November ‘25 enterprise roundup
November 5, 2025 // 20 min read
In case you missed it…
Published via GitHub Executive Insights | Authored by Dave Burnison
This month's Roundup starts off with all of the key updates and sessions from GitHub Universe '25. Next, we have curated the most impactful updates, best practices, and strategic insights from GitHub’s own engineering playbook, blog posts, changelogs, whitepapers and other resources—each link is handpicked to help you and your teams ship faster, reduce toil, and unlock new levels of developer creativity. This is an invaluable resource for any software developer or engineering leader navigating the rapidly evolving landscape of AI-powered development, security, and platform governance.
We don't expect every person to read every word of this post. Skim through the topics that apply to how you and your teams use GitHub and dig into links that are the most relevant to you. Since some readers may skip over entire sections, you may see the same link appear in multiple sections such as a link that applies to both Code Security and CI/CD. Any one person will not read everything here but, across a team of several people, I wouldn't be surprised if every link is read by at least one of those team members. Pass this Enterprise Roundup along to your colleagues or pass along specific links that will be beneficial to others.
Prefer to get updates through podcasts? Check out the GitHub at Work Podcast. This is a great resource if you like to use your commute time, run/walk time, etc. as an opportunity to continually learn about the latest and greatest from GitHub.
Want to get notified of when the next Monthly Enterprise Roundup (MER) is available? Go to GitHub Enterprise on LinkedIn and click on the "Follow" button. In addition to MER notifications you'll be notified when new episodes of GitHub at Work Podcast and other enterprise focused content becomes available.
Contents at a Glance
- GitHub Universe ’25
- Events
- GitHub platform - Enterprise Management & Governance
- AI & ML – GitHub Copilot
- Security
- CI/CD
- Developer skills
- Engineering
- Legend
GitHub Universe '25
I encourage everyone to read this section regardless of your role or specific area of interest in GitHub.
GitHub Universe was this past October 28–29, it’s our biggest event of the year—bringing together enterprise leaders and engineering experts shaping the future with AI. This section highlights the available resources focused on enterprise governance, AI-powered development, enterprise-grade automation, and security best practices.
- 📺 Day 1 Announcements (10:40) - Catch the biggest announcements in this short video! We introduced Agent HQ, transforming GitHub into an open ecosystem for all coding agents (from OpenAI, Google, Anthropic, xAI & more). Plus, learn about new enterprise controls, Mission Control, Plan Mode, Custom Agents and more.
- 📺 "You have to be here": a look inside GitHub Universe 2025 (1:33) - Watch a quick overview of what it was like to be in person at GitHub Universe '25, see some of the industry leaders who were on stage and learn when to mark your calendar for Universe '26.
- 📢 Introducing Agent HQ: Any agent, any way you work - See all of the Day 1 Announcements in this GitHub Universe blog post. The post includes links to additional resources so that you can take a deep dive into the announcements that you find most intriguing.
- 🌐 GitHub Universe · Recap - Catch up on the key announcements shaping the future of software development. This recap leads you to the resources you need to dive in and learn more, such as blog posts, changelogs, features summaries and documentation. The recap is broken down into the following areas:
- 🌐 Enterprise - Govern agent workflows at scale: Centrally manage your agents and custom agents, audit their activity, set security policies, create an MCP server allowlist, and configure what agents can and can’t access. GitHub Code Quality: Get org-wide visibility, governance, and reporting to improve code maintainability, reliability, and test coverage across every repository. Copilot metrics dashboard and API: Get a complete picture of Copilot usage across your enterprise with aggregated metrics on active users, feature adoption, model distribution, and code contribution—all in a single dashboard view.
- 🌐 Agents - Introducing Agent HQ: Agent HQ transforms GitHub into an open ecosystem that unites every agent on a single platform. Over the coming months, coding agents from Anthropic, OpenAI, Google, Cognition, xAI, and more will become available directly within GitHub as part of your paid GitHub Copilot subscription. Mission Control: Assign, steer, track, and review your agents and their complex tasks from a unified view across GitHub, Mobile, CLI, and VS Code. Customize agents with the tailored prompts, tools, and context optimized for specific development tasks and share them across your team.
- 🌐 Workflows - Wherever you work, from chat conversations to project tracking tools, Copilot keeps your flow moving. Assign tasks to Copilot in Microsoft Teams, Slack, Azure Boards & Linear and let it use the full context of your chats or issues to move work forward. Agentic code review with Copilot: Get tailored, agentic reviews in every PR. Copilot now combines model intelligence with CodeQL to find security issues, apply all fixes, and let your team focus on the big picture.
