Sign in

Jesse Houwing

@jessehouwing.net
87 followers 91 following 183 posts

Loves Charlotte and Lily & Mika. Works at Xebia. Scrum.org, Github and Microsoft Trainer

PostsRepliesMedia
Jesse Houwing @jessehouwing.net · 27/09/2026
@arjenlubach.bsky.social je bent ook al internationaal doorgebroken als taskmaster, maar wel met een Rrrpr naam
000
Jesse Houwing @jessehouwing.net · 24/09/2026
Hey @1password.bsky.social any chance you can officially add this feature to the one-password CLI? The request has come up multiple times and the fix looks deceptively simple ;). github.com/jessehouwing...
github.com
GitHub - jessehouwing/op-pinentry: GnuPG pinentry replacement for Windows that fetches passphrases from 1Password on demand
GnuPG pinentry replacement for Windows that fetches passphrases from 1Password on demand - jessehouwing/op-pinentry
000
Jesse Houwing @jessehouwing.net · 23/09/2026
After previously releasing a new version of the #Azure DevOps Marketplace actions, I've now added a @visualstudio.com Marketplace action as well. Adding Azure Pipelines and #GitHub Actions support for publishing to the Marketplace. github.com/jessehouwing...
github.com
GitHub - jessehouwing/vs-marketplace: CI/CD for Visual Studio Extensions
CI/CD for Visual Studio Extensions. Contribute to jessehouwing/vs-marketplace development by creating an account on GitHub.
010
Jesse Houwing @jessehouwing.net · 21/09/2026
YES
010
Reposted by Jesse Houwing
Jesse Houwing @jessehouwing.net · 15/09/2026
Many customer struggle with this question: Which GitHub Actions should I trust? And unfortunately, there is no formal checklist answer. I've capture my own mental checklist in this blog post, it's not as easy as checking all the boxes, but it's a start: jessehouwing.net/a-trust-chec...
jessehouwing.net
A trust checklist for GitHub Actions
Every action you reference in a workflow runs on your runner, with access whatever token you hand it. `uses: some-org/some-action@v3` is an instruction to execute someone else's code. It deserves at l...
012
Reposted by Jesse Houwing
Jesse Houwing @jessehouwing.net · 15/09/2026
A colleague recently ran an experiment on GitHub to try and build a "dark software factory" (yes, ominous term!). It's not as easy on GitHub due to constraints put in place to ensure human-in-the-loop reviews.
jessehouwing.net
Can one agent start another? Queueing sub-tasks in GitHub Agentic Workflows
Consider a "dark factory" setup: a software factory with almost no people on the production line. A small number of people orchestrate the system, but agents do most of the work: planning, coding, rev...
111
Reposted by Jesse Houwing
Jesse Houwing @jessehouwing.net · 15/09/2026
When using AI, be it GitHub Copilot or Claude against very recent technology developments, you'll run into issues where the agent just doesn't have recent enough examples of how to work with this new thing. Especially when there have been recent breaking changes, this can be extra frustrating.
jessehouwing.net
Ground your GitHub Copilot agent in a local clone instead of letting it guess
A long debugging session lost to GitHub Agentic Workflows. Not because the tool was broken, but because the agent kept inventing how it worked. The model was not being unreasonable. It was being asked...
101
Reposted by Jesse Houwing
Jesse Houwing @jessehouwing.net · 17/09/2026
Ans now there is a massive PR that fixed a bunch of logic bugs, fixes 6 threading bugs, delivers 50% performance improvements for cold runs (great for CI). The scary bit is now getting it through, gathering enough evidence it doesn't break anything. github.com/PowerShell/P...
github.com
Fix intermittent "The term 'Get-Command' is not recognized" failures during recursive analysis and improve performance while doing so. by jessehouwing · Pull Request #2206 · PowerShell/PSScriptAnalyze...
This pull request makes significant improvements to the thread safety, reliability, and performance of the CommandInfoCache and related PowerShell command metadata retrieval in the ScriptAnalyzer e...
