GitHub Releases

GitHub changelog, platform updates, and Copilot coding-assistant releases. New features, breaking changes, security advisories and deprecations - each summarised in plain English and updated continuously.

Tracking 199 GitHub releases · Updated

  • GitHub Changelog aideprecationengineer ·

    GitHub Copilot Deprecates Gemini 2.5 Pro and 3 Flash Models

    GitHub Copilot is deprecating Gemini 2.5 Pro and Gemini 3 Flash models as of July 31, 2026. This change affects all Copilot experiences, including chat and code completions. Users are advised to update workflows to supported alternatives like Gemini 3.1 Pro and 3.6 Flash, with administrators needing to enable these via Copilot settings.

    deprecation
  • GitHub Changelog aiawspreviewengineer ·

    GitHub Copilot Enterprise Teams Model Policy Targeting in Public Preview

    GitHub Copilot Enterprise customers with Copilot Business or Enterprise licenses can now use user-based model policy targeting in public preview. This feature allows AI administrators to set baseline models for the enterprise and grant additional models to specific teams, enabling finer-grained control mapped to job roles or experimentation. Access begins rolling out on August 3rd, with opt-in available through an Enterprise teams mode toggle.

    feature announcement
  • GitHub Changelog securitygovernanceengineer ·

    npm restricts granular access token ability to bypass 2FA for sensitive actions

    npm granular access tokens (GATs) configured to bypass two-factor authentication (2FA) can no longer perform sensitive account, organization, and package management actions. This change closes a significant attack vector where leaked tokens could be used for account takeovers. The restriction impacts only npm granular access tokens and requires users to perform these actions interactively with a 2FA challenge.

    security patch
  • GitHub Changelog aideprecationengineer ·

    GitHub Models officially retired

    GitHub Models has been officially retired as of July 30, 2026, making its playground, catalog, and APIs unavailable. Existing customers with active usage are impacted. For AI model access, Microsoft Foundry and GitHub Copilot are recommended alternatives. Further details are available in the documentation and community forums.

    deprecation
  • GitHub Changelog infrapreviewengineer ·

    GitHub Stacked Pull Requests Enter Public Preview

    GitHub has launched Stacked Pull Requests in public preview, allowing engineers to break large changes into smaller, ordered, and reviewable pull requests. This feature aims to improve the review process for substantial code modifications, making it easier to maintain quality and speed up delivery. The preview is rolling out to all repositories, with merge queue support coming soon.

    feature announcement
  • GitHub Changelog aiazurepreviewengineer ·

    GitHub Copilot Visual Studio Update Adds New Agent, Skills, Code Review

    GitHub Copilot for Visual Studio has released an update introducing a new agent in public preview, built-in expertise from .NET and Azure teams, and enhanced code review capabilities. This update aims to improve developer productivity by offering more tailored assistance and streamlined workflows. The new agent and skills are available to all plans, while organization-level custom instructions require a Business or Enterprise subscription.

    feature announcement
  • GitHub Changelog aigaengineer ·

    GitHub Copilot: Default Model Enablement for Business and Enterprise Plans

    GitHub is rolling out a global default enablement policy for generally available Copilot models on Business and Enterprise plans. This change aims to simplify management by automatically enabling new models, requiring only an opt-out for organizations needing stricter governance. Admins have 28 days to configure this new policy before it takes effect on August 26, after which models not explicitly configured will follow the default setting unless manually overridden.

    feature announcement
  • GitHub Changelog securityengineermedia ·

    npm Adds Publish-Time Malware Scanning and Dual-Use Metadata

    npm now automatically scans packages for malware at publish time, introducing a brief delay before packages are available. This enhances supply-chain security for all users but may require automation updates to tolerate the delay. A new metadata requirement, `contentPolicy` in `package.json` and a `DISCLOSURE` file, is introduced for dual-use content to aid automated scanning and manual review. Publishers of dual-use packages must also enforce two-factor authentication during publishing.

    feature security
  • GitHub Changelog aiengineer ·

    Grok 4.5 reasoning model available in GitHub Copilot

    Grok 4.5, xAI's latest reasoning model, is now rolling out in GitHub Copilot for various SKUs, offering fast, agentic coding with a 500,000 token context window. It supports text and image inputs and is designed for complex, time-sensitive workflows, showing strong performance in internal testing. Administrators must enable the Grok 4.5 policy, which is off by default, to access this model.

    feature announcement
  • GitHub Changelog securityinfraengineer ·

    GitHub Actions holds workflows for approval to prevent attacks

    GitHub Actions now automatically holds potentially malicious workflows for approval before execution to prevent supply chain attacks. This measure requires a repository collaborator with write access to review and approve the workflow run through an authenticated web session. This protection is active for public repositories on GitHub.com and is not configurable by users. GitHub Enterprise Server is not affected by this change.

    security announcement
  • GitHub Changelog securitygaengineer ·

    Dependabot alerts expand to cover malicious packages from OpenSSF

    GitHub's Dependabot alerts now incorporate malware advisories from the OpenSSF malicious-packages repository, broadening detection across ecosystems like npm and PyPI. This enhancement means users with malware alerting enabled will automatically benefit from expanded coverage, identifying risks from newly published malicious packages. To leverage this, users can enable malware alerting in repository settings or browse advisories directly on GitHub.

