default, all newly minted GitHub App installation tokens will be in the stateless ghs_APPID_JWT format, which makes tok

addedfixedchanged
Copilot code review: API support and new default effort level

You can now request a GitHub Copilot code review through the REST and GraphQL APIs and set the review effort level for each request. Balanced is also now the default review effort level. These changes are generally available to Copilot Pro,

added
Unvalidated npm trusted publishing configurations now expire

Unvalidated npm trusted publishing configurations now expire 48 hours after creation and can no longer authorize publishing. This limits the risk of trusting a repository or project name that changes ownership. Your configuration becomes va

added
npm staged publishing now supports creating new packages

You can now create a new npm package with npm stage publish, using a local session or a granular access token, including a stage-only token. This lets you create packages from your automated workflows without a manual first publish. This wo

added
Selected models in GitHub Copilot deprecated

As of today, October 2, 2026, we have deprecated the following models across all GitHub Copilot experiences (including Copilot Chat, inline edits, ask and agent modes, and code completions). Model Deprecation date Suggested alternative Gemi

changeddeprecated
GitHub Copilot weekly releases — September 28

This week, put Copilot to work with new models, reusable workflows and desktop app automation, plus Azure canvases and VS Code improvements. GitHub Copilot Claude Sonnet 5.5 is available to Copilot Pro, Pro+, Max, Business, and Enterprise u

addedchanged
New fields for SecurityAdvisory GraphQL API

You can now read more of the GitHub Advisory Database directly from the GraphQL API without falling back to the REST API. The SecurityAdvisory object gained five new fields: cveId: The advisory’s CVE identifier. sourceCodeLocation: A link t

securityadded
Confidential comments on repository security advisories

You can now post confidential comments on repository security advisories. Confidential comments are visible only to people with write access to the repository, so you can discuss a report with your team without the reporter or other invited

securitychanged
Repository security advisory comments API in public preview

You can now read, add, and edit comments on repository security advisories using the REST API, including advisories created from private vulnerability reports. Until now, the discussion on an advisory was only reachable in the web UI, even

securityadded
Rate limits for private vulnerability reports

Open source maintainers are receiving more low-quality and automated vulnerability reports, which can bury the reports that matter. Rate limits cap how many new reports a single account can submit in a day, both to your repository and acros

securityaddedchanged
Structured forms for private vulnerability reports

Private vulnerability reports can now use a structured form that asks reporters for the details you need to assess a vulnerability, including a reproducible proof of concept. A single free-text box made it easy to submit low-quality or AI-g

securityaddedchanged
GitHub Actions: macOS 14 runner image retirement

The macOS 14 runner image will be retired on November 2, 2026. To raise awareness of the upcoming removal, jobs using macOS 14 will temporarily fail during the following scheduled brownout periods: October 5, 14:00 UTC to October 6, 00:00 U

changeddeprecated
GitHub Copilot in VS Code, September 2026 releases

This changelog covers VS Code v1.136 through v1.140, shipped throughout September 2026. September’s releases streamline agent-driven development from implementation through pull request merge. Automations handle repeatable tasks, agent merg

addedchanged
Accessibility statements highlighted on repository overview

You can now find an ACCESSIBILITY.md file in your repository’s root, the .github/ directory, or the docs/ directory highlighted on the repository overview. You can also add or propose an accessibility statement from a public repository’s Co

added
Actions retention now covers checks, runs, and statuses

As previously announced, checks, workflow runs, and statuses are now governed by the same GitHub Actions retention setting that controls how long artifacts and logs are kept. These records are automatically cleaned up when they exceed the r

changedremoved
Scheduled code scanning skips inactive repositories

Weekly scheduled scans for code scanning default setup and GitHub Code Quality now start only after a push or pull request triggers an analysis, rather than counting every kind of scan as recent activity. Previously, activity for a reposito

