GitHub now auto-flags leaked Supabase, Lovable, and Pydantic keys
New detectors for the stacks builders actually ship on, plus a week of Copilot upgrades: review via API and an agent that drives your desktop apps.

Copy markdown
Leaked keys for your stack now get caught
GitHub's secret-scanning partner program added detectors for Supabase (OAuth and scoped personal access tokens), Lovable (lovable_api_key), and Pydantic (Logfire tokens and AI Gateway keys). In public repos a match is auto-reported to the vendor to revoke; in private repos it raises a scanning alert. A key pasted into a commit no longer sits there unnoticed.
Copilot code review is now an API call
Trigger Copilot code reviews from your own scripts, CI, and internal tools over REST and GraphQL, with a per-request effort level (Lite, or Balanced—now the default). It's generally available on Pro, Pro+, Max, Business, and Enterprise, so an automated first-pass review can gate PRs without touching the GitHub UI.
Copilot can now drive your desktop apps
Computer use is in public preview in Copilot CLI (/computer on) and the Copilot app on macOS and Windows: it clicks, types, scrolls, and moves data between apps that expose no API, CLI, or MCP. Each app needs your approval and sits on a resettable allowlist—a weekend unlock for the GUI-only tools stuck in your workflow.