vibehacker
News
GitLab Blog ·

GitLab Dependency Firewall blocks malicious or too-new packages before agent-added dependencies hit the build

In early access since Oct 6 for Premium and Ultimate on GitLab.com and Self-Managed, it checks npm, pip, Poetry, Maven, Gradle, and Bundler installs against policies for malware flags, vulnerability severity, license, and a minimum package age, starting in warn mode before you switch to block, with a CLI check your agent can run before adding a dependency. GitLab pitches it at coding agents that pull in unreviewed packages, after its researchers found typosquats of Flask, Requests, and NumPy stealing CI credentials in June.

More news

View all

Jira can now assign tickets to Devin, Factory, or Warp, and Code Context indexes your repos for agents

Announced Oct 7 at Team '26 Europe, you can pick one of these coding agents in a Jira ticket's assignee field (or @mention it in a comment) and it works from the ticket and opens a pull request, with OpenAI Codex coming soon and Jira events usable as automation triggers. Code Context, now rolling out in open beta to paid customers, indexes code across connected Bitbucket and GitHub repos so agents can search it alongside the linked Jira, Confluence, and Loom context…

Atlassian Blog

Atlassian rebuilds its MCP server: 220+ tools across Jira, Confluence, Bitbucket, and Loom, now GA

Announced Oct 6 at Team '26 Europe, the hosted server (OAuth 2.1 + PKCE, respects each user's existing permissions) now reaches Bitbucket Cloud PRs, semantic Code Search, Confluence whiteboards and databases, and Loom transcripts, and Atlassian says it uses up to 25% fewer tokens than the old version on the same Jira and Confluence work. Read, write, and destructive tools are split so clients like Cursor or Claude Code can require confirmation on the risky ones, and you can now ship custom MCP tools through Forge…

Atlassian Blog

Claude now runs in a sidebar inside Google Docs, Sheets, and Slides, and can live-edit Google files from chat

Claude for Google Workspace, a public beta on all paid plans since Oct 6, installs once from the Google Workspace Marketplace and reads and edits whichever doc, sheet, or deck you have open (with an ask before edits mode), while new Docs, Sheets, and Slides connectors let Claude create and edit Google files in a pane beside the chat. In the beta, each task is limited to six minutes, it can't touch other Drive files, and Firefox isn't supported; on Team and Enterprise an owner has to turn the connectors on first…

Claude Blog

Wiz AI SAST enters public preview, hunting logic bugs like IDOR that rule-based scanners miss

Released Oct 6 for all Wiz Code customers, the scanner runs on the Atlas harness (No. 1 on CyberGym at its July launch) to find intent dependent flaws like broken access control and missing ownership checks, with confidence scores, reproduction commands, and retesting plus semantic dedupe so findings stay stable between non deterministic runs. Its Green Agent can hand fix context to a coding agent like Claude Code, which matters if your agent built endpoints skip auth checks that look syntactically fine…

Wiz Blog

LiteLLM open-sources Moyai, a self-hosted cloud agent that runs Claude Code or Codex and returns a PR

Released Oct 7, Moyai takes a task from Slack or the browser, runs it in its own cloud workspace with a terminal and browser using Hermes, Claude Code, Codex, OpenCode, or Deep Agents, and opens a pull request while your laptop is closed, with any of 100+ providers routed through your LiteLLM gateway and keys kept out of the sandbox. LiteLLM says it cut its internal bill from $101,872 on Devin to about $21,700 over 31 days, and the repo ( BerriAI/moyai ) has a local demo that needs no API keys…

LiteLLM Blog

Spotted something we missed? Start a thread.