security
Code coverage uploads no longer fail CI for new branches

Code coverage uploads from the GitHub Code Quality upload-code-coverage action no longer fail CI when you push a branch that doesn’t yet have an open pull request. Previously, the coverage API required a pull request number for any push to

added
Dynamic workflows in Copilot CLI and the Copilot app

Dynamic workflows are now available in Copilot CLI, the GitHub Copilot app, and the GitHub Copilot SDK. These let you define an orchestration in code to get the reliability and observability that complex, multi-agent work demands. What is a

changed
New dashboard experience now the default

The new dashboard experience, previously available as a feature preview, is now the default view for everyone. The redesigned dashboard helps you focus on the work that matters most and makes it easier to find and act on what you need next.

addedchanged
GitHub async merge API generally available

You can now use the generally available GitHub async merge API to merge individual or stacked pull requests, add pull requests to a merge queue, or merge pull requests directly. This includes optionally bypassing rules if you have permissio

added
Actions Runner Controller release 0.15.0

GitHub Actions Runner Controller 0.15.0 includes reliability, scalability, and observability improvements for runner scale sets. These updates help you operate larger runner fleets with fewer disruptions during upgrades and Kubernetes API u

fixedchanged
Opt-in dist-tag permissions for npm trusted publishing

Trusted publishing configurations for npm can now be granted permission to manage dist-tags (e.g., promoting a version to latest, updating next and beta pointers) using short-lived OIDC credentials instead of a long-lived access token. Prev

added
GitHub Advanced Security trials for GitHub Team

GitHub Team customers can now start self-serve trials of GitHub Advanced Security to evaluate GitHub Code Security and GitHub Secret Protection. Start a trial from your organization’s Overview page, Billing and licensing > Licensing page, o

security
HydraFusion in VS Code and the GitHub Copilot app

The HydraFusion research preview is now available in Visual Studio Code and the GitHub Copilot app, expanding beyond Copilot CLI. HydraFusion appears in the model picker, but rather than being a single model, it orchestrates multiple models

changed
X25519-only TLS ends for GHE.com on October 7

Beginning October 7, 2026, GitHub Enterprise Cloud with data residency will no longer accept TLS connections from clients that offer only X25519 for key agreement. Most customers don’t need to take action. The affected endpoints will contin

securitychanged
Repository custom runner settings for Dependabot

As a repository administrator, you can now configure the runner type, optional custom label, and optional runner group for Dependabot version and security updates. This extends the runner configuration already available at the organization

securitychanged
Bring business context with external custom properties

You can now seamlessly bring business context about your repositories from an external system of record (e.g., a configuration management database (CMDB), an internal developer portal, or an in-house system) into GitHub with external custom

changed
GPT-6.1 Sol in GitHub Copilot

GPT-6.1 Sol, the latest model from OpenAI, is now generally available and rolling out in GitHub Copilot. You can use it for agentic coding and terminal workflows with strong multistep coding performance and efficient token use. In early tes

added
Self-hosted runner version enforcement date has moved

The enforcement date for GitHub Actions minimum version requirements for self-hosted runners on GitHub Enterprise Cloud has changed. The change ships Monday, September 28, 2026, and full enforcement now begins Tuesday, September 29, 2026. T

addedchangeddeprecated
Claude Sonnet 5.5 in GitHub Copilot

Claude Sonnet 5.5, Anthropic’s newest Sonnet model, is now generally available in GitHub Copilot. It is designed for well-scoped everyday work like building features and fixing bugs. In our early testing, Sonnet 5.5 stood out for its effici

added
Enterprise managed settings in-product validator

You can now use an in-product validator for enterprise managed settings for GitHub Copilot. The validator detects malformed JSON, unsupported configurations, invalid team mappings, and other errors that can prevent policies from being enfor

