Devops iconDevopsSep 28, 2026 ~5 min source read

GitHub’s agentic autofix now stores repository fix patterns in Copilot Memory

Autofix checks Copilot Memory before acting, saves validated fix patterns for reuse across alerts and Copilot features, and automatically expires unused repository facts after 28 days.

GitHub’s Security Autofix Agent Now Remembers What It Fixed

Share this story

Send the public story page.

Useful takeaways from this story.

Agentic autofix consults Copilot Memory before generating a security fix and saves validated fix patterns for later reuse across alerts, code review, and the Copilot cloud agent.

Memory is on by default for individual plans but requires an administrator to enable it for organization or enterprise plans, so activation is an administrative decision.

# What changed GitHub's agentic autofix now integrates with Copilot Memory for customers who have Memory enabled. Before making a fix, the autofix agent checks repository-specific memories for relevant context. After creating a fix, the agent saves the fix pattern as a repository memory so the knowledge can be reused later across security alerts, Copilot code review, and the Copilot cloud agent.

# together Agentic autofix (public preview since July 10) is assigned a code-scanning alert and performs an exploratory workflow: it reads relevant files, proposes a fix, reruns CodeQL to confirm the alert is gone, retries if needed, and opens a draft pull request explaining the change. With Memory integrated, that workflow first consults repository facts that contain coding conventions, architecture notes, build commands, and other repository-specific items.

Copilot Memory stores two kinds of information: repository facts and user preferences. Repository facts are stored with citations pointing to the code that supports them. Copilot validates those citations against the current branch before using the fact. If a fact goes unused for 28 days it is deleted automatically.

# Licenses, activation, and cost implications

# Why this matters operationally

Mitch Ashley of The Futurum Group commented that tying fix patterns to citations that expire once code changes helps the agent show its work and improves trust in agent memory.

# Questions teams should ask now

  • When is a fix pattern saved? Before human approval or after a PR is approved? That timing affects how quickly a weak pattern could propagate.
  • Who in the organization should enable Memory and under what policy guardrails? Security and platform teams should decide together.
  • What are the cost implications? More successful autofix runs can increase AI credit and Actions usage.
  • How will the 28-day expiry affect rare bug classes that might not recur within that window?

# Practical next steps for DevOps and security teams Evaluate Memory policies and administrative controls in your org. Test autofix workflows in preview on noncritical repositories to observe when patterns are banked and how they behave in code review. Track AI credit and Actions usage to understand cost changes as autofix adoption grows.

# Bottom line Copilot Memory gives agentic autofix a way to retain repository-specific security fixes and share those lessons across GitHub's tooling, subject to validation and a 28-day expiry. That can move security work earlier in development, but organizations must decide whether and how to enable Memory, monitor costs, and confirm when fix patterns are recorded.

More context around this story.

JFrog Moves to Secure Agentic Engineering Workflows
Devops iconDevopsSep 2, 2026

JFrog Moves to Secure Agentic Engineering Workflows

JFrog today at its swampUP 2026 conference added a zero touch remediation capability that ensures the most secure version of a binary is provided even when application developers request a version that has known vulnerabilities. Additionally, JFrog is adding tools and capabilities to secure artificial intelligence (AI)

Loading more related stories...

Keep reading in the app

Open the app view to save this story, compare related coverage, and continue from the same source.

Open in app