111
Reposted by Jesse Houwing
Jesse Houwing @jessehouwing.net · 17/09/2026
This is why I love open source! And copilot! I'd been running into an intermittent issue with the PowerShell Script Analyzer and together with Copilot I philosophized why it might occur, distilled a failing test case, then analyzed the impact on performance, found ways to optimize that performance
231
Reposted by Jesse Houwing
Jesse Houwing @jessehouwing.net · 18/09/2026
Yesterday I shared a Pull Request that's pending, I decided to see if I could turn that into a more readable story format for those interested. jessehouwing.net/fixing-compl... #githubcopilot #github #powershell #opensource
jessehouwing.net
Fixing complex bugs with AI - A deepdive into the PowerShellScriptAnalyzer
Some build failures are annoying. Others are simply impossible. Mine was the second kind. On a plain `ubuntu-latest` runner, a recursive `Invoke-ScriptAnalyzer` run would stop dead with an error sayi...
031
Jesse Houwing @jessehouwing.net · 18/09/2026
Yesterday I shared a Pull Request that's pending, I decided to see if I could turn that into a more readable story format for those interested. jessehouwing.net/fixing-compl... #githubcopilot #github #powershell #opensource
jessehouwing.net
Fixing complex bugs with AI - A deepdive into the PowerShellScriptAnalyzer
Some build failures are annoying. Others are simply impossible. Mine was the second kind. On a plain `ubuntu-latest` runner, a recursive `Invoke-ScriptAnalyzer` run would stop dead with an error sayi...
031
Jesse Houwing @jessehouwing.net · 17/09/2026
I did an extensive writeup here jessehouwing.net/fixing-compl...
jessehouwing.net
Fixing complex bugs with AI - A deepdive into the PowerShellScriptAnalyzer
Some build failures are annoying. Others are simply impossible. Mine was the second kind. On a plain `ubuntu-latest` runner, a recursive `Invoke-ScriptAnalyzer` run would stop dead with an error sayi...
110
Jesse Houwing @jessehouwing.net · 17/09/2026
I 1.24 also had a much lower failure rate than 1.25, so next I asked copilot to compare the diff and come up with possible reasons for the increase. Added my own thoughts. And together we found the first few issues.
000
Jesse Houwing @jessehouwing.net · 17/09/2026
I happened to have a repo that had about a 50% chance of hitting it. I started with a simple loop that just ran 10x on my own project. Almost 100% failure rate. Brainstormed with opus on the possible reasons and had it analyze the existing issues and abandoned PRs.
000
Jesse Houwing @jessehouwing.net · 17/09/2026
Do you have a PowerShell library? Test it with my forked version and let me know if you found any issues!
010
Jesse Houwing @jessehouwing.net · 17/09/2026
Ans now there is a massive PR that fixed a bunch of logic bugs, fixes 6 threading bugs, delivers 50% performance improvements for cold runs (great for CI). The scary bit is now getting it through, gathering enough evidence it doesn't break anything. github.com/PowerShell/P...
github.com
Fix intermittent "The term 'Get-Command' is not recognized" failures during recursive analysis and improve performance while doing so. by jessehouwing · Pull Request #2206 · PowerShell/PSScriptAnalyze...
This pull request makes significant improvements to the thread safety, reliability, and performance of the CommandInfoCache and related PowerShell command metadata retrieval in the ScriptAnalyzer e...
111
Jesse Houwing @jessehouwing.net · 17/09/2026
This is why I love open source! And copilot! I'd been running into an intermittent issue with the PowerShell Script Analyzer and together with Copilot I philosophized why it might occur, distilled a failing test case, then analyzed the impact on performance, found ways to optimize that performance
231
Jesse Houwing @jessehouwing.net · 15/09/2026
Here's one way to deal with that, when you have access to the sources! Clone the repo locally and instruct your agent to look at the included docs and the actual implementation to ground its understanding. jessehouwing.net/ground-your-...
jessehouwing.net
Ground your GitHub Copilot agent in a local clone instead of letting it guess
A long debugging session lost to GitHub Agentic Workflows. Not because the tool was broken, but because the agent kept inventing how it worked. The model was not being unreasonable. It was being asked...
