AI Agents, DevOps Changes, and Platform Security: Weekly Technology Update
Welcome to the weekly technology news summary, where new updates are shaping software development, DevOps practices, and platform security. GitHub Copilot launches a series of tools and integrations—highlighted by new GPT and Claude models, automation workflows, Agent Skills, Mission Control, improvements for real-time code review, and cross-platform context management. Copilot’s trajectory from a code completion tool to a broad developer platform is now more visible, with prompt design and AI literacy becoming key skills for development teams.
Microsoft introduces new agent-based AI frameworks through Azure AI Foundry, along with open orchestration tools and secure, scalable approaches for enterprise AI. Microsoft Fabric’s machine learning workflows benefit from an improved runtime and security-first enhancements. Azure delivers a range of infrastructure and governance updates, enhancing performance, networking, DevOps, and data engineering tools. Security remains a major focus, as teams manage vulnerabilities like React2Shell and adopt new resilience controls. As VS Code and .NET bring updated workflows and DevOps platforms adjust cost and integration models, developers and organizations are better prepared to use AI in their workflows—securely and effectively. Explore the most relevant stories for your team this week.
This Week’s Overview
- GitHub Copilot
- AI Model Releases and Chat Model Availability
- Agent Skills and Automation Ecosystem
- Integrated Workflows and Mission Control
- Code Review, Security, and Metrics
- IDE Integration, Debugging, and Language Support
- Prompt Engineering and Context Management
- Advanced Agent Capabilities and Memory
- Real-World Usage and Ecosystem News
- Effective Use of Copilot in Domain-Specific Contexts
- Other GitHub Copilot News
- AI
- ML
- Azure
- Coding
- DevOps
- GitHub Actions Self-Hosted Runners: Pricing Changes, Roadmap, and Community Impact
- Dependabot Expands Ecosystem: Conda, OpenTofu, Julia, Bazel Automated Updates
- Azure DevOps Productivity: Microsoft.Testing.Platform Integration and Security Workflows
- Microsoft Fabric and Azure DevOps: CI/CD Automation and Integration
- Other DevOps News
- Security
GitHub Copilot
GitHub Copilot introduced additional features this week, expanding its model choices and workflow tools to better serve development teams. OpenAI’s newest GPT models are now generally available, enhancing Copilot’s context-aware assistance across several IDEs. New rollouts include Agent Skills and a Mission Control dashboard, which extend Copilot’s usefulness for workflow automation and team customization. These improvements make Copilot more relevant for code review, issue tracking, and security tasks, reflecting its ongoing shift toward a complete developer productivity solution.
AI Model Releases and Chat Model Availability
GitHub Copilot’s list of supported AI models continues to grow. GPT-5.2 is now available on all plans, building on earlier GPT-5.1, GPT-5.1-Codex, and Codex-Max releases. Developers can access these models directly in supported tools, including VS Code, Visual Studio, JetBrains IDEs, Xcode, Eclipse, GitHub Mobile, and the GitHub website. The recent addition of Claude Opus 4.5 offers another model for users, while Gemini 3 Flash has entered public preview—demonstrating Copilot’s ongoing focus on giving organizations flexibility and more administrative control. These tools grant transparency and allow real-time model selection, making it easier to match team needs and governance policies.
- GPT-5.2 is now generally available in GitHub Copilot
- GPT-5.1 and GPT-5.1-Codex Now Available in GitHub Copilot
- GPT-5.1-Codex-Max Now Available in GitHub Copilot Across Platforms
- Claude Opus 4.5 Now Available in GitHub Copilot
- Gemini 3 Flash Public Preview Released for GitHub Copilot Users
Agent Skills and Automation Ecosystem
Developers can now use Agent Skills to organize and share reusable instructions following the open Skills.md standard. This helps standardize workflows and encourages sharing across teams. Community-curated repositories—such as ‘github/awesome-copilot’—enable faster onboarding and foster workflow automation. These additions support earlier work on creating repeatable, integrated DevOps flows.
