# What changed GitHub's agentic autofix now integrates with Copilot Memory for customers who have Memory enabled. Before making a fix, the autofix agent checks repository-specific memories for relevant context. After creating a fix, the agent saves the fix pattern as a repository memory so the knowledge can be reused later across security alerts, Copilot code review, and the Copilot cloud agent.
# together Agentic autofix (public preview since July 10) is assigned a code-scanning alert and performs an exploratory workflow: it reads relevant files, proposes a fix, reruns CodeQL to confirm the alert is gone, retries if needed, and opens a draft pull request explaining the change. With Memory integrated, that workflow first consults repository facts that contain coding conventions, architecture notes, build commands, and other repository-specific items.
Copilot Memory stores two kinds of information: repository facts and user preferences. Repository facts are stored with citations pointing to the code that supports them. Copilot validates those citations against the current branch before using the fact. If a fact goes unused for 28 days it is deleted automatically.
# Licenses, activation, and cost implications
# Why this matters operationally
Mitch Ashley of The Futurum Group commented that tying fix patterns to citations that expire once code changes helps the agent show its work and improves trust in agent memory.
# Questions teams should ask now
- When is a fix pattern saved? Before human approval or after a PR is approved? That timing affects how quickly a weak pattern could propagate.
- Who in the organization should enable Memory and under what policy guardrails? Security and platform teams should decide together.
- What are the cost implications? More successful autofix runs can increase AI credit and Actions usage.
- How will the 28-day expiry affect rare bug classes that might not recur within that window?
# Practical next steps for DevOps and security teams Evaluate Memory policies and administrative controls in your org. Test autofix workflows in preview on noncritical repositories to observe when patterns are banked and how they behave in code review. Track AI credit and Actions usage to understand cost changes as autofix adoption grows.
# Bottom line Copilot Memory gives agentic autofix a way to retain repository-specific security fixes and share those lessons across GitHub's tooling, subject to validation and a 28-day expiry. That can move security work earlier in development, but organizations must decide whether and how to enable Memory, monitor costs, and confirm when fix patterns are recorded.