- 🌐 VS Code - Use Plan Mode in VS Code to build a step-by-step plan and consider questions about your implementation, giving you full control and visibility before any code is written. Define project guidelines in AGENTS.md and ensure every custom agent in VS Code stays aligned with your team’s coding standards. Access and install MCP servers from the GitHub MCP Registry—all within VS Code.
- 🌐 & 🚢 We shipped many new capabilities and updates in conjunction with GitHub Universe. We created the What’s new at GitHub Universe? page to break down all of the updates by area. Here are some of the highlights:
- 🚢 Enterprise Tools, for example:
- Enterprise AI controls & the agent control plane are in public preview. NOTE: See also Delegate AI controls management to members of your enterprise - GitHub Changelog
- Managing Copilot Business in enterprise is now generally available.
- 🚢 Security, for example:
- Copilot coding agent now automatically validates code security and quality.
- Assign code scanning alerts to Copilot for automated fixes in public preview.
- GitHub Code Quality in public preview, providing in‑context feedback about the quality of your code and an easier way to turn technical debt into reviewable fixes.
- 🚢 CI/CD / Actions, for example:
- Custom images for GitHub-hosted runners are now available in public preview.
- Copilot coding agent now supports self-hosted runners.
- 🚢 GitHub Copilot, for example:
- Copilot usage metrics dashboard and API in public preview.
- A mission control to assign, steer, and track Copilot coding agent tasks.
- Custom agents for GitHub Copilot.
- New public preview features in Copilot code review: AI reviews that see the full picture.
- 🚢 All GitHub Universe '25 Releases - Skim through all 26 Changelogs tagged with "UNIVERSE '25".
- 🚢 Enterprise Tools, for example:
- 📢 Announcing the 2025 GitHub Partner Award winners 🎉 - Partnerships aren’t just about sales—they’re the engine driving innovation, security, and scale in modern software development. This post highlights the 2025 GitHub Partner Award winners, showcasing the companies setting new standards for collaboration and impact across the developer ecosystem. Check out this post to understand which partnerships are shaping the future of enterprise software and why these alliances matter for your strategy.
- 📢 Octoverse: A new developer joins GitHub every second as AI leads TypeScript to #1 - AI isn’t just speeding up coding—it’s reshaping the entire development landscape. GitHub’s Octoverse 2025 report reveals record-breaking growth of the GitHub platform, which now has over 180M developers. See how TypeScript has overtaken Python and JavaScript as the most-used language, driven by typed systems that make AI-assisted coding more reliable. Regarding security, average fix times for critical severity vulnerabilities have improved by 30% over the past year, as AI assisted remediation is beginning to keep pace with faster software development. If you lead a team or build enterprise software, these trends signal a fundamental shift in how developers choose tools, collaborate, and scale—understanding them now means staying competitive tomorrow.
- 📺 Full List of Recorded Sessions - Dozens of presentations were recorded. Watch these sessions to gain insights from not only GitHub's leaders and product managers but key stakeholders from some of GitHub's largest enterprise customers such as General Motors, CVS Health, Cathay Pacific Airlines and more. Before skimming through the full list of recorded sessions, check out these specially curated lists for Engineering Leaders, Developers and Security Professionals.
- 📺 Engineering Leader focused recorded sessions - Here are a few of the available recorded sessions from this curated list.
- 📺 Opening Keynote (1:00:05) - From AI and agents as true accelerators, to the strength of our global ecosystem, see how we’re helping developers move faster and build with confidence. See our latest product announcements, live demos, and a few surprises that showcased the future of building with GitHub. Hear from GitHub's Chief Operating Officer, Chief Product Officer, and others from GitHub as well as Satya Nadella, CEO & Chairman, Microsoft; Mike Krieger, CPO, Anthropic and Alexander Embiricos, Codex Product Lead, OpenAI.
- 📺 Empowering business leaders to scale innovation in the age of AI (37:00) Agentic AI isn’t a trend - it’s a shift in how software is created. The next wave of innovation won’t come just from developers, but from the collaboration between humans and agents. In this session, GitHub’s Chief Product Officer Mario Rodriguez shares how we’re expanding GitHub’s AI-powered Developer Platform for this new, AI-native SDLC. See how teams can move at AI speed while staying secure, visible, and in control.