- GitHub Copilot Now Supports Agent Skills
- Agent Skills (Skills.md) in GitHub Copilot for Visual Studio Code
Integrated Workflows and Mission Control
Mission Control is now available as a central tool for managing and observing agents, promoting better visibility into automated workflows. With real-time monitoring and tools for ensuring workflow consistency between local and cloud setups, Mission Control improves process management. The integration of Azure Boards with Copilot connects DevOps tracking directly with AI-aided code generation. New workflow options like manual branch selection and feedback tracking through Kanban boards also add to operational flexibility.
- Manage All GitHub Copilot Agents with Mission Control
- Azure Boards Now Integrates Directly with GitHub Copilot Coding Agent
- GitHub Copilot Coding Agent: Practical Automation Examples
Code Review, Security, and Metrics
With the latest update, organizations can enable Copilot code review feedback for all contributors—even those without licenses—which broadens accessibility and usage across teams. New features have been added for tracking review actions, managing usage metrics, and monitoring team-level activity. Mission Control integrates security scanning tools like CodeQL and ESLint, further supporting compliance needs. Administrators now have access to detailed metrics for pull request activity and Copilot usage, making tracking and reporting more straightforward.
- Copilot Code Review Now Available for Organization Members Without a License
- GitHub Copilot Code Review Preview Features Now Available in Enterprise Cloud with Data Residency
- Enhanced Copilot Autofix Metrics for CodeQL Security Overview on GitHub
- Enterprise Pull Request Metrics Now Included in GitHub Copilot Usage Metrics API
- Track Organization Copilot Usage with Copilot Usage APIs
IDE Integration, Debugging, and Language Support
Visual Studio 2026 delivers a new debugging experience powered by Copilot for faster startup and improved diagnostics. The Debugger Agent is now integrated with test tools, creating a more consistent workflow from coding through to solution diagnosis. New C++ code editing tools for VS 2026 Insiders enhance symbol support and refactoring in multilingual environments. Copilot-driven SQL features for VS Code are now generally available, with capabilities for traditional and vector database projects.
- Debugging, but Without the Drama: Visual Studio 2026’s Copilot-Powered Experience
- C++ Code Editing Tools for GitHub Copilot in Visual Studio 2026 Insiders Public Preview
- Next-Level SQL in VS Code: GitHub Copilot GA and AI-Ready SQL
Prompt Engineering and Context Management
Recent guidance helps developers apply prompt patterns—like Persona and Reflection—to refine Copilot’s support for specific use cases. Copilot can now generate dynamic prompts linked directly from GitHub documentation, bridging learning resources and AI code suggestions for a smoother workflow.
- Cook’n with GitHub Copilot: Recap of Context Engineering Prompt Patterns
- Dynamic Copilot Prompts Now Available on GitHub Docs
Advanced Agent Capabilities and Memory
Copilot introduces early access for repository-specific memory to Pro and Pro+ users, allowing agents to retain project knowledge and reduce repeated prompts. This addition follows ongoing improvements for agent persistence and more focused support on recurring automation.
Real-World Usage and Ecosystem News
Developer onboarding metrics show strong Copilot adoption. This week’s discussions reinforce the importance of AI fluency, prompt design, and open governance through standards like the Model Context Protocol. Security news—including the React2Shell vulnerability—connects to wider conversations about platform resilience and best practices.
- The Download: React2Shell Vulnerability, GPT 5.2 in GitHub Copilot, and Open Source News
- A New Kind of Developer is Emerging on GitHub
Effective Use of Copilot in Domain-Specific Contexts
A new resource explains how to configure Copilot for highly specialized languages and workflows. It covers using copilot-instructions.md, maintaining up-to-date reference files, and incorporating compiler validation to improve Copilot’s performance in unique environments. This pairs with community-led initiatives like DSL-Copilot and custom repository templates for real-world situations.
Other GitHub Copilot News
When users assign GitHub Copilot to an issue, they are now added as an assignee, further improving team transparency and workflow clarity.
