You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 396f518
Browse filesBrowse the repository at this point in the historyBrowse files
authored
clarify security campaign filters for agentic autofix (#63397)
Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
Co-authored-by: Laura Coursen <lecoursen@github.com>
Co-authored-by: Jon Janego <jonjanego@github.com>
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: jonjanego <1334913+jonjanego@users.noreply.github.com>
Copy file name to clipboardExpand all lines: content/code-security/how-tos/manage-security-alerts/remediate-alerts-at-scale/creating-managing-security-campaigns.md
+10-6Lines changed: 10 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -25,7 +25,7 @@ Security campaigns are created and managed from the **{% data variables.product.
25
25
26
26
You choose the alerts that you want to include in the campaign by using either:
27
27
28
-
***Campaign templates**: Campaign templates contain filters for the most common alert selections. {% ifversion security-campaigns-autofix %}For code campaigns, they also all include the requirement that {% data variables.copilot.copilot_autofix %} is supported for all the alert types included (that is, `autofix:supported`).{% endif %}
28
+
***Campaign templates**: Campaign templates contain filters for the most common alert selections. {% ifversion security-campaigns-autofix %}When agentic autofix is disabled, they also use `autofix:supported` to include only alerts for rules supported by {% data variables.copilot.copilot_autofix %}.{% endif %}
29
29
***Custom filters**: Creating a campaign using custom filters lets you define your own criteria for selecting alerts for the campaign, and lets you tailor your campaign to your organization's specific needs.
30
30
31
31
{% data reusables.code-scanning.campaigns-api %}
@@ -74,7 +74,11 @@ All the template filters use `is:open` to include only alerts that need to be re
74
74
Additional default filters for {% data variables.product.prodname_code_scanning %} alerts:
75
75
76
76
*`autofilter:true` includes only alerts that appear to be in application code. {% ifversion security-campaigns-autofix %}
77
-
*`autofix:supported` includes only alerts that are for rules that are supported for {% data variables.copilot.copilot_autofix %}.{% endif %}
77
+
78
+
> [!NOTE]
79
+
> When agentic autofix is enabled for your organization or enterprise, the `autofix` filter is unavailable, and adding `autofix:supported` does not change the results. For alerts in repositories where {% data variables.copilot.copilot_cloud_agent %} and {% data variables.copilot.copilot_autofix_short %} are available, you can use **Assign to {% data variables.product.prodname_copilot_short %}** for any {% data variables.product.prodname_code_scanning %} alert in a campaign.
80
+
81
+
{% endif %}
78
82
79
83
For more information about filtering alerts, see [AUTOTITLE](/code-security/tutorials/secure-your-organization/best-practice-fix-alerts-at-scale#2-select-alerts-for-your-campaign) and [AUTOTITLE](/code-security/how-tos/manage-security-alerts/remediate-alerts-at-scale/filtering-alerts-in-security-overview).
80
84
@@ -84,11 +88,11 @@ For more information about filtering alerts, see [AUTOTITLE](/code-security/tuto
84
88
85
89
{% endif %}
86
90
87
-
In addition to the core filters, you will usually want to add a filter to limit results to a specific rule name, severity, or tag.
91
+
Use `autofilter:true` with `rule:`, `tag:`, or `severity:`to scope your campaign.
88
92
89
-
*`is:open autofilter:true {% ifversion security-campaigns-autofix %}autofix:supported {% endif %}rule:java/log-injection` to show only alerts for log injection in Java code. See [AUTOTITLE](/code-security/reference/code-scanning/codeql/codeql-queries).
90
-
*`is:open autofilter:true {% ifversion security-campaigns-autofix %}autofix:supported {% endif %}tag:external/cwe/cwe-117` to show only alerts for "CWE 117: Improper Output Neutralization for Logs". This includes log injection in Java and other languages.
91
-
*`is:open autofilter:true {% ifversion security-campaigns-autofix %}autofix:supported {% endif %}severity:critical` to show only alerts with a security severity of critical.
93
+
*`is:open autofilter:true rule:java/log-injection` to show only alerts for log injection in Java code. See [AUTOTITLE](/code-security/reference/code-scanning/codeql/codeql-queries).
94
+
*`is:open autofilter:true tag:external/cwe/cwe-117` to show only alerts for "CWE 117: Improper Output Neutralization for Logs". This includes log injection in Java and other languages.
95
+
*`is:open autofilter:true severity:critical` to show only alerts with a security severity of critical.
Copy file name to clipboardExpand all lines: content/code-security/reference/security-at-scale/overview-dashboard-filters.md
+4Lines changed: 4 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -227,6 +227,10 @@ You can click any result to see full details of the relevant query and the line
227
227
228
228
| Qualifier | Description |
229
229
| -------- | -------- |
230
+
|`autofilter`|Display only alerts that appear to be in application code (`autofilter:true`).|
231
+
|{% ifversion code-scanning-autofix %}|
232
+
|`autofix`|Display only alerts for rules supported by {% data variables.copilot.copilot_autofix %} (`autofix:supported`). When agentic autofix is enabled for your organization or enterprise, this filter is unavailable and does not affect results.|
233
+
|{% endif %}|
230
234
|`is`|Display {% data variables.product.prodname_code_scanning %} alerts that are open (`open`) or closed (`closed`).|
231
235
|`resolution`| Display {% data variables.product.prodname_code_scanning %} alerts closed as "false positive" (`false-positive`), "fixed" (`fixed`), "used in tests" (`used-in-tests`), or "won't fix" (`wont-fix`).|
232
236
|`rule`|Display {% data variables.product.prodname_code_scanning %} alerts identified by the specified rule.|
0 commit comments