GitHub Code Quality in public preview
GitHub Code Quality is now available in public preview! It turns every pull request into an opportunity to improve. With in-context findings, one-click Copilot fixes, and reliability and maintainability scores,…
GitHub Code Quality is now available in public preview! It turns every pull request into an opportunity to improve. With in-context findings, one-click Copilot fixes, and reliability and maintainability scores,…
Copilot code review (CCR) now blends LLM detections and tool calling with deterministic tools like ESLint and CodeQL, delivering smarter reviews and a seamless handoff to the Copilot coding agent…
To help you understand ownership and impact of a leaked secret, GitHub secret scanning now surfaces additional metadata for supported secret types. What’s changing? Secret scanning already performs validity checks…
GitHub releases now support immutability, adding a new layer of supply chain security. With immutable releases, assets and tags are protected from tampering after publication, so the software you publish—and…
Custom images for GitHub-hosted runners are now available in public preview. This feature allows you to start with a GitHub-curated base image and build your own virtual machine image tailored…
You can now assign GitHub code scanning alerts directly to Copilot to assist with automated remediation. This extends Copilot coding agent capabilities to security vulnerabilities, enabling faster resolution of common…
Learn how to bring structure and security to your AI ecosystem with the GitHub MCP Registry, the single source of truth for managing and governing MCP servers.
CodeQL is the static analysis engine behind GitHub code scanning, which finds and remediates security issues in your code. We’ve recently released CodeQL 2.23.3, which makes Rust analysis and C/C++…
Last month, GitHub Enterprise Cloud introduced a public preview of enterprise teams for managing Copilot Business licenses in their enterprise account. We are back with more capabilities that allow enterprise…
Organization custom properties, now in public preview, let you add metadata to your organizations for streamlined ruleset targeting. What are organization custom properties? Just like custom properties for repositories, organization…
Have you ever thought about using AI to update community health files for your repositories? This blog shares actionable next steps for doing just that, including a starter kit with a checklist and tutorials on how to create three useful files.
Log4Shell proved that open source security isn’t guaranteed and isn’t just a code problem. It’s about supporting, enabling, and empowering the people behind the projects that build our digital infrastructure.
Ahead of the sunset of Copilot knowledge bases on November 1, 2025, we’ve introduced a new way for you to migrate your legacy knowledge bases into a Copilot Space. Simply…
GitHub Copilot and VS Code teams, along with the Microsoft Open Source Program Office (OSPO), sponsored these nine open source MCP projects that provide new frameworks, tools, and assistants to unlock AI-native workflows, agentic tooling, and innovation.
Actions Runner Controller (ARC) release 0.13.0 is now available and provides improvements in storage, networking, platform, and metrics. Enable container hooks to remove storage limitations ARC now supports container lifecycle…
Discover how GitHub Copilot has evolved from a high-powered autocomplete tool to a powerful, multi-model agentic assistant.
We’ve added support for Rust and scanning C/C++ projects without builds in CodeQL, the engine powering GitHub code scanning. Both of these initiatives have ended their public preview and are…
GitHub Enterprise Server (GHES) 3.18 enhances deployment efficiency, monitoring capabilities, code security, and policy management. Here are a few highlights in the 3.18 release: Enterprise administrators can define custom properties…
We’ve removed offset-based pagination parameters (page, first, and last) in all GitHub Dependabot alerts for REST API endpoints. Going forward, we only support cursor-based pagination parameters (before, after, and per_page).…
See how this three-part framework will turn AI into a repeatable and reliable engineering practice.
CodeQL is the static analysis engine behind GitHub code scanning, which finds and remediates security issues in your code. We’ve recently released CodeQL 2.23.2, which introduces a new Rust security…
Build what’s next on GitHub, the place for anyone from anywhere to build anything.
Join us October 28-29 in San Francisco or online for GitHub Universe, our flagship developer event uniting people, agents, and the world’s code.