AI
Microsoft is rolling out new options for building, orchestrating, and scaling AI agents. Azure AI Foundry adds open-source runtime, managed hosting, and developer guides to support a range of projects. Microsoft Fabric extends automation, insight into agent activity, and lower-code options for data transformation—reinforcing efforts to streamline enterprise AI development and operations.
Azure AI Foundry and the Expanding Agentic AI Ecosystem
Azure AI Foundry brings new open-source components for orchestrating secure and flexible AI agents. Hosted Agents now provide persistent memory and simplified management, with deployment and onboarding tools supporting rapid development. The bring-your-own-model (BYO Model Gateway) now includes broader LLM support, such as Claude, Sora 2, and Mistral. Developers can use the Model Router, now generally available, to optimize AI model usage and manage costs. New Foundry Tools and security enhancements with Entra Agent ID centralize AI governance. Feedback from Discord and GitHub channels continues to shape feature planning and onboarding.
- What’s New in Microsoft Foundry: Agents, Models, and Enterprise-Grade AI (October–November 2025)
- Getting Started with Azure AI Foundry: A Beginner’s Guide
- Getting Started with Azure AI Foundry
Agent-Oriented Architecture: Durable Task Extension and Orchestration Guides
Durable Task Extension enhances agent orchestration, making it simpler to manage dependable workflows. Examples like the AI Travel Planner demonstrate how agents can operate in sequence or in parallel. Human oversight and rollback features are supported for easier troubleshooting. Guides using Azure Functions, Static Web Apps, and OpenTelemetry continue to encourage best practices for agent communication and security.
- Building Reliable AI Travel Agents with the Durable Task Extension for Microsoft Agent Framework
- Best Practices for Architecting AI Agents in Enterprise Systems
Model Context Protocol (MCP) and Model Router in Developer Workflows
The Model Context Protocol (MCP) now features sessions that clarify how to link AI models, APIs, and data sources in daily work. Hands-on workshops and labs continue to build on this, while the new Model Router lets developers tune model use and integrate policies into agent workflows with better control.
- Leveraging the Model Context Protocol (MCP) in Visual Studio Code for Enhanced Development
- Using Foundry’s Model Router to Simplify Optimal AI Model Selection
Autonomous Agents and AI-Powered Data Transformation in Microsoft Fabric
Microsoft Fabric updates make agent consumption and billing reports more transparent, letting teams optimize usage and spending. Dataflow Gen2 gains AI-powered capabilities for prompt-based operations in Power Query, enabling summarization, classification, sentiment analysis, and translation directly—offering more advanced BI and analytics via easier-to-use interfaces and simple documentation.
- Understanding Operations Agent Capacity Usage and Billing in Microsoft Fabric
- AI-Powered Data Transformation with Dataflow Gen2 in Microsoft Fabric
ML
Machine learning on Microsoft Fabric benefits from quicker turnaround, more reliable orchestration options, and easier evaluation for document AI pipelines. New features boost large-scale analytics and streamline adoption for enterprise users.
Microsoft Fabric ML Platform Advances
Fabric Runtime 2.0 (experimental) debuts with Apache Spark 4.0 for scalable distributed processing. Additional upgrades include Java 21, Scala 2.13, Python 3.12, and Delta Lake 4.0, aiding migration and analysis speed. The year-end review covers improvements in platform security, migration help, Copilot access, improved SQL/KQL tooling, and consistent DevOps support—summarizing a year centered on usability and developer needs.
- Fabric Runtime 2.0 Experimental Preview: Scalable Data Engineering with Spark
- Microsoft Fabric 2025 Recap: Unified Data and AI Innovations
Performance, Reliability, and Security in ML Workflows
Fabric increases productivity with environment library management running up to 2.5 times faster for custom libraries, and Python Spark session startups now completing 70% quicker. New lightweight install modes are inbound for small deployments. Spark job orchestration supports Service Principal and Workspace Identity authentication, reducing reliance on user credentials in production pipelines. Updated documentation simplifies setup and migration.
