At a glance
- GitHub Changelog (Sep 21) rolls Grok 4.7 into Copilot for Pro through Enterprise; Cursor and xAI put the same model in Cursor at Grok 4.6 price and speed.
- GitHub Enterprise (Sep 21) adds credential inventory exports so owners can CSV or API-dump every SSH key, PAT, OAuth token, and GitHub App token that can reach the enterprise.
- CodeQL (Sep 22) deprecates the all-platform bundle starting in CLI v2.27.0, with removal targeted for mid-March 2027.
- The refreshed repository pull requests page (Sep 21) is generally available, with stronger filters and bulk actions for busy PR queues.
Tuesday is thinner on brand-new Claude, Codex, and Gemini product GAs than on model distribution and GitHub hygiene, so the useful work is picker policy, credential inventory, and CodeQL install pins. Grok 4.7 lands in Copilot and Cursor while Grok 4.5 already sits on the October 19 Copilot deprecation list from Friday, Enterprise owners finally get a single export of every credential that can touch the org, CodeQL stops treating the all-platform tarball as the long-term default, and the new PRs page makes agent PR triage less noisy.
Treat today as a Grok-4.7-enable, credential-inventory-export, CodeQL-platform-bundle, and PR-queue-filter day. Confirm Grok 4.7 appears in the Copilot model picker (or is allowed in Business/Enterprise model policy), pull one credential inventory CSV for a non-production org slice, find any Actions job still curling `codeql-bundle.tar.gz`, and try content-assist filters on a repo with a busy agent PR list.
Top Stories
Grok 4.7 rolls into GitHub Copilot (and Cursor) for agentic coding
Practical dev impact: GitHub Changelog (Sep 21) says Grok 4.7, xAI’s latest reasoning model, is rolling out in GitHub Copilot for agentic coding and complex multistep workflows, billed at provider list pricing under usage-based billing. It is available to Copilot Pro, Pro+, Max, Business, and Enterprise, and selectable in VS Code, Visual Studio, Copilot CLI, the Copilot cloud agent, the Copilot app, JetBrains, Xcode, and Eclipse, with a gradual rollout so some seats may not see it yet. Business and Enterprise admins gate it through the model policy; under default model enablement, new models turn on unless the global default is off or the model is explicitly disabled. The same day, Cursor’s blog and xAI’s announcement put Grok 4.7 in Cursor (and Grok Build) at the same price and speed as Grok 4.6, with xAI citing CursorBench 4.0 at 46.3% versus 40.4% for 4.6 and Terminal-Bench 4.0 at 38.0% versus 20.3%, plus $2 / $6 per million input/output tokens. Pair that with Friday’s Copilot notice that Grok 4.5 (among other models) retires on October 19, 2026, so today is less a new toy and more a reason to update the picker pin and the admin allowlist before October.
GitHub Enterprise credential inventory exports for incident response
Practical dev impact: GitHub Changelog (Sep 21) lets enterprise owners export a complete inventory of every credential that can access the enterprise, including SSH keys, classic and fine-grained personal access tokens, OAuth App access tokens, and GitHub App user-to-server and installation tokens. Owners (and members with the fine-grained `View enterprise credentials` permission) can export a CSV from Settings → Authentication Security → Credentials, or pull the same inventory through a paginated REST API, then filter by user, app, credential type, or organization and review owners, scopes, creation and expiration dates, last-used dates, and target organizations or repositories. The post frames it for security incidents: assess blast radius, plan remediation, and correlate with audit log activity. It is live on GitHub Enterprise Cloud now, with GitHub Enterprise Server support called out for upcoming releases. For teams that let coding agents mint PATs and app installations, this is the inventory step that recent sandbox and marketplace trust stories made uncomfortable to skip.
All-platform CodeQL bundle deprecated from CLI v2.27.0
Practical dev impact: GitHub Changelog (Sep 22) marks the all-platform CodeQL bundle (`codeql-bundle.tar.gz` and `codeql-bundle.tar.zst`) as deprecated starting with CodeQL CLI v2.27.0, with removal planned for mid-March 2027. Download the platform-specific bundle for your OS and architecture instead. Linux ARM64 binaries ship only through those platform-specific downloads and are not included in the all-platform bundle. If your Actions workflows or self-hosted runners still pin the all-platform tarball URL, start migrating the pin now rather than waiting for a hard break next March.
Refreshed repository pull requests page generally available
Practical dev impact: GitHub Changelog (Sep 21) makes the new repository pull requests page generally available to all users. Content assist helps apply filters, advanced search supports `AND` / `OR` and nested searches, a collapsible sidebar exposes common filters such as “Authored by me” and “Involves me,” compact mode fits more PRs on screen, and rows show status-check counts, stack indicators, and unread updates. Since preview, GitHub added bulk close/label/milestone actions, milestones and linked issues, clickable review-status filters, and full profile names when enabled for the enterprise. For repos where agents open many PRs, this is UI triage, not a new review model, so keep claims inside filtering and bulk actions.
