INITIALIZING

Author name: ITMAITY

tech blog

Welcome to the Eternal September of open source. Here’s what we plan to do for maintainers.

Open collaboration runs on trust. For a long time, that trust was protected by a natural, if imperfect filter: friction. If you were on Usenet in 1993, you’ll remember that every September a flood of new university students would arrive online, unfamiliar with the norms, and the community would patiently onboard them. Then mainstream dial-up ISPs became popular and a continuous influx of new users came online. It became the September that never ended. Today, open source is experiencing its own Eternal September. This time, it’s not just new users. It’s the sheer volume of contributions. When the cost to contribute drops In the era of mailing lists contributing to open source required real effort. You had to subscribe, lurk, understand the culture, format a patch correctly, and explain why it mattered. The effort didn’t guarantee quality, but it filtered for engagement. Most contributions came from someone who had genuinely engaged with the project. It also excluded people. The barrier to entry was high. Many projects worked hard to lower it in order to make open source more welcoming. A major shift came with the pull request. Hosting projects on GitHub, using pull requests, and labeling “Good First Issues” reduced the friction needed to contribute. Communities grew and contributions became more accessible. That was a good thing. But friction is a balancing act. Too much keeps people and their ideas out, too little friction can strain the trust open source depends on. Today, a pull request can be generated in seconds. Generative AI makes it easy for people to produce code, issues, or security reports at scale. The cost to create has dropped but the cost to review has not. It’s worth saying: most contributors are acting in good faith. Many want to help projects they care about. Others are motivated by learning, visibility, or the career benefits of contributing to widely used open source. Those incentives aren’t new and they aren’t wrong. The challenge is what happens when low-quality contributions arrive at scale. When volume accelerates faster than review capacity, even well-intentioned submissions can overwhelm maintainers. And when that happens, trust, the foundation of open collaboration, starts to strain. The new scale of noise It is tempting to frame “low-quality contributions” or “AI slop” contributions as a unique recent phenomenon. It isn’t. Maintainers have always dealt with noisy inbound. The Linux kernel operates under a “web of trust” philosophy and formalized its SubmittingPatches guide and introduced the Developer Certificate of Origin (DCO) in 2004 for a reason. Mozilla and GNOME built formal triage systems around the reality that most incoming bug reports needed filtering before maintainers invested deeper time. Automated scanners: Long before GenAI, maintainers dealt with waves of automated security and code quality reports from commercial and open source scanning tools. The question from maintainers has often been the same: “Are you really trying to help me, or just help yourself?“ Just because a tool—whether a static analyzer or an LLM—makes it easy to generate a report or a fix, it doesn’t mean that contribution is valuable to the project. The ease of creation often adds a burden to the maintainer because there is an imbalance of benefit. The contributor maybe gets the credit (or the CVE, or the visibility), while the maintainer gets the maintenance burden. Maintainers are feeling that directly. For example: curl ended its bug bounty program after AI-generated security reports exploded, each taking hours to validate. Projects like Ghostty are moving to invitation-only contribution models, requiring discussion before accepting code contributions. Multiple projects are adopting explicit rules about AI-generated contributions. These are rational responses to an imbalance. What we’re doing at GitHub At GitHub, we aren’t just watching this happen. Maintainer sustainability is foundational to open source, and foundational to us. As the home of open source, we have a responsibility to help you manage what comes through the door. We are approaching this from multiple angles: shipping immediate relief now, while building toward longer-term, systemic improvements. Some of this is about tooling. Some is about creating clearer signals so maintainers can decide where to spend their limited time. Features we’ve already shipped Pinned comments on issues: You can now pin a comment to the top of an issue from the comment menu. Banners to reduce comment noise: Experience fewer unnecessary notifications with a banner that encourages people to react or subscribe instead of leaving noise like “+1” or “same here.” Pull request performance improvements: Pull request diffs have been optimized for greater responsiveness and large pull requests in the new files changed experience respond up to 67% faster. Faster issue navigation: Easier bug triage thanks to significantly improved speeds when browsing and navigating issues as a maintainer. Temporary interaction limits: You can temporarily enforce a period of limited activity for certain users on a public repository. These improvements focus on reducing review overhead. Features we’ll be shipping soon Repo-level pull request controls: Gives maintainers the option to limit pull request creation to collaborators or disable pull requests entirely. While the introduction of the pull request was fundamental to the growth of open source, maintainers should have the tools they need to manage their projects. Pull request deletion from the UI: Remove spam or abusive pull requests so repositories can stay more manageable. Exploring next steps We know that walls don’t build communities. As we explore next steps, our focus is on giving maintainers more control while helping protect what makes open source communities work. Some of the directions we’re exploring in consultation with maintainers include: Criteria-based gating: Requiring a linked issue before a pull request can be opened, or defining rules that contributions must meet before submission. Improved triage tools: Potentially leveraging automated triage to evaluate contributions against a project’s own guidelines (like CONTRIBUTING.md) and surface which pull requests should get your attention first. These tools are meant to support decision-making, not replace it. Maintainers should always remain in control. We are also aware of tradeoffs. Restrictions can disproportionately affect first-time contributors

