Skip to content

#GitHub

4 items today
Today10/6Tue
  1. Tproger · Программирование58

    GitHub 与 Microsoft 开放 ReviewBench 评测 AI 代码评审

    GitHub 和 Microsoft 于 2026 年 10 月 5 日开放研究预览版 ReviewBench,用于评测 AI 代码评审智能体。该基准包含来自 187 个公开仓库、19 种语言的 219 个 pull request,语言和仓库规模分布基于对 GitHub 上 1.039 亿个 pull request 的分析,并刻意提高了实质性改动的占比。

    Awaiting translation

  2. 宝玉71

    据 The Information 10 月 5 日报道,Meta 和微软都在减少员工内部使用 Anthropic 的 Claude,转向自家模型和工具。

    Awaiting translation

    QuotedNIK@ns123abc

    🚨BREAKING: Microsoft and META are aggressively cutting employee use of Claude ahead of Anthropic's IPO Microsoft has cut internal claude spend by more than 33%, nuked per-employee token budget from $100k/month to $10k/month, and forced Copilot to auto-route to cheaper models META used Claude code to build Muse, then cut active users from 60,000 to 30,000 (50% decline) after launch, and replaced it with Muse Code Palantir and Nvidia are also scaling back claude over soaring prices and data privacy fears it’s OVER…

  3. GitHub Blog · Copilot66

    GitHub 发布 AI 代码评审开放基准 ReviewBench

    GitHub 发布代码评审离线基准 ReviewBench,基于 1.039 亿个 GitHub PR 的分布特征,构建了覆盖 19 种语言、219 个公开 PR 的评测集,并公开数据集、评分规则与 LLM 评审模型配置。

    Awaiting translation

    Why it matters: GitHub 公开了 AI 代码评审基准的数据集、评分规则与评测入口,读者可据此对比不同评审智能体。

10/5Mon
10/4Sun
  1. DEV Community · AI Coding26

    2026 年 7 款最佳 GitHub Copilot 替代品实测:免费额度与价格对比

    2026 年 10 月的实测对比显示,Cursor 以 4.4 分成为多数开发者的最佳 GitHub Copilot 替代品,Hobby 免费、Pro 每月 20 美元;Zed AI 和 Continue 在免费额度上最强,Claude Code 智能体得分最高(5.0)但无免费层。GitHub Copilot 仍以每月 10 美元的 Pro 席位守住性价比基线,其免费层仅支持自动模型选择。

    Awaiting translation

10/2Fri
10/1Thu
9/27Sun
9/25Fri
  1. Vibe Built · Blog62

    用一个功能规格和六项评分表自行评测 AI 编程助手

    作者提出用一个小功能规格来评测 AI 编程助手:在临时目录建两个 Python 文件,让助手给 notes_cli.py 加 --since YYYY-MM-DD 过滤选项,要求非法日期以状态码 2 退出并只向 stderr 输出一行、补充边界日和非法日期测试、只改这两个文件、运行 python3 -m unittest -v 并展示完整输出。

    Awaiting translation

9/24Thu
  1. Tproger · Программирование58

    GitHub Copilot App 推出本地沙箱,限制文件、网络与凭据访问

    GitHub 于 9 月 23 日为 GitHub Copilot App 推出本地沙箱,目前处于公开预览,仅适用于使用本地仓库和工作树的会话。沙箱可分别限制文件系统读写路径、外网与局域网访问,以及 Git credentials 和 GitHub CLI 数据的使用,企业策略还能进一步收紧;若操作系统无法应用规则,隔离环境会报错退出而不执行命令。

    Awaiting translation

9/12Sat
9/5Sat
  1. GitHub Blog · Copilot71

    GitHub Copilot launches Project HydraFusion, using multi-model runtime orchestration to improve coding quality

    GitHub has launched Project HydraFusion as a research preview in the Copilot CLI. It uses runtime orchestration to pick an execution plan across models from multiple providers. Users select it just like any other model, and billing follows each model's standard rates.

    Why it matters: GitHub lays out three orchestration modes for HydraFusion and compares cost versus quality across three benchmarks, so you can judge the trade-offs of multi-model orchestration on real coding tasks.

9/4Fri
9/3Thu
8/17Mon
8/2Sun
6/18Thu
  1. Augment Code · Blog71

    Augment launches Project Builder on the Cosmos platform, taking large projects from design doc to merge

    Augment launches Project Builder on the Cosmos platform. This Cosmos expert turns a one-line feature description into a design doc grounded in the real codebase; after human review, it orchestrates worker agents to implement the work and drive it to merge.