- 📺 Revving up innovation: Reimagining a century of engineering at General Motors (15:00) - With over a century of engineering excellence in their rearview mirror, General Motors is building its next chapter on GitHub’s integrated developer platform. See how they transitioned from a fragmented development environment to a modern, scalable ecosystem that streamlines operations, boosts developer productivity and collaboration, and lays the foundation for sustained digital innovation.
- 📺 Repo rally: CVS Health's journey from legacy tools to seamless developer experience (23:00) - See how CVS Health migrated 150,000 repositories from a tangled web of legacy CI/CD tools to GitHub — and lived to tell the tale. They reshaped their entire developer experience by consolidating disparate tools into GitHub and GitHub Actions Thousands of developers now share a modern workflow that makes collaboration faster, easier, and more consistent across one of healthcare's largest tech organizations.
- 📺 Developer focused recorded sessions - Here are a few of the available recorded sessions from this curated list.
- 📺 Day 2 Keynote: Dream it in the morning, build it in the afternoon: Collapsing the distance from idea to impact (41:00) - The distance from idea to impact is collapsing. What once took months now takes days. Speed isn’t the whole story. Creativity and intent matter more than ever. In an era of “instant building,” it’s the human spark behind the keyboard that determines what gets built, shipped, and changes the world. In this era of instant possibility, creativity, intent, and imagination matter more than ever — the work that truly moves the world forward. Hear from Martin Woodward, VP, Developer Relations and Helen Hou-Sandi, Staff Software Engineering Manager, Accessibility, GitHub; Bodhish Thomas, Head of Digital Public Goods & Gigin Chandy George, Founding Engineer, Open Healthcare Network and Dylan Morley, Distinguished Engineer, Asos
- 📺 5 ways to automate everyday workflows with GitHub Actions (15:00) - GitHub Actions has revolutionized the way developers automate workflows, streamline processes, and supercharge their development cycle. Whether you're a seasoned pro or just getting started with automation, this talk will explore five powerful ways to leverage GitHub Actions for efficiency, reliability, and innovation.
- 📺 Security Professional focused recorded sessions - Here are a few of the available recorded sessions from this curated list.
- 📺 Increasing velocity while lowering risk: Cathay’s Enterprise journey to integrated AI and DevSecOps (31:03) - Cathay Pacific Airlines is moving beyond standalone tools by integrating GitHub Copilot, GitHub Actions, and GitHub Code Security into developer workflows on GitHub’s platform, boosting productivity, strengthening security, and establishing governance for enterprise-scale adoption. See Cathay’s playbook for integrated AI adoption, from early pilots to scaling AI-powered development across 1,000 developers.
- 📺 Scaling code quality in the age of AI (23:25) - We believe software must be secure and of high quality by default. AI agents are transforming how applications are created, and this presents an unprecedented opportunity to give them better context about your codebase, security requirements, and coding standards. In this session, you'll see how GitHub is making this vision a reality with new capabilities that span the entire developer workflow, from code creation and code review to code lifecycle management. Get a preview of innovations that will change how developers and AI work together to improve both security and quality of your code.
- 📺 Engineering Leader focused recorded sessions - Here are a few of the available recorded sessions from this curated list.
NOTE: The items in the remainder of the items in this document were released prior to or, after GitHub Universe, (i.e. between October 1st and October 27th or, after October 29th).
Events
While GitHub hosts our own marquee events like Universe and Galaxy each year, you will also find GitHub participating in other industry events. Here is the latest news about upcoming conferences and webinars.
- 📅 Microsoft Ignite - Get the edge you need to drive impact in the era of AI. Join us to bolster your knowledge, build connections, and explore emerging technologies. San Francisco, Moscone Center November 18–21, 2025 and Online November 18–20, 2025. You’ll learn about the latest tech trends and innovations that can help your organization gain a competitive edge and drive impact in the era of AI. Plus, you’ll get hands-on experience with cutting-edge AI, security, and IT solutions to bolster your knowledge and expand your expertise. It’s also a chance to connect with GitHub and Microsoft experts, partners, executives, and customers, allowing you to grow our network. Check out the more than 50 GitHub related sessions.
