GitHub announced AI-powered fixes for CodeQL alerts in pull requests as a public beta on March 20, 2024. The feature is no longer simply a beta announcement: GitHub now calls it Copilot Autofix, and announced general availability within GitHub Advanced Security on August 14, 2024. Current documentation covers supported CodeQL alerts in pull requests and on the default branch. It does not cover every alert, and its suggested changes still need developer review.
What the March 2024 beta offered
The original beta targeted CodeQL alerts in JavaScript, TypeScript, Java, and Python. For a supported alert, GitHub presented an explanation and a preview of a proposed code change. Developers could accept, edit, or dismiss the suggestion. A fix could touch multiple files and, when necessary, add or change dependencies.
GitHub said the feature was automatically enabled on private repositories for GitHub Advanced Security customers. Administrators could configure it at repository, organization, or enterprise level. The launch announcement described average support for 90% of alerts from the Default code scanning suite’s queries in those four languages. That was GitHub’s March 2024 launch-era statement, not a current coverage guarantee: eligibility depended on the alert’s context and location, and syntax or safety checks could prevent a suggestion from appearing. Read the March 20, 2024 beta announcement.
What Copilot Autofix does now
Current GitHub documentation describes Copilot Autofix as an LLM-powered feature that generates a potential fix and explanation for a CodeQL alert. It uses alert information, SARIF data, surrounding code snippets, and query help text. GitHub announced general availability within GitHub Advanced Security in August 2024; the announcement was updated January 21, 2025. See GitHub’s general-availability announcement.
#1 Best Overall
There are two places to use it:
- Pull requests: For supported alerts found in a pull request, review the proposed fix as part of the code review.
- Existing default-branch alerts: Generate a proposed fix from the alert page. GitHub’s July 2024 public-beta expansion said users could create a pull request from that page, and that this existing-alert workflow did not require a Copilot license. Read the July 16, 2024 announcement.
How do I get AI autofixes for CodeQL alerts in a pull request?
Use GitHub code scanning with CodeQL and open or review a pull request that contains an eligible alert. When GitHub can generate a suggestion for that alert, it appears for developer review. The current documentation says Copilot Autofix does not require a GitHub Copilot subscription; availability is tied to CodeQL analysis and the applicable GitHub security offering and configuration. The original beta’s private-repository enablement and administrative controls were described specifically for GitHub Advanced Security customers.
Coverage is limited to supported queries in subsets of the default and security-extended CodeQL suites. Current documentation lists supported coverage across C#, C/C++, Go, Java/Kotlin, Swift, JavaScript/TypeScript, Python, Ruby, and Rust; a language being listed does not mean every alert in it can receive a fix. Query coverage can change, so consult GitHub’s CodeQL query suites documentation for current details and GitHub’s Copilot Autofix responsible-use guidance for operational limits.
Does GitHub automatically merge the suggested fix?
No. Autofix provides a proposal for a developer to review; it is not an automatic merge or proof that the vulnerability is resolved. Treat each suggestion like a code review request:
- Inspect every changed file and check that the edit belongs in the right location.
- Reason through the application’s intended behavior, including edge cases the suggestion may not account for.
- Verify any dependency name and version before accepting it; a proposed package or version may be unsupported, insecure, or fabricated.
- Run relevant tests and CI, then confirm that CodeQL no longer reports the alert before merging.
What can go wrong, and what data does GitHub use?
Generated output is non-deterministic and can be syntactically invalid, misplaced, semantically incorrect, incomplete, or ineffective at removing the vulnerability. A change can also introduce a new problem. Multi-file changes and subtle logic are particularly difficult, and very large files or repositories can exceed the context available to the system. In addition to incomplete language and query coverage, operational limits can prevent a fix from being generated.
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #3
GitHub says data handled by Copilot Autofix is not used to train LLMs. That does not remove the need to review the actual code changes or validate their behavior.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What GitHub reported about remediation time
GitHub’s August 2024 announcement reported results from its public-beta customer data for May through July 2024. The cohort was new CodeQL alerts in pull requests on repositories with GitHub Advanced Security enabled. These are vendor-reported figures, not results from an independent trial or a promise of the same time savings for another team.
Rank #4
| Alert group | With Autofix | Manual | GitHub’s reported comparison |
|---|---|---|---|
| All included new pull-request alerts | Median 28 minutes to use Autofix to automatically commit a fix | Median 1.5 hours | 3× faster |
| Cross-site scripting | Median 22 minutes | Almost 3 hours | 7× faster |
| SQL injection | Median 18 minutes | 3.7 hours | 12× faster |
GitHub also quoted Otto (GmbH & Co KG) Community Manager, Security Mario Landgraf praising the feature’s ability to recommend changes and free up team time. That is customer testimony in GitHub’s announcement, not independent evidence of typical results.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

