Explore GitHub’s latest transparency data and learn more about policy updates affecting developers and open source.
The post Developer policy update: Transparency, state policy, and what’s ahead appeared first on The GitHub Blog.
A look at the targeted AI taskflows behind these findings, the critical Android bugs they uncovered, and how to run the same open-source agent on your own app.
The post How we found 24 Android vulnerabilities using our open source AI security agent appeared first on The GitHub Blog.
The open source Git project just released Git 2.56. Here is GitHub's look at some of the most interesting features and changes introduced since last time.
The post Highlights from Git 2.56 appeared first on The GitHub Blog.
Describe the interface you need in plain English, then let the agent build a live surface you can both use and update—so you spend less time adapting to tools and more time getting work done.
The post GitHub Copilot app for Beginners: How to build custom workflows with canvases appeared first on The GitHub Blog.
What is a developer to do when they need something more tangible than a chat box? Enter canvases.
The post When chat is the wrong UI appeared first on The GitHub Blog.
In this blog post, I explain how to use the new fuzzing taskflow based on the GitHub Security Lab Taskflow Agent AI framework.
The post AI-powered fuzzing with the GitHub Security Lab Taskflow Agent appeared first on The GitHub Blog.
How we rebuilt the diff surface in the GitHub Copilot app to open a million-line pull request with hundreds of inline review comments.
The post Rendering huge pull requests in the GitHub Copilot app appeared first on The GitHub Blog.
New research from GitHub and Yale Program on Climate Change Communication finds strong demand for tools, measurement, and practical guidance that can help developers reduce wasted compute.
The post Developers want more efficient software. Here’s what over 1000 GitHub users told us they need. appeared first on The GitHub Blog.
We dive into these questions and other AI hot takes on the latest episode of the GitHub Podcast.
The post Should you read the code, is RAG dead, and did Skills kill MCP? appeared first on The GitHub Blog.
A rewrite this size wasn't affordable before agents. Here's what porting the Copilot agent runtime to 800,000 lines of production Rust actually took.
The post Migrating the GitHub Copilot runtime to Rust, using Copilot appeared first on The GitHub Blog.
If you can write down how you do your work, you can automate it. Here's what I did to support GitHub's APAC marketing team.
The post Marketing ops as code: Automating events from planning to follow-up on GitHub appeared first on The GitHub Blog.
Checking agent-generated code usually means hopping between tabs. Learn how to view diffs, run terminal commands, and preview web apps side by side in the GitHub Copilot app.
The post GitHub Copilot app for Beginners: Using the diff, terminal, and browser appeared first on The GitHub Blog.
In August, we experienced five incidents that resulted in degraded performance across GitHub services.
The post GitHub availability report: August 2026 appeared first on The GitHub Blog.
In controlled offline evaluations, HydraFusion’s selective coding workflows matched or exceeded the evaluated Opus 5 baseline while reducing estimated workflow cost. Now available as a research preview in GitHub Copilot.
The post Project HydraFusion: Frontier quality via multi-model orchestration appeared first on The GitHub Blog.
Learn how to run parallel agents in the GitHub Copilot app, and experience the moment it stops feeling scary and starts feeling powerful.
The post GitHub Copilot app for Beginners: Run several agents at once appeared first on The GitHub Blog.
From loop engineering to harnesses, squads, and open weights, the GitHub Podcast breaks down the AI terms showing up in developer conversations.
The post Decoding the new AI lingo: Loops, harnesses, squads, hill climbing… oh my! appeared first on The GitHub Blog.
Why shorter outputs can cost more, and how GitHub Copilot reduces wasted work across the complete coding task.
The post How we make AI coding more cost efficient without sacrificing task quality appeared first on The GitHub Blog.
OpenClaw is the fastest-growing project in GitHub history. Peter Steinberger and several maintainers share what they learned in the project's first six months.
The post OpenClaw went viral. Meet the maintainers building and securing it. appeared first on The GitHub Blog.
Managing library updates can be tedious at times. Learn how the GitHub Copilot app can handle this type of repetitive task.
The post GitHub Copilot app for Beginners: Automate Dependabot pull request triage appeared first on The GitHub Blog.
