Browse All Posts (138)

.NET Team announces upcoming NuGet.org publishing security changes: new API keys will be capped at 30 days starting August 17, 2026, and older keys will expire on November 1, 2026. The post explains the supply-chain risk of long-lived secrets and recommends migrating to NuGet Trusted Publishing using OIDC.
News
Allison announces general availability of GitLab-to-GitHub migrations using GitHub Enterprise Importer, including a self-serve GitHub CLI extension for single-repo and bulk migrations, plus options for staging migration archives in GitHub storage, AWS S3, or Azure Blob Storage.
News

ASP.NET Community Standup: What's new in .NET 11 Preview 7?

Daniel Roth and Javier Calvarro Nelson tour what’s new for ASP.NET Core and Blazor in .NET 11 Preview 7, including Blazor output caching, QuickGrid virtualization improvements, and changes to Blazor Server circuit behavior.
Videos
Tzvia introduces Eventhouse in Microsoft Fabric and explains how it helps data engineers ingest, store, and analyze high-volume streaming event data in near real time, reducing the usual tuning and plumbing required for streaming workloads.
News
GitHub demonstrates how to clean up and submit stacked pull requests using the GitHub CLI stacked PRs extension, including inspecting PR layers, folding redundant commits, renaming layers, and submitting PRs for sequential review and merge on GitHub.
Videos
John Savill explains Azure Standard Service Endpoints, focusing on how Network Identifiers (NIDs) simplify and scale VNet-to-PaaS access, and how they work alongside Network Security Perimeter controls for securing inbound access to supported Azure services.
Videos
John Savill gives a quick overview of Azure’s new Standard service endpoints, focusing on what they are and why they matter for networking scenarios that connect VNets/subnets to Azure platform services.
Videos
John Edward explains Microsoft’s retirement of support for the Microsoft Entra SSO plug-ins used with self-hosted Atlassian Jira and Confluence (Server/Data Center), what “unsupported” means in practice, and the security and operational risks organizations should plan for after July 31, 2026.
Blogs
John Edward breaks down what GitHub Copilot does (and doesn’t) send to the service, how training and retention settings vary by subscription, and the practical security risks teams should plan for when using AI-assisted coding in real projects.
Blogs
This week's DevOps roundup is anchored in supply chain hardening, with npm adding publish-time malware scanning, dual-use metadata requirements, and tighter 2FA enforcement that will change how automated releases behave. GitHub followed up with new guardrails in Actions and Dependabot, including approvals for suspicious workflow runs and broader malware advisory coverage to slow down common abuse paths. On the delivery side, stacked pull requests moved into public preview (and into the Copilot app), while Copilot governance expanded with MCP connections, enterprise managed settings, and clearer cost controls. We also cover practical platform work: Terraform AzureRM 5.0 GA, policy-driven Log Analytics retention, Azure APIM AI Gateway preview, and tooling updates that make agents easier to debug and safer to operate.
Roundups
This week's AI roundup centers on turning fast-moving model and agent ecosystems into something you can run in production: governed, observable, and cost-controlled. GitHub retired GitHub Models while Copilot continued rotating available models, pushing enterprises to tighten policy management, managed settings, and usage reporting. At the same time, MCP gained more standardized building blocks (including the MCP C# SDK v2.0 and broader IDE integrations), and Azure added more runtime control points through API Management's AI Gateway tier and new cost-management toolsets for agents.
Roundups
Pamela Fox shares the materials from the “Microsoft IQ Deep Dive with Python” livestream series, showing how to ground AI apps and agents using Web IQ, Work IQ, Fabric IQ, and Foundry IQ via MCP endpoints, plus code samples, slides, and write-ups for building and deploying Python agents.
Community
This week's GitHub Copilot roundup focuses on model churn and tighter governance: Gemini deprecations forced admin action, while new default enablement and team-targeted model policies changed how access evolves over time. GitHub Models retired, pushing model operations toward Microsoft Foundry while Copilot stays the developer-facing layer for chat, agents, and review. On the product side, Grok 4.5 and MAI-Code-1-Flash add new tradeoffs around context, latency, and token efficiency, and client updates across VS Code, Visual Studio, JetBrains, and the Copilot app make agent workflows easier to run at scale. We also cover the practical side of adoption, including expanded usage rollups, budget enforcement that can actually stop overages, and managed settings that extend to the Copilot app, cloud agent, and remote control.