010
Jesse Houwing @jessehouwing.net · 15/09/2026
When using AI, be it GitHub Copilot or Claude against very recent technology developments, you'll run into issues where the agent just doesn't have recent enough examples of how to work with this new thing. Especially when there have been recent breaking changes, this can be extra frustrating.
jessehouwing.net
Ground your GitHub Copilot agent in a local clone instead of letting it guess
A long debugging session lost to GitHub Agentic Workflows. Not because the tool was broken, but because the agent kept inventing how it worked. The model was not being unreasonable. It was being asked...
101
Jesse Houwing @jessehouwing.net · 15/09/2026
There are a few ways "around" this, by preemptively authorizing work using a personal access token for example. In this blog I look at the problems and potential solutions, while also trying to provide context on why these constraints exist. jessehouwing.net/can-one-agen...
jessehouwing.net
Can one agent start another? Queueing sub-tasks in GitHub Agentic Workflows
Consider a "dark factory" setup: a software factory with almost no people on the production line. A small number of people orchestrate the system, but agents do most of the work: planning, coding, rev...
000
Jesse Houwing @jessehouwing.net · 15/09/2026
A colleague recently ran an experiment on GitHub to try and build a "dark software factory" (yes, ominous term!). It's not as easy on GitHub due to constraints put in place to ensure human-in-the-loop reviews.
jessehouwing.net
Can one agent start another? Queueing sub-tasks in GitHub Agentic Workflows
Consider a "dark factory" setup: a software factory with almost no people on the production line. A small number of people orchestrate the system, but agents do most of the work: planning, coding, rev...
111
Jesse Houwing @jessehouwing.net · 15/09/2026
Many customer struggle with this question: Which GitHub Actions should I trust? And unfortunately, there is no formal checklist answer. I've capture my own mental checklist in this blog post, it's not as easy as checking all the boxes, but it's a start: jessehouwing.net/a-trust-chec...
jessehouwing.net
A trust checklist for GitHub Actions
Every action you reference in a workflow runs on your runner, with access whatever token you hand it. `uses: some-org/some-action@v3` is an instruction to execute someone else's code. It deserves at l...
012
Reposted by Jesse Houwing
Jesse Houwing @jessehouwing.net · 16/06/2026
Added a new feature to our AI Fluency extension. It checks your past session history for skill files and MCP servers that are enabled, but haven't been used. They sometimes add a significant amount of token overhead to every session. github.com/rajbos/ai-en... #githubcopilot #usagebasedbilling
Two tips showing that the current Tools, Skills and MCP Servers are adding significant overhead, but haven't been used in the past months.A more detailed overview of which MCPs are adding overhead.
031
Jesse Houwing @jessehouwing.net · 19/06/2026
Migrating from #AzureDevOps to #GitHub with Data Residency? These are the steps to rewire your #AzurePipelines so you can keep using them while you're converting them to #GitHubActions. The steps aren't as simple as you might expect unfortunately. jessehouwing.net/configure-az...
jessehouwing.net
Configure Azure Pipelines app in ghe.com
I recently helped a client migrate from Azure DevOps to GitHub Enterprise Managed Users with Data Residency (ghe.com for short). And as part of the migration we rewired the exiting Azure Pipelines fro...
010
Jesse Houwing @jessehouwing.net · 16/06/2026
Added a new feature to our AI Fluency extension. It checks your past session history for skill files and MCP servers that are enabled, but haven't been used. They sometimes add a significant amount of token overhead to every session. github.com/rajbos/ai-en... #githubcopilot #usagebasedbilling
Two tips showing that the current Tools, Skills and MCP Servers are adding significant overhead, but haven't been used in the past months.A more detailed overview of which MCPs are adding overhead.
031
Jesse Houwing @jessehouwing.net · 09/06/2026
Spent a couple of hours last night trying to figure out why a specific task version wasn't showing up after deploying a new #azurepipelines task from #githubactions. Turns out a specific misconfiguration isn't caught in tfx, visualstudio marketplace nor azure devops. github.com/microsoft/tf...
github.com
Incorrect vss-extension.json not caught by tfx, nor marketplace not Azure DevOps · Issue #542 · microsoft/tfs-cli
When an extension declares 2 contributions, say vsts-msbuild-helper-task-v0 and vsts-msbuild-helper-task-v1 and each of these point to a task.json that has the same name and id, but 2 different maj...
