release aidev SIG 3/5

Devin: centralized plugin skill management, multi-repo code scans, chained attack paths

Skills can now be distributed via centrally governed Plugins across Devin Cloud, CLI, and Desktop. Code scans span multiple repositories with per-repo details. Related findings link as chained attack paths. Automations support GitHub Enterprise Server and long-running sessions. Numerous UI improvements including inline link previews, sortable tables, custom Slack emoji, and redesigned Automations pages.

PUBLISHED2026-07-17
OBSERVED2026-08-21
AGE1mo
SOURCES1
  • Plugin skill management: Skills distributed via centrally governed Plugins; admins configure required/optional/forbidden plugins; orgs inherit enterprise-managed policies
  • Multi-repo code scans: Single scan across multiple repos with per-repository details and repository filter on findings
  • Chained attack paths: Related findings linked to show how individual vulnerabilities combine into larger risks
  • Queued messages: Preference to auto-queue messages while Devin works; Enter sends next queued message; defaults to immediate send when Devin becomes available
  • Tasks tab: New tab showing Devin's latest task list
  • Inline link previews: Links render inline previews for markdown, PDF, HTML, CSV
  • Sortable tables: Tables in chat sortable by column
  • Custom Slack emoji: Workspace custom emoji render correctly in synced session history
  • Instant Slack unsync: "unsync" or "!unsync" in synced Slack thread immediately stops syncing
  • Revamped Automations: Redesigned editor, clearer trigger config, option for long-running session receiving subsequent trigger events
  • GitHub Enterprise Server support: Automations can target GHES-hosted repos
  • Fixes: improved bulk secret import with name validation, expanded keyboard shortcuts, better mobile layouts, cleaner Slack send options, more reliable MCP HTTP server tool listing

COMMUNITY

No curated reactions recorded for this event. Facts and takes are kept in separate layers — community context is added by hand, never blended into the record above.