
GitHub has released VS Code versions 1.136 through 1.140, introducing significant updates to its Copilot agent capabilities. Key features include Agent Merge, which automates the handling of review feedback, merge conflicts, and CI checks, and HydraFusion, a research preview feature for coordinating multiple AI models. The update also enhances session management with hierarchical navigation, Dev Container integration, and cross-app continuity with ChatGPT's Codex. These changes aim to streamline the entire development lifecycle from implementation to pull request merging.
Read originalEarlier coverage that leads up to this article, and what followed. Lines connect each piece to the closest one after it, converging here.
Cole Medin · June 15, 2026 · Related
The Verge AI · August 20, 2026 · Related
The Rundown AI · August 21, 2026 · Related
GitHub Changelog · August 31, 2026 · Same story
GitHub Changelog · September 10, 2026 · Same story
The Verge AI · September 25, 2026 · Related
GitHub Copilot adds Claude Opus 5.5 and GPT-6
3 developments
© GitHub ChangelogGitHub is finally capping the flood of automated junk hitting maintainers' inboxes. By enforcing daily per-user limits on new private vulnerability reports, the platform stops bad actors from burying legitimate security findings under noise. Admins can now set custom caps or whitelist trusted researchers, ensuring that actual threats get seen. This shifts the burden from manual triage to automated gating, protecting open source maintainers without blocking genuine disclosures.
© GitHub ChangelogGitHub is killing the free-text black hole for private vulnerability reports by mandating structured fields. Reporters must now provide a summary, details, impact assessment, and a proof of concept with at least 150 characters, forcing signal over noise. The platform allows custom forms via YAML to tailor these requirements, while also introducing an AI disclosure checkbox to track automated submissions. This shift moves security triage from manual parsing of vague text to structured data that can be programmatically reviewed or integrated into existing workflows.
© GitHub ChangelogGitHub Copilot now controls your mouse and keyboard, bridging the gap between code generation and actual desktop automation. By leveraging accessibility APIs to read screens and click controls, it can navigate legacy GUI software that lacks APIs or CLIs. This moves AI from a coding assistant to an operational agent for tasks like expense reporting in Safari. You retain control with approval gates, but the ability to automate non-API workflows is a significant shift in utility.
Anthropic quietly fixed a critical credential leakage bug where MCP error messages were exposing raw API keys in plaintext logs. Beyond the security patch, this release stabilizes the notoriously fragile background agent system by fixing subagent hand-offs and connection stalls that previously caused silent failures. The update also tightens session management for cloud environments, ensuring large transcripts actually load instead of hanging indefinitely. It’s a maintenance-heavy release, but essential for anyone running complex, multi-step automated workflows.
This update shifts Claude Code from a simple CLI wrapper to a more extensible platform by introducing 'Claude Mods,' allowing plugins to modify deeper behavior rather than just adding tools. The inclusion of a built-in 'You should know' side agent that flags potential oversights is a notable step toward autonomous oversight within the coding workflow. Beyond features, the release addresses critical stability issues in remote sessions and significantly improves accessibility for screen reader users, making the tool more robust for enterprise and diverse developer environments.
The v0.31.0rc3 release of vLLM brings a critical infrastructure tweak to the new Model Runner V2: support for randomized dummy inputs. This isn't a feature for end-users but a developer-facing fix that stabilizes how the runner handles initial tensor shapes during compilation and warm-up phases. By allowing randomized inputs, it reduces the likelihood of shape-mismatch errors when tracing models with dynamic dimensions. For builders running large-scale inference workloads, this means fewer silent failures and more robust model loading sequences in production environments.