
GitHub has released CodeQL 2.25.4, enhancing its static analysis engine used for code scanning. This update introduces support for Swift 6.3.1 and improves C# analysis by expanding ASP.NET source modeling. Java and Kotlin benefit from reduced false positives through better path normalization and sensitive data handling. Additionally, the update extends security analysis to Vercel serverless functions, enhancing vulnerability detection. These improvements make CodeQL a more comprehensive tool for developers aiming to enhance code security and quality.
Read original
© GitHub ChangelogGitHub has expanded its Copilot code review capabilities, making agent skills and MCP server integration available to Pro, Business, and Enterprise users. These features allow teams to embed their internal tools and coding standards directly into the code review process, providing more tailored and context-rich reviews. By linking to third-party platforms like issue trackers and documentation systems, Copilot can draw in relevant information to enhance the review process. This update marks a significant advancement in AI-assisted code reviews, offering a more customized and informed approach for development teams using GitHub.
© GitHub ChangelogGitHub is making it easier for Business and Enterprise users to access new Copilot models by implementing a default enablement policy. This change means that new models will automatically be available unless administrators decide to opt out, reducing the need for manual activation. The policy will be effective from August 26, giving organizations a 28-day period to adjust their settings if they prefer manual control. This approach minimizes the administrative workload and ensures users can quickly benefit from the latest AI advancements, while still allowing organizations to maintain oversight by opting out if necessary.
© GitHub ChangelogThe latest update to CodeQL, version 2.26.1, brings significant improvements to the static analysis engine used in GitHub code scanning. This release enhances framework coverage for languages like Go, Java/Kotlin, and JavaScript/TypeScript, while also reducing false positives in Rust analysis. Notably, it introduces better modeling for Go's structured logging and recognizes Angular decorators in JavaScript/TypeScript. These updates mean developers can expect more accurate security issue detection and remediation, making CodeQL a more reliable tool for maintaining secure codebases.
© Matt WolfeAnthropic has introduced a sandboxed in-app browser for Claude Code on desktop, enhancing its research and debugging capabilities.
The latest update to Claude Code, v2.1.218, introduces several improvements and fixes that enhance user experience and functionality. Notably, the /code-review feature now operates as a background subagent, preventing conversation clutter and improving workflow efficiency. The update also addresses various bugs, such as Windows path corruption and session stability issues, ensuring smoother operations. These changes make Claude Code more robust and user-friendly, particularly for developers relying on its tools for code review and management.
© Lev SelectorGoogle has launched TurboQuant, a new tool for vector compression.