Zum Inhalt springen

GitHub Release Notes

52 Einträge aus 2 Quellen. Zuletzt aktualisiert:

Folge GitHub, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Copilot CLI von GitHub

Version 1.0.92-4: copilot config-Unterbefehle und bessere MCP-Verbindung

Version 1.0.92-4 ergänzt copilot config-Unterbefehle, verbessert Start und MCP-Verbindungsaufbau, lässt Canvas-Aktionen Bilder an das Modell zurückgeben und behebt mehrere Fehler zu MCP, Compaction, Shell-Ausgabe, Sandbox und Plannutzung.

Added

  • Add copilot config subcommands to list, read, set, and remove settings.

Improved

  • Improve first-run startup by extracting the bundled CLI package in a child process
  • Improve startup responsiveness when connecting many MCP servers at once
  • Canvas actions can now return images to the model in invoke_canvas_action.

Fixed

  • Legacy HTTP+SSE MCP connections no longer hang indefinitely when a message POST is never acknowledged; the acknowledgement is bounded by the server's configured timeout
  • Voice runtime install errors name why the download from nuget.org failed, not only the fallback feed's 401
  • Compaction keeps your latest prompt when requests exceed context limits
  • Large Anthropic requests rejected by provider size limits now retry after downscaling images or removing attachments
  • Custom agent model entries keep model-bound reasoning effort only when that model is selected
  • Shell tool calls now stream live stdout and stderr output reliably in the timeline
  • Usage reporting preserves provider-reported reasoning token totals when available
  • Sessions no longer slow to a crawl for minutes after the agent writes a very large file in one step
  • Sandboxed shells now withhold ambient GITHUB_TOKEN unless explicitly configured.
  • Plan usage reflects the current billing period after quota resets
  • Custom agents launched through ACP task calls now resolve and run correctly …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Copilot CLI von GitHub

Version 1.0.92-3: Ctrl+E-Umgebungsauswahl für lokale und Cloud-Läufe

Version 1.0.92-3 fügt eine Ctrl+E-Umgebungsauswahl für lokale und Cloud-Läufe hinzu, verbessert Eingabe und Sandbox-Verhalten, hält Sub-Agents nach Wechsel der Zugangsdaten lauffähig und entfernt eingestellte Modelle aus dem Modellwähler.

Added

  • Add a pre-conversation Ctrl+E environment picker to switch between local and cloud runs

Fixed

  • Keyboard, paste, and mouse input now stay ordered and responsive during rapid interaction.
  • Sandboxed shell commands offer a network bypass prompt whenever the proxy blocks a destination
  • Sandboxed scripts that run Git now authenticate with masked credentials and SSH remote rewrites
  • Sub-agents keep working after you replace your GitHub authentication credentials

Removed

  • Remove retired models from the model picker and supported CLI selections

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Copilot CLI von GitHub

Version 1.0.92-2: Windows-Sandbox-Temp-Dateien und sessionEnd-Hook

Version 1.0.92-2 sorgt dafür, dass Sandbox-Befehle unter Windows temporäre Dateien im freigegebenen Temp-Verzeichnis ablegen, und löst im Prompt-Modus nur noch einen sessionEnd-Hook nach Stop-Hook-Fortsetzungen aus.

Fixed

  • Sandboxed commands on Windows write temporary files to the granted temp directory, so tools that rename a temp file into place work
  • Prompt-mode sessions fire a single sessionEnd hook after Stop-hook continuations complete

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Copilot CLI von GitHub

Version 1.0.92-1: Remote-MCP-Wiederverbindung und bessere Hintergrund-Agents

Version 1.0.92-1 stellt Verbindungen zu Remote-MCP-Servern nach abgelaufenen Sitzungen wieder her, verbessert Hintergrund-Agents und Context-Rollovers und zeigt Subagents nicht mehr fälschlich als konfiguriert an.

