Maya: Hey builders! Here's what's on the radar today on Pivot Build. Copilot drops four models, a Python tutorial builds an agent harness from scratch, a free GitHub harness course, the jpm package manager, and the Klarion secrets scanner. I'm Maya. James: And I'm James. Let's get into it. Maya: So GitHub deprecated four Copilot models on October second, across chat, inline edits, ask, agent modes and completions. Gemini three point five and three point six Flash, Kimi K two point seven Code, and Claude Opus four point seven are all retiring. James: Right, and GitHub names a replacement for each, Maya. Flash points to Gemini three point eight, Kimi to K three, Opus four point seven to Opus five point five. No action needed to remove them, but Enterprise admins may have to enable alternatives in model policies. Maya: Exactly right, and one subscriber still on the old PRU plan tells a different story. They say GPT five point four leaves October nineteenth, cutting their list to three models. That date and the PRU plan aren't in GitHub's changelog. James: And their complaint is economics, not features. They accept the old plan won't get new models, but they ask why GitHub won't offer Kimi K two point seven, which they say priced far cheaper than GPT five point three Codex or five point four. Maya: Onto a great teaching piece, James. A Python walkthrough builds a Claude Code-style agent harness with no framework, just six scripts and three packages, mcp, openai and pydantic, installed with the uv manager. The harness is the code around a model that runs its actions. James: And it builds up in numbered steps, Maya. Version zero is a plain chat call against a local Ollama server, no API key. Version one adds tool calling, but only one round, so a task needing a second call came back blank. Maya: Then version two is the real agent loop, a while-true that keeps running tools and feeding results back until the model answers without asking for another. Version three plugs in MCP servers for time and web pages, and version four adds a markdown memory file. James: And the speaker is honest about limits. He recommends Qwen three point five at four billion parameters, says the first local response was slower than expected, and the agent couldn't delete files because no delete tool was given to it. Maya: Staying on harnesses, there's a free GitHub course, Learn Harness Engineering from the walkinglabs organization. Fourteen lectures, eight hands-on projects, teaching the layer that runs a model, hands it tasks, loops it and tests what it produces. James: And the topics are specific, Maya. How Claude Code, Codex and DeepSeek build their harnesses, loop and graph engineering, automated agent loops, and observability, testing and verification. Charly Wargnier called it one of the best free harness courses on GitHub. Maya: One promoter makes a stronger claim, that with the same model and prompt one version failed in twenty minutes while another shipped a working game, and the harness was the difference. That's the promoter's account, not a tested result. James: Now jpm, a JavaScript package manager. JT Turner is credited as director, and the site says Claude Code, running Claude Opus five point five, wrote every line, including the TLS and cryptography code, with Turner making the calls. It's MIT-licensed. Maya: And the speed numbers are from jpm's own site, James. A cold install of nuxt's five hundred ninety-one packages took one point two two seconds on GitHub's test servers, against eighteen point five four for npm. The site calls that fifteen times faster. James: And switching is one command. Running jpm install reads an existing lockfile and writes jpm.lock with the same versions, leaving the old one untouched. Install scripts wait for jpm approve, and versions published in the last day are skipped. Maya: Those numbers are the author's, though, James, run on thirty September and first October, three to five runs per median. The site itself says the practical test is trying it in your own CI, so builders should verify before trusting the claims. James: Fair point, Maya. Last one, Klarion, a free MIT-licensed secrets scanner. Its developer says the Claude Code plugin is a hook that blocks a flagged write before the file exists, covering both file edits and Bash commands. It decides in two steps. Maya: Right, James. First a keyword check, eighty-one regex rules and a Rényi entropy score flag anything suspicious, then an AI model reads each hit with its surrounding code and judges whether it's real. It also runs in Cursor, CI and git hooks. Maya: That's your Pivot Build daily brief. Check pivotbuild.ai for the full stories. Keep building.