Skip to content
context Security

GitHub expands AI Scan for pull requests to repositories without CodeQL default setup

clearly official source

GitHub has enabled AI Scan to find security issues in pull requests even without CodeQL default setup configured. The feature is in public preview for GitHub Advanced Security customers on github.com; GitHub Enterprise Server is not yet supported.

GitHub has expanded the availability of AI Scan for pull requests so that it now also works in repositories where CodeQL default setup is not configured. Previously, AI Scan for pull requests ran only in repositories with CodeQL default setup enabled. According to GitHub, code scanning and AI Scan for pull requests must still be enabled at the repository, organization or enterprise level (if the organization belongs to an enterprise) – the same permissions hierarchy continues to apply. According to GitHub, organizations that already have AI Scan enabled do not need to take any additional steps – the tool will automatically extend to all eligible repositories regardless of whether they have CodeQL default setup.

The feature is now in public preview for both organization-owned repositories and personal repositories on github.com, exclusively for GitHub Advanced Security customers. GitHub Enterprise Server does not yet support this new feature.

What changed

Why it matters

Until now, AI checks for security issues in pull requests worked only where CodeQL default setup was configured – leaving many repositories without this coverage. The expansion means that organizations with a GitHub Advanced Security license can get broader automatic detection of vulnerabilities in code before a pull request is merged, without having to configure anything else, provided they already have AI Scan enabled.

Two audiences, two different impacts

What this means

01

For individuals

Developers and pull request reviewers may now see findings from AI Scan even in repositories where this check previously did not run because CodeQL default setup was missing.

What to do Check whether code scanning and AI Scan for pull requests are enabled for the organization for the repositories I work with.
More practical updates →
02

For a business

Companies with a GitHub Advanced Security license can now get automatic AI checks for security issues in pull requests even in repositories where CodeQL default setup has not yet been configured, without any additional setup.

Risks and compliance
What to decide Verify whether the company holds a GitHub Advanced Security license and consider enabling AI Scan at the organization level, including for repositories without CodeQL default setup configured.
More business impacts →
AI Scan bezpečnost kódu code scanning GitHub GitHub Advanced Security pull requesty

Check the original

Event sources

clearly official source · 1 publisher, 0 independent. We count feeds from the same owner only once.

1
GitHub Changelog (Copilot and AI features) primary source · first detected Code scanning AI Scan no longer requires CodeQL default setup