    feature announcement
  • GitHub Changelog securityinfraengineer ·

    GitHub Actions holds potentially malicious workflows for approval

    GitHub Actions now holds certain workflow runs for approval to protect public repositories from supply chain attacks. This feature automatically prevents malicious workflows from executing until a collaborator with write access reviews and approves them via an authenticated web session. This protection is applied automatically and currently only affects public repositories on github.com, not GitHub Enterprise Server.

    security announcement
  • GitHub Changelog aiengineer ·

    Claude Opus 5 model now available in GitHub Copilot

    GitHub Copilot now supports Anthropic's Claude Opus 5, designed for complex coding tasks requiring multi-step reasoning and tool use. This new model enhances performance on agentic workflows and includes improved safeguards for cyber content, though these may occasionally block security-related requests. It's available to specific Copilot plan users, with gradual rollout and administrator policy enablement required.

    feature announcement
  • GitHub Changelog aigaengineer ·

    GitHub Copilot cloud agent for Linear now generally available

    GitHub Copilot cloud agent for Linear is now generally available, allowing users to assign issues directly to Copilot for automated pull request creation and progress tracking within Linear. This feature enhances developer workflows by automating coding tasks and integrating directly with issue tracking. It is available for Copilot Pro, Pro+, Business, and Enterprise users, requiring specific GitHub and Linear administrative permissions to set up.

    feature announcement
  • GitHub Changelog aipreviewengineer ·

    GitHub Issues public preview adds agent automation controls

    GitHub Issues is introducing agent automation controls in public preview, enabling users to review suggested changes to issues before they are applied. These controls include approvals, confidence ratings, and rationale for automated actions, offering more granular control over automation levels. This feature is aimed at improving issue triage and metadata enrichment for software engineering teams, allowing them to balance automation with manual review.

    feature announcement
  • GitHub Changelog governancepreviewengineer ·

    GitHub Projects and Issues: Multi-select fields now in public preview

    GitHub has introduced multi-select fields for Projects and Issues, allowing a single field to store multiple values. This enhancement enables users to tag items with multiple categories, teams, or modules, offering more flexibility than single-select options. The feature is currently in public preview and can be tested by creating or editing a field and selecting the multi-select type. Users can then set multiple values and filter by them within project views.

    feature announcement
  • GitHub Changelog governanceinfraengineer ·

    GHES appliance update required for support bundle uploads

    GitHub Enterprise Server (GHES) will reject command-line support bundle uploads from unpatched appliances starting August 18, 2026. This change impacts users submitting support bundles via specific command-line tools. To avoid disruption, administrators must update their GHES instances to the latest available patch release for their version line or contact GitHub Support if an update is not feasible by the deadline.

    security deprecation
  • GitHub Changelog aiengineer ·

    Gemini 3.6 Flash model now available in GitHub Copilot

    GitHub Copilot is rolling out Google's Gemini 3.6 Flash model, designed for web and app development, coding, and agentic tasks. This update offers improved task completion and token efficiency over the previous Gemini 3.5 Flash. It is available to Copilot Pro, Pro+, Max, Business, and Enterprise users, with administrators needing to enable a preview policy for Business and Enterprise plans.

    feature announcement
  • GitHub Changelog aisecuritygaengineer ·

    GitHub Code Quality GA for Enterprise Cloud and Team

    GitHub Code Quality is now generally available for Enterprise Cloud and Team, offering AI-accelerated code analysis to detect maintainability and reliability issues. This feature pairs CodeQL with AI-assisted detection and Copilot Autofix, helping teams ship more trustworthy code with improved maintainability and reliability scores. New capabilities include organization-wide enablement, code coverage metrics, quality gates, and APIs, with billing commencing July 20, 2026, for active committers and AI usage.

    feature announcement
  • GitHub Changelog aigaengineer ·

    GitHub Copilot repository-level usage metrics now generally available

    GitHub Copilot usage metrics are now available at the repository level via new REST API endpoints for enterprise and organization reports. This allows teams to track Copilot's impact on pull request activity directly within specific codebases. The feature is for enterprise owners, organization owners, and users with specific permissions, provided Copilot usage metrics are enabled.

    feature announcement

About GitHub release tracking on ReleaseBytes

The GitHub changelog covers Actions, Copilot, code security, the API and the platform itself — dozens of entries a week. ReleaseBytes summarises each changelog entry and tags breaking changes and deprecations (like Actions runner image retirements and API sunsets) so platform teams catch them before workflows break.

Frequently asked questions

How often are GitHub release notes updated on ReleaseBytes?

Continuously. ReleaseBytes monitors the official GitHub release channels around the clock and publishes a plain-English summary of each announcement shortly after it lands.

What kinds of GitHub changes does ReleaseBytes track?

New features, enhancements, bug fixes, security advisories, breaking changes, deprecations and end-of-life announcements. Every item is tagged by type so you can filter to just the changes that need action.

How can I get alerts for new GitHub releases?

Set up a free email or Slack alert filtered to GitHub, subscribe to the weekly digest, or follow the RSS feed. Teams can also install the ReleaseBytes GitHub App or connect via MCP.

Where does the GitHub release data come from?

From the official sources: GitHub changelog, platform updates, and Copilot coding-assistant releases. Every item links back to the original vendor announcement.