Skip to content

Product1 publisher3 min readPublished

GitHub turns its autofix agent's security fixes into memories Copilot code review can reuse

GitHub's agentic autofix now saves a pattern from each security fix it creates in Copilot Memory and passes those patterns to code review and the cloud agent. Teams that enable Memory now decide whether an agent's fixes deserve to guide reviews across a repository.

The Product Desk · Product desk

Illustration accompanying GitHub turns its autofix agent's security fixes into memories Copilot code review can reuse

What happened

  • GitHub announced the change on September 25 for customers with Memory turned on, and the agent now checks stored memories for context before it starts on an alert.
  • Repository facts are stored with citations to supporting code, checked against the current branch before use, and deleted automatically after 28 days without use.
  • Memory is on by default for individual plans, but on organization and enterprise plans an administrator has to enable the policy before any of this happens.
  • Autofix needs a Code Security or Advanced Security license plus Copilot with the cloud agent enabled, and it draws on the organization's AI credits and Actions minutes.
  • Both agentic autofix and Copilot Memory are still in public preview.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

  • decision On managed plans, the admin who enables the Memory policy is choosing two things at once: whether autofix remembers, and whether what it remembers shapes code review and cloud agent work.
  • exposure If patterns are banked when a fix is created, a fix that cleared CodeQL but was never approved by a reviewer could still inform Copilot's review of other pull requests in that repository.
  • constraint An organization that repeats the same flaw across many repositories gets the benefit one repository at a time, because repository facts stay where they were learned.

A developer assigns a code scanning alert to Copilot. The agent explores the relevant files, proposes a fix, reruns CodeQL to confirm the alert is gone, and tries again if it is not [8]. Then it opens a draft pull request explaining the fix. GitHub says a run usually takes two to four minutes [9].

That loop has been in public preview since July 10 [10]. The September update gives each run a second output, a stored fix pattern. According to GitHub's changelog, autofix saves the pattern when it creates a fix [11]. The changelog does not say whether that happens before or after a human approves the pull request [11].

GitHub pitches the stored patterns as repository-specific secure development practice [2]. The thing being done is narrower: an agent writes a patch, CodeQL confirms one alert has cleared, and the pattern is stored as the fix is created [8][11]. Mitch Ashley, a vice president and practice lead at The Futurum Group, puts the weight on that sequence. "Whether autofix banks a pattern before or after a human approves the fix will decide how much this helps. Bank it too early, and a weak pattern can spread faster than review catches it," he said [12].

Ashley also likes the design. "Tying a fix pattern to citations that expire once the code changes is a real step toward self-evidencing agent memory, a piece most agentic tooling still lacks," he said [13]. The documented check compares a pattern's citations with the current branch [4]. That tells Copilot the cited code is still there. Whether the original fix was sound was settled earlier, by CodeQL's rerun and by whoever read the draft [8]. The 28-day deletion only clears patterns that go unused. A pattern that code review keeps drawing on stays in place [4].

I'd switch Memory on for repositories where the same alert class keeps reappearing and where people already read Copilot's review comments and cloud agent pull requests before accepting them. I'd hold it everywhere else until GitHub says when patterns are saved. Holding has a cost: on those repositories, a repeat flaw found in a new file gets fixed from scratch, as it is now [16].

Two facts about each repository sort the cases in between. One is recurrence, meaning how often the same alert class comes back after a fix. The other is downstream checking, meaning whether Copilot code review comments and cloud agent pull requests get a human read before they land. High recurrence with real checking is the case GitHub built this for. High recurrence with light checking has the most to gain and the most exposure, and Ashley's warning about early banking applies there first [12]. Low recurrence gives Memory little to reuse, so enabling it there adds preview risk for a small return [7].

What to watch

  • Whether GitHub documents if autofix saves a pattern before or after a human approves the pull request.
  • Whether GitHub adds a separate control that keeps autofix memories out of code review and the cloud agent while Memory stays on.
  • How AI credit and Actions minute consumption is priced when agentic autofix and Copilot Memory leave public preview.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories