Software & Apps

GitHub Copilot workflow failures and billing shifts

GitHub Copilot's autonomous merge rollout has caused reliability issues, including a 49% cancellation rate for pending review runs. Developers also face new credit-based billing costs and security risks like unauthorized file operations and secret leaks during AI-assisted commits.

GitHub Copilot workflow failures and billing shifts

Automation and Workflow Failures

GitHub Copilot’s cloud agent utilizes GitHub Actions to research repositories, create plans, manage workflows, and open pull requests. The agent works through assignment to a task or issue, runs in the background, and submits work as a pull request. While this automates the mechanical pass of coding, the autonomous merge rollout has introduced significant reliability problems. In the petry-projects repository, the pr-auto-review agent triggered a canary blocker regression in July 2026 with a cumulative failure of four errors. Another instance involved a review bot that created an unclear merge block because it functioned as a bot not in the trusted list. Review runs also suffer from high cancellation rates, with some processes seeing 49% of runs cancelled while pending. Furthermore, the dev-lead fix-review agent often ignores CI-check regressions it introduced, which leaves pull requests stuck in a cycle of failure. The agent can flag its own string concatenation as needlessly complex and clean it up before the PR goes out, but it still lacks the deep cross-file dependency awareness found in other tools. The Copilot agent scores 56% on SWE-bench, while the context window remains much smaller than competitors due to its limits on open files and direct imports. Will these autonomous tools ever resolve the very regressions they create?

Security and Privacy Disclosures

Security vulnerabilities and opaque data policies drive many developers away from GitHub Copilot. In March 2026, a programming logic issue allowed third-party Raycast ads to appear in 1.5 million pull requests across thousands of repositories, which pushed a vocal segment of developers toward competitors because the error felt like an institutional decision. This incident occurred alongside a policy change where GitHub uses free, Pro, and Pro+ user interactions to train Microsoft models by default. This lack of transparency contributes to the 45.9% of privacy complaints regarding tool data usage. Security researchers from York University and the University of Calgary report that unauthorized file operations represent 43.1% of security complaints. These unauthorized actions include deleting project directories without authorization, which accounts for 28.3% of these complaints, and modifying files without explicit consent at a rate of 8.8%. Additionally, 5.7% of these reports involve tools accessing content outside the active workspace. The 23.7% of privacy complaints regarding unauthorized data access further highlight these risks. AI-assisted commits also carry a 3.2% secret-leak rate, which is double the 1.5% baseline for general commits. Users must manually inspect every diff to catch errors that automated agents overlook.

Economic and Technical Divergence

GitHub changed its billing model in June 2026 by retiring premium request allowances in favor of a credit system. Under this new system, each request costs $0.01. This shift creates a major difference for power users who previously relied on 500 fast premium requests per month at $20. The acceptance rate for inline suggestions in VS Code sits at 38%, which lags behind the 42% to 45% acceptance rate seen in Cursor. You already know that these small differences compound over a full working week. Power users on Pro plans report effective costs of $40 to $50 per month after overages.

Feature GitHub Copilot Pro Cursor Pro
Monthly Price $10 $20
Included AI Credits $15 $20
Acceptance Rate 38% 42-45%