16 × AIAI signal, amplified
AI newsTopicsAboutSources
TelegramFollow on Telegram
AI newsTopicsAboutSources
16 × AIAI signal, amplified

An AI news engine that ingests trusted sources, scores with Claude, and posts only what clears the bar.

Follow on Telegram →

Subscribe

  • Telegram
  • RSS
  • All channels

Newsletter

Used only to send this newsletter. Privacy

Legal

  • Privacy
  • Imprint
© 2026 16 × AI. All rights reserved.A new issue every two days.
Home/Coding Tools
Coding Tools

GitHub API adds security advisory comments

GitHub Changelog·October 2, 2026·high confidence

Why it matters

  • →Enables automated triage workflows for security vulnerabilities using standard REST endpoints.
  • →Allows programmatic export of advisory discussions for compliance audits and migrations.
  • →Brings security advisory management parity with existing issue and pull request automation tools.
GitHub API adds security advisory comments
©GitHub Changelog

GitHub has released a public preview for repository security advisory comments via its REST API, allowing users to list, add, and edit discussions tied to vulnerability reports. The update includes comment counts in advisory responses to help identify active threads without fetching full content, supporting automated triage and audit exports. Access controls mirror existing advisory permissions, excluding confidential comments and requiring specific scopes. Deletion functionality is not yet available through the API.

Read original

The story around this

Earlier coverage that leads up to this article, and what followed. Lines connect each piece to the closest one after it, converging here.

GitHub Launches Innersource Security Advisories — GitHub Changelog1GitHub API adds security advisory commentsGitHub adds confidential comments to security advisories — GitHub Changelog2Jul 8You are hereOct 2

How we got here

  1. 1
    GitHub Launches Innersource Security Advisories

    GitHub Changelog · July 8, 2026 · Related

What happened next

  1. 2
    GitHub adds confidential comments to security advisories

    GitHub Changelog · October 2, 2026 · Same story

Follow this story

Open the full story →

GitHub enforces structured vulnerability reports

3 developments

  1. Oct 1 · GitHub Changelog
    GitHub enforces structured vulnerability reports
  2. Oct 1 · GitHub Changelog
    GitHub rate limits private vulnerability reports↳ GitHub enforces daily per-user limits on new private vulnerability reports to stop automated spam and protect maintainers.
  3. Oct 2 · GitHub Changelog
    GitHub API adds security advisory comments (This article)↳ GitHub API now exposes security advisory comments via REST for automated triage, though confidential comments remain excluded.

More from GitHub Changelog

GitHub Copilot Code Review API and Default Effort Change© GitHub Changelog
Coding Toolscoding

GitHub Copilot Code Review API and Default Effort Change

GitHub finally exposes Copilot code review to external automation via REST and GraphQL APIs, moving it from a manual UI action to an integrable pipeline step. This allows developers to trigger reviews directly from scripts or internal tools rather than relying on the web interface. Simultaneously, the default effort level shifts to Balanced, striking a middle ground between speed and depth for most repositories. While Lite remains available for those prioritizing raw throughput, the API access is the real win here, enabling true CI/CD integration for automated code quality checks.

GitHub Changelog·Oct 2, 2026
GitHub Copilot deprecates specific models© GitHub Changelog
Coding Toolscoding

GitHub Copilot deprecates specific models

GitHub quietly retired several underlying models for Copilot Chat and code completions, forcing a shift in the default inference stack. Enterprise admins must now manually enable alternative models via policy settings to maintain access, turning what was once automatic into an administrative task. This signals that GitHub is actively pruning its model portfolio rather than just adding new ones, likely to consolidate costs or improve quality control. Developers relying on specific legacy behaviors may find their workflows broken until policies are updated.

GitHub Changelog·Oct 2, 2026
GitHub GraphQL API expands SecurityAdvisory fields© GitHub Changelog
Coding Toolscoding

GitHub GraphQL API expands SecurityAdvisory fields

GitHub’s GraphQL API now exposes critical vulnerability metadata directly, eliminating the need to fall back to REST for basic advisory data. Five new fields like cveId and nvdPublishedAt allow developers to pull CVE identifiers and NVD publication times in a single query. The addition of severities and isWithdrawn filters enables server-side narrowing, which significantly reduces client-side processing and rate limit consumption. This consolidation streamlines security integrations by unifying authentication paths and simplifying the construction of triage feeds.

GitHub Changelog·Oct 2, 2026

More in Coding Tools

Coding Toolscoding

Claude Code v2.1.288 fixes resume and MCP bugs

This release stabilizes the core session management of Claude Code, specifically targeting the fragile state of resumed conversations where context or thinking traces were previously lost. It also patches critical reliability issues in the Model Context Protocol (MCP) integration, ensuring tool calls don't duplicate or hang indefinitely when remote servers misbehave. The addition of $.ui.selection() for mods and better GitHub CLI handling in cloud sessions shows a focus on developer workflow friction rather than new capabilities. These are necessary maintenance updates that make the tool more robust for heavy daily use.

Claude Code Releases·Oct 4, 2026
Coding Toolscoding

Claude Code v2.1.289 patches sandbox and plugin stability

This release is a classic maintenance patch for Claude Code, focusing on stabilizing the terminal interface and tightening security rules. It fixes critical bugs where deny/ask rules were bypassed in nested shell commands or via symlinks, ensuring sandbox policies actually hold. The update also resolves numerous UI freezes caused by malformed HTML tags and plugin rendering errors, making the agent feel less brittle during complex coding sessions.

Claude Code Releases·Oct 4, 2026
Coding Toolscoding

llama.cpp b11372 optimizes Qwen4-Exp memory and GPU support

This release tackles the notorious memory hunger of long-context inference for Qwen4-exp models by halving indexer score memory. The optimization works by computing head scores in place rather than materializing separate tensors, a change that significantly reduces VRAM pressure during heavy workloads. Beyond memory efficiency, b11372 expands hardware coverage with CUDA 13 support and Vulkan tiling for the lightning indexer. It also adds ROCm 10.0 binaries, keeping AMD users in step with NVIDIA's latest driver ecosystem. The result is a leaner runtime that handles extended contexts without hitting out-of-memory errors as quickly.

llama.cpp Releases·Oct 4, 2026