Customize code scanning default setup at scale
You can now apply your own configuration file to code scanning default setup, using the new github-codeql-config-file repository property. This gives you control over how CodeQL scans your code for security vulnerabilities, whether that’s on one repository or across your whole organization.
Read GitHub's release noteshttps://github.blog/changelog/2026-08-04-customize-code-scanning-default-setup-at-scale
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Code coverage automatic enablement in Code Quality settings
PreviewAI agentsSecurityData integration
CodeQL 2.26.2 adds Swift 6.3.3 and Kotlin 2.4.10 support
UpdateSQLGovernanceSecurity
CodeQL 2.26.1 improves analysis accuracy and framework coverage
UpdateSQLSecurityObservability
npm publish-time malware scanning and dual-use metadata
UpdateGovernanceSecurityObservability
Dependabot alerts on malicious packages across more ecosystems
UpdateSecurityData integration
Also shipped on Aug 4, 2026
Gateway Monitoring & A/B Testing (General availability)
GASQLObservabilityPerformance
Unity Gateway is now generally available
GAAI agentsMCPGovernance