The GitHub Blog
Blog
GitHub, Inc. is an Internet hosting service for software development and version control using Git. It provides the distributed version control of Git plus access control, bug tracking, software feature requests, task management, continuous integration, and wikis for every project. Headquartered in California, it has been a subsidiary of Microsoft since 2018. Source
Actions
Media Outlet details
| Scope | International |
|---|---|
| Language | English |
| Country | United States of America |
|
Similarweb UVM |
Request pricing |
|
Comscore UVM |
Request pricing |
Recent Articles
Search ArticlesRate limits for private vulnerability reports
Open source maintainers are receiving more low-quality and automated vulnerability reports, which can bury the reports that matter. Rate limits cap how many new reports a single account can submit in a day, both to your repository and across GitHub. This helps protect you from bulk and automated submissions, while legitimate researchers can still reach you. With this update: Private vulnerability reporting now applies daily per-user rate limits to new reports.
Structured forms for private vulnerability reports
Private vulnerability reports can now use a structured form that asks reporters for the details you need to assess a vulnerability, including a reproducible proof of concept. A single free-text box made it easy to submit low-quality or AI-generated reports and hard for you to find the signal in them. Now, by default, reporters must fill in four required fields: summary, details, proof of concept (at least 150 characters), and impact.
GitHub Copilot can now interact with desktop apps with computer use
Computer use is now available in public preview in GitHub Copilot CLI and the GitHub Copilot app on macOS and Windows. Copilot can interact with desktop applications on your behalf (e.g., reading accessible app content and visual context, clicking controls, entering and editing text, pressing keys, scrolling, dragging, and navigating workflows across applications).
GitHub Actions: macOS 14 runner image retirement
The macOS 14 runner image will be retired on November 2, 2026.
GitHub Copilot in VS Code, September 2026 releases
This changelog covers VS Code v1.136 through v1.140, shipped throughout September 2026. September’s releases streamline agent-driven development from implementation through pull request merge. Automations handle repeatable tasks, agent merge helps land changes, and improved session management keeps work organized. Agents are also more flexible across workspaces, Dev Containers, and apps, while GitHub context helps you collaborate without breaking your flow.
Accessibility statements highlighted on repository overview
You can now find an ACCESSIBILITY.md file in your repository’s root, the .github/ directory, or the docs/ directory highlighted on the repository overview. You can also add or propose an accessibility statement from a public repository’s Community Standards page. This improvement is available on all GitHub plans on github.com and will be available in GitHub Enterprise Server 3.24. For more information, see Adding an accessibility page to your repository.
Actions retention now covers checks, runs, and statuses
As previously announced, checks, workflow runs, and statuses are now governed by the same GitHub Actions retention setting that controls how long artifacts and logs are kept. These records are automatically cleaned up when they exceed the retention period configured for your enterprise, organization, or repository. This applies to checks and statuses created by GitHub Actions and third-party applications. The setting is labeled “Check, workflow run, status, artifact and log retention” in the UI.
Scheduled code scanning skips inactive repositories
Weekly scheduled scans for code scanning default setup and GitHub Code Quality now start only after a push or pull request triggers an analysis, rather than counting every kind of scan as recent activity. Previously, activity for a repository was based on any unscheduled scan, including the one-time validation scan that runs when you first enable default setup and scans triggered by a change in detected languages.
Code coverage uploads no longer fail CI for new branches
Code coverage uploads from the GitHub Code Quality upload-code-coverage action no longer fail CI when you push a branch that doesn’t yet have an open pull request. Previously, the coverage API required a pull request number for any push to a non-default branch. Since that number only exists once a pull request is open, pushing a new branch before opening a pull request caused the coverage-upload step to fail, even though nothing was actually wrong with your workflow.
Dynamic workflows in Copilot CLI and the Copilot app
Dynamic workflows are now available in Copilot CLI, the GitHub Copilot app, and the GitHub Copilot SDK. These let you define an orchestration in code to get the reliability and observability that complex, multi-agent work demands. A dynamic workflow is a program that defines how a task is carried out. It combines automated steps with the work of one or more agents, and those steps can run one after another, in parallel, or both.