diff --git a/assets/images/help/code-quality/code-quality-merge-block.png b/assets/images/help/code-quality/code-quality-merge-block.png
index a6b611237ae4..8be88ea57c78 100644
Binary files a/assets/images/help/code-quality/code-quality-merge-block.png and b/assets/images/help/code-quality/code-quality-merge-block.png differ
diff --git a/content/authentication/keeping-your-account-and-data-secure/creating-a-strong-password.md b/content/authentication/keeping-your-account-and-data-secure/creating-a-strong-password.md
index 71ef197f2f14..a287e2b2f7bc 100644
--- a/content/authentication/keeping-your-account-and-data-secure/creating-a-strong-password.md
+++ b/content/authentication/keeping-your-account-and-data-secure/creating-a-strong-password.md
@@ -15,7 +15,7 @@ category:
- Manage access credentials
---
You must choose or generate a password for your account on {% data variables.product.prodname_dotcom %} that is at least:
-* {% ifversion ghes %}Seven{% else %}Eight{% endif %} characters long, if it includes a number and a lowercase letter, or
+* Eight characters long, if it includes a number and a lowercase letter, or
* 15 characters long with any combination of characters
To keep your account secure, we recommend you follow these best practices:
diff --git a/content/billing/concepts/product-billing/github-code-quality.md b/content/billing/concepts/product-billing/github-code-quality.md
index a0c4c1918d1e..3f23980126db 100644
--- a/content/billing/concepts/product-billing/github-code-quality.md
+++ b/content/billing/concepts/product-billing/github-code-quality.md
@@ -1,6 +1,6 @@
---
title: '{% data variables.product.prodname_code_quality %} billing'
-intro: 'Learn how usage of {% data variables.product.prodname_code_quality_short %} is measured.'
+intro: 'In addition to standard {% data variables.product.prodname_actions %} minutes, {% data variables.product.prodname_code_quality %} billing has two parts: a per-committer license and {% data variables.product.prodname_ai_credit_singular %} usage for AI-powered features.'
product: '{% data reusables.gated-features.code-quality-availability %}'
versions:
feature: code-quality
@@ -10,63 +10,24 @@ category:
- Understand product costs
---
-
-
-> [!NOTE]
-> {% data variables.product.prodname_code_quality %} will become generally available on July 20, 2026, at which point usage will incur charges. To avoid being charged, disable {% data variables.product.prodname_code_quality_short %} before that date. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/disable-code-quality).
-
-
-
## How {% data variables.product.prodname_code_quality %} billing is measured
-
-
-{% data variables.product.prodname_code_quality_short %} billing depends on whether the product is generally available or in {% data variables.release-phases.public_preview %}. The feature will move from {% data variables.release-phases.public_preview %} to general availability on July 20, 2026.
-
-### During the {% data variables.release-phases.public_preview %} (until July 20, 2026)
-
-When you scan private repositories during the {% data variables.release-phases.public_preview %}, you **will not be billed** for {% data variables.product.prodname_ai_credits_short %} or active committer usage, but {% data variables.product.prodname_actions %} minutes **will be consumed**.
-
-#### Check {% data variables.product.prodname_actions %} usage during preview
-
-To view consumption of actions by the `{% data variables.code-quality.workflow_name_billing %}` workflow, download a detailed usage report from the "Billing and licensing" tab. See [AUTOTITLE](/billing/how-tos/products/view-productlicense-use).
-
-> [!NOTE]
-> {% data reusables.code-quality.shared-workflow-preview %}
-
-#### View your license estimate during preview
-
-During the {% data variables.release-phases.public_preview %}, you can preview your license cost for {% data variables.product.prodname_code_quality_short %} before charges begin on July 20, 2026. On the licensing page of the "Billing and licensing" tab, the **Consumed licenses** and **Estimated monthly payment** for {% data variables.product.prodname_code_quality_short %} show how many active committers would count toward your license and the estimated cost.
-
-Because active-committer counts use a rolling 90-day window, this estimate can still change before then. When {% data variables.product.prodname_code_quality_short %} becomes generally available, the same calculation applied to your then-current committers determines your bill.
-
-#### What the estimate includes and excludes
-
-The estimate only reflects the per-committer license cost. It does not include the {% data variables.product.prodname_actions %} minutes that {% data variables.product.prodname_codeql %} analysis consumes or usage-based charges for AI-powered capabilities such as {% data variables.copilot.copilot_autofix %}. It also reflects standard list pricing, so it does not account for any discounts that may apply to your account.
-
-
-
-
-### After general availability (from July 20, 2026)
-
-
-
-When {% data variables.product.prodname_code_quality_short %} is generally available, use of the product will incur three types of costs for an organization:
+Use of {% data variables.product.prodname_code_quality_short %} incurs three types of costs for an organization:
* **{% data variables.product.prodname_actions %} minutes** — {% data variables.product.prodname_code_quality_short %} scans run as {% data variables.product.prodname_actions %} workflows and consume {% data variables.product.prodname_actions %} minutes, unless you use self-hosted runners. For more information, see [AUTOTITLE](/billing/concepts/product-billing/github-actions).
-* **{% data variables.product.prodname_ai_credits %}** — {% data variables.product.prodname_code_quality_short %} features that use AI models consume {% data variables.product.prodname_ai_credits_short %}. Each interaction is priced based on the number of tokens consumed, where 1 {% data variables.product.prodname_ai_credit_singular %} = {% data variables.product.prodname_ai_credits_value %}. {% data reusables.code-quality.model-usage %} For more information about how {% data variables.product.prodname_ai_credits_short %} work, see [AUTOTITLE](/copilot/concepts/billing/usage-based-billing-for-organizations-and-enterprises).
-* **Active committers** — Your license usage is calculated based on the number of unique, active committers to repositories with {% data variables.product.prodname_code_quality_short %} enabled. {% data variables.product.prodname_github_app %} bots are ignored. For information about differences between bot and machine accounts, see [AUTOTITLE](/apps/oauth-apps/building-oauth-apps/differences-between-github-apps-and-oauth-apps#machine-vs-bot-accounts).
+* **{% data variables.product.prodname_ai_credits %}** — {% data variables.product.prodname_code_quality_short %} features that use AI models consume {% data variables.product.prodname_ai_credits_short %} from your shared {% data variables.product.prodname_ai_credits_short %} pool, rather than a separate {% data variables.product.prodname_code_quality_short %} allowance. Each interaction is priced based on the number of tokens consumed, where 1 {% data variables.product.prodname_ai_credit_singular %} = {% data variables.product.prodname_ai_credits_value %}. {% data reusables.code-quality.model-usage %} For more information about how {% data variables.product.prodname_ai_credits_short %} work, see [AUTOTITLE](/copilot/concepts/billing/usage-based-billing-for-organizations-and-enterprises).
+* **Active committers** — {% data variables.product.prodname_code_quality %} is a standalone product with its own license: it uses **one {% data variables.product.prodname_code_quality %} license per active committer**, and does not consume {% data variables.product.prodname_GH_advanced_security %} or any other product's licenses. Your license usage is calculated based on the number of unique, active committers to repositories with {% data variables.product.prodname_code_quality_short %} enabled. {% data variables.product.prodname_github_app %} bots are ignored. For information about differences between bot and machine accounts, see [AUTOTITLE](/apps/oauth-apps/building-oauth-apps/differences-between-github-apps-and-oauth-apps#machine-vs-bot-accounts).
-#### Active and unique committers
+### Active and unique committers
-Each **active committer** to at least one repository with {% data variables.product.prodname_code_quality_short %} enabled uses **one license**. A committer is considered active if one of their commits has been pushed to the repository within the last 90 days, regardless of when it was originally authored.
+Each **active committer** to at least one repository with {% data variables.product.prodname_code_quality_short %} enabled uses **one {% data variables.product.prodname_code_quality %} license**. A committer is considered active if one of their commits has been pushed to the repository within the last 90 days, regardless of when it was originally authored.
-* **Active committers** are committers who contributed to at least one repository and have a {% data variables.product.prodname_team %} or {% data variables.product.prodname_enterprise %} license with your organization or enterprise. That is, they are also a member, an enterprise-managed user, an external collaborator, or have a pending invitation to join your organization or enterprise.
+* **Active committers** are committers who contributed to at least one repository and have a {% data variables.product.prodname_team %} or {% data variables.product.prodname_enterprise %} license with your organization or enterprise. This includes members, enterprise-managed users, external collaborators, and people with a pending invitation to join your organization or enterprise.
* **Unique committers** is the number of active committers who contributed only to one repository, or only to repositories in one organization. You can free up this number of licenses by disabling {% data variables.product.prodname_code_quality_short %} for that repository or organization.
Users can contribute to multiple repositories or organizations. Usage is measured across the whole organization or enterprise to ensure that each member uses one license regardless of how many repositories or organizations the user contributes to.
## Further reading
-* [AUTOTITLE](/code-security/tutorials/improve-code-quality/quickstart)
+* [AUTOTITLE](/code-security/tutorials/improve-code-quality/catch-issues-before-merge)
* [AUTOTITLE](/billing/concepts/product-billing/github-actions)
* [AUTOTITLE](/copilot/concepts/billing/usage-based-billing-for-organizations-and-enterprises)
diff --git a/content/code-security/concepts/about-code-quality.md b/content/code-security/concepts/about-code-quality.md
deleted file mode 100644
index 35be6bcc60c2..000000000000
--- a/content/code-security/concepts/about-code-quality.md
+++ /dev/null
@@ -1,150 +0,0 @@
----
-title: About GitHub Code Quality
-shortTitle: GitHub Code Quality
-allowTitleToDifferFromFilename: true
-intro: '{% data variables.product.prodname_code_quality %} flags code quality issues in pull requests and repository scans, applies {% data variables.product.prodname_copilot_short %}-powered autofixes, and enforces standards with rulesets.'
-product: '{% data reusables.gated-features.code-quality-availability %}'
-versions:
- feature: code-quality
-contentType: concepts
-audience:
- - driver
-redirect_from:
- - /code-security/code-quality/concepts/about-code-quality
- - /code-security/code-quality/concepts
- - /code-security/code-quality
-category:
- - Improve code quality
----
-
-{% data reusables.code-quality.code-quality-preview-note %}
-
-## Overview
-
-{% data variables.product.prodname_code_quality %} helps you ensure your codebase is reliable, maintainable, and efficient. Whether you're building a new feature, reducing technical debt, or reporting on repository health, {% data variables.product.prodname_code_quality_short %} provides actionable insights and automated fixes so you can improve and maintain the code health of your repository efficiently.
-
-## Key features and benefits
-
-With {% data variables.product.prodname_code_quality_short %}, you can:
-
-* Identify code quality risks and opportunities in **pull requests** and through **repository scans**.
-* Review clear explanations for findings and apply one-click **{% data variables.product.prodname_copilot_short %}-powered autofixes**.
-* Use **repository dashboards** to track reliability and maintainability scores, identify areas needing attention, and prioritize remediation.
-* Monitor **organization dashboards** to understand the code health of your repositories at a glance and determine which repositories to investigate further.
-* Set up **rulesets** for pull requests to enforce code quality standards and block changes that do not meet your criteria. You can also enforce coverage thresholds with rulesets to block pull requests that don't meet a minimum coverage percentage or that cause coverage to drop by more than the allowed amount.
-* Upload **code coverage** reports to see test coverage metrics directly on pull requests, helping reviewers identify untested code.
-* Easily assign remediation work to **{% data variables.copilot.copilot_cloud_agent %}**, if you have a {% data variables.product.prodname_copilot_short %} license.
-
-## Availability and usage costs
-
-{% data variables.product.prodname_code_quality %} is available for organization-owned repositories on {% data variables.product.prodname_team %} and {% data variables.product.prodname_ghe_cloud %} plans.
-
-
-
-{% data variables.product.prodname_code_quality %} is currently in {% data variables.release-phases.public_preview %} and will become generally available on July 20, 2026. During {% data variables.release-phases.public_preview %}, {% data variables.product.prodname_code_quality_short %} scans will consume {% data variables.product.prodname_actions %} minutes but you will not be billed for other usage. From July 20, 2026, usage will incur additional charges. See [AUTOTITLE](/billing/concepts/product-billing/github-code-quality).
-
-If you want to avoid charges, disable {% data variables.product.prodname_code_quality_short %} before July 20, 2026. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/disable-code-quality).
-
-
-
-> [!NOTE]
-> You **don't** need a {% data variables.product.prodname_copilot_short %} or a {% data variables.product.prodname_code_security %} license to use {% data variables.product.prodname_code_quality_short %} or apply {% data variables.product.prodname_copilot_short %}-powered autofixes.
-
-## Supported languages
-
-{% data variables.product.prodname_code_quality_short %} performs rule-based analysis of the following languages using {% data variables.product.prodname_codeql %}:
-
-{% data reusables.code-quality.codeql-supported-languages %}
-
-{% data variables.product.prodname_code_quality_short %} also performs AI-powered analysis with results displayed separately on the "**{% data variables.code-quality.recent_suggestions %}**" repository dashboard. Unlike the rule-based {% data variables.product.prodname_codeql %} analysis that scans the entire codebase and pull requests, this AI-powered analysis only examines files recently pushed to the default branch and may identify issues in languages beyond those listed above. For more information, see [AUTOTITLE](/code-security/code-quality/responsible-use/code-quality).
-
-## Where will findings appear?
-
-Once you enable {% data variables.product.prodname_code_quality_short %} for a repository, you'll see {% data variables.product.prodname_codeql %} scans for:
-
-* Every new pull request opened against the default branch
-* All existing pull requests to the default branch when they are updated, triggering a new run of CI tests
-* The whole codebase on the default branch at the time and date shown on the "{% data variables.code-quality.code_quality_ui %}" settings page
-
-In addition, you'll see an AI-powered analysis of all recent pushes to the default branch.
-
-### Pull request results
-
-When {% data variables.product.prodname_codeql %} finds rule-based problems on pull requests, you'll see comments from the `{% data variables.code-quality.pr_commenter %}`. Where possible, each comment will include a {% data variables.copilot.copilot_autofix_short %} suggestion on how to fix the problem. See [AUTOTITLE](/code-security/code-quality/tutorials/fix-findings-in-prs).
-
-If you have set up code coverage, the `{% data variables.code-quality.pr_commenter %}` also posts a coverage summary showing the aggregate coverage percentage for the PR branch compared to the default branch. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/interpret-results#viewing-code-coverage-on-pull-requests).
-
-### Default branch results
-
-{% data variables.product.prodname_code_quality_short %} findings on the default branch are reported on "{% data variables.code-quality.code_quality_ui %}" pages on the **{% data variables.product.prodname_security_and_quality_tab %}** tab for the repository:
-
-* **{% data variables.code-quality.all_findings %}** shows the results of {% data variables.product.prodname_codeql %} quality analysis. See [AUTOTITLE](/code-security/code-quality/tutorials/improve-your-codebase).
-* **{% data variables.code-quality.recent_suggestions %}** shows the results of AI-powered analysis of the files most recently pushed to the default branch. See [AUTOTITLE](/code-security/code-quality/tutorials/improve-recent-merges).
-
-### Scan information
-
-Each {% data variables.product.prodname_codeql %} analysis will use {% data variables.product.prodname_actions %} minutes and can be seen on the **Actions** tab of the repository as a run of the dynamic "{% data variables.code-quality.workflow_name_actions %}" workflow.
-
-## How enablement works across your enterprise
-
-{% data variables.product.prodname_code_quality_short %} is controlled at three levels, so you can decide how much autonomy to give organizations and repositories:
-
-* **Enterprise:** An enterprise owner must first allow {% data variables.product.prodname_code_quality_short %} for the enterprise. Until they do, organization owners cannot enable it.
-* **Organization:** Organization owners control which repositories have {% data variables.product.prodname_code_quality_short %} enabled or disabled, by granting access to all repositories, a selected list, or repositories that match a filter. They can also enforce these settings so that repository administrators cannot change them.
-* **Repository:** Repository administrators can enable or disable {% data variables.product.prodname_code_quality_short %} for individual repositories, unless organization-level enforcement applies.
-
-When {% data variables.product.prodname_code_quality_short %} is enabled on a repository, {% data variables.product.prodname_codeql %} analysis runs via {% data variables.product.prodname_actions %} and surfaces findings in pull requests and on the default branch. Developers see quality checks and annotations on their pull requests.
