// updates

What's new at the club

Follow with RSS
  1. Workshop
  2. Events
  3. Epoch

    Epoch is coming in December

    Our flagship fest runs on its own currency. Everyone gets 398 Epoch Coins at check-in to spend across 21 booths.

  4. Website

    A new home for the club

    Join in one step, add every event to your calendar, learn Git at your own pace, and carry your Epoch wallet on your phone.

// shipped on github

What GitHub shipped lately

Straight from GitHub's own changelog. Knowing what's new is half of knowing GitHub.

github.blog/changelogupdated hourly
  1. CopilotCode scanning AI Scan enablement status in security overview (opens the GitHub Changelog)

    Organization and enterprise administrators can now see AI Scan for pull requests enablement status in the security overview coverage view.

  2. SecuritySecret scanning adds detectors for Lovable, Supabase, and more (opens the GitHub Changelog)

    Secret scanning now detects new secret types from Lovable Labs, Pydantic Services Inc., and Supabase.

  3. PlatformStateless GitHub App installation tokens rolled out (opens the GitHub Changelog)

    The staged rollout of the stateless GitHub App installation token format, which began on April 27, 2026, is complete.

  4. CopilotCopilot code review: API support and new default effort level (opens the GitHub Changelog)

    You can now request a GitHub Copilot code review through the REST and GraphQL APIs and set the review effort level for each request.

  5. PackagesUnvalidated npm trusted publishing configurations now expire (opens the GitHub Changelog)

    Unvalidated npm trusted publishing configurations now expire 48 hours after creation and can no longer authorize publishing.

  6. Packagesnpm staged publishing now supports creating new packages (opens the GitHub Changelog)

    You can now create a new npm package with npm stage publish, using a local session or a granular access token, including a stage-only token.

  7. CopilotSelected models in GitHub Copilot deprecated (opens the GitHub Changelog)

    As of today, October 2, 2026, we have deprecated the following models across all GitHub Copilot experiences (including Copilot Chat, inline edits, ask and agent modes, and code…

  8. SecurityNew fields for SecurityAdvisory GraphQL API (opens the GitHub Changelog)

    You can now read more of the GitHub Advisory Database directly from the GraphQL API without falling back to the REST API.

  9. SecurityConfidential comments on repository security advisories (opens the GitHub Changelog)

    You can now post confidential comments on repository security advisories.

  10. SecurityRepository security advisory comments API in public preview (opens the GitHub Changelog)

    You can now read, add, and edit comments on repository security advisories using the REST API, including advisories created from private vulnerability reports.

Everything on the GitHub Changelog GitHub's RSS feed