These are the lessons we learned evaluating LLMs for real-world secret scanning.
The post How to evaluate LLMs before production appeared first on The GitHub Blog.
We built a plugin for the GitHub Accessibility Scanner to make sure your alt text is actually accessible. Here's how it works.
The post Your alt text passes automated checks. That doesn’t mean it’s any good. appeared first on The GitHub Blog.
An update on the August 17 outage and the steps we're taking to improve reliability.
The post The August 17 outage, and the work ahead appeared first on The GitHub Blog.
If you’re juggling multiple Copilot sessions, use the My work pane to track what's in flight, what's done, and what's next.
The post GitHub Copilot app for Beginners: Managing your work appeared first on The GitHub Blog.
Chat is great for intent, but agent work gets lost in the scroll. Here is how I use canvases with my agentic workflows—and why your workflow also deserves a canvas.
The post How canvases make agentic workflows visible, steerable, and cost-efficient appeared first on The GitHub Blog.
See how four GitHub agent apps can help you scope, secure, roll out, and ship a feature across the SDLC–all without leaving GitHub.
The post How to bring your software delivery workflow into GitHub with agent apps appeared first on The GitHub Blog.
The GitHub Universe session catalog is live. Explore interactive workshops, community talks, demos, and panels. Plus, register before August 19 to save $300.
The post Your guide to GitHub Universe 2026 is here: The schedule just launched! appeared first on The GitHub Blog.
See how the open source projects in Session 4 of the GitHub Secure Open Source Fund combined AI-assisted workflows, maintainer expertise, GitHub security tools, expert guidance, and funding to improve project security.
The post What 50 open source projects taught us about security in the AI era appeared first on The GitHub Blog.
In July, we experienced eight incidents that resulted in degraded performance across GitHub services.
The post GitHub availability report: July 2026 appeared first on The GitHub Blog.
Learn how to write your first prompt in the GitHub Copilot app, choose the right context and model, and start your first task with confidence.
The post Write your first prompt with the GitHub Copilot app appeared first on The GitHub Blog.
AI contributors are already in your queue. AutoGPT maintainer Nicholas Tindle shares the repo instructions, gates, and boundaries that keep maintainers in control.
The post Your contributors are AI-first now. Is your project? appeared first on The GitHub Blog.
Developers are owning more of the delivery system around code, not just code itself. Join us during GitHub Universe to meet other devs, learn something new, and explore what's next.
The post From coder to orchestrator: How agents shift the role of a developer appeared first on The GitHub Blog.
Enterprise Java developers have a new superpower—drive GitHub Copilot from idiomatic Java code with annotations, virtual threads, and more.
The post Using the GitHub Copilot SDK for Java appeared first on The GitHub Blog.
Go beyond chat in the GitHub Copilot app with these slash commands. They'll help you plan, collaborate, automate, and customize your dev workflow.
The post A guide to slash commands in the GitHub Copilot app appeared first on The GitHub Blog.
GitHub malware advisories no longer stop at npm. Here's how we wired OpenSSF's malicious-packages data into the Advisory Database, and why we built the pipeline paranoid.
The post How we took malware advisories beyond npm appeared first on The GitHub Blog.
Learn how to build tools to simplify how you work—without writing a single line of code.
The post How the GitHub legal team used Copilot CLI to streamline their workflows appeared first on The GitHub Blog.
Instead of one huge, un-reviewable pull request, teach coding agents to decompose work into a clean, ordered stack with GitHub stacked pull requests.
The post Turn one giant AI-generated pull request to a reviewable stack appeared first on The GitHub Blog.
How a branch-free loop and byte-space arithmetic let GitHub case-fold every byte of code search at >45 GiB/s on a single core.
The post Don’t stop early: Case-folding source code at memory speed appeared first on The GitHub Blog.
Learn how I modernized an old codebase of mine using stacked sessions and pull requests in the GitHub Copilot app.
The post Stacked sessions and pull requests in the GitHub Copilot app appeared first on The GitHub Blog.
Dependabot keeps your dependencies current, but its defaults can flood your repository with pull requests. Here's how grouping updates, slowing the cadence, and keeping security fixes fast cut the noise on a Microsoft open source project.