Usage metrics API adds pull request review stages

The enterprise and organization repository-level Copilot usage metrics reports now break down how long pull requests spend in each stage of review. A new pull_request_review_times array on each repos-1-day row reports a median and a 90th pe

added
Changes to query results in the GitHub Actions API and UI

Queries for workflow runs in the GitHub Actions API and UI now return a less precise but more accurate count of records when you search by workflow, event, status, branch, or actor. We will continue to return paginated results of up to 1,00

changed
Agentic autofix now uses Copilot Memory

Agentic autofix now uses Copilot Memory for customers who’ve enabled it. When you use agentic autofix, it reviews existing memories for context that can help resolve security alerts. When it creates a fix, it stores the fix pattern as a mem

security
GitHub Copilot weekly releases — September 21

This week’s releases add new models to Copilot, local sandboxing in the Copilot app, and updates to Copilot in Slack, Microsoft Teams, JetBrains, and VS Code. GitHub Copilot Claude Opus 5.5 is available to Copilot Pro+, Max, Business, and E

addedchanged
Updates to GitHub Copilot for Slack and Microsoft Teams

GitHub Copilot in Slack and Microsoft Teams now gives you more context, more control, and a clearer path from conversation to GitHub work. Whether you’re sharing files in Slack or images and forwarded messages in Teams, Copilot can use more

addedfixedchanged
CodeQL 2.27.1 adds C and C++ query and Kotlin 2.4.20 support

CodeQL 2.27.1 adds new queries for C/C++ and C#, support for Kotlin 2.4.20, and query-accuracy improvements. CodeQL is the static analysis engine behind GitHub code scanning, which helps you find and remediate security issues in your code.

securityaddedfixed
Require proof of presence for high-impact actions

You can now require an interactive re-authentication or a multi-factor challenge before members take high-impact actions on GitHub Enterprise Cloud accounts. Proof of presence is an expansion of GitHub’s sudo mode for enterprises, enforcing

securityaddedchanged
Expired GitHub Actions artifacts no longer shown in UI and API

Expired artifacts are no longer displayed in the GitHub Actions run summary or returned by the REST API. Previously, an expired artifact remained visible with an “Expired” pill, even though the underlying files had already been deleted from

More ways to request and configure Copilot code reviews

GitHub Copilot code review now offers additional personal configurations to an expanded set of Copilot plans and an enterprise-level default setting. These improvements are now generally available: A dedicated personal settings page for aut

added
Node 20 is no longer available in GitHub Actions

This is the final notification that Node 20 is no longer available on GitHub Actions runners. Runners now use Node 24 for JavaScript actions. The temporary ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION opt-out is no longer available. If you maint

addedchanged
Local sandboxing in the GitHub Copilot app

Local sandboxing helps reduce the potential impact of unintended commands by limiting access to files, network resources, and credentials on your machine. In the GitHub Copilot app, you configure it per project for local repository and work

added
OpenTelemetry in the GitHub Copilot app

Understand how Copilot agents perform and interact with models and tools. The GitHub Copilot app now supports OpenTelemetry (OTel) configuration through enterprise-managed settings. OTel is an open source observability framework. Administra

New features and improvements in Copilot for JetBrains

GitHub Copilot for JetBrains 1.18.0 brings AI-assisted tool approvals, more control over agent conversations, and shared skills and instructions for your organization. You can also review plans with the Codex agent and manage MCP tools with

addedchangeddeprecated
Faster C++ code intelligence with whole codebase indexing

C++ code intelligence in GitHub Copilot CLI is now faster with support for whole codebase indexing. C++ repositories can contain millions of lines of code across deeply connected source files and headers. Without a reusable index, code-inte

changed
Claude Opus 5.5 is now available in GitHub Copilot

Claude Opus 5.5, Anthropic’s newest Opus model, is now available in GitHub Copilot. You can use it for agentic coding, long-running agentic tasks, and knowledge work. In early testing, Opus 5.5 resolved tasks comparably to Claude Opus 5 whi

added
OpenAI’s GPT-6 Sol and GPT-6 Luna now available

OpenAI’s GPT-6 family is expanding in GitHub Copilot with two additional models: GPT-6 Sol, and GPT-6 Luna. Joining the previously released GPT-6 Astra, these new options let you select the model that best fits your task, whether that’s eve

