Strengthening supply chain security: Preparing for the next malware campaign
Security advice for users and maintainers to help reduce the impact of the next supply chain malware attack.
Security advice for users and maintainers to help reduce the impact of the next supply chain malware attack.
Looking ahead to the New Year? These GitHub Podcast episodes help you cut through the noise and build with more confidence across AI, open source, and developer tools.
From Appwrite to Zulip, Universe 2025’s Open Source Zone was stacked with standout projects showing just how far open source can go. Meet the maintainers—and if you want to join them in 2026, you can now apply for next year’s cohort.
Organizations now have more granular control over who can request GitHub Apps and OAuth apps. This enhancement helps you implement stricter governance policies while maintaining flexibility for your security posture.…
Copilot memory is now available in public preview for GitHub Copilot Pro and Pro+ users, with support in Copilot coding agent and Copilot code review. Copilot memory Copilot memory enables…
When you assign an issue to Copilot, you’ll now automatically be added as an assignee yourself. This makes it easier to track your work using filters like assignee:@me and understand…
You can now create Agent Skills to teach Copilot how to perform specialized tasks in a specific, repeatable way. Agent Skills are folders containing instructions, scripts, and resources that Copilot…
Claude Opus 4.5 is generally available to Copilot Enterprise, Copilot Business, Copilot Pro, and Copilot Pro+. You’ll now be able to access the model in GitHub Copilot Chat on github.com,…
You can now manage GitHub Teams from a dedicated page in Settings, instead of the left-hand navigation menu. This change streamlines the navigation and makes other important features easier to…
GitHub Enterprise Cloud with data residency now supports Copilot code review preview features, providing you an opportunity to try the latest agentic code review capabilities in your pull requests. These…
You can now view pull request–level activity metrics for your enterprise—including overall pull request creation and review activity—as well as how GitHub Copilot participates in that workflow. All of this…
GPT-5.2 is generally available to Copilot Enterprise, Copilot Business, Copilot Pro, and Copilot Pro+. You’ll now be able to access the model in GitHub Copilot Chat on github.com, GitHub Mobile,…
GPT-5.1-Codex-Max is generally available to Copilot Enterprise, Copilot Business, Copilot Pro, and Copilot Pro+. You’ll now be able to access the model in GitHub Copilot Chat on github.com, GitHub Mobile,…
GPT-5.1 and GPT-5.1-Codex are generally available to Copilot Enterprise, Copilot Business, Copilot Pro, and Copilot Pro+. You’ll now be able to access the model in GitHub Copilot Chat on github.com,…
Organizations can now apply Copilot code review to all pull requests, including those from contributors without a Copilot license. Usage is billed seamlessly to the organization as premium requests, without…
Gemini 3 Flash, ideal for tasks where speed is crucial, is now rolling out in public preview in GitHub Copilot. Availability in GitHub Copilot Gemini 3 Flash is now rolling…
Dependabot now supports parsing and updating environment.yml Conda environment specification files. This release includes version updates for Conda-based projects. Why it matters Many projects rely on Conda for managing dependencies…
Developers can now use Dependabot to automatically keep their Julia dependencies up to date. For projects that use Julia as a package manager, Dependabot version updates can now ensure dependencies…
Developers can now use Dependabot to automatically keep their Bazel dependencies up to date. For projects that use Bazel—either Bzlmod or WORKSPACE—Dependabot version updates can now ensure dependencies stay current…
Developers can now use Dependabot to automatically keep their OpenTofu dependencies up to date. For projects that use OpenTofu, Dependabot version updates can now ensure dependencies stay current with the…
Dependabot now supports security alerts and updates for uv. When vulnerabilities are detected in your uv dependencies, Dependabot can automatically open security alerts and pull requests to update to secure…
Build what’s next on GitHub, the place for anyone from anywhere to build anything.
Catch up on the GitHub podcast, a show dedicated to the topics, trends, stories and culture in and around the open source developer community on GitHub.