Fetching from the wire…
Security2026-09-25 · source-backed
Before high-impact actions, creating a token, editing webhooks, changing org security settings, viewing recovery codes, GitHub now requires re-authentication or MFA. PR merges are next. The changelog names stolen session cookies, long-lived tokens from recent supply-chain attacks, and "agents going an extra step without your knowledge." (GitHub Changelog) A passed challenge lasts two hours per browser session, and the preview only covers EMU enterprises and GHEC-DR on Entra ID SSO. Naming agent overreach in a security control's threat model is new, and I expect more of it.
Each link below shares sources, entities, or timing with this story.
The July 23 changelog moves issue-tracker-triggered agent work out of preview, and the same day GitHub Mobile gained the ability to fix failing Actions checks via the cloud agent (GitHub Changelog). Together they push agent invocation off the desktop entirely. An agent that st...
GitHub's June 22 changelog brings Claude as an agent provider into public preview in JetBrains IDEs via the Claude Code CLI, and lets admins publish curated org/enterprise agents that show up for everyone automatically (GitHub Changelog). It also adds CLI message queue/steer/s...
The September 4 changelog announces a REST endpoint returning historical star counts with timestamps but no stargazer identities, restoring growth tracking that broke when stargazer listing got restricted to admins and collaborators earlier this year. Called against repos/verc...
The July 30 changelog closed the hosted model-catalog and playground service that let developers prototype against multiple LLMs from GitHub directly. If you prototyped against Models endpoints, this is a migration event, not a skim. The surrounding changelog items (Copilot up...
GitHub's getting-started guide describes a standalone workspace rather than an editor extension: pick a repo as a project, run multiple agent sessions against it simultaneously, keep separate Quick Chat threads open. Canvases created with /create-canvas preview a running appli...
The GitHub Blog checklist closes the easy doors on open-source repos with zero-cost, immediately-actionable settings. For solo builders and OSS maintainers this is a low-effort hardening pass that materially raises the bar against opportunistic attacks. Do it in the next hour....
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.