- Fabric Environment Library Management Performance Improvements for Developers
- Run Spark Job Definitions in Pipelines with Service Principal or Workspace Identity
Evaluation and Best Practices for Azure-based Document AI Pipelines
A practical guide outlines deploying and evaluating document AI workflows with Azure. The resource covers building a ground truth set, technical steps (OCR, labeling, retrieval), error assessment, and performance tuning with continuous monitoring. It includes architecture diagrams and code examples for developers working on enterprise IDP projects.
Azure
Azure’s latest updates reinforce reliability, data management, modern migration pathways, and governance. Infrastructure improvements, end-of-life advisories, developer tooling, and messaging features are central themes.
Azure Networking, Resiliency, and Security Enhancements
This week’s networking improvements include 400 Gbps ExpressRoute options for high-demand workloads, increased VPN Gateway throughput, larger Virtual WAN and Route Server scaling, new forced tunneling and DNS Security rules, and automated failover scoring through ExpressRoute Resiliency Insights. A Copilot-based chatbot helps with networking troubleshooting.
Updates to Azure Front Door clarify new deployment procedures (configuration validation, rapid rollback, edge resilience validation) and future enhancement plans around safety and isolation. Note also the upcoming deprecation of Docker Content Trust for Azure Container Registry, with planned migration to the Notary Project.
- Azure Networking 2025: Powering Cloud Innovation and AI at Global Scale
- Azure Front Door: Hardening Configuration Resiliency After October Outages
- Azure Policy: Required Actions for Docker Content Trust Deprecation in Azure Container Registry
Migration, Modernization, and Strategic Guidance
Support for BizTalk Server ends in 2030; teams should migrate to Logic Apps and Integration Services. Existing mainframe connections remain supported through Host Integration Server, and tooling is available to help with these transitions.
Guidance for Oracle Database@Azure addresses deeper integrations and AI enablement, while Storage Account replication changes (LRS to GZRS) require planned downtime—see official resources for planning.
- Microsoft BizTalk Server Product Lifecycle Update: Modernization and Migration Guidance
- Modernizing Oracle Workloads with Oracle Database@Azure and AI Solutions
- Minimizing Downtime When Migrating Azure Storage Account Replication
Developer Tools, Language Ecosystems, and Hands-On Guides
The December release of the Azure Developer CLI (v1.22.x) enhances extension management, distributed tracing, and resource management. The release supports easier onboarding and new agent-style extensions are in planning.
Updated guidance covers building and deploying MCP servers with Python, using Azure services for authorization, networking, and observability. Azure’s year-end Python review discusses top packages and workflow trends for Python developers.
- Azure Developer CLI (azd) December 2025: Extensions, Foundry, and Pipeline Updates
- Building and Deploying MCP Servers with Python and Azure
- Python on Azure: 2025 Year in Review – Trends, Learning, and Future Directions
Messaging Patterns, Data Engineering, and Microsoft Fabric Features
Azure Service Bus Premium supports active geo-replication for improved continuity. Developers benefit from workflow patterns—sessions, scheduling, retries, and dead-letter handling—for robust agent backends. SQL Telemetry on Microsoft Fabric highlights new analytics options, with autoscaling, data quality tools, and real-time analytics. Fabric adds support for DATE_BUCKET() and Eventstream SQL operator, providing improved time-series and event-based workflows.
- Announcing General Availability of Geo-Replication for Azure Service Bus Premium
- Enterprise Messaging Patterns for Agentic AI Backends with Azure Service Bus
- Building a Petabyte-Scale Data Platform with Microsoft Fabric and SQL Telemetry
- Flexible Time-Based Reporting with DATE_BUCKET() in Microsoft Fabric Data Warehouse
- Fabric Eventstream SQL Operator: Real-Time Data Processing in Microsoft Fabric
- Microsoft Fabric Influencers Spotlight: December 2025 Highlights
Schema Management and Change-Driven Architecture
A new Azure schema language, JSON Structure, offers advanced typing, contract enforcement, and multi-language support. VS Code extensions and related tools simplify schema management. Drasi provides options for event-driven to change-driven migration, helping manage database change projections for phased modernization.
