
GitHub has expanded its Dependabot alerts by incorporating malware advisories from the OpenSSF malicious-packages repository. This integration increases the breadth of malware data available, covering ecosystems such as npm and PyPI. Users with malware alerting enabled will automatically receive alerts for dependencies that match the expanded advisories. This update provides developers with broader security coverage, enhancing their ability to detect and address potential threats.
Read original
© GitHub ChangelogGitHub has enhanced its Copilot usage metrics API, now offering more granular insights into individual user activity within the Copilot app. Previously, Copilot app usage was only visible at an enterprise or organization level, but now it includes detailed breakdowns by feature, model, and language. This allows enterprise owners and billing managers to better understand how the Copilot app is being used, who is using it, and what it produces. The update makes it easier to compare Copilot app activity with other surfaces like IDEs and coding agents, providing a comprehensive view of AI-assisted coding within organizations.
© GitHub Changelognpm is stepping up its supply-chain security by implementing automatic malware scanning for packages at the time of publishing. This new measure introduces a short delay before packages become available, ensuring they are safe for use. Publishers of dual-use content must now declare this in their package metadata and provide a disclosure file, which may trigger additional scrutiny. This move aims to enhance security while maintaining transparency about package capabilities, although it may require developers to adjust their publishing workflows.
© GitHub ChangelogGrok 4.5, xAI's latest reasoning model, is now integrated into GitHub Copilot, enhancing its capabilities for complex coding tasks. With a massive context window of up to 500,000 tokens and support for both text and image inputs, Grok 4.5 is designed for fast, agentic coding and multi-step workflows. It excels in terminal-based coding tasks, particularly in Visual Studio Code and Copilot CLI, making it ideal for time-sensitive and complex coding challenges. This integration marks a significant step in improving the efficiency and capability of GitHub Copilot for developers.
The latest update to Claude Code, v2.1.218, introduces several improvements and fixes that enhance user experience and functionality. Notably, the /code-review feature now operates as a background subagent, preventing conversation clutter and improving workflow efficiency. The update also addresses various bugs, such as Windows path corruption and session stability issues, ensuring smoother operations. These changes make Claude Code more robust and user-friendly, particularly for developers relying on its tools for code review and management.
© Lev SelectorGoogle has launched TurboQuant, a new tool for vector compression.
The latest update to Claude Code, version 2.1.214, brings a host of fixes and enhancements aimed at improving security and functionality. Notably, it addresses permission-check bypasses in Windows PowerShell and enhances Bash permission checks to handle complex commands more securely. The update also introduces the EndConversation tool, allowing Claude to terminate sessions with abusive users, and adds new logging attributes for better message-level correlation. These changes make the platform more robust and user-friendly, particularly for developers working in complex environments.