The post Tame Dependabot: Group your updates, slow the cadence, keep security fast appeared first on The GitHub Blog.
Explore the changes we've shipped across npm and GitHub Actions over the past few months to disrupt supply chain attack techniques and limit their impact.
The post Disrupting supply chain attacks on npm and GitHub Actions appeared first on The GitHub Blog.
A practical GitHub Copilot workflow for prototyping, planning, implementing, and reviewing software without chasing every new AI tool.
The post The harness is all you need (mostly) appeared first on The GitHub Blog.
New to the GitHub Copilot app? Learn how to start projects, work with AI agents, explore canvases, and streamline your development workflow.
The post GitHub Copilot app for Beginners: Getting started appeared first on The GitHub Blog.
A new default three-day cooldown delays version update pull requests so maintainers and security researchers can address findings in a release before it gets into your code.
The post The case for a cooldown: Why Dependabot now waits before issuing version updates appeared first on The GitHub Blog.
Copilot now bills usage at listed API rates. Compare direct model access with the coding workflow, policy, and harness work around it.
The post Copilot vs. raw API access: What are you actually paying for? appeared first on The GitHub Blog.
GitHub is making some significant changes to its bug bounty program, shifting its focus to give researchers a better experience working with the GitHub team.
The post Next chapter: Restructuring GitHub’s bug bounty program appeared first on The GitHub Blog.
Canvases turn AI into interactive workspaces where you can visualize information, explore workflows, and take action across complex tasks.
The post How to build interactive experiences with canvases appeared first on The GitHub Blog.
Celebrating $100 million contributed by the community to the people who build and sustain open source every day.
The post $100 million for open source: A milestone built by the community appeared first on The GitHub Blog.
The cost of writing code dropped; the cost of owning it didn't. A framework for deciding which changes are actually cheap in the AI era.
The post The cost of saying yes has changed appeared first on The GitHub Blog.
New to GitHub? This beginner's guide explains version control, repositories, and pull requests—plus everything else you need to start working confidently on GitHub.
The post GitHub for Beginners: Your roadmap to mastering the GitHub essentials appeared first on The GitHub Blog.
How migrating Copilot code review to shared Unix-style code exploration tools reduced review cost by reshaping agent workflows around pull request evidence.
The post Better tools made Copilot code review worse. Here’s how we actually improved it. appeared first on The GitHub Blog.
GitHub had over 14,000 repositories. Fewer than half had clear ownership. Here's how we gave every active repository a validated owner in under 45 days, archived the rest, and made ownership the foundation for everything that followed.
The post How GitHub gave every repository a durable owner appeared first on The GitHub Blog.
Explore how the Aspire team turns merged product changes into SME-reviewed docs pull requests, closing the gap between release and documentation.
The post Automating cross-repo documentation with GitHub Agentic Workflows appeared first on The GitHub Blog.
In June, we experienced six incidents that resulted in degraded performance across GitHub services.
The post GitHub availability report: June 2026 appeared first on The GitHub Blog.
Go from an empty repository to a live custom domain with HTTPS in about 14 minutes, without manually editing a single DNS record.
The post How GitHub Copilot enables zero DNS configuration for GitHub Pages appeared first on The GitHub Blog.
New Innovation Graph data shows global developer communities growing faster than ever, with collaboration reaching new highs across many economies.
The post Q1 2026 Innovation Graph update: Open source collaboration is accelerating worldwide appeared first on The GitHub Blog.
GitHub had 20,000+ secret scanning alerts across 15,000 repositories. Here's how we separated signal from noise, built remediation workflows, and reached inbox zero in nine months.
The post How GitHub used secret scanning to reach inbox zero appeared first on The GitHub Blog.
These six free settings will not make your project unhackable. Nothing will. What they will do is close the easy doors. Turn these on, and your project will be meaningfully harder to attack than it was before.
The post 6 security settings every GitHub maintainer should enable this week appeared first on The GitHub Blog.
Explore how the Open Source Program Office uses GitHub’s new license compliance product to manage open source dependencies at scale.
The post How GitHub maintains compliance for open source dependencies appeared first on The GitHub Blog.
