Home Blog

GitHub launches MCP Registry to supply central location for trusted servers


GitHub has launched an MCP Registry to supply builders with a curated listing of MCP servers.

“Should you’ve tried connecting AI brokers to your growth instruments, the ache: MCP servers scattered throughout quite a few registries, random repos, buried in neighborhood threads — making discovery sluggish and stuffed with friction with out a central place to go. In the meantime, MCP server creators are worn out from publishing to a number of locations and answering the identical setup questions repeatedly,” GitHub wrote in a weblog submit.

Every server within the Registry is related to its personal GitHub repository, and they are often sorted by GitHub stars and neighborhood exercise.

In response to GitHub, this backing builds belief in particular MCP servers, resulting in a more healthy general AI ecosystem.

GitHub’s personal just lately launched MCP server is included within the repository. It permits brokers to attach with content material in GitHub repositories, points, and pull requests.

The corporate additionally mentioned that it has been working with Anthropic—creator of MCP—to create an open supply registry that integrates with this one introduced at the moment. That mission is the OSS MCP Group Registry, and any server revealed there’ll mechanically present up in GitHub’s MCP Registry. In response to the corporate, this collaboration will scale back duplication throughout registries, floor clear metadata, and allow contribution at scale.

“Along with the open supply neighborhood, Anthropic, and the MCP Steering Committee, we’re constructing an open ecosystem the place discovering the correct AI functionality is so simple as looking GitHub. The GitHub MCP Registry is your quickest path from concept to integration, and the muse for a more healthy, extra interoperable AI toolchain,” Anthropic wrote.

“Whether or not you’re constructing with GitHub Copilot, brokers, or any AI instrument that speaks MCP, that is the place to seek out what you want. With GitHub already dwelling to most MCP servers, the MCP Registry makes them dramatically simpler to find, discover, and use — serving to builders discover the correct instruments quicker and contribute to a extra open, interoperable ecosystem,” GitHub wrote.

Amplifying AI Readiness within the DoD Workforce


AI readiness is a longtime precedence for the Division of Protection workforce, together with preparation of the workforce to make use of and combine information applied sciences and synthetic intelligence capabilities into skilled and warfighting practices. One problem with figuring out staff educated in information/AI areas is the dearth of formal certifications held by staff. Employees can develop related data and abilities utilizing non-traditional studying paths, and in consequence civilian and federal organizations can overlook certified candidates. Employees could select to domesticate experience on their very own time with on-line assets, private tasks, books, and so forth., in order that they’re ready for open positions even after they lack a level or different conventional certification.

The SEI’s Synthetic Intelligence Division is working to handle this problem. We just lately partnered with the Division of the Air Power Chief Information and AI Workplace (DAF CDAO) to develop a method to establish and assess hidden workforce expertise for information and AI work roles. The collaboration has had some vital outcomes, together with (1) a Information/AI Cyber Workforce Rubric (DACWR) for evaluation of abilities recognized inside the DoD Cyberworkforce Framework, (2) prototype assessments that seize an information science pipeline (information processing, mannequin creation, and reporting), and (3) a proof-of-concept platform, SkillsGrowth, for staff to construct profiles of their experience and evaluation efficiency and for managers to establish the info/AI expertise they want. We element beneath the advantages of those outcomes.

A Information/AI Cyber Workforce Rubric to Improve Usability of the DoD Cyber Workforce Growth Framework

The DoD Cyber Workforce Framework (DCWF) defines information and AI work roles and “establishes the DoD’s authoritative lexicon based mostly on the work a person is performing, not their place titles, occupational collection, or designator.” The DCWF supplies consistency when defining job positions since completely different language could also be used for a similar information and AI educational and trade practices. There are 11 information/AI work roles, and the DCWF covers a variety of AI disciplines (AI adoption, information analytics, information science, analysis, ethics, and so forth.), together with the data, abilities, talents, and duties (KSATs) for every work position. There are 296 distinctive KSATs throughout information and AI work roles, and the variety of KSATs per work position varies from 40 (information analyst) to 75 (AI check & analysis specialist), the place most KSATs (about 62 p.c) seem in a single work position. The KSAT descriptions, nonetheless, don’t distinguish ranges of efficiency or proficiency.

