Browse All Posts (145)
Daniel Roth and Jon Galloway introduce the new Blazor AI Components and show how they can be used to build agent-centric Blazor apps where AI participates in the UI, drives workflows, and takes actions beyond a simple chat experience.
Allison announces the deprecation of several AI models across GitHub Copilot experiences and explains what Copilot Enterprise admins may need to change to keep model selection working in Copilot Chat and other modes.
John Savill runs through the Azure Weekly Update for 2nd October 2026, covering a mix of retirements and new capabilities across compute, containers, storage, databases, Arc, and regional expansion, plus an AI model availability update.
John Edward explains Microsoft’s 2026 retirement of SharePoint Online’s one-time passcode (SPO OTP) flow and the shift to Microsoft Entra B2B guest accounts for external sharing in SharePoint Online and OneDrive, including what breaks, what stays, and what admins should do before the October–November rollout completes.
Julia Kasper introduces Project HydraFusion, an experimental GitHub Copilot CLI capability that routes prompts across multiple AI models based on intent. The session explains HydraFusion’s execution patterns (single, cascade, critique), shows efficiency-focused demos, and covers transparency goals like reducing user bias in model selection.
GitHub closes out Universe with a Day 2 keynote focused on building in the open, featuring open source voices and live demos aimed at developers working with GitHub.
GitHub opens Universe Day 1 with a keynote on where software development is heading and how GitHub is evolving its tools and workflows, including GitHub Copilot. The session is positioned around announcements and demos aimed at helping developers build and ship software more effectively.
Allison announces new read-only fields and filters for the GitHub GraphQL SecurityAdvisory API, making it easier to query advisory metadata (like CVE and NVD timestamps) and filter results server-side for security and compliance integrations.
Allison announces a GitHub Security Advisories update that lets maintainers add confidential comments to repository security advisories, keeping sensitive investigation and coordination notes visible only to users with write access.
Allison announces a public preview REST API that lets you read, add, and edit comments on GitHub repository security advisories, making it easier to automate vulnerability triage notes, export advisory discussions for audits or migrations, and build workflows around advisory discussion activity.
Fokko at Work walks through the key updates in Visual Studio Code 1.140 with a focus on GitHub Copilot changes, including HydraFusion and new session capabilities. The video uses short demos to show how the features work and notes that availability can depend on enterprise policies and licensing.
Microsoft Developer explains how to evaluate Azure AI Foundry Model Router against a baseline model (for example GPT-5) to understand cost, latency, and quality trade-offs, using the open-source Model Router Auto Evaluation toolkit and its HTML dashboard output.
Allison announces daily rate limits for GitHub private vulnerability reports, aimed at reducing bulk and automated submissions while keeping legitimate researcher reports flowing. The update adds per-account caps, repository-level customization, and an allow list for trusted reporters, configured via GitHub Advanced Security settings.
Allison announces structured forms for GitHub private vulnerability reports, adding required fields and optional enforcement (like CWE selection) to improve report quality while keeping existing REST API integrations working unless a custom form is enforced.
Carlotta Castelluccio introduces the Foundry Toolkit for Visual Studio Code and how it brings common AI workflows—model selection, prompt testing, and wiring agents—directly into VS Code to reduce context switching while building AI-powered apps.
Allison announces a public preview feature that lets GitHub Copilot interact with desktop apps via “computer use” in Copilot CLI and the GitHub Copilot app on macOS and Windows, including cross-app workflows with user approval and configurable permissions.
Allison announces the retirement of the GitHub Actions macOS 14 runner image on November 2, 2026, including scheduled brownout windows where macOS 14 jobs will fail and the workflow label updates teams should make to move to supported macOS arm64 runner images.
Allison’s September 2026 changelog summarizes GitHub Copilot updates in VS Code v1.136–v1.140, focused on agent-driven workflows from implementation through pull request merge. It highlights new Agents window capabilities, scheduled automations, agent merge for handling review feedback and conflicts, and smoother context sharing across workspaces and Dev Containers.
Allison announces a GitHub repository UI improvement that highlights an ACCESSIBILITY.md file on the repository overview and adds a shortcut in the sidebar, making accessibility statements easier to discover and propose via the Community Standards page.
Allison announces an update to GitHub Actions retention: checks, workflow runs, and statuses are now cleaned up using the same retention setting as artifacts and logs, with enterprise/org caps still applying and public repos capped at 90 days.
Allison announces a change to GitHub code scanning default setup and GitHub Code Quality: weekly scheduled scans now start only after a push or pull request triggers an analysis, reducing unexpected scans on dormant repositories when rolling out security configurations at scale.
