GitHub Copilot: Per-User AI Credits Visibility + AI Security Detections on Pull Requests
What's new
- AI credits per billing cycle (July 20): Copilot Business/Enterprise users can see AI credits consumed per current cycle even without a set budget — greater cost transparency
- AI security detections on PR (July 14, public preview): code scanning displays AI-powered security findings directly on pull requests for languages/frameworks outside CodeQL coverage; findings labeled 'AI', no Copilot license required to view
- Secret scanning enhancements (July 15): Resend and APIclub partners, VolcEngine push blocking,
secret_categoryfield in webhooks - GitHub Code Quality GA (July 20): moves from preview to a paid product ($10/active committer/month) with org-wide dashboards and quality scoring
Why it matters
AI security detections on PRs is a significant shift: AI security findings appear in the PR workflow without CodeQL setup. Credits visibility addresses growing CFO concerns about AI token costs. GitHub Code Quality GA is a new paid product — organizations will need to actively evaluate it.
How to try it
AI security detections: available in public preview for repositories with code scanning enabled. AI credits: visible in Billing & Usage section of Copilot account.
Open original source
GitHub