The open source Git project just released Git 2.55. Here is GitHub’s look at some of the most interesting features and changes introduced since last time.
The post Highlights from Git 2.55 appeared first on The GitHub Blog.
The GitHub Advisory Database is processing more vulnerability reports than ever before. Here's what's driving the surge, how we're responding, and how the community can help.
The post Inside the Advisory Database and what happens when vulnerability volume breaks records appeared first on The GitHub Blog.
GitHub joined the United Nations Development Programme in Ghana to explore how open source governance can support one of West Africa's most ambitious digital reform efforts.
The post GitHub and UNDP team up to advance development priorities in Ghana with open source appeared first on The GitHub Blog.
Explore how the GitHub Copilot agentic harness delivers strong results across multiple benchmarks and leading token efficiency, while maintaining flexibility to choose among more than 20 models.
The post Evaluating performance and efficiency of the GitHub Copilot agentic harness across models and tasks appeared first on The GitHub Blog.
Explore how my day as a senior leader looks now that I use 40 automations to help, and learn more about some of my favorites.
The post I automated my job (and it made me a better leader) appeared first on The GitHub Blog.
We’re calling for targeted amendments to resolve conflicts with open source licensing and align with international transparency frameworks while preserving regulatory intent.
The post GitHub joins coalition advocating for fixes to California AI Transparency Act to protect open source appeared first on The GitHub Blog.
Learn about the progress we’ve made toward our accessibility goals and how you can help make open source more inclusive.
The post From pledge to practice: Building a more inclusive open source ecosystem appeared first on The GitHub Blog.
Qubot, our internal Copilot-powered analytics agent, allows any GitHub employee to ask questions about our data in plain language. Here's what we learned as we built it.
The post How we built an internal data analytics agent appeared first on The GitHub Blog.
Learn how pull request limits can help manage contribution volume in your repositories, and see what’s next on the roadmap.
The post How pull request limits are cutting down the noise appeared first on The GitHub Blog.
How GitHub Copilot is making more of each session go toward useful work, so your credits go further.
The post Getting more from each token: How Copilot improves context handling and model routing appeared first on The GitHub Blog.
Git worktrees have been around since 2015, but it wasn't until recently they became popular. Learn what they are, how to use them, and why you might.
The post What are git worktrees, and why should I use them? appeared first on The GitHub Blog.
GitHub Copilot CLI for Beginners: Learn how to use slash commands to control your terminal AI agent.
The post GitHub Copilot CLI for Beginners: Overview of common slash commands appeared first on The GitHub Blog.
A new repository-level dataset, published on GitHub under CC0-1.0, helps researchers and developers discover multilingual developer content across READMEs, issues, and pull requests.
The post Accelerating researchers and developers building multilingual AI with a new open dataset appeared first on The GitHub Blog.
Better orchestration, fewer handoffs, faster progress, without a single new knob.
The post How we made GitHub Copilot CLI more selective about delegation appeared first on The GitHub Blog.
In May, we experienced nine incidents that resulted in degraded performance across GitHub services.
The post GitHub availability report: May 2026 appeared first on The GitHub Blog.
Alerts are more trustworthy and actionable when noise is reduced. See how we improved the verification step with context-aware LLM reasoning.
The post Making secret scanning more trustworthy: Reducing false positives at scale appeared first on The GitHub Blog.
Install and configure LSP servers for GitHub Copilot CLI, replacing brute-force grep/decompile with real code intelligence.
The post Give GitHub Copilot CLI real code intelligence with language servers appeared first on The GitHub Blog.
Custom agents let GitHub Copilot CLI understand your stack and team workflows, turning one-off terminal prompts into repeatable, reviewable processes.
The post From one-off prompts to workflows: How to use custom agents in GitHub Copilot CLI appeared first on The GitHub Blog.
Find the answers to some of the most common GitHub-related questions.
The post GitHub for Beginners: Answers to some common questions appeared first on The GitHub Blog.
GitHub Universe is back: returning to the historic Fort Mason Center in San Francisco on October 28–29, 2026.
The post GitHub Universe is back: All together now, in the agentic era appeared first on The GitHub Blog.
At Microsoft Build 2026, GitHub introduced new tools, updates, and surfaces so agents can work the way you already work.
