GitHub Releases

GitHub changelog, platform updates, and Copilot coding-assistant releases. New features, breaking changes, security advisories and deprecations - each summarised in plain English and updated continuously.

Tracking 199 GitHub releases · Updated

  • GitHub Changelog aiawspreviewengineer ·

    GitHub Copilot Enterprise Teams Model Policy Targeting in Public Preview

    GitHub Copilot Enterprise customers with Copilot Business or Enterprise licenses can now use user-based model policy targeting in public preview. This feature allows AI administrators to set baseline models for the enterprise and grant additional models to specific teams, enabling finer-grained control mapped to job roles or experimentation. Access begins rolling out on August 3rd, with opt-in available through an Enterprise teams mode toggle.

    feature announcement
  • GitHub Changelog securitygovernanceengineer ·

    npm restricts granular access token ability to bypass 2FA for sensitive actions

    npm granular access tokens (GATs) configured to bypass two-factor authentication (2FA) can no longer perform sensitive account, organization, and package management actions. This change closes a significant attack vector where leaked tokens could be used for account takeovers. The restriction impacts only npm granular access tokens and requires users to perform these actions interactively with a 2FA challenge.

    security patch
  • GitHub Changelog aiengineer ·

    GitHub Copilot VS Code Updates: Agents, Chat, UI, and Accessibility

    GitHub Copilot for VS Code received significant updates in July 2026, enhancing agent interactions, code review, and chat capabilities. These improvements aim to streamline developer workflows, offering features like multi-chat sessions, faster review tools, and better session management. The releases also introduce a modernized UI preview, improved editor and terminal navigation, and new accessibility features including built-in dictation. These changes affect developers and architects using Copilot within Visual Studio Code.

    feature patch
  • GitHub Changelog infrapreviewengineer ·

    GitHub Stacked Pull Requests Enter Public Preview

    GitHub has launched Stacked Pull Requests in public preview, allowing engineers to break large changes into smaller, ordered, and reviewable pull requests. This feature aims to improve the review process for substantial code modifications, making it easier to maintain quality and speed up delivery. The preview is rolling out to all repositories, with merge queue support coming soon.

    feature announcement
  • GitHub Changelog aiazurepreviewengineer ·

    GitHub Copilot Visual Studio Update Adds New Agent, Skills, Code Review

    GitHub Copilot for Visual Studio has released an update introducing a new agent in public preview, built-in expertise from .NET and Azure teams, and enhanced code review capabilities. This update aims to improve developer productivity by offering more tailored assistance and streamlined workflows. The new agent and skills are available to all plans, while organization-level custom instructions require a Business or Enterprise subscription.

    feature announcement
  • GitHub Changelog aigapreviewengineer ·

    GitHub Copilot Code Review: Agent Skills and MCP Now Generally Available

    GitHub Copilot code review now offers generally available support for agent skills and MCP servers, enhancing reviews with team tools and external context. This feature, previously in public preview, integrates custom tools and data from third-party platforms directly into the review process. It is available to Copilot Pro, Pro+, Business, and Enterprise users, with existing preview configurations carrying over.

    feature patch
  • GitHub Changelog aigaengineer ·

    GitHub Copilot: Default Model Enablement for Business and Enterprise Plans

    GitHub is rolling out a global default enablement policy for generally available Copilot models on Business and Enterprise plans. This change aims to simplify management by automatically enabling new models, requiring only an opt-out for organizations needing stricter governance. Admins have 28 days to configure this new policy before it takes effect on August 26, after which models not explicitly configured will follow the default setting unless manually overridden.

    feature announcement
  • GitHub Changelog securityinfraengineer ·

    CodeQL 2.26.1 enhances analysis accuracy and framework coverage

    CodeQL version 2.26.1 improves static analysis accuracy and expands framework coverage for Go, Java/Kotlin, and JavaScript/TypeScript, while reducing false positives in Rust analysis. These enhancements aim to improve security issue detection for users of GitHub code scanning. The update is automatically deployed to GitHub.com users and will be included in a future GHES release.

    patch
  • GitHub Changelog aiengineer ·

    Grok 4.5 reasoning model available in GitHub Copilot

    Grok 4.5, xAI's latest reasoning model, is now rolling out in GitHub Copilot for various SKUs, offering fast, agentic coding with a 500,000 token context window. It supports text and image inputs and is designed for complex, time-sensitive workflows, showing strong performance in internal testing. Administrators must enable the Grok 4.5 policy, which is off by default, to access this model.

    feature announcement
  • GitHub Changelog securityinfraengineer ·

    GitHub Actions holds workflows for approval to prevent attacks

    GitHub Actions now automatically holds potentially malicious workflows for approval before execution to prevent supply chain attacks. This measure requires a repository collaborator with write access to review and approve the workflow run through an authenticated web session. This protection is active for public repositories on GitHub.com and is not configurable by users. GitHub Enterprise Server is not affected by this change.

    security announcement
  • GitHub Changelog securitygaengineer ·

    Dependabot alerts expand to cover malicious packages from OpenSSF

    GitHub's Dependabot alerts now incorporate malware advisories from the OpenSSF malicious-packages repository, broadening detection across ecosystems like npm and PyPI. This enhancement means users with malware alerting enabled will automatically benefit from expanded coverage, identifying risks from newly published malicious packages. To leverage this, users can enable malware alerting in repository settings or browse advisories directly on GitHub.

