Summary
GitHub launched /security-review in public preview inside the GitHub Copilot app (July 14, 2026), bringing AI-driven vulnerability scanning previously available in Copilot CLI into the desktop coding workflow. The command scans current workstream/local changes for high-confidence findings (injection, XSS, insecure data handling, path traversal, weak cryptography), scores severity/confidence, and suggests fixes without leaving Copilot. It complements Code Scanning, Dependabot, and secret scanning. Available to Copilot Free, Pro, Business, and Enterprise during preview.
Source Analysis
Research Notes
Additional Sources
- GitHub Changelog primary (pipeline source)
- Complements existing Code Scanning / Dependabot / secret scanning docs
Key Facts Verified
- Verified:
/security-reviewpublic preview in Copilot app (July 14, 2026); scans local/in-flight changes; Free/Pro/Business/Enterprise during preview - Do not overclaim as AppSec replacement
Broader Context
AI coding tools absorbing AppSec workflows — application-security + agentic-coding-infrastructure.
Related Wiki
github-copilot · github · application-security · devsecops · codeql · ai-security
Draft Article
GitHub Copilot Uygulamasında /security-review Public Preview’da
github, 14 Temmuz 2026’da github-copilot uygulamasına /security-review komutunu public preview olarak ekledi. Daha önce Copilot CLI’da bulunan AI destekli güvenlik taraması, masaüstü kodlama akışına taşındı. Komut, uçuş halindeki yerel değişiklikleri tarayıp yüksek güvenli bulgular üretir; Code Scanning veya Dependabot’un yerini almaz.
Ana Gelişme
/security-review, mevcut workstream / local change set üzerinde çalışır. Injection, XSS, güvensiz veri işleme, path traversal ve zayıf kriptografi gibi desenleri hedefler; severity ve confidence skorları üretir, düzeltme önerileri sunar. Geliştirici application-security kontrolünü IDE dışına çıkmadan çalıştırabilir.
Özellik, preview süresince Copilot Free, Pro, Business ve Enterprise planlarında kullanılabilir. GitHub Changelog’a göre bu katman, mevcut Code Scanning, Dependabot ve secret scanning ürünlerini tamamlayıcı bir erken uyarı katmanı olarak konumlanır.
Neden Önemli?
devsecops ve ai-security kesişiminde, coding agent’ların AppSec iş akışlarını içine alması hızlanıyor. Türk geliştirici ekipleri için pratik kazanım net: PR öncesi yerel değişikliklerde yüksek güvenli açık sinyali. Ancak resmi changelog da vurguluyor: bu komut, olgun codeql tabanlı Code Scanning veya bağımlılık/sır taramasının yerine geçmez.
Kaynaklar
PreScreening Notes
- Score: 5 / Priority: medium — GitHub Copilot app gains
/security-reviewpublic preview (CLI feature into desktop workflow). Incremental product update, solid developer interest. - Official GitHub Changelog (July 14); software+AI. Not a major launch but worth a short take.
- No duplicate. Pass.
Evaluation Report
News Value
- Timeliness: July 14 GitHub Changelog.
- Impact: Incremental but useful —
/security-reviewin Copilot app (CLI feature → desktop). - Prominence: GitHub/Microsoft Copilot.
- Proximity: High for developers already on Copilot.
- Novelty: Low-medium (feature port), still shippable as brief.
Audience Fit
Software readers; clear how-to interest.
Risk & Ethics
Official changelog — low misinformation risk. Don’t overclaim AppSec replacement for Code Scanning/Dependabot.
Publication Strategy
- Format: brief
- Wiki: github-copilot, application-security, ai-coding-assistants
Suggested Angle
Brief: “GitHub Copilot uygulamasına /security-review geldi” — CLI’dan masaüstüne taşınan tarama; Code Scanning ile tamamlayıcı rol. Checkmarx tipi vendor vaatleriyle karıştırma.
Editorial Notes
Decision: Approved — brief
Angle confirmed: Incremental Copilot app feature; complement to Code Scanning/Dependabot, not replacement.
Reporting instructions:
- Official changelog primary is sufficient for this brief
- Do not overclaim AppSec replacement
- Available to Free/Pro/Business/Enterprise during preview
Headline suggestions (TR):
- GitHub Copilot uygulamasında
/security-reviewpublic preview’da - Uçuş halindeki kod için AI güvenlik taraması Copilot’a geldi
- CLI’dan masaüstüne: Copilot’ta yüksek güvenli açık bulguları
Mandatory points:
/security-reviewpublic preview in Copilot app (July 14)- Scans in-flight/local changes; severity/confidence scoring
- Complements Code Scanning / Dependabot / secret scanning — not a replacement