Skip to content

Commit 396f518

Browse files
corycalahanCopilotlecoursenjonjanegoCopilot
authored
clarify security campaign filters for agentic autofix (#63397)
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com> Co-authored-by: Laura Coursen <lecoursen@github.com> Co-authored-by: Jon Janego <jonjanego@github.com> Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com> Co-authored-by: jonjanego <1334913+jonjanego@users.noreply.github.com>
1 parent a3acef5 commit 396f518

2 files changed

Lines changed: 14 additions & 6 deletions

File tree

‎content/code-security/how-tos/manage-security-alerts/remediate-alerts-at-scale/creating-managing-security-campaigns.md‎

Lines changed: 10 additions & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -25,7 +25,7 @@ Security campaigns are created and managed from the **{% data variables.product.
2525

2626
You choose the alerts that you want to include in the campaign by using either:
2727

28-
* **Campaign templates**: Campaign templates contain filters for the most common alert selections. {% ifversion security-campaigns-autofix %}For code campaigns, they also all include the requirement that {% data variables.copilot.copilot_autofix %} is supported for all the alert types included (that is, `autofix:supported`).{% endif %}
28+
* **Campaign templates**: Campaign templates contain filters for the most common alert selections. {% ifversion security-campaigns-autofix %}When agentic autofix is disabled, they also use `autofix:supported` to include only alerts for rules supported by {% data variables.copilot.copilot_autofix %}.{% endif %}
2929
* **Custom filters**: Creating a campaign using custom filters lets you define your own criteria for selecting alerts for the campaign, and lets you tailor your campaign to your organization's specific needs.
3030

3131
{% data reusables.code-scanning.campaigns-api %}
@@ -74,7 +74,11 @@ All the template filters use `is:open` to include only alerts that need to be re
7474
Additional default filters for {% data variables.product.prodname_code_scanning %} alerts:
7575

7676
* `autofilter:true` includes only alerts that appear to be in application code. {% ifversion security-campaigns-autofix %}
77-
* `autofix:supported` includes only alerts that are for rules that are supported for {% data variables.copilot.copilot_autofix %}.{% endif %}
77+
78+
> [!NOTE]
79+
> When agentic autofix is enabled for your organization or enterprise, the `autofix` filter is unavailable, and adding `autofix:supported` does not change the results. For alerts in repositories where {% data variables.copilot.copilot_cloud_agent %} and {% data variables.copilot.copilot_autofix_short %} are available, you can use **Assign to {% data variables.product.prodname_copilot_short %}** for any {% data variables.product.prodname_code_scanning %} alert in a campaign.
80+
81+
{% endif %}
7882

7983
For more information about filtering alerts, see [AUTOTITLE](/code-security/tutorials/secure-your-organization/best-practice-fix-alerts-at-scale#2-select-alerts-for-your-campaign) and [AUTOTITLE](/code-security/how-tos/manage-security-alerts/remediate-alerts-at-scale/filtering-alerts-in-security-overview).
8084

@@ -84,11 +88,11 @@ For more information about filtering alerts, see [AUTOTITLE](/code-security/tuto
8488

8589
{% endif %}
8690

87-
In addition to the core filters, you will usually want to add a filter to limit results to a specific rule name, severity, or tag.
91+
Use `autofilter:true` with `rule:`, `tag:`, or `severity:` to scope your campaign.
8892

89-
* `is:open autofilter:true {% ifversion security-campaigns-autofix %}autofix:supported {% endif %}rule:java/log-injection` to show only alerts for log injection in Java code. See [AUTOTITLE](/code-security/reference/code-scanning/codeql/codeql-queries).
90-
* `is:open autofilter:true {% ifversion security-campaigns-autofix %}autofix:supported {% endif %}tag:external/cwe/cwe-117` to show only alerts for "CWE 117: Improper Output Neutralization for Logs". This includes log injection in Java and other languages.
91-
* `is:open autofilter:true {% ifversion security-campaigns-autofix %}autofix:supported {% endif %}severity:critical` to show only alerts with a security severity of critical.
93+
* `is:open autofilter:true rule:java/log-injection` to show only alerts for log injection in Java code. See [AUTOTITLE](/code-security/reference/code-scanning/codeql/codeql-queries).
94+
* `is:open autofilter:true tag:external/cwe/cwe-117` to show only alerts for "CWE 117: Improper Output Neutralization for Logs". This includes log injection in Java and other languages.
95+
* `is:open autofilter:true severity:critical` to show only alerts with a security severity of critical.
9296

9397
{% ifversion security-campaigns-secrets %}
9498

‎content/code-security/reference/security-at-scale/overview-dashboard-filters.md‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -227,6 +227,10 @@ You can click any result to see full details of the relevant query and the line
227227

228228
| Qualifier | Description |
229229
| -------- | -------- |
230+
|`autofilter`|Display only alerts that appear to be in application code (`autofilter:true`).|
231+
|{% ifversion code-scanning-autofix %}|
232+
|`autofix`|Display only alerts for rules supported by {% data variables.copilot.copilot_autofix %} (`autofix:supported`). When agentic autofix is enabled for your organization or enterprise, this filter is unavailable and does not affect results.|
233+
|{% endif %}|
230234
|`is`|Display {% data variables.product.prodname_code_scanning %} alerts that are open (`open`) or closed (`closed`).|
231235
|`resolution`| Display {% data variables.product.prodname_code_scanning %} alerts closed as "false positive" (`false-positive`), "fixed" (`fixed`), "used in tests" (`used-in-tests`), or "won't fix" (`wont-fix`).|
232236
|`rule`|Display {% data variables.product.prodname_code_scanning %} alerts identified by the specified rule.|

0 commit comments

Comments
 (0)