added
Security improvements for SSH

We’re removing several SSH algorithms, adding a new algorithm, and requiring larger RSA SSH keys to improve security. The changes are as follows: We’re removing the ability to use RSA keys using SHA-1 in SSH (i.e., the ssh-rsa signature typ

securityaddedchanged
Deprecation notice: All-platform CodeQL bundle

Starting with CodeQL CLI 2.27.0, the all-platform CodeQL bundle (i.e., codeql-bundle.tar.gz and codeql-bundle.tar.zst), which includes the binaries for all supported platforms up to this release, is marked as deprecated. In mid-March 2027,

deprecated
Refreshed repository pull requests page generally available

The new repository pull requests page is now generally available to all GitHub users. Highlights The new page makes it easier to find and act on pull requests in a repository, with new filtering and search options to help you find exactly w

addedchanged
GitHub Enterprise adds credential inventory exports

Enterprise owners can now export a complete inventory of every credential that can access their enterprise (e.g., SSH keys, classic and fine-grained personal access tokens, OAuth App access tokens, and GitHub App user-to-server and installa

securityadded
Grok 4.7 is now available in GitHub Copilot

Grok 4.7, xAI’s latest reasoning model, is now rolling out in GitHub Copilot. Building on Grok 4.6, it is designed for agentic coding and complex, multistep workflows. This model is billed at provider list pricing under usage-based billing.

added
Copilot code review: An improved review experience

Copilot code review now gives you a clearer view of how a review changes over time, more intelligently auto-resolves its own suggestions, and generates useful commit messages when you accept eligible suggestions in a batch. These updates he

addedfixedchanged
Manage the code coverage ruleset condition with the REST API

You can now use the generally available REST API to manage the Restrict code coverage repository ruleset option, in addition to the existing UI support. This ruleset lets you enforce a minimum code coverage percentage based on line coverage

changed
GitHub Copilot weekly releases — September 14

This week, GitHub Copilot adds new model selection options, code review updates, and Sentry integration in the Copilot app. There are also updates for admins, plus new agent features in VS Code. GitHub Copilot Copilot code review now resolv

addedchanged
Stage-only npm tokens for safer automation

You can now select Read and write (stage only) when creating an npm granular access token. This lets your automated workflows stage package versions for review without giving the token permission to publish new versions directly to the npm

added
Copilot impact dashboard now shows feature engagement

The Copilot impact dashboard now shows how many active users regularly use key Copilot features. Enterprise administrators can quickly see which experiences are widely adopted and which may need more enablement. Enterprise and organization

added
Agentic CLI customizations now in the usage metrics API

GitHub Copilot expands existing CLI report coverage with agentic activity metrics for skills, custom agents, Model Context Protocol (MCP) servers, slash commands, and plugins. What’s new The fields appear in enterprise and organization per-

added
Ubuntu 26 generally available and latest migration

The Ubuntu 26.04 runner image for GitHub Actions is now out of public preview and fully supported for production workflows on both x64 and arm64. As part of this release, the ubuntu-latest label will migrate to Ubuntu 26.04, giving you the

addedchangedremoved
Automate SSO authorization for classic PATs and SSH keys

Enterprise admins can now automate SSO authorization for existing classic personal access tokens (PATs) and SSH keys for organizations in GitHub Enterprise Cloud, replacing manual per-organization authorization by your developers. If your e

added
SCIM user responses now include a profileUrl attribute

SCIM user responses from GitHub now include the standard profileUrl attribute defined by RFC 7643, containing the absolute URL of the GitHub account linked to the external identity. Previously, matching a SCIM record to the corresponding Gi

added
Copilot budget increase requests are generally available

Previously, when a member used all the Copilot AI credits available to them, they were blocked from Copilot features that consume credits. This release adds a flow for them to request more budget the moment they hit the limit. You can appro