tech blog

Automate repository tasks with GitHub Agentic Workflows  

Imagine visiting your repository in the morning and feeling calm because you see: Issues triaged and labelled CI failures investigated with proposed fixes Documentation has been updated to reflect recent code changes. Two new pull requests that improve testing await your review. All of it visible, inspectable, and operating within the boundaries you’ve defined. That’s the future powered by GitHub Agentic Workflows: automated, intent-driven repository workflows that run in GitHub Actions, authored in plain Markdown and executed with coding agents. They’re designed for people working in GitHub, from individuals automating a single repo to teams operating at enterprise or open-source scale. At GitHub Next, we began GitHub Agentic Workflows as an investigation into a simple question: what does repository automation with strong guardrails look like in the era of AI coding agents? A natural place to start was GitHub Actions, the heart of scalable repository automation on GitHub. By bringing automated coding agents into actions, we can enable their use across millions of repositories, while keeping decisions about when and where to use them in your hands. GitHub Agentic Workflows are now available in technical preview. In this post, we’ll explain what they are and how they work. We invite you to put them to the test, to explore where repository-level AI automation delivers the most value. AI repository automation: A revolution through simplicity  The concept behind GitHub Agentic Workflows is straightforward: you describe the outcomes you want in plain Markdown, add this as an automated workflow to your repository, and it executes using a coding agent in GitHub Actions. This brings the power of coding agents into the heart of repository automation. Agentic workflows run as standard GitHub Actions workflows, with added guardrails for sandboxing, permissions, control, and review. When they execute, they can use different coding agent engines—such as Copilot CLI, Claude Code, or OpenAI Codex—depending on your configuration. The use of GitHub Agentic Workflows makes entirely new categories of repository automation and software engineering possible, in a way that fits naturally with how developer teams already work on GitHub. All of them would be difficult or impossible to accomplish traditional YAML workflows alone: Continuous triage: automatically summarize, label, and route new issues. Continuous documentation: keep READMEs and documentation aligned with code changes. Continuous code simplification: repeatedly identify code improvements and open pull requests for them. Continuous test improvement: assess test coverage and add high-value tests. Continuous quality hygiene: proactively investigate CI failures and propose targeted fixes. Continuous reporting: create regular reports on repository health, activity, and trends. These are just a few examples of repository automations that showcase the power of GitHub Agentic Workflows. We call this Continuous AI: the integration of AI into the SDLC, enhancing automation and collaboration similar to continuous integration and continuous deployment (CI/CD) practices. GitHub Agentic Workflows and Continuous AI are designed to augment existing CI/CD rather than replace it. They do not replace build, test, or release pipelines, and their use cases largely do not overlap with deterministic CI/CD workflows. Agentic workflows run on GitHub Actions because that is where GitHub provides the necessary infrastructure for permissions, logging, auditing, sandboxed execution, and rich repository context. In our own usage at GitHub Next, we’re finding new uses for agentic workflows nearly every day. Throughout GitHub, teams have been using agentic workflows to create custom tools for themselves in minutes, replacing chores with intelligence or paving the way for humans to get work done by assembling the right information, in the right place, at the right time. A new world of possibilities is opening for teams and enterprises to keep their repositories healthy, navigable, and high-quality. Let’s talk guardrails and control  Designing for safety and control is non-negotiable. GitHub Agentic Workflows implements a defense-in-depth security architecture that protects against unintended behaviors and prompt-injection attacks. Workflows run with read-only permissions by default. Write operations require explicit approval through safe outputs, which map to pre-approved, reviewable GitHub operations such as creating a pull request or adding a comment to an issue. Sandboxed execution, tool allowlisting, and network isolation help ensure that coding agents operate within controlled boundaries. Guardrails like these make it practical to run agents continuously, not just as one-off experiments. See our security architecture for more details. One alternative approach to agentic repository automation is to run coding agent CLIs, such as Copilot or Claude, directly inside a standard GitHub Actions YAML workflow. This approach often grants these agents more permission than is required for a specific task. In contrast, GitHub Agentic Workflows run coding agents with read-only access by default and rely on safe outputs for GitHub operations, providing tighter constraints, clearer review points, and stronger overall control. A simple example: A daily repo report   Let’s look at an agentic workflow which creates a daily status report for repository maintainers. In practice, you will usually use AI assistance to create your workflows. The easiest way to do this is with an interactive coding agent. For example, with your favorite coding agent, you can enter this prompt: Generate a workflow that creates a daily repo status report for a maintainer. Use the instructions at https://github.com/github/gh-aw/blob/main/create.md The coding agent will interact with you to confirm your specific needs and intent, write the Markdown file, and check its validity. You can then review, refine, and validate the workflow before adding it to your repository. This will create two files in .github/workflows:  daily-repo-status.md (the agentic workflow)   daily-repo-status.lock.yml (the corresponding agentic workflow lock file, which is executed by GitHub Actions)  The file daily-repo-status.md will look like this:  — on: schedule: daily permissions: contents: read issues: read pull-requests: read safe-outputs: create-issue: title-prefix: “[repo status] ” labels: [report] tools: github: — # Daily Repo Status Report Create a daily status report for maintainers. Include – Recent repository activity (issues, PRs, discussions, releases, code changes) – Progress tracking, goal reminders and highlights – Project status and recommendations – Actionable next steps for maintainers Keep it concise and link to the relevant issues/PRs. This file has two parts:  Frontmatter (YAML between — markers) for configuration  Markdown instructions that describe the job in natural language in natural language The Markdown is the intent, but the trigger, permissions, tools, and allowed outputs

