
GitHub has released CodeQL 2.25.5, enhancing the static analysis engine used for code scanning. This update improves query accuracy across C/C++, Java/Kotlin, and GitHub Actions, reducing false positives and expanding detection capabilities. Notably, the update refines the identification of read-only path sinks in Java/Kotlin and adjusts the cpp/cleartext-transmission query for C/C++. GitHub Actions queries now analyze composite action metadata, providing more comprehensive security checks. These improvements are automatically deployed to GitHub code scanning users and will be included in the upcoming GitHub Enterprise Server release.
Read original
© GitHub ChangelogGitHub has introduced hard budget limits for its Advanced Security offerings, allowing enterprise administrators to prevent overspending by blocking additional license usage once a set threshold is reached. This new feature replaces the previous soft budget system, which only provided notifications without enforcing limits. The change offers enterprises greater control over their security spending, ensuring that budgets are not exceeded during processes like user onboarding. This update is particularly beneficial for organizations looking to manage costs more effectively while maintaining security standards.
© GitHub ChangelogClaude Opus 4.8, Anthropic's latest model, is now part of GitHub Copilot, bringing a notable leap in code comprehension and generation. This model excels in tackling intricate problem-solving and efficiently navigating extensive codebases, surpassing previous iterations. Available to Copilot Pro+, Business, and Enterprise users, it can be accessed through Visual Studio Code, JetBrains, and GitHub Mobile, among others. The gradual rollout means some users might need to wait a bit longer to access it. This integration is set to significantly enhance the coding workflow for developers leveraging GitHub Copilot.
© GitHub ChangelogGitHub's Copilot Memory is refining its control features, offering users more precise management over memory deletion and scope. With a new repository-level off switch, admins can now disable Copilot Memory for specific repositories, ensuring repository-level facts are not stored or read. The Copilot CLI has been updated to allow users to enable or disable memory and check its status with simple commands. These enhancements aim to give users and admins greater control over how Copilot Memory functions, making it more adaptable to individual and organizational needs.
The latest update to Claude Code, version 2.1.153, introduces several enhancements and fixes that improve user experience and functionality. Notably, the update adds a skipLfs option to the GitHub plugin marketplace, allowing users to bypass Git LFS downloads, and enhances the autocomplete feature for Claude agents. Additionally, it addresses various bugs, including memory usage issues and installation errors on Windows. These changes streamline operations and ensure smoother interactions with the platform, particularly for developers using Claude Code in complex environments.
The latest update to Claude Code, version 2.1.154, introduces several enhancements aimed at improving task management and efficiency. Notably, the new dynamic workflows feature allows users to orchestrate complex tasks across multiple agents, making it easier to handle larger projects. The update also brings cost-effective fast mode on Opus 4.8, offering increased speed at a reduced rate. Additionally, the release refines the system's decision-making process by reserving multiple-choice prompts for genuinely uncertain situations. These changes collectively enhance the platform's usability and performance, particularly for developers managing intricate workflows.
Claude Code's latest update, v2.1.152, introduces several enhancements and bug fixes aimed at improving user experience and functionality. Notably, the /code-review --fix command now automatically applies review findings, enhancing code efficiency and reuse. The update also allows for dynamic skill management with the /reload-skills command, enabling seamless integration of new skills without restarting sessions. Additionally, the update addresses various bugs, such as terminal styling issues and plugin management errors, ensuring smoother operation. These changes collectively enhance the robustness and usability of Claude Code for developers.