Skip to content Skip to footer

What GitHub’s Latest Copilot and Security API Changes Mean for Developer Tooling

What Happened

GitHub added REST and GraphQL support for requesting Copilot code reviews, including a per-request effort setting. Balanced became the default effort level on September 28 for new and existing repositories and organizations; explicit Lite selections remain in place. Settings can be configured at enterprise, organization, repository, and personal levels, with lower levels able to override higher ones. The change is generally available on eligible Copilot plans. [1]

GitHub also deprecated four Copilot models across chat, edits, agent mode, and completions. Workflows using Gemini 3.5 Flash, Gemini 3.6 Flash, Kimi K2.7 Code, or Claude Opus 4.7 should move to the listed successors; Enterprise administrators may need to enable replacement models in policy. [2]

On the security side, GitHub added advisory metadata and server-side filters to GraphQL, introduced confidential comments for repository security advisories, and put a REST API for non-confidential advisory comments into public preview. Separately, GitHub Actions will retire its macOS 14 runner image on November 2, with scheduled October brownouts for affected jobs. [4][5][6][7]

These notes establish changes at GitHub; they do not establish new releases for Cursor, Windsurf, Replit, Sourcegraph, JetBrains, VS Code, or Continue.dev.

Why It Matters to Businesses

API-driven reviews make Copilot easier to fit into pull-request workflows, but the new Balanced default can change review behavior without a team editing its configuration. Model deprecations create a separate maintenance task for pinned integrations and Enterprise model policies. Neither change removes the need for engineers to assess correctness, tests, and whether the proposed work meets the user’s need. [1][2][3]

Security teams can retrieve more advisory data through one GraphQL authentication path and use server-side filtering. They must distinguish confidential discussions, available through GraphQL to people with current write access, from the non-confidential comments exposed by the preview REST API. [4][5][6]

Kimbodo Engineering Perspective

Treat an AI review as decision support, not a merge gate by itself. A second model can challenge a first answer, but a human owner still needs to resolve competing findings and weigh product and technical trade-offs. For repeatable operations, explicitly set review effort rather than assuming an organizational default will hold at every level. [1][3]

Keep the advisory integration narrow: choose GraphQL when the workflow needs confidential comments or the new advisory fields; use preview REST comment endpoints only for non-confidential discussions that the caller is permitted to access. Do not equate a missing REST comment with an absence of confidential discussion. [4][5][6]

How We Would Implement It

  • Inventory repositories, Copilot review settings, model identifiers, and workflows using macOS 14 labels. Record intentional Lite selections before changing defaults. [1][2][7]
  • Set review effort explicitly in API-driven requests where consistency matters, and test the effective behavior at enterprise, organization, repository, and personal levels. [1]
  • Replace deprecated model references, confirm permitted alternatives in Enterprise policy, and run representative chat, edit, agent, and completion checks. [2]
  • Extend advisory ingestion with the new GraphQL fields and filters; test access separately for confidential GraphQL comments and non-confidential REST comments. [4][5][6]
  • Migrate macOS 14 jobs to a supported arm64 runner label and validate builds ahead of the October brownouts and November 2 retirement. [7]

Risks, Costs and Security

Review-effort changes may affect review workload; measure request volume, latency, and usefulness before standardizing a level. Model replacements may change output, so regression-test important workflows rather than treating the new names as interchangeable. [1][2]

Confidential advisory comments are visible only to people with current write access, their views are audit-logged, and their confidentiality cannot be changed after posting. Apply least-privilege access and verify which API surfaces a security integration consumes. The REST comments API is still in public preview and does not support deletion. [5][6]

Runner migration has an immediate reliability risk: macOS 14 jobs may fail during the scheduled brownouts, and reduced capacity may lengthen queues even before retirement. Budget time for platform-specific build and test validation. [7]

Where Kimbodo Comes In

Kimbodo builds and operates this in production for businesses — see our AI Application Development practice, or Estimate My AI Application.

Sources

  1. [1] Copilot code review: API support and new default effort level
  2. [2] Selected models in GitHub Copilot deprecated
  3. [3] AI is changing developer work. Here are three skills to strengthen.
  4. [4] New fields for SecurityAdvisory GraphQL API
  5. [5] Confidential comments on repository security advisories
  6. [6] Repository security advisory comments API in public preview
  7. [7] GitHub Actions: macOS 14 runner image retirement

Leave a comment

0.0/5