tech blog

Why Dell Server Management Tools Outperform HPE: Comparative Analysis

Key takeaways: Dell server management tools streamline workflows, provide deeper visibility and deliver actionable sustainability insights, outperforming comparable tools from …   ​  ​Key takeaways: Dell server management tools streamline workflows, provide deeper visibility and deliver actionable sustainability insights, outperforming comparable tools from … PowerEdge Blog | Dell

tech blog

Breaking the Multiphysics Simulation Bottleneck

Multiphysics simulation no longer requires compromise. Modern workstations and GPUs are unlocking full‑fidelity insight.   ​  ​Multiphysics simulation no longer requires compromise. Modern workstations and GPUs are unlocking full‑fidelity insight. Dell Pro Max Blog | Dell

tech blog

Simplified Storage for SMBs with Dell PowerVault ME5

Storage isn’t a compromise. Modern IT demands simplicity: deploy fast, manage easily, scale with confidence, stay protected.   ​  ​Storage isn’t a compromise. Modern IT demands simplicity: deploy fast, manage easily, scale with confidence, stay protected. Technology Solutions Blog | Dell

tech blog

Dell Private Cloud Expands Choice with Nutanix Support

Dell Private Cloud now supports Nutanix with external storage flexibility. Keep the simplicity you love, gain the freedom to scale independently.   ​  ​Dell Private Cloud now supports Nutanix with external storage flexibility. Keep the simplicity you love, gain the freedom to scale independently. Launch Blog | Dell

tech blog

A New Era of Ransomware Defense

Block the access attackers rely on to infiltrate your environment with the first and only commercial PCs equipped for ransomware resilience,* offered exclusively by Dell and Halcyon.   ​  ​Block the access attackers rely on to infiltrate your environment with the first and only commercial PCs equipped for ransomware resilience,* offered exclusively by Dell and Halcyon. Launch Blog | Dell

tech blog

Wade Trim Accelerates Material Design and Simulation

Wade Trim’s hydraulic simulations took 48 hours. Now they finish overnight with a level of detail engineers once dreamt about.   ​  ​Wade Trim’s hydraulic simulations took 48 hours. Now they finish overnight with a level of detail engineers once dreamt about. Dell Pro Max Blog | Dell

tech blog

How Dell Powers Creativity at a Whole New Level

Discover how Dell Technologies and Cindy Olivo are driving innovation for the next generation of storytelling.   ​  ​Discover how Dell Technologies and Cindy Olivo are driving innovation for the next generation of storytelling. Dell Pro Max Blog | Dell