- 📅 AppSec at Universe 2025: What You Need to Know November 13, 7:00 AM — 8:00 AM PDT - In this session we will focus exclusively on the announcements that matter most for AppSec leaders and practitioners. From AI-driven security features in GitHub Copilot to enhanced vulnerability management and new protections across the software supply chain, we will highlight the key innovations and what they mean for your development and security workflows. Join us to get a clear, actionable view of how the latest GitHub capabilities can strengthen your AppSec strategy and help you build more secure software faster.
- 📅 GitHub Roadmap Webinar, Q4 2025 - The Americas and Europe November 13 at 8:00 AM PT | 11:00 AM ET | 5:00 PM CEST - We'll delve into our advancements in agent-powered developer experiences and offer live demonstrations of our newest features. This is an invaluable opportunity for anyone, from individual contributors to team leads, to witness what's coming, interact with experts, and find inspiration for future endeavors.
- 📅 Check out the complete upcoming conference schedule and upcoming webinar schedule.
GitHub Platform - Enterprise Management & Governance
We have been listening to our enterprise customers for years. We are thrilled to share some exciting updates to assist those who manage the rollout and maintenance of GitHub for hundreds if not thousands of stakeholders.
- 📺 Empowering business leaders to scale innovation in the age of AI (37:00) Agentic AI isn’t a trend - it’s a shift in how software is created. The next wave of innovation won’t come just from developers, but from the collaboration between humans and agents. In this session, GitHub’s Chief Product Officer Mario Rodriguez shares how we’re expanding GitHub’s AI-powered Developer Platform for this new, AI-native SDLC. See how enterprise teams can move at AI speed while staying secure, visible, and in control.
- 🚢 Managing roles and governance via enterprise teams is in public preview - This update introduces enterprise-wide teams and custom roles, giving organizations a scalable way to manage governance, permissions, and security across multiple GitHub organizations. With new capabilities like predefined security roles and API support, enterprises can centralize control while empowering local admins—streamlining compliance and reducing operational overhead.
- 🚢 Organization custom properties are now available in public preview - Attach structured metadata to each organization in your enterprise, enabling precise policy targeting without manual configuration. This new capability streamlines governance, improves security and compliance, and gives you flexibility to tailor rulesets to organizational needs like department, region, or regulatory requirements. Explore how this feature can save time and reduce errors while scaling enterprise management.
- 🎧 S0104 GitHub Copilot, Security, and Enterprise at Scale | GitHub at Work Podcast - This episode covers 80 GitHub code releases from September 2025, with a focus on Copilot updates, secret protection, code security, and supply chain security. The deep dive explores security campaigns, Copilot Autofix, and enterprise updates for managing GitHub at scale.
- 🚢 Delegate AI controls management to members of your enterprise - Empower your teams to manage AI and Copilot policies at scale with new fine-grained permissions that delegate control without sacrificing enterprise security or ownership.
- 🚢 Enterprise access restrictions now supports multiple enterprises - GitHub Enterprise Access Restrictions now works across multiple enterprise accounts, which is great news for large companies: a central admin can set one set of IP allow/block rules and have them consistently enforce security across all of their separate GitHub Enterprise Cloud instances.
- 📄 Automating app installations in your enterprise's organizations - This guide shows how to programmatically install GitHub Apps with fine-grained permissions, ensuring compliance, scalability, and auditability without relying on broad, risky tokens. If you manage enterprise workflows or enforce policies, this approach is critical for maintaining security while automating at scale.
- 🚢 Manage budgets and track usage with new billing API updates - Gain full programmatic control over budgets and real-time usage tracking with new REST APIs designed to simplify enterprise cost management and improve financial visibility.
- 🚢 Control AI spending with budget tracking for GitHub AI Tools - Gain precise control over AI-related costs with new SKU-level budgets, bundled options, and overage policies that make scaling GitHub Copilot and Spark predictable and governance-ready.
- 🚢 GitHub Copilot policy now supports agent mode in the IDE - GitHub admins can now manage access to Copilot agent mode for IDE via the Copilot policies page on github.com for enterprises and organizations.
- 🚢 GitHub now supports social login with Apple - Developers and contributors can now sign into GitHub using their Apple ID, providing a convenient and secure new SSO option that can simplify account management and onboarding, especially for organizations leveraging Apple’s identity ecosystem.
- 🚢 Improved blocked users view in organization and personal settings - GitHub has redesigned the “blocked users” management page for both personal accounts and organizations, giving admins a clearer overview of blocked users and making it easier to review or adjust who is prevented from interacting with your repositories.
