跳到主内容
@wquguru
精选78GitHub Changelog云与平台

GitHub Code Scanning AI Scan 不再强制要求启用 CodeQL 默认设置

Code scanning AI Scan no longer requires CodeQL default setup

原文
发到 X
推荐理由

核心安全工具降低了集成门槛,移除了对 CodeQL 默认设置的硬性依赖,建议开启 GHAS 的读者立即检查并启用以扩大扫描覆盖面。

You can now use AI Scan for pull requests to find security vulnerabilities, even when CodeQL default setup isn’t enabled on a repository. Previously, AI Scan for pull requests only ran on repositories where CodeQL default setup was configured.

您现在可以使用针对拉取请求的 AI 扫描来查找安全漏洞,即使仓库中未启用 CodeQL 默认设置。此前,针对拉取请求的 AI 扫描仅在配置了 CodeQL 默认设置的仓库上运行。

What’s changed

变更内容

Code scanning and AI Scan for pull requests must still be enabled at the repository, organization, or enterprise level, if the organization belongs to an enterprise. The same permission hierarchy still applies. There’s no new setup step. If you’ve already enabled GitHub code scanning’s AI Scan for your organization, it now runs more broadly across your eligible repositories, regardless of whether CodeQL default setup is configured.

代码扫描和针对拉取请求的 AI 扫描仍需在仓库、组织或企业级别启用(如果组织隶属于某个企业)。相同的权限层级仍然适用。无需新的设置步骤。如果您已为组织启用了 GitHub 代码扫描的 AI 扫描功能,它现在将在您所有符合条件的仓库中更广泛地运行,无论是否配置了 CodeQL 默认设置。

This change is now in public preview for organization-owned and personal repositories on github.com for GitHub Advanced Security customers. GitHub Enterprise Server is not supported for this release.

此项变更现已在 github.com 上的组织拥有的仓库和个人仓库中对 GitHub Advanced Security 客户开放公共预览。GitHub Enterprise Server 暂不支持此版本。

To learn more, see our docs about AI-powered security detections.

如需了解更多,请参阅我们关于 AI 驱动的安全检测的文档。

Join the discussion and leave feedback on GitHub Community.

加入讨论并在 GitHub Community 留下反馈。

The post Code scanning AI Scan no longer requires CodeQL default setup appeared first on The GitHub Blog.

《代码扫描 AI 扫描不再需要 CodeQL 默认设置》一文最初发布于 The GitHub Blog。

更进一步:量化金融体系

看懂新闻只是起点——沿量化金融路径,把它变成能交付的工程能力

进入量化体系 →

相似阅读

关联信息,但可能不是同一事件