The info/AI cyber workforce rubric that we created builds on the DCWF, including ranges of proficiency, defining primary, intermediate, superior, and professional proficiency ranges for every KSAT.

figure1_06242025

Determine 1: An Excerpt from the Rubric

Determine 1 illustrates how the rubric defines acceptable efficiency ranges in assessments for one of many KSATs. These proficiency-level definitions assist the creation of knowledge/AI work role-related assessments starting from conventional paper-and-pencil exams to multimodal, simulation-based assessments. The rubric helps the DCWF to offer measurement choices {of professional} apply in these work roles whereas offering flexibility for future adjustments in applied sciences, disciplines, and so forth. Measurement towards the proficiency ranges can provide staff perception into what they will do to enhance their preparation for present and future jobs aligned with particular work roles. The proficiency-level definitions can even assist managers consider job seekers extra constantly. To establish hidden expertise, you will need to characterize the state of proficiency of candidates with some cheap precision.

Addressing Challenges: Confirming What AI Employees Know

Potential challenges emerged because the rubric was developed. Employees want a method to display the power to use their data, no matter the way it was acquired, together with by means of non-traditional studying paths similar to on-line programs and on-the-job ability growth. The evaluation course of and information assortment platform that helps the evaluation should respect privateness and, certainly, anonymity of candidates – till they’re able to share info relating to their assessed proficiency. The platform ought to, nonetheless, additionally give managers the power to find wanted expertise based mostly on demonstrated experience and profession pursuits.

This led to the creation of prototype assessments, utilizing the rubric as their basis, and a proof-of-concept platform, SkillsGrowth, to offer a imaginative and prescient for future information/AI expertise discovery. Every evaluation is given on-line in a studying administration system (LMS), and every evaluation teams units of KSATs into at the very least one competency that displays each day skilled apply. The aim of the competency groupings is pragmatic, enabling built-in testing of a associated assortment of KSATs somewhat than fragmenting the method into particular person KSAT testing, which may very well be much less environment friendly and require extra assets. Assessments are supposed for basic-to-intermediate degree proficiency.

4 Assessments for Information/AI Job Expertise Identification

The assessments observe a primary information science pipeline seen in information/AI job positions: information processing, machine studying (ML) modeling and analysis, and outcomes reporting. These assessments are related for job positions aligned with the info analyst, information scientist, or AI/ML specialist work roles. The assessments additionally present the vary of evaluation approaches that the DACWR can assist. They embrace the equal of a paper-and-pencil check, two work pattern exams, and a multimodal, simulation expertise for staff who might not be snug with conventional testing strategies.

On this subsequent part, we define a number of of the assessments for information/AI job expertise identification:

  • The Technical Abilities Evaluation assesses Python scripting, querying, and information ingestion. It accomplishes this utilizing a piece pattern check in a digital sandbox. The check taker should examine and edit simulated personnel and gear information, create a database, and ingest the info into tables with particular necessities. As soon as the info is ingested, the check taker should validate the database. An automatic grader supplies suggestions (e.g., if a desk identify is wrong, if information shouldn’t be correctly formatted for a given column, and so forth.). As proven in Determine 2 beneath, the evaluation content material mirrors real-world duties which can be related to the first work duties of a DAF information analyst or AI specialist.

figure2_06242025

Determine 2: Making a Database within the Technical Abilities Evaluation

  • The Modeling and Simulation Evaluation assesses KSATs associated to information evaluation, machine studying, and AI implementation. Just like the Technical Abilities Evaluation, it makes use of a digital sandbox setting (Determine 3). The principle job within the Modeling and Simulation Evaluation is to create a predictive upkeep mannequin utilizing simulated upkeep information. Take a look at takers use Python to construct and consider machine studying fashions utilizing the scikit-learn library. Take a look at takers could use no matter fashions they need, however they have to obtain particular efficiency thresholds to obtain the best rating. Computerized grading supplies suggestions upon resolution submission. This evaluation displays primary modeling and analysis that might be carried out by staff in information science, AI/ML specialist, and presumably information analyst-aligned job positions.

figure3_06242025

Determine 3: Making ready Mannequin Creation within the Modeling and Simulation Evaluation

