GitHub Updates Copilot Code Review Controls and Settings
GitHub Copilot code review has used an agentic architecture running on GitHub Actions since March 5, 2026. It uses a GitHub-hosted runner by default, but can instead use a self-hosted or larger runner. The computing environment for AI reviews, the content they can access and the rules governing teams have therefore become important elements of corporate governance and cybersecurity controls.
GitHub announced an update on June 12, 2026, allowing organization administrators to centrally specify and lock a default runner across all repositories. Copilot will also follow content-exclusion rules at the repository, organization and enterprise levels. GitHub has removed the previous 4,000-character reading limit for custom instruction files in the .github directory and has not announced any additional fees.
All Coverage
2 original reportsThe Backstory
The history behind this eventAI Coding Pushes Software Teams Toward Spec-Driven Development
Generative AI tools including Anthropic’s Claude and GitHub Copilot are moving deeper into corporate software development, shifting adoption beyond conversational code assistance toward specification-driven development, or SDD. The transition matters because it changes the engineer’s role: less time may be spent writing code line by line, while more attention goes to system architecture, validation and the governance of AI agents operating across development workflows.
Recent enterprise use cases show AI being applied to code rewrites and component development, compressing work that previously required longer manual cycles. Teams are increasingly defining specifications first, then assigning AI agents to generate, test and revise software under human oversight. The available report, however, does not identify participating companies or provide implementation dates, investment amounts or quantified productivity gains, leaving the financial and operational impact dependent on project scale and governance quality.
GitHub MCP Server Adds Pre-Commit Scanning to Bolster AI-Assisted Development Security
GitHub MCP Server uses the Model Context Protocol to connect AI development tools such as GitHub Copilot CLI and Visual Studio Code. While AI agents can accelerate coding, they may inadvertently expose API keys or add vulnerable packages. Moving security checks ahead of commits or pull requests can help reduce credential leaks and supply-chain risks.
On May 5, 2026, GitHub announced the general availability of secret scanning in MCP Server for repositories with GitHub Secret Protection enabled, following a public preview that began on March 17. Dependency scanning entered public preview the same day and requires Dependabot alerts to be enabled. It reports affected packages, severity levels and patched versions. GitHub did not disclose any additional fees.
Atlassian CTO Examines How AI Coding Agents Are Reshaping Software Engineering
AI coding agents are shifting the bottleneck in software engineering away from writing code and toward clarifying requirements, designing systems, testing and operations. Atlassian Chief Technology Officer Rajeev Rajan believes engineers will increasingly act as orchestrators coordinating people and agents. But if companies focus solely on generating code faster, the risks to quality, security and customer trust will rise in tandem.
The Rundown AI published an interview with Rajan on March 8, 2026. By 2028, most code at large enterprises could be generated by AI, while research indicates that 45% of AI-generated code contains security flaws. Atlassian's Rovo Dev has shortened pull-request cycles by 45% and automatically resolved 51% of potential security vulnerabilities, with humans still responsible for review, monitoring and rollbacks.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →