跳到正文
GitHub Blog· Andrea Griffiths·· 3 小时前AI 评分37

GitHub Universe 2026 值得期待的 10 场技术演讲

10 technical talks I’m excited about at GitHub Universe 2026

AI 导读

GitHub Universe 2026 的 10 场技术演讲聚焦智能体记忆、评估与权限,包括 GitHub 研究人员用真实 pull request 序列构建 benchmark,发现累积上下文反而会拖累性能。

正文

I’m looking for ideas I can take back to my own work, from verifying agent-written code and securing dependencies to building software that works where internet access is unreliable.

There are more sessions at GitHub Universe than I can fit into two days. To narrow the list, I built my agenda around questions I’m working through right now:

  • How do we know an agent’s code works?
  • What should it remember?
  • What are we trusting every time we install a dependency?

That puts agent memory, evaluations, and permissions high on my list. I’m also making room for JavaScript tooling and building software where internet access is unreliable. Here are my 10 picks.

What happens behind the scenes when you run npm install

Most of us use npm, but the truth is that many of us rarely stop to think about the people, permissions, and release processes behind the packages it pulls in. Karen Li and Leo Balter from GitHub will trace those dependencies through the systems that publish and protect them. I’m interested in what npm audit can’t catch, and where package provenance and OpenID Connect fit into the picture.

View the full session description >

How GitHub taught Copilot to remember and when to forget

GitHub researchers Cooper Nederhood and Alejandro Carderera built a benchmark from sequences of real pull requests and found that accumulated context can hurt performance. We expend a lot of effort deciding what context to give an agent. I want to understand what to not give. They’ll cover how that research informs their work on agent memory, including features still in development.

View the full session description >

Treat your AI context as infrastructure

You’ve written instructions, built and installed skills, and added your MCP servers. It works for you. How do you make that context useful across a team? Christopher Harrison from GitHub will break down what each tool is good for and how to distribute the right context consistently as your setup grows.

View the full session description >

Open pull requests, don’t merge them: Fine-grained authorization for hosted MCP servers

“Open a pull request, but do not merge” is a boundary I want enforced in permissions. Putting it in an instructions file feels like an inadequate setup. Nick Taylor from Pomerium will demonstrate an identity-aware proxy that adds per-identity authorization in front of a hosted MCP server without changing the upstream server. I want to see how the rule holds up when an agent actually tries to act.

View the full session description >

Your benchmark is lying: What evals actually look like

A model can score well on a benchmark and still disappoint developers using it. Walker Chabbott from GitHub and Julia Kasper from Microsoft will show how Copilot evaluates models in production, including what the team measures and what they stopped measuring. Metrics help us and models make real decisions, so understanding what to measure is more important than ever. This session is a Sandbox Session, so I’m looking forward to working through the question of what makes an evaluation useful.

View the full session description >

Beyond pass or fail: How agents verify AI-generated code 

The test passed so why is the app still broken? Safe to say we’ve all been there. Jeff An from Momentic will explore how agents investigate applications, reproduce unexpected behavior, and distinguish product bugs from broken tests or infrastructure failures.  I’m especially interested in the deterministic controls that limit what those agents can do while they investigate. 

View the full session description >  

The 2 a.m. RCA Agent: Architecting AI that investigates, not hallucinates 

In the architecture Achin Gupta from Intuit and Divya Mahajan from Amazon will present, deterministic code handles signal collection, topology traversal, correlation, and scoring. The language model narrates the evidence. That’s a clear split of responsibilities, and I want to understand the decisions behind it. 

View the full session description >  

Disrupting supply chain attacks: A threat framework for GitHub Actions 

 A workflow with access to credentials and the ability to publish a release is an attractive target. Steve Glass and Greg Ose from GitHub will map supply chain attack techniques to GitHub Actions controls, covering the ecosystem, workflow attack surface, and runner infrastructure. I want a clearer picture of where to put defenses in a pipeline I’d trust with a release. 

View the full session description >  

One CLI to replace your entire JavaScript toolchain 

“Your entire JavaScript toolchain” is a bold statement. I’m glad this session includes a real migration. Alexander Lichter from VoidZero will walk through Vite+, an open source CLI for managing the front-end toolchain. Bundling, testing, linting, formatting, runtime management: there’s plenty of configuration in that list. I want to see what Vite+ replaces today, what I’d need to manage separately, and what’s on the roadmap. 

View the full session description >  

Lessons from building tech in a low-connectivity community 

Alex Junior Antwi from Braveon AI will share lessons from building CarbonSight for low-connectivity communities in Ghana. There is a long list of concerns when building for less-than-ideal connectivity scenarios, and shouldn’t we all build for our least-connected users? I’m very excited about the offline demo on this one. 

View the full session description >  

Come build a skill with us 

I’ll also join Shishir Tewari from Procore for Build once, run on any agent: a practical guide to agent skills. I’ll bring the skills I’ve built for recurring work; Shishir will bring his experience building skills for a production data engineering team. We’ll explore when a workflow belongs in a reusable skill. If you’re tired of repeating yourself to your coding agent and want to understand what makes a skill useful in both your work and personal projects, come join us. 

Want to see what else is happening at Universe? Think about the topics you are prioritizing, then check out the rest of the schedule here and add sessions to your agenda. And if you haven’t registered yet, there’s still time to pick up in-person or virtual passes. I hope to see you there October 28–29!

The post 10 technical talks I’m excited about at GitHub Universe 2026 appeared first on The GitHub Blog.

来源:GitHub Blog · github.blog