-
-## Organization-level repository access
-
-At the organization level, you control {% data variables.product.prodname_code_quality_short %} with a single **Repository access** setting. This setting determines which repositories have {% data variables.product.prodname_code_quality_short %} enabled and which have it disabled: repositories within your selection are enabled, and repositories outside your selection are disabled.
-
-> [!IMPORTANT]
-> Changing the **Repository access** setting can both enable **and** disable {% data variables.product.prodname_code_quality_short %} across many repositories at once. For example, if you enable {% data variables.product.prodname_code_quality_short %} for repositories matching a filter, any repository that does not match the filter is disabled. Before your change is applied, a dialog shows the total number of enabled and disabled repositories, along with the billing impact.
-
-### Repository access options
-
-You can apply one of the following options at a time.
-
-| Option | Behavior |
-| ------ | -------- |
-| **No repositories** | Disables {% data variables.product.prodname_code_quality_short %} for all current and future repositories in the organization. |
-| **Let repositories decide** | The organization neither enables nor disables {% data variables.product.prodname_code_quality_short %}. Repository administrators choose whether to enable it for their own repositories. This option cannot be enforced. |
-| **All repositories** | Enables {% data variables.product.prodname_code_quality_short %} for all current and future repositories. |
-| **Selected repositories** | Enables {% data variables.product.prodname_code_quality_short %} for a specific list of repositories that you choose. Repositories you do not select are disabled, and new repositories are not enabled automatically. Best for pilots or exceptions. |
-| **Matching a filter** | Enables {% data variables.product.prodname_code_quality_short %} for repositories that match a filter you define, now and in the future. Repositories that do not match are disabled. See [Filtering repositories](#filtering-repositories). |
-
-### Filtering repositories
-
-When you choose **Matching a filter**, you create a dynamic filter that automatically enables {% data variables.product.prodname_code_quality_short %} for existing and future repositories that match your criteria. This is useful for ongoing governance at scale.
-
-You can filter on any combination of the following criteria:
-
-* **Visibility:** Whether repositories are public, private, or internal. Useful for broad policies, such as enabling {% data variables.product.prodname_code_quality_short %} for all private repositories.
-* **Fork status:** Whether repositories are forks. Useful when forks should not consume analysis resources.
-* **Custom property:** Whether repositories have a specific custom property value. For example, you could target repositories with a `team:platform` property.
-
-All conditions in a filter are combined with `AND`, so a repository must match every condition to be enabled. You can also exclude repositories that match specific conditions.
-
-### Enforcing access
-
-By default, repository administrators can change {% data variables.product.prodname_code_quality_short %} settings for their own repositories. To prevent this, enable **Enforce access**.
-
-Enforcement locks in both the enabled and disabled states set by your **Repository access** option, so repository administrators cannot override them. This improves consistency across your organization, but reduces flexibility for individual repository administrators.
-
-* Enforcement applies to most **Repository access** options you select, including **No repositories**, which enforces {% data variables.product.prodname_code_quality_short %} as disabled.
-* Enforcement is not available with **Let repositories decide**, which intentionally leaves the choice to repository administrators.
-
-## Planning your rollout
-
-Because enabling {% data variables.product.prodname_code_quality_short %} can affect many repositories at once and each analysis consumes {% data variables.product.prodname_actions %} minutes, plan how you roll it out across your organization:
-
-* **Start with a pilot group.** Enable a small, representative set of repositories first—for example, by selecting them individually or matching a custom property—so you can validate results before expanding.
-* **Check your {% data variables.product.prodname_actions %} capacity.** Confirm your runners can absorb the additional load before you enable {% data variables.product.prodname_code_quality_short %} broadly.
-* **Decide whether to enforce enablement.** Enforcement gives you consistent coverage and prevents repository administrators from opting out, but it removes their flexibility. Leaving enforcement off during a pilot lets teams opt in and out as they learn.
-* **Expand once results are trusted.** After you've confirmed that analysis runs smoothly and developers understand the findings, widen your selection or filter to cover more repositories.
-
-## Next steps
-
-* **For your repository or organization:** Turn on {% data variables.product.prodname_code_quality_short %} to start generating results. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/enable-code-quality).
-* **For your enterprise:** Ensure repositories in your enterprise can enable {% data variables.product.prodname_code_quality_short %}. See [AUTOTITLE](/code-security/how-tos/secure-at-scale/configure-enterprise-security/configure-specific-tools/allow-github-code-quality-in-enterprise).
diff --git a/content/code-security/concepts/code-quality/code-quality.md b/content/code-security/concepts/code-quality/code-quality.md
new file mode 100644
index 000000000000..4493ebe85200
--- /dev/null
+++ b/content/code-security/concepts/code-quality/code-quality.md
@@ -0,0 +1,67 @@
+---
+title: GitHub Code Quality
+shortTitle: GitHub Code Quality
+allowTitleToDifferFromFilename: true
+intro: '{% data variables.product.prodname_code_quality %} catches quality issues before merge, delivers one-click {% data variables.product.prodname_copilot_short %}-powered fixes inline, and checks your code coverage.'
+product: '{% data reusables.gated-features.code-quality-availability %}'
+versions:
+ feature: code-quality
+contentType: concepts
+audience:
+ - driver
+redirect_from:
+ - /code-security/code-quality/concepts/about-code-quality
+ - /code-security/code-quality/concepts
+ - /code-security/code-quality
+ - /code-security/concepts/about-code-quality
+category:
+ - Improve code quality
+---
+
+{% data variables.product.prodname_code_quality %} analyzes your code for quality and coverage issues and delivers {% data variables.product.prodname_copilot_short %}-powered fixes you can apply in one click. It runs in two places:
+
+* **On pull requests**, findings appear as inline comments before code is merged. If you upload a Cobertura XML coverage report, coverage metrics show whether a change maintains or reduces coverage. You can enforce quality and coverage thresholds with rulesets to block pull requests that don't meet your criteria, so new quality debt doesn't accumulate.
+* **On the default branch**, scans identify existing quality debt across your codebase, with autofixes you can apply directly or assign to {% data variables.copilot.copilot_cloud_agent %} to resolve on your behalf.
+
+Detection combines deterministic {% data variables.product.prodname_codeql %} rules for known anti-patterns with AI-powered analysis for issues that fall outside existing rule sets, including languages not yet covered by {% data variables.product.prodname_codeql %} queries.
+
+## Use cases
+
+Here's what {% data variables.product.prodname_code_quality %} looks like in practice.
+
+For developers and teams:
+
+* **A developer opens a pull request** that introduces a reliability or maintainability issue. {% data variables.product.prodname_code_quality_short %} posts a comment explaining the issue and offers a one-click fix before the code is merged. The developer also sees a report of coverage metrics, and can tell at a glance whether the pull request improves or reduces coverage compared to the default branch.
+* **A team adopts AI coding assistants** and needs assurance that generated code meets the same bar as hand-written code. AI-powered analysis catches issues that rule-based queries weren't written for, while {% data variables.product.prodname_codeql %} rules cover well-defined anti-patterns.
+* **A team inherits a large codebase** with years of accumulated quality debt. {% data variables.product.prodname_code_quality_short %} scans the default branch, surfaces findings with autofixes on a dashboard, and the team assigns remediation work to {% data variables.copilot.copilot_cloud_agent %} to open fix pull requests automatically.
+
+For administrators and leads:
+
+* **An engineering lead sets coverage and quality thresholds** using rulesets. Pull requests that don't meet the criteria are blocked from merging, so no new quality or coverage debt accumulates.
+* **An administrator needs visibility across repositories** for audits or compliance reporting. {% data variables.product.prodname_code_quality_short %} reports through the security overview alongside security tools, so they can see quality posture across the organization at a glance, identify which repositories need attention, and track improvement metrics using standard {% data variables.product.github %} audit controls and policies.
+
+## Availability and billing
+
+Usage costs are determined by:
+
+* A per-seat license fee based on active committers.
+* AI-powered detections and {% data variables.product.prodname_copilot_short %}-powered autofixes, which consume {% data variables.product.prodname_ai_credits %} (no {% data variables.product.prodname_copilot_short %} license required).
+* {% data variables.product.prodname_actions %} minutes for deterministic {% data variables.product.prodname_codeql %} scans, if you don't use self-hosted runners.
+
+Optional features, such as delegating code quality remediation work to {% data variables.product.prodname_copilot_short %}, require a {% data variables.product.prodname_copilot_short %} license.
+
+For more information, see [AUTOTITLE](/billing/concepts/product-billing/github-code-quality).
+
+## Supported languages
+
+{% data variables.product.prodname_code_quality_short %} performs rule-based analysis of the following languages using {% data variables.product.prodname_codeql %}:
+
+{% data reusables.code-quality.codeql-supported-languages %}
+
+It also performs AI-powered analysis on pull requests and on your repository's recently changed code, including languages beyond those supported by rule-based queries.
+
+## Next steps
+
+* **For your enterprise:** Ensure repositories in your enterprise can enable {% data variables.product.prodname_code_quality_short %}. See [AUTOTITLE](/code-security/how-tos/secure-at-scale/configure-enterprise-security/configure-specific-tools/allow-github-code-quality-in-enterprise?utm_campaign=code-quality-ga-july-2026&utm_medium=docs&utm_source=docs-cq-intro-enable-cq-enterprise).
+* **For your repository or organization:** Turn on {% data variables.product.prodname_code_quality_short %} to start generating results. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/enable-code-quality?utm_campaign=code-quality-ga-july-2026&utm_medium=docs&utm_source=docs-cq-intro-enable-cq-repo).
+* **On your pull request:** Learn how to fix code quality findings on your pull request. See [AUTOTITLE](/code-security/tutorials/improve-code-quality/catch-issues-before-merge).
diff --git a/content/code-security/concepts/code-quality/enablement-at-scale.md b/content/code-security/concepts/code-quality/enablement-at-scale.md
new file mode 100644
index 000000000000..42539ae29814
--- /dev/null
+++ b/content/code-security/concepts/code-quality/enablement-at-scale.md
@@ -0,0 +1,74 @@
+---
+title: Code Quality enablement across organizations and enterprises
+shortTitle: Enablement at scale
+allowTitleToDifferFromFilename: true
+intro: '{% data variables.product.prodname_code_quality %} can cover one repository or thousands from a single control point, giving every team the same quality baseline and giving you the guardrails to keep it there.'
+versions:
+ feature: code-quality
+contentType: concepts
+product: '{% data reusables.gated-features.code-quality-availability %}'
+audience:
+ - driver
+category:
+ - Improve code quality
+---
+
+## How enablement works across your enterprise
+
+{% data variables.product.prodname_code_quality_short %} is controlled at three levels, so you can decide how much autonomy to give organizations and repositories:
+
+* **Enterprise:** An enterprise owner must first allow {% data variables.product.prodname_code_quality_short %} for the enterprise. Until they do, organization owners cannot enable it.
+* **Organization:** Organization owners control which repositories have {% data variables.product.prodname_code_quality_short %} enabled or disabled, by granting access to all repositories, a selected list, or repositories that match a filter. They can also enforce these settings so that repository administrators cannot change them.
+* **Repository:** Repository administrators can enable or disable {% data variables.product.prodname_code_quality_short %} for individual repositories, unless organization-level enforcement applies.
+
+When {% data variables.product.prodname_code_quality_short %} is enabled on a repository, {% data variables.product.prodname_codeql %} analysis runs via {% data variables.product.prodname_actions %} and surfaces findings in pull requests and on the default branch. Developers see quality checks and annotations on their pull requests.
+
+## Organization-level repository access
+
+At the organization level, you control {% data variables.product.prodname_code_quality_short %} with a single **Repository access** setting. This setting determines which repositories have {% data variables.product.prodname_code_quality_short %} enabled and which have it disabled: repositories within your selection are enabled, and repositories outside your selection are disabled.
+
+> [!IMPORTANT]
+> Changing the **Repository access** setting can both enable **and** disable {% data variables.product.prodname_code_quality_short %} across many repositories at once. For example, if you enable {% data variables.product.prodname_code_quality_short %} for repositories matching a filter, any repository that does not match the filter is disabled. Before your change is applied, a dialog shows the total number of enabled and disabled repositories, along with the billing impact.
+
+### Repository access options
+
+You can apply one of the following options at a time.
+
+| Option | Behavior |
+| ------ | -------- |
+| **No repositories** | Disables {% data variables.product.prodname_code_quality_short %} for all current and future repositories in the organization. |
+| **Let repositories decide** | The organization neither enables nor disables {% data variables.product.prodname_code_quality_short %}. Repository administrators choose whether to enable it for their own repositories. This option cannot be enforced. |
+| **All repositories** | Enables {% data variables.product.prodname_code_quality_short %} for all current and future repositories. |
+| **Selected repositories** | Enables {% data variables.product.prodname_code_quality_short %} for a specific list of repositories that you choose. Repositories you do not select are disabled, and new repositories are not enabled automatically. Best for pilots or exceptions. |
+| **Matching a filter** | Enables {% data variables.product.prodname_code_quality_short %} for repositories that match a filter you define, now and in the future. Repositories that do not match are disabled. See [Filtering repositories](#filtering-repositories). |
+
+### Filtering repositories
+
+When you choose **Matching a filter**, you create a dynamic filter that automatically enables {% data variables.product.prodname_code_quality_short %} for existing and future repositories that match your criteria. This is useful for ongoing governance at scale.
+
+You can filter on any combination of the following criteria:
+
+* **Visibility:** Whether repositories are public, private, or internal. Useful for broad policies, such as enabling {% data variables.product.prodname_code_quality_short %} for all private repositories.
+* **Fork status:** Whether repositories are forks. Useful when forks should not consume analysis resources.
+* **Custom property:** Whether repositories have a specific custom property value. For example, you could target repositories with a `team:platform` property.
+
+All conditions in a filter are combined with `AND`, so a repository must match every condition to be enabled. You can also exclude repositories that match specific conditions.
+
+### Enforcing access
+
+By default, repository administrators can change {% data variables.product.prodname_code_quality_short %} settings for their own repositories. To prevent this, enable **Enforce access**.
+
+Enforcement locks in both the enabled and disabled states set by your **Repository access** option, so repository administrators cannot override them. This improves consistency across your organization, but reduces flexibility for individual repository administrators.
+
+* Enforcement applies to most **Repository access** options you select, including **No repositories**, which enforces {% data variables.product.prodname_code_quality_short %} as disabled.
+* Enforcement is not available with **Let repositories decide**, which intentionally leaves the choice to repository administrators.
+
+## Planning your rollout
+
+Because a single **Repository access** setting change can enable {% data variables.product.prodname_code_quality_short %} across many repositories at once, and each analysis consumes {% data variables.product.prodname_actions %} minutes, it's worth rolling out in phases rather than all at once. As you plan, weigh a few things:
+
+* **Cost and capacity.** Confirm your runners can absorb the additional {% data variables.product.prodname_actions %} load before you enable {% data variables.product.prodname_code_quality_short %} broadly.
+* **How much to enforce.** Enforcement gives you consistent coverage and stops repository administrators opting out, but it removes their flexibility. Leaving it off lets teams opt in on their own timeline.
+* **When to expand.** Start with a small, representative pilot group, confirm that analysis runs smoothly and developers trust the findings, then widen your selection or filter to cover more repositories.
+
+For a step-by-step rollout procedure, including piloting your quality thresholds in evaluate mode before you enforce them, see [AUTOTITLE](/code-security/how-tos/maintain-quality-code/roll-out-at-scale?utm_campaign=code-quality-ga-july-2026&utm_medium=docs&utm_source=docs-enable-at-scale-roll-out-plan).
diff --git a/content/code-security/concepts/code-quality/index.md b/content/code-security/concepts/code-quality/index.md
new file mode 100644
index 000000000000..e3760a936fc2
--- /dev/null
+++ b/content/code-security/concepts/code-quality/index.md
@@ -0,0 +1,11 @@
+---
+title: Concepts for code quality
+shortTitle: Code quality
+intro: Learn core concepts for {% data variables.product.prodname_code_quality %}.