- 🚢 GitHub Changelog - GitHub Platform, October, 2025 - Skim through all of the GitHub Platform related changes from October.
AI & ML - GitHub Copilot
For our biggest Copilot announcements from the month of October, see the GitHub Universe '25 section above. This section covers additional advancements and feature updates for GitHub Copilot that happened before and after GitHub Universe.
GitHub Copilot coding agent and Agent Mode
- 📢 Copilot: Faster, smarter, and built for how you work now - GitHub Copilot has evolved into a multi-model agentic assistant. This post dives into new capabilities that help developers stay in flow and leaders accelerate delivery without sacrificing quality.
- 🚢 GitHub Copilot in Visual Studio — October update - The October update of Copilot in Visual Studio brings new AI model options, greater project awareness, and built-in task planning to help dev teams code smarter and manage complex tasks without leaving the IDE.
- 📢 How to build reliable AI workflows with agentic primitives and context engineering - Turn AI into a repeatable engineering practice with a three-part framework. Perfect for leaders looking to standardize AI-driven development across teams.
- 📢 How GitHub Copilot and AI agents are saving legacy systems - Legacy COBOL systems aren’t going away—but AI can make them manageable. Learn how Copilot and AI agents modernize critical infrastructure without costly rewrites.
- 📄 Review AI-generated code - AI-generated code can accelerate development, but it also introduces risks like hidden bugs, and misaligned architecture. This guide shows you how to combine human judgment with automated checks to ensure Copilot’s output meets enterprise standards for functionality, maintainability, and compliance. If you’re responsible for code quality or leading teams, these techniques will help you prevent costly mistakes and build trust in AI-assisted workflows.
- 🚢 Copilot coding agent uses better branch names and pull request titles - GitHub Copilot’s coding agent now auto-suggests clearer, more descriptive branch names and PR titles, helping teams maintain cleaner repositories and more informative change histories with minimal effort.
- 🚢 Copilot coding agent can now search the web - GitHub’s autonomous Copilot coding agent gains the ability to search the internet for information, equipping your AI assistant to gather external context and solve problems beyond your codebase whenever needed.
- 🚢 GitHub Copilot policy now supports agent mode in the IDE - GitHub admins can now manage access to Copilot agent mode for IDE via the Copilot policies page on github.com for enterprises and organizations.
Getting the Most from GitHub Copilot across the Enterprise
- 📚 Playbook series: Creating clear AI policies and guardrails - Clear AI policies aren’t just compliance—they’re the foundation for safe, scalable innovation. Without them, developers risk either stalling progress or exposing the business to security and data leaks. This post gives you a practical blueprint for building guardrails that empower teams to adopt AI confidently and responsibly in a rapidly evolving tool landscape.
- 📄 GitHub Copilot licenses - Licensing for GitHub Copilot directly impacts how your organization controls costs and scales AI-powered development. This new documentation explains how seats are measured, billed, and managed across personal, organizational, and enterprise plans—critical for avoiding unexpected charges and ensuring compliance. If you’re responsible for budgeting or assigning developer tools, understanding these details will help you optimize spend and prevent disruptions.
- 📄 GitHub Copilot premium requests - Premium requests unlock advanced Copilot capabilities like large context windows, enhanced reasoning models, and coding agents—but they also impact your budget and usage limits. Understanding how these requests are measured, billed, and controlled is critical for managing costs and ensuring uninterrupted access to AI-powered development features across your organization.
- 🚢 Control AI spending with budget tracking for GitHub AI Tools - Gain precise control over AI-related costs with new SKU-level budgets, bundled options, and overage policies that make scaling GitHub Copilot and Spark predictable and governance-ready.
GitHub Copilot and Model Context Protocol (MCP) Servers
- 📢 How to find, install, and manage MCP servers with the GitHub MCP Registry - Bring structure and security to your AI ecosystem with the MCP Registry—a single source of truth for managing and governing MCP servers. This post explains how to streamline AI workflows while maintaining compliance and trust, a must-read for teams scaling AI adoption.
- 📢 Measuring what matters: How offline evaluation of GitHub MCP Server works - Offline evaluation isn’t just a testing step—it’s your safeguard against regressions and a blueprint for improving AI-driven workflows. This post reveals how GitHub’s MCP Server evaluation pipeline ensures tool descriptions, parameters, and integrations work flawlessly across models, so your Copilot experience stays reliable and performant. If you’re building or leading enterprise software teams, understanding this process is critical to maintaining quality while shipping faster.