120
Jesse Houwing @jessehouwing.net · 01/06/2026
Adding Google Test Framework for C++ guidance to the dotnet skills library to extend the test agent in Visual Studio 2026. github.com/jessehouwing... Working pretty well so far! @github.com #copilot @dotnetfoundation.org @visualstudio.com
github.com
skills/plugins/dotnet-test at main · jessehouwing/skills
Repository for skills to assist AI coding agents with .NET and C# - jessehouwing/skills
030
Jesse Houwing @jessehouwing.net · 01/06/2026
I'm seeing some users having issues with @github.com copilot today. Turns out their "billing entity" isn't set in their user profile: If copilot usage is being blocked and you should be able to spend AI credits, check here: github.com/settings/cop... #usagebasedbilling #userlevelbudgets
000
Jesse Houwing @jessehouwing.net · 01/06/2026
Blog post updated with details unconvered today: * API doesn't support swapover from PRU -> AICs. Requires delete+create. * Added full script at the bottom of the blog post! #github #usagebasedbilling #githubcopilot
030
Jesse Houwing @jessehouwing.net · 01/06/2026
It looks like there is a bug in the Budgets API when swapping from PRUs to AICs. Instead of updating, you need to delete and recreate the budgets: ``` Updating budget ~~~ to $500 gh: The following fields cannot be updated: budget_product_sku. (HTTP 400) ``` @github #usagebasedbilling
000
Jesse Houwing @jessehouwing.net · 29/05/2026
Automatically assign individual user budgets to your users using the new @GitHub Enterprise Budgets API which ships next week. jessehouwing.net/auto-assign-... #githubcopilot #usagebasedbilling #finops
jessehouwing.net
Auto-assign GitHub Copilot AI Credit budget to users
The deadline for GitHub Copilot Usage Based Billing is approaching rapidly. And today I've been busy setting up automation to assign each user their own bucket of Copilot AIC budget. On June 1st, all...
020
Jesse Houwing @jessehouwing.net · 26/05/2026
With the new pricing for @github.com Copilot I'm receiving more and more questions on how to measure the value. And the question is HARD. Scientifically proven to be hard. Here's my opinion, supported by a number of previous studies. jessehouwing.net/measuring-th...
jessehouwing.net
Measuring the Value of AI
The honeymoon is over. After months of aggressive rollouts, enterprises across the globe have given their employees access to AI coding assistants, copilots, and chat interfaces. And now the inevitabl...
020
Jesse Houwing @jessehouwing.net · 18/05/2026
You'll see some pretty big differences at the user level. Want to check out your most expensive users? Go to copilot-billing.xebia.ms
copilot-billing.xebia.ms
Xebia Copilot Billing Preview
Preview how GitHub's move to AI Credits-based billing for Copilot will impact your organization's costs. Customized by Xebia.
000
Jesse Houwing @jessehouwing.net · 18/05/2026
I just pushed an update to my fork which doesn't just calculate the AIC Net Cost based on your usage patterns for April, but also calculates a Fair AIC cost which fairly distributes the pooled enterprise/organization budget across all users, regardless of the day of the month the cost was incurred.
100
Jesse Houwing @jessehouwing.net · 18/05/2026
The GitHub #Copilot Billing Preview tool uses your April 2026 bill as a baseline to predict the cost in the future. But... In many European countries, April is a month with many holidays, which changes how the costs are distributed across your users.
A table showing significant differences between per-user costs based on their pattern of usage. Some users remain pretty much the same (had spent tokens throughout the month). Some users see a spike, they likely spent most tokens at the beginning of the month, then went on vacation.
100
Jesse Houwing @jessehouwing.net · 14/05/2026
* we keep all models enabled for everyone (we probably won't) * copilot's usage of tokens stay's the same (it won't) * assuming out number of assigned licenses stays the same (it won't) At least this allows us to have a conversation with finance and leadership.