Fixed

  • Reconnect to remote MCP servers after idle Streamable HTTP sessions expire
  • Messaging a running background agent now steers its active turn at the next processing opportunity.
  • Context rollovers keep your latest requests in the recovery context.
  • Hide the automatic sandbox CA setup prompt on Windows accounts that cannot self-elevate
  • Copilot no longer describes a subagent as configured when the current session cannot run it. Previously a session that could not use rubber-duck still reported it as set up in /subagents, and asking for it failed instead of being skipped cleanly.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

GitHub

Stateless GitHub-App-Installation-Tokens werden ausgerollt

Neu erzeugte GitHub App installation tokens liegen standardmäßig im stateless Format ghs_APPID_JWT vor und sind mit rund 520 statt 40 Zeichen deutlich länger, während der Header X-GitHub-Stateless-S2S-Token am 30. November 2026 abgekündigt wird.

The staged rollout of the stateless GitHub App installation token format, which began on April 27, 2026, is complete. By default, all newly minted GitHub App installation tokens will be in the stateless ghs_APPID_JWT format, which makes token issuance and validation faster and improves the reliability of the GitHub API.

What’s changed

Installation tokens still start with the ghs_ prefix, but they’re now about 520 characters long instead of 40.

Token permissions, repository scoping, the one-hour expiration, and the installation access token REST API endpoint are unchanged. Tokens minted before the change continue to work until they expire.

What to expect going forward

The temporary X-GitHub-Stateless-S2S-Token request header, which we introduced so you could validate the new format on demand, will be deprecated on November 30, 2026. After that date, GitHub will no longer respect the header, and all eligible apps will always receive stateless tokens. To learn more about the temporary header, see our original changelog for its release.

Once you’ve validated your apps and workflows with both token formats, remove the header from your production code before November 30, 2026.

Check your integrations …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

GitHub

Copilot Code Review per API und neuer Standard-Aufwand „Balanced“

Copilot code review lässt sich jetzt über die REST- und GraphQL-APIs anfordern, wobei sich der Review-Aufwand pro Anfrage festlegen lässt und „Balanced" der neue Standard ist.

You can now request a GitHub Copilot code review through the REST and GraphQL APIs and set the review effort level for each request. Balanced is also now the default review effort level. These changes are generally available to Copilot Pro, Pro+, Max, Business, and Enterprise plans.

🔌 Request Copilot code review with the API

You can now request a review from Copilot using the supported REST and GraphQL APIs. When you make a request, you can optionally set the review effort level for that review.

This lets you bring Copilot code review into your own scripts, workflows, and internal tools, so reviews can start from the systems your team already uses.

⚖️ Balanced is now the default review effort level

As announced on August 28, 2026, the Default review effort level now uses Balanced for new and existing repositories and organizations using Copilot code review. If you explicitly selected Lite in your settings, that selection was respected. This change took effect September 28, 2026.

⚙️ Configure your review effort level

If you prefer Lite or want to try out the options available to you, you can change the review effort level from Default to Lite at the level you manage: …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

GitHub

Nicht validierte npm-Trusted-Publishing-Konfigurationen laufen ab

Nicht validierte npm trusted publishing configurations laufen 48 Stunden nach der Erstellung ab, und Tokens aus GitHub Actions issue_comment-Events werden abgelehnt.

Unvalidated npm trusted publishing configurations now expire 48 hours after creation and can no longer authorize publishing. This limits the risk of trusting a repository or project name that changes ownership.

Your configuration becomes validated and exempt from expiry after its first successful publish. Changing the repository or project identity requires a new trust relationship with a fresh 48-hour validation window—ordinary edits don’t restart the deadline.

If your configuration expires, recreate it to start a new 48-hour window. Expired configurations remain visible in trusted publisher settings but don’t count toward per-package limits. Other valid configurations on the package are unaffected.

npm also now rejects trusted publishing tokens from GitHub Actions issue_comment events, alongside the existing pull_request_target restriction. If affected, move publishing to a permitted event such as push, release, or workflow_dispatch.

Join the discussion within GitHub Community.

The post Unvalidated npm trusted publishing configurations now expire appeared first on The GitHub Blog.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

GitHub

npm Staged Publishing unterstützt jetzt neue Pakete

Mit npm stage publish lassen sich jetzt auch neue npm-Pakete anlegen, wobei die erste Version in die Staging-Warteschlange kommt und von einem Maintainer freigegeben werden muss.

