Browse DevOps News (170)

Allison provides an in-depth overview of the GitHub Enterprise Server 3.20 release candidate, breaking down new security, DevOps, and collaboration features for enterprise development teams.
Advanced SecurityAPIBackup ServiceCode SecurityCollaboration+13 more
Allison details the CodeQL 2.24.2 release, highlighting expanded language support, security query updates for Microsoft technologies, and improved detection accuracy for DevOps and security teams.
Application SecurityAzure SDKC#CodeQLCross Site Request Forgery+14 more
Allison introduces a Dependabot feature that allows grouping dependency updates by name across directories, simplifying dependency upgrades and reducing pull request volume for developers.
AutomationCode SecurityConfigurationDependabotDependabot.yml+10 more
Allison details the public preview of GitHub Code Quality's organization-level dashboard, providing a new way for organizations to assess code health and quality metrics across their repositories.
Application SecurityCode HealthCode QualityDeveloper ToolsDevOps+10 more
Allison introduces the now generally available GitHub repository dashboard, highlighting new features like admin access view and command palette integration that improve repository navigation and management.
Admin AccessCollaborationCollaboration ToolsCommand PaletteDevOps+11 more

Malicious Next.js Repositories Used in Developer-Targeting Attack: RCE and C2 via Build Workflows

Microsoft Defender Experts and the Security Research Team provide an in-depth report on a developer-targeted campaign using malicious Next.js repositories that exploit common coding workflows. The analysis details how attackers achieve remote code execution and persistent C2, with actionable security guidance.
Advanced HuntingAttack Surface ReductionAzureBuild SecurityC2 Infrastructure+20 more
Allison details the new enterprise-defined custom organization roles feature in GitHub Enterprise, making it easier for administrators to standardize and manage access permissions across organizations.
Access ControlAPI IntegrationCloud AdministrationCustom RolesDevOps+8 more
Allison highlights how GitHub Enterprise Cloud's IP allow list now extends to Enterprise Managed User namespaces, providing unified network access control for organizations.
Access ControlAPI SecurityDevOpsEnterprise AdministrationEnterprise Managed Users+10 more
Allison reports on GitHub Enterprise's new API enhancements, enabling organization and enterprise owners to manage and query both enterprise teams and organization teams efficiently from a unified set of endpoints.
Access ControlAPI EnhancementDevOpsEnterprise AdministrationEnterprise Management Tools+11 more
Allison provides an update on a new feature for GitHub Actions: the workflow dispatch API now returns run IDs and details, streamlining workflow tracking for developers and DevOps teams.
ActionsAPIAPI EndpointAPI ImprovementAutomation+13 more
Allison summarizes GitHub's updated policy for when test merge commits are generated on pull requests, emphasizing improved performance and system reliability for development workflows.
Branch ManagementChange ManagementCode ReviewCollaborationCollaboration Tools+9 more
Allison provides an overview of the latest GitHub Projects features, focusing on importing project items via search queries and improved hierarchy management for streamlined workflow organization.
DevOpsGitHub IssuesGitHub ProjectsHierarchy ViewIssue Tracking+9 more
Allison details recent improvements to GitHub's pull request review process, showing developers how to access and manage all comments directly from the Files changed page without leaving their code review context.
Code ReviewCollaborationCollaboration ToolsComments PanelDeveloper Experience+9 more
Andrea Griffiths delves into how AI is transforming developer technology choices, using real-world Octoverse 2025 data to highlight GitHub Copilot's influence and provide practical advice for developers and leaders.
AIAI & MLAI AdoptionArchitectural PatternsCopilot Usage+18 more
Allison details how the Copilot usage metrics API helps enterprise admins gain visibility into the impact of GitHub Copilot on pull request workflows and team productivity.
Account ManagementAIAPI IntegrationCopilotCopilot Metrics API+11 more
The Microsoft Fabric Blog introduces the officially supported fabric-cicd Python library, providing robust, automated CI/CD capabilities for Fabric workspaces. Learn from Microsoft's announcement how this tool simplifies cross-workspace deployments and modernizes DevOps for Fabric.
AzureBuild And Release PipelineCI/CDContinuous DeploymentCross Workspace Deployment+14 more
Allison explains how to set up the Copilot coding agent for Windows-based projects—helpful for developers who want Copilot to build and test code autonomously with GitHub Actions integration.
AICI/CDCopilotCopilot Coding AgentCopilot Setup Steps.yml+12 more
Allison details improvements to GitHub secret scanning that add extended metadata checks, providing richer context on exposed secrets and supporting more effective remediation for development and security teams.
Access ControlApplication SecurityAudit LogCode SecurityCredential Leak Detection+13 more
Allison details the major new Git hooks support in GitHub Desktop 3.5.5, along with other development-focused improvements like terminal compatibility, Copilot commit attribution, and crash fixes.
Client AppsCommit AutomationCopilot IntegrationCross Platform DevelopmentDeveloper Tools+13 more
Dylan Birtolo delves into the trends shaping open source in 2026, examining GitHub’s Octoverse data for 2025. The analysis spotlights global growth, AI’s benefits and challenges, and strategies for maintainers navigating the evolving open source landscape.
AIAI ContributionsAI SlopCode ReviewComfyUI+16 more

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.