A chart showing the current cost in the PRU era (1x), the projected cost in the Promotional Period (3x without intervention, 2x with optimization) and the projected cost post promotional period (currently at 3.6x)
010
Jesse Houwing @jessehouwing.net · 14/05/2026
ASSUMING: * usage stays the same to April 2026 (it won't) * the token prices stay the same (they won't) * the available models won't change (they will) * we don't put extra budgets in place (we will)
100
Jesse Houwing @jessehouwing.net · 14/05/2026
I also ran the projection for spend post September 1st. Which is based on MANY many assumptions, but we see another 1.8x increase of the optimized spend after the promo period.
100
Jesse Houwing @jessehouwing.net · 14/05/2026
Had to hack the preview app in order to see this and asked Copilot (how fitting) to build a license optimization routine for me. For some customers it's even beneficial to assign up to 60 extra Copilot for Enterprise licenses to current users of GitHub Enterprise.
120
Jesse Houwing @jessehouwing.net · 14/05/2026
This is due to the extra +$31 AICs included in Copilot Enterprise in the promotional period for current users of GitHub Copilot who upgrade to Copilot for Enterprise on June 1st. The extra license costs are worth the extra AICs for the organizations I looked at so far.
110
Jesse Houwing @jessehouwing.net · 14/05/2026
Ran the numbers for the new #Copilot Usage based billing across a couple of organizations. We're seeing an average 3x increase in spend during the promotional pricing period if we don't do anything. Upgrading all our users to Copilot Enterprise, can reduce the cost increase to roughly 2x.
A chart showing the current cost in the PRU era (1x), the projected cost in the Promotional Period (3x without intervention, 2x with optimization) and the projected cost post promotional period (currently at 3.6x)
100
Reposted by Jesse Houwing
Scrum Bug @index.jessehouwing.net.ap.brid.gy · 11/05/2026
Last month GitHub announced Usage Based Billing for GitHub Copilot. This completely changes the way its costs are calculated. A lot has already been written about the impact and a lot is still unknown.
jessehouwing.net
The why for Usage Based Billing for GitHub Copilot
Last month GitHub announced Usage Based Billing for GitHub Copilot. This completely changes the way its costs are calculated. A lot has already been written about the impact and a lot is still unknown. In this post I want to explore the reasons why this switch was inevitable and how it enables new scenarios to make Copilot perform better than it did before. ## Quick recap of copilots current pricing model GitHub Copilot is currently available in 5 different plans: * GitHub Copilot Free - severely rate limited free version with no option to buy additional requests. * GitHub Copilot Pro - Individual license with limited Premium Request Units. * GitHub Copilot Pro+ - Individual license with more extensive Premium Request Units. * GitHub Copilot for Business - License for organizations with centralized policies and limited Premium Request Units. * GitHub Copilot Enterprise - License for organizations with centralized policies and more extensive Premium Request Units. Each of these licenses has a fixed monthly price. GitHub Copilot includes suggestions and a limited set of free models. And about a year ago, GitHub introduced the concept of Premium Request Units to pay for more powerful models and and PRUs are the used to charge for specific features like the Cloud Coding Agent and Copilot Code Review. When the Cloud Coding Agent was introduced, it could use more than 1 PRU per request. This made the cost of the agent unpredictable and GitHub soon changed the price of the Cloud Coding Agent to a single PRU per request. When a user has exhausted their included PRU budget, additional PRUs are charged. Additional PRUs have a fixed cost. ## Usages of PRUs The primary use of PRUs are to charge the costs of requests to the users of GitHub Copilot. Each model is assigned a multiplier of 0, 1, up to 50 (highest so far) PRUs. The model multiplier wasn't just used to charge the cost, it's an open secret that it was also used to divert users to other models to load balance them. Most people are more hesitant to use expensive models carelessly. The introduction of the "Auto" mode rests on this principle. Users get a 10% discount on PRUs if they let GitHub select their model. While most users seem to assume this will route them to the "best model for the task", this generally sends the request to the "model with the best availability". Premium Request Units were also reduced for promotional purposes. When Claude Opus 4.7 was introduced, it's multiplier was temporarily set to 3x, later increased to 15x. This promotional use isn't just to get us "hooked" on the more powerful model features, it's also to allow GitHub to get crucial statistics on how these new models perform and to help them iron out bugs. ## How GitHub pays for model usage The model providers, Anthropic, Google, OpenAI, X, don't charge the cost of their models in