Tip
If you're new to Code Quality, see Preventing code quality issues from reaching your default branch for a guided walkthrough of how Code Quality works on pull requests.
How Code Quality works on pull requests
When you open a pull request, Code Quality runs two types of analysis and posts findings as comments on the pull request.
-
github-code-quality[bot]findings: Code Quality uses CodeQL to perform a rule-based scan of your changes. These findings are posted as comments bygithub-code-quality[bot]and include a suggested autofix. Findings are labeled by severity (Error, Warning, Note), and administrators can set quality gates to block merges based on the severity of these findings. -
Copilot findings: If your organization has Copilot licenses and AI features are enabled for your enterprise, Code Quality uses Copilot code review to identify quality issues that rules-based analysis may not detect. These findings are posted as comments by Copilot, and include a suggested autofix. See About GitHub Copilot code review.
Resolving a finding
- On GitHub, navigate to your open pull request.
- On the Files Changed tab, scroll to a comment left by
github-code-quality[bot]or Copilot. - Carefully review the comment and the suggested autofix for logic, security, and style.
- If you agree with the suggestion and you want to apply the fix, click Commit suggestion, or Add suggestion to batch.
- Alternatively, if the finding isn't relevant or actionable, you can dismiss the finding. For example, you might dismiss a finding that is in legacy code no longer maintained, is a known exception to your team's coding standards, or is a false positive that doesn't pose a real quality risk.
- For comments left by
github-code-quality[bot], click Dismiss finding. - For comments left by Copilot, click Resolve.
- For comments left by
Delegating remediation work to Copilot
If you have a Copilot license, you can delegate the remediation work to Copilot cloud agent. Comment on the pull request mentioning @Copilot and request that Copilot fix the detected issues.

Copilot responds with an eyes emoji (👀) to your comment, starts a new agent session, and opens a pull request with the necessary fixes.
You can track Copilot cloud agent's work:
- In the pull request, the summary is updated as work progresses.
- Using the agents page or session logs, see Managing agent sessions.
You need a Copilot license to invoke Copilot cloud agent.
Sign up for Copilot