HomeSecurityGitHub Code Scanning Autofix: New AI tool fixes vulnerabilities in code

GitHub Code Scanning Autofix: New AI tool fixes code vulnerabilities

GitHub has introduced a new AI feature, called Code Scanning Autofix , that helps fix vulnerabilities during code generation . The feature is currently in public beta and is automatically enabled in all private repositories for GitHub Advanced Security (GHAS) customers .

GitHub Code Scanning Autofix

Code Scanning Autofix is ​​powered by GitHub Copilot and CodeQL and is designed to help address over 90% of alert types in JavaScript, Typescript, Java, and Python.

Once enabled, it provides potential fixes that can potentially address more than two-thirds of vulnerabilities found during code generation, with minimal or no editing.

See also: 2023: 12 million sensitive data leaked on GitHub

“When a vulnerability is discovered in a supported language, fix suggestions will include an explanation, in natural language, of the proposed fix along with a preview of the code suggestion that the developer can accept, edit, or reject,” said ’s Pierre Tempel and Eric Tooley about Code Scanning Autofix.

GitHub Code Scanning Autofix: New AI tool fixes code vulnerabilities

The code suggestions and explanations provided by GitHub Code Scanning Autofix can include changes to the current file, multiple files, and dependencies of the current project.

GitHub hopes that this new AI tool will significantly reduce the frequency of vulnerabilities that security, allowing them to focus on the security of the organization instead of devoting unnecessary resources to addressing new vulnerabilities introduced during the development process.

See also: GitHub: Secret Scanning Push Protection now available by default

“Just as GitHub Copilot frees developers from tedious and repetitive tasks, code scanning autofix will help development teams reclaim the time they previously spent on remediation“.

However, developers should always verify whether security, as GitHub Code Scanning Autofix may suggest fixes that only partially address the security vulnerability or impact the intended code functionality.

The company plans to add support for additional languages ​​in the coming months, with C# and Go support to follow.

More details about the new tool are available on the GitHub website

GitHub Code Scanning Autofix: New AI tool fixes code vulnerabilities

The impact of this tool on GitHub Advanced Security customers

This new tool introduced by GitHub, which is based on artificial intelligence, has the potential to accelerate the correction of vulnerabilities during programming. This means that GitHub Advanced Security customers will be able to fix any vulnerabilities in their code faster, thus strengthening the security of their applications and systems .

See also: GitHub Copilot Enterprise: New AI Programming Assistant

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Additionally, GitHub Code Scanning Autofix is ​​automatically enabled on all private repositories for GHAS customers . This means they don't need to spend time and resources to enable or configure it, as the tool works automatically and seamlessly.

Finally, the fact that the tool is in public beta means that GHAS customers will have the opportunity to contribute to the improvement and evolution of the tool by providing feedback and comments. This can lead to a more tailored and effective experience for customers down the road.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS