Most codebases have a favorite mistake. It might be a query built from string concatenation, or a missing check on user input. A developer fixes it in one file. A few weeks later, the scanner finds the same flaw in another file, and the fix starts from scratch. GitHub wants to stop paying for that lesson twice. On September 25, the company said agentic autofix now uses Copilot Memory for customers who have turned Memory on. Before the agent works on a security alert, it checks stored memories for context that might help. After it creates a fix, it saves the fix pattern as a memory for later use. Those patterns don’t stay inside autofix. According to GitHub’s changelog, they help the agent resolve other security alerts, and they inform other Copilot features, including code review and the Copilot cloud agent, about secure development practices specific to the repository. Both agentic autofix and Copilot Memory are still in public preview. How the Pieces Fit Agentic autof...
Security researchers have uncovered a GitLab behavior that could let attackers use a leaked project email address to push code, trigger CI/CD jobs and reach other repositories accessible to the address owner. Aikido Security researcher Joe Leon detailed the attack path this week in a blog post after reporting it to GitLab earlier this year. The issue involves GitLab’s incoming email token, a credential embedded in private email addresses that GitLab provides for creating issues and merge requests by email. “The token inside this email address is essentially a fine-grained personal access token with significant access to your GitLab projects,” the report said. GitLab’s documentation says the token never expires and warns that anyone who obtains it can create issues and merge requests as the user. GitLab also allows users to attach .patch files when creating merge requests by email. GitLab applies the patches to the named source branch or creates the branch if it does not already exi...