GreatAIPrompts 2024年12月19日
GitHub Introduces Code Scanning Autofix, Powered by Copilot and CodeQL
index_new5.html
../../../zaker_core/zaker_tpl_static/wap/tpl_guoji1.html

 

GitHub为高级安全客户推出代码扫描 autofix 功能,由 Copilot 和 CodeQL 提供支持,可帮助开发者快速修复漏洞,减少安全债务问题,该功能支持多种语言,提供自然语言解释和代码建议,公司计划增加更多语言支持并鼓励用户反馈。

🎯GitHub推出代码扫描autofix功能,现处于公开测试阶段。

💻该功能由Copilot和CodeQL提供支持,可助开发者快速修复漏洞。

📜支持多种流行编程语言,发现漏洞时提供自然语言解释和代码建议。

🚀公司计划继续增加语言支持,鼓励用户反馈以改进该功能。

March 21st, 2024: GitHub has launched a new feature called code scanning autofix, which is now available in public beta for all GitHub Advanced Security customers.

The feature, powered by GitHub Copilot and CodeQL, aims to help developers fix vulnerabilities more quickly and easily, reducing the growing problem of “application security debt.”

Code scanning autofix supports more than 90% of alert types in popular programming languages such as JavaScript, TypeScript, Java, and Python.

When a vulnerability is discovered in one of these languages, the feature provides developers with a natural language explanation of the suggested fix, along with a preview of the code suggestion.

Developers can then accept, edit, or dismiss the suggestion. Remarkably, these code suggestions have been shown to remediate more than two-thirds of found vulnerabilities with little or no editing required.

Pierre Tempel and Eric Tooley, authors of the blog post announcing the feature, state that code scanning autofix is “the next leap forward” in GitHub’s vision for application security, where “found means fixed.”

Code Scanning Autofix

By prioritizing the developer experience, the company aims to help teams remediate vulnerabilities up to seven times faster than traditional security tools.

Behind the scenes, code scanning autofix leverages the CodeQL engine and a combination of heuristics and GitHub Copilot APIs to generate code suggestions.

These suggestions can include changes to multiple files and the dependencies that should be added to the project.

GitHub plans to continue adding support for more languages, with C# and Go coming next.

The company encourages users to join the autofix feedback and resources discussion to share their experiences and help guide further improvements to the feature.

The introduction of code scanning autofix is expected to benefit both development and security teams.

Developers will be able to reclaim time previously spent on remediation, while security teams can focus on protecting the business and keeping up with the accelerated pace of development, as the volume of everyday vulnerabilities is reduced.

The post GitHub Introduces Code Scanning Autofix, Powered by Copilot and CodeQL appeared first on Weam - AI For Digital Agency.

Fish AI Reader

Fish AI Reader

AI辅助创作,多种专业模板,深度分析,高质量内容生成。从观点提取到深度思考,FishAI为您提供全方位的创作支持。新版本引入自定义参数,让您的创作更加个性化和精准。

FishAI

FishAI

鱼阅,AI 时代的下一个智能信息助手,助你摆脱信息焦虑

联系邮箱 441953276@qq.com

相关标签

GitHub 代码扫描 自动修复 Copilot CodeQL
相关文章