Practical Impact Analysis
The through-line is distribution and inventory: which models your agents may call, which credentials those agents can still use, and which CI artifacts your scanners still download. Grok 4.7 arriving in Copilot and Cursor while Grok 4.5 sits on the October 19 Copilot retirement list means picker pins and Business/Enterprise model policies need a deliberate refresh, not a silent default. Credential inventory exports then give Enterprise owners a single CSV or API plane over PATs, SSH keys, and app tokens that agent workflows tend to multiply, which is the governance move after a week of sandbox and marketplace trust stories. CodeQL’s all-platform bundle deprecation is quieter but operational: platform-specific pins avoid a mid-March 2027 surprise, especially on Linux ARM64. The refreshed PRs page is the human side of the same week, because agent-opened pull request queues need better filters and bulk actions once the models and tokens are sorted.
If you run Copilot Business or Enterprise, Tuesday is the day to check whether default model enablement already exposed Grok 4.7, whether your policy should allow it for agent mode, and which seats still pin Grok 4.5 ahead of October 19. If you own a GitHub Enterprise Cloud tenant, export one credential inventory for a pilot organization, filter to fine-grained PATs and GitHub App installations, and map last-used dates against known agent bots. Platform and security engineering should grep Actions for `codeql-bundle.tar.gz` / `.tar.zst` and switch those jobs to OS/arch-specific URLs before v2.27.0 becomes your fleet default. PR maintainers can switch one busy repo to the new PRs page, save an “Involves me” plus failing-checks filter, and decide whether bulk labeling replaces a manual triage doc.
If you only do three things this morning: enable or verify Grok 4.7 in Copilot (and try it once in Cursor if you use it), export one Enterprise credential inventory CSV and review PAT/app rows, and replace any all-platform CodeQL bundle download with a platform-specific pin.
Tutorial
Verify Grok 4.7 in Copilot policy, export a credential inventory checklist, and find all-platform CodeQL pins. Run these checks on an admin or maintainer machine, not inside an untrusted agent session. Keep tokens out of the script body.
1. In VS Code or Copilot CLI, confirm “Grok 4.7” appears in the model picker after gradual rollout. For Business/Enterprise, open org Copilot settings → model policy and allow Grok 4.7 (or confirm default enablement). Note the Oct 19, 2026 Copilot retirements (including Grok 4.5) from the Sep 18 changelog. 2. Export an Enterprise credential inventory (Cloud UI or API; needs enterprise owner or fine-grained “View enterprise credentials”). UI path: Enterprise settings → Authentication Security → Credentials → Export CSV. Then filter the CSV for fine-grained PATs and GitHub App installation tokens used by bots. 3. Grep this repo’s workflows for all-platform CodeQL bundle pins (`codeql-bundle.tar.gz` / `.tar.zst`) and switch to platform-specific URLs for your runner OS/arch. Linux ARM64 is platform-specific only. 4. Next: open one busy repo on the new Pull requests page and save an Involves-me plus failing-checks filter.
Confirm the model picker or policy shows Grok 4.7, that the credential CSV opened and was filtered to agent-relevant token types, and that no workflow still hard-depends on the all-platform CodeQL tarball. Then exercise the new PRs page filters on a real queue.
Recommended AI prompt
Copy this paragraph into ChatGPT, Claude, Gemini, Grok, or whatever you use.
You are my staff engineer for Copilot/Cursor model pinning, GitHub Enterprise credential inventory, and CodeQL CI bundle hygiene. Context for 2026-09-22: GitHub Changelog (Sep 21) rolls Grok 4.7 into Copilot for Pro/Pro+/Max/Business/Enterprise across VS Code, Visual Studio, Copilot CLI, cloud agent, Copilot app, JetBrains, Xcode, and Eclipse, billed at provider list pricing under usage-based billing, gradual rollout, gated by Business/Enterprise model policy with default model enablement; Cursor blog and xAI news (Sep 21) put Grok 4.7 in Cursor at Grok 4.6 price/speed ($2/$6 per M input/output per xAI) with stronger CursorBench 4.0 and Terminal-Bench 4.0 scores; Sep 18 Copilot notice retires Grok 4.5 (and other models) on October 19, 2026. GitHub Changelog (Sep 21) adds Enterprise credential inventory exports (CSV or paginated REST) covering SSH keys, classic and fine-grained PATs, OAuth App tokens, and GitHub App user-to-server and installation tokens, with filters and audit-log correlation, on Enterprise Cloud now. GitHub Changelog (Sep 22) deprecates the all-platform CodeQL bundle from CLI v2.27.0 with removal mid-March 2027; use platform-specific bundles; Linux ARM64 only via platform-specific downloads. Refreshed repository PRs page is GA (Sep 21) with advanced filters and bulk actions. Ask which Copilot SKUs and Cursor usage we have, which Enterprise orgs we can export, and where CodeQL is installed in CI. Then produce (1) a Grok 4.7 enablement and Oct 19 deprecation migration checklist, (2) a credential-inventory export and PAT/app review runbook, (3) a CodeQL platform-specific bundle migration steps list, and (4) a short PRs-page triage filter recipe for agent-heavy repos. Keep it concrete and copy-paste ready.
Sources
Recommended AI prompt
Explore each Top Story in Grok. Links open in a new tab. On phones, the same link may open the Grok app if you have it installed (via your device's normal link handling).
Article: Copilot and Cursor Add Grok 4.7 as GitHub Exports Credentials and Deprecates CodeQL Bundles
Privacy: links open grok.com in your session only. AIDevPulse does not run your prompts through our API.