Roundups
This week's Security roundup links attacker tradecraft with platform-side guardrails, starting with Microsoft's CaptiveCrunch reporting on Midnight Blizzard targeting travelers through captive portals and device code authentication abuse. On the supply chain front, npm and GitHub tightened automation paths with restrictions on bypass-2FA tokens, publish-time malware scanning, expanded malware advisories for Dependabot, and workflow runs that can be held for approval in public repos. Microsoft and Azure updates rounded out the week with identity and AI protections (including agentic SecOps and expanded external AI red teaming), plus concrete governance controls across Azure Policy, Fabric encryption, and data egress boundaries.
Roundups
This week's ML roundup focuses on turning ML work into repeatable, production-friendly systems. Microsoft outlined an API-driven GeoAI pipeline for generating GIS-ready vector layers from Earth observation imagery using the MARS model, while Microsoft Research shared Echoverse, a set of stateful synthetic environments with database-grounded verifiers to make computer-use agent training and evaluation more reliable. On the data platform side, Fabric and OneLake updates emphasized zero-copy access to telemetry and open table formats, stronger governance and outbound controls, and more operable real-time and Spark foundations that feed analytics and ML workflows.
Roundups
This week in Azure, the focus shifted from AI prototypes to production agentic apps, with GPT-5.6 now GA in Microsoft Foundry, stronger Agent Service hosting and observability, and practical IDE support in the Foundry Toolkit for VS Code. FinOps and governance got more actionable too, as MCP toolsets exposed cost and pricing data to agents, and APIM patterns tightened real-time enforcement for BYOK and token controls. On the platform side, Azure API Management introduced an AI Gateway tier in preview, Azure Monitor logs moved closer to Fabric and OneLake via zero-copy style previews, and Terraform AzureRM provider 5.0 GA landed with upgrade-impacting changes. The thread running through everything is clearer operational controls (identity, telemetry, policy, and budgets) that help teams ship AI and cloud workloads with fewer surprises.
Roundups
This week's .NET roundup centers on MCP becoming a practical foundation for agent tooling, with the MCP C# SDK v2.0 and new Agent Framework hooks that let agents discover skills at runtime with clearer safety boundaries. Visual Studio and VS Code also pushed further into agent-driven workflows, from a Copilot Chat Agent preview to an MCP-backed MSBuild binlog analyzer that can explain failures and performance bottlenecks. On the engineering side, the focus shifted to reliable automation (a unit-test agent that validates tests end-to-end and traced multi-agent orchestration with OpenTelemetry) plus a solid web security refresher on Fetch Metadata headers for defense-in-depth CSRF protection.
Roundups
GitHub shows how to use voice prompting in the GitHub Copilot app to quickly turn a spoken “brain dump” into a usable text prompt, helping you get started faster when you’re not sure how to phrase what you want.
Videos
Visual Studio Code shares a quick update that OpenAI reduced pricing for GPT-5.6 Luna and GPT-5.6 Terra, and points developers to try both models directly in VS Code.
Videos
Microsoft Threat Intelligence details CaptiveCrunch, a Storm-2945 (Midnight Blizzard) campaign abusing captive portals to manipulate traffic, deliver malware, and steal credentials and tokens. The post breaks down the CornFlake and ChocoShell toolchain, device code phishing against Microsoft Entra ID, and provides Defender/Sentinel hunting queries plus practical mitigations for travelers and enterprises.
News
Allison announces the deprecation of the Gemini 2.5 Pro and Gemini 3 Flash models across GitHub Copilot experiences, and explains what Copilot Enterprise admins may need to change in model policies so users can select supported alternatives in VS Code and on github.com.
News
Allison announces a public preview for GitHub Enterprise that lets Copilot admins target AI model policies to enterprise teams, so different groups can be granted additional models beyond an enterprise-wide baseline.
News

