Boosting Code Quality: AI Security Detections Enhance Software Project KPIs

In the fast-paced world of software development, catching security vulnerabilities early is paramount. GitHub is stepping up its game with a significant new feature: AI-powered security detections directly within pull requests (PRs). This innovation, currently in public preview, promises to transform how teams identify and address potential security issues, ultimately contributing positively to critical software project KPIs related to code quality and security posture.

Developer reviewing AI-powered security alerts in code.
Developer reviewing AI-powered security alerts in code.

Revolutionizing Code Security with AI

Traditionally, code scanning tools like CodeQL have been indispensable. However, GitHub's new AI-powered engine expands this capability significantly. The core idea is to provide broader, more intelligent coverage, ensuring fewer blind spots in your codebase.

Key Innovations: What's New?

  • Expanded Language and Framework Coverage: Beyond CodeQL's native analysis, AI detections cast a wider net, identifying potential issues in code that might otherwise be overlooked. This means more comprehensive security checks across your diverse tech stack.
  • Seamless PR Integration: Security alerts now appear natively within pull requests. Developers can review and address these potential issues as part of their standard workflow, before code is merged. AI-generated alerts are clearly labeled as AI, distinguishing them from traditional CodeQL findings. This integration streamlines the feedback loop, enhancing developer productivity.
  • Simple Activation: Once an enterprise owner allows it, enabling AI security detections is straightforward for organizations and repositories utilizing GitHub Code Security and CodeQL default setup.
AI security detections integrated into a pull request workflow.
AI security detections integrated into a pull request workflow.

How AI Security Detections Work

The system is designed for efficiency and minimal disruption. Powered by GitHub’s AI detection engine, scans run automatically whenever a pull request is opened or updated. Results are streamed in as they become available, meaning you don't have to wait for all analysis sources to complete before seeing findings.

It's important to note that these initial AI findings are informational and currently do not block pull request merges. This approach allows teams to integrate the new insights without immediately disrupting existing CI/CD pipelines, providing a grace period to understand and adapt to the new detection capabilities.

Requirements for Implementation

To leverage this powerful new feature, a few prerequisites must be met:

  1. An enterprise owner must explicitly allow AI security detections within the enterprise policy settings.
  2. The feature needs to be enabled at the organization level.
  3. The specific repository must have CodeQL default setup enabled. While CodeQL doesn't perform the AI analysis itself, the AI detection engine relies on this setup for its operation.

Availability and Billing During Public Preview

AI security detections in PRs are currently in public preview on GitHub.com. They are available to customers with GitHub Code Security (GitHub Advanced Security). Eligible organizations and repositories can enable the feature after enterprise-level allowlisting.

During this public preview phase, there are specific billing considerations:

  • A GitHub Copilot license is required.
  • Detections consume your organization’s AI Credits.
  • AI Credits are only drawn down when detections actually run.

This new capability offers a significant leap forward in proactive security, providing valuable data points that can be integrated into your performance dashboard software to track improvements in code quality and security health, ultimately boosting overall software development KPI dashboard metrics.

For more detailed information, refer to GitHub's official code scanning documentation. We encourage you to join the discussion and share your feedback on this exciting new feature!

|

Dashboards, alerts, and review-ready summaries built on your GitHub activity.

 Install GitHub App to Start
Dashboard with engineering activity trends