Skip to content Skip to footer

What GitHub Copilot and JetBrains Air Updates Mean for AI-Assisted Development

What Happened

GitHub expanded Copilot from code assistance into workflow execution. In public preview, computer use lets Copilot CLI and the Copilot desktop app read and control approved macOS or Windows applications, including GUI-only tools. Dynamic workflows, also in public preview, let developers define multi-stage agent processes in code, pass structured results between stages, and pause for review [2][8].

🎧 Listen to this briefing (8 minutes)

Watch this briefing on the Kimbodo YouTube channel.

September’s VS Code releases added scheduled agent automations, pull request creation, agent-assisted merge handling, Dev Container support, and issue and pull request context. Some capabilities remain in preview. GitHub’s default dashboard now surfaces active agent sessions alongside issues and pull requests [3][9].

JetBrains Air entered Early Access in JetBrains IDEs. It provides parallel agent sessions, review, and validation for agents including Codex, Gemini, Copilot, Claude Agent, and Junie; Cursor and other agents can connect through ACP. Air is not itself an AI provider, and a cloud run requires a JetBrains AI subscription [11].

GitHub also changed surrounding developer controls: private vulnerability reports now have rate limits; Actions retention includes checks and statuses, including those from third-party apps; scheduled code scans skip repositories without a qualifying push- or pull-request-triggered analysis; and coverage uploads skip branches without an open pull request instead of failing CI [1][5][6][7].

Why It Matters to Businesses

The unit of automation is shifting from a single code suggestion to a session that can use tools, change files, operate applications, and advance a pull request. That can reduce handoffs, but it also makes permissions, review points, and records of agent actions part of the delivery process [2][3][8]. Teams using JetBrains IDEs gain another way to evaluate agents within their existing environment rather than standardizing on one assistant interface [11].

Kimbodo Engineering Perspective

Use the narrowest capable workflow. A code-defined dynamic workflow is preferable when stages and approvals must be repeatable; desktop computer use is better reserved for tasks that lack a reliable API or CLI. GUI automation has a wider interaction surface and should not become a shortcut around controlled integrations [2][8]. Early-access and preview features warrant measured pilots, not an assumption of stable behavior or interfaces [2][8][11].

How We Would Implement It

  • Start with one bounded task, such as preparing a pull request from an issue. Define inputs, permitted repositories and tools, a verification stage, and a human approval before merge [3][8].
  • Run agents in isolated development environments where practical. Keep CI tests and security checks independent of an agent’s own assessment, and record the resulting pull request, test results, and approval [3].
  • Enable desktop control only for named workflows and approved apps. Review persistent app allowances, and disable computer use at the organization level where the control cannot be justified [2].
  • Test CI triggers explicitly: coverage on a new branch is skipped until a pull request exists, unless a supported pull request event triggers the workflow [7].

Risks, Costs and Security

Desktop control can expose application content and perform clicks or typing, so permission prompts do not replace least-privilege access and human review [2]. Parallel agent sessions and scheduled automations can increase model usage and review load; pilots should measure both against completed, accepted work [3][11].

Retention settings now delete old checks and statuses as well as logs and artifacts, potentially removing evidence needed for audits or incident investigations; changing the setting cannot restore deleted records [5]. Rate limits may slow legitimate vulnerability reporters unless administrators allow-list trusted reporters, while reduced scanning of inactive repositories should not be mistaken for continuous coverage [1][6].

Where Kimbodo Comes In

Kimbodo builds and operates this in production for businesses — see our AI Application Development practice, or Estimate My AI Application.

Sources

  1. [1] Rate limits for private vulnerability reports
  2. [2] GitHub Copilot can now interact with desktop apps with computer use
  3. [3] GitHub Copilot in VS Code, September 2026 releases
  4. [5] Actions retention now covers checks, runs, and statuses
  5. [6] Scheduled code scanning skips inactive repositories
  6. [7] Code coverage uploads no longer fail CI for new branches
  7. [8] Dynamic workflows in Copilot CLI and the Copilot app
  8. [9] New dashboard experience now the default
  9. [11] A New Agentic Experience: JetBrains Air in IDEs – EAP Now Open

Leave a comment

0.0/5