
GitHub has released CodeQL 2.26.2, enhancing its static analysis tool with support for Swift 6.3.3 and Kotlin 2.4.10. This update improves the accuracy of security queries related to path injection and URL redirection, offering developers more precise vulnerability detection. The changes are automatically deployed to GitHub code scanning users, with future inclusion in GitHub Enterprise Server releases. These enhancements aim to bolster security analysis for developers using these programming languages.
Read original
© GitHub ChangelogGitHub has introduced a new feature that allows developers to apply custom configuration files to the CodeQL code scanning setup, enhancing security analysis across repositories. This update provides granular control over security scans without the need to maintain separate GitHub Actions workflows for each repository. Organizations can now centralize their security configurations, ensuring consistency while allowing flexibility for individual repositories to tailor settings as needed. This feature is now available on GitHub.com and will be included in GitHub Enterprise Server 3.23, marking a significant step in scalable security management.
© GitHub ChangelogGitHub is phasing out GitHub Spark by August 2026, marking a shift towards more integrated development workflows. This decision aligns with the increasing developer preference for tools like GitHub Copilot, which seamlessly integrate with environments such as VS Code and Copilot CLI. While existing Spark applications will remain operational, the platform will stop accepting new users and app creations from August 4, 2026. Developers using Spark's llm() function must transition to other inference providers, as GitHub Models has already been retired. This change reflects GitHub's strategy to enhance developer experiences by focusing on cohesive toolsets that streamline the development process.
© GitHub ChangelogGitHub is making it easier to set up code coverage by introducing an AI-driven feature in its Code Quality settings. This new capability allows users to automatically generate a coverage workflow, significantly cutting down the time and effort usually required. By initiating a pull request for review, GitHub ensures that users can seamlessly integrate this feature into their repositories. This development is currently in public preview for GitHub Code Quality users on github.com, enhancing the efficiency of code quality management without the need for manual workflow authoring.
© Matt WolfeAnthropic has introduced a sandboxed in-app browser for Claude Code on desktop, enhancing its research and debugging capabilities.
The latest update to Claude Code, v2.1.218, introduces several improvements and fixes that enhance user experience and functionality. Notably, the /code-review feature now operates as a background subagent, preventing conversation clutter and improving workflow efficiency. The update also addresses various bugs, such as Windows path corruption and session stability issues, ensuring smoother operations. These changes make Claude Code more robust and user-friendly, particularly for developers relying on its tools for code review and management.
© Lev SelectorGoogle has launched TurboQuant, a new tool for vector compression.