addedchanged
Code scanning AI Scan no longer requires CodeQL default setup

You can now use AI Scan for pull requests to find security vulnerabilities, even when CodeQL default setup isn’t enabled on a repository. Previously, AI Scan for pull requests only ran on repositories where CodeQL default setup was configur

securityaddedchanged
Enforce GitHub Advanced Security configurations

Enterprise administrators can now enforce GitHub Advanced Security configurations across their organizations. This prevents both organization and repository administrators from overriding settings defined at the enterprise level, helping se

security
GitHub Copilot suggests custom properties definitions

GitHub Copilot can now suggest allowed values when you create a custom property for repositories in your organization. This feature is in public preview for GitHub Copilot Business and Copilot Enterprise plans. Custom properties let enterpr

added
SHA-1 in HTTPS on GitHub sunset

Previously we announced we would be disabling SHA-1 in HTTPS for GitHub on September 15th, 2026. Following the planned schedule, GitHub has disabled SHA-1 in HTTPS for github.com and partner CDNs, including GitHub Enterprise Cloud and GitHu

Configure cost and quality in Copilot auto model selection

GitHub Copilot auto model selection now offers three tiers: efficiency, balance, and intelligence. Choose the tier that reflects how you want auto to weigh cost, quality, and response time for each prompt. Copilot will then optimize accordi

Profiles now show your highest achievement badge tier

Your GitHub profile now displays the highest tier you’ve earned for achievements with multiple levels. Previously, profiles could display the first tier earned, even after you had progressed to a higher level. Now, your profile better refle

Add VS Code Agents to Copilot usage metrics

GitHub Copilot usage metrics reports now include generally available metrics for activity in the dedicated VS Code Agents window, helping you measure adoption and engagement across enterprises and organizations. What’s new Aggregate enterpr

added
Auto-resolution and analysis updates in Copilot code review

Copilot code review now resolves its own comments once you address them and writes smart commit messages for you when you apply its code suggestions. Behind the scenes, Copilot now uses a broader set of shell tools to validate the code it r

changed
GitHub Copilot weekly releases — September 7

This week, GitHub Copilot introduces Jira integration in Copilot app and adaptive model orchestration with Project HydraFusion in Copilot CLI. We also introduced new agent automation in Visual Studio Code and expanded enterprise controls fo

addedchanged
Refreshed repository pull requests page in public preview

A refreshed repository-level pull request listing page is now in public preview for all GitHub users. It brings powerful filtering, compact presentation mode, and more. Highlights The new page makes it easier to find and act on pull request

addedchanged
AI Scan for pull request APIs in public preview

You can now manage GitHub code scanning’s AI Scan for pull request enablement with REST API endpoints at the organization and repository levels. This public preview gives teams a programmatic way to roll out AI-powered security detections f

securityaddedchanged
Control GitHub Actions cache access with cache-mode

You can now use cache-mode to apply least-privilege access to the GitHub Actions cache at the workflow or job level. By granting each workflow or job only the cache access it needs, you can prevent unnecessary restores or saves and help pro

added
MAI-Code-1-Flash deprecated

We have deprecated MAI-Code-1-Flash across all GitHub Copilot experiences (including Copilot Chat, inline edits, ask and agent modes, and code completions) today, September 10, 2026. Model Deprecation date Suggested alternative MAI-Code-1-F

changeddeprecated
Xcode 27 runner image now runs on macOS 27

You can now validate your Apple apps against macOS 27 using the Xcode 27 runner image for GitHub-hosted macOS runners, available in public preview. The image previously ran on macOS 26. How you target the image stays the same. Keep using th

npm extends recovery-code security holds to all accounts

npm now places a temporary 72-hour security hold on any account after a successful recovery-code sign-in, extending a protection that previously applied only to high-impact accounts. This change applies to all npm accounts. During the hold,

