Copilotの自動修正 is an expansion of code scanning that provides you with targeted recommendations to help you fix code scanning alerts so you can avoid introducing new security vulnerabilities. The potential fixes are generated automatically by large language models (LLMs) using data from the codebase and from code scanning analysis.
How Copilotの自動修正 works
Copilotの自動修正 translates the description and location of an alert into code changes that may fix the alert. It interfaces with the large language model GPT-5.1 from OpenAI, which has sufficient generative capabilities to produce both suggested fixes in code and explanatory text for those fixes.
Enabling and managing Copilotの自動修正
You do not need a subscription to GitHub Copilot to use GitHub Copilot Autofix. Copilotの自動修正 is available to all public repositories on GitHub.com, as well as internal or private repositories owned by organizations and enterprises that have a license for GitHub Code Security.
Copilotの自動修正 is allowed by default and enabled for every repository that uses CodeQL, regardless of whether it uses default or advanced setup for code scanning. There is no separate step to enable Copilotの自動修正: enabling code scanning with CodeQL is sufficient. See コード スキャンの既定セットアップの構成.
Administrators at the enterprise, organization, and repository levels can choose to disable Copilotの自動修正. If Copilotの自動修正 has been disabled at your level, you can re-enable it by following the same steps used to disable it and selecting the option to allow Copilotの自動修正. To learn how to manage Copilotの自動修正 at each level, see コード スキャンのセキュリティ アラートに対する Copilot 自動修正の無効化.