Allison announces an improvement to the GitHub Code Quality upload-code-coverage action: coverage uploads won’t fail CI when pushing a new branch that doesn’t yet have an open pull request. The action now skips the upload and explains why, while default-branch and PR-event uploads continue to work as before.
Allison announces dynamic workflows for Copilot CLI, the GitHub Copilot app, and the GitHub Copilot SDK, a way to define repeatable multi-agent orchestration in code with checkpoints, parallel tasks, and structured handoffs between stages.
Allison announces that GitHub’s redesigned dashboard is now the default experience, bringing issues, pull requests, and active agent sessions into a single view with configurable filters and a separate Feed tab.
Microsoft Developer hosts a Data Exposed episode with the Azure SQL product management and engineering team, explaining how Azure SQL Database Hyperscale implements vector indexing (DiskANN) to support fast approximate vector search, filtering, and DML at scale, including billion-row scenarios and GA availability.
Andrea Griffiths shares 10 GitHub Universe 2026 sessions she’s building her agenda around, spanning Copilot agent memory and evals, MCP context and authorization, npm dependency provenance, and supply-chain defenses for GitHub Actions—plus a few talks on JavaScript tooling and building for low-connectivity environments.
Allison announces the general availability of GitHub’s async merge API, which lets automations merge individual or stacked pull requests, add PRs to a merge queue, and track merge progress without blocking on long-running merges.
Matthew Thomas summarizes findings from the 2026 Microsoft Digital Defense Report for government organizations, highlighting faster attacker timelines, increased phishing and identity compromise, and why resilience now depends on planning for incidents that spread across interconnected partners and essential services.
Terrell Cox highlights themes from the 2026 Microsoft Digital Defense Report, focusing on how an increasingly interconnected environment changes both attacker workflows and defender practices, including the growing role of AI in social engineering, vulnerability discovery, and enterprise security operations.
Allison announces Actions Runner Controller 0.15.0, focusing on operating GitHub Actions runner scale sets on Kubernetes with fewer disruptions during upgrades. The release improves in-place patch upgrades, shutdown behavior, scale set re-registration, API payload size, metrics-based status aggregation, and configurable rate limits and controller concurrency.
Eric van Wijk announces the general availability of GitHub-hosted agents in Azure Pipelines, including pay-as-you-go billing and new macOS SKUs, plus preview Linux and Windows SKUs. The post explains available VM images and rates, how to enable the new agent pool, how to target it from YAML, and how to monitor minutes and costs.
kinfey describes a hands-on experiment comparing a traditional GitHub Copilot tool-calling agent loop with a Jev-based “decision harness” that produces typed choices and confidence signals before execution. The post focuses on splitting responsibilities between models and ordinary code to reduce unnecessary model work and improve observability.
Wiliam_Rosa breaks down Lakeflow in Azure Databricks, explaining how it unifies ingestion, transformation, and orchestration, and why Unity Catalog-based governance and lineage can reduce the “glue work” of multi-tool data engineering stacks.
Christine Caggiano explains how a multidisciplinary team used the Microsoft Discovery app to design an inspectable, reproducible bioinformatics workflow for phage therapy—connecting curated literature, genomic analysis, and external tools via MCP-based adapters, with validation steps and safety checks built into each stage.
paulyuk introduces the Azure Functions Hosted Skills canvas inside the GitHub Copilot app, showing how to build and test an event-driven Function App locally, invoke triggers on demand, and debug runs with logs and evidence links. The post also covers deployment to Azure with azd and exposing skills as MCP tools.
Allison announces an update to npm trusted publishing that lets maintainers opt in to managing dist-tags using short-lived OIDC credentials, reducing reliance on long-lived access tokens for post-release tag changes like promoting versions to latest or updating next and beta.
sbaynes describes how the Microsoft Discovery app can help scientists and data teams design an inspectable, reproducible bioinformatics workflow for phage therapy research, from profiling antibiotic resistance and bacterial defenses to searching environmental metagenomic data and ranking candidate phages with traceable evidence and validation steps.
shashankamalladi announces the general availability of Network Security Perimeter (NSP) metrics and explains how to use Azure Monitor to track allowed/denied access, spot unexpected traffic, and validate access rule changes with dashboards, workbooks, and metric alerts.
Lindsay Myers outlines what to expect from the Microsoft Security track at Microsoft Ignite 2026, including the Security Pre-Day, key session formats, and four themes focused on agentic SOC operations, securing AI and agents, Zero Trust foundations, and data protection with Microsoft Defender and Microsoft Purview.
David Burg shows how to use the Azure Connectors SDK (preview) to call Azure Logic Apps/Power Platform connectors from a .NET 10 Azure Functions app, including creating a Connector Namespace, authorizing an Office 365 connection, wiring up a connector trigger, and deploying securely with managed identity.