Best of GitHubJuly 2026

  1. 1
    Article
    Avatar of hnHacker News·7w

    Why developers are ditching GitHub for Codeberg and self-hosting alternatives

    GitHub remains dominant by the numbers, but a growing number of open source projects are migrating away due to concerns over frequent downtime, Microsoft's ownership, AI training on code, and political direction. High-profile departures include Ghostty (a terminal emulator), Tenacity (an audio editor), the Dillo browser, and the Hare programming language. Alternatives gaining traction include Codeberg (powered by Forgejo), Sourcehut, Gitea, and self-hosted forges. The Software Freedom Conservancy also runs an active campaign encouraging developers to leave GitHub.

  2. 2
    Article
    Avatar of theregisterThe Register·7w

    GitHub AI agent leaks private repos when asked nicely

    GitHub's AI agent has a vulnerability that allows private repository data to be leaked when prompted in a certain way. The issue, dubbed 'GitLost,' has no fix and no official documentation from GitHub addressing it.

  3. 3
    Article
    Avatar of github_updatesGitHub Changelog·8w

    GitHub Models is being fully retired on July 30, 2026

    GitHub Models is being fully retired on July 30, 2026. This affects all customers — the playground, model catalog, inference API, and BYOK endpoints will all be shut down. Scheduled brownouts on July 16 and July 23 will serve as advance warnings. Existing users are directed to Azure AI Foundry for model access or GitHub Copilot for AI workflows within GitHub.

  4. 4
    Article
    Avatar of dotnet.NET Blog·6w

    Announcing .NET Modernization for Beginners

    Microsoft has released a free, open-source, hands-on course called '.NET Modernization for Beginners' to help developers upgrade legacy ASP.NET applications to .NET 10 using the GitHub Copilot modernization agent. The four-chapter course covers assessment, planning, upgrade execution, and cloud deployment to Azure App Service. Unlike typical agentic tools, the GitHub Copilot modernization agent produces transparent, editable artifacts (assessment.md, plan.md, tasks.md) that developers review and adjust before any code changes occur. A GitHub Copilot subscription and Visual Studio 2022 (17.10+) are required.

  5. 5
    Video
    Avatar of primeagenThePrimeTime·4w

    The Anti-Github

    Codeberg, a FOSS-focused GitHub alternative, has updated its terms of use to ban projects that mostly consist of AI/LLM-generated code, and also prohibits cryptocurrency projects. The author breaks down Codeberg's reasoning from their blog: unclear copyright status of LLM training data (copyleft concerns), community trust erosion from low-effort AI submissions burdening maintainers, and rising hardware/hosting costs exacerbated by AI crawlers and mass commits. The author agrees with the copyright and community arguments but strongly disagrees with Codeberg's negative framing of single-use software, arguing that vibe-coded throwaway projects are actually valuable for rapid experimentation. The post also contextualizes Codeberg as a small nonprofit that shouldn't be held to the same standards as GitHub, a Microsoft-backed platform.

  6. 6
    Article
    Avatar of jetbrainsJetBrains·5w

    What’s New in RustRover 2026.2

    RustRover 2026.2 ships several notable improvements: axum and reqwest support with URL resolution, endpoint discovery, and route-handler navigation; Ferrocene toolchain integration via criticalup; an interactive declarative macro tester showing expansion and input-output mapping; Criterion benchmark run configurations launchable from the gutter; smarter import cleanup with fewer false positives; local variable completion inside struct literals; .env file support with completion and navigation; a faster Copy Reference action for fully qualified Rust paths; and smoother editing in split/remote mode. On the AI side, the release adds an agent skills manager for persistent domain knowledge, support for third-party OpenAI-compatible providers in AI completion, and native GitHub Copilot integration via a JetBrains-Microsoft partnership.

  7. 7
    Article
    Avatar of dotnet.NET Blog·7w

    Modernize .NET applications in the GitHub Copilot app

    GitHub Copilot now includes an interactive upgrade canvas in the GitHub Copilot app for modernizing .NET applications. The upgrade agent assesses the application, identifies NuGet package updates, breaking API changes, and project dependencies, then generates a structured upgrade plan with actionable tasks. Progress is tracked in a single live view covering assessment, planning, execution, build failures, and results. The feature is also available in Visual Studio, VS Code, and the GitHub Copilot CLI. Setup requires installing the upgrade-agent plugin from the GitHub Copilot marketplace.

  8. 8
    Article
    Avatar of github_updatesGitHub Changelog·7w

    Per-user budgets for cost centers in the billing UI

    GitHub Enterprise Cloud now lets enterprise admins create per-user AI credit budgets for cost centers directly in the billing UI, without needing the REST API. Admins can add teams or individual users to a cost center, set a single per-user budget, and have it automatically apply to all members. Budget coverage stays in sync as team membership changes, eliminating manual reconfiguration.

  9. 9
    Video
    Avatar of codingwithlewisCoding with Lewis·4w

    I Built an App That Finds if Your App Already Exists

    A developer built a tool that scrapes ~15,000 GitHub repositories into Supabase and uses pgvector for semantic similarity search to check whether your app idea already exists. An LLM then explains how existing projects compare to your idea, helping you avoid rebuilding something already abandoned by someone else.

