Skip to content

Commit 9050d92

Browse files
mchammer01Copilotam-steadjf205
authored
GitHub Code Quality: Agentic Autofix for Backlog Experiences [public preview] (#61831)
Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: Anne-Marie <102995847+am-stead@users.noreply.github.com> Co-authored-by: James Fletcher <42464962+jf205@users.noreply.github.com> Copilot-Session: cc516c8e-bdeb-4490-85c3-6ef91946419a Copilot-Session: 2c5b1fb4-960a-4056-9b94-da74ddd243bb Copilot-Session: e03f76ef-c46c-49a6-b767-f5b01e370f56 Copilot-Session: 7330ec01-3ba0-45a2-98bd-aa2f2c1b20f3
1 parent 81f2df2 commit 9050d92

6 files changed

Lines changed: 43 additions & 11 deletions

File tree

333 KB
Loading

‎content/code-security/how-tos/maintain-quality-code/fix-backlog-findings.md‎

Lines changed: 26 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -22,13 +22,19 @@ category:
2222

2323
1. **{% data variables.code-quality.all_findings %}**: {% data variables.product.prodname_code_quality_short %} uses {% data variables.product.prodname_codeql %} to perform a deterministic, rules-based scan of your default branch. Finding are grouped by rule and language, labeled by severity (**Error**, **Warning**, **Note**), and each includes a suggested autofix.
2424

25-
1. **{% data variables.code-quality.recent_suggestions %}**: {% data variables.product.prodname_code_quality_short %} uses AI-powered analysis to identify quality issues in the files most recently pushed to your default branch, including issues that rule-based analysis may not detect - such as best practices, naming conventions, or design considerations.
25+
1. **{% data variables.code-quality.recent_suggestions %}**: {% data variables.product.prodname_code_quality_short %} uses AI-powered analysis to identify quality issues in the files most recently pushed to your default branch, including issues that rule-based analysis may not detect - such as best practices, naming conventions, or design considerations.
2626

27-
{% data reusables.code-quality.recent-suggestions-preview-note %}
27+
{% data reusables.code-quality.recent-suggestions-preview-note %}
2828

29-
For information on resolving {% data variables.code-quality.recent_suggestions %}, see [AUTOTITLE](/code-security/how-tos/maintain-quality-code/fix-findings-in-recent-merges).
29+
For information on resolving {% data variables.code-quality.recent_suggestions %}, see [AUTOTITLE](/code-security/how-tos/maintain-quality-code/fix-findings-in-recent-merges).
3030

31-
## Resolving a standard finding
31+
## Resolving standard findings
32+
33+
You can resolve findings individually or assign multiple findings to {% data variables.product.prodname_copilot_short %}.
34+
35+
{% data reusables.code-quality.agentic-autofix-preview-note %}
36+
37+
### Resolving a single finding
3238

3339
{% data reusables.code-quality.dashboard-navigation-repo %}
3440
{% data reusables.code-quality.dashboard-all-findings %}
@@ -48,6 +54,22 @@ category:
4854

4955
To raise a maintainability or reliability score, you must resolve every finding at the highest severity level currently affecting that metric. See [AUTOTITLE](/code-security/reference/code-quality/metrics-and-ratings).
5056

57+
### Assigning multiple findings to {% data variables.product.prodname_copilot_short %}
58+
59+
If you have many findings for a rule and want to remediate them efficiently, you can select these findings in bulk and assign them to {% data variables.product.prodname_copilot_short %} for agentic remediation. {% data variables.product.prodname_copilot_short %} will open a pull request with fixes for the selected findings.
60+
61+
You don't need a {% data variables.product.prodname_copilot_short %} license to use this feature, but your enterprise owner must allow {% data variables.product.prodname_code_quality_short %} for your organization. See [AUTOTITLE](/code-security/how-tos/secure-at-scale/configure-enterprise-security/configure-specific-tools/allow-github-code-quality-in-enterprise).
62+
63+
For the best results, start with a single rule that has many high-severity findings. This lets you validate the quality of the autofixes on a cohesive set of changes before expanding to other rules.
64+
65+
{% data reusables.code-quality.dashboard-navigation-repo %}
66+
{% data reusables.code-quality.dashboard-all-findings %}
67+
1. Select the findings you want to remediate. You can select up to 25 findings per page, one page at a time.
68+
1. Click **Assign to {% data variables.product.prodname_copilot_short %}**.
69+
70+
![Screenshot of the "Standard findings" view. The "3 of 3 selected" checkbox and the "Dismiss" and "Assign to Copilot" buttons are outlined in orange.](/assets/images/help/code-quality/assign-findings-bulk.png)
71+
1. {% data variables.product.prodname_copilot_short %} will open a pull request with fixes for the selected findings. Review the pull request carefully before merging.
72+
5173
## Verifying that your code quality scores have updated
5274