- JSON Structure: A Next-Gen Schema Language for Messaging on Azure
- Event-Driven to Change-Driven: Low-cost Dependency Inversion
Other Azure News
Developers can now manage Azure NetApp Files from VS Code using an extension with AI-powered features. The Azure Update for December 19th covers improvements for Service Bus triggers, NetApp ransomware protection, data platform enhancements, and more. Azure Arc monthly forum brings upgrades for agent automation and Linux support. There are also troubleshooting guides for Azure Virtual Desktop and Data Gateway releases. Microsoft continues contributions to Fedora Linux and now offers GitHub Enterprise Cloud data residency in Japan. SQL Server and Azure SQL year-in-review posts track overall advancement in the data ecosystem.
- Streamline Azure NetApp Files Management Directly from VS Code
- Azure Update - 19th December 2025: Service Improvements, AI, and Security News
- Azure Arc Monthly Forum Recap – November 2025
- Troubleshooting User Session Issues in Azure Virtual Desktop (Pooled Host Pools)
- On-Premises Data Gateway December 2025 Release: Manual Update Preview and Power BI Desktop Compatibility
- Microsoft’s Contributions to Fedora Linux: Cloud Delivery, Security, and Azure Integration
- GitHub Enterprise Cloud Data Residency Now Available in Japan
- 2025 SQL Year in Review: SQL Server, Azure SQL, and Fabric Updates
Coding
Developer-focused platforms rolled out updated workspace experiences, expanded roadmaps, and improved diagnostics. VS Code and Cursor Editor offered fresh productivity features, and .NET teams gained new widgets guidance and transparent roadmap planning.
.NET Development: Cross-Platform Widgets and ASP.NET Core Roadmaps
A .NET MAUI walkthrough demonstrates how to build interactive iOS widgets leveraging shared .NET logic and integrating Swift for platform-specific needs. ASP.NET Core’s .NET 11 planning is underway, with opportunities for community input and transparent discussions—helping teams prepare for migration and long-term design decisions.
- Building iOS Widgets with .NET MAUI: From Setup to Interactive Features
- ASP.NET Core Planning Kickoff for .NET 11
- ASP.NET Core Server & APIs Roadmap Discussion for .NET 11
Editor Experiences: VS Code and Cursor AI Updates
VS Code 1.107 launches inline chat editing, advanced renaming, and persistent local agents for background tasks. Cursor AI Editor 2.2 introduces a visual workflow designer and quick access to LLM options but continues to draw developer concerns over frequent interface changes and complex pricing. These updates feed into broader conversations about balancing speed, usability, and control.
- VS Code 1.107 Release Highlights
- AI-Driven Cursor Editor Adds Visual Designer Amid Developer Frustrations
Practical Profiling and Feedback Workflows
A new guide details profiling the .NET CLR using C# and Silhouette, removing the dependency on C++ for diagnostics and performance monitoring. Another post explains how Visual Studio’s feedback process uses transparent triage and prioritization to connect developer suggestions directly to product improvements.
- Creating a .NET CLR profiler with C# NativeAOT and Silhouette
- How Visual Studio Feedback Improves the Developer Experience
DevOps
The week brings cost model updates, dependency coverage improvements, workflow automation, and CI/CD integrations—addressing developer feedback and team needs.
GitHub Actions Self-Hosted Runners: Pricing Changes, Roadmap, and Community Impact
Starting in March 2026, GitHub will charge for self-hosted Actions runners on private repositories ($0.002/min), while maintaining free access on public repositories and Enterprise Server. Lower costs for hosted runners offset the change for most users, but planning and migration resources are central to the transition. Competitive alternatives (e.g., Depot), coming platform support, better workflow metrics, and ongoing documentation updates aim to ease migration.
- GitHub to Charge for Self-Hosted Runners on GitHub Actions Starting March 2026
- GitHub Actions Pricing Update: Lower Runner Costs, Platform Enhancements Coming in 2026
Dependabot Expands Ecosystem: Conda, OpenTofu, Julia, Bazel Automated Updates
Dependabot now offers automatic updates for Conda (popular with Python/data science), OpenTofu (IaC), Julia (scientific), and Bazel (build systems), broadening security and maintenance coverage. Documentation and troubleshooting resources help support this expanded ecosystem.