    feature announcement
  • GitHub Changelog securityinfraengineer ·

    GitHub Actions holds potentially malicious workflows for approval

    GitHub Actions now holds certain workflow runs for approval to protect public repositories from supply chain attacks. This feature automatically prevents malicious workflows from executing until a collaborator with write access reviews and approves them via an authenticated web session. This protection is applied automatically and currently only affects public repositories on github.com, not GitHub Enterprise Server.

    security announcement
  • GitHub Changelog aiinfraengineer ·

    GitHub Copilot for JetBrains: Enhanced Config & Model Management

    GitHub Copilot for JetBrains has been updated with improved OpenTelemetry configuration and model management, offering greater control over agent workflows and cost. This release introduces new options for token limits, disabling/enabling models, and integrating MCP servers and custom agents in Claude flows. The enhancements benefit engineers and architects managing observability, cost control, and custom IDE workflows.

    feature patch
  • GitHub Changelog aiengineer ·

    Claude Opus 5 model now available in GitHub Copilot

    GitHub Copilot now supports Anthropic's Claude Opus 5, designed for complex coding tasks requiring multi-step reasoning and tool use. This new model enhances performance on agentic workflows and includes improved safeguards for cyber content, though these may occasionally block security-related requests. It's available to specific Copilot plan users, with gradual rollout and administrator policy enablement required.

    feature announcement
  • GitHub Changelog aigaengineer ·

    GitHub Copilot cloud agent for Linear now generally available

    GitHub Copilot cloud agent for Linear is now generally available, allowing users to assign issues directly to Copilot for automated pull request creation and progress tracking within Linear. This feature enhances developer workflows by automating coding tasks and integrating directly with issue tracking. It is available for Copilot Pro, Pro+, Business, and Enterprise users, requiring specific GitHub and Linear administrative permissions to set up.

    feature announcement
  • GitHub Changelog aipreviewengineer ·

    GitHub Issues public preview adds agent automation controls

    GitHub Issues is introducing agent automation controls in public preview, enabling users to review suggested changes to issues before they are applied. These controls include approvals, confidence ratings, and rationale for automated actions, offering more granular control over automation levels. This feature is aimed at improving issue triage and metadata enrichment for software engineering teams, allowing them to balance automation with manual review.

    feature announcement
  • GitHub Changelog governancepreviewengineer ·

    GitHub Projects and Issues: Multi-select fields now in public preview

    GitHub has introduced multi-select fields for Projects and Issues, allowing a single field to store multiple values. This enhancement enables users to tag items with multiple categories, teams, or modules, offering more flexibility than single-select options. The feature is currently in public preview and can be tested by creating or editing a field and selecting the multi-select type. Users can then set multiple values and filter by them within project views.

    feature announcement
  • GitHub Changelog aiengineer ·

    Gemini 3.6 Flash model now available in GitHub Copilot

    GitHub Copilot is rolling out Google's Gemini 3.6 Flash model, designed for web and app development, coding, and agentic tasks. This update offers improved task completion and token efficiency over the previous Gemini 3.5 Flash. It is available to Copilot Pro, Pro+, Max, Business, and Enterprise users, with administrators needing to enable a preview policy for Business and Enterprise plans.

    feature announcement
  • GitHub Changelog aiengineer ·

    GitHub Copilot shows AI credit usage per billing cycle

    GitHub Copilot Business and Enterprise users can now track their AI credit usage directly on the Copilot usage page, regardless of whether an individual budget is set. This change provides clearer visibility into monthly token consumption, addressing a previous limitation where usage was only shown as a percentage of a budget. The updated page now reflects actual usage against the total budgeted amount or total used if no budget is configured.

    feature patch
  • GitHub Changelog aisecuritygaengineer ·

    GitHub Code Quality GA for Enterprise Cloud and Team

    GitHub Code Quality is now generally available for Enterprise Cloud and Team, offering AI-accelerated code analysis to detect maintainability and reliability issues. This feature pairs CodeQL with AI-assisted detection and Copilot Autofix, helping teams ship more trustworthy code with improved maintainability and reliability scores. New capabilities include organization-wide enablement, code coverage metrics, quality gates, and APIs, with billing commencing July 20, 2026, for active committers and AI usage.

    feature announcement

About GitHub release tracking on ReleaseBytes

The GitHub changelog covers Actions, Copilot, code security, the API and the platform itself — dozens of entries a week. ReleaseBytes summarises each changelog entry and tags breaking changes and deprecations (like Actions runner image retirements and API sunsets) so platform teams catch them before workflows break.

Frequently asked questions

How often are GitHub release notes updated on ReleaseBytes?

Continuously. ReleaseBytes monitors the official GitHub release channels around the clock and publishes a plain-English summary of each announcement shortly after it lands.

What kinds of GitHub changes does ReleaseBytes track?

New features, enhancements, bug fixes, security advisories, breaking changes, deprecations and end-of-life announcements. Every item is tagged by type so you can filter to just the changes that need action.

How can I get alerts for new GitHub releases?

Set up a free email or Slack alert filtered to GitHub, subscribe to the weekly digest, or follow the RSS feed. Teams can also install the ReleaseBytes GitHub App or connect via MCP.

Where does the GitHub release data come from?

From the official sources: GitHub changelog, platform updates, and Copilot coding-assistant releases. Every item links back to the original vendor announcement.