GitHub expands AI Scan for pull requests to repositories without CodeQL default setup
GitHub has enabled AI Scan to find security issues in pull requests even without CodeQL default setup configured. The feature is in public preview for GitHub Advanced Security customers on github.com; GitHub Enterprise Server is not yet supported.
GitHub has expanded the availability of AI Scan for pull requests so that it now also works in repositories where CodeQL default setup is not configured. Previously, AI Scan for pull requests ran only in repositories with CodeQL default setup enabled. According to GitHub, code scanning and AI Scan for pull requests must still be enabled at the repository, organization or enterprise level (if the organization belongs to an enterprise) – the same permissions hierarchy continues to apply. According to GitHub, organizations that already have AI Scan enabled do not need to take any additional steps – the tool will automatically extend to all eligible repositories regardless of whether they have CodeQL default setup.
The feature is now in public preview for both organization-owned repositories and personal repositories on github.com, exclusively for GitHub Advanced Security customers. GitHub Enterprise Server does not yet support this new feature.
Why it matters
Until now, AI checks for security issues in pull requests worked only where CodeQL default setup was configured – leaving many repositories without this coverage. The expansion means that organizations with a GitHub Advanced Security license can get broader automatic detection of vulnerabilities in code before a pull request is merged, without having to configure anything else, provided they already have AI Scan enabled.
Two audiences, two different impacts
What this means
For individuals
Developers and pull request reviewers may now see findings from AI Scan even in repositories where this check previously did not run because CodeQL default setup was missing.
For a business
Companies with a GitHub Advanced Security license can now get automatic AI checks for security issues in pull requests even in repositories where CodeQL default setup has not yet been configured, without any additional setup.
Risks and complianceCheck the original
Event sources
clearly official source · 1 publisher, 0 independent. We count feeds from the same owner only once.