tech blog

Choosing Your AI Arsenal, Dell Pro Max GPU Guide

Skip the specs confusion. Match your Dell Pro Max workstation GPU to your actual AI workload and avoid costly mistakes.   ​  ​Skip the specs confusion. Match your Dell Pro Max workstation GPU to your actual AI workload and avoid costly mistakes. Artificial Intelligence Blog | Dell

tech blog

Updates in two of our core priorities

Satya Nadella, Chairman and CEO, posted the below message to employees on Viva Engage this morning. I am excited to share a couple updates in two of our core priorities: security and quality. Hayete Gallot is rejoining Microsoft as Executive Vice President, Security, reporting to me. I’ve also asked Charlie Bell to take on a new role focused on engineering quality, reporting to me. Charlie and I have been planning this transition for some time, given his desire to move from being an org leader to being an IC engineer. And I love how energized he is to practice this craft here day in and day out! Hayete joins us from Google where she was President, Customer Experience for Google Cloud. Before that, she spent more than 15 years at Microsoft with senior leadership roles across engineering and sales, playing multiple critical roles in building two of our biggest franchises – Windows and Office, leading our commercial solution areas’ go-to-market efforts. And she was instrumental in the design and implementation of our Security Solution Area. She brings an ethos that combines product building with value realization for customers, which is critical right now. As we shared during our quarterly earnings last week, we have great momentum in security, including progress with Security Copilot agents, strong Purview adoption, and continued customer growth, and we will build on this. We have a deep bench of talent and leaders across our security business, and this team will now report to Hayete. Additionally, Ales Holecek will take on a new role as Chief Architect for Security, reporting to Hayete. Ales has spent years leading architecture and development across some of our most important platforms and will help bring that same sensibility to security and its connections back to our existing scale businesses and the Agent Platform. As we shared yesterday, we have a new operating rhythm with commercial cohorts, and Hayete and her team will now be accountable for our security product rhythms as part of this process. Charlie built our Security, Compliance, Identity, and Management organization and helped rally the company behind the Secure Future Initiative. And we’re fortunate to have his continued focus and leadership on another one of our top priorities. With our Quality Excellence Initiative, we have increased accountability and accelerated progress against our engineering objectives to ensure we always deliver durable, high quality-experiences at global scale. And Charlie will partner closely with Scott Guthrie and Mala Anand on this work. I’m excited to welcome Hayete back to Microsoft to advance this mission critical work, and grateful to Charlie for all he has done for our security business and what he will continue to do for the company. Satya The post Updates in two of our core priorities appeared first on The Official Microsoft Blog. ​Satya Nadella, Chairman and CEO, posted the below message to employees on Viva Engage this morning. I am excited to share a couple updates in two of our core priorities: security and quality. Hayete Gallot is rejoining Microsoft as Executive Vice President, Security, reporting to me. I’ve also asked Charlie Bell to take on a… The post Updates in two of our core priorities appeared first on The Official Microsoft Blog.  Featured, The Official Microsoft Blog The Official Microsoft Blog

tech blog

Scaling AI Securely: The Dell Enterprise Hub Advantage

Dell Enterprise Hub secures AI supply chains with multi-layered protection, cryptographic signing, and offline deployment capabilities.   ​  ​Dell Enterprise Hub secures AI supply chains with multi-layered protection, cryptographic signing, and offline deployment capabilities. AI Solutions Blog | Dell

tech blog

AI Without Limits: Dell Pro Max Laptops Transform Work

Unlock true mobile AI power: Dell Pro Max laptops with NVIDIA RTX PRO GPUs bring desktop‑class intelligence anywhere.   ​  ​Unlock true mobile AI power: Dell Pro Max laptops with NVIDIA RTX PRO GPUs bring desktop‑class intelligence anywhere. Dell Pro Max Blog | Dell

tech blog

Ericsson Service Orchestration Validated on Dell Infrastructure

Progress in telecom thrives on collaboration. We’re excited to announce Ericsson’s Service Orchestration validated on Dell Telecom Blocks for Red Hat!   ​  ​Progress in telecom thrives on collaboration. We’re excited to announce Ericsson’s Service Orchestration validated on Dell Telecom Blocks for Red Hat! Edge Blog | Dell

tech blog

Leading the Charge in AI Supercomputing, Innovation and Initiatives

Discover how Dell Technologies is revolutionizing AI supercomputing and driving innovation across industries with bold initiatives and groundbreaking partnerships.   ​  ​Discover how Dell Technologies is revolutionizing AI supercomputing and driving innovation across industries with bold initiatives and groundbreaking partnerships. Government Blog | Dell

