Code scanning AI Scan no longer requires CodeQL default setup
You can now use AI Scan for pull requests to find security vulnerabilities, even when CodeQL default setup isn’t enabled on a repository. Previously, AI Scan for pull requests only ran on repositories where CodeQL default setup was configured.
Read GitHub's release noteshttps://github.blog/changelog/2026-09-16-code-scanning-ai-scan-no-longer-requires-codeql-default-setup
Summaries of vendors' own notes. Product names and logos belong to their owners; logos via logo.dev.
More GitHub Advanced Security releases
Enforce GitHub Advanced Security configurations
UpdateGovernanceSecurityObservability
Manage the code coverage ruleset condition with the REST API
GAObservabilityDeveloper tools
Stage-only npm tokens for safer automation
UpdateGovernanceSecurityDeveloper tools
GitHub Enterprise adds credential inventory exports
UpdateSecurityPricingObservability
Deprecation notice: All-platform CodeQL bundle
DeprecationObservabilityDeveloper tools
AI Scan for pull request APIs in public preview
PreviewSecurityObservabilityDeveloper tools
npm extends recovery-code security holds to all accounts
UpdateSecurityObservability
Also shipped on Sep 16, 2026
Include and exclude per-user quota users by name (General availability)
GAGovernancePricingDeveloper tools