+versions:
+ feature: code-quality
+contentType: concepts
+children:
+ - /code-quality
+ - /enablement-at-scale
+---
diff --git a/content/code-security/concepts/index.md b/content/code-security/concepts/index.md
index 33cfaa1dbc3b..8c5a93544721 100644
--- a/content/code-security/concepts/index.md
+++ b/content/code-security/concepts/index.md
@@ -11,7 +11,7 @@ children:
- /secret-security
- /code-scanning
- supply-chain-security
- - /about-code-quality
+ - /code-quality
- vulnerability-reporting-and-management
- /security-at-scale
---
diff --git a/content/code-security/how-tos/maintain-quality-code/disable-code-quality.md b/content/code-security/how-tos/maintain-quality-code/disable-code-quality.md
index 3e00b7fd1361..1bf3656bba5d 100644
--- a/content/code-security/how-tos/maintain-quality-code/disable-code-quality.md
+++ b/content/code-security/how-tos/maintain-quality-code/disable-code-quality.md
@@ -1,23 +1,18 @@
---
title: Disabling {% data variables.product.prodname_code_quality %}
shortTitle: Disable Code Quality
-intro: Stop {% data variables.product.prodname_code_quality_short %} scans and avoid charges before the feature becomes generally available.
+intro: Stop {% data variables.product.prodname_code_quality_short %} scans on a repository or across your organization, and know what happens to billing and your existing data before you do.
versions:
feature: code-quality
product: '{% data reusables.gated-features.code-quality-availability %}'
permissions: '{% data reusables.permissions.code-quality-repo-enable %}'
+audience:
+ - driver
contentType: how-tos
category:
- Improve code quality
---
-{% data reusables.code-quality.code-quality-preview-note %}
-
-
-
-
-When {% data variables.product.prodname_code_quality_short %} becomes generally available on July 20, 2026, usage will incur charges. If you want to avoid charges, you can disable {% data variables.product.prodname_code_quality_short %} before that date. **Disabling {% data variables.product.prodname_code_quality_short %} stops all future scans and billing.**
-
## Disabling {% data variables.product.prodname_code_quality_short %} for your repository
{% data reusables.repositories.navigate-to-repo %}
@@ -26,4 +21,41 @@ When {% data variables.product.prodname_code_quality_short %} becomes generally
1. Click **Disable**.
1. Click **Save changes**.
-This stops all future {% data variables.product.prodname_code_quality_short %} scans and associated billing for the repository.
+This stops all future {% data variables.product.prodname_code_quality_short %} scans, and the billing they generate, for that repository.
+
+## Disabling {% data variables.product.prodname_code_quality_short %} for an organization
+
+Disabling at the organization level turns {% data variables.product.prodname_code_quality_short %} off across your organization in a single change.
+
+{% data reusables.organizations.navigate-to-org %}
+{% data reusables.organizations.org_settings %}
+1. In the sidebar, under "Security", click **{% data variables.code-quality.code_quality_ui_settings %}**.
+1. Under "Repository access", select **No repositories** from the dropdown menu. This sets your organization's default to off, disabling {% data variables.product.prodname_code_quality_short %} in every repository that follows the organization default, for both current and future repositories.
+1. To also disable {% data variables.product.prodname_code_quality_short %} in repositories where an administrator has deliberately enabled it, and to prevent administrators from re-enabling it, turn on **Enforce access**. Without enforcement, those repositories keep {% data variables.product.prodname_code_quality_short %} enabled.
+1. Unless you select **Let repositories decide**, a "Review enablement and billing changes" dialog appears, showing the total number of affected repositories. Review the details, then click **Confirm**.
+
+For the full list of access options and how enforcement works, see [AUTOTITLE](/code-security/concepts/code-quality/enablement-at-scale#organization-level-repository-access).
+
+## What happens to your existing data
+
+Disabling {% data variables.product.prodname_code_quality_short %}:
+
+* Turns off future scanning. It doesn't remove your repository's code or commit history.
+* Retains your existing {% data variables.product.prodname_code_quality_short %} data. Findings, quality scores, and history from previous scans aren't deleted when you disable {% data variables.product.prodname_code_quality_short %}, so there's no data loss, and this data is available again if you re-enable it.
+
+## When billing stops
+
+Disabling stops new scans right away, so no further {% data variables.product.prodname_actions %} minutes or {% data variables.product.prodname_ai_credits_short %} are consumed.
+
+Usage you've already accrued this cycle still bills as normal. All metered usage adds up over the course of the month and bills on your next billing cycle date, so your next bill will show the {% data variables.product.prodname_ai_credits_short %} usage and licenses consumed before you disabled the feature. You won't see new charges accrue after the disable date.
+
+## Confirming {% data variables.product.prodname_code_quality_short %} is off
+
+What confirms the change depends on the level you disabled it at.
+
+**At the organization level**, open the organization's "{% data variables.code-quality.code_quality_ui %}" settings page and check that **Repository access** shows your selection (for example, **No repositories**) and that **Enforce access** is on if you enforced it. The organization-level {% data variables.product.prodname_code_quality_short %} dashboard also stops showing data for the affected repositories. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/explore-code-quality).
+
+**At the repository level**, the repository's "{% data variables.code-quality.code_quality_ui %}" settings page shows that {% data variables.product.prodname_code_quality_short %} analysis is disabled. If organization or enterprise enforcement applies, the page also shows a message that a policy prevents changing the {% data variables.product.prodname_code_quality_short %} setting. No new {% data variables.product.prodname_code_quality_short %} runs start on later pull requests or pushes; on the **Actions** tab, these runs are labeled by trigger, for example "{% data variables.product.prodname_code_quality_short %}: push on main".
+
+> [!NOTE]
+> These runs use the workflow name {% data variables.product.prodname_codeql %}, the same name {% data variables.product.prodname_code_scanning %} uses, so you can't reliably tell {% data variables.product.prodname_code_quality_short %} and {% data variables.product.prodname_code_scanning %} runs apart by workflow name. Identify {% data variables.product.prodname_code_quality_short %} runs by their {% data variables.product.prodname_actions %} label instead, for example "{% data variables.product.prodname_code_quality_short %}: push on main".
diff --git a/content/code-security/how-tos/maintain-quality-code/enable-code-quality.md b/content/code-security/how-tos/maintain-quality-code/enable-code-quality.md
index f04f0646d54c..8746033893ba 100644
--- a/content/code-security/how-tos/maintain-quality-code/enable-code-quality.md
+++ b/content/code-security/how-tos/maintain-quality-code/enable-code-quality.md
@@ -1,7 +1,7 @@
---
title: Enabling {% data variables.product.prodname_code_quality %}
shortTitle: Enable Code Quality
-intro: Enable {% data variables.product.prodname_code_quality_short %} across your organization's repositories to automatically identify and remediate code quality issues at scale, helping you maintain consistency and reduce operational risk.
+intro: 'Turn on {% data variables.product.prodname_code_quality_short %} to give your teams a consistent quality baseline: automatically catching, fixing, and reporting code quality issues in pull requests and on your default branch.'
versions:
feature: code-quality
product: '{% data reusables.gated-features.code-quality-availability %}'
@@ -15,13 +15,13 @@ category:
- Improve code quality
---
-{% data reusables.code-quality.code-quality-preview-note %}
+You can enable {% data variables.product.prodname_code_quality_short %} for a single repository, or for every repository in an organization at once. Enabling at the organization level gives all your teams a consistent quality baseline with a single change, while enabling per repository lets you target specific projects or roll out gradually.
## Prerequisites
* An enterprise owner must have allowed {% data variables.product.prodname_code_quality_short %} in your enterprise. See [AUTOTITLE](/code-security/code-quality/how-tos/allow-in-enterprise).
* {% data variables.product.prodname_actions %} must be enabled because {% data variables.product.prodname_code_quality_short %} uses actions to run each {% data variables.product.prodname_codeql %} analysis.
-* To get the full benefit of the feature, your repository should include one of the languages supported for quality analysis by {% data variables.product.prodname_codeql %}. See [Supported languages](/code-security/code-quality/concepts/about-code-quality#supported-languages).
+* To get the full benefit of the feature, your repository should include one of the languages supported for quality analysis by {% data variables.product.prodname_codeql %}. See [Supported languages](/code-security/concepts/code-quality/code-quality#supported-languages).
## Enabling {% data variables.product.prodname_code_quality_short %} for your repository
@@ -36,16 +36,13 @@ category:
1. Click **Save changes** to save your configuration for {% data variables.product.prodname_code_quality_short %}.
-> [!TIP]
-> If your organization has configured caching of private registries, these will be available for code quality analysis to use to resolve dependencies. See [AUTOTITLE](/code-security/securing-your-organization/enabling-security-features-in-your-organization/giving-org-access-private-registries#code-quality-access-to-private-registries).
+If your organization has configured caching of private registries, these will be available for code quality analysis to use to resolve dependencies. See [AUTOTITLE](/code-security/securing-your-organization/enabling-security-features-in-your-organization/giving-org-access-private-registries#code-quality-access-to-private-registries).
## Enabling {% data variables.product.prodname_code_quality_short %} for your organization
-{% data reusables.code-quality.code-quality-org-targeting-preview-note %}
-
At the organization level, you control {% data variables.product.prodname_code_quality_short %} with a single **Repository access** setting. This gives you granular options, from enabling every repository to targeting a specific list or a dynamic filter, so you can pilot {% data variables.product.prodname_code_quality_short %} intentionally and roll it out at your own pace. Repositories within your selection are enabled, and repositories outside your selection are disabled.
-For the available access options, and how filtering and enforcement work, see [AUTOTITLE](/code-security/code-quality/concepts/about-code-quality#organization-level-repository-access).
+For the available access options, and how filtering and enforcement work, see [AUTOTITLE](/code-security/concepts/code-quality/enablement-at-scale#organization-level-repository-access).
{% data reusables.organizations.navigate-to-org %}
{% data reusables.organizations.org_settings %}
@@ -58,8 +55,9 @@ For the available access options, and how filtering and enforcement work, see [A
Your changes are saved automatically and begin to propagate immediately. In large organizations, it can take several minutes for the changes to apply across all repositories.
+If you're rolling out the feature across many teams, we recommend you pilot on a small group and tune your quality thresholds before you enable everywhere. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/roll-out-at-scale).
+
## Next steps
-* **For your repository:** Explore your code quality findings and merge your first fix. See [AUTOTITLE](/code-security/tutorials/improve-code-quality/quickstart).
-* **Add code coverage:** Upload test coverage reports to see coverage results directly on pull requests. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/set-up-code-coverage).
-* **For your organization:** Understand the code health of your repositories at a glance. See [AUTOTITLE](/code-security/how-tos/view-and-interpret-data/analyze-organization-data/explore-code-quality).
\ No newline at end of file
+* **Add code coverage:** Upload reported code coverage from your test suite to see coverage results directly on pull requests. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/set-up-code-coverage).
+* **For your organization:** Understand the code health of your repositories at a glance. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/explore-code-quality).
diff --git a/content/code-security/how-tos/view-and-interpret-data/analyze-organization-data/explore-code-quality.md b/content/code-security/how-tos/maintain-quality-code/explore-code-quality.md
similarity index 78%
rename from content/code-security/how-tos/view-and-interpret-data/analyze-organization-data/explore-code-quality.md
rename to content/code-security/how-tos/maintain-quality-code/explore-code-quality.md
index 9d85135722e0..50601523cb99 100644
--- a/content/code-security/how-tos/view-and-interpret-data/analyze-organization-data/explore-code-quality.md
+++ b/content/code-security/how-tos/maintain-quality-code/explore-code-quality.md
@@ -3,28 +3,33 @@ title: Exploring GitHub Code Quality results in your organization
shortTitle: Explore code quality
intro: Understand your organization's code health at a glance with the organization-level dashboard for {% data variables.product.prodname_code_quality_short %}.
product: '{% data reusables.gated-features.code-quality-availability %}'
-permissions: 'Organization members'
+permissions: Organization members
+audience:
+ - driver
contentType: how-tos
versions:
feature: code-quality
category:
- Secure at scale
+redirect_from:
+ - /code-security/how-tos/view-and-interpret-data/analyze-organization-data/explore-code-quality
---
-{% data reusables.code-quality.code-quality-preview-note %}
-
## Prerequisites
-* If your organization belongs to an enterprise, an enterprise owner must enable {% data variables.product.prodname_code_quality_short %} for your organization. See [AUTOTITLE](/code-security/how-tos/secure-at-scale/configure-enterprise-security/configure-specific-tools/allow-github-code-quality-in-enterprise).
-* Your organization must have repositories with {% data variables.product.prodname_code_quality_short %} enabled. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/enable-code-quality).
+* If your organization belongs to an enterprise, an enterprise owner must enable {% data variables.product.prodname_code_quality_short %} for your organization. See [AUTOTITLE](/code-security/how-tos/secure-at-scale/configure-enterprise-security/configure-specific-tools/allow-github-code-quality-in-enterprise?utm_campaign=code-quality-ga-july-2026&utm_medium=docs&utm_source=docs-explore-cq-enterprise-enablement).
+* Your organization must have repositories with {% data variables.product.prodname_code_quality_short %} enabled. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/enable-code-quality?utm_campaign=code-quality-ga-july-2026&utm_medium=docs&utm_source=docs-explore-cq-repo-enablement).
## Viewing code quality insights for your organization
-1. On {% data variables.product.prodname_dotcom %}, navigate to the main page of your organization. For example, from [https://github.com/settings/organizations](https://github.com/settings/organizations?ref_product=github&ref_type=engagement&ref_style=text).
+1. On {% data variables.product.prodname_dotcom %}, navigate to the main page of your organization. For example, from [https://github.com/settings/organizations](https://github.com/settings/organizations?ref_product=github&ref_type=engagement&ref_style=text&utm_campaign=code-quality-ga-july-2026&utm_medium=docs&utm_source=docs-explore-cq-org-settings).
{% data reusables.organizations.security-overview %}
1. In the "Insights" section of the sidebar, click {% octicon "code-square" aria-hidden="true" aria-label="code-square" %} **Code quality**.
-> [!NOTE] The dashboard only displays data for repositories where the viewer can see code quality findings.
+> [!NOTE]
+> What you see on the dashboard depends on your access:
+> * Organization owners see data for **every** repository that has {% data variables.product.prodname_code_quality_short %} enabled.
+> * All other organization members see data only for repositories where they can view {% data variables.product.prodname_code_quality_short %} findings (the repository-level pages), up to a maximum of 3,000 repositories.
## Interpreting the score distribution chart
diff --git a/content/code-security/how-tos/maintain-quality-code/fix-backlog-findings.md b/content/code-security/how-tos/maintain-quality-code/fix-backlog-findings.md
new file mode 100644
index 000000000000..ccf36d0052d1
--- /dev/null
+++ b/content/code-security/how-tos/maintain-quality-code/fix-backlog-findings.md
@@ -0,0 +1,60 @@
+---
+title: Fixing code quality findings in your repository backlog
+shortTitle: Fix backlog findings
+intro: 'Generate autofixes for findings on the default branch of your repository, or dismiss findings that aren''t relevant.'
+versions:
+ feature: code-quality
+product: '{% data reusables.gated-features.code-quality-availability %}'
+permissions: '{% data reusables.permissions.code-quality-see-repo-findings %}'
+contentType: how-tos
+redirect_from:
+ - /code-security/code-quality/how-tos/fix-backlog-findings
+category:
+ - Improve code quality
+---
+
+> [!TIP]
+> If you're new to {% data variables.product.prodname_code_quality_short %}, see [AUTOTITLE](/code-security/tutorials/improve-code-quality/raise-your-quality-rating?utm_campaign=code-quality-ga-july-2026&utm_medium=docs&utm_source=docs-fix-backlog-walkthrough-tip) for a guided walkthrough of reviewing and improving your repository's quality scores.
+
+## How {% data variables.product.prodname_code_quality_short %} works on your default branch
+
+{% data variables.product.prodname_code_quality_short %} scans your default branch and reports findings on "{% data variables.code-quality.code_quality_ui %}" pages on the **{% data variables.product.prodname_security_and_quality_tab %}** tab of your repository. It runs **two types of analysis**.
+
+1. **{% data variables.code-quality.all_findings %}**: {% data variables.product.prodname_code_quality_short %} uses {% data variables.product.prodname_codeql %} to perform a deterministic, rules-based scan of your default branch. Finding are grouped by rule and language, labeled by severity (**Error**, **Warning**, **Note**), and each includes a suggested autofix.