You can now create a new npm package with npm stage publish, using a local session or a granular access token, including a stage-only token. This lets you create packages from your automated workflows without a manual first publish.

This works for public scoped and unscoped packages, and private scoped packages. Your first version enters the staged queue and requires a maintainer to promote it before that version becomes available to install. After package creation, you can manage its settings and configure trusted publishing.

Learn more about staged publishing.

Join the npm roadmap discussion in GitHub Community to share feedback and discuss what’s next.

The post npm staged publishing now supports creating new packages appeared first on The GitHub Blog.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

GitHub

Ausgewählte Modelle in GitHub Copilot abgekündigt

GitHub hat in allen Copilot-Umgebungen die Modelle Gemini 3.5 Flash, Gemini 3.6 Flash, Kimi K2.7 Code und Claude Opus 4.7 abgekündigt und empfiehlt stattdessen Gemini 3.8 Flash, Kimi K3 bzw. Claude Opus 5.5.

As of today, October 2, 2026, we have deprecated the following models across all GitHub Copilot experiences (including Copilot Chat, inline edits, ask and agent modes, and code completions).

Model

Deprecation date

Suggested alternative

Gemini 3.5 Flash

2026-10-02

Gemini 3.8 Flash

Gemini 3.6 Flash

2026-10-02

Gemini 3.8 Flash

Kimi K2.7 Code

2026-10-02

Kimi K3

Claude Opus 4.7

2026-10-02

Claude Opus 5.5

Please update your workflows and integrations to use supported models. Copilot Enterprise administrators may need to enable access to alternative models through their model policies in Copilot settings. As an administrator, you can verify availability by checking your individual Copilot settings and confirming that the policy is enabled for the specific model. Once enabled, you’ll see the model in the Copilot Chat model selector in VS Code and on github.com. No action is required to remove the deprecated models.

GitHub Enterprise customers with questions or concerns are encouraged to reach out to their account manager for further assistance.

Share your feedback

To learn more about the models available in Copilot, see our documentation on models and get started with Copilot today. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

GitHub

Neue Felder in der SecurityAdvisory-GraphQL-API

Das SecurityAdvisory-Objekt der GraphQL API enthält fünf neue Felder, und die securityAdvisories-Abfrage bietet die neuen Filter severities und isWithdrawn.

You can now read more of the GitHub Advisory Database directly from the GraphQL API without falling back to the REST API.

The SecurityAdvisory object gained five new fields:

  • cveId: The advisory’s CVE identifier.
  • sourceCodeLocation: A link to the affected source code relevant to the advisory.
  • githubReviewedAt: When GitHub reviewed the advisory.
  • nvdPublishedAt: When the National Vulnerability Database (NVD) published its record.
  • repositoryAdvisoryUrl: A link to the linked repository security advisory when there is one.

The securityAdvisories query also gained two new filters, severities and isWithdrawn, so you can narrow results on the server instead of downloading everything and filtering it yourself. They work alongside the filters you already use, such as classification, identifier, EPSS, and published or updated since.

This means fewer round trips, one authentication path, and one rate limit budget for integrations that read advisory data. It also makes it easier to build things like severity-based triage feeds, withdrawn advisory audits, and tracking of how quickly advisories move from NVD publication to GitHub review.

These changes are additive and read-only, so your existing queries keep working.

Learn more in the GraphQL API documentation and share your feedback. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

GitHub

Vertrauliche Kommentare bei Repository Security Advisories

Bei Repository Security Advisories lassen sich jetzt vertrauliche Kommentare posten, die nur Personen mit Schreibzugriff auf das Repository sehen können.

You can now post confidential comments on repository security advisories. Confidential comments are visible only to people with write access to the repository, so you can discuss a report with your team without the reporter or other invited collaborators seeing it.

Previously, every comment on an advisory was visible to all of its collaborators, including the reporter. To discuss suspected abuse, investigation details, or coordination notes, you had to move the conversation somewhere else and lose it from the advisory’s history.

