Summary

GitHub launched /security-review in public preview inside the GitHub Copilot app (July 14, 2026), bringing AI-driven vulnerability scanning previously available in Copilot CLI into the desktop coding workflow. The command scans current workstream/local changes for high-confidence findings (injection, XSS, insecure data handling, path traversal, weak cryptography), scores severity/confidence, and suggests fixes without leaving Copilot. It complements Code Scanning, Dependabot, and secret scanning. Available to Copilot Free, Pro, Business, and Enterprise during preview.

Source Analysis

Research Notes

Additional Sources

  • GitHub Changelog primary (pipeline source)
  • Complements existing Code Scanning / Dependabot / secret scanning docs

Key Facts Verified

  • Verified: /security-review public preview in Copilot app (July 14, 2026); scans local/in-flight changes; Free/Pro/Business/Enterprise during preview
  • Do not overclaim as AppSec replacement

Broader Context

AI coding tools absorbing AppSec workflows — application-security + agentic-coding-infrastructure.

github-copilot · github · application-security · devsecops · codeql · ai-security

Draft Article

GitHub Copilot Uygulamasında /security-review Public Preview’da

github, 14 Temmuz 2026’da github-copilot uygulamasına /security-review komutunu public preview olarak ekledi. Daha önce Copilot CLI’da bulunan AI destekli güvenlik taraması, masaüstü kodlama akışına taşındı. Komut, uçuş halindeki yerel değişiklikleri tarayıp yüksek güvenli bulgular üretir; Code Scanning veya Dependabot’un yerini almaz.

Ana Gelişme

/security-review, mevcut workstream / local change set üzerinde çalışır. Injection, XSS, güvensiz veri işleme, path traversal ve zayıf kriptografi gibi desenleri hedefler; severity ve confidence skorları üretir, düzeltme önerileri sunar. Geliştirici application-security kontrolünü IDE dışına çıkmadan çalıştırabilir.

Özellik, preview süresince Copilot Free, Pro, Business ve Enterprise planlarında kullanılabilir. GitHub Changelog’a göre bu katman, mevcut Code Scanning, Dependabot ve secret scanning ürünlerini tamamlayıcı bir erken uyarı katmanı olarak konumlanır.

Neden Önemli?

devsecops ve ai-security kesişiminde, coding agent’ların AppSec iş akışlarını içine alması hızlanıyor. Türk geliştirici ekipleri için pratik kazanım net: PR öncesi yerel değişikliklerde yüksek güvenli açık sinyali. Ancak resmi changelog da vurguluyor: bu komut, olgun codeql tabanlı Code Scanning veya bağımlılık/sır taramasının yerine geçmez.


Kaynaklar

PreScreening Notes

  • Score: 5 / Priority: medium — GitHub Copilot app gains /security-review public preview (CLI feature into desktop workflow). Incremental product update, solid developer interest.
  • Official GitHub Changelog (July 14); software+AI. Not a major launch but worth a short take.
  • No duplicate. Pass.

Evaluation Report

News Value

  • Timeliness: July 14 GitHub Changelog.
  • Impact: Incremental but useful — /security-review in Copilot app (CLI feature → desktop).
  • Prominence: GitHub/Microsoft Copilot.
  • Proximity: High for developers already on Copilot.
  • Novelty: Low-medium (feature port), still shippable as brief.

Audience Fit

Software readers; clear how-to interest.

Risk & Ethics

Official changelog — low misinformation risk. Don’t overclaim AppSec replacement for Code Scanning/Dependabot.

Publication Strategy

Suggested Angle

Brief: “GitHub Copilot uygulamasına /security-review geldi” — CLI’dan masaüstüne taşınan tarama; Code Scanning ile tamamlayıcı rol. Checkmarx tipi vendor vaatleriyle karıştırma.

Editorial Notes

Decision: Approved — brief
Angle confirmed: Incremental Copilot app feature; complement to Code Scanning/Dependabot, not replacement.

Reporting instructions:

  • Official changelog primary is sufficient for this brief
  • Do not overclaim AppSec replacement
  • Available to Free/Pro/Business/Enterprise during preview

Headline suggestions (TR):

  1. GitHub Copilot uygulamasında /security-review public preview’da
  2. Uçuş halindeki kod için AI güvenlik taraması Copilot’a geldi
  3. CLI’dan masaüstüne: Copilot’ta yüksek güvenli açık bulguları

Mandatory points:

  • /security-review public preview in Copilot app (July 14)
  • Scans in-flight/local changes; severity/confidence scoring
  • Complements Code Scanning / Dependabot / secret scanning — not a replacement