A pull request review panel connects to Jira cards and a guarded plugin marketplace
A pull request review panel connects to Jira cards and a guarded plugin marketplace
+ Microsoft News

GitHub turns Copilot governance into a code-review and Jira story

GitHub's June 25 Copilot updates pair cheaper code-review analysis with Jira agent visibility and stricter controls over plugin marketplaces.

GitHub published a set of Copilot changes on June 25 that are easy to read as separate product notes. Together, they show where Copilot is going: deeper into code review, project-management context, and enterprise control surfaces.

The sharpest change is inside Copilot code review. GitHub says the review system now uses file-exploration tools from the Copilot CLI and SDK, including grep, rg, glob, and view, instead of custom file tools. GitHub says that change, plus instruction tuning, reduced code-review costs by about 20% while maintaining the same review-quality standard in offline and online evaluation.

That is not only an efficiency note. It means Copilot’s review path is becoming closer to the same tool-using agent surface developers use in the terminal.

Review depth is becoming a managed setting

GitHub also added more visibility and control for teams using the Medium analysis depth public preview. Copilot code review now labels medium-depth runs in the pull request overview comment, and organizations can set a default review level for repositories that have not configured one.

The practical effect is clearer accountability. If an automated review missed something, a team can tell whether it came from a medium-depth run. If an organization wants a higher or lower default review posture across repositories, it can set that once and still allow repository-level overrides.

That matters because AI code review is not a magic gate. It is a managed risk-control layer. Review depth, review cost, and review signal quality all need to be visible enough for engineering leaders to tune them deliberately.

Plugin governance moves before tool execution

GitHub’s second June 25 item is about plugin control. Enterprises can now add strictKnownMarketplaces to enterprise-managed settings.json so Copilot in VS Code and the Copilot CLI only allows plugins from explicitly defined marketplaces.

That is a small setting with a large governance implication. As coding agents gain plugins, skills, and MCP-style tool connections, the risk is no longer only what the model says. It is what the toolchain is allowed to install and execute before a developer notices.

GitHub frames this as a way to enforce client governance before tool execution. That is the right layer. A policy that only reviews agent output is late; a policy that controls trusted plugin sources shapes the agent’s working environment.

Jira makes the workflow wider

The third update is GitHub Copilot for Jira reaching general availability. Since the March 2026 public preview, GitHub says it added model selection, Confluence context through MCP, custom agents, custom fields, space-level guidance, and review-request notifications in Jira.

The GA release continues that direction with more visibility and control over agent sessions. For teams that live between Jira tickets, pull requests, and documentation, this is the important shift: Copilot is not confined to the editor. It is being placed across the planning-to-code path.

That can save context-switching, but it also creates new admin questions. Which Jira spaces can inform the agent? Which repositories can it touch? Which plugin marketplaces are trusted? Which review depth is the default? Copilot is becoming a workflow system, so it inherits workflow governance.

Sources

The AI Feed Desk

The AI Feed Desk

Editorial desk

The AI Feed Desk tracks AI provider updates, model releases, agent tooling, and enterprise adoption, turning fast-moving announcements into source-linked context for builders and operators.

Noticed a typo, incorrect information, or translation error?

Tell us so we can fix it.

Help Improve This Article

Related Articles

A Copilot routing panel sends developer tasks either to automatic model selection or to private model providers

GitHub makes Copilot routing more automatic while opening BYOK in the app

GitHub's latest Copilot changes push Free and Student users toward automatic model routing while giving Copilot app users bring-your-own-key model providers.

The AI Feed Desk

By The AI Feed Desk

A usage dashboard shows AI credit consumption bars for individual developers

GitHub adds per-user AI credit metrics for Copilot admins

GitHub's Copilot usage metrics API now reports per-user AI credit consumption, giving enterprise and organization admins a clearer signal for adoption and budget planning.

The AI Feed Desk

By The AI Feed Desk

A routing switchboard sends coding tasks into different model lanes from an admin control plate

Copilot auto model selection turns routing into an admin setting

GitHub Enterprise admins can now default Copilot conversations to auto model selection through managed-settings.json, tying model routing to enterprise AI standards.

The AI Feed Desk

By The AI Feed Desk

Shared AI credit tokens flow through team lanes while one cost center lane is stopped by a cap gauge

GitHub cost centers can cap shared AI credit pools

GitHub added AI credit pools for cost centers, letting enterprise admins cap how much monthly included Copilot credit one group can draw before metered budgets apply.

The AI Feed Desk

By The AI Feed Desk

A developer operations dashboard connects Copilot activity, AI credit counters, and team-level usage reports

GitHub adds AI credit usage to Copilot admin metrics

GitHub's Copilot usage metrics API now reports per-user AI credits consumed, giving enterprise and organization admins another signal for adoption and budget planning.

The AI Feed Desk

By The AI Feed Desk