+
+ 1. **{% data variables.code-quality.recent_suggestions %}**: {% data variables.product.prodname_code_quality_short %} uses AI-powered analysis to identify quality issues in the files most recently pushed to your default branch, including issues that rule-based analysis may not detect - such as best practices, naming conventions, or design considerations.
+
+ {% data reusables.code-quality.recent-suggestions-preview-note %}
+
+ For information on resolving {% data variables.code-quality.recent_suggestions %}, see [AUTOTITLE](/code-security/how-tos/maintain-quality-code/fix-findings-in-recent-merges).
+
+## Resolving a standard finding
+
+{% data reusables.code-quality.dashboard-navigation-repo %}
+{% data reusables.code-quality.dashboard-all-findings %}
+1. Use the dashboard filters to focus on the findings most likely to affect your quality scores. For example, to see all "Error"-level findings for "Reliability", set the filter to:
+
+ `is:open category:reliability severity:error`
+1. Findings are grouped by rule. Click a rule name to be taken to a detailed view of all findings for that rule.
+
+ 
+
+1. Click **Show more**, then review the explanation of the rule, what the recommended fix is, supporting code examples and references.
+
+ 
+{% data reusables.code-quality.generate-autofix-from-dashboard %}
+1. When the autofix pull request is ready for review, change its status from "Draft" to "Ready for review", and wait for CI checks to pass before merging.
+1. Alternatively, if a finding isn't relevant or actionable, click **Dismiss**. For example, you might dismiss a finding that is in legacy code no longer maintained, is a known exception to your team's coding standards, or is a false positive that doesn't pose a real quality risk.
+
+To raise a maintainability or reliability score, you must resolve every finding at the highest severity level currently affecting that metric. See [AUTOTITLE](/code-security/reference/code-quality/metrics-and-ratings).
+
+## Verifying that your code quality scores have updated
+
+After your autofix pull requests are merged, return to the "{% data variables.code-quality.all_findings %}" view to confirm that:
+
+* The number of findings has decreased.
+* The maintainability or reliability score has improved, if you resolved all findings at the current minimum severity level for that metric.
+
+## Next steps
+
+* [AUTOTITLE](/code-security/how-tos/maintain-quality-code/fix-findings-in-recent-merges)
diff --git a/content/code-security/how-tos/maintain-quality-code/fix-findings-in-recent-merges.md b/content/code-security/how-tos/maintain-quality-code/fix-findings-in-recent-merges.md
new file mode 100644
index 000000000000..26847a118fa8
--- /dev/null
+++ b/content/code-security/how-tos/maintain-quality-code/fix-findings-in-recent-merges.md
@@ -0,0 +1,71 @@
+---
+title: Fixing code quality findings in recently merged files
+shortTitle: Fix findings in recent merges
+intro: Apply autofixes or delegate remediation work to {% data variables.product.prodname_copilot_short %} for quality issues detected by AI-powered analysis of recently merged code.
+versions:
+ feature: code-quality
+product: '{% data reusables.gated-features.code-quality-availability %}'
+permissions: '{% data reusables.permissions.code-quality-see-repo-findings %}'
+contentType: how-tos
+redirect_from:
+ - /code-security/code-quality/tutorials/improve-active-code
+ - /code-security/code-quality/tutorials/improve-recent-merges
+ - /code-security/tutorials/improve-code-quality/improve-recent-merges
+ - /code-security/how-tos/maintain-quality-code/fix-recent-merge-findings
+category:
+ - Improve code quality
+---
+
+> [!TIP]
+> If you're new to {% data variables.product.prodname_code_quality_short %}, see [AUTOTITLE](/code-security/tutorials/improve-code-quality/raise-your-quality-rating?utm_campaign=code-quality-ga-july-2026&utm_medium=docs&utm_source=docs-fix-recent-merges-walkthrough-tip) for a guided walkthrough of reviewing and improving your repository's quality scores.
+
+## How {% data variables.product.prodname_code_quality_short %} analyzes recently merged files
+
+{% data variables.product.prodname_code_quality_short %} runs an AI-powered scan on recently changed files after code is merged to your default branch. This scan uses a large language model to report up to {% data variables.code-quality.num_ai_findings %} findings per file in up to {% data variables.code-quality.num_ai_findings %} files—across all languages, without being limited to predefined rules.
+
+{% data reusables.code-quality.recent-suggestions-preview-note %}
+
+## Viewing recent suggestions
+
+{% data reusables.code-quality.dashboard-navigation-repo %}
+{% data reusables.code-quality.dashboard-recent-suggestions %}
+
+ On the **{% data variables.code-quality.recent_suggestions %}** page, each file is listed with the number of quality problems identified and when the file was pushed to the default branch. Click a file name to view the quality problems and their suggested fixes.
+
+ 
+
+> [!NOTE]
+> This view is empty if the repository is inactive or if LLM analysis could not suggest ways to improve code quality in recent pushes to the default branch.
+
+## Resolving a finding
+
+You can delegate remediation work to {% data variables.product.prodname_copilot_short %} or open a pull request yourself.
+
+### Delegate to {% data variables.product.prodname_copilot_short %}
+
+You need a {% data variables.product.prodname_copilot_short %} license to assign work to {% data variables.copilot.copilot_cloud_agent %}.
+
Sign up for {% data variables.product.prodname_copilot_short %} {% octicon "link-external" height:16 aria-label="link-external" %}
+
+1. Select the file or files you want to include for the fix, then click **Assign to {% data variables.product.prodname_copilot_short %}**.
+1. There is a delay while {% data variables.product.prodname_copilot_short %} sets up the work. When the pull request is open and work is in progress, a banner is displayed with a link to the pull request.
+1. Track {% data variables.product.prodname_copilot_short %}'s work:
+ * In the pull request, the summary is updated as work progresses.
+ * Using the [agents page](https://github.com/copilot/agents?ref_product=copilot&ref_type=engagement&ref_style=text&utm_campaign=code-quality-ga-july-2026&utm_medium=docs&utm_source=docs-fix-findings-merge-agent-page) or session logs. See [AUTOTITLE](/copilot/how-tos/copilot-on-github/use-copilot-agents/manage-and-track-agents).
+
+### Open a pull request
+
+1. Click the file name to view details of the quality problems detected.
+1. Review the problems and suggested fixes.
+1. Expand the drop-down and then click {% octicon "git-pull-request" aria-hidden="true" aria-label="Pull request" %} **Open pull request**.
+
+ 
+
+1. Click **Open pull request** to open a dialog of commit options.
+1. Click **Commit change** to create a pull request with the fixes.
+
+> [!NOTE]
+> When you open a pull request yourself, you can only commit fixes to one file at a time. To fix multiple files at once, you must delegate the work to {% data variables.product.prodname_copilot_short %}.
+
+## Further reading
+
+* [AUTOTITLE](/code-security/how-tos/maintain-quality-code/fix-backlog-findings)
diff --git a/content/code-security/how-tos/maintain-quality-code/fix-findings-on-a-pr.md b/content/code-security/how-tos/maintain-quality-code/fix-findings-on-a-pr.md
new file mode 100644
index 000000000000..37977ea588ce
--- /dev/null
+++ b/content/code-security/how-tos/maintain-quality-code/fix-findings-on-a-pr.md
@@ -0,0 +1,44 @@
+---
+title: Fixing code quality findings on a pull request
+shortTitle: Fix findings on a PR
+intro: Keep quality issues out of your default branch by applying autofixes, delegating remediation work to {% data variables.product.prodname_copilot_short %}, or dismissing irrelevant findings.
+versions:
+ feature: code-quality
+product: '{% data reusables.gated-features.code-quality-availability %}'
+permissions: '{% data reusables.permissions.code-quality-see-repo-findings %}'
+contentType: how-tos
+redirect_from:
+ - /code-security/code-quality/how-tos/fix-pr-findings
+ - /code-security/how-tos/maintain-quality-code/fix-pr-findings
+category:
+ - Improve code quality
+---
+
+> [!TIP]
+> If you're new to {% data variables.product.prodname_code_quality_short %}, see [AUTOTITLE](/code-security/tutorials/improve-code-quality/catch-issues-before-merge?utm_campaign=code-quality-ga-july-2026&utm_medium=docs&utm_source=docs-fix-pr-findings-walkthrough-tip) for a guided walkthrough of how {% data variables.product.prodname_code_quality_short %} works on pull requests.
+
+## How {% data variables.product.prodname_code_quality_short %} works on pull requests
+
+When you open a pull request, {% data variables.product.prodname_code_quality_short %} runs **two types of analysis** and posts findings as comments on the pull request.
+
+1. **`{% data variables.code-quality.pr_commenter %}` findings**: {% data variables.product.prodname_code_quality_short %} uses {% data variables.product.prodname_codeql %} to perform a rule-based scan of your changes. These findings are posted as comments by `{% data variables.code-quality.pr_commenter %}` and include a suggested autofix. Findings are labeled by severity (**Error**, **Warning**, **Note**), and administrators can set quality gates to block merges based on the severity of these findings.
+
+1. **{% data variables.product.prodname_copilot_short %} findings**: If your organization has {% data variables.product.prodname_copilot_short %} licenses and AI features are enabled for your enterprise, {% data variables.product.prodname_code_quality_short %} uses **{% data variables.copilot.copilot_code-review_short %}** to identify quality issues that rules-based analysis may not detect. These findings are posted as comments by **{% data variables.product.prodname_copilot_short %}**, and include a suggested autofix. See [AUTOTITLE](/copilot/concepts/agents/code-review).
+
+## Resolving a finding
+
+1. On {% data variables.product.github %}, navigate to your open pull request.
+1. On the **Files Changed** tab, scroll to a comment left by **`{% data variables.code-quality.pr_commenter %}`** or **{% data variables.product.prodname_copilot_short %}**.
+{% data reusables.code-quality.review-comment-and-autofix %}
+{% data reusables.code-quality.apply-suggestion %}
+1. Alternatively, if the finding isn't relevant or actionable, you can dismiss the finding. For example, you might dismiss a finding that is in legacy code no longer maintained, is a known exception to your team's coding standards, or is a false positive that doesn't pose a real quality risk.
+ * For comments left by `{% data variables.code-quality.pr_commenter %}`, click **Dismiss finding**.
+ * For comments left by {% data variables.product.prodname_copilot_short %}, click **Resolve**.
+
+## Delegating remediation work to {% data variables.product.prodname_copilot_short %}
+
+{% data reusables.code-quality.fix-findings-with-cloud-agent %}
+
+## Next steps
+
+* [AUTOTITLE](/code-security/how-tos/maintain-quality-code/view-coverage-on-prs)
diff --git a/content/code-security/how-tos/maintain-quality-code/index.md b/content/code-security/how-tos/maintain-quality-code/index.md
index 173c5f812ddd..a75127610e42 100644
--- a/content/code-security/how-tos/maintain-quality-code/index.md
+++ b/content/code-security/how-tos/maintain-quality-code/index.md
@@ -9,11 +9,19 @@ contentType: how-tos
children:
- /enable-code-quality
- /disable-code-quality
- - /set-up-code-coverage
- - /interpret-results
+ - /roll-out-at-scale
- /set-pr-thresholds
+ - /set-up-code-coverage
- /restrict-code-coverage
+ - /fix-findings-on-a-pr
- /unblock-your-pr
+ - /view-coverage-on-prs
+ - /fix-backlog-findings
+ - /fix-findings-in-recent-merges
+ - /interpret-results
+ - /explore-code-quality
+ - /view-and-manage-cost
redirect_from:
- /code-security/code-quality/how-tos
---
+
diff --git a/content/code-security/how-tos/maintain-quality-code/interpret-results.md b/content/code-security/how-tos/maintain-quality-code/interpret-results.md
index bf8c63a586b4..a9ed8c032054 100644
--- a/content/code-security/how-tos/maintain-quality-code/interpret-results.md
+++ b/content/code-security/how-tos/maintain-quality-code/interpret-results.md
@@ -2,11 +2,13 @@
title: Interpreting the code quality results for your repository
shortTitle: Interpret results
allowTitleToDifferFromFilename: true
-intro: View {% data variables.product.prodname_code_quality %} findings for your default branch.
+intro: Understand the maintainability and reliability of your codebase so you can prioritize where your teams focus remediation effort.
versions:
feature: code-quality
product: '{% data reusables.gated-features.code-quality-availability %}'
permissions: '{% data reusables.permissions.code-quality-see-repo-findings %}'
+audience:
+ - driver
contentType: how-tos
redirect_from:
- /code-security/code-quality/how-tos/interpret-results
@@ -14,18 +16,16 @@ category:
- Improve code quality
---
-{% data reusables.code-quality.code-quality-preview-note %}
-
## Prerequisites
-* {% data variables.product.prodname_code_quality_short %} is enabled, see [AUTOTITLE](/code-security/code-quality/how-tos/enable-code-quality).
+* {% data variables.product.prodname_code_quality_short %} is enabled, see [AUTOTITLE](/code-security/how-tos/maintain-quality-code/enable-code-quality?utm_campaign=code-quality-ga-july-2026&utm_medium=docs&utm_source=docs-interpret-results-enable-cq).
## Viewing the full backlog of code quality results
{% data reusables.code-quality.dashboard-navigation-repo %}
{% data reusables.code-quality.dashboard-all-findings %}
-Alternatively, if you want to view AI-powered findings for the most recently changed files, see [AUTOTITLE](/code-security/code-quality/tutorials/improve-recent-merges).
+Alternatively, if you want to view AI-powered findings for the most recently changed files, see [AUTOTITLE](/code-security/how-tos/maintain-quality-code/fix-recent-merge-findings).
## Exploring the backlog for your repository
@@ -44,29 +44,17 @@ Explore the results by expanding a rule to list the affected files and clicking

-## Interpreting ratings and metrics
+## Interpreting scores and metrics
Code quality results should always be interpreted in the context of your repository. For example:
-* Small repositories, or repositories with only a small amount of code written in supported languages, tend to have few results and good ratings.
-* Repositories with a lot of generated code may have many maintenance results, lowering the rating for maintainability. This is not a problem if the source code itself is maintainable.
+* Small repositories, or repositories with only a small amount of code written in supported languages, tend to have few results and good scores.
+* Repositories with a lot of generated code may have many maintenance results, lowering the score for maintainability. This is not a problem if the source code itself is maintainable.
* Large repositories with a lot of code in a fully supported language often have many results even if the majority of the code has good maintainability and reliability standards.
-To learn more about the metrics and how the ratings are calculated, see [AUTOTITLE](/code-security/code-quality/reference/metrics-and-ratings).
-
-## Viewing code coverage on pull requests
-
-After code coverage is configured for your repository, the `{% data variables.code-quality.pr_commenter %}` posts a coverage summary comment on each pull request. The comment includes:
-
-* **Branch-vs-default-branch comparison:** The aggregate coverage percentage for the pull request branch and the default branch (for example, "65% on pull request branch, 44% on default branch").
-* **Most impacted files:** The 10 files with the largest coverage changes between the default branch and the pull request branch. This list may include files not directly modified in the pull request. New or modified files are ranked above deleted files. Within each group, files are sorted by the absolute change in line coverage weighted by the number of lines in the file, with coverage magnitude and then filename as tiebreakers.
-* **Per-file breakdown:** An expandable section listing each file with its coverage percentage and delta value. A positive delta means the file gained coverage on this branch. A negative delta indicates coverage decreased, which may signal untested code paths introduced by the change.
-
-Use the coverage summary to identify files with low or declining coverage and prioritize review attention on untested changes.
-
-For more information about how the coverage percentage is calculated, see [AUTOTITLE](/code-security/reference/code-quality/metrics-and-ratings#code-coverage).
+To learn more about the metrics and how the scores are calculated, see [AUTOTITLE](/code-security/reference/code-quality/metrics-and-ratings).
## Next steps
-* Remediate quality findings in your default branch and improve the maintainability and reliability rating for your repository. See [AUTOTITLE](/code-security/code-quality/tutorials/improve-your-codebase).
+* Remediate quality findings in your default branch and improve the maintainability and reliability score for your repository. See [AUTOTITLE](/code-security/tutorials/improve-code-quality/raise-your-quality-rating).