  • The Technical Communication Evaluation focuses on reporting outcomes and visualizing information, focusing on each technical and non-technical audiences. Additionally it is aligned with information analyst, information scientist, and different associated work roles and job positions (Determine 4). There are 25 questions, and these are framed utilizing three query sorts – a number of alternative, assertion choice to create a paragraph report, and matching. The query content material displays widespread information analytic and information science practices like explaining a time period or end in a non-technical approach, choosing an applicable solution to visualize information, and making a small story from information and outcomes.

figure4_06242025

Determine 4: Making a Paragraph Report within the Technical Communications Evaluation

  • EnGauge, a multimodal expertise, is another strategy to the Technical Abilities and Technical Communication assessments that gives analysis in an immersive setting. Take a look at takers are evaluated utilizing lifelike duties in contexts the place staff should make choices about each the technical and interpersonal necessities of the office. Employees work together with simulated coworkers in an workplace setting the place they interpret and current information, consider outcomes, and current info to coworkers with completely different experience (Determine 5). The check taker should assist the simulated coworkers with their analytics wants. This evaluation strategy permits staff to point out their experience in a piece context.

figure5_06232025

Determine 5: Working with a Simulated Coworker within the EnGauge Multimodal Evaluation

A Platform for Showcasing and Figuring out Information/AI Job Expertise

We developed the SkillsGrowth platform to additional help each staff in showcasing their expertise and managers in figuring out staff who’ve obligatory abilities. SkillsGrowth is a proof-of-concept system, constructing on open-source software program, that gives a imaginative and prescient for the way these wants will be met. Employees can construct a resume, take assessments to doc their proficiencies, and fee their diploma of curiosity in particular abilities, competencies, and KSATs. They will seek for roles on websites like USAJOBS.

SkillsGrowth is designed to display instruments for monitoring the KSAT proficiency ranges of staff in real-time and for evaluating these KSAT proficiency ranges towards the KSAT proficiencies required for jobs of curiosity. SkillsGrowth can be designed to assist use circumstances similar to managers looking resumes for particular abilities and KSAT proficiencies. Managers can even assess their groups’ information/AI readiness by viewing present KSAT proficiency ranges. Employees can even entry assessments, which might then be reported on a resume.

In brief, we suggest to assist the DCWF by means of the Information/AI Cyber Workforce Rubric and its operationalization by means of the SkillsGrowth platform. Employees can present what they know and ensure what they know by means of assessments, with the info managed in a approach that respects privateness issues. Managers can discover the hidden information/AI expertise they want, gauge the info/AI ability degree of their groups and extra broadly throughout DoD.

SkillsGrowth thus demonstrates how a sensible profiling and evaluative system will be created utilizing the DCWF as a basis and the CWR as an operationalization technique. Assessments inside the DACWR are based mostly on present skilled practices, and operationalized by means of SkillsGrowth, which is designed to be an accessible, easy-to-use system.

figure6_06242025

Determine 6: Checking Private and Job KSAT Proficiency Alignment in SkillsGrowth

In search of Mission Companions for Information/AI Job Expertise Identification

We are actually at a stage of readiness the place we’re in search of mission companions to iterate, validate, and broaden this effort. We wish to work with staff and managers to enhance the rubric, evaluation prototypes, and the SkillsGrowth platform. There’s additionally alternative to construct out the set of assessments throughout the info/AI roles in addition to to create superior variations of the present evaluation prototypes.

There’s a lot potential to make figuring out and creating job candidates more practical and environment friendly to assist AI and mission readiness. If you’re enthusiastic about our work or partnering with us, please ship an e mail to data@sei.cmu.edu.

Measuring data, abilities, potential, and job success for information/AI work roles is difficult. You will need to take away boundaries in order that the DoD can discover the info/AI expertise it wants for its AI readiness targets. This work creates alternatives for evaluating and supporting AI workforce readiness to attain these targets.

MongoDB brings Search and Vector Search to self-managed variations of database


At the moment at its person convention MongoDB.native NYC, the favored database firm introduced that the Search and Vector Search capabilities which have been obtainable within the Atlas cloud platform are actually obtainable in preview within the Group Version and Enterprise Server.

Beforehand, clients utilizing self-managed variations of MongoDB would have wanted to make use of a third-party service for vector databases, resulting in a fragmented search stack that provides pointless complexity and danger, based on MongoDB.