- 🚢 GitHub MCP Server now comes with server instructions, better tools, and more - Unlock streamlined workflows and smarter automation with new server instructions, consolidated multifunctional tools, and simplified configuration options that make GitHub MCP Server more powerful and easier to customize than ever.
- 🚢 GitHub MCP Server now supports GitHub Projects and more - The GitHub MCP Server (an on-premises AI-powered development aide) now integrates with GitHub Projects and additional features, so enterprise teams using this server can coordinate project planning and issue tracking directly alongside the AI coding assistance, all within their self-hosted environment.
- 📢 Anthropic's Claude Sonnet 4.5 is now generally available in GitHub Copilot - Copilot coding agent will now use Claude Sonnet 4.5 for all subscription types, regardless of your Copilot Chat and IDE settings.
GitHub Copilot CLI
- 📢 GitHub Copilot CLI: How to get started - Bring Copilot to your terminal for streamlined workflows—from cloning repos to opening PRs. This post shows how CLI integration can boost efficiency for DevOps-heavy teams.
- 📺 The ultimate guide to the GitHub Copilot CLI | Full demo | GitHub Checkout (6:17) - Discover how the GitHub Copilot CLI transforms developer productivity by bringing AI-powered assistance directly into your terminal—no matter your environment—streamlining onboarding, troubleshooting, and code contribution tasks. See real-world demos of Copilot CLI handling everything from project exploration to automating common developer headaches, making it an essential tool for teams seeking to accelerate delivery and reduce friction in their workflows.
- 🚢 GitHub Copilot CLI: Faster, more concise, and prettier - The Copilot CLI tool gets a boost in speed and output quality, delivering quicker responses with more concise, well-formatted code suggestions to streamline developers’ command-line workflows.
- 🚢 Copilot CLI: Multiline input, new MCP enhancements, and Haiku 4.5 - The Copilot CLI now supports multi-line prompts and includes new “MCP” configuration enhancements along with the latest Claude Haiku 4.5 model, allowing more complex queries and customized AI behavior for advanced command-line assistance.
GitHub Copilot - New Models
- 📢 The road to better completions: Building a faster, smarter GitHub Copilot with a new custom model - Discover how GitHub is pushing Copilot beyond autocomplete with custom models that deliver faster, more accurate code completions. Learn why these improvements matter for productivity and developer experience in enterprise environments.
- 📢 Anthropic's Claude Sonnet 4.5 is now generally available in GitHub Copilot - Claude Sonnet 4.5 is generally available to Copilot Enterprise, Copilot Business, Copilot Pro, and Copilot Pro+ customers.
- 📢 GPT-4.1 Copilot code completion model — October update - We’ve enhanced the GPT-4.1 Copilot code completion model to improve the model’s ability to infer your intent from code context. As a result, you’ll see more accurate and contextually relevant inline code suggestions.
- 📢 Claude Haiku 4.5 is generally available in all supported IDEs - Claude Haiku 4.5 is generally available to Copilot Enterprise, Copilot Business, Copilot Pro, and Copilot Pro+.
- 📢 Grok Code Fast 1 is now generally available in GitHub Copilot - Grok Code Fast 1 is generally available to Copilot Enterprise, Copilot Business, Copilot Pro, and Copilot Pro+.
Additional GitHub Copilot Updates
- 🎧 S0103 Models, MCP, and More | GitHub at Work Podcast - This episode Of GitHub at Work covers the September 2025 GitHub releases, with a focus on GitHub Spark, Copilot, and MCP updates. Deep dive into GitHub Universe, the general availability of the Copilot coding agent, and Copilot Spaces.
- 🚢 Copilot-generated commit messages on github.com are generally available - AI-powered commit message generation is now enabled for all users on GitHub.com, letting developers save time with automatic draft commit notes while still maintaining clear, detailed commit histories.
- 🚢 GitHub Changelog - Copilot, October, 2025 - Skim through all of the Copilot changes from October.
Security
Application security with GitHub, ensuring the code that lives in GitHub and the dependencies that go into the solutions you build are secure and do not contain any secrets.
Supply Chain Security
- 📢 & 📺 Inside the breach that broke the internet: The untold story of Log4Shell (33:43) - A deep dive into one of the most significant security incidents in recent history. This post offers lessons on resilience and the human side of open source security. The GitHub Secure Open Source Fund | Enhancing open source security is powered by GitHub sponsors. If you lead enterprise software development efforts, please support the developers who power the open source used in your applications via the GitHub Sponsors program.