Scale limits in network security perimeter

shashankamalladi outlines updated scale limits for Azure Network Security Perimeter, including new hard limits for perimeters, profiles, rule elements, and associated PaaS resources, plus what changes apply to existing configurations through the 10/31/26 transition window.
Community
nelsontam introduces Microsoft’s MARS (Map Autoregressive) model on Microsoft Foundry and explains how it converts satellite imagery into GIS-ready vector map data. The post outlines an end-to-end workflow with Microsoft Planetary Computer Pro, including STAC/COG ingestion requirements and practical deployment settings for running geospatial feature extraction at scale.
Community
Allison announces a security change for npm: granular access tokens configured to bypass 2FA can no longer perform sensitive account, org, and package-management actions without an interactive 2FA challenge, and automated publishing should move to trusted or staged publishing.
News
Samantha Kubota introduces Echoverse, a set of high-fidelity synthetic “worlds” for training computer-use agents, and explains why depth (stateful workflows and database-grounded grading) matters more than sheer environment count. The post shares results from supervised fine-tuning and reinforcement learning, plus links to released code and datasets.
News
Alexander Neubeck explains how GitHub sped up Unicode case folding for code search by removing early-exit branches, enabling SIMD vectorization, and using byte-space arithmetic to avoid UTF-8 decode/encode work. The post also covers allocation-avoidance techniques and a compact lookup-table design for fast “does this fold?” checks.
News

Azure Update 31st July 2026

John Savill rounds up a week of Azure platform updates, spanning AKS, networking, API Management, monitoring, data services, and regional expansion, plus a few notable AI model availability items and security-related changes like Azure Enclave and Key Vault symmetric keys.
Videos
Amaury Levé introduces an open-source polyglot unit-test generation agent that learns a repo’s conventions, writes tests, and validates they build and run in the project’s normal test workflow. The post explains the agent’s research/plan/execute/check loop, shows benchmark results versus stock Copilot, and includes setup commands for Copilot CLI and VS Code.
News
TomClaes explains how to govern Azure Log Analytics retention across many workspaces by keeping workspace defaults low, setting per-table interactive retention, and using long-term retention only where needed. The post includes an Azure Policy-based, DeployIfNotExists solution with auditing, drift detection, and automated remediation.
Community
junjieli summarizes the July 2026 releases (1.6.3–1.6.6) of the Foundry Toolkit for VS Code, focusing on a flatter, tabbed workspace, inline tool wiring, deeper agent debugging via event-level inspection, and a new Agent Optimization preview that supports measured compare-and-deploy tuning for hosted agents.
Community
HimanshuYadav explains how to transfer a live GitLab project to a new group without accidentally “resetting” Terraform state or breaking pipelines, focusing on what changes during a namespace move (variables, runners, identity mappings) and how to validate and roll back safely.
Community
Zoran Jovanovic breaks down the main regional distribution patterns for Azure workloads—single region, failover, parallel (active-active), segmented, and portable—framing each as a deliberate reliability and risk decision with clear trade-offs around cost, complexity, RTO/RPO, and service capabilities.
Community
Authorised Territory demonstrates how a .NET MCP server can expose a skill as a resource, and how an AI agent client can use that skill to answer a question, using a locally running LLM via Ollama.
Videos
KishoreKumarPattabiraman explains how to choose between building an interactive “skill” and an autonomous “sub-agent” when designing reusable AI capabilities, using practical checks around iteration style, voice fidelity, review gates, risk blast radius, and frequency of reuse.
Community

Azure Developer CLI (azd) July 2026

Kristen Womack’s July 2026 roundup for Azure Developer CLI (azd) summarizes releases 1.27.0 through 1.29.0, including new extension install options, a full tool uninstall workflow, Azure AI Foundry resource modeling in azure.yaml, container deployments to Azure App Service, and CI-friendly non-interactive behavior plus a breaking flag rename.
News
diptiborkar summarizes why Microsoft Fabric and OneLake were recognized as a Leader in Forrester’s 2026 Data Lakehouses report, focusing on a unified lakehouse foundation for analytics and AI, open table formats, cross-cloud interoperability, and built-in governance and security across engines like Spark, SQL, KQL, and Power BI.
News
GitHub announces stacked pull requests and points to the official docs, focusing on how the feature helps teams review and manage a series of dependent changes more clearly.
Videos

GitHub Models is now retired

Allison announces the retirement of GitHub Models as of July 30, 2026, including the shutdown of the playground, model catalog, inference API, and BYOK support. The post also points teams to Microsoft Foundry for model access and GitHub Copilot for building AI-powered workflows on GitHub.
News
arindamc explains how Workspace Outbound Access Protection (OAP) in Microsoft Fabric controls outbound connectivity for Eventstream, so streaming pipelines can only read from approved sources and write to approved destinations (including cross-workspace routes) using data connection rules.
News

Rejoining the server...

Rejoin failed... trying again in seconds.

Failed to rejoin.
Please retry or reload the page.

The session has been paused by the server.

Failed to resume the session.
Please reload the page.