Ben Flast, director of product administration at MongoDB, defined that the workforce had been engaged on bringing this to the Group Version and Enterprise Server for some time, and have lastly gotten to some extent the place it’s able to be added.

“We introduced Search and Vector Search to market in Atlas solely six or seven years in the past, and the intention there was actually like the place did we expect we might construct a brand new service and evolve it in a short time, and we felt like a managed software program could be a better place to get that product began and get it to a extra mature place. And now that we’re there, we’re actually excited to convey it to the group as a result of a lot of the way in which MongoDB is used is within the Group Version,” he stated.

In line with Flast, one of many greatest issues was ensuring that Search and Vector Search might be as scalable and performant in self-managed variations as it’s in Atlas.

“What we launched immediately is the binary that sits beneath the search functionality. By having it as a standalone binary, you may put it on separate {hardware}, you may scale it up independently or run it regionally and have a single occasion,” he stated.

Vector search unlocks capabilities like autocomplete and fuzzy search, search faceting, inside search instruments, AI-powered semantic search, RAG, brokers, hybrid search, and textual content evaluation.

In line with MongoDB, a number of of its companions helped to check and validate these search capabilities within the Group Version, together with Volcano Engine Cloud, LangChain, and LlamaIndex.

Updates to Queryable Encryption

MongoDB additionally introduced the most recent launch of its platform, 8.2. In comparison with MongoDB 8.0, the most recent model offers 49% sooner efficiency for unindexed queries, 10% sooner in-memory reads, 20% sooner array traversal, and virtually triple the throughput for time-series bulk insertions, based on the corporate.

MongoDB 8.2 additionally provides partial match help to Queryable Encryption expertise. MongoDB defined that this permits textual content searches to be finished on encrypted knowledge with out revealing the underlying info.

Queryable Encryption permits knowledge to be protected at relaxation, in transit, and in use. In line with the corporate, encryption at relaxation and in transit is commonplace, however encrypting knowledge that’s in use has been tougher to attain. It is because encryption makes knowledge unreadable, and queries can’t be carried out on this state.

“As an illustration, a healthcare supplier may have to seek out  all sufferers with diagnoses that embrace the phrase ‘diabetes.’ Nonetheless, with out decrypting the medical data, the database can’t seek for that time period,” the corporate wrote in a weblog publish. To work round this, organizations usually go away delicate fields unencrypted or construct separate search indexes.

With Queryable Encryption, queries may be finished on the encrypted delicate knowledge with out that knowledge ever being uncovered to the database server.

MongoDB MCP Server

After a profitable public preview, MongoDB introduced that its MCP Server is now typically obtainable.

As a part of immediately’s launch, enterprise-grade authentication with OIDC, LDAP, and Kerberos has been added, together with proxy connectivity. There’s additionally now self-hosted distant deployment help in order that groups can share deployments and have a centralized configuration.

The MongoDB Server may be obtained in a bundle with MongoDB for VS Code extension.

MongoDB AMP

Moreover, yesterday, the corporate introduced MongoDB AMP, a platform that applies AI to the appliance modernization course of. MongoDB AMP consists of an AI-powered software program platform, supply framework, and skilled engineers to information the technical implementation course of.

Shilpa Kolhar, SVP of product and engineering at MongoDB, defined that the AI brokers will deal with duties like including documentation that was lacking or including purposeful checks, after which specialists can take over when conditions come up that the tooling can’t deal with by itself.

“If you find yourself changing out of your legacy Java stack to Java Spring Boot, it’s an ordinary framework. The instruments deal with most of it and the shoppers see an enormous discount in time for code transformation. But it surely’s not nearly code transformation, proper? We need to have the code transformation in place and comply with all the very best practices which are wanted in software improvement. And corporations might need particular wants for his or her safety and compliance, and so forth, and that’s the place our specialists are available,” she stated.

She defined that many occasions, clients will are available and say they’ve one database, however then the transformation begins and so they uncover they’ve many various ones. “That’s the place we have to convey a number of instruments collectively, and that’s one other space the place our specialists are available and tie varied issues collectively,” she stated.

In line with Kolhar, this chance for such diversified infrastructure is without doubt one of the issues that makes legacy methods such an issue. As soon as an organizations goes via the modernization course of, nevertheless, their infrastructure will hopefully be standardized in such a manner that future modifications develop into a lot easier.

