Value Prop
You can now enable AI security detections independently of CodeQL, so your team gets AI-powered vulnerability detection at the pull request level regardless of which languages your codebase uses. If your projects rely primarily on languages like PHP that aren't covered by CodeQL, you no longer need to configure CodeQL default setup first. This makes it faster and simpler to start catching vulnerabilities with AI on every pull request.
Expected Outcome
By removing the dependency on CodeQL default setup, AI security detections become accessible to a significantly broader set of development teams, including those working in language ecosystems that CodeQL doesn't cover. This simplifies the enablement experience and reduces the friction that prevented many GitHub Advanced Security customers from using the feature. More teams should be able to activate and benefit from AI-powered security coverage with fewer configuration steps.
Value Prop
You can now enable AI security detections independently of CodeQL, so your team gets AI-powered vulnerability detection at the pull request level regardless of which languages your codebase uses. If your projects rely primarily on languages like PHP that aren't covered by CodeQL, you no longer need to configure CodeQL default setup first. This makes it faster and simpler to start catching vulnerabilities with AI on every pull request.
Expected Outcome
By removing the dependency on CodeQL default setup, AI security detections become accessible to a significantly broader set of development teams, including those working in language ecosystems that CodeQL doesn't cover. This simplifies the enablement experience and reduces the friction that prevented many GitHub Advanced Security customers from using the feature. More teams should be able to activate and benefit from AI-powered security coverage with fewer configuration steps.