October 7, 2026

What changed for engineering teams this week (7 October 2026)

Nine changes from 1 to 7 October 2026 that engineering leaders may need to act on: a DNS root key rollover, npm publishing expiry, Apple signing and more.

News

Tech

Two deadlines bite first. The DNS root key changes on 11 October, which matters only if you run your own validating resolvers. And npm now expires unvalidated trusted-publishing configurations after 48 hours and rejects publishing tokens from issue_comment events, so any workflow triggered by a comment needs a new trigger today.

If you report AI return on investment from GitHub Copilot usage metrics, check those numbers too. GitHub says agent activity was undercounted and it can't backfill the gap.

The DNS root key changes on 11 October

Cloudflare's rollover post says the DNS root is scheduled to change its key-signing key on 11 October 2026, only the second time that has ever happened. The new key is KSK-2024, key tag 38696.

Who has to do anything? Operators of DNSSEC-validating resolvers, meaning anyone who runs their own recursive DNS. If your resolver doesn't pick up the new key, validated lookups can start failing. Cloudflare says most website operators need no changes, and users of its DNS services, 1.1.1.1 included, need no action. The post links to a test site where you can check whether your resolver trusts the new key.

If you run validating resolvers, act now and check before Sunday. Otherwise ignore it.

Apple: signing certificates expire and Full Disk Access tightens

Developer ID sub-CA expires on 1 February 2027

Apple's Developer ID notice says the original Developer ID Certification Authority (Sub-CA) expires on 1 February 2027, and certificates it issued stop working that day. From then on, .pkg files signed with an affected certificate no longer install.

Software you already shipped isn't at risk. Apple says previously signed and notarized Mac software with a secure timestamp keeps working. The work is in your release pipeline: when you create a replacement certificate and are asked for a Developer ID Certificate Intermediary, pick G2 Sub-CA. Apple warns that another choice may issue a certificate that also expires in 2027.

Plan for it, and ignore it unless you ship .pkg installers.

Apple will add controls on Full Disk Access

Apple's Full Disk Access post says it will introduce additional controls so that users who want to grant an app that extraordinary level of access can do so only through very explicit action. It ties the change to AI agents, noting that as they become more capable and autonomous, the risks of this access grow substantially.

Apple gave no version, no date and no developer action. That's our reading of the gap, not Apple's: anything else we'd say about timing would be a guess.

If your macOS tool, backup agent or coding agent depends on Full Disk Access, expect a more deliberate approval flow at some point.

Plan for it, but only as far as listing which of your tools rely on it.

GitHub: npm publishing, Copilot metrics, secret scanning and stacked PRs

npm trusted publishing: unvalidated configurations expire after 48 hours

GitHub's npm changelog entry says unvalidated trusted publishing configurations now expire 48 hours after creation and can no longer authorize publishing. A configuration becomes validated, and exempt from expiry, after its first successful publish.

Two other details matter. npm now rejects publishing tokens from issue_comment events, alongside the existing pull_request_target restriction, so move those workflows to push, release or workflow_dispatch. And changing the repository or project identity starts a fresh 48-hour window.

Set up a configuration on Monday and publish on Friday, and the publish fails.

If you publish from CI, act now.

Copilot usage metrics undercounted agent activity

GitHub's Copilot metrics update explains that SDK-based sessions didn't identify their source IDE, so agent activity was undercounted. Billing isn't affected. GitHub also says it can't backfill the missing data, and that Copilot CLI metrics may be inflated because some activity from other SDK-based clients was counted as CLI activity.

Fixed IDE versions: VS Code 1.139.0 and later is available now, Visual Studio 18.12 is expected in October, JetBrains gets it in its next plugin release in late October, and Eclipse and Xcode follow in November.

Any adoption chart that starts before the fix has a hole in it. See how to measure AI coding tools ROI for what to track beyond vendor dashboards.

If you report adoption or ROI from these numbers, act now.

Secret scanning adds Lovable and Supabase detectors

GitHub's secret scanning changelog adds detectors for lovable_api_key, logfire_token, pydantic_ai_gateway_api_key, supabase_oauth_access_token and supabase_scoped_personal_access_token.

Partner secrets found in public repositories are reported to the issuer. User secrets raise alerts in public or private repositories. Check your own secret scanning settings to see which detectors are switched on for your repos.

The tokens that these detectors catch tend to live in apps assembled quickly with AI builders. If you inherit one, taking a vibe-coded app to production covers the cleanup beyond secrets. A related GitHub change: GitHub Actions run history is now deleted by retention.

Plan for it.