* Stop your repository from accumulating more code quality problems by setting a quality threshold for pull requests using rulesets. See [AUTOTITLE](/code-security/code-quality/how-tos/set-pr-thresholds).
diff --git a/content/code-security/how-tos/maintain-quality-code/restrict-code-coverage.md b/content/code-security/how-tos/maintain-quality-code/restrict-code-coverage.md
index 9af90a811783..32ccb7b3ab22 100644
--- a/content/code-security/how-tos/maintain-quality-code/restrict-code-coverage.md
+++ b/content/code-security/how-tos/maintain-quality-code/restrict-code-coverage.md
@@ -1,7 +1,8 @@
---
-title: Restricting code coverage on pull requests
-shortTitle: Restrict code coverage
-intro: Protect your test coverage by automatically blocking pull requests that fall below the coverage levels your team requires.
+title: Setting code coverage thresholds for pull requests
+shortTitle: Set coverage thresholds
+intro: Protect your code coverage by automatically blocking pull requests that fall below the coverage levels your team requires.
+allowTitleToDifferFromFilename: true
versions:
feature: code-quality
permissions: '{% data reusables.permissions.code-quality-repo-enable %}'
diff --git a/content/code-security/how-tos/maintain-quality-code/roll-out-at-scale.md b/content/code-security/how-tos/maintain-quality-code/roll-out-at-scale.md
new file mode 100644
index 000000000000..26a79aa8154f
--- /dev/null
+++ b/content/code-security/how-tos/maintain-quality-code/roll-out-at-scale.md
@@ -0,0 +1,74 @@
+---
+title: Rolling out {% data variables.product.prodname_code_quality %} at scale
+shortTitle: Roll out at scale
+intro: 'Bring {% data variables.product.prodname_code_quality_short %} to every team with confidence by piloting on a small group first, then expanding once your quality thresholds are tuned.'
+versions:
+ feature: code-quality
+product: '{% data reusables.gated-features.code-quality-availability %}'
+permissions: '{% data reusables.permissions.code-quality-repo-enable %}'
+audience:
+ - driver
+contentType: how-tos
+category:
+ - Improve code quality
+---
+
+Turning {% data variables.product.prodname_code_quality_short %} on everywhere at once means every team starts seeing {% data variables.product.prodname_code_quality_short %} findings on their pull requests on the same day, which can be surprising and disruptive. In this tutorial, you'll learn how to roll it out in phases: introduce findings to a small group first, calibrate your thresholds, and then expand. You'll prove the value before it affects your whole organization.
+
+## Prerequisites
+
+* An enterprise owner has allowed {% data variables.product.prodname_code_quality_short %} in your enterprise. See [AUTOTITLE](/code-security/code-quality/how-tos/allow-in-enterprise?utm_campaign=code-quality-ga-july-2026&utm_medium=docs&utm_source=docs-roll-out-at-scale-enable-cq).
+* You're an organization owner, so you can enable {% data variables.product.prodname_code_quality_short %} and configure rulesets at the organization level.
+
+## Plan your pilot
+
+**Start with a small pilot group** rather than your whole organization. A good pilot group is a single engineering team, or a related set of applications, that's active enough to generate meaningful findings and owned by people who can give you feedback on the results.
+
+To target that group, use your organization's **Repository access** setting for {% data variables.product.prodname_code_quality_short %}. You have two good options for a pilot:
+
+* **Selected repositories:** Pick a fixed list of pilot repositories by hand. Best when your pilot group is small and stable.
+* **Matching a filter:** Enable every repository that matches criteria you define, such as a custom property like `code-quality-enabled: true`. Best when you want the pilot to grow automatically as teams tag more repositories.
+
+Targeting by a custom property, rather than naming repositories one by one, means you can widen the pilot later just by setting the property on more repositories. If you want to use a custom property:
+
+1. Create the custom property. See [AUTOTITLE](/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization).
+1. Enable {% data variables.product.prodname_code_quality_short %} at the organization level, for repositories matching a filter. See [AUTOTITLE](/code-security/concepts/code-quality/enablement-at-scale#organization-level-repository-access).
+
+## Turn on quality rulesets in evaluate mode
+
+**Enable your quality thresholds in evaluate mode first.** In this mode, {% data variables.product.prodname_code_quality_short %} reports which pull requests *would* be blocked, without actually blocking them, so your pilot teams can see the impact before it becomes enforcing.
+
+Set up your thresholds as an organization ruleset scoped to the pilot repositories, and leave it in evaluate mode until you've gathered enough pull request activity to judge the impact, typically **a week or two**. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/set-pr-thresholds).
+
+## Tune your thresholds
+
+**Use the evaluate-mode results to calibrate your thresholds.** Check the **ruleset insights** (the ruleset's history) to see exactly which pull requests would have been blocked and why. If too many pull requests would be blocked, your thresholds may be stricter than your codebase is ready for. If almost none would be blocked, you may want to tighten them. Adjust until the gate reflects the quality bar you actually want to enforce.
+
+## Move to enforce mode
+
+**When the evaluate-mode results look right, switch your ruleset from Evaluate to Active.** The thresholds now start blocking pull requests that don't meet them. Your pilot teams experience the enforced gate, giving you a final check before you widen the rollout.
+
+## Expand across your organization
+
+**Expand the rollout using what you learned from the pilot.** You can widen it in two ways:
+
+* Add repositories to your **Selected repositories** list, or set your custom property on more repositories that match your filter.
+* Once you're confident in your thresholds, switch your **Repository access** setting to **All repositories** to apply {% data variables.product.prodname_code_quality_short %} across your whole organization in a single change.
+
+A few things to know about how organization-level enablement behaves, so you can choose the right approach:
+
+* Your **Repository access** choice applies to **both existing and future repositories**, so repositories created later inherit your choice automatically. This is true for **All repositories**, **Matching a filter**, and **No repositories**.
+* Turn on **Enforce access** for a guaranteed baseline that repository administrators can't override. Leave it off, or choose **Let repositories decide**, to let teams opt in on their own timeline.
+* Enabling {% data variables.product.prodname_code_quality_short %} does **not** automatically turn on **code coverage**. Coverage is opt-in per repository. It starts reporting only after someone adds a workflow that uploads coverage data, so teams can adopt {% data variables.product.prodname_code_quality_short %} first and add coverage later. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/set-up-code-coverage).
+
+For the full list of access options and how enforcement works, see [AUTOTITLE](/code-security/concepts/code-quality/enablement-at-scale#organization-level-repository-access).
+
+### Scale programmatically
+
+For most rollouts, enabling through the UI is the best starting point: it lets you filter and target repositories directly, which is harder to reproduce in a script.
+
+If you need automation around your rollout, you can fetch {% data variables.product.prodname_code_quality_short %} findings through the REST API, which is useful for reporting on progress as you expand. You can also enable {% data variables.product.prodname_code_quality_short %} on repositories through the REST API, so you can script enablement across your organization instead of enabling each repository in the UI. See [AUTOTITLE](/rest/code-quality/code-quality).
+
+## Next steps
+
+* **Assess health across your organization.** See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/explore-code-quality).
diff --git a/content/code-security/how-tos/maintain-quality-code/set-pr-thresholds.md b/content/code-security/how-tos/maintain-quality-code/set-pr-thresholds.md
index 9ebeef9f176c..8998bfb0828d 100644
--- a/content/code-security/how-tos/maintain-quality-code/set-pr-thresholds.md
+++ b/content/code-security/how-tos/maintain-quality-code/set-pr-thresholds.md
@@ -1,11 +1,14 @@
---
title: Setting code quality thresholds for pull requests
-shortTitle: Set PR thresholds
-intro: Create a {% data variables.product.prodname_code_quality_short %} gate for pull requests to increase the quality of code merged into your repository.
+shortTitle: Set quality thresholds
+intro: Enforce your code quality standards automatically by blocking pull requests that fall below the thresholds you set, at the repository or organization level.
+allowTitleToDifferFromFilename: true
versions:
feature: code-quality
product: '{% data reusables.gated-features.code-quality-availability %}'
permissions: '{% data reusables.permissions.code-quality-repo-enable %}'
+audience:
+ - driver
contentType: how-tos
redirect_from:
- /code-security/code-quality/how-tos/set-pr-thresholds
@@ -13,16 +16,19 @@ category:
- Improve code quality
---
-{% data reusables.code-quality.code-quality-preview-note %}
+You can block pull requests that don't meet your code quality standards by adding {% data variables.product.prodname_code_quality_short %} thresholds to a ruleset. If a pull request doesn't meet a threshold, it can't be merged.
-## Introduction
+You can set thresholds for:
-You can block pull requests that don't meet your code quality standards by adding the **Require code quality results** branch rule to a ruleset and specifying the severity level you require. If a pull request doesn't reach this threshold, it can't be merged.
+* **{% data variables.product.prodname_codeql %} findings**, by the lowest severity of results you require to be resolved.
+* **Code coverage**, by the minimum percentage of code that must be covered by tests.
+
+You can enforce these thresholds at the **repository** level, or at the **organization** level to apply the same standard across many repositories at once. Choose the organization level when you want a consistent quality bar across teams, and the repository level when a single project needs its own standard. {% data variables.product.prodname_code_quality_short %} AI detections cannot be set as a threshold.
## Prerequisites
-* {% data variables.product.prodname_code_quality_short %} is enabled. See [AUTOTITLE](/code-security/code-quality/how-tos/enable-code-quality)
-* Code in a supported language. See [Supported languages](/code-security/code-quality/concepts/about-code-quality#supported-languages).
+* {% data variables.product.prodname_code_quality_short %} is enabled. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/enable-code-quality?utm_campaign=code-quality-ga-july-2026&utm_medium=docs&utm_source=docs-set-quality-thresholds-enable-cq)
+* Code in a supported language. See [Supported languages](/code-security/concepts/code-quality/code-quality#supported-languages).
> [!NOTE]
> The threshold will have an impact only if the repository has code in one or more of the supported languages, see [AUTOTITLE](/code-security/code-quality/how-tos/enable-code-quality).
@@ -38,6 +44,8 @@ For more information, see [AUTOTITLE](/code-security/code-quality/reference/code
## Adding or updating a ruleset to include {% data variables.product.prodname_code_quality_short %}
+The following steps create or update a ruleset at the repository level. To enforce the same threshold across multiple repositories at once, create an organization ruleset with the same **Require code quality results** rule instead. See [AUTOTITLE](/organizations/managing-organization-settings/creating-rulesets-for-repositories-in-your-organization).
+
1. Navigate to the "Settings" tab of your repository.
1. In the left sidebar, under "Code and automation", expand {% octicon "repo-push" aria-hidden="true" aria-label="repo-push" %} **Rules**, then click **Rulesets**.
1. If you don't already have a ruleset to protect your default branch, expand **New ruleset** and click **New branch ruleset**. Alternatively, open your existing ruleset for the default branch and move to step 5.
@@ -53,6 +61,10 @@ For more information, see [AUTOTITLE](/code-security/code-quality/reference/code
* Set "All" to block pull requests with **any** unresolved code quality results being merged.
1. When you have finished defining or editing the ruleset, click **Create** or **Save changes**.
+## Setting a code coverage threshold
+
+You can also block pull requests that fall below a code coverage threshold. This uses a separate **Restrict code coverage** rule, not the **Require code quality results** rule used above, and your repository must upload code coverage data first. For the full procedure, see [AUTOTITLE](/code-security/how-tos/maintain-quality-code/restrict-code-coverage).
+
## Next steps
-Learn how {% data variables.product.prodname_code_quality %} works on pull requests to prevent code quality issues from reaching your default branch. See [AUTOTITLE](/code-security/code-quality/tutorials/fix-findings-in-prs).
+Learn how {% data variables.product.prodname_code_quality %} works on pull requests to prevent code quality issues from reaching your default branch. See [AUTOTITLE](/code-security/tutorials/improve-code-quality/catch-issues-before-merge).
diff --git a/content/code-security/how-tos/maintain-quality-code/set-up-code-coverage.md b/content/code-security/how-tos/maintain-quality-code/set-up-code-coverage.md
index 121ea4f890f9..b764100cbf88 100644
--- a/content/code-security/how-tos/maintain-quality-code/set-up-code-coverage.md
+++ b/content/code-security/how-tos/maintain-quality-code/set-up-code-coverage.md
@@ -1,20 +1,20 @@
---
title: Setting up code coverage for your repository
shortTitle: Set up code coverage
-intro: 'Upload test coverage reports to see coverage results directly on pull requests, helping reviewers identify untested code before merging.'
+intro: 'Give your teams visibility into code coverage directly on pull requests, without paying for or maintaining a separate third-party coverage service.'
versions:
feature: code-quality
product: '{% data reusables.gated-features.code-quality-availability %}'
permissions: '{% data reusables.permissions.code-quality-repo-enable %}'
+audience:
+ - driver
contentType: how-tos
layout: inline
category:
- Improve code quality
---
-{% data reusables.code-quality.code-quality-preview-note %}
-
-In the following procedures, you will generate a Cobertura XML coverage report from your test suite, upload it to {% data variables.product.github %}, and view the coverage results on your pull requests.
+Built-in code coverage lets you track how thoroughly your tests exercise your code, without adding a third-party service to your toolchain or budget. In the following procedures, you will generate a Cobertura XML coverage report from your test suite, upload it to {% data variables.product.github %}, and view the coverage results on your pull requests.
## Prerequisites
diff --git a/content/code-security/how-tos/maintain-quality-code/unblock-your-pr.md b/content/code-security/how-tos/maintain-quality-code/unblock-your-pr.md
index 2cfdc6c9ef59..7b2352f53cf2 100644
--- a/content/code-security/how-tos/maintain-quality-code/unblock-your-pr.md
+++ b/content/code-security/how-tos/maintain-quality-code/unblock-your-pr.md
@@ -12,61 +12,30 @@ category:
- Improve code quality
---
-{% data reusables.code-quality.code-quality-preview-note %}
-
## Understanding why your pull request is blocked
-Repository administrators can set quality gates using {% data variables.product.prodname_code_quality %}. When you open a pull request, checks automatically run to evaluate your changes against these standards.
+Repository administrators and organization owners can set quality gates using {% data variables.product.prodname_code_quality %}. When you open a pull request, checks automatically run to evaluate your changes against these standards.
There are two types of blocks:
* **Code quality findings**: your changes introduce issues that fall below the required quality threshold.
* **Coverage threshold**: your changes cause code coverage to fall below a required minimum, or cause coverage to drop by more than a permitted amount relative to the default branch.
-If your pull request introduces code that falls below the required quality threshold, you'll see a merge block banner at the bottom of the pull request in the "Checks" section: "Merging is blocked: Code quality findings were detected."
-
-
-
These checks help maintain a healthy, maintainable codebase and prevent technical debt from accumulating.
-## Viewing scan results and their severity levels
-
-The results of the scan are reported as comments on your pull request, left by the `{% data variables.code-quality.pr_commenter %}`. Each comment corresponds to a specific code quality problem that was detected in your changes.
-
-Comments are labeled by severity (**Error**, **Warning**, **Note**). To learn more about what the severity levels mean, see [Severity levels](/code-security/code-quality/reference/metrics-and-ratings#severity-levels).
-
-## Determining which findings are blocking your pull request
-
-The quality gate set by repository administrators defines the **minimum severity level** that will block merging.
-
-The merge block banner may specify the minimum severity level. All findings at that severity level or higher must be addressed before you can merge your pull request.
+## Resolving a code quality findings block
-
-
-> [!NOTE]
-> If you don't see a severity level defined in the merge block banner, it means that your repository is using the most stringent code quality thresholds, which require **all findings** to be addressed before merging.
-
-## Fixing or dismissing each finding
-
-In order to unblock your pull request, you need to resolve each required finding by deciding whether to **fix** the issue in your code or **dismiss** the comment.
-
-### Leveraging {% data variables.copilot.copilot_autofix_short %} and {% data variables.copilot.copilot_cloud_agent %} to fix findings
-
-#### {% data variables.copilot.copilot_autofix_short %}
-
-{% data reusables.code-quality.fix-findings-with-copilot-autofix %}
-
-#### {% data variables.copilot.copilot_cloud_agent %}
-
-{% data reusables.code-quality.fix-findings-with-cloud-agent %}
+If your pull request introduces code that falls below the required quality threshold, you'll see a merge block banner at the bottom of the pull request in the "Checks" section: "Merging is blocked: Code quality findings were detected."
