What Happened
GitHub is redesigning its Git infrastructure for repositories where developers and agents work concurrently. Monthly Git events more than doubled between September 2025 and August 2026, reaching 473.3 billion. Its proposed architecture coordinates reference updates while parallelizing other push work, moves maintenance off the serving path, and separates compute from durable storage. GitHub reports up to 35× higher write throughput in internal benchmarks; that is not a production performance guarantee. [1]
Stacked pull requests are now generally available on github.com plans. Updates preserve approvals on unchanged code during rebases, keep rebased commits signed, and move stacks through the merge queue as a group. The gh stack extension supports Git worktrees; auto-merge is still rolling out, and GitHub Enterprise Server support is planned rather than available. [2]
Security administrators can now see and export repository-level enablement status for AI Scan on pull requests. GitHub secret scanning also added detectors for Lovable, Pydantic, and Supabase credentials. [3][4]
Why It Matters to Businesses
AI coding tools can produce more concurrent changes, but repository throughput is only part of the constraint. Teams still need reviewable change sizes, predictable merge behavior, and visibility into whether security checks are enabled. Stacked pull requests address review structure; scan coverage reporting addresses an administrative visibility gap. Neither substitutes for evaluating code quality. [2][3]
GitHub reports that repositories using stacks merged 9% more code than peers, while top repositories using them saw a 5% improvement in time-to-merge. These comparisons do not establish that stacks alone caused the gains. [2]
Kimbodo Engineering Perspective
We would treat agent output as proposed code, not trusted code. Small, dependent pull requests are easier to review and revert than one large agent-generated change, provided dependency order and merge-queue behavior are tested. Worktrees can isolate concurrent tasks, but teams still need ownership rules to prevent agents and developers from changing the same files without coordination. [2]
The notes substantiate these GitHub changes, not comparable new releases from Cursor, Windsurf, Replit, Sourcegraph, JetBrains, VS Code, or Continue.dev. Tool selection across those products should therefore rest on a separate evaluation, not an assumed feature parity.
How We Would Implement It
- Give each agent task an isolated worktree and short-lived branch; limit its repository permissions and define which paths it may edit. Use stacked pull requests when a change can be split into independently reviewable steps. [2]
- Require CI, code review, and merge-queue checks on each pull request. Test how approvals, signatures, and failed checks behave when a stack is rebased or merged as a group. [2]
- Set an organization baseline for AI Scan enablement, then use security overview filters and CSV exports to find repositories that do not meet it. Track exceptions explicitly. [3]
- Enable secret scanning where applicable, verify alerts reach an owner, and rehearse credential rotation. Include the newly detected Lovable, Pydantic, and Supabase credential types in that review. [4]
- Measure push latency, queue time, review time, failed checks, and secret-alert response before increasing agent concurrency. GitHub’s infrastructure benchmarks should not be used as capacity estimates for an individual repository. [1]
Risks, Costs and Security
More simultaneous agents can increase CI consumption, review load, merge conflicts, and the number of credentials exposed through generated code or configuration. Stacks add dependency management; a blocked lower pull request can delay the rest. Security coverage reporting identifies enablement, not whether a scan finds every vulnerability. Secret scanning adds detection paths, but exposed credentials still require prompt revocation or rotation. [2][3][4]
Where Kimbodo Comes In
Kimbodo builds and operates this in production for businesses — see our AI Application Development practice, or Estimate My AI Application.