She additionally defined that for some time, there’s been a forwards and backwards of corporations pushing aside modernization as a result of they will’t assure the return on funding, however we’ve reached a cut-off date now the place legacy databases and software platforms can’t sustain with the tempo AI is altering issues.

She additionally stated that due to automation, modernization can occur a lot sooner, and never as many individuals must be devoted to the method.

“We’re prepared that will help you with the tooling we have now constructed over the previous few years and the expertise of the final 15 years,” she stated.

Cisco strengthens built-in IT/OT community and safety controls



One other vital transfer that can assist IT/OT integration is the deliberate integration of the administration console for Cisco’s Catalyst and Meraki networks. That mixture will enable IT and OT groups to see the identical dashboard for industrial OT and IT enterprise/campus networks. Cyber Imaginative and prescient will feeds into the dashboard together with different Cisco administration choices reminiscent of ThousandEyes, which supplies prospects a shared stock of belongings, visitors flows and safety.

“What we’re specializing in helps our prospects have the safe networking basis and structure that lets IT groups and operational groups form of have one material, one structure, that goes from the carpeted areas all the best way to the far reaches of their OT community,” Butaney stated. 

For too lengthy, OT safety has been regarded as a selected cybersecurity apply to be managed with level merchandise, Butaney wrote in a weblog put up earlier this 12 months: “As industrial organizations begin deploying these, they understand that they want most of their IT cybersecurity instruments to correctly defend the OT atmosphere, and that in addition they must detect and remediate threats throughout domains.”

“Defending industrial operations means profiling and monitoring tens of hundreds of commercial belongings, usually put in in hard-to-reach places. The standard method consisting of deploying devoted home equipment for OT visibility, risk detection, community segmentation, and safe distant entry is proving too advanced to deploy, too pricey to scale, and in some circumstances simply impractical,” Butaney wrote.

A current report from IDC went even additional, stating that fifty% of OT belongings are greater than 10 years outdated, and their safety posture must be assessed.

“Most OT networks stay unsegmented, leaving crucial belongings uncovered and growing the probability of lateral motion throughout assaults. Adaptive safety insurance policies and real-time segmentation are frequent in IT. These options might help reduce dangers in OT with out disrupting operations if they’re built-in with OT visibility merchandise,” wrote IDC’s Romain Fouchereau, senior analysis supervisor, European safety.

Android 16 QPR2 Beta 2 is Right here



Android 16 QPR2 has launched Platform Stability right this moment with Beta 2! That signifies that the API floor is locked, and the app-facing behaviors are remaining, so you may incorporate them into your apps and make the most of our newest platform improvements.

New within the QPR2 Beta

At this later stage within the improvement cycle, we’re targeted on the important work of readying the platform for launch. Listed here are the few impactful modifications we wish to spotlight:

Testing developer verification

To higher shield Android customers from repeat offenders, Android is introducing developer verification, a brand new requirement to make app set up safer by stopping the unfold of malware and scams. Beginning in September 2026 and in particular areas, Android would require apps to be registered by verified builders to be put in on licensed Android units, with an exception made for installs made by means of the Android Debug Bridge (ADB).

As a developer, you’re free to put in apps with out verification by utilizing ADB, so you may proceed to check apps that aren’t meant or not but able to distribute to the broader client inhabitants.

For apps that allow user-initiated set up of app packages, Android 16 QPR2 Beta 2 incorporates new APIs that help developer verification throughout set up, together with a brand new adb command to allow you to pressure a verification end result for testing functions.

adb shell pm set-developer-verification-result

By utilizing this command, (see adb shell pm assist for full particulars)  now you can simulate verification failures. This lets you perceive the end-to-end person expertise for each profitable and unsuccessful verification, so you may put together accordingly earlier than enforcement begins.

We encourage all builders who distribute apps on licensed Android units to join early entry to prepare and keep up to date.

SMS OTP Safety

The supply of messages containing an SMS retriever hash will likely be delayed for many apps for 3 hours to assist stop OTP hijacking. The RECEIVE_SMS broadcast will likely be withheld and sms supplier database queries will likely be filtered. The SMS will likely be accessible to those apps after the three hour delay.