    Why it matters: Augment has shared how Project Builder handles design review and orchestration, plus the code volume and launch timelines of three production projects—enough to judge whether design-first plus agent orchestration is workable.

5/27Wed
5/21Thu
  1. Permission Protocol · AI Agent Incident Tracker71

    Composio 遭 LLM 生成攻击模式入侵,5,001 个 GitHub token 被窃

    攻击者用 LLM 生成的攻击模式暴力破解漏洞,攻入 Composio 内部智能体监控工具,随后注册恶意工具定义提权到修复系统,在工具执行沙箱中执行任意代码,窃取 5,001 个 GitHub OAuth token,涉及 Gmail、Slack、Notion、Jira、HubSpot、Render、Vercel 等 26 种连接器类型的凭据。

    Awaiting translation

5/12Tue
  1. DevAgentStack · Field Notes62

    如何在接入生产数据前划定 MCP 访问权限

    作者提出在给编码智能体接入 MCP 工具前,先问最小能力边界而非能连什么,并按五级权限阶梯逐步放开。只读工具(读数据库 schema、错误日志、内部文档、GitHub issue)最安全,任意 SQL 或 shell 工具风险高,写入应走提案模式由人工审批后再执行。判断工具是否过早接入的信号包括无法说出具体任务、接受任意命令、响应含密钥或 PII、无审计记录和回滚方案。

    Awaiting translation

5/11Mon
  1. Permission Protocol · AI Agent Incident Tracker88

    Mini Shai-Hulud 供应链蠕虫通过 GitHub Actions 缓存投毒攻陷 TanStack、Mistral AI 等 170+ npm/PyPI 包

    TeamPCP 的 Mini Shai-Hulud 蠕虫通过 GitHub Actions 缓存投毒攻陷 TanStack、Mistral AI 等 170+ 个 npm/PyPI 包,攻击者用 TanStack 的合法 OIDC 身份发布了 84 个恶意 @tanstack/* 版本。

    Awaiting translation

    Why it matters: 复盘了攻击者如何借 GitHub Actions 缓存投毒窃取 OIDC 令牌并写入 Claude Code Hook 实现持久化,可了解供应链攻击的新手法。

5/6Wed
5/4Mon
4/15Wed
  1. Permission Protocol · AI Agent Incident Tracker87

    约翰霍普金斯研究者通过 PR 标题注入从 Claude Code、Gemini CLI 和 GitHub Copilot 窃取 API 密钥

    约翰霍普金斯研究者 Aonan Guan 利用 PR 标题提示词注入,从 Claude Code Security Review、Gemini CLI Action 和 GitHub Copilot 中窃取 API 密钥与 GitHub token。

    Awaiting translation

    Why it matters: 约翰霍普金斯研究者用 PR 标题注入从三个 AI 编程智能体中窃取凭据,三家厂商均静默修复并支付漏洞赏金。

3/31Tue
3/30Mon
3/19Thu
2/3Tue
  1. Vercel · v0 Blog60

    Vercel 发布新版 v0,从生成演示转向生产级应用

    Vercel 发布新版 v0,将其定位从生成演示转向生产级应用和智能体。新版本基于沙箱运行时,可导入任意 GitHub 仓库并自动拉取 Vercel 上的环境变量和配置;新增 Git 面板,让非工程成员也能为每个对话建分支、向 main 提 PR 并在合并后部署;同时提供与 Snowflake 和 AWS 数据库的安全集成,以及默认开启的部署保护和访问控制。

    Awaiting translation

    Why it matters: v0 从生成演示转向生产级应用,给出导入 GitHub 仓库、Git 面板和数据库集成等具体能力变化。

1/23Fri
12/31Wed
9/28Sun
11/29Wed
8/1Tue
  1. Martin Fowler · Exploring Generative AI52

    行内代码补全什么时候更有用

    Martin Fowler 结合 Thoughtworks 内部使用 GitHub Copilot 的经验,分析行内代码生成在什么情况下更有用。他给出的有利条件包括技术栈更主流、问题更常见、生成片段更小、开发者更有经验、出错代价更低,并指出经验不足的开发者使用这类工具时任务耗时可能反而增加 7% 到 10%。他建议开发者花一段时间在安全区内外实验,逐步建立对工具适用边界的判断。

    Awaiting translation