Skip to content

Commit 851cc68

Browse files
AlonaHlobinaCopilotCopilot
authored
document AI Scan coverage status (#63597)
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com> Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>
1 parent 1f69c85 commit 851cc68

4 files changed

Lines changed: 12 additions & 0 deletions

File tree

‎content/code-security/concepts/code-scanning/ai-powered-security-detections.md‎

Lines changed: 2 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -77,4 +77,6 @@ You do not need to select a model to enable AI Scan.
7777
* **Organization**: The **AI Scan** setting under "Code scanning" enables AI Scan for eligible repositories in the organization where {% data variables.product.prodname_code_scanning %} is enabled. See [AUTOTITLE](/code-security/how-tos/secure-at-scale/configure-organization-security/establish-complete-coverage/configure-global-settings#enabling-ai-scan).
7878
* **Repository**: For an organization-owned repository, the **AI Scan for pull requests** toggle under "Code scanning" lets repository administrators opt out when AI Scan is enabled for the organization. For an eligible public repository owned by a personal account, the toggle enables or disables AI Scan directly.
7979

80+
Organization owners and security managers can review the effective enablement status of AI Scan for pull requests in the "Coverage" view of security overview. See [AUTOTITLE](/code-security/how-tos/view-and-interpret-data/analyze-organization-data/assessing-adoption-code-security).
81+
8082
You can use the REST API to manage the organization or repository `ai-scan` setting. See [AUTOTITLE](/rest/code-scanning/code-scanning#get-the-ai-scan-setting-for-an-organization).

‎content/code-security/how-tos/view-and-interpret-data/analyze-organization-data/export-data.md‎

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -19,6 +19,10 @@ category:
1919

2020
The CSV file you download will contain data corresponding to the filters you have applied to security overview. For example, if you add the filter `dependabot-alerts:enabled`, your file will only contain data for repositories that have enabled {% data variables.product.prodname_dependabot_alerts %}.
2121

22+
{% ifversion ai-powered-security-detections %}
23+
CSV files exported from the "Coverage" view include a `Code Scanning AI Scan for pull requests` column. The value for each repository is `enabled` or `not-enabled`.
24+
{% endif %}
25+
2226
> [!NOTE]
2327
> In the "Teams" column of the CSV file, each repository will list a maximum of 20 teams with write access to that repository. If more than 20 teams have write access to a repository, the data will be truncated.
2428

‎content/code-security/reference/security-at-scale/overview-dashboard-filters.md‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -117,6 +117,9 @@ You can limit the data to repositories owned by a single organization in your en
117117
| Qualifier | Description |
118118
| -------- | -------- |
119119
| `code-scanning-default-setup`| Display data for repositories where {% data variables.product.prodname_code_scanning %} is enabled or not enabled using {% data variables.product.prodname_codeql %} default setup. |
120+
| {% ifversion ai-powered-security-detections %} |
121+
| `code-scanning-ai-scan-pr-scan` | Display data for repositories where AI Scan for pull requests is effectively enabled or not enabled. Use `code-scanning-ai-scan-pr-scan:enabled` to display enabled repositories, or `code-scanning-ai-scan-pr-scan:not-enabled` to display repositories where the feature is not enabled. |
122+
| {% endif %} |
120123
| `code-scanning-pull-request-alerts`| Display data for repositories where {% data variables.product.prodname_code_scanning %} is enabled or not enabled to run on pull requests. |
121124
| `dependabot-security-updates` | Display data for repositories where {% data variables.product.prodname_dependabot_security_updates %} is enabled or not enabled. |
122125
| `secret-scanning-push-protection` | Display data for repositories where push protection for {% data variables.product.prodname_secret_scanning %} is enabled or not enabled. |

‎data/reusables/code-scanning/using-security-overview-coverage.md‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,7 @@
11
1. Use options in the page summary to filter results to show the repositories you want to assess. The list of repositories and metrics displayed on the page automatically update to match your current selection. For more information on filtering, see [AUTOTITLE](/code-security/how-tos/manage-security-alerts/remediate-alerts-at-scale/filtering-alerts-in-security-overview).
2+
{% ifversion ai-powered-security-detections %}
3+
For **AI Scan for pull requests**, the summary shows the number of repositories where the feature is enabled or not enabled, and the repository list shows each repository's status. An `enabled` status reflects effective enablement after enterprise policy, organization configuration, prerequisites, and any repository opt-out are applied. A `not enabled` status can include repositories that are ineligible for AI Scan, and security overview does not distinguish the reason why the feature is not enabled.
4+
{% endif %}
25
* Use the **Teams** dropdown to show information only for the repositories owned by one or more teams. For more information, see [AUTOTITLE](/organizations/managing-user-access-to-your-organizations-repositories/managing-repository-roles/managing-team-access-to-an-organization-repository).
36
* Click **NUMBER enabled** or **NUMBER not enabled** in the header for any feature to show only the repositories with that feature enabled or not enabled.
47
* At the top of the list of repositories, click **NUMBER Archived** to show only repositories that are archived.

0 commit comments

Comments
 (0)