Fetching from the wire…
Security2026-07-12 · source-backed
Released July 11, it adds static-analysis queries that flag prompt-injection vulnerabilities in JavaScript and TypeScript, plus Kotlin 2.4.0 support (GitHub). Treating untrusted-input-into-LLM flows as a first-class security defect class is the right call. If you're wiring LLM calls into a JS/TS app, you can now catch injection sinks in CI instead of at runtime. Turn it on.
Each link below shares sources, entities, or timing with this story.
Now generally available for Enterprise Cloud and Team, flagging maintainability and reliability issues inside pull requests (release notes). Same release fixed Copilot CLI subagents with additional directories and relative-link resolution in custom agent instructions. This is...
In public preview, Copilot explores the relevant files, proposes a remediation, and re-runs CodeQL to confirm the alert is actually closed, then opens a draft PR for review. (GitHub) This is the closed-loop, self-verifying security agent showing up inside the default dev platf...
High-performance GraphRAG reimplemented in Rust. Achieves ~200ms query times vs ~500ms for Python equivalents (2.5x faster). Multi-pass gleaning catches 15-25% more entities. SDKs in TypeScript, Python, Rust, Java, Kotlin. For production RAG builders who need speed. GitHub
CLI, IDE extension, macOS app, and Codex Web all sit on the same harness, linked by a bidirectional JSON-RPC-over-stdio process that hosts core threads and translates client requests into Codex operations. Partners have written clients in Go, Python, TypeScript, Swift, and Kot...
It refines C/C++ CodeQL queries by synthesizing programs whose execution disagrees with the query verdict, treating that disagreement as ground truth for an LLM repair loop, with no labeled dataset or vulnerability templates. Refined queries detected up to 119.8% more true pos...
semantica-agi/semantica surged +1,181 stars to 7,761 today, and the release driving it is a security release from August 11 fixing six externally-reported flaws across the Explorer API and the graph store backends, plus a CodeQL-flagged ReDoS. GitHub A missing-authentication g...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.