5375
After your autofix pull requests are merged, return to the "{% data variables.code-quality.all_findings %}" view to confirm that:

‎content/code-security/how-tos/secure-at-scale/configure-enterprise-security/configure-specific-tools/allow-github-code-quality-in-enterprise.md‎

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -17,7 +17,13 @@ category:
1717
---
1818

1919
> [!NOTE]
20-
> Previously, {% data variables.product.prodname_AS %} policies also controlled access to {% data variables.product.prodname_code_quality_short %}. Those existing policy settings are automatically applied to the standalone {% data variables.product.prodname_code_quality_short %} policies.
20+
> {% data variables.product.prodname_code_quality_short %} has its own standalone enterprise policies. Access was previously controlled by your {% data variables.product.prodname_AS %} policies, and those existing settings are automatically applied to the new {% data variables.product.prodname_code_quality_short %} policies.
21+
22+
{% data reusables.code-quality.agentic-autofix-preview-note %}
23+
24+
When you allow {% data variables.product.prodname_code_quality_short %} for an organization and set the repository admin policy to **Allowed**, repository administrators can enable {% data variables.product.prodname_code_quality_short %} scans and all associated capabilities, including bulk agentic remediation with {% data variables.product.prodname_copilot_short %}. There is no separate policy for agentic remediation.
25+
26+
If you restrict {% data variables.product.prodname_code_quality_short %}, repository administrators cannot enable scans or use {% data variables.product.prodname_copilot_short %}-powered autofixes for code quality findings.
2127

2228
1. Navigate to your enterprise. For example, from [https://github.com/settings/enterprises](https://github.com/settings/enterprises?ref_product=ghec&ref_type=engagement&ref_style=text).
2329
{% data reusables.enterprise-accounts.policies-tab %}

‎content/code-security/tutorials/improve-code-quality/raise-your-quality-rating.md‎

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -64,10 +64,13 @@ Once you've picked a rule, decide how to handle each finding:
6464

6565
| Assessment | Recommended action | Notes |
6666
| --- | --- | --- |
67-
| The finding is legitimate. | Click **Generate fix** and open a pull request | Clicking **Generate fix** consumes {% data variables.product.prodname_ai_credits_short %}. You can add multiple autofixes to the same branch to group remediation work in one pull request. |
68-
| The finding doesn't apply. For example, it's in legacy code, an intentional pattern, or a false positive | Click **Dismiss**. | The finding is considered resolved and removed from the list of open findings. |
67+
| One finding is legitimate. | Click **Assign to {% data variables.product.prodname_copilot_short %}**. | {% data variables.product.prodname_copilot_short %} opens a pull request containing fixes for the selected findings. Assigning to {% data variables.product.prodname_copilot_short %} consumes {% data variables.product.prodname_ai_credits_short %}. |
68+
| Multiple findings for the same rule are legitimate. | Select up to 25 findings on a page, then click **Assign to {% data variables.product.prodname_copilot_short %}**. | {% data variables.product.prodname_copilot_short %} opens a pull request containing fixes for the selected findings. Assigning to {% data variables.product.prodname_copilot_short %} consumes {% data variables.product.prodname_ai_credits_short %}|
69+
| A finding doesn't apply. For example, it's in legacy code, an intentional pattern, or a false positive. | Click **Dismiss**. | The finding is considered resolved and removed from the list of open findings. |
6970

70-
In our example, we generate autofixes for the 40 "Overwritten property" findings and open a pull request. Because they share a single pattern, the fixes are nearly identical. We merge the pull request once CI checks pass.
71+
{% data reusables.code-quality.agentic-autofix-preview-note %}
72+
73+
In our example, we assign the 40 "Overwritten property" findings to {% data variables.product.prodname_copilot_short %} in batches of up to 25. We review the resulting pull requests and merge them once the CI checks pass.
7174

7275
## Step 4: Communicate impact
7376

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,2 @@
1+
> [!NOTE]
2+
> Agentic Autofix for {% data variables.product.prodname_code_quality %} backlog findings is currently in {% data variables.release-phases.public_preview %} and subject to change.
Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,2 @@
1-
1. To the right of an individual finding, click **Generate fix**.
2-
1. Review the diff of the proposed change. If you agree with it, click **Open pull request**.
3-
1. In the "Commit autofix to branch" dialog, select "Open a pull request", then click **Commit change**.
1+
1. To the right of an individual finding, click **Assign to {% data variables.product.prodname_copilot_short %}**. Assigning a finding to {% data variables.product.prodname_copilot_short %} consumes {% data variables.product.prodname_ai_credits_short %}.
2+
1. Review the draft pull request that {% data variables.product.prodname_copilot_short %} opens with a fix for the finding.

0 commit comments

Comments
 (0)