Releases Index
GitHub

GitHub

github.comDeveloper Tools
$npx @buildinternet/releases get github

Claude Haiku 5.5 lands; agent sandboxing now GA

This release6 featuresNew capabilitiesAI-tallied from the release notes

Claude Haiku 5.5 is available to Copilot Pro, Pro+, Max, Business, and Enterprise users, and local sandboxing that limits agents' access to files, networks, and credentials is now generally available in Copilot CLI, the Copilot app, and VS Code sessions using Agent Host at no extra cost. The Copilot app now supports separate GitHub accounts for your Copilot license and your repositories, Copilot CLI can discover local Ollama models via /model, and VS Code 1.141 adds side-by-side agent sessions and worktree cleanup.

Read more →

Go CFG reworked; macOS 27 traced builds unsupported

BreakingThis release1 featureNew capabilities9 enhancementsImprovements to existing features3 fixesBug fixesAI-tallied from the release notes
GitHub Changelog · v2.27.2

CodeQL autobuild and manual build modes no longer support compiled languages on macOS 27 with any Xcode version, or on macOS 26 with Xcode 27, because Apple stopped shipping multi-architecture x86-64/arm64 binaries. The Go control-flow graph now uses the shared CFG library, changing nodes, edges, locations, and basic-block boundaries, alongside a C++ std::regex ECMAScript parser and language analysis improvements for Go, Rust, and JavaScript.

Read more →

Copilot code review billing can now hit org cost centers

This release2 featuresNew capabilitiesAI-tallied from the release notes

Organization owners can bill Copilot code reviews from licensed members to the organization's cost center instead of consuming member Copilot quotas, requiring AI Credits paid usage with an optional budget. Owners and repository admins can also restrict review requests to users holding a Copilot license from their organization or enterprise.

Read more →

Timelines navigable as lists; loaded items announced

This release2 featuresNew capabilitiesAI-tallied from the release notes

Issue, pull request, commit, secret scanning alert, and license compliance alert timelines now expose list structure, item count, and current position to screen readers, and "Load more" or "Load all" announces how many events loaded after focus moves to the newest event. The update is available on github.com and GitHub Enterprise Server 3.23.

Read more →

Draft PRs can now count toward PR limits

This release1 featureNew capabilitiesAI-tallied from the release notes

Pull request limits can now be configured to include draft pull requests, closing a loophole where users could open unlimited drafts even after a limit was set. The change is aimed at reducing clutter, notifications, and CI runs from low-quality repository spam.

Read more →

Claude Haiku 5.5 reaches GA in GitHub Copilot

This release1 featureNew capabilitiesAI-tallied from the release notes

Anthropic's newest lightweight model is generally available across Copilot surfaces including VS Code, Visual Studio, Copilot CLI, the cloud agent, github.com, mobile, and JetBrains, Xcode, and Eclipse IDEs, billed at provider list pricing under usage-based billing. Business and Enterprise administrators can manage access through the model policy in Copilot settings, where new models are enabled by default unless the global default was turned off.

Read more →

AI secret detection model launches; push protection checks billed

This release3 featuresNew capabilities2 enhancementsImprovements to existing featuresAI-tallied from the release notes

GitHub's fine-tuned secret detection model reads surrounding code to flag likely credentials, including passwords without a recognizable token format. Existing AI-detected password alerts are automatically upgraded to the new model at no charge for GHSP and GHAS customers, while new opt-in push protection checks and Copilot /security-review checks will consume AI Credits, billed to the owning organization.

Read more →

Local sandboxing now GA for Copilot

This release1 featureNew capabilitiesAI-tallied from the release notes

Local sandboxing for GitHub Copilot is generally available in Copilot CLI, the Copilot app, and VS Code sessions using Agent Host, giving agent-initiated tools and commands a restricted execution boundary over filesystem, network, credentials, and other system capabilities based on developer or organization policies. It is powered by Microsoft eXecution Container (MXC), which maps a common sandbox policy to native OS controls on Windows, macOS, and Linux, and is included with Copilot at no additional cost.

Read more →

Local Ollama models discoverable from /model picker

This release1 featureNew capabilitiesAI-tallied from the release notes

Starting in CLI version 1.0.94-0, /model discovers supported models from a running local Ollama instance alongside configured and Copilot cloud models, and a discovered model can be added for the current session without restarting the CLI. Ollama and the model must already be installed, models must support tool calling and streaming, and provider connection failures surface in the picker with an explanation.