Premium Request Units. They charge the cost in terms of Tokens. Input Tokens, Output tokens and Cached tokens at the highest level. Given the amount GitHub uses, they have probably got a really good deal. But GitHub needs to balance the cost for the Tokens it spends against what it can charge its users in Premium Request Units. GitHub also balances the costs between Tokens and PRUs by limiting the maximum token window for models. For example, if you're using Claude Opus 4.6 through GitHub Copilot, the maximum token window is 200k tokens. If you use the same model directly through Anthropic you have a maximum of 1m tokens. As Agent Mode and Cloud Coding Agent got more powerful, more tools appeared, the models are using more and more tokens for every request, reducing the available token window for your requests. ## Other ways GitHub control costs GitHub has a few other options to control the maximum number of tokens you can use for each Premium Request Unit they charge you. **Agent Mode -** Agent Mode spends tokens and action minutes. GitHub can control the token spend by forcing the agent to come to an early conclusion or to postpone work to a future session. **Cloud Coding Agent** - The cloud coding agent spends tokens and action minutes. GitHub can control the token spend by forcing the agent to come to an early conclusion or to postpone work to a future session. The workflows running the Cloud Coding Agent runs on is limited to 2 hours. **Code Review** - Similar to the Cloud Coding Agent, when using GitHub's Code Review feature, GitHub can control the token spend by limiting the total time and the total of tokens the feature can spend. When using these features, GitHub can also control which model is used to perform these tasks. Some features, like tool optimization in Visual Studio Code also limit the total number of tokens used for each session by default. ## Recent creative uses New features, like subagent and fleets have multiplied the number of tokens you can use in a single Agent request. Visual Studio Code extensions have allowed users to steer the agent without completing the Agent request. These creative usages, some people might call them abuse, have allowed some people to use significantly more tokens costs than the PRU is worth. In some cases thousands time more. And instead of figuring out how to charge its users in Premium Request Units in this new model, GitHub will charge us for the actual tokens instead. ## So what changes Instead of the abstract thing, called Premium Request Units, acting as a proxy for the real cost of AI usage, we're going to be charged in tokens, the same unit in which GitHub is charged. Unfortunately, the different model providers, each charge different prices for different kinds of tokens. So GitHub still uses a multiplier so they can charge a single unit for the bill. GitHub explains how the new pricing model works on the GitHub Blog. You can see find the upcoming changes to the model multiplier in the GitHub docs. The new multipliers should not just result in higher costs, but is also expected to more equally spread the load across the available models as users will be more likely to try to find the most cost effective model to use for the work they're trying to accomplish. ## Additional changes for Business accounts In addition to the new pricing, GitHub is introducing a number of welcome changes for business accounts (Copilot for Business and Copilot Enterprise). **Pooled usage** - Under the current model, when a user has spent all of its budget, additional requests are automatically charged. Under the new model, the budget of all users is pooled together. So the unused budget from less frequent users can be consumed by more frequent users in the same organization. Only when the full pooled budget is used up, will additional usage be charged. **Individual additional budgets** - Under the current model, additional charges can be controlled through budgets, these are pooled together for all users in the same cost center. In the new model it's possible to set a per-user budget as well as a universal budget for all users in addition to the already existing budget control options. In addition to these changes, existing policy options to control costs are still available: **Enterprise, Organization** and **Cost Center Budgets** - Existing budget options to limit the total spend at the Enterprise, Organization and Cost Center can still be configured to limit the total spend on AI costs. **Limit model availability** - Enterprise and Organization level policies allow admins to control the available models. This can remove less effective and more expensive model options. **Limit feature availability** - Enterprise and Organization level policies allow admins to control the available features. This can remove more expensive features like Code Review and Cloud Coding Agent for specific users. But, ultimately, limiting the cost isn't the path forward. Optimizing the value delivered through AI is. Use these limits to bridge the time it takes to educate your users.
