Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

GitHub announced the general availability of security campaigns with Copilot Autofix on April 8, 2025, as part of GitHub Code Security. Campaigns give security teams a way to group and prioritize code-scanning alerts across repositories for a time-bounded remediation effort. They coordinate suggested fixes, developer notifications, and progress tracking; they do not automatically deploy fixes.

What GitHub security campaigns do

A security campaign turns selected code-scanning alerts across repositories into a shared remediation effort with a chosen scope and timeframe. Security teams can prioritize the work, while developers familiar with the affected code review suggested fixes and decide how to remediate the vulnerabilities.

Copilot Autofix suggests fixes when a campaign is created. Developers are notified, can review the suggestions, and can open pull requests to address the alerts. Security teams can monitor campaign progress and the number of alerts fixed. A suggestion is not a completed fix: developers review and apply the change through their workflow.

What the April 2025 general-availability announcement added

GitHub’s April 8, 2025 announcement highlighted three campaign-management additions:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Draft campaigns: Security managers can prepare and refine a campaign’s scope before making it available to developers.
  • Optional automated GitHub issues: Issues can be created in repositories containing campaign alerts and updated as the campaign progresses.
  • Organization-level statistics: Aggregate views show progress across active and past campaigns.

These are capabilities highlighted in the launch announcement, not a complete inventory of what campaigns support today.

Who could use campaigns at launch—and what to verify now

The April 2025 announcement said security campaigns were available to GitHub Code Security users on GitHub Enterprise Cloud. That describes GitHub’s launch eligibility statement; it does not establish every current plan entitlement, account restriction, regional condition, or setup requirement.

GitHub’s September 2025 changelog index later listed an announcement about security campaigns and assignable alerts for code scanning and secret scanning, indicating that the scope described at launch was not the final word. The index listing alone does not establish the full current feature set or its limits.

Before planning a rollout, confirm the live requirements and behavior for your account with current GitHub documentation or your GitHub administrator. In particular, check:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Which alert types your organization can include in a campaign.
  • Which plans, repositories, and configuration are required.
  • How campaign scope and timeframe are set, and whether draft review suits your team’s process.
  • Whether optional issue creation fits repository workflows and who will maintain those issues.
  • Which organization-level progress measures are available to your team.

What the reported results do—and do not—show

SecurityWeek reported a GitHub analysis from the public-preview period in which 55% of prioritized security debt was fixed with campaigns, compared with 10% without campaigns.

Reported group Share of prioritized security debt fixed Qualification
With campaigns 55% GitHub result relayed by SecurityWeek for the public-preview period; methodology was not explained in the available report.
Without campaigns 10% GitHub result relayed by SecurityWeek for the public-preview period; methodology was not explained in the available report.

This is a vendor-reported comparison, not an independently validated benchmark or a forecast for every organization. The available report does not establish that the groups were comparable in all relevant ways, so teams should not assume campaigns alone will produce the same difference in their own remediation rates.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to assess whether campaigns fit your remediation process

Campaigns are most relevant when security teams need to coordinate remediation across repositories and want developers close to the affected code to assess suggested changes. A practical evaluation should focus on fit rather than treating the feature as an automatic fix mechanism:

  • Choose a clearly prioritized set of eligible alerts and a realistic campaign timeframe.
  • Decide whether managers should refine a draft before notifying developers.
  • Agree how developers will review Autofix suggestions and handle cases where a suggestion is unsuitable.
  • Determine whether automatically created issues will add useful visibility or duplicate existing tracking.
  • Use the available progress statistics to monitor work, while distinguishing alerts fixed from suggestions merely presented.

GitHub’s launch announcement summarized the milestone as: “Security campaigns with Copilot Autofix are now generally available.” The statement marks the April 8, 2025 launch; later changes and account-specific eligibility should be checked against current GitHub information.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.