Code scanning AI Scan no longer requires CodeQL default setup
PreviewVerifiedAdded Sep 22, 2026
You can now use AI Scan for pull requests to find security vulnerabilities, even when CodeQL default setup isn’t enabled on a repository. Previously, AI Scan for pull requests only ran on repositories where CodeQL default setup was configured.
Topics: Security, Observability
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Every GitHub Advanced Security release| Date | Release | Type |
|---|---|---|
| Sep 15 | Enforce GitHub Advanced Security configurations Update | Update |
| Sep 18 | Manage the code coverage ruleset condition with the REST API GA | GA |
| Sep 18 | Stage-only npm tokens for safer automation Update | Update |
| Sep 21 | GitHub Enterprise adds credential inventory exports Update | Update |
| Sep 22 | Security improvements for SSH Update | Update |
| Sep 22 | Deprecation notice: All-platform CodeQL bundle Deprecation | Deprecation |
| Sep 10 | AI Scan for pull request APIs in public preview Preview | Preview |
| Sep 9 | npm extends recovery-code security holds to all accounts Update | Update |