[{"data":1,"prerenderedAt":69},["ShallowReactive",2],{"blog-ai-scan-enhances-security-for-pull-requests-without-codeql-setup":3},{"_path":4,"_dir":5,"_draft":6,"_partial":6,"_locale":7,"title":8,"description":9,"date":10,"tags":11,"cover":16,"body":17,"_type":63,"_id":64,"_source":65,"_file":66,"_stem":67,"_extension":68},"/blog/ai-scan-enhances-security-for-pull-requests-without-codeql-setup","blog",false,"","AI Scan Enhances Security for Pull Requests Without CodeQL Setup","GitHub's AI Scan now finds vulnerabilities in pull requests even when CodeQL default setup isn’t enabled. Learn how this improves security checks.","2026-09-17",[12,13,14,15],"github","devsecops","security","codescanning",true,{"type":18,"children":19,"toc":57},"root",[20,29,35,41,46,52],{"type":21,"tag":22,"props":23,"children":25},"element","h2",{"id":24},"ai-scan-for-pull-requests-without-codeql-default-setup",[26],{"type":27,"value":28},"text","AI Scan for Pull Requests Without CodeQL Default Setup",{"type":21,"tag":30,"props":31,"children":32},"p",{},[33],{"type":27,"value":34},"GitHub's AI Scan tool now identifies security vulnerabilities in pull requests even when the repository does not have the CodeQL default setup enabled. Previously, AI Scan depended on this setup to function, which could limit its effectiveness across varied repositories.",{"type":21,"tag":22,"props":36,"children":38},{"id":37},"what-this-means-for-developers",[39],{"type":27,"value":40},"What This Means for Developers",{"type":21,"tag":30,"props":42,"children":43},{},[44],{"type":27,"value":45},"This update simplifies security scanning. Developers can now leverage AI Scan’s capabilities more broadly, ensuring potential vulnerabilities are caught early during code review without additional configuration.",{"type":21,"tag":22,"props":47,"children":49},{"id":48},"enhancing-secure-development-practices",[50],{"type":27,"value":51},"Enhancing Secure Development Practices",{"type":21,"tag":30,"props":53,"children":54},{},[55],{"type":27,"value":56},"By removing reliance on CodeQL’s default setup, GitHub is enabling more teams to integrate security scanning seamlessly into their workflows, promoting faster and safer software development cycles.",{"title":7,"searchDepth":58,"depth":58,"links":59},2,[60,61,62],{"id":24,"depth":58,"text":28},{"id":37,"depth":58,"text":40},{"id":48,"depth":58,"text":51},"markdown","content:blog:ai-scan-enhances-security-for-pull-requests-without-codeql-setup.md","content","blog/ai-scan-enhances-security-for-pull-requests-without-codeql-setup.md","blog/ai-scan-enhances-security-for-pull-requests-without-codeql-setup","md",1789629523413]