-### Dismissing the finding
+
-{% data reusables.code-quality.dismiss-irrelevant-findings %}
+The quality gate set by your repository administrator or organization owner defines the **minimum severity level** that will block merging. All findings at that severity level or higher must be fixed or dismissed before you can merge. If the merge block banner does not specify a severity level, your repository requires **all findings** to be addressed.
-## Verifying that you've met the requirements
+To unblock your pull request, you need to fix or dismiss the findings that meet or exceed the blocking severity:
-To see if you've met the code quality requirements, look at the "Checks" section at the bottom of your pull request. The merge block banner should no longer be present, and you should be able to merge your changes as usual.
+1. Review the comments left by the `{% data variables.code-quality.pr_commenter %}` on your pull request. Each comment is labeled by severity (**Error**, **Warning**, **Note**).
+1. Fix or dismiss the relevant findings. For detailed instructions, see [AUTOTITLE](/code-security/how-tos/maintain-quality-code/fix-pr-findings).
+1. Verify the merge block banner is no longer present in the "Checks" section of your pull request.
## Resolving a coverage threshold block
@@ -78,9 +47,9 @@ If your pull request is blocked by a coverage threshold rule, you'll see a merge
To unblock your pull request, you need to add or modify tests so that more of the codebase is executed:
1. Review the coverage summary comment on your pull request to identify which files or areas lack coverage.
-1. Add or update tests to increase execution coverage.
+1. Add or update tests to increase execution coverage. {% data variables.product.prodname_copilot_short %} can help you write and update your tests. See [AUTOTITLE](/copilot/tutorials/copilot-cookbook/testing-code).
1. Push your changes. The coverage check will re-run automatically.
## Next steps
-Reduce technical debt by fixing findings in recently changed files. See [AUTOTITLE](/code-security/code-quality/tutorials/improve-recent-merges).
+* [AUTOTITLE](/code-security/how-tos/maintain-quality-code/fix-backlog-findings)
diff --git a/content/code-security/how-tos/maintain-quality-code/view-and-manage-cost.md b/content/code-security/how-tos/maintain-quality-code/view-and-manage-cost.md
new file mode 100644
index 000000000000..d9d379e1ecb1
--- /dev/null
+++ b/content/code-security/how-tos/maintain-quality-code/view-and-manage-cost.md
@@ -0,0 +1,83 @@
+---
+title: Viewing and managing {% data variables.product.prodname_code_quality %} costs
+shortTitle: View and manage cost
+intro: 'Keep your {% data variables.product.prodname_code_quality_short %} spend predictable by seeing exactly where charges come from and using the levers that bring them down.'
+versions:
+ feature: code-quality
+product: '{% data reusables.gated-features.code-quality-availability %}'
+permissions: '{% data reusables.permissions.enhanced-billing-cloud-all %}'
+audience:
+ - driver
+contentType: how-tos
+category:
+ - Improve code quality
+---
+
+Knowing what {% data variables.product.prodname_code_quality_short %} costs, and which levers you can pull, lets you justify the spend before you roll it out, and keep it predictable afterward. This article covers where charges come from, where to watch your usage, and how to bring costs down.
+
+## How you're charged for {% data variables.product.prodname_code_quality_short %}
+
+{% data variables.product.prodname_code_quality_short %} usage adds up from three types of cost across your organization:
+
+* **License usage**, based on the number of unique, active committers to repositories where {% data variables.product.prodname_code_quality_short %} is enabled.
+* **{% data variables.product.prodname_actions %} minutes**, consumed each time a scan runs (unless you use self-hosted runners).
+* **{% data variables.product.prodname_ai_credits %}**, consumed by {% data variables.product.prodname_code_quality_short %}'s AI features: the fixes it generates for findings, and the AI detections scans if you turn that page on.
+
+For exactly how each cost is measured, see [AUTOTITLE](/billing/concepts/product-billing/github-code-quality?utm_campaign=code-quality-ga-july-2026&utm_medium=docs&utm_source=docs-view-manage-cost-billing).
+
+It's important to understand how {% data variables.product.prodname_code_quality %} uses {% data variables.product.prodname_ai_credits_short %} before you scale:
+
+* {% data variables.product.prodname_code_quality_short %} draws from your **shared {% data variables.product.prodname_ai_credits_short %} pool**, the same pool every AI product (like {% data variables.product.prodname_copilot_short %}) draws from. It isn't a separate {% data variables.product.prodname_code_quality_short %} allowance.
+* This pool is shared at your **billing entity** level. If your organization is billed through an enterprise, {% data variables.product.prodname_code_quality_short %} draws from the enterprise-wide pool rather than an organization-only one.
+* Once the shared pool is exhausted, what happens next depends on how you've configured your policy for additional usage. To avoid unexpected charges, set a budget with a hard stop.
+* Your per-committer license charge is separate and isn't affected by {% data variables.product.prodname_ai_credits_short %} usage.
+
+## Where to see your usage
+
+{% data variables.product.prodname_code_quality_short %} usage appears in the **same billing and usage views as your other products**, not in a separate {% data variables.product.prodname_code_quality_short %} meter. Where you look depends on how granular a breakdown you need:
+
+* **For a repository- or organization-level breakdown, download the billing usage report** from the "Billing and licensing" tab. This is the only place you can attribute {% data variables.product.prodname_code_quality_short %} spend, including {% data variables.product.prodname_actions %} minutes, down to a specific repository or organization. There's no equivalent view in the UI. See [AUTOTITLE](/billing/how-tos/products/view-productlicense-use).
+* **For {% data variables.product.prodname_code_quality_short %}'s {% data variables.product.prodname_ai_credits_short %} usage over time, use the AI usage page** and group it by **Product** using the dropdown at the top right. This separates {% data variables.product.prodname_code_quality_short %} from your other AI products, like {% data variables.product.prodname_copilot_short %}, so you can track its share of the pool. To monitor the pool as a whole instead, see [AUTOTITLE](/copilot/concepts/billing/usage-based-billing-for-organizations-and-enterprises).
+
+## Monitoring your spend
+
+Once {% data variables.product.prodname_code_quality_short %} is running, watch your actual usage over time so costs stay predictable. Track two things:
+
+* Your **{% data variables.product.prodname_actions %} minutes**, which grow with the number of repositories running scans.
+* Your **shared {% data variables.product.prodname_ai_credits_short %} pool**, which {% data variables.product.prodname_code_quality_short %} draws down alongside your other AI products. Watch the pool as a whole to avoid overage, and group the AI usage page by **Product** when you want {% data variables.product.prodname_code_quality_short %}'s share specifically.
+
+## Controlling your costs
+
+You have several levers to keep spend in check. In rough order of impact:
+
+* **Enable selectively.** Turn {% data variables.product.prodname_code_quality_short %} on where it adds value rather than across every repository at once. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/enable-code-quality).
+* **Disable low-value repositories.** Disabling {% data variables.product.prodname_code_quality_short %} on a repository frees the licenses for committers unique to it, and stops its scans and AI usage. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/disable-code-quality).
+* **Set a budget.** A budget for {% data variables.product.prodname_code_quality_short %} stops your spending automatically once you hit your limit, because the hard stop is mandatory (see below).
+* **Keep the AI detections page off.** This page is **off by default** and stays in {% data variables.release-phases.public_preview %}, so it only draws down {% data variables.product.prodname_ai_credits_short %} if you turn it on. Repositories that enabled it during the preview keep it on, so turn it off there if you don't want the usage.
+
+
+
+### Setting a budget
+
+Budgets are your main control for the {% data variables.product.prodname_ai_credits_short %} side of {% data variables.product.prodname_code_quality_short %}, because {% data variables.product.prodname_code_quality_short %} draws from the shared {% data variables.product.prodname_ai_credits_short %} pool.
+
+For {% data variables.product.prodname_code_quality_short %}, a budget is always a hard cap. When you create the budget, **Stop usage when budget limit is reached** is enabled by default and can't be turned off, so usage stops automatically once you exhaust the budget.
+
+When you create a budget, you choose a **Budget type**. Two apply to {% data variables.product.prodname_code_quality_short %}:
+
+* An **{% data variables.product.prodname_ai_credits_short %} budget**, which covers every SKU that consumes {% data variables.product.prodname_ai_credits_short %}, including {% data variables.product.prodname_code_quality_short %}. Use this to cap total AI spend across products.
+* A **SKU-level budget**, scoped to {% data variables.product.prodname_code_quality_short %} alone, so you can limit its spend without affecting your other AI products. This gives you granular, product-specific control, for example to contain spend during a rollout without touching your {% data variables.product.prodname_copilot_short %} budget.
+
+To get started, see [AUTOTITLE](/billing/how-tos/set-up-budgets).
+
+## What you can't control
+
+Be aware of two limits so there are no surprises:
+
+* **You can't pre-estimate spend** before you enable {% data variables.product.prodname_code_quality_short %}. Usage depends on your committers, scan frequency, and findings, so plan to watch actuals after you turn it on rather than forecast them precisely.
+* **You can't turn off the in-pull-request AI features.** {% data variables.product.prodname_code_quality_short %} generates a fix for every detected finding, so {% data variables.product.prodname_ai_credits_short %} usage is inherent to running it. To stop that usage entirely, disable {% data variables.product.prodname_code_quality_short %} on the repository.
+
+## Next steps
+
+* **Roll out across your organization.** See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/roll-out-at-scale).
+* **Assess health across your organization.** See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/explore-code-quality).
diff --git a/content/code-security/how-tos/maintain-quality-code/view-coverage-on-prs.md b/content/code-security/how-tos/maintain-quality-code/view-coverage-on-prs.md
new file mode 100644
index 000000000000..f7e7c8894133
--- /dev/null
+++ b/content/code-security/how-tos/maintain-quality-code/view-coverage-on-prs.md
@@ -0,0 +1,33 @@
+---
+title: Viewing code coverage on pull requests
+shortTitle: View coverage on PRs
+allowTitleToDifferFromFilename: true
+intro: 'Review the coverage summary posted on your pull requests to identify files with low or declining code coverage.'
+versions:
+ feature: code-quality
+product: '{% data reusables.gated-features.code-quality-availability %}'
+permissions: '{% data reusables.permissions.code-quality-see-repo-findings %}'
+contentType: how-tos
+category:
+ - Improve code quality
+---
+
+## Prerequisites
+
+* Code coverage is configured for your repository. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/set-up-code-coverage).
+
+## Reading the coverage summary comment
+
+After code coverage is configured for your repository, the `{% data variables.code-quality.pr_commenter %}` posts a coverage summary comment on each pull request. The comment includes:
+
+* **Branch-vs-default-branch comparison:** The aggregate coverage percentage for the pull request branch and the default branch (for example, "65% on pull request branch, 44% on default branch").
+* **Most impacted files:** The 10 files with the largest coverage changes between the default branch and the pull request branch. This list may include files not directly modified in the pull request. New or modified files are ranked above deleted files. Within each group, files are sorted by the absolute change in line coverage weighted by the number of lines in the file, with coverage magnitude and then filename as tiebreakers.
+* **Per-file breakdown:** An expandable section listing each file with its coverage percentage and delta value. A positive delta means the file gained coverage on this branch. A negative delta indicates coverage decreased, which may signal untested code paths introduced by the change.
+
+Use the coverage summary to identify files with low or declining coverage and prioritize review attention on untested changes.
+
+If you need to extend coverage of your test suite, {% data variables.product.prodname_copilot_short %} can help you write and update your tests. See [AUTOTITLE](/copilot/tutorials/copilot-cookbook/testing-code).
+
+## Next steps
+
+* [AUTOTITLE](/code-security/how-tos/maintain-quality-code/unblock-your-pr)
diff --git a/content/code-security/how-tos/secure-your-supply-chain/establish-provenance-and-integrity/prevent-release-changes.md b/content/code-security/how-tos/secure-your-supply-chain/establish-provenance-and-integrity/prevent-release-changes.md
index 03b85181325a..5dee705027d4 100644
--- a/content/code-security/how-tos/secure-your-supply-chain/establish-provenance-and-integrity/prevent-release-changes.md
+++ b/content/code-security/how-tos/secure-your-supply-chain/establish-provenance-and-integrity/prevent-release-changes.md
@@ -22,6 +22,6 @@ category:
{% data reusables.organizations.navigate-to-org %}
{% data reusables.organizations.org_settings %}
-1. In the "Code, planning, and automation" section of the sidebar, select the {% octicon "repo" aria-hidden="true" %} **Repository** dropdown menu, then click **General**.
+1. {% data reusables.user-settings.code-planning-automation %} select the {% octicon "repo" aria-hidden="true" %} **Repository** dropdown menu, then click **General**.
1. In the "Releases" section of the page, select the **No policy** {% octicon "triangle-down" aria-hidden="true" %} dropdown menu, then click either **All repositories** or **Selected repositories**. Be aware that immutability will only apply to future releases.
1. If you chose **Selected repositories**, to the right of the dropdown menu, click {% octicon "gear" aria-label="Select repositories" %}. Select the repositories you want to include, then click **Select repositories**.
diff --git a/content/code-security/how-tos/view-and-interpret-data/analyze-organization-data/index.md b/content/code-security/how-tos/view-and-interpret-data/analyze-organization-data/index.md
index 19af1ecfae7a..22ad5aea2a63 100644
--- a/content/code-security/how-tos/view-and-interpret-data/analyze-organization-data/index.md
+++ b/content/code-security/how-tos/view-and-interpret-data/analyze-organization-data/index.md
@@ -10,7 +10,6 @@ contentType: how-tos
children:
- /assessing-code-security-risk
- /assessing-adoption-code-security
- - /explore-code-quality
- /find-insecure-repositories
- /export-data
- /viewing-security-insights
diff --git a/content/code-security/index.md b/content/code-security/index.md
index ab70c776e0a9..c360e6c143f2 100644
--- a/content/code-security/index.md
+++ b/content/code-security/index.md
@@ -31,7 +31,7 @@ carousels:
- /code-security/concepts/secret-security/secret-scanning
- /code-security/concepts/code-scanning/code-scanning
- /code-security/tutorials/secure-your-dependencies/dependabot-quickstart
- - /code-security/tutorials/improve-code-quality/quickstart
+ - /code-security/concepts/code-quality/code-quality
- /code-security/tutorials/secure-your-organization/prevent-data-leaks
- /code-security/concepts/supply-chain-security/best-practices-for-maintaining-dependencies
versions:
diff --git a/content/code-security/reference/code-quality/code-coverage.md b/content/code-security/reference/code-quality/code-coverage.md
new file mode 100644
index 000000000000..aef9e718ba10
--- /dev/null
+++ b/content/code-security/reference/code-quality/code-coverage.md
@@ -0,0 +1,28 @@
+---
+title: Code coverage reference
+shortTitle: Code coverage
+intro: '{% data variables.product.prodname_code_quality_short %} shows how much of your code your tests actually exercise, so you can find untested code before you merge.'
+versions:
+ feature: code-quality
+contentType: reference
+category:
+ - Improve code quality
+---
+
+Code coverage measures what percentage of your source code is executed when your test suite runs. {% data variables.product.prodname_code_quality_short %} displays a coverage percentage on pull requests after you upload a Cobertura XML coverage report.
+
+## How coverage is calculated
+
+The coverage percentage represents the number of lines covered by tests divided by the total number of lines, expressed as a percentage. {% data variables.product.prodname_code_quality_short %} stores the latest upload for each branch (including the default branch) and compares the pull request branch coverage to the default branch coverage.
+
+For example, if your default branch has 44% coverage and your pull request branch has 65% coverage, the pull request gained 21 percentage points of coverage.
+
+## Per-file delta
+
+The per-file breakdown on pull requests shows how coverage changed for each modified file. A positive delta means the file gained coverage on the pull request branch compared to the default branch.
+
+To set up code coverage for your repository, see [AUTOTITLE](/code-security/how-tos/maintain-quality-code/set-up-code-coverage).