security
CodeQL 2.27.0 adds support for Linux ARM64

CodeQL 2.27.0 is now available on Linux ARM64, adds a new Rust security query, expanded framework coverage for Java/Kotlin and C#, and analysis accuracy improvements across multiple languages. CodeQL is the static analysis engine behind Git

securityaddedchanged
GitHub Advanced Security expands trial availability

More GitHub Enterprise Cloud customers can now start a self-serve GitHub Advanced Security trial to evaluate GitHub Code Security and GitHub Secret Protection. Eligibility has expanded from enterprises with up to 100 licenses to enterprises

security
Block pull requests with exposed secrets from merging

Repository rulesets allow you to easily add scalable protections across your repositories. Starting today, you can use repository rulesets to block pull requests from merging when the pull request introduces secret scanning alerts. What’s n

securityadded
Remediate Code Quality findings with agentic autofix

Agentic autofix is now available to help you burn down findings in your code quality backlog. You can select up to 25 standard findings on a page and assign the whole set to Copilot in one action. Copilot starts fixing them agentically on a

Enterprise-managed sandbox in Copilot for JetBrains

This update brings support for enterprise-managed sandbox policies, cross-file cursor jumps for next edit suggestions, global project context in chat, enterprise policy diagnostics, and a new connection between terminal Copilot CLI sessions

addedfixedchanged
GitHub Enterprise Server 3.22 is now generally available

GitHub Enterprise Server (GHES) 3.22 is now available and introduces new capabilities across the platform. Here are a few highlights in the 3.22 release: Administrators can configure Copilot CLI to work with GHES for enterprises that operat

securityadded
New customer portal help.github.com

The support portal has been redesigned and moved to a new home at help.github.com. It brings support, docs, learning, community, and account resources together in one place with Copilot-powered search across all of them. What’s new for you:

added
Automatic Dependabot access to GitHub-hosted registries

Dependabot can now read from private GitHub Packages registries without a personal access token. If a package has granted your repository access through “Manage Actions access” in the package settings, Dependabot reuses that grant. What’s n

addedchanged
GitHub Copilot weekly releases — August 31

This week, GitHub Copilot expands model choice and content protections, while VS Code adds new ways to manage agent sessions and get pull requests merge-ready. GitHub Copilot, general Claude Fable 5.1 is available to Copilot Pro+, Max, Busi

addedchanged
GPT-6 Astra is generally available in GitHub Copilot

GPT-6 Astra from OpenAI is now available in GitHub Copilot. OpenAI’s latest general-purpose model, GPT-6 Astra, is designed for long-horizon, autonomous coding and agentic tasks. In our internal testing, GPT-6 Astra stood out for how it wor

added
New API endpoint provides privacy-safe star history data

Track repository star growth over time with the new star history REST API endpoint without exposing stargazer identities. Earlier this year, stargazer listing endpoints were restricted to admins and collaborators to protect user privacy. No

addedchanged
New customer portal help.github.com

The support portal has been redesigned and moved to a new home at help.github.com. It brings support, docs, learning, community, and account resources together in one place with Copilot-powered search across all of them. What’s new for you:

added
Multiple trusted publishing configurations for npm

We’re continuing to make trusted publishing smoother for npm publishers, guided by maintainers feedback. Three updates to npm publishing are now generally available: Multiple trusted publishing configurations per package Staged packages can

addedchanged
GitHub Actions: Early September 2026 updates

GitHub Actions now includes three updates that give you clearer visibility and finer-grained control over your workflows. New REST API for runner version deprecations A new REST API returns when registration and runtime support end for a gi

addedchangeddeprecated
Upcoming deprecation of selected GitHub Copilot models

We will deprecate the following models across all GitHub Copilot experiences (including Copilot Chat, inline edits, ask and agent modes, and code completions) on October 2nd, 2026: Model Deprecation date Suggested alternative Gemini 3.5 Fla

changeddeprecated
GitHub CLI Linux package signing key expires September 5

The current PGP key for the GitHub CLI Linux package repositories expires on Saturday, September 5, 2026. Beginning with the first release after that date, APT and RPM repository metadata and newly published RPM packages will be signed with

