GitHub Copilot can now operate desktop apps, not just code
The useful boundary change is that Copilot can now cross from code and terminals into ordinary desktop interfaces, with per-app approval and organisation-level controls.
Find published research by company, product, platform or technology.
Showing 1–20 of 122 dossiers
The useful boundary change is that Copilot can now cross from code and terminals into ordinary desktop interfaces, with per-app approval and organisation-level controls.
Rosetta’s transition is now an application compatibility deadline rather than an open-ended safety net. Intel-only Mac apps need an Apple-silicon build before support ends after macOS 27, with only a narrow exception retained for older unmaintained games.
GitHub OAuth apps can now use eight-hour access tokens with rotating refresh tokens, register up to 10 callback URLs, and explicitly control wildcard callback matching. New apps default to expiring tokens, while existing single-callback apps should review a legacy wildcard setting GitHub has now made visible.
The corrected rollout matters for supply-chain configuration: teams can still remove PATs for qualifying GitHub Packages, but GitHub changed the precedence model after some npm update jobs were mistakenly routed through GitHub Packages.
The migration is no longer an open-ended future plan. Reddit is killing RSS on November 13 and says remaining public API access ends by March 2027, giving bots, moderation tools, social-listening products and research integrations concrete deadlines.
Approved apps can move from the standard 20%/25% non-recurring service-fee rates to 15%/20% for new/existing installs from September 30, before any applicable billing fee. Current enrollment is limited to developer account groups with at least $1 million in earnings over the previous 12 months.
Google Play’s 2026 target-API cutoff has two separate consequences: most new submissions and updates need API 36, while existing apps below API 35 can lose distribution to new users on newer Android devices. Developers who need more time can request an extension to November 1.
GitHub has moved local Copilot sandboxes from preview to GA. Enterprises can now combine centrally managed approval policies with operating-system-enforced limits on what coding agents can actually reach.
Stacked pull requests are now generally available on GitHub. The shift matters as coding agents make large changes faster than humans can safely review them: teams can keep one coherent change dependency-ordered while reviewing it as smaller PRs.
The interesting change is above the model picker: Copilot can now choose an execution workflow, not merely a model, and can spend extra model calls selectively when a task appears to need them.
GitHub’s credential-response story now has both discovery and containment: enterprise owners can export SSH keys, PATs, OAuth and GitHub App tokens with ownership, scope and last-use metadata, then use selective revocation rather than invalidating every credential a user holds.
The useful part is not the 800,000-line headline. GitHub has published unusually detailed receipts for a production-scale agent-assisted migration: roughly $120,000 of token spend, 14.5 weeks of incremental releases, dozens of regressions, extensive compatibility tests and a workload-specific jump from 7.55 to 120 session lifecycles per second.
GitHub Actions now has enforceable actor and event rules before a workflow starts, plus a coming default block for a trigger that can expose repository secrets to untrusted fork code.
GitHub-hosted Actions jobs that use `ubuntu-latest` are about to change operating-system generation without a YAML edit; teams can test on `ubuntu-26.04` now or pin 24.04 while they migrate.
The scanner itself is not the new part. The September 16 change removes the CodeQL-default-setup gate that GitHub’s July rollout originally required, making AI-assisted vulnerability detection easier to add to repositories with different code-scanning configurations.
The deadline is no longer theoretical: browsers, Git HTTPS backends and API clients that still depend on SHA-1-era TLS algorithms can now lose connectivity to GitHub.com.
The material change is that model routing is no longer a single opaque optimization target. Developers can now tell Copilot whether to bias Auto toward lower cost, a middle ground or higher quality while GitHub still chooses a model prompt by prompt.
GitHub Spark stops being available to existing users on August 31, 2026. Deployed apps are meant to keep running, but owners should export code to a repository now; Spark apps using `llm()` need a separate inference provider because the underlying GitHub Models service retired July 30.
The change turns cache poisoning from mostly a workflow-design warning into an enforceable permission boundary. Teams can let untrusted jobs restore caches without writing them, prevent reusable workflows from escalating cache access and isolate jobs that only need to publish cache entries.
The useful change is where enforcement happens. Teams can now make unresolved leaked credentials a branch-policy failure, with organization and enterprise rollout plus API configuration for large repository fleets.