- Dependabot now ingests malware advisories from the OpenSSF malicious‑packages repository
- Expands the range of malicious package data shown in alerts across more ecosystems
- Improves early detection and remediation of known malicious packages
Official GitHub changelog summary with source attribution, release tags, and community reactions.
Track this GitHub release note alongside related changelog updates, risky changes, and weekly digest signals from the developer community.
Every summary should remain traceable to the original changelog or release source.
Turn this GitHub release note into a weekly digest for the tools you actually use.
Create digestExpanded Copilot app usage metrics to cover additional API report rollups.
Grok 4.5, xAI’s latest reasoning model, is now rolling out in GitHub Copilot.
GitHub Actions now automatically holds potentially malicious workflows for manual approval before execution.