Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →GitHub announced on April 8, 2025, that Security Campaigns with Copilot Autofix were generally available for code-scanning alerts. The feature lets security teams group alerts across repositories, set a remediation deadline, notify developers, and track progress. GitHub later announced secret-scanning campaigns as generally available in November 2025, although its current overview still labels them as public preview.
What GitHub Security Campaigns do
A Security Campaign groups related security alerts into a coordinated remediation effort. A security team selects alerts, sets a due date, names campaign managers, and can add a description and contact link. Developers receive campaign context in GitHub, review alerts in their repository workflow, and can coordinate with the campaign managers.
For code-scanning alerts, Copilot Autofix can generate suggested fixes as capacity allows. GitHub says suggestions that can be generated are usually ready within an hour, though complex alerts or busy periods can take longer. Developers can review a suggestion and use it to create a pull request; the suggestion is not itself a guarantee that an issue has been fixed.
GitHub’s overview also describes assigning campaign alerts to Copilot cloud agent to generate pull requests where that capability is available. The April 2025 general-availability announcement specifically highlighted Copilot Autofix.
Recommended Free Tools
#1 Best Overall
Announcement timeline and alert types
| Alert type or milestone | What GitHub announced | Qualification |
|---|---|---|
| Code-scanning campaigns | Generally available on April 8, 2025, with Copilot Autofix. | The announcement presented campaigns as part of GitHub Code Security on GitHub Enterprise Cloud. |
| Secret-scanning campaigns | Public preview announced September 23, 2025; generally available announcement published November 25, 2025. | GitHub’s current “About security campaigns” overview still calls secret-scanning campaigns public preview. The dated GA announcement and current overview therefore conflict; confirm the live documentation for current status. |
Code-scanning and secret-scanning campaigns should not be treated as identical workflows. Current documentation says campaign notifications and assignment permissions differ for secret alerts. Assigning a secret alert can temporarily give an assignee permission to view and edit that alert even if they could not previously view the alert list; that additional access ends when the assignment ends. GitHub’s overview says users with write access can be assigned code-scanning or secret-scanning alerts.
What was included in the April 2025 GA release
The original general-availability announcement described more than grouping and Autofix. Security teams could prepare campaigns as drafts, optionally create a GitHub issue in each included repository, and view campaign statistics at the organization level. Repository issues can make a campaign visible in teams’ existing project workflows; their bodies can include the campaign description, contact information, and deadline, and GitHub documents updates and comments for relevant campaign changes.
The April announcement described code-scanning campaigns. The later secret-scanning rollout is a separate development, not evidence that every feature or permission behavior in the original release applies equally to secret alerts.
Eligibility and access
GitHub’s current overview says organizations on GitHub Team with GitHub Secret Protection or GitHub Code Security enabled can use Security Campaigns. The April 2025 announcement described availability for GitHub Code Security on GitHub Enterprise Cloud. These statements reflect different points in the rollout; check GitHub’s current plan documentation and organization settings to confirm entitlement for a specific account.
Rank #3
How to plan a campaign
GitHub’s current tutorial allows up to 1,000 alerts in a campaign, and its creation guide sets a limit of 10 active campaigns. These are current product limits in GitHub documentation accessed in 2026; narrow the alert selection or divide the work into multiple campaigns when necessary. Completed or paused campaigns can be closed, and closed campaigns can be reopened.
- Define the objective. Select a focused set of alerts, such as one recurring vulnerability class, when the aim is to teach a repeatable secure-coding practice.
- Prepare campaign context. Write a description, provide a contact link, and include useful educational material. GitHub’s tutorial cites OWASP resources as one possible source of supporting context.
- Set a workable deadline. Base it on alert count, developer capacity, and calendar constraints instead of choosing an arbitrary date.
- Decide whether to create repository issues. Enable them if teams need campaign visibility in their existing issue workflows; they are optional.
- Use a draft when coordination is needed. Review scope and messaging before making the campaign active and notifying developers.
Tracking campaign progress
GitHub’s campaign tracking view shows campaign status along with repository and alert details. For code campaigns, alert states include open, in progress, fixed, and dismissed. This lets campaign managers see where work is moving without treating a suggested fix or an opened pull request as a completed remediation.
Rank #4
GitHub’s November 25, 2025 announcement also described list views and REST API capabilities for secret-scanning campaigns and secret-scanning alert assignees. Teams that need automated tracking should consult the current REST API documentation and confirm which campaign and alert operations are available for their alert type.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Why GitHub introduced campaigns
Security campaigns are designed to connect security teams, which prioritize vulnerabilities, with developers who can fix them in repository workflows. GitHub Blog author James Fletcher described the purpose this way: “Security campaigns bridge this gap by bringing security experts and developers together, streamlining the vulnerability remediation process right within your workflow, and at scale.”
Quick Recap
Best Value
Sources
- GitHub Changelog: Security campaigns with Copilot Autofix are now generally available
- GitHub Docs: About security campaigns
- GitHub Docs: Creating a security campaign
- GitHub Docs: Security campaign tutorial
- GitHub Docs: Tracking the progress of a security campaign
- GitHub Changelog: Secret scanning campaigns public preview
- GitHub Changelog: Secret scanning campaigns and secret scanning alert assignees are now generally available
- GitHub Blog: Found means fixed: Reduce security debt at scale with GitHub security campaigns
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

