Summary
GitHub AI Scan for pull requests no longer requires CodeQL default setup on each repository. Existing organization or enterprise enablement now reaches all eligible repositories under the same permission hierarchy. The feature remains a public preview for organization-owned and personal repositories on github.com. It requires GitHub Advanced Security and does not support GitHub Enterprise Server.
Why it matters
For AppSec teams, this removes a repository-by-repository dependency that limited AI-assisted pull-request scanning coverage. Measure finding quality and review load before broad rollout because preview availability does not establish precision. Existing enterprise policy still controls where the scanner runs.
Technical details
| Status | public preview |
|---|---|
| Scope | organization-owned and personal repositories on github.com |
| Requirement Removed | CodeQL default setup per repository |
| Requirements | GitHub Advanced Security plus code scanning and AI Scan enabled by repository, organization or enterprise policy |
| Unsupported | GitHub Enterprise Server |
Tags
GitHubAI-ScanCodeQLAppSecpull-request