Code Security
- 🚢 CodeQL scanning Rust and C/C++ without builds is now generally available - GitHub Advanced Security can now scan Rust and C/C++ projects without requiring a full build, enabling faster and easier setup of code scanning for low-level languages and helping teams find vulnerabilities earlier in the development cycle.
- 🚢 CodeQL 2.23.2 adds additional detections for Rust, and improves accuracy across languages - The CodeQL 2.23.2 release introduces new security queries for Rust and enhances analysis accuracy for multiple languages, meaning your code scanning can now catch more potential issues (especially in Rust code) with fewer false positives.
- 🚢 CodeQL 2.23.3 adds a new Rust query, Rust support, and easier C/C++ scanning - The CodeQL 2.23.3 update further expands Rust security coverage with a new query and improved support, while also streamlining the scanning setup for C/C++ projects, giving security teams even stronger automated code analysis for those ecosystems.
Secret Protection
- 🚢 Secret Protection expands default pattern support – September 2025 - GitHub Secret Protection has widened its built-in detection patterns (as of the September 2025 update), allowing it to automatically catch an even broader range of secrets and credentials in your repositories to prevent leaks.
Additional Security Updates
- 🎧 S0104 GitHub Copilot, Security, and Enterprise at Scale | GitHub at Work Podcast - This episode covers 80 GitHub code releases from September 2025, with a focus on Copilot updates, secret protection, code security, and supply chain security. The deep dive explores security campaigns, Copilot Autofix, and enterprise updates for managing GitHub at scale.
- 🚢 GitHub Changelog - Security, October, 2025 - Skim through all of the security related changes from October.
CI/CD
Continuous Integration & Continuous Deployment with GitHub Actions.
- 🚢 Actions Runner Controller release 0.13.0 - The self-hosted Actions Runner Controller (for managing GitHub Actions runners on Kubernetes) has been updated to v0.13.0, bringing improvements that make it easier for enterprise DevOps teams to scale and control their CI/CD runner infrastructure reliably.
- 🚢 GitHub Changelog - Actions, October, 2025 - Skim through all of the security related changes from October.
Developer Skills
General developer expertise based on our own experience and the collective experience of our customers and partners. It's time to start diving into how AI is going to work along side of you to make you a better, more productive developer not, replace you. Check out the new posts 📢, documentation 📄, and articles 📚 to see how AI can make you an awesome developer and guidance for how large enterprises should approach adopting AI.
- 📢 Completing urgent fixes anywhere with GitHub Copilot coding agent and mobile - Discover how Copilot and GitHub Mobile empower developers to resolve critical issues on the go. Ideal for teams managing distributed systems and 24/7 uptime.
Engineering
An inside look at how we’re building the home for all developers. Resources based on our internal experiences.
- 📢 Measuring what matters: How offline evaluation of GitHub MCP Server works - Offline evaluation isn’t just a testing step—it’s your safeguard against regressions and a blueprint for improving AI-driven workflows. This post reveals how GitHub’s MCP Server evaluation pipeline ensures tool descriptions, parameters, and integrations work flawlessly across models, so your Copilot experience stays reliable and performant. If you’re building or leading enterprise software teams, understanding this process is critical to maintaining quality while shipping faster.
- 📢 How GitHub Copilot enabled accessibility governance process improvements in record time - See how Copilot automated accessibility compliance workflows, reducing manual effort and improving accountability—a blueprint for enterprise governance.
Legend
- GitHub Universe
- 📅 Events
- 📢 GitHub Blog
- 📺 GitHub on YouTube
- 🚢 The GitHub Changelog
- 📚 GitHub Resources
- 📄 GitHub Docs
- 🗣️ GitHub public feedback & discussions
- 🎧 Podcasts such as GitHub at Work Podcast
- 🙋♂️ Training
- 🌐 Third Party Web Site
That’s it for the November '25 edition of the enterprise roundup. Check back in to the GitHub Executive Insights at the beginning of next month to see the next round of key updates.
We want to hear from you! Did you find this curated list of updates from GitHub helpful? Do you have suggestions on how we can provide the information that is going to be the most useful and timely for your role? Visit the GitHub Community. November ‘25 enterprise roundup - community · Discussion
Tags