16 × AIAI signal, amplified
AI newsTopicsAboutSources
TelegramFollow on Telegram
AI newsTopicsAboutSources
16 × AIAI signal, amplified

An AI news engine that ingests trusted sources, scores with Claude, and posts only what clears the bar.

Follow on Telegram →

Subscribe

  • Telegram
  • RSS
  • All channels

Newsletter

Used only to send this newsletter. Privacy

Legal

  • Privacy
  • Imprint
© 2026 16 × AI. All rights reserved.A new issue every two days.
Home/Coding Tools
Coding Tools

GitHub rate limits private vulnerability reports

GitHub Changelog·October 1, 2026·high confidence

Why it matters

  • →Reduces noise for maintainers by blocking automated spam submissions.
  • →Protects legitimate security researchers from being buried under junk reports.
  • →Gives repository admins granular control over reporting thresholds via allow lists.
GitHub rate limits private vulnerability reports
©GitHub Changelog

GitHub has implemented daily per-user rate limits for private vulnerability reports to combat low-quality and automated submissions. The new policy restricts how many new reports a single account can submit to a repository or across the platform in a day, while comments on existing advisories remain unaffected. Repository administrators gain control through custom daily limits and allow lists for trusted reporters. This feature is available for public repositories with private vulnerability reporting enabled across GitHub Free, Pro, Team, and Enterprise Cloud plans.

Read original

The story around this

Earlier coverage that leads up to this article, and what followed. Lines connect each piece to the closest one after it, converging here.

GitHub Limits Open Pull Requests for Non-Writers — GitHub Changelog1GitHub Adds AI Security Detections to Pull Requests — GitHub Changelog2GitHub rate limits private vulnerability reportsJun 17You are here

How we got here

  1. 1
    GitHub Limits Open Pull Requests for Non-Writers

    GitHub Changelog · June 17, 2026 · Related

  2. 2
    GitHub Adds AI Security Detections to Pull Requests

    GitHub Changelog · July 14, 2026 · Related

Follow this story

Open the full story →

GitHub enforces structured vulnerability reports

2 developments

  1. Oct 1 · GitHub Changelog
    GitHub enforces structured vulnerability reports
  2. Oct 1 · GitHub Changelog
    GitHub rate limits private vulnerability reports (This article)↳ GitHub enforces daily per-user limits on new private vulnerability reports to stop automated spam and protect maintainers.

More from GitHub Changelog

GitHub enforces structured vulnerability reports© GitHub Changelog
Coding Toolscoding

GitHub enforces structured vulnerability reports

GitHub is killing the free-text black hole for private vulnerability reports by mandating structured fields. Reporters must now provide a summary, details, impact assessment, and a proof of concept with at least 150 characters, forcing signal over noise. The platform allows custom forms via YAML to tailor these requirements, while also introducing an AI disclosure checkbox to track automated submissions. This shift moves security triage from manual parsing of vague text to structured data that can be programmatically reviewed or integrated into existing workflows.

GitHub Changelog·Oct 1, 2026
GitHub Copilot adds desktop computer use© GitHub Changelog
Coding Toolsagents

GitHub Copilot adds desktop computer use

GitHub Copilot now controls your mouse and keyboard, bridging the gap between code generation and actual desktop automation. By leveraging accessibility APIs to read screens and click controls, it can navigate legacy GUI software that lacks APIs or CLIs. This moves AI from a coding assistant to an operational agent for tasks like expense reporting in Safari. You retain control with approval gates, but the ability to automate non-API workflows is a significant shift in utility.

GitHub Changelog·Oct 1, 2026
GitHub Copilot Agents Automate PR Merges© GitHub Changelog
Coding Toolscoding

GitHub Copilot Agents Automate PR Merges

GitHub is closing the gap between coding and deployment with Agent Merge, letting AI handle review feedback, conflicts, and checks automatically. This moves beyond simple code generation into autonomous workflow execution within VS Code. HydraFusion coordinates multiple models for complex tasks, while cross-app continuity lets developers pick up Codex sessions from ChatGPT directly in their IDE. The focus is on reducing manual handoffs between writing code and merging it.

GitHub Changelog·Oct 1, 2026

More in Coding Tools

Coding Toolscoding

Claude Code v2.1.286 patches security and session stability

Anthropic quietly fixed a critical credential leakage bug where MCP error messages were exposing raw API keys in plaintext logs. Beyond the security patch, this release stabilizes the notoriously fragile background agent system by fixing subagent hand-offs and connection stalls that previously caused silent failures. The update also tightens session management for cloud environments, ensuring large transcripts actually load instead of hanging indefinitely. It’s a maintenance-heavy release, but essential for anyone running complex, multi-step automated workflows.

Claude Code Releases·Oct 2, 2026
Coding Toolscoding

Claude Code v2.1.287 adds plugins and fixes

This update shifts Claude Code from a simple CLI wrapper to a more extensible platform by introducing 'Claude Mods,' allowing plugins to modify deeper behavior rather than just adding tools. The inclusion of a built-in 'You should know' side agent that flags potential oversights is a notable step toward autonomous oversight within the coding workflow. Beyond features, the release addresses critical stability issues in remote sessions and significantly improves accessibility for screen reader users, making the tool more robust for enterprise and diverse developer environments.

Claude Code Releases·Oct 2, 2026
Coding Toolscoding

vLLM v0.31.0rc3 adds Model Runner V2 dummy inputs

The v0.31.0rc3 release of vLLM brings a critical infrastructure tweak to the new Model Runner V2: support for randomized dummy inputs. This isn't a feature for end-users but a developer-facing fix that stabilizes how the runner handles initial tensor shapes during compilation and warm-up phases. By allowing randomized inputs, it reduces the likelihood of shape-mismatch errors when tracing models with dynamic dimensions. For builders running large-scale inference workloads, this means fewer silent failures and more robust model loading sequences in production environments.

vLLM Releases·Oct 2, 2026