
GitHub has released weekly updates for Copilot, introducing local sandboxing for agents in VS Code and the CLI to restrict access to sensitive resources. Claude Haiku 5.5 is now available across all paid plans, including Pro, Business, and Enterprise tiers. The Copilot app allows separate GitHub accounts for licensing and repository access, while the CLI supports discovering local Ollama models via the /model command. Additional features include side-by-side agent session viewing and worktree cleanup tools to manage disk space.
Read originalEarlier coverage that leads up to this article, and what followed. Lines connect each piece to the closest one after it, converging here.
Anthropic · June 30, 2026 · Related
GitHub Changelog · September 23, 2026 · Same story
GitHub Changelog · October 7, 2026 · Same story
The Verge AI · October 7, 2026 · Related
Claude Code Releases · October 10, 2026 · Related
© GitHub ChangelogCodeQL 2.27.2 tightens security coverage with new C++ regex parsing and SQL-injection models for Comdb2, while refining Rust async data flow. The release also corrects false positives in C# clickjacking and XSS queries, making enterprise scanning more precise. However, the most disruptive change is the abrupt loss of support for macOS 27 and Xcode 27 due to Apple dropping multi-architecture binaries, forcing developers to downgrade their toolchains for compiled language analysis. This update underscores the fragility of static analysis pipelines when underlying OS dependencies shift without warning.
© GitHub ChangelogGitHub is tightening the leash on enterprise AI spending with new billing and access controls for Copilot Code Review. Organizations can now shift costs from individual member quotas to a central cost center using AI Credits, preventing personal license exhaustion from halting team workflows. Simultaneously, admins can block external licenses from triggering reviews, ensuring only authorized corporate accounts consume resources. This moves Copilot from a perk to a managed utility, giving finance teams actual visibility into AI consumption.
© GitHub ChangelogGitHub finally plugs a loophole that let spammers bypass repository pull request limits by opening endless drafts. Maintainers can now configure these limits to include draft PRs, directly reducing notification clutter and wasted CI runs from low-quality contributions. This is a practical quality-of-life fix for open source maintainers tired of managing spam rather than code. It shifts the burden slightly toward contributors but protects repository health.
This release tightens the leash on Claude Code's autonomous capabilities while fixing critical sandbox escapes. The new effort parameter for Agent tools lets developers explicitly control sub-agent depth, a necessary guardrail as these systems grow more complex. Security fixes are prominent, addressing how plugins handle network paths and how file permissions persist during session resumption. It’s a stability patch that ensures the tool remains usable in enterprise environments without compromising on the new agent features.
Anthropic quietly shipped a significant model update alongside routine maintenance. Claude Haiku 5.5 is now the default on the API, offering a 1M context window at $0.10 per million tokens, which lowers the cost floor for high-volume coding tasks. The release also patches critical stability issues in the local agent runtime, specifically fixing memory leaks in HTTP MCP connections and resolving session state corruption during context compaction. These fixes matter because they stabilize the autonomous coding workflow that developers rely on daily. With Haiku 5.5 now standard, teams can deploy cheaper, faster iterations without manual configuration.
Anthropic quietly patched a frustrating edge case in Claude Code’s agent hooks. Previously, instructions like 'Block commands that...' were often ignored because the model didn't recognize them as valid blocking criteria. This update ensures those prompts are properly interpreted, while also refining how stop conditions are judged to prevent premature termination. It’s a small but necessary fix for anyone relying on strict guardrails in automated coding workflows.