Dev Tools — page 2 of 3
- Dev Tools6 min
Gang Scheduling Is Beta, and Beta Means Off
By Petru Popa ·Kubernetes v1.37 graduates gang scheduling to Beta through the Workload and PodGroup APIs. The feature gate that turns it on ships defaulted to false, and the DRA piece that makes it useful for GPU jobs is a second gate, also off, that depends on the first.
Read - Dev Tools6 min
Stacked Diffs Split the Change, Not the Reviewers
By Petru Popa ·maiao v1.4.0 brings Gerrit-style stacked diffs to six git hosts, weeks after GitHub put native stacked pull requests into public preview. The repository ships itself as a stack, which turns its own release into a measurement of what stacking buys.
Read - Dev Tools5 min
Write Access Decides Who Starts the Agent, Not Who It Hears
By Petru Popa ·GitHub shipped shared Copilot cloud agent sessions into Slack and Microsoft Teams in public preview. Only people with repository write access can trigger the agent, and guests cannot start or steer a session at all. But the docs also say the agent reads every message in the conversation. Those are two different boundaries, and only one of them is enforced.
Read - Dev Tools6 min
The OAuth Consent Screen Can Now Hand Back Less Than You Asked For
By Petru Popa ·Cloudflare added an optional_scopes field to third-party OAuth clients, so a user can clear individual permissions at the consent screen and the issued token carries only what survived. The announcement tells you to check the granted scope set. It does not say which field carries it, and neither does the client documentation. RFC 6749 does.
Read - Dev Tools5 min
The Mojo License Is Apache. The MAX SDK License Is Not.
By Petru Popa ·Modular put the Mojo compiler on GitHub under Apache 2.0 with LLVM exceptions. The same repository carries the Modular MAX Community License, whose terms are not the Apache terms and which never names the packages it governs. Nine merged pull requests across all of 2026 answers the other question a technical lead has.
Read - Dev Tools6 min
The Reviewable Unit Is the Pull Request, Not the Commit
By Petru Popa ·Wiz published research on an Actions script injection that leaked a Jira API token from a Snowflake runner. The pull request that introduced it carries a commit attributed to Copilot Autofix, and the diff removed the exact mitigation GitHub's own hardening page prescribes. The artifact cannot tell you which lines the model wrote — and that gap, not the model's error rate, is what your review process has to absorb.
Read - Dev Tools6 min
Your Refresh Token Is Now a Lock, Not a Secret
By Petru Popa ·OAuth apps on GitHub can now register up to ten redirect URIs and refresh short-lived tokens. The authorization docs add the part the changelog leaves out: refreshing invalidates the refresh token and the old access token together, which turns a copyable secret into something exactly one process may hold.
Read - Dev Tools6 min
Conformance Lets a Client Ignore Half Your Plugin
By Petru Popa ·GitHub shipped Agent Plugins 1.0 across VS Code, Copilot CLI, the Copilot SDK and the Copilot app. The spec repository behind it standardizes the package and explicitly defers trust, permissions, sandboxing and provenance to the client — and lets a conforming client implement skills without MCP servers.
Read - Dev Tools6 min
The Audience Is the One Claim Your Attacker Picks
By Petru Popa ·A proposal to let GitHub Actions workflows pre-declare OIDC audiences is the wrong fix to wait for. Reading the permission schema and AWS's condition-key reference shows why the control that holds today lives on the relying party.
Read - Dev Tools6 min
Three Meters and One Brake
By Petru Popa ·Between 6 and 7 August, GitHub shipped per-agent usage metrics, an effort dial for Copilot code review, an ROI section that prices a developer in pull requests per month, and an organization-wide pull request limit. The limit is documented as applying only to public repositories and only to users without write access — which is not where your agents are.
Read - Dev Tools6 min
The Client List Is the Policy
By Petru Popa ·MCP allowlists went generally available in enterprise managed settings, and a day later enterprises could install third-party GitHub Apps. GitHub's own reference pages name the clients that enforce the first and the missing event stream under the second, and the Copilot cloud agent is covered by neither. What that changes about how you govern agents this quarter.
Read - Dev Tools5 min
MCP's Twelve-Month Deprecation Window Doesn't Cover This Revision
By Petru Popa ·MCP revision 2026-07-28 makes the protocol stateless and adopts a feature lifecycle policy with a twelve-month floor before removal. The removals that will cost you time this quarter never entered that policy, and the deprecated feature with the nearest removal date is the one that has read as deprecated since March 2025.
Read