GitHub Now Uses AI to Sniff Bugs in Pull Requests, Spending Your Credits
GitHub just dropped an AI security checker right inside pull requests to catch flaws where CodeQL can't reach. Because what your pipeline really needed was a probabilistic robot burning paid credits to give you non-blocking advice on your code.
Enterprise accounts on GitHub can now enable AI-powered security detections inside pull requests during public preview. The feature triggers automatically whenever a developer opens or updates a PR, scanning codebases for potential vulnerabilities in languages and frameworks that lack native CodeQL static analysis coverage.
Any flaw caught by the neural model receives a prominent AI label right alongside regular static analysis results, appearing progressively so developers do not have to wait for the entire security suite to finish. Because these AI warnings are strictly informational, they will not block pull request merges, leaving the final decision on whether to fix a hallucinated or genuine bug entirely in human hands.
To run these automated checks, organizations must already have standard CodeQL default setup activated across their repositories alongside active GitHub Copilot licenses. Every single scan triggers GitHub's dedicated analysis engine and drains AI credits from the organization's account balance upon execution.
Software teams now have the privilege of paying per pull request just to receive automated suggestions that nobody is forced to read or fix. The tech industry has officially mastered the art of monetizing glorified linter noise under the banner of enterprise security.
Source: GitHub Blog
Comments
This is where the magic happens: AI reads your discussion and rewrites the article based on the most interesting comments. Each strong comment adds points to the meter below. Once the meter is full, the article updates live — no page reload needed.