{"id":5978,"date":"2024-03-22T09:24:15","date_gmt":"2024-03-22T01:24:15","guid":{"rendered":"https:\/\/www.1ai.net\/?p=5978"},"modified":"2024-03-22T09:24:15","modified_gmt":"2024-03-22T01:24:15","slug":"github-%e6%9c%80%e6%96%b0-ai-%e5%b7%a5%e5%85%b7%e5%8f%af%e5%b8%ae%e5%8a%a9%e7%94%a8%e6%88%b7%e8%87%aa%e5%8a%a8%e4%bf%ae%e5%a4%8d%e4%bb%a3%e7%a0%81%e4%b8%ad%e7%9a%84%e9%94%99%e8%af%af%e5%92%8c%e6%bc%8f","status":"publish","type":"post","link":"https:\/\/www.1ai.net\/en\/5978.html","title":{"rendered":"GitHub&#039;s new AI tool helps users automatically fix bugs and vulnerabilities in their code"},"content":{"rendered":"<p data-vmark=\"d7da\"><a href=\"https:\/\/www.1ai.net\/en\/tag\/github\" title=\"_Other Organiser\" target=\"_blank\" >GitHub<\/a> Launched today for all Advanced Security (GHAS) licensees, the new \"<a href=\"https:\/\/www.1ai.net\/en\/tag\/%e4%bb%a3%e7%a0%81\" title=\"[See articles with [code] labels]\" target=\"_blank\" >Code<\/a>Scan\" feature (in preview) to search GitHub code for potential<a href=\"https:\/\/www.1ai.net\/en\/tag\/%e5%ae%89%e5%85%a8%e6%bc%8f%e6%b4%9e\" title=\"_Other Organiser\" target=\"_blank\" >Security Vulnerabilities<\/a>and coding errors.<\/p>\n<p data-vmark=\"d4c3\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-5979\" title=\"828938a8-6674-4465-985a-6a26c9d385c2\" src=\"https:\/\/www.1ai.net\/wp-content\/uploads\/2024\/03\/828938a8-6674-4465-985a-6a26c9d385c2.jpg\" alt=\"828938a8-6674-4465-985a-6a26c9d385c2\" width=\"1199\" height=\"864\" \/><\/p>\n<p data-vmark=\"f378\">This new feature uses Copilot and CodeQL, a code analysis engine developed by GitHub to automate security checks, to find possible vulnerabilities or bugs in your code, categorize them, and prioritize fixes. It's worth noting that Code Scan consumes GitHub Actions minutes.<\/p>\n<p data-vmark=\"5505\">Code Scan is also described as preventing developers from introducing new issues, and supports scanning at specific dates and times, or triggering a scan when a specific event occurs in the repository (e.g., a push).<\/p>\n<p data-vmark=\"e4ad\">If the AI finds a possible vulnerability or bug in your code, GitHub alerts the repository and cancels the alert after the user fixes the code that triggered it.<\/p>\n<p data-vmark=\"9a4b\">To monitor your repository or organization's Code Scanning results, you can use web hooks and the code scanning API, and Code Scanning can also interoperate with third-party code scanning tools that output Static Analysis Result Interchange Format (SARIF) data. Code Scan can also interoperate with third-party code scanning tools that output static analysis result interchange format (SARIF) data.<\/p>\n<p data-vmark=\"1bee\">Currently, there are three main approaches to CodeQL analysis for Code Scanning:<\/p>\n<ul class=\"list-paddingleft-2\">\n<li>\n<p data-vmark=\"2cfb\">Quickly configure CodeQL analysis for Code Scan on the repository using the default settings. The default settings automatically select the language to analyze, the query suite to run, and the event that triggers the scan, or you can manually select the query suite to run and the language to analyze if desired. When CodeQL is enabled, GitHub Actions performs a workflow run to scan code.<\/p>\n<\/li>\n<li>\n<p data-vmark=\"8f74\">Add a CodeQL workflow to the repository using the advanced settings. This will generate a customizable workflow file that runs the CodeQL CLI using github \/ codeql-action.<\/p>\n<\/li>\n<li>\n<p data-vmark=\"cecb\">Run the CodeQL CLI directly on an external CI system and upload the results to GitHub.<\/p>\n<\/li>\n<\/ul>\n<p data-vmark=\"83c9\">GitHub promises that this AI system can fix more than two-thirds of the vulnerabilities it discovers, so there's generally no need for developers to actively edit code. The company also promises that the code scanning auto-remediation will cover more than 90% alert types in its supported languages, which currently include JavaScript, Typescript, Java, and Python.<\/p>","protected":false},"excerpt":{"rendered":"<p>GitHub today launched a new \"Code Scan\" feature (preview) for all Advanced Security (GHAS) licensees to search for potential security vulnerabilities and coding errors in GitHub code. This new feature leverages Copilot and CodeQL, a code analysis engine developed by GitHub to automate security checks, to find, categorize, and prioritize fixes for potential vulnerabilities or bugs in your code. It's worth noting that Code Scan consumes GitHub Actions minutes. Code Scan is also described as preventing developers from introducing new issues, and supports the use of the code scanner on specific days and times.<\/p>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[146],"tags":[385,1809,1100],"collection":[],"class_list":["post-5978","post","type-post","status-publish","format-standard","hentry","category-news","tag-github","tag-1809","tag-1100"],"acf":[],"_links":{"self":[{"href":"https:\/\/www.1ai.net\/en\/wp-json\/wp\/v2\/posts\/5978","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.1ai.net\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.1ai.net\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.1ai.net\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.1ai.net\/en\/wp-json\/wp\/v2\/comments?post=5978"}],"version-history":[{"count":0,"href":"https:\/\/www.1ai.net\/en\/wp-json\/wp\/v2\/posts\/5978\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.1ai.net\/en\/wp-json\/wp\/v2\/media?parent=5978"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.1ai.net\/en\/wp-json\/wp\/v2\/categories?post=5978"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.1ai.net\/en\/wp-json\/wp\/v2\/tags?post=5978"},{"taxonomy":"collection","embeddable":true,"href":"https:\/\/www.1ai.net\/en\/wp-json\/wp\/v2\/collection?post=5978"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}