Code scanning shows AI security detections on pull requests
GitHub code scanning now surfaces AI-powered security detections directly on pull requests, expanding vulnerability coverage to languages and frameworks not currently supported by CodeQL. These detections help teams identify and address potential issues in parts of the codebase that previously had no native scanning coverage, all before code is merged.
Read GitHub's release noteshttps://github.blog/changelog/2026-07-14-code-scanning-shows-ai-security-detections-on-pull-requests
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Dependabot version updates introduce default package cooldown
UpdateSecurityObservability
Improvements to secret scanning and public monitoring
UpdateSecurityObservability
Manage secret scanning custom patterns via REST API
GASecurityObservabilityDeveloper tools
GitHub Code Quality license estimate in public preview
PreviewPricingDeveloper toolsCoding agents
CodeQL 2.26.0 adds Kotlin 2.4.0 support and AI prompt injection detection
UpdateSQLStreamingSecurity
Clearer names for secret scanning detector types
UpdateSecurityObservabilityDeveloper tools
Organization-level targeting for GitHub Code Quality
PreviewPricingObservability
Also shipped on Jul 14, 2026
Catalog integration for Snowflake Postgres (General availability)
GAGovernanceApache IcebergPostgres
Admin API adds Claude Enterprise user management in beta
BetaLLMsDeveloper tools