
GitHub has updated its AI Scan feature for pull requests to no longer require the CodeQL default setup to be enabled on a repository. Previously, access to AI-powered vulnerability detection was gated behind specific CodeQL configurations, limiting its adoption. The change allows GitHub Advanced Security customers to run AI Scan across eligible organization-owned and personal repositories immediately after enabling the feature at the organizational level. This update is currently available in public preview for github.com users, though it remains unsupported on GitHub Enterprise Server.
Read original
© GitHub ChangelogGitHub Enterprise Cloud finally addresses the friction of manual SSO authorization for classic tokens and SSH keys. Admins can now delegate bulk authorization to GitHub Apps via a new API, handling up to 50 organizations in one request without exposing secrets. This shift from manual per-org clicks to automated delegation reduces the temptation to use insecure long-lived tokens. It is a practical infrastructure improvement that streamlines credential rotation for large enterprises managing complex access controls.
© GitHub ChangelogGitHub finally aligns its SCIM implementation with RFC 7643 by adding the profileUrl attribute to user responses. This small but necessary change eliminates the need for identity providers to perform extra lookups or infer account links when provisioning access. The update is additive, meaning existing integrations remain unaffected while new ones can now rely on a standardized field. It’s a quiet fix that reduces friction for enterprise IT teams managing GitHub access at scale.
© GitHub ChangelogGitHub finally closes the friction gap in its usage-based billing model. Instead of hitting a hard wall when credits run out, members can now request more budget directly from their settings, with approvals routing automatically to the correct organizational or enterprise billing manager. This removes the administrative bottleneck that previously stalled productivity, allowing teams to scale AI adoption without constant manual intervention. It is a pragmatic fix for enterprise governance rather than a technological breakthrough.
This release targets the friction points that make local AI coding feel fragile. The most critical fix addresses MCP servers timing out after five minutes regardless of configuration, a major blocker for complex agent workflows. Session reliability also improves with self-healing corrupted transcripts and better handling of background agents during resumption. While not feature-heavy, these patches stabilize the environment for developers relying on long-running automated tasks.
This release patches a critical remote code execution vulnerability in the llama.cpp server that allowed unauthenticated attackers to hijack memory via dangling pointers. The flaw stemmed from caching compute graphs that referenced freed buffers, enabling heap corruption and arbitrary code execution through subsequent tensor commands. By discarding cached graphs when buffers are freed, the fix forces a safe fallback to full recomputation without changing the API. This is a vital security update for anyone running the llama.cpp server remotely, closing a direct path to system compromise.
A copy-paste error in llama.cpp was corrupting matrix transpositions on Spacemit hardware, causing significant data corruption for int16 operations. This release patches the specific RVV instruction call to ensure correct computation on these RISC-V based chips. While niche, it prevents silent inference failures for users relying on this specific accelerator architecture. The update also ships binaries for CUDA 13 and ROCm 10.0, keeping the runtime current with latest driver ecosystems.