
GitHub has made innersource security advisories available for its Advanced Security enterprise customers. These advisories function like open source advisories but are limited to the enterprise's own repositories. A new REST API endpoint allows enterprises to manage vulnerabilities, including creating, updating, or withdrawing advisories. Dependabot assists by notifying internal repositories of vulnerabilities and initiating pull requests for version upgrades. This feature aims to streamline internal security processes for enterprises using GitHub.
Read originalEarlier coverage that leads up to this article, and what followed. Lines connect each piece to the closest one after it, converging here.
GitHub Changelog · May 11, 2026 · Related
GitHub Changelog · July 28, 2026 · Same story
© GitHub ChangelogGitHub finally exposes Copilot code review to external automation via REST and GraphQL APIs, moving it from a manual UI action to an integrable pipeline step. This allows developers to trigger reviews directly from scripts or internal tools rather than relying on the web interface. Simultaneously, the default effort level shifts to Balanced, striking a middle ground between speed and depth for most repositories. While Lite remains available for those prioritizing raw throughput, the API access is the real win here, enabling true CI/CD integration for automated code quality checks.
© GitHub ChangelogGitHub quietly retired several underlying models for Copilot Chat and code completions, forcing a shift in the default inference stack. Enterprise admins must now manually enable alternative models via policy settings to maintain access, turning what was once automatic into an administrative task. This signals that GitHub is actively pruning its model portfolio rather than just adding new ones, likely to consolidate costs or improve quality control. Developers relying on specific legacy behaviors may find their workflows broken until policies are updated.
© GitHub ChangelogGitHub’s GraphQL API now exposes critical vulnerability metadata directly, eliminating the need to fall back to REST for basic advisory data. Five new fields like cveId and nvdPublishedAt allow developers to pull CVE identifiers and NVD publication times in a single query. The addition of severities and isWithdrawn filters enables server-side narrowing, which significantly reduces client-side processing and rate limit consumption. This consolidation streamlines security integrations by unifying authentication paths and simplifying the construction of triage feeds.
© TechCrunch AIAWS is dropping NDAs in government dealings to combat the growing backlash against AI infrastructure. This move targets a core complaint from activists like Erin Brockovich about opaque project approvals. With over 100 moratoriums pending, Amazon argues that secrecy fuels distrust and threatens U.S. competitiveness. The policy shift aims to rebuild trust, though skeptics remain unconvinced by corporate transparency claims.
© The AI Daily BriefNew KPMG research identifies how leading organizations are scaling AI agents and connecting spending to revenue growth.
© The AI Daily BriefAI safety lab Anthropic is reportedly preparing for an initial public offering before the Thanksgiving holiday.