Read more →

Open repo in Copilot from menu; screen readers get real markdown labels

preThis release1 featureNew capabilities3 enhancementsImprovements to existing features3 fixesBug fixesAI-tallied from the release notes
GitHub Desktop · release-3.6.7-beta3

Repositories can now be opened in GitHub Copilot from the Repository menu or a keyboard shortcut, and Copilot no longer adds itself as a co-author to generated commit messages. Fixed sandboxed markdown content being announced as "frame 0" by VoiceOver and NVDA, Finder warnings when Spotlight metadata is unavailable, and a hidden window not reappearing when a menu item is chosen on macOS.

Read more →

Copilot agent metrics undercounted; IDE updates restore counting

This release1 enhancementImprovements to existing featuresAI-tallied from the release notes

IDEs that moved Copilot agent sessions to the Copilot SDK didn't identify the originating IDE, so agent activity was left out of usage metrics and some was counted as Copilot CLI activity; the fix is available in VS Code 1.139.0 and later, with Visual Studio, JetBrains, Eclipse, and Xcode fixes rolling out by November 2026. Billing is unaffected, but missing data can't be backfilled, so activity is undercounted until developers update.

Read more →

Stacked pull requests GA; merge queue treats stack as one group

This release10 featuresNew capabilities1 enhancementImprovements to existing featuresAI-tallied from the release notes

Stacked pull requests are now generally available on all github.com plans, with Rebase stack preserving approvals and signed commits, bypass permissions applying to stacks, and stacks entering the merge queue as a single merge group. Also adds auto-merge for stacks rolling out over the next few weeks, always-visible stack context in the PR header, Shift+J/Shift+K navigation, a stacked action on the pull_request webhook, and gh stack support for Git worktrees.

Read more →

Internal ops move to Node 24; broker WebSocket probes added

BreakingThis release3 featuresNew capabilities1 enhancementImprovements to existing featuresAI-tallied from the release notes
Actions Runner · v2.338.0

The runner's own Node usage for hashFiles(), ./run.sh --check, and the runsvc.sh service wrapper now uses Node 24 instead of Node 20; set ACTIONS_RUNNER_FORCED_INTERNAL_NODE_VERSION=node20 to temporarily revert. Also added broker-listener WebSocket connectivity probes, owned session IDs on broker session deletes, and support for $/ self-repository references in action manifests.

Read more →

Security overview shows AI Scan enablement status

This release1 featureNew capabilitiesAI-tallied from the release notes

Organization and enterprise administrators can now see AI Scan for pull requests enablement status in the security overview coverage view, with enabled and not enabled repository counts in the code scanning summary and per-repository effective status. The coverage view is filterable with code-scanning-ai-scan-pr-scan:enabled and not-enabled, and CSV exports include a Code Scanning AI Scan for pull requests column.

Read more →

New secret scanning detectors for Lovable, Pydantic, Supabase

This release1 featureNew capabilitiesAI-tallied from the release notes

Secret scanning now detects six new secret types from Lovable Labs, Pydantic Services Inc., and Supabase, including lovable_api_key, logfire_token, pydantic_ai_gateway_api_key, and Supabase OAuth and scoped personal access tokens. Lovable Labs also joined the secret scanning partnership program, so its secrets found in public repositories are forwarded to the provider for revocation.

Read more →

Installation tokens now ~520 chars; legacy header deprecated

BreakingThis release1 featureNew capabilities1 enhancementImprovements to existing featuresAI-tallied from the release notes

All newly minted GitHub App installation tokens now use the stateless ghs_APPID_JWT format, roughly 520 characters long instead of 40, with permissions, repo scoping, one-hour expiration, and the installation access token REST endpoint unchanged. The temporary X-GitHub-Stateless-S2S-Token header is deprecated on November 30, 2026, and integrations should treat tokens as opaque strings rather than assuming 40-character length.

Read more →

Copilot code review hits API; Balanced now default effort

Breaking (minor)This release1 featureNew capabilities1 enhancementImprovements to existing featuresAI-tallied from the release notes

Copilot code review can now be requested through REST and GraphQL APIs with a per-request review effort level, and the Default review effort level now uses Balanced for new and existing repositories and organizations as of September 28, 2026. Explicit Lite selections were respected, and effort can be set per level in enterprise, organization, repository, or personal settings.

Read more →

Unvalidated npm publish configs expire in 48 hours

BreakingThis release1 featureNew capabilities2 enhancementsImprovements to existing featuresAI-tallied from the release notes

Unvalidated npm trusted publishing configurations now expire 48 hours after creation and can no longer authorize publishing, becoming validated and exempt after a first successful publish. npm also rejects trusted publishing tokens from GitHub Actions issue_comment events, alongside the existing pull_request_target restriction.

Read more →