Stacked pull requests are generally available

GitHub's stacked PR announcement says the feature is on all github.com plans and will come to an upcoming GitHub Enterprise Server release. Approvals stay in place for unchanged code, and rebased commits stay signed.

GitHub also claims that since public preview, repositories using stacks have seen a 9% increase in merged code compared to peers. That's GitHub's own figure, not an independent result, and merged-code volume isn't a quality or ROI measure. Our judgment: treat it as a reason to trial stacks on one team, not as a benchmark.

Plan for it, and try it where reviews of large changes are slow.

Claude Code 2.1.292 fixes permission and sandbox bypasses

The Claude Code changelog lists one fix labelled Security in 2.1.292, released 6 October, plus several other permission and sandbox fixes. PreToolUse hook approvals and auto mode could bypass the permission prompt for file reads from network (UNC) paths. Sandboxed commands could read staged copies of /ultrareview uploads. A managed sandbox read-deny path that appears or re-points mid-session no longer drops project grants or ends credential injection. And a tampered on-disk cache of server-managed settings could switch off or unseat the built-in policy plugin while the settings fetch failed.

That last one is aimed squarely at managed fleets, where the policy plugin is the control. Updating managed installs is our recommendation, not the changelog's. For the admin side, see what Claude Code mods mean for admins.

On managed fleets, act now. Everywhere else, update when convenient.

OpenAI API usage tiers drop from five to three

OpenAI's API changelog says it simplified usage tiers from five to three on 6 October: Build, Launch and Grow. OpenAI's rate limits guide puts Build at $5 in credit purchases with a $500 monthly cap, Launch at $100 with $5,000, and Grow at $500 with $200,000. It also lists a Free tier with a $100 monthly limit for organizations in allowed geographies.

Neither page sets the old limits beside the new ones, so we're not saying any limit went up or down. What you can do is look up which tier your organization sits in now and read off its monthly cap. If you run a production workload that gets close to $500 or $5,000 a month, that cap is the number to know before a traffic spike finds it for you.

Plan for it, starting with a check of your org's tier and monthly cap.

What this means for this sprint versus next quarter

The call is which of these nine goes into this sprint and which can wait. Our judgment, not a vendor's ranking:

This sprint: the npm workflow changes, the Claude Code update on managed machines, and a caveat on any Copilot numbers you present. Add the DNS resolver check before Sunday if you run validating resolvers.

Next quarter: the Apple re-sign, due by 1 February 2027, secret scanning coverage, a stacked PR trial, the OpenAI tier check and a watch on Full Disk Access.

Two of these probably belong to someone else. The Apple certificate is the macOS release engineer's, and the DNS check is the network owner's. Name those people this week so the deadline doesn't sit in a ticket nobody reads. The Copilot caveat belongs to whoever builds your engineering reports.

For the running list of platform changes, read Platform and language release notes: what breaks and what to fix.

FAQ

Do we need to do anything for the DNS root key rollover?

Most website operators don't. The rollover affects people who run DNSSEC-validating resolvers, who should confirm their resolvers trust the new KSK-2024 key before 11 October. Cloudflare says users of its DNS services, including 1.1.1.1, need no action. If you only use a managed resolver, check your provider's notice.

Will our existing Mac apps stop working when Apple's Developer ID sub-CA expires?

No. Apple says previously signed and notarized Mac software with a secure timestamp keeps working. What changes is .pkg installers signed with an affected certificate, which stop installing from 1 February 2027. Re-sign new installers with a certificate issued under the G2 Sub-CA.

Can we trust our Copilot agent-usage numbers from before this week's fix?

Not for agent activity from affected IDE versions. GitHub says it can't backfill the missing data, and that Copilot CLI metrics may be inflated by activity from other SDK-based clients. Update to a fixed IDE version, such as VS Code 1.139.0 or later, and treat earlier agent activity as a floor, and CLI counts as possibly high.

Share this article

Author Image

HighCircl Editorial Team

The HighCircl editorial team writes about hiring software engineers, nearshore development, and engineering team building. Our articles draw on direct experience sourcing and placing senior developers across Poland, Hungary, Slovakia, Serbia, Slovenia, Romania, and Spain — and on candid conversations with the CTOs and engineering leads who hire them.

HighCircl is a nearshore engineering network that delivers matched candidate shortlists in 72 hours. Every piece of content we publish is informed by real engagement data: actual developer rates, real hiring timelines, and what separates engineering teams that scale cleanly from those that stall.

Take Me to the Experts

Access our network of industry-leading software engineers.

Start Now