Humans out of the loop
A blog post argues that the software industry's default "human in the loop" approval for AI-agent-generated changes is often a rubber stamp, citing Dependabot pull requests such as RuboCop 1.90.0 to 1…
A blog post argues that the software industry's default "human in the loop" approval for AI-agent-generated changes is often a rubber stamp, citing Dependabot pull requests such as RuboCop 1.90.0 to 1…
OpenAI announced Codex Security Cloud at its DevDay on September 29, a GitHub-only code security tool that scans repositories commit-by-commit, validates each finding in an isolated sandbox, and opens…
A developer diffed the OpenAPI specs of GitHub, Stripe and OpenAI across recent commit windows, finding three distinct change regimes: GitHub removed 8 operations and newly deprecated 7 (six of them t…
Thoughtbot published a consolidated collection of its agent skills in the thoughtbot/skills GitHub repository, making publicly available a set of Claude-compatible skills the consultancy had previousl…
GitHub shipped three Actions changes on September 3, 2026: a runner deprecation REST API, a new `vulnerability-alerts` permission for `GITHUB_TOKEN` that grants read-only Dependabot alert access witho…
A developer outlines a four-pillar Application Security program that uses AI to filter false positives from SAST findings, auto-generate STRIDE threat models, and enforce tiered guardrails rather than…
A developer built Release Radar, an AI agent that detects deprecated dependencies by reading repository descriptions and release notes, after discovering that tutorials for Amazon Bedrock AgentCore's …
GitHub has introduced automations in its GitHub Copilot app that allow developers to triage Dependabot pull requests automatically, grouping them by risk, verifying CI status, and delivering a summary…
Coding agents that install dependencies at machine speed make registry-side vulnerability checks and install blocking a critical choke point, according to Omniline's blog. The article argues that huma…
A 2025 Veracode analysis of over 100 large language models found that 45% of AI-generated code causes known security issues and vulnerabilities, while human review effectiveness drops after 400 lines …
Plannotator, a free, MIT/Apache-2.0 licensed local code review tool, launches with a diff viewer for git, jj, and Perforce, supporting local diffs, commits, branches, worktrees, and GitHub/GitLab PRs.…
Repairo, a new CLI tool for TypeScript and OpenAPI, detects breaking API changes and automatically opens a pull request with fixes, claiming zero AI hallucinations and zero data retention. The tool, b…
A developer describes the shift in application security from merely detecting vulnerabilities to automatically fixing them, enabled by AI agents that can reproduce bugs, write tests, and iterate on pa…
Sentinel, a new open-source tool, detects breaking changes in vendor API changelogs before they affect customer codebases, scans repositories for affected usages, and opens a pull request with fix dif…
GitHub made a three-day cooldown the default for Dependabot version updates on July 14, and PyPI began rejecting new files uploaded to releases older than 14 days on July 22, betting that patience bea…
MyZubster, a project running on Monero's Tari sidechain, is deploying GitHub Actions and automated bots to handle issue triage, dependency management, Rust linting, and testing. The workflow uses Depe…
GitHub shipped /security-review to its Copilot desktop app on July 14, putting AI-powered pre-commit vulnerability scanning in front of every Copilot user, including those on the free tier, without re…
GitHub has shipped a pre-commit vulnerability scanning feature for Copilot, available to all subscribers including Free tier users. The slash command scans uncommitted diffs for five OWASP vulnerabili…
GitHub Copilot launched a public preview of /security-review, an AI-driven slash command that scans in-flight diffs for high-confidence security vulnerabilities before code is committed. The feature, …
GitHub released a public preview of the `/security-review` slash command in the GitHub Copilot app, enabling developers to run AI-driven vulnerability scans on in-flight code changes directly from the…