Gemini 3.8 Flash is now available in GitHub Copilot

Gemini 3.8 Flash, Google’s latest Flash model, is now available in GitHub Copilot. In our early testing, Gemini 3.8 Flash performed strongly on complex terminal-based coding tasks and demonstrated rigorous validation and persistent recovery

added
Reopening Copilot Business and Enterprise signups

We’re gradually reopening sign-ups for Copilot Business and Copilot Enterprise customers paying by credit card or PayPal over the next couple of weeks. If you’ve been waiting to get started with Copilot, select the plan that fits your needs

addedchanged
CodeQL 2.26.4 improves GitHub actions security detections

CodeQL is the static analysis engine behind GitHub code scanning, which finds and remediates security issues in your code. We’ve recently released CodeQL 2.26.4, which adds support for Go 1.27, improves alert locations for Rust data flow qu

securityaddedchanged
Enterprise-managed settings support any default model

You can now set your preferred GitHub Copilot model as the default for new conversations through enterprise-managed settings. This lets you choose the default model that best fits your workflows. You can also customize the default by enterp

addedchanged
Content exclusions generally available in Copilot app and CLI

The GitHub Copilot app and Copilot CLI now respect content exclusion policies configured by enterprise, organization, and repository administrators. Copilot won’t use excluded files as context, helping you protect sensitive code across agen

Set an expiration date for individual user budgets

You can now set an optional expiration date on an individual user budget, and GitHub removes the budget on that date. This capability is generally available. The user then falls back to the next budget that applies to them (i.e., their cost

changedremoved
Copilot code review can now approve pull requests

Copilot now tells you when a pull request is ready to approve, and admins can authorize it to sign off on approval. The ability for Copilot to approve is off by default and configurable at the enterprise, organization, and repository level.

added
Block users from discussion comments in personal repositories

You can now block or unblock users directly from discussion comments in repositories owned by personal GitHub accounts, extending the in-context blocking controls already available for issue and pull request comments. To block or unblock a

added
Claude Fable 5.1 is generally available in GitHub Copilot

Claude Fable 5.1 from Anthropic is now available in GitHub Copilot. The latest model in Anthropic’s Mythos class, Claude Fable 5.1 is designed for long-horizon, autonomous coding and knowledge-work tasks. In our internal testing, Claude Fab

GitHub CLI: Media in issues, pull requests, and comments

GitHub CLI now has a repeatable --attach flag that uploads a local image or video and references it inline in an issue, pull request, or comment body. This is now generally available to all users on GitHub across all plans. You just need to

securitychanged
Copilot model access update for GitHub Team plans

We have updated how model access is determined for Copilot users who hold seats in more than one organization. To keep billing and governance in sync, your model access is now determined only by the organization paying for your usage. What’

changed
Selected GitHub Copilot models deprecated

As of today, September 1, 2026, we have deprecated the following models across most GitHub Copilot experiences (including Copilot Chat, inline edits, ask and agent modes, and code completions). Note that Claude Sonnet 4.6 is still available

changeddeprecated
GitHub Copilot in VS Code, August 2026 releases

This changelog covers VS Code v1.132 through v1.135, shipped throughout August 2026. These releases make it easier to organize agent sessions, review changes, and navigate long conversations. Agent Host, the integrated browser, and dictatio

addedchanged
GitHub Copilot in Visual Studio — August update

August 2026 brought more control over how GitHub Copilot reasons, which models you use, how teams share specialized agents, and when you ask for a code review. Highlights Here’s what’s new with GitHub Copilot in Visual Studio 2026. Check th

addedchanged
GitHub Copilot weekly releases — August 24

This week’s updates give you more control over how Copilot runs, from team sessions in Slack and Teams to customization across the app, CLI, and your IDE. GitHub Copilot in Slack and Microsoft Teams Turn team conversations into shared agent

addedchanged
Upcoming changes to GitHub Copilot policies and billing

To provide a strong, consistent Copilot experience, we’re making three separate, upcoming changes to Copilot policies and billing. Please review the upcoming updates to understand what may impact you. Reopening Copilot Business and Enterpri

addedchanged
Better label management on issues is generally available

We’re making it easier to keep labels organized and find the right one, especially in repositories with long and growing label lists. Suggested Labels You can now find the right label faster with suggestions based on what a repository has b