The post GitHub Copilot app: The agent-native desktop experience appeared first on The GitHub Blog.
The ESC collection lets you escape the confines of your desk and get out into the sun where good ideas are bound to happen.
The post Still a developer. Just outside. Our latest GitHub Shop collection is here. appeared first on The GitHub Blog.
Discover how to use VS Code to interact with GitHub and maintain your projects.
The post GitHub for Beginners: Getting started with Git and GitHub in VS Code appeared first on The GitHub Blog.
We are committed to empowering every developer by building an open, secure, and AI-powered platform that defines the future of software development.
The post GitHub recognized as a Leader in the Gartner® Magic Quadrant™ for Enterprise AI Coding Agents for the third year in a row appeared first on The GitHub Blog.
Check out these 10 open source tools that help game developers create art, animation, levels, audio, dialogue, debug UIs, and engine-ready assets.
The post Beyond the engine: 10 open source projects shaping how games actually get made appeared first on The GitHub Blog.
Explore our update on GitHub’s accessibility strategy, and learn how you can join us in building a culture of accessibility.
The post Building GitHub’s next chapter in accessibility appeared first on The GitHub Blog.
If any impact is discovered, customers will be notified via established incident response and notification channels.
The post Investigating unauthorized access to GitHub’s internal repositories appeared first on The GitHub Blog.
Kick off work in VS Code or the CLI, finish it from your phone. Remote control for GitHub Copilot sessions is now generally available on github.com and GitHub Mobile.
The post Take your local GitHub sessions anywhere appeared first on The GitHub Blog.
Learn about the experimental general-purpose accessibility agent that GitHub is piloting.
The post Building a general-purpose accessibility agent—and what we learned in the process appeared first on The GitHub Blog.
We're updating our bug bounty program standards to prioritize quality submissions, clarify shared responsibility boundaries, and evolve how we reward low-risk findings.
The post Raising the bar: Quality, shared responsibility, and the future of GitHub’s bug bounty program appeared first on The GitHub Blog.
In April, we experienced 10 incidents that resulted in degraded performance across GitHub services.
The post GitHub availability report: April 2026 appeared first on The GitHub Blog.
How the GitHub Issues team used client-side caching, smart prefetching, and service workers to make navigation feel instant.
The post From latency to instant: Modernizing GitHub Issues navigation performance appeared first on The GitHub Blog.
Roguelikes don’t die. They fork, mutate, get argued over, rewritten, abandoned, and revived again. Sometimes all at once.
The post Dungeons & Desktops: 10 roguelikes that never die (because their communities won’t let them) appeared first on The GitHub Blog.
Starting June 1, our lineup of individual plans will update based on your feedback.
The post GitHub Copilot individual plans: Introducing flex allotments in Pro and Pro+, and a new Max plan appeared first on The GitHub Blog.
Learn how one Hubber used GitHub Copilot CLI to build an extension that turns any codebase into a unique, roguelike dungeon.
The post Dungeons & Desktops: Building a procedurally generated roguelike with GitHub Copilot CLI appeared first on The GitHub Blog.
Learn how to find opportunities to contribute to the open source community.
The post GitHub for Beginners: Getting started with OSS contributions appeared first on The GitHub Blog.
Youth safety requirements are moving down the tech stack to operating systems and app stores—raising new questions for open source developers.
The post Why age assurance laws matter for developers appeared first on The GitHub Blog.
Researchers share in an interview how they used GitHub data to predict GDP, inequality, and emissions in ways that traditional economic data misses, along with our Q4 2025 data release.
The post How researchers are using GitHub Innovation Graph data to reveal the “digital complexity” of nations appeared first on The GitHub Blog.
Agentic workflows that run on every pull request can quietly accumulate large API bills. Here's how we instrumented our own production workflows, found the inefficiencies, and built agents to fix them.
The post Improving token efficiency in GitHub Agentic Workflows appeared first on The GitHub Blog.
A practical guide to reviewing agent-generated pull requests: what to look for, where issues hide, and how to catch technical debt before it ships.
The post Agent pull requests are everywhere. Here’s how to review them. appeared first on The GitHub Blog.