Skip to main content

Fixing code quality findings on a pull request

Keep quality issues out of your default branch by applying autofixes, delegating remediation work to Copilot, or dismissing irrelevant findings.

Wer kann dieses Feature verwenden?

Benutzer*innen mit Schreibzugriff

GitHub Team oder GitHub Enterprise Cloud

Tipp

If you're new to Code Quality, see Preventing code quality issues from reaching your default branch for a guided walkthrough of how Code Quality works on pull requests.

How Code Quality works on pull requests

When you open a pull request, Code Quality runs two types of analysis and posts findings as comments on the pull request.

  1. github-code-quality[bot] findings: Code Quality uses CodeQL to perform a rule-based scan of your changes. These findings are posted as comments by github-code-quality[bot] and include a suggested autofix. Findings are labeled by severity (Error, Warning, Note), and administrators can set quality gates to block merges based on the severity of these findings.

  2. Copilot findings: If your organization has Copilot licenses and AI features are enabled for your enterprise, Code Quality uses Copilot Codeüberprüfung to identify quality issues that rules-based analysis may not detect. These findings are posted as comments by Copilot, and include a suggested autofix. See Informationen zur GitHub Copilot Code-Review.

Resolving a finding

  1. On GitHub, navigate to your open pull request.
  2. On the Files Changed tab, scroll to a comment left by github-code-quality[bot] or Copilot.
  3. Carefully review the comment and the suggested autofix for logic, security, and style.
  4. If you agree with the suggestion and you want to apply the fix, click Commit suggestion, or Add suggestion to batch.
  5. Alternatively, if the finding isn't relevant or actionable, you can dismiss the finding. For example, you might dismiss a finding that is in legacy code no longer maintained, is a known exception to your team's coding standards, or is a false positive that doesn't pose a real quality risk.
    • For comments left by github-code-quality[bot], click Dismiss finding.
    • For comments left by Copilot, click Resolve.

Delegating remediation work to Copilot

Alternativ, wenn Sie über eine Copilot Lizenz verfügen, können Sie die Remediierungsarbeit auch Copilot-Cloud-Agent delegieren. Kommentieren Sie die Pullanforderung und erwähnen Sie @Copilot und bitten Sie Copilot, die erkannten Probleme zu beheben.

Screenshot eines PR-Kommentars, der den Copilot-Cloud-Agent aufgerufen hat.

Copilot antwortet mit einem Augen-Emoji (👀) auf Ihren Kommentar, startet eine neue Agent-Sitzung und öffnet eine Pull-Anforderung mit den erforderlichen Fixes.

Sie können die Arbeit von Copilot-Cloud-Agent nachverfolgen.

Zum Aufrufen von Copilot benötigen Sie eine Copilot-Cloud-Agent-Lizenz.
Registrieren für Copilot

Next steps