
GitHub Actions has officially deprecated Node 20, replacing it with Node 24 as the default runtime for JavaScript actions. The temporary opt-out allowing insecure node versions is no longer available, enforcing immediate compliance. Maintainers of JavaScript actions must update their 'runs.using' metadata to node24 and publish new releases. Workflow users should upgrade to the latest versions of first-party and third-party actions that support Node 24. Note that Node 24 does not support macOS 13.4 or earlier, nor ARM32 architectures, affecting self-hosted runner configurations.
Read original
© GitHub ChangelogGitHub Copilot is finally addressing the security risks of AI agents running on your machine with a new local sandboxing feature. By default off, this preview allows developers to strictly limit what the AI can read, write, or access over the network for specific projects. It enforces these policies at the OS level, failing safely if restrictions cannot be applied rather than silently ignoring them. This shifts Copilot from a trust-based assistant to a tool with explicit, configurable boundaries, reducing the blast radius of accidental commands.
© GitHub ChangelogGitHub Copilot finally gives enterprises visibility into their AI agents with native OpenTelemetry support. Administrators can now route agent traces to existing monitoring tools, tracking model requests and tool usage without forcing developers to configure telemetry individually. This closes a critical gap in observability, allowing teams to investigate unexpected behavior through step-by-step execution flows. Prompt content remains excluded by default, balancing transparency with privacy concerns for sensitive code.
© GitHub ChangelogGitHub Copilot for JetBrains is tightening the leash on autonomous coding with assisted approvals that auto-accept low-risk tool calls while flagging higher-risk actions. The update brings organizational governance to individual IDEs, allowing teams to deploy shared skills and custom instructions across both local and agent sessions. Codex agents now offer a plan mode, letting developers review strategies before implementation begins. This shift moves the plugin from simple code completion toward managed, enterprise-grade automation.
This release stabilizes Claude Code's core reliability by fixing persistent bugs in session resumption and prompt caching that previously caused data loss or infinite loops. It also tightens enterprise security with new Bedrock upstream support for IAM role assumption and mandatory guardrail application. The update addresses critical edge cases like proxy stream drops and oversized tool calls, ensuring smoother operation in complex development environments.
This release targets a specific bottleneck in long-context inference by optimizing the sparse flash attention prefill step for NVIDIA GPUs. By templating kernels to unroll loops at compile time, batched sparse operations drop from 586 microseconds to 244 microseconds on 49k context windows. This isn't just a generic speed bump; it makes handling very long documents significantly more efficient for users relying on sparse attention mechanisms. The change is already baked into the standard CUDA builds, requiring no special flags.
The latest llama.cpp build brings immediate relevance to users on bleeding-edge NVIDIA hardware with native CUDA 13.4 support across Linux and Windows, closing the gap for those testing next-gen GPU architectures. More notably, it finally addresses the mobile inference landscape by including a dedicated build for Linux arm64 Snapdragon devices, covering CPU, Adreno GPU, and Hexagon NPU paths. This moves local AI beyond just desktop GPUs into the realm of high-performance edge computing on Qualcomm silicon. While Apple Silicon builds have KleidiAI disabled in this specific release, the expansion to ARM-based mobile NPUs marks a significant shift in where llama.cpp can run efficiently.