011
Jesse Houwing @jessehouwing.net · 12/05/2026
To better understand why GitHub is changing the billing of Copilot, and why it may not be a bad thing for us in the end, I put this blogpost together. - It limits abuse - It loadbalances model usage - It allows for longer workflows - It allows for more tokens jessehouwing.net/usage-based-...
jessehouwing.net
The why for Usage Based Billing for GitHub Copilot
Last month GitHub announced Usage Based Billing for GitHub Copilot. This completely changes the way its costs are calculated. A lot has already been written about the impact and a lot is still unknown...
000
Jesse Houwing @jessehouwing.net · 24/04/2026
I just moved my late father's website, so it may stay around to show his legacy and to support readers of his books. The most important reason, to keep scammers from using it for nefarious purposes. These things are much harder than they first seem. Not just technically, but also emotionally.
000
Jesse Houwing @jessehouwing.net · 24/04/2026
I've always had this association with guitar hero when viewing really convoluted git histories. And today I turned that into reality :). Introducing: gh guitar-hero! Hard-fast is really only for the best typists I suppose ;). #github #copilot #vibecoding
010
Jesse Houwing @jessehouwing.net · 15/04/2026
@lirantal.com why would #snyk recommend to use their action pinned at `@master` instead of an immutable version or a sha? ``` name: Security - name: Run Snyk to check for vulnerabilities uses: snyk/actions/node@master ``` BAD idea. snyk.io/articles/how...
snyk.io
Securing your GitHub Actions workflows to Enhance JavaScript Security | Snyk
Snyk provides a pre-built custom Snyk GitHub Actions workflow that you can add to your CI and saves you the trouble of managing the vulnerability scans using the Snyk CLI directly.
000
Reposted by Jesse Houwing
Scrum Bug @index.jessehouwing.net.ap.brid.gy · 15/04/2026
With the current political climate there has quite a bit of buzz around Data Residency and Data Sovereignty. One of the gaps in GitHub with Data Residency, was that all Copilot data could still leave the region. This is now a thing of the past
jessehouwing.net
Github Copilot now available with Data Residency in the EU
With the current political climate there has quite a bit of buzz around Data Residency and Data Sovereignty. And the number of inquiries to migrate from GitHub Enterprise Cloud to the Data Resident version have gone up. One of the gaps in GitHub with Data Residency, was that all Copilot data could still leave the region. This is now a thing of the past: Copilot data residency in US + EU and FedRAMP compliance now available - GitHub ChangelogGitHub Copilot now supports data residency for US and EU regions, ensuring all inference processing and associated data stay within your designated geography. For US government customers, all model hosts…The GitHub BlogAllison To make use of this new feature, you must already be using the Data Resident version of GitHub Enterprise Cloud (also known as `ghe.com` or by GitHub's internal codename Proxima). To restrict Copilot to only use Data Resident models, a policy must be enabled at the Enterprise or Organization level: Set ****Restrict Copilot to Data Residency Models**** to ****Enabled everywhere**** to ensure copilot data is processed in your Data Residency region. Currently all **Generally available** copilot features are included according to GitHub, but new features may take a bit longer to be enabled on your GitHub environment, as they may not yet be available for Data Residency during preview phases. This has been the case with other GitHub features as well, so this shouldn't come as a surprise.
021
Jesse Houwing @jessehouwing.net · 15/04/2026
With the current political climate there has quite a bit of buzz around #DataResidency and #DataSovereignty. One of the gaps in @github.com with Data Residency, was that all Copilot data could still leave the region. This is now a thing of the past: jessehouwing.net/github-copil...
jessehouwing.net
Github Copilot now available with Data Residency in the EU
With the current political climate there has quite a bit of buzz around Data Residency and Data Sovereignty. One of the gaps in GitHub with Data Residency, was that all Copilot data could still leave ...
000
Jesse Houwing @jessehouwing.net · 05/04/2026
Aaaaand may god grant us the power and the will to act
030
Jesse Houwing @jessehouwing.net · 05/04/2026
They will probably still try to collect the taxes.
010