- Dependabot Adds Conda Ecosystem Support for Automated Version Updates
- Dependabot Adds Support for OpenTofu Dependency Updates
- Dependabot Adds Version Update Support for Julia
- Dependabot Version Updates Now Support Bazel
Azure DevOps Productivity: Microsoft.Testing.Platform Integration and Security Workflows
Azure DevOps now fully supports Microsoft.Testing.Platform—streamlining .NET test commands, automatic retries, and publishing of results. Vulnerability management links GitHub Advanced Security alerts to Azure DevOps Boards, streamlining issue triage and resolution.
- Azure DevOps Gains Full Support for Microsoft.Testing.Platform
- Work Item Linking for GitHub Advanced Security Alerts in Azure DevOps Now Available
Microsoft Fabric and Azure DevOps: CI/CD Automation and Integration
Microsoft Fabric now features direct guides for automating SQL database deployment with Azure DevOps. Secure connection support (service principal, OAuth 2.0) enables better CI/CD integration and supports complex automation scenarios across cloud environments.
- Performing CI/CD for SQL Databases in Fabric Using Azure DevOps
- How to Connect Microsoft Fabric to Azure DevOps Using Service Principal
Other DevOps News
GitHub Teams administration is now consolidated under the ‘Settings → Teams’ menu, promoting easier management. The Azure SRE Agent automates incident response by running playbooks and collecting evidence when triggered by alerts in PagerDuty, ServiceNow, or Azure Monitor—removing the need for manual intervention in multi-cloud environments.
- Teams Management Relocated to Settings in GitHub
- Automating On-Call Runbooks with Azure SRE Agent for Incident Response
Security
Security updates include actionable guidance for vulnerability management, improved dependency workflows, more options for compliance, and identity lifecycle changes—as well as strategies for evolving cloud access.
React2Shell Vulnerability Response Across Microsoft Defender and Azure
React2Shell (CVE-2025-55182) affects Next.js and Node.js workloads, with attackers exploiting React Server Component build pipelines. Recommendations include updating to secured frameworks, scanning assets with Microsoft Defender, setting up custom Azure WAF rules, and using Sentinel or Security Copilot for further analysis. Teams should establish a combination of automated and manual incident handling.
GitHub Security Ecosystem Updates: Dependabot uv Support, Code Scanning, Secret Management
Dependabot now supports uv packages, improving automated vulnerability tracking. Code scanning alert assignment via REST API is now generally available. CodeQL improvements boost detection for Go and Rust. Secret scanning governance has been expanded, and dismissing Dependabot alerts now requires a peer review. More organizations can access Advanced Security trials with the latest expansion.
- Dependabot Security Updates Now Support uv
- General Availability of Code Scanning Alert Assignees in GitHub
- CodeQL 2.23.7 and 2.23.8 Released: Enhanced Security Queries for Go and Rust
- Enterprise Governance and Policy Improvements for GitHub Secret Scanning
- GitHub Advanced Security Trials Expanded for Enterprise Customers
- Require Reviews for Dependabot Alert Dismissal with Delegated Alert Dismissal in GitHub
Evolving Cloud and Identity Security: TLS, Managed Identities, and Access Fabric Strategies
Azure App Service users should prepare for upcoming TLS certificate and authentication changes. Managed Identities for Azure Files SMB allow password-free access for automated agents, AKS nodes, and cloud applications. Microsoft’s Access Fabric moves device and network checks directly into access enforcement, supporting Zero Trust principles.
- Preparing for Industry-wide TLS Certificate Changes in Azure App Service (2026 Update)
- Secure Access with Managed Identities for Azure Files SMB
- Access Fabric: Modernizing Identity and Network Access Security with Microsoft Entra
Other Security News
A Microsoft e-book explains the benefits of unified, AI-capable security platforms (Defender, Sentinel, Copilot) for incident management. Also available is a practical guide for configuring Sensitivity Labels in Microsoft Teams, employing Purview Information Protection for automated policies, encryption, and compliance.