+
+## Further reading
+
+* [AUTOTITLE](/code-security/reference/code-quality/metrics-and-ratings)
diff --git a/content/code-security/reference/code-quality/codeql-detection.md b/content/code-security/reference/code-quality/codeql-detection.md
index 6efa4d18eff5..b90e0766dbe9 100644
--- a/content/code-security/reference/code-quality/codeql-detection.md
+++ b/content/code-security/reference/code-quality/codeql-detection.md
@@ -12,8 +12,6 @@ category:
- Improve code quality
---
-{% data reusables.code-quality.code-quality-preview-note %}
-
## {% data variables.product.prodname_codeql %}-powered analysis
{% data variables.product.prodname_code_quality_short %} uses {% data variables.product.prodname_codeql %} to perform rule-based analysis of pull requests and your default branch.
@@ -24,6 +22,10 @@ category:
{% data variables.copilot.copilot_autofix_short %} suggestions are provided for findings where possible.
+### Scan information
+
+Each {% data variables.product.prodname_codeql %} analysis will use {% data variables.product.prodname_actions %} minutes and can be seen on the **Actions** tab of the repository. These runs use the workflow name {% data variables.product.prodname_codeql %}, the same name {% data variables.product.prodname_code_scanning %} uses, so you can't reliably tell {% data variables.product.prodname_code_quality_short %} and {% data variables.product.prodname_code_scanning %} runs apart by workflow name. Identify {% data variables.product.prodname_code_quality_short %} runs by their {% data variables.product.prodname_actions %} label instead, for example "Code Quality: push on main"
+
### Query lists for supported languages
Each {% data variables.product.prodname_code_quality_short %} rule is written as a query in {% data variables.product.prodname_codeql %} and then run using {% data variables.product.prodname_actions %}.
@@ -37,11 +39,11 @@ The rules are continually refined by both {% data variables.product.github %} an
* [AUTOTITLE](/code-security/code-quality/reference/codeql-queries/python-queries)
* [AUTOTITLE](/code-security/code-quality/reference/codeql-queries/ruby-queries)
-For more information about the {% data variables.product.prodname_codeql %} project, see [https://codeql.github.com/](https://codeql.github.com/).
+For more information about the {% data variables.product.prodname_codeql %} project, see [https://codeql.github.com/](https://codeql.github.com).
## Workflow used for code quality analysis
-You can see all the workflow runs for {% data variables.product.prodname_code_quality_short %} on the **Actions** tab for your repository. The dynamic workflow is called "{% data variables.code-quality.workflow_name_actions %}".
+You can see all the workflow runs for {% data variables.product.prodname_code_quality_short %} on the **Actions** tab for your repository. You can identify {% data variables.product.prodname_code_quality_short %} runs by their {% data variables.product.prodname_actions %} label, for example "{% data variables.product.prodname_code_quality_short %}: push on main"
By default, the {% data variables.code-quality.workflow_name_actions %} workflow runs on standard {% data variables.product.github %} runners but you can configure {% data variables.product.prodname_code_quality_short %} to use runners with a specific label. These may be hosted by {% data variables.product.github %} or self-hosted.
diff --git a/content/code-security/reference/code-quality/index.md b/content/code-security/reference/code-quality/index.md
index f13ed3f1ff50..1f836330b5c4 100644
--- a/content/code-security/reference/code-quality/index.md
+++ b/content/code-security/reference/code-quality/index.md
@@ -9,6 +9,7 @@ versions:
contentType: reference
children:
- /metrics-and-ratings
+ - /code-coverage
- /codeql-detection
- /codeql-queries
redirect_from:
diff --git a/content/code-security/reference/code-quality/metrics-and-ratings.md b/content/code-security/reference/code-quality/metrics-and-ratings.md
index bd4a5ae9009e..16c1c28cf9d7 100644
--- a/content/code-security/reference/code-quality/metrics-and-ratings.md
+++ b/content/code-security/reference/code-quality/metrics-and-ratings.md
@@ -1,6 +1,7 @@
---
-title: Metrics and ratings reference
-shortTitle: Metrics and ratings
+title: Metrics and scores reference
+shortTitle: Metrics and scores
+allowTitleToDifferFromFilename: true
intro: Understand the terminology used by {% data variables.product.github %} to assess the quality of your repository's code.
versions:
feature: code-quality
@@ -11,9 +12,7 @@ category:
- Improve code quality
---
-{% data reusables.code-quality.code-quality-preview-note %}
-
-This article provides definitions for the metrics and ratings used by {% data variables.product.prodname_code_quality_short %}.
+This article provides definitions for the metrics and scores used by {% data variables.product.prodname_code_quality_short %}.
You can see the rule-based results for your repository on your **{% data variables.product.prodname_security_and_quality_tab %}** tab, in the **{% data variables.code-quality.all_findings %}** tab under "{% data variables.code-quality.code_quality_ui_views %}".
@@ -21,26 +20,19 @@ You can see the rule-based results for your repository on your **{% data variabl
The following table provides definitions for each metric that is reported for your repository.
-| Metric | Definition | Example findings |
-|----------------|-----------------|----------------------|
-| **Reliability** | Assess whether the code performs its intended function correctly, predictably, and consistently. Reliable code is free from bugs, handles errors safely, and operates as expected under normal and edge-case conditions. | Issues with performance, concurrency, error handling, correctness, API design, accessibility, internationalization, or security |
-| **Maintainability** | Assess how easy it is to understand, modify, and extend the code over time. Maintainable code follows best practices, avoids unnecessary complexity, and is organized for ease of future changes and collaboration. | Not using best practices, unused/dead code, duplicate code, complexity, logical redundancies, inadequate documentation, dependency issues |
+{% data reusables.code-quality.metrics-definitions-table %}
## Severity levels
Severity levels are used to indicate the potential impact or urgency of a code quality finding. They help users prioritize remediation efforts and communicate risks to stakeholders. Severity is determined by the rule that detected the issue, following conventions from {% data variables.product.prodname_codeql %} and industry standards.
-| Severity | Definition |
-|-----------|--------------------|
-| **Error** | Indicates a high-severity issue that is likely to cause bugs, failures, or major maintainability risks. |
-| **Warning** | Indicates a moderate-severity issue that may impact code quality or reliability, but is not immediately critical. |
-| **Note** | Indicates a low-severity issue, minor improvement, or recommendation. These findings are useful for ongoing code health and maintainability. |
+{% data reusables.code-quality.severity-levels-table %}
-## Ratings definitions
+## Scores definitions
-These ratings are used to summarize the overall reliability and maintainability of a repository based on the severity of rule-based results found by {% data variables.product.prodname_codeql %} scans of the full default branch:
+These scores are used to summarize the overall reliability and maintainability of a repository based on the severity of rule-based results found by {% data variables.product.prodname_codeql %} scans of the full default branch:
-| Rating | Definition | Criteria (based on findings) |
+| Scores | Definition | Criteria (based on findings) |
|----------------------|--------------|-------------------------------|
| **Excellent** | Codebase demonstrates best practices for reliability and maintainability. | No code quality findings detected |
| **Good** | Codebase has low-severity issues or minor improvements are suggested. | ≥1 "Note" level finding |
@@ -49,21 +41,9 @@ These ratings are used to summarize the overall reliability and maintainability
## Code coverage
-Code coverage measures what percentage of your source code is executed when your test suite runs. {% data variables.product.prodname_code_quality_short %} displays a coverage percentage on pull requests after you upload a Cobertura XML coverage report.
-
-### How coverage is calculated
-
-The coverage percentage represents the number of lines covered by tests divided by the total number of lines, expressed as a percentage. {% data variables.product.prodname_code_quality_short %} stores the latest upload for each branch (including the default branch) and compares the PR branch coverage to the default branch coverage.
-
-For example, if your default branch has 44% coverage and your PR branch has 65% coverage, the PR gained 21 percentage points of coverage.
-
-### Per-file delta
-
-The per-file breakdown on pull requests shows how coverage changed for each modified file. A positive delta means the file gained coverage on the PR branch compared to the default branch.
-
-To set up code coverage for your repository, see [AUTOTITLE](/code-security/how-tos/maintain-quality-code/set-up-code-coverage).
+For details about how {% data variables.product.prodname_code_quality_short %} measures and reports code coverage, see [AUTOTITLE](/code-security/reference/code-quality/code-coverage).
## Further reading
-* [AUTOTITLE](/code-security/code-quality/concepts/about-code-quality)
+* [AUTOTITLE](/code-security/concepts/code-quality/code-quality)
* [AUTOTITLE](/code-security/code-quality/how-tos/interpret-results)
diff --git a/content/code-security/responsible-use/security-and-quality-ai-features.md b/content/code-security/responsible-use/security-and-quality-ai-features.md
index ab8f1551e8b3..4d35da7ba285 100644
--- a/content/code-security/responsible-use/security-and-quality-ai-features.md
+++ b/content/code-security/responsible-use/security-and-quality-ai-features.md
@@ -285,7 +285,7 @@ For additional guidance on the responsible use of GitHub Security AI features, w
* [AUTOTITLE](/admin/enforcing-policies/enforcing-policies-for-your-enterprise/enforcing-policies-for-code-security-and-analysis-for-your-enterprise#enforcing-a-policy-to-manage-the-use-of-generic-secret-detection-for-secret-scanning-in-your-enterprises-repositories){% endif %}
* [AUTOTITLE](/code-security/how-tos/secure-your-secrets/customize-leak-detection/generating-regular-expressions-for-custom-patterns-with-ai)
* [AUTOTITLE](/code-security/how-tos/secure-your-secrets/customize-leak-detection/define-custom-patterns)
-* [AUTOTITLE](/code-security/tutorials/improve-code-quality/quickstart)
+* [AUTOTITLE](/code-security/concepts/code-quality/code-quality)
* [AUTOTITLE](/copilot/responsible-use/agents)
* [Community discussion for Code Quality feedback](https://github.com/orgs/community/discussions/177488)
diff --git a/content/code-security/tutorials/improve-code-quality/catch-issues-before-merge.md b/content/code-security/tutorials/improve-code-quality/catch-issues-before-merge.md
new file mode 100644
index 000000000000..711a727ce7eb
--- /dev/null
+++ b/content/code-security/tutorials/improve-code-quality/catch-issues-before-merge.md
@@ -0,0 +1,139 @@
+---
+title: Preventing code quality issues from reaching your default branch
+shortTitle: Catch issues before merge
+intro: 'Move through {% data variables.product.prodname_code_quality_short %} findings on your pull request, including understanding severity labels, when each finding is best fixed, delegated, or dismissed, and how those choices shape your repository''s code health.'
+versions:
+ feature: code-quality
+product: '{% data reusables.gated-features.code-quality-availability %}'
+permissions: '{% data reusables.permissions.code-quality-see-repo-findings %}'
+contentType: tutorials
+redirect_from:
+ - /code-security/code-quality/tutorials/fix-findings-in-prs
+ - /code-security/tutorials/improve-code-quality/fix-findings-in-prs
+ - /code-security/code-quality/get-started/quickstart
+ - /code-security/code-quality/get-started
+ - /code-security/tutorials/improve-code-quality/quickstart
+category:
+ - Improve code quality
+---
+
+## Introduction
+
+In this tutorial, you'll follow a single pull request through {% data variables.product.prodname_code_quality_short %}'s analysis, from first comment to merge. You'll learn:
+
+* How to read the {% data variables.product.prodname_code_quality_short %} comments on a pull request and tell the two types of finding apart.
+* How to use a finding's severity label to decide what to fix, what to dismiss, and in what order.
+* How the choices you make on a pull request shape your repository's scores, backlog, and merge gates.
+
+By the end, you'll have resolved every blocking finding on the example pull request and merged it with a clean {% data variables.product.prodname_code_quality_short %} check, and you'll understand *why* you made each choice.
+
+This is a guided walkthrough, so it favors understanding over speed. For basic steps on how to commit an autofix or dismiss a finding, see the companion how-to: [AUTOTITLE](/code-security/how-tos/maintain-quality-code/fix-findings-on-a-pr).
+
+### Before you start
+
+* {% data variables.product.prodname_code_quality_short %} is enabled on a repository you contribute to. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/enable-code-quality).
+* The repository uses a language supported by {% data variables.product.prodname_codeql %} so that rule-based findings and scores are generated. For a list of supported languages, see [AUTOTITLE](/code-security/concepts/code-quality/code-quality#supported-languages).
+* You have a pull request open against the default branch with at least one {% data variables.product.prodname_code_quality_short %} finding to triage. If you don't have a pull request ready, you can follow the example below.
+
+Throughout this tutorial, we'll use a running example: a pull request that refactors some code will introduce several code quality issues into the default branch if it's merged as it is. A {% data variables.product.prodname_code_quality_short %} scan has automatically run on the pull request and has reported several findings as comments.
+
+## Why the pull request is the best place to fix a finding
+
+Every finding you don't resolve at the pull request stage becomes an action item in your repository's backlog, and technical debt is often more expensive to pay down later than to address now. Right now, while the pull request is open, the code's context and intent are still fresh in your mind, which makes each finding, and its autofix, faster to assess, apply, or confidently dismiss.
+
+Resolving findings at the pull request stage means your team spends less time triaging remediation work against feature work, and avoids the overhead of extra pull requests just to burn down a backlog.
+
+## Step 1: Find the {% data variables.product.prodname_code_quality_short %} comments on your pull request
+
+When you open a pull request, {% data variables.product.prodname_code_quality_short %} runs **two types of analysis** and posts findings as comments. Open the **Files changed** tab of your pull request and look at who left each comment—the author tells you which type of finding it is.
+
+1. **Rules-based findings** are posted by the **`{% data variables.code-quality.pr_commenter %}`**. {% data variables.product.prodname_code_quality_short %} uses {% data variables.product.prodname_codeql %} to scan your changes against a set of rules, and each comment includes a suggested autofix.
+
+1. **AI-powered findings** are posted by **{% data variables.product.prodname_copilot_short %}**. If your organization has {% data variables.product.prodname_copilot_short %} licenses and AI features are enabled for your enterprise, {% data variables.copilot.copilot_code-review_short %} looks for quality issues that rules-based analysis may miss. These comments also include a suggested autofix.
+
+In our example, we'll look at three comments that have come from `{% data variables.code-quality.pr_commenter %}`, so they're rules-based findings. On your own pull request you may see both types—note which is which before you go further, because severity labels (Step 2) apply only to the rules-based comments.
+
+## Step 2: Read the severity label to decide what matters
+
+Every rules-based finding from `{% data variables.code-quality.pr_commenter %}` carries a severity label—**Error**, **Warning**, or **Note**. Find the label on one of the comments and check it against this table.
+
+{% data reusables.code-quality.severity-levels-table %}
+
+The label is doing two jobs for you at once:
+
+1. **It tells you what to fix first.** Severity reflects the expected impact of a rule across typical code. In our example, you'd start with the **Error**, then the **Warning**, and treat the **Note** as optional polish.
+1. **It may decide whether you can merge at all.** A repository administrator or organization owner can configure {% data variables.product.prodname_code_quality_short %} as a merge gate. For example, if the threshold for merging is "Warning and above", every **Warning** *and* **Error**-level finding must be fixed or dismissed before you can merge (**Note** findings wouldn't prevent you from merging). Similarly, a stricter threshold may require you to resolve _all_ findings before merge.
+
+To see whether a gate is in effect, scroll to the **Checks** section at the bottom of the pull request. If your changes fall below the required threshold, you'll see a merge block banner: "Merging is blocked: Code quality findings were detected."
+
+
+
+In our example the gate is set to "Warning and above", so the banner is present: the **Error** and the **Warning** are blocking the merge, and the **Note** is not. That tells you what you have to clear before this pull request can be merged.
+
+If the merge block banner doesn't specify a severity level, you must clear _all_ findings in order to merge your pull request.
+
+## Step 3: Resolve each finding
+
+For every finding, decide whether it applies to your code and, if it does, how to fix it. That leads you to one of three actions.
+
+| Assessment | Recommended action | Notes |
+| --- | --- | --- |
+| The finding is legitimate and the suggested fix looks correct | **Apply the autofix suggestion** | Clicking **Commit suggestion** doesn't consume {% data variables.product.prodname_ai_credits_short %}, and rules-based autofixes don't require a {% data variables.product.prodname_copilot_short %} license. |
+| The finding is real but you want to fix several at once, or the suggested fix needs adapting | **Delegate to {% data variables.product.prodname_copilot_short %}**—mention `@copilot` in a comment to hand the work to the cloud agent. {% data variables.product.prodname_copilot_short %} reacts with 👀, starts a new agent session, and pushes the necessary fixes to the pull request's branch | Requires a {% data variables.product.prodname_copilot_short %} license and consumes {% data variables.product.prodname_ai_credits_short %}. |
+| The finding doesn't apply, for example, it's test code, an intentional pattern, or a false positive | Click **Dismiss finding** and provide a reason | You'll be able to merge your pull request, but the finding will appear in the repository backlog, and in future pull requests. |
+
+Apply the practice to your own pull request, working in severity order.