With this update:

  • Select Confidential. Only maintainers will see this comment below the comment box before you post.
  • Confidential comments are clearly marked in the advisory timeline.
  • Reporters and invited collaborators without write access can’t see confidential comments and aren’t notified about them.
  • Access follows current repository permissions. If someone loses write access, they can no longer read confidential comments.
  • Views of confidential comments are recorded in the audit log.

You can’t switch a comment between confidential and regular after you post it. Confidential comments are available in the GraphQL API, but they aren’t returned by the REST API.

This is available for public repositories with private vulnerability reporting enabled on GitHub Free, GitHub Pro, GitHub Team, and GitHub Enterprise Cloud. …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Copilot CLI von GitHub

Version 1.0.92-0: MCP-Tools nach OAuth-Neuauthentifizierung weiter nutzbar

Version 1.0.92-0 sorgt dafür, dass MCP-Tools nach einer OAuth-Neuauthentifizierung weiterarbeiten, wenn sich die Tool-Definitionen nicht geändert haben.

Fixed

  • MCP tools continue working after OAuth reauthentication when tool definitions are unchanged

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Copilot CLI von GitHub

Version 1.0.91: copilot sandbox ca-Befehle und mehrere Fehlerbehebungen

Version 1.0.91 ergänzt copilot sandbox ca-Befehle zur Verwaltung des Proxy-CA-Vertrauens und behebt Probleme bei Sitzungsanzeige, Windows-Sandbox, Footer-Auswahl und Telemetrie beim Beenden.

2026-10-01

  • Add copilot sandbox ca commands to check, create, trust, rotate, and remove proxy CA trust, including unattended Windows setup; /sandbox ca install becomes create and trust
  • Session timelines now clear busy status after interrupted turns finish.
  • Sandboxed commands run on Windows versions without filesystem enumeration support, with a warning that PowerShell's current location may be wrong
  • Footer text selection stays on the same visible line when the footer grows or shrinks.
  • Offer sandbox network bypass for Node/npm EACCES socket denials on Windows
  • CLI shutdown flushes pending telemetry before exit, with a bounded delay when telemetry is still initializing.
  • Complete, statically analyzable read-only shell pipelines can now enter execution-evidence review, while incomplete or unbound pipelines require explicit approval.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Copilot CLI von GitHub

Version 1.0.91-1: Proxy-CA-Befehle, Telemetrie beim Beenden und Fixes

Version 1.0.91-1 fügt copilot sandbox ca-Befehle für das Proxy-CA-Vertrauen hinzu, leert Telemetrie beim Beenden und behebt Fehler bei Busy-Status, Windows-Sandbox und Footer-Textauswahl.

Added

  • Add copilot sandbox ca commands to check, create, trust, rotate, and remove proxy CA trust, including unattended Windows setup; /sandbox ca install becomes create and trust

Improved

  • CLI shutdown flushes pending telemetry before exit, with a bounded delay when telemetry is still initializing.

Fixed

  • Session timelines now clear busy status after interrupted turns finish.
  • Sandboxed commands run on Windows versions without filesystem enumeration support, with a warning that PowerShell's current location may be wrong
  • Footer text selection stays on the same visible line when the footer grows or shrinks.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Copilot CLI von GitHub

Version 1.0.91-0: Shell-Pipelines in Prüfung, Sandbox-Netzwerk-Bypass unter Windows

Version 1.0.91-0 lässt vollständige, statisch analysierbare schreibgeschützte Shell-Pipelines in die Execution-Evidence-Prüfung gehen und bietet unter Windows einen Sandbox-Netzwerk-Bypass bei Node/npm-EACCES-Socketfehlern an.

Improved

  • Complete, statically analyzable read-only shell pipelines can now enter execution-evidence review, while incomplete or unbound pipelines require explicit approval.

Fixed

  • Offer sandbox network bypass for Node/npm EACCES socket denials on Windows

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Copilot CLI von GitHub

Version 1.0.90: GPT-6.1 Sol, --mcp-github-auth und viele Fehlerbehebungen

Version 1.0.90 unterstützt GPT-6.1 Sol in der Modellauswahl, ergänzt --mcp-github-auth und sitzungsbezogene schreibgeschützte Verzeichnisfreigaben und behebt viele Fehler bei Berechtigungen, Compaction, MCP, Wayland-Zwischenablage und Startmeldungen.

