AI & Tech Brief — 17 September 2026: AI Scanning, Copilot Budgets and Repository Governance

Overview

Edition: 17 September 2026 (Japan Standard Time). Three GitHub updates announced on 15–16 September focus on where AI-assisted development meets security, spending controls, and repository governance. These are vendor announcements, not claims that every team has adopted or enabled the features.

Key takeaways

  • AI Scan for pull requests no longer depends on CodeQL default setup, but the relevant scanning features still need to be enabled.
  • Copilot Business and Enterprise members can request a budget increase when they exhaust their AI credits; a paying account's manager decides whether to approve it.
  • Copilot can suggest allowed values while administrators define repository custom properties in a public preview.

Top stories

1. AI Scan removes a CodeQL setup dependency

Announced: 16 September 2026. GitHub says AI Scan for pull requests can find security vulnerabilities even where CodeQL default setup is not configured. Code scanning and AI Scan for pull requests must still be enabled at the applicable repository, organization, or enterprise level. The change is a public preview on github.com for GitHub Advanced Security customers, including organization-owned and personal repositories; GitHub Enterprise Server is not supported in this release. Teams should check their actual enablement and coverage rather than assuming all pull requests are scanned.

Primary source: GitHub Changelog

2. Copilot adds a budget-increase request workflow

Announced: 16 September 2026. Members who use all their Copilot AI credits can now request more budget from the account that pays for it. Organization owners, enterprise owners, and billing managers can review requests, set an amount, and approve, adjust, or deny them in settings. Approval raises the member's budget and restores access to credit-consuming features. GitHub says this is generally available for Copilot Business and Enterprise under usage-based billing. A request itself does not authorize spending; managers should review cost implications before changing a budget.

Primary source: GitHub Changelog

3. Copilot suggests repository custom-property values

Announced: 15 September 2026. When an administrator creates a custom property definition at the organization or enterprise level, Copilot can suggest allowed values based on the property's name. GitHub gives compliance and internet-facing classifications as examples. Owners can control availability through a policy for repository custom-property suggestions. The feature is in public preview for Copilot Business and Enterprise. Administrators still need to choose values that fit their governance rules; a suggestion is not an approved classification.

Primary source: GitHub Changelog

Watchlist

  • Security coverage: Verify which repositories and pull requests actually receive AI Scan during the preview.
  • Budget governance: Monitor requests and approval amounts without treating a notification as permission to spend.
  • Repository metadata: Review suggested property values for consistent meaning before using them in rulesets.

The product details above are attributed to GitHub's linked announcements. The checks in this watchlist are editorial analysis and do not assert measured outcomes.

コメント

このブログの人気の投稿

Faber:コードグラフ活用のコスト効率良いオープンソースAIコーディングエージェント

Claudeの電子透かし、仕組みと限界をAnthropicが公表

AI & Tech Brief — 8 September 2026: Making AI Work Beyond the Lab