tech blog

Year recap and future goals for the GitHub Innovation Graph

Today’s data release marks our second full year of regular releases since the launch of the GitHub Innovation Graph. The Innovation Graph serves as a stable, regularly updated source for aggregated statistics on public software development activity around the world, informing public policy, strengthening research, guiding funding decisions, and equipping organizations with the evidence needed to build secure and resilient AI systems.   Updated bar chart races With our new data release, we’ve updated the bar chart race videos to the git pushes, repositories, developers, and organizations global metrics pages. Let’s take a look back at some of the progress the Innovation Graph has helped drive.  Academic papers One of the most rewarding aspects of the past year has been seeing the growing range of research questions addressed with Innovation Graph data. Recent papers have explored everything from global collaboration networks to the institutional foundations of digital capabilities. These studies showcase how network analysis techniques can be applied to Innovation Graph data, in addition to  earlier work we referenced last year linking open source to economic value, innovation measurement, labor markets, and AI-driven productivity through other methodologies. Historical Institutions and Modern Digital Capabilities: New Evidence from GitHub in Africa Research by an economist at the Federal Reserve Board uses GitHub data to examine how the density of Protestant mission stations correlates with present-day participation in digital production across African countries. Olana, Deriba, “Historical Institutions and Modern Digital Capabilities: New Evidence from GitHub in Africa” (November 25, 2025). Available at SSRN: https://ssrn.com/abstract=5805622 or http://dx.doi.org/10.2139/ssrn.5805622. The Structure of Cross-National Collaboration in Open-Source Software Development Researchers from MIT, Carnegie Mellon, and the University of Chicago analyze international collaboration patterns in the Innovation Graph’s economy collaborators dataset, shedding light on how common colonial histories influence modern software development collaboration activities. Xu, Henry, et al. “The Structure of Cross-National Collaboration in Open-Source Software Development,” (November 10, 2025). Available at doi.org/10.1145/3746252.3761237. Replication package available at https://github.com/hehao98/github-innovation-graph.   Small-World Phenomenon of Global Open-Source Software Collaboration on GitHub A social network analysis by researchers at Midwestern State University and Tarleton State University highlights the tightly connected, small-world structure of global OSS collaboration. Zhang, Guoying, et al. “Small-World Phenomenon of Global Open-Source Software Collaboration on Github: A Social Network Analysis.” Journal of Global Information Management Vol. 33, No. 1 (2025). Available at doi.org/10.4018/JGIM.387412.  The Software Complexity of Nations These researchers extend countries’ software economic complexity into the digital economy by leveraging the geographic distribution of programming languages in open source software, showing that software economic complexity predicts GDP, income inequality, and emissions, which have important policy implications. Juhász, Sándor, et al. “The Software Complexity of Nations.” Research Policy Vol. 55, No. 3. Available at doi.org/10.1016/j.respol.2026.105422. Conferences The Innovation Graph and related GitHub datasets were featured prominently in academic and policy discussions at a wide range of venues, including: ATLC25: The 10th Atlanta Conference on Science and Innovation Policy OpenForum Academy Symposium 2025 2nd CEU Vienna Data Analytics Jamboree Wharton Human-AI Research: 3rd Annual Business & Generative AI Conference News publications We were also encouraged to see Innovation Graph data referenced in major international reporting. In 2025, two pieces in The Economist drew on GitHub data examining China’s approach to open technology (June 17, 2025) and India’s potential role as a distinctive kind of AI superpower (September 18, 2025). Coverage like this reinforces the role that data on open source activity can play in understanding geopolitical and economic shifts. Reports Once again, Innovation Graph data contributed to several flagship reports, including: The 2025 Stanford AI Index Report The 2025 WIPO Global Innovation Index The Rise of FOSS in India report from the National Law School of India University We continue to value these opportunities to support macro-level measurement efforts, and we’re equally excited by complementary work that dives deeper into regional, institutional, and community-level dynamics. Moving forward As we move through 2026, we’re grateful for the community that has formed around the Innovation Graph, and we’re looking forward to building the next chapter together. Our focus will be on deepening collaboration, welcoming new perspectives, and creating clearer pathways for people to apply the Innovation Graph data in their own contexts, from strategy and research to product development and policy. The post Year recap and future goals for the GitHub Innovation Graph appeared first on The GitHub Blog. ​ News & insights, Policy, Innovation Graph, open source The GitHub Blog

Scroll to Top