2026-09-30

  • Add support for GPT-6.1 Sol in model selection
  • Add --mcp-github-auth to scope GitHub account auth to approved MCP server origins
  • Add session-scoped read-only directory approvals to path access prompts
  • Permission prompts remain answerable after resuming interrupted sessions.
  • Auto-approval now takes into account messages you type while the agent is working, as it already did for prompts sent while it was idle
  • Compaction now returns a summary even when instructions ask for tool use.
  • Copying selected text on Wayland now finishes as soon as wl-copy accepts it, instead of timing out and falling back to the in-process clipboard that can print "Somebody else owns the clipboard now" over the UI
  • A narrow Sessions sidebar drops keyboard hints that do not fit instead of cutting one off mid-word
  • MCP tools recover after transient discovery failures without restarting the session; unchanged catalogs remain available during recovery.
  • "No supported model available" is no longer shown on launch or in the model picker when a configured provider already supplies a model
  • MCP tool calls complete even when servers keep sending progress updates after responding
  • A fresh launch no longer prints "Failed to read model provider attribution" errors while it signs in
  • MCP OAuth sign-in to servers such as Datadog reuses a still-valid cached token
  • Withdrawn running prompts stay removed after session resume …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Copilot CLI von GitHub

Version 1.0.90-7: Nicht näher beschriebene Fehlerbehebungen und Änderungen

Version 1.0.90-7 enthält laut Eintrag nicht näher beschriebene Fehlerbehebungen und Änderungen.

Fixes and changes

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Copilot CLI von GitHub

Version 1.0.90-6: GPT-6.1 Sol, Tool-Calls einklappen und Sprachmodus-Hinweise

Version 1.0.90-6 unterstützt GPT-6.1 Sol in der Modellauswahl, erleichtert das Einklappen von Tool-Calls und liefert Hinweise zum Sprachmodus, außerdem Fixes zu Berechtigungsabfragen, Auto-Approval, Compaction, Wayland-Kopieren und MCP-Tools.

Added

  • Add support for GPT-6.1 Sol in model selection

Improved

  • Click anywhere on expanded tool calls in compact timeline to collapse them
  • Holding Space and Ctrl+X V explain when voice mode is off or still getting ready

Fixed

  • Permission prompts remain answerable after resuming interrupted sessions.
  • Auto-approval now takes into account messages you type while the agent is working, as it already did for prompts sent while it was idle
  • Compaction now returns a summary even when instructions ask for tool use.
  • Copying selected text on Wayland now finishes as soon as wl-copy accepts it, instead of timing out and falling back to the in-process clipboard that can print "Somebody else owns the clipboard now" over the UI
  • A narrow Sessions sidebar drops keyboard hints that do not fit instead of cutting one off mid-word
  • MCP tools recover after transient discovery failures without restarting the session; unchanged catalogs remain available during recovery.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Copilot CLI von GitHub

Version 1.0.90-5: Keine irreführende Modellmeldung, MCP-Aufrufe schließen ab

Version 1.0.90-5 verhindert die irreführende Meldung „No supported model available“ bei konfiguriertem Provider und lässt MCP-Tool-Aufrufe trotz weiterer Fortschrittsmeldungen der Server abschließen.

Fixed

  • "No supported model available" is no longer shown on launch or in the model picker when a configured provider already supplies a model
  • MCP tool calls complete even when servers keep sending progress updates after responding

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum aus der Quelle.

Erstmals gesehen am .

Copilot CLI von GitHub

Version 1.0.90-4: Keine Fehlermeldung zur Provider-Attribution beim Start

Version 1.0.90-4 verhindert, dass ein frischer Start während der Anmeldung die Fehlermeldung „Failed to read model provider attribution“ ausgibt.

Fixed

  • A fresh launch no longer prints "Failed to read model provider attribution" errors while it signs in

Originalquelle(öffnet in neuem Tab)Problem melden