  10. 10
    Article
    Avatar of ghblogGitHub Blog·7w

    Automating cross-repo documentation with GitHub Agentic Workflows

    The Aspire team (microsoft/aspire) built a cross-repo documentation automation pipeline using GitHub Agentic Workflows. When a product pull request merges, a workflow called pr-docs-check automatically drafts a documentation pull request in the separate aspire.dev repo, assigns the original feature's SME as reviewer, and posts a link back to the source PR. The system uses a scoped GitHub App token limited to exactly two repos, a safe-outputs handler that separates agent reasoning from write actions, and milestone-to-release-branch mapping for accurate targeting. Over a 30-day window spanning Aspire 13.3 and 13.4, 82 docs PRs were created with a 100% merge rate and median time-to-merge of 44.8 hours. The post covers the security model, lessons learned (over-eager docs detection, cross-repo checkout patterns, prompt budget management), and four additional companion workflows also running in production.

  11. 11
    Article
    Avatar of freecodecampfreeCodeCamp·5w

    The New Agency Stack: How Dev Shops Use Claude, Cursor, and Copilot in Production

    Dev agencies have shifted AI coding tools from experimental to production-standard. Most now use a three-layer stack: chat assistants (Claude, ChatGPT) for planning and architecture, AI-native editors (Cursor) for building features across codebases, and inline assistants (GitHub Copilot) for boilerplate. The real-world workflow keeps humans in the loop — engineers break work into small tasks, review every AI-generated line, and run code through normal pull request processes. AI has compressed MVP timelines from 4–6 months to 6–12 weeks and improved test coverage, but token costs for heavy agentic use are a new expense. A 'vibecode rescue' niche has emerged for fixing AI-built apps that hit stability walls. The agencies that succeed are those with senior engineers who know when to trust the tools and when to override them.

  12. 12
    Article
    Avatar of socketdevSocket·7w

    Malicious Go Module Exposes GitHub Malware Lure Network Span...

    Socket researchers uncovered Operation 'Muck and Load', a malware campaign that began with a malicious Go module impersonating a DNS/subdomain scanner. The module embedded hidden PowerShell execution that downloaded encrypted payloads from public dead-drop services (Pastebin, YouTube, Instagram, Telegram), ultimately deploying AsyncRAT, Quasar, Remcos RATs, Vidar infostealer, and Monero cryptominers via password-protected archives. Pivoting from the initial module revealed a GitHub lure network of 222 confirmed repositories across 190 accounts, all using automated commit-farming GitHub Actions workflows to appear active and legitimate. The repositories targeted users seeking crypto tools, wallet utilities, game cheats, and offensive tooling. At least 14 confirmed malware files were found across the network. The malicious Go module has been blocked from the Go module proxy, and GitHub has been notified. The campaign overlaps with previously reported ischhfd83-linked repository-backdoor activity.

  13. 13
    Article
    Avatar of collectionsCollections·4w

    Visual Studio July 2026 Copilot update: new SDK-based agent, built-in skills, and org-wide instructions

    The July 2026 Visual Studio update brings several Copilot improvements: a new agent built on the GitHub Copilot SDK (public preview) for a more consistent experience across CLI, VS Code, and Visual Studio; built-in .NET and Azure skills in the agentic tool picker; a 'Review Selection' feature for inline code review comments; org-wide custom instructions for Copilot Business/Enterprise plans; branch context attachment in Copilot Chat; and a new opt-in C++ toolset auto-discovery property for MSVC builds.

  14. 14
    Video
    Avatar of ericparkerEric Parker·6w

    What this "Fixed Version" is really doing?

    A malware campaign is targeting GitHub issue trackers across popular open source projects, including Claude Code's repository. Attackers post fake 'fix' links in issue comments, leading victims to download a ZIP containing a legitimate Windows executable (MPDLP service) bundled with a malicious DLL. Analysis reveals the payload is a multi-stage info stealer (StealC and Vidor) that spawns hidden browser windows to bypass app-bound encryption, exfiltrates credentials, and uses Telegram as a resilient C2 fallback. The campaign spans many projects (Godot, data visualization tools, etc.) and uses newly created GitHub accounts. Defensive recommendations include common-sense URL scrutiny, application allowlisting tools like ThreatLocker, least-privilege access, and zero-trust architecture to limit blast radius from a single compromised endpoint.

  15. 15
    Article
    Avatar of jetbrainsJetBrains·6w

    What's New in IntelliJ IDEA 2026.2

    IntelliJ IDEA 2026.2 has been released with several notable updates. Key highlights include day-one support for Java 27 and Kotlin 2.4 stable features, native GitHub Copilot integration, new AI agent skills, and AI completion support for third-party providers. Productivity improvements include logpoints for debugging, dependency completion, early Gradle 10 support with migration assistance, streamlined Git conflict resolution, and Docker Compose improvements. The release also adds Spring support improvements, a Terraform testing framework, and TypeScript 7.0 support.