Theregister Microsoft Reverses VS Code AI Attribution After Developer Backlash
Article Content
- •Microsoft reverted a change that added AI attribution to commits by default in VS Code.
- •Developers reported that the attribution was added even when Copilot was not used.
- •The fix will be included in the upcoming VS Code 1.119 release, changing the setting to opt-in.
Microsoft has rolled back a controversial change in VS Code that automatically added a 'Co-authored-by: Copilot' line to commits, which was intended to credit AI assistance. This change, introduced in March 2026, faced significant backlash from developers who reported that the attribution was added even when Copilot was not used. Many users expressed frustration that their manual commit messages were altered without their consent, leading to concerns about professional workflow integrity. Dmitriy Vasyura, the reviewer who approved the change, acknowledged the oversight and stated the fix would revert the setting to opt-in for AI attribution. The upcoming VS Code 1.119 release will implement this fix. Similar issues have been reported with other AI tools, highlighting a broader concern about AI attribution practices in software development. The incident reflects ongoing debates about AI's role in coding and the importance of accurate authorship representation.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track Anthropic in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…