Copilot code review: Resolution reasons and expanded capabilities

Copilot code review can now review two types of pull requests it didn’t cover before: Reviews requested automatically on pull requests authored by bots, including Copilot cloud agent Very large pull requests Additionally, you can now submit

addedchanged
GitHub Classroom deprecated

As of August 28, 2026, GitHub Classroom is now deprecated in favor of our selected partner solutions. The GitHub Classroom website, APIs, and related services have now been decommissioned. However, any GitHub user accounts, repositories, an

deprecated
Actions retention will cover checks, workflow runs, and statuses

Starting October 1, 2026, checks, workflow runs, and statuses will be governed by the same Actions retention setting that already controls how long artifacts and logs are kept, with a default of 90 days. Until now, checks, workflow runs, an

removed
Close all open contributions authored by a blocked user

You can now automatically close all open issues, discussions, and pull requests authored by a user when you block them from your personal account or organization. To use this option, select Close content authored by this user in the block d

Global model policy generally available

In July, we announced a default model policy for generally available GitHub Copilot models on Copilot Business and Copilot Enterprise plans. Starting today, we’re gradually rolling out enforcement of the policy through September 1, so it wi

added
GitHub Apps can now access enterprise billing data

Enterprise owners can now grant a GitHub App access to enterprise billing data. When you create or configure a GitHub App, you can select the enterprise billing permission and choose one of two levels: read or read and write. Previously, th

changed
Rule insights dashboard generally available

The rule insights dashboard is now generally available at both the repository and organization levels. You get a visual, high-level view of how GitHub evaluates and enforces your GitHub repository rulesets, so you can spot trends and report

GitHub Copilot app Customize tab is generally available

GitHub Copilot is more useful when it works with the tools, knowledge, and workflows your team already relies on. The new Customize tab in the GitHub Copilot app brings MCP servers, plugins, skills, and canvases together in one place. Explo

added
Block users directly from security advisories

You can now block a user directly from a security advisory page in public repositories owned by either an organization or a personal account. This brings the streamlined moderation experience available for issues and pull requests to securi

securitychanged
Push rules in rulesets now support path exceptions

You can now configure push rules more granularly by exempting specific file paths, so a rule applies everywhere in scope except the paths you choose. Path exceptions are in public preview. Push rules give you strong control over what enters

added
Better tools for managing blocked users

Managing blocked users is now faster and clearer for personal accounts and organizations. With this update, you can: Search by username, full name, or email. Sort and paginate long lists. Filter by block reason (e.g., Spam, Misconduct, or H

addedchanged
The new GitHub Copilot experience in Slack

The GitHub integration in Slack now brings the agentic capabilities of GitHub Copilot CLI and the GitHub Copilot app into Slack in public preview. You can work with @GitHub to plan changes, investigate problems, and hand off coding tasks fr

addedchanged
Shared agentic work with GitHub Copilot in Microsoft Teams

Turn a Microsoft Teams discussion into a collaborative agent session everyone can see and help direct. Mention @GitHub in a channel, thread, or direct message to start a GitHub Copilot cloud agent session. Anyone in the conversation can ask

added
Windows 11 arm64 VS2026 image generally available

The Windows 11 arm64 image with Visual Studio 2026 is now generally available on standard and larger GitHub-hosted runners. To use it in GitHub Actions, update your workflow file to runs-on: windows-11-vs2026-arm. Prepare for the upcoming m

breakingaddedchanged