GitHub
2026-09-16
AI Scan for pull requests can now find security vulnerabilities even when CodeQL default setup is not enabled on a repository. Previously, AI Scan for pull requests required CodeQL default setup.
2026-09-15
GitHub has completed the scheduled sunset of SHA-1 for HTTPS on github.com and partner services. SHA-1 is now disabled for HTTPS connections.
2026-09-11
GitHub profiles now display the highest tier earned for achievements that have multiple levels. Before this change, profiles could show the first tier earned even after a user progressed further.
Copilot code review now auto-resolves its own comments after you address them, and it can generate commit messages when you apply its code suggestions. The update also includes behind-the-scenes analysis changes.
2026-09-10
GitHub is previewing a refreshed repository-level pull request listing page for all users. The update adds stronger filtering and a compact presentation mode.
GitHub code scanning’s AI Scan for pull request feature can now be enabled and managed via REST API at both the organization and repository levels. The APIs are in public preview.
2026-09-09
CodeQL 2.27.0 is available on Linux ARM64. The release also adds a new Rust security query, expands framework coverage for Java/Kotlin and C#, and includes analysis accuracy improvements across multiple languages.
GitHub added a repository ruleset capability to prevent pull requests from merging when they introduce exposed secrets. This extends rulesets as a repository-wide protection mechanism.
GitHub added agentic autofix for Code Quality findings, allowing users to select and assign up to 25 standard findings at once for automated remediation. The feature is aimed at reducing backlog items in code quality reports.
2026-09-08
GitHub moved and redesigned its support portal to help.github.com. The new portal combines support, documentation, learning, community, account resources, and Copilot-powered search in one place.
2026-09-04
GitHub added a new REST API endpoint for repository star history that lets users track star growth over time without exposing individual stargazer identities. This follows earlier restrictions on stargazer listing endpoints to admins and collaborators.
2026-09-03
GitHub says three npm publishing updates are now generally available, including support for multiple trusted publishing configurations per package. The post also mentions staged publishing and another publishing-related change, but the provided excerpt does not include the full details.