Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
In this sprint, Copilot Autofix adds agentic capabilities and repository context. We're also introducing EPSS data to help prioritize dependency alerts, configurable Copilot code review effort levels, more reliable pull request status checks, new Microsoft-hosted agent images, and multi-target framework code coverage.
Check out the release notes for details.
GitHub Advanced Security for Azure DevOps
- Copilot Autofix now uses an agentic foundation and repository context
- Prioritize dependency alerts with EPSS data
Azure Repos
- Effort level configuration for Copilot code reviews (public preview)
- Reliability improvements for pull request status checks
Azure Pipelines
- Windows Server 2025 with Visual Studio 2026 is generally available
- Ubuntu 26.04 is generally available
Azure Test Plans
GitHub Advanced Security for Azure DevOps
Copilot Autofix now uses an agentic foundation and repository context
Copilot Autofix for GitHub Advanced Security for Azure DevOps now supports generating fixes for code scanning alerts from CodeQL and third-party scanning tools.
Autofix also now runs on an agentic foundation. Agentic Autofix can review and refine its proposed changes before returning a suggestion. It can use custom instructions and skills defined in supported .github or .agents locations in your repository. This context helps suggested changes follow your team's coding standards, architecture, and remediation patterns.
The Autofix experience stays the same. Open a code scanning alert, select Generate fix, and review the explanation and proposed diff before creating a pull request. For more information, see Fix code scanning alerts with Copilot Autofix.
Autofix remains in limited public preview, and we aren't accepting additional participants at this time. We'll share more when the public preview opens.
Prioritize dependency alerts with EPSS data
Dependency scanning alerts now show Exploit Prediction Scoring System (EPSS) percentile data in alert details. EPSS estimates the likelihood that a vulnerability will be exploited in the wild, giving you more context to prioritize remediation alongside severity.
You can also filter the Alerts page by EPSS percentile to focus on vulnerabilities with a higher likelihood of exploitation. For more information, see Dependency scanning alerts.
Azure Repos
Effort level configuration for Copilot code reviews (public preview)
If you use GitHub Copilot Code Review with Azure Repos, you can now select the effort level for a code review.
The effort level controls how much time Copilot spends reviewing a pull request. This gives you more control over the review and can help reduce costs for pull requests that don't require an in-depth code review.

You can also configure the default effort level as Lite or Balanced at the project or repository level. Project administrators can set the default across all repositories in a project, while individual repositories can have their own default when needed.

This gives teams the flexibility to choose the appropriate level of review based on their needs.
If you aren't yet using GitHub Copilot Code Review for Azure Repos, learn more about the feature and how to get started in our public preview announcement.
Reliability improvements for pull request status checks
We fixed a rare issue that could cause a pull request's status checks to fail to load, both in the web experience and when retrieving them through the REST API. When this issue happened, requests to read a pull request's statuses could return an error, which could block the pull request from being completed and disrupt automation or integrations that rely on status checks.
With this update, pull request statuses load reliably again, so checks and branch policies evaluate correctly, completion works as expected, and tools reading statuses through the API no longer hit the error. No action is needed, affected pull requests recover automatically.
Azure Pipelines
Windows Server 2025 with Visual Studio 2026 is generally available
Windows Server 2025 with Visual Studio 2026 is now generally available for Microsoft-hosted agents in Azure Pipelines. The windows-2025 label continues to use Visual Studio 2022 and will transition to Visual Studio 2026 by November 15, 2026. We recommend that you transition to the latest available image.
For more information, see the Windows Server 2025 image announcement.
Ubuntu 26.04 is generally available
Ubuntu 26.04 is now generally available for Microsoft-hosted agents in Azure Pipelines. To use this image, select the ubuntu-26.04 image label.
For more information, see the Ubuntu 26.04 image announcement.
Azure Test Plans
Code coverage supports multi-target framework projects
Azure DevOps code coverage now supports multi-target framework (multi-TFM) .NET projects. The service preserves and reports coverage results independently for each target framework, making it easier to compare coverage, validate migrations to newer .NET versions, and maintain accurate testing insights across multi-target applications.
This enhancement provides more reliable coverage reporting and better visibility into test quality throughout application modernization efforts.
Next steps
Note
These features will roll out over the next two to three weeks. Go to Azure DevOps and take a look.
How to provide feedback
We want to hear what you think about these features. Use the help menu to report a problem or provide a suggestion.

You can also get advice and have your questions answered by the community on Stack Overflow.