Sure apps such because the default SMS, assistant, and dialer apps, together with linked gadget companion, system apps, and many others will likely be exempt from this delay, and apps can proceed to make use of the SMS retriever API to entry messages meant for them in a well timed method.

Customized app icon shapes


Android 16 QPR2 permits customers to pick out from an inventory of icon shapes that apply to all app icons and folder previews. Examine to make it possible for your adaptive icon works properly with any form the person selects.

Extra environment friendly rubbish assortment

The Android Runtime (ART) now features a Generational Concurrent Mark-Compact (CMC) Rubbish Collector in Android 16 QPR2 that focuses assortment efforts on newly allotted objects, which usually tend to be rubbish. You possibly can count on lowered CPU utilization from rubbish assortment, a smoother person expertise with much less jank, and improved battery effectivity.

Native step monitoring and expanded train information in Well being Join

Well being Join now routinely tracks steps utilizing the gadget’s sensors. In case your app has the READ_STEPS permission, this information will likely be accessible from the “android” package deal. Not solely does this simplify the code wanted to do step monitoring, it is extra energy environment friendly as properly.

Additionally, the ExerciseSegment and ExerciseSession information varieties have been up to date. Now you can document and browse weight, set index, and Price of Perceived Exertion (RPE) for train segments. Since Well being Join is up to date independently of the platform, checking for function availability earlier than writing the info will guarantee compatibility with the present native model of Well being Join.

// Examine if the expanded train options can be found
val newFieldsAvailable = healthConnectClient.options.getFeatureStatus(
    HealthConnectFeatures.FEATURE_EXPANDED_EXERCISE_RECORD
) == HealthConnectFeatures.FEATURE_STATUS_AVAILABLE

val section = ExerciseSegment(
    //...
    // Conditionally add the brand new information fields
    weight = if (newFieldsAvailable) Mass.fromKilograms(50.0) else null,
    setIndex = if (newFieldsAvailable) 1 else null,
    rateOfPerceivedExertion = if (newFieldsAvailable) 7.0f else null
)

A minor SDK model

QPR2 marks the primary Android launch with a minor SDK model permitting us to extra quickly innovate with new platform APIs offered exterior of our traditional once-yearly timeline. Not like the foremost platform launch (Android 16) in 2025-Q2 that included conduct modifications that impression app compatibility, the modifications on this launch are largely additive and designed to reduce the necessity for added app testing.

Android 16 SDK release cadence

Your app can safely name the brand new APIs on units the place they’re accessible by utilizing SDK_INT_FULL and the respective worth from the VERSION_CODES_FULL enumeration.

if (Construct.VERSION.SDK_INT_FULL >= Construct.VERSION_CODES_FULL.BAKLAVA_1) {
    // Name new APIs from the Android 16 QPR2 launch
}

It’s also possible to use the Construct.getMinorSdkVersion() technique to get simply the minor SDK model quantity.

val minorSdkVersion = Construct.getMinorSdkVersion(VERSION_CODES_FULL.BAKLAVA)

The unique VERSION_CODES enumeration can nonetheless be used to match towards the SDK_INT enumeration for APIs declared in non minor releases.

if (Construct.VERSION.SDK_INT >= Construct.VERSION_CODES.BAKLAVA) {
    // Name new APIs from the Android 16 launch
}

Since minor releases aren’t meant to have breaking conduct modifications, they can’t be used within the uses-sdk manifest attributes.

Get began with the Android 16 QPR2 beta

You possibly can enroll any supported Pixel gadget to get this and future Android Beta updates over-the-air. In the event you don’t have a Pixel gadget, you may use the 64-bit system pictures with the Android Emulator in Android Studio.  If you’re already within the Android Beta program, you can be provided an over-the-air replace to Beta 2. We’ll replace the system pictures and SDK often all through the Android 16 QPR2 launch cycle.

If you’re within the Canary program and want to enter the Beta program, you have to to wipe your gadget and manually flash it to the beta launch.

For the very best improvement expertise with Android 16 QPR2, we suggest that you simply use the most recent Canary model of Android Studio Narwhal Characteristic Drop.

We’re searching for your suggestions so please report points and submit function requests on the suggestions web page. The sooner we get your suggestions, the extra we will embrace in our work on the ultimate launch. Thanks for serving to to form the way forward for the Android platform.