megachangelog
Feature

Security reviews now available in GitHub Copilot app

The /security-review slash command is now available in public preview in the GitHub Copilot app, allowing developers to run security reviews on in-flight code changes directly from the app.

You can now run a security review on your in-flight code changes directly from the GitHub Copilot app. The /security-review slash command is shipping in public preview, bringing the same AI-driven vulnerability scanning already available in Copilot CLI into your everyday coding workflow.

The /security-review appearing as a suggested command in the GitHub Copilot app chat window

What it does

/security-review analyses your current workstream changes and returns:

  • High-confidence security findings, scored by severity and confidence.
  • Actionable suggestions you can apply and reverify without leaving Copilot.
  • A focused, prioritised view so you can fix the issues that matter before code lands.

The scan is tuned to catch common, high-impact vulnerability classes such as injection flaws, cross-site scripting, insecure data handling, path traversal and weak cryptography.

Why it matters

The /security-review command gives you a way to catch issues while you’re still working without leaving your coding environment. It complements GitHub code scanning, Dependabot, and secret scanning by giving you a lightweight, on-demand check on your local changes.

How to try it

Open a project in the Copilot app, make your code changes, and run /security-review to scan those changes. The command is available to Copilot Free, Pro, Business, and Enterprise users during public preview.

Join the discussion and share your feedback in the GitHub Community.

The post Security reviews now available in the GitHub Copilot app appeared first on The GitHub Blog.

copilotsecurityaipreview

Source: original entry ↗

More from GitHub

Follow GitHub to get its new changes in your feed and email digest.

Announcement

Claude Haiku 5.5 now available in GitHub Copilot

Claude Haiku 5.5, Anthropic's lightweight model, is now generally available in GitHub Copilot for fast, high-volume tasks like subagents, quick edits, and terminal operations.

copilotaimodelsannouncement
Feature

Purpose-built model for leaked secret detection

GitHub introduced a new purpose-built model for detecting leaked secrets that provides context-aware detection to keep pace with modern software development practices, including AI-assisted coding.

securitysecret-detectionaiprotection
Announcement

Local sandboxing for GitHub Copilot now generally available

GitHub Copilot's local sandboxing feature is now generally available across GitHub Copilot CLI, the GitHub Copilot app, and VS Code sessions using Agent Host, providing developers with a secure environment for testing and development.

copilotaisecuritysandboxvscode
See all GitHub changes →