+
+In our example:
+
+* The **Error**- and **Warning**-level findings are genuine bugs and the suggested autofixes look reasonable, so we apply the autofix suggestions. The findings resolve and drop out of the blocking count.
+* A **Note**-level finding flags a minor pattern in an adjacent test helper. It's intentional, so we dismiss it with a reason like "Used in tests".
+* There are several additional **Note**-level findings. Instead of working through each autofix suggestion one by one, we comment: "`@copilot`, fix all the remaining Note-level findings". We track {% data variables.product.prodname_copilot_short %}'s progress in the **Agents** tab of the repository, and review the commits it pushes to the pull request when they're ready.
+
+## Step 4: Confirm your pull request is unblocked (optional)
+
+If you *do* have blocking findings, once you've fixed or dismissed the relevant findings, return to the **Checks** section at the bottom of the pull request.
+
+In our example, with the **Error** and **Warning** findings resolved, the merge block banner disappears. Your pull request is now clear to merge.
+
+If the banner is still there, it means a finding at or above the blocking severity is still open.
+
+## Step 5: Resolve the AI-powered findings from {% data variables.product.prodname_copilot_short %}
+
+If your organization has {% data variables.product.prodname_copilot_short %} licenses and AI features are enabled for your enterprise, you'll also see comments posted by {% data variables.product.prodname_copilot_short %}. These are the **AI-powered findings** introduced in Step 1, and they come from {% data variables.copilot.copilot_code-review_short %} rather than from `{% data variables.code-quality.pr_commenter %}`.
+
+Where the rules-based findings match your changes against a fixed set of {% data variables.product.prodname_codeql %} rules, {% data variables.copilot.copilot_code-review_short %} reasons about the intent of your code. It catches quality issues that don't map to a specific rule, so it's a useful complement to the rules-based comments rather than a replacement for them.
+
+These findings don't carry a severity label of "Error", "Warning", or "Note". Since the merge gate you saw in Step 2 counts only the severity of *rules-based findings*, AI-powered findings never block your pull request on their own. That doesn't make them optional, resolving them in context is still the optimal place to keep quality issues out of your default branch.
+
+You resolve an AI-powered finding with the same three choices you used in Step 3:
+
+* **Apply the autofix suggestion.** Each comment includes a suggested fix. If it's correct as-is, click **Commit suggestion**. Applying the autofix doesn't consume {% data variables.product.prodname_ai_credits %}.
+* **Delegate to {% data variables.product.prodname_copilot_short %}**—mention `@copilot` in a comment to hand the work to the cloud agent. {% data variables.product.prodname_copilot_short %} reacts with 👀, starts a new agent session, and pushes the necessary fixes to the pull request's branch. This option requires a {% data variables.product.prodname_copilot_short %} license, and does consume {% data variables.product.prodname_ai_credits %}.
+* **Resolve the comment.** If it doesn't apply to your code, click **Resolve**.
+
+## How this connects to the rest of your code health
+
+The pull request you just cleared is part of a bigger picture:
+
+* **Scores.** Your repository's reliability and maintainability scores are computed from findings on the default branch. Resolving findings before merge is how you keep those scores from drifting. See [AUTOTITLE](/code-security/code-quality/reference/metrics-and-ratings).
+* **Backlog.** Anything you don't fix in the pull request joins the backlog of findings on the default branch. Working that backlog down is a discipline of its own. See [AUTOTITLE](/code-security/tutorials/improve-code-quality/raise-your-quality-rating).
+* **Compliance.** When a class of findings genuinely must not reach the default branch, the "Require code quality results" ruleset helps repository administrators and organization owners encode that decision as a merge gate. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/unblock-your-pr).
+
+The healthiest teams combine all three: deliberate triage and remediation at the pull request stage, periodic backlog work, and enforced thresholds at the merge boundary.
+
+## Troubleshooting
+
+* **I don't see any {% data variables.product.prodname_code_quality_short %} comments.** The scan may still be running, your changes may not touch a supported language, or you don't have any findings. Confirm {% data variables.product.prodname_code_quality_short %} is enabled and give the check (called "{% data variables.code-quality.check_status_name %}") time to finish. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/enable-code-quality).
+* **I only see comments from `{% data variables.code-quality.pr_commenter %}`, never from {% data variables.product.prodname_copilot_short %}.** AI-powered findings require {% data variables.product.prodname_copilot_short %} licenses and AI features enabled for your enterprise. Without them, you'll see only rules-based findings.
+* **I don't see autofixes for my code quality findings.** Autofix generation consumes {% data variables.product.prodname_ai_credits %}. Your organization may have depleted its monthly budget of {% data variables.product.prodname_ai_credits_short %}.
+* **The merge block banner won't clear.** At least one finding at or above the blocking severity is still open. If you don't see a severity level defined in the merge block banner, it means that your repository is using the most stringent code quality thresholds, which require *all* findings to be addressed before merging. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/unblock-your-pr).
+
+## Conclusion
+
+In this tutorial, you've worked through {% data variables.product.prodname_code_quality_short %} comments on a pull request, used severity to prioritize remediation, and resolved each finding intentionally before merging your pull request. By treating each finding, and its autofix, as a small, in-context decision, you prevented code quality debt from reaching your default branch.
+
+## Next steps
+
+* Apply the same thinking to your existing backlog: [AUTOTITLE](/code-security/tutorials/improve-code-quality/raise-your-quality-rating).
+* Learn how findings translate into scores so you can measure the impact of the work: [AUTOTITLE](/code-security/code-quality/reference/metrics-and-ratings).
diff --git a/content/code-security/tutorials/improve-code-quality/fix-findings-in-prs.md b/content/code-security/tutorials/improve-code-quality/fix-findings-in-prs.md
deleted file mode 100644
index a7b01048cc8b..000000000000
--- a/content/code-security/tutorials/improve-code-quality/fix-findings-in-prs.md
+++ /dev/null
@@ -1,77 +0,0 @@
----
-title: Fixing code quality findings before merging your pull request
-shortTitle: Fix findings in PRs
-intro: Catch quality issues before they reach your default branch and fix them with {% data variables.copilot.copilot_autofix_short %} and {% data variables.copilot.copilot_cloud_agent %}.
-versions:
- feature: code-quality
-product: '{% data reusables.gated-features.code-quality-availability %}'
-permissions: '{% data reusables.permissions.code-quality-see-repo-findings %}'
-contentType: tutorials
-redirect_from:
- - /code-security/code-quality/tutorials/fix-findings-in-prs
-category:
- - Improve code quality
----
-
-{% data reusables.code-quality.code-quality-preview-note %}
-
-## Introduction
-
-This tutorial shows you how to work with {% data variables.product.prodname_code_quality %} on pull requests to identify code quality issues that your changes may otherwise inadvertently introduce, and how to address and resolve code quality findings with {% data variables.copilot.copilot_autofix_short %} and {% data variables.copilot.copilot_cloud_agent %}.
-
-### Benefits of catching issues early
-
-Catching code quality issues early keeps your team's codebase in shape. {% data variables.product.prodname_code_quality %} checks your code for:
-
-* **Reliability**: For example, logic errors, unsafe error handling, or race conditions that could cause your app to crash or behave unpredictably. By addressing this type of issue early, you make your software more robust and dependable for users.
-* **Maintainability**: For example, duplicated code, overly complex logic, unused variables, or violations of coding best practices. Fixing these issues makes your code cleaner and easier to read, so future changes are faster and less risky.
-
-## 1. Understand how {% data variables.product.prodname_code_quality %} works on pull requests
-
-When you open a pull request, {% data variables.product.prodname_code_quality %} uses {% data variables.product.prodname_codeql %} to automatically scan your changes for quality issues like those described above.
-
-The results of the {% data variables.product.prodname_codeql %} scan are reported as comments on your pull request, left by the `{% data variables.code-quality.pr_commenter %}`. Each comment corresponds to a specific code quality problem that was detected in your changes, and comes with a suggested autofix.
-
-Comments are labeled by severity (**Error**, **Warning**, **Note**), so you can see which findings are the most critical to address.
-
-## 2. Prioritize fixes based on severity
-
-Scan through the comments and identify the findings that have the highest severity level ("Error") first.
-
-If there are no "Error" findings, look for findings of the next severity level ("Warning"), and so on.
-
-High severity findings indicate more serious code quality issues that are more likely to introduce reliability or maintainability problems in your codebase. By resolving high severity findings, you're doing the most impactful work to maintain the quality of your team's code.
-
-> [!NOTE]
-> A repository administrator may have set a code quality gate that **blocks** merging on your pull request, if the pull request contains {% data variables.product.prodname_code_quality_short %} findings of a particular severity level or above. See [AUTOTITLE](/code-security/code-quality/how-tos/unblock-your-pr).
-
-## 3. Leverage {% data variables.copilot.copilot_autofix_short %} or {% data variables.copilot.copilot_cloud_agent %} to fix findings
-
-### {% data variables.copilot.copilot_autofix_short %}
-
-{% data reusables.code-quality.fix-findings-with-copilot-autofix %}
-
-### {% data variables.copilot.copilot_cloud_agent %}
-
-{% data reusables.code-quality.fix-findings-with-cloud-agent %}
-
-## 4. Dismiss irrelevant findings
-
-{% data reusables.code-quality.dismiss-irrelevant-findings %}
-
-## 5. Push changes and wait for the scan
-
-After fixing or dismissing findings, push your changes to the branch associated with your pull request. {% data variables.product.prodname_code_quality %} will automatically re-scan your changes and update the comments on your pull request accordingly.
-
-## 6. Check your repository's code quality ratings
-
-Anyone with write access can view the overall code quality ratings for a repository, which summarize the state of the code's reliability and maintainability across the default branch.
-
-To view your repository's ratings, navigate to the **{% data variables.product.prodname_security_and_quality_tab %}** tab of your repository, expand **{% data variables.code-quality.code_quality_ui_views %}** in the sidebar, then click **{% data variables.code-quality.all_findings %}**.
-
-By resolving issues before merging your pull request, you've directly contributed to maintaining these ratings.
-
-## Next steps
-
-* Address code quality findings in your default branch and understand your repository’s reliability and maintainability ratings. See [AUTOTITLE](/code-security/code-quality/tutorials/improve-your-codebase).
-* Provide feedback on {% data variables.product.prodname_code_quality %} in the [community discussion](https://github.com/orgs/community/discussions/177488).
diff --git a/content/code-security/tutorials/improve-code-quality/improve-recent-merges.md b/content/code-security/tutorials/improve-code-quality/improve-recent-merges.md
deleted file mode 100644
index 5475b664b1cf..000000000000
--- a/content/code-security/tutorials/improve-code-quality/improve-recent-merges.md
+++ /dev/null
@@ -1,113 +0,0 @@
----
-title: Improving the quality of recently merged code with AI
-shortTitle: Improve recent merges
-intro: Explore {% data variables.product.prodname_code_quality %} findings for recently merged code and fix with {% data variables.copilot.copilot_autofix_short %} or delegate remediation work to {% data variables.copilot.copilot_cloud_agent %}.
-versions:
- feature: code-quality
-product: '{% data reusables.gated-features.code-quality-availability %}'
-permissions: '{% data reusables.permissions.code-quality-see-repo-findings %}'
-contentType: tutorials
-redirect_from:
- - /code-security/code-quality/tutorials/improve-active-code
- - /code-security/code-quality/tutorials/improve-recent-merges
-category:
- - Improve code quality
----
-
-{% data reusables.code-quality.code-quality-preview-note %}
-
-## Introduction
-
-This tutorial shows you how to explore and remediate quality issues that have been detected by {% data variables.product.prodname_code_quality_short %}'s AI-powered analysis of code that was recently merged into your default branch.
-
-When you improve quality of recently merged files, you reduce technical debt in the repository and make it easier for other developers to work on files that are under active development.
-
-### {% data variables.product.prodname_code_quality_short %} has two lines of defense
-
-{% data variables.product.prodname_code_quality_short %} scans pull requests and comments on quality concerns, **then runs a second AI scan** after the pull request is merged. The two types of scan use complementary technologies:
-
-* **Pull request scans** use {% data variables.product.prodname_codeql %} rules to identify problems. This analysis is thoroughly tested, good at identifying where code doesn't match the quality rules, and can analyze many files. However, it supports a subset of coding languages and cannot identify problems where there is no rule.
-
-* **Recently merged file scans** use a large language model to analyze your most recently changed files and report findings for up to {% data variables.code-quality.num_ai_findings %} files. This analysis examines your code across all languages, without being limited by rules, and provides contextual insights and suggestions that can go beyond what {% data variables.product.prodname_codeql %} rules offer.
-
-### Prerequisites
-
-* {% data variables.product.prodname_code_quality_short %} is enabled, see [AUTOTITLE](/code-security/code-quality/how-tos/enable-code-quality).
-* At least one pull request has been merged since {% data variables.product.prodname_code_quality_short %} was enabled.
-
-## 1. View the AI suggestions for your repository
-
-After a {% data variables.product.prodname_code_quality_short %} scan of the recently merged files on your default branch, you can see the results under the **{% data variables.code-quality.recent_suggestions %}** view, which displays findings for up to {% data variables.code-quality.num_ai_findings %} files.
-
-{% data reusables.code-quality.dashboard-navigation-repo %}
-{% data reusables.code-quality.dashboard-recent-suggestions %}
-
-> [!NOTE]
-> This view is empty if the repository is inactive or if LLM analysis could not suggest ways to improve code quality in recent pushes to the default branch.
-
-## 2. Explore suggested improvements for your repository
-
-On the **{% data variables.code-quality.recent_suggestions %}** page, each file is listed with the number of quality problems identified and when the file was pushed to the default branch.
-
-* Click a file name to view details of the quality problems detected and the suggested fixes.
-
-
-
-## 3. Delegate remediation work or open pull requests yourself
-
-You can open a pull request to apply the suggested autofixes to a file or delegate the remediation work to {% data variables.copilot.copilot_cloud_agent %}. You need a {% data variables.product.prodname_copilot_short %} license to assign work to {% data variables.copilot.copilot_cloud_agent %}.
-
Sign up for {% data variables.product.prodname_copilot_short %} {% octicon "link-external" height:16 aria-label="link-external" %}
-
-### Delegate work to {% data variables.copilot.copilot_cloud_agent %}
-
-You can ask {% data variables.copilot.copilot_cloud_agent_short %} to open pull requests to make improvements to files using the suggested changes as a prompt. This is the best option if the suggested changes look good to you and you want to open a pull request that applies fixes to more than one file.
-
-To delegate pull request creation:
-
-* **Multiple files:** Select the files you want to include, then click **Assign selected to {% data variables.product.prodname_copilot_short %}** in the header for the list of files.
-* **One file:** Click **Assign to {% data variables.product.prodname_copilot_short %}** for the file.
-
-There is a delay while the {% data variables.copilot.copilot_cloud_agent_short %} sets up the work. When the pull request is open and work is in progress, a banner is displayed with a link to the pull request.
-
-You can track {% data variables.copilot.copilot_cloud_agent %}'s work:
-
-* In the pull request, the summary is updated as work progresses.
-* Using the [agents page](https://github.com/copilot/agents?ref_product=copilot&ref_type=engagement&ref_style=text) or session logs. See [AUTOTITLE](/copilot/how-tos/copilot-on-github/use-copilot-agents/manage-and-track-agents).
-
-### Open your own pull requests
-
-You can open pull requests yourself to apply autofix suggestions. This is the best option if:
-
-* You want to work on the changes locally or in {% data variables.product.prodname_desktop %} before opening a pull request
-* You do not have access to {% data variables.copilot.copilot_cloud_agent %}
-
-> [!NOTE]
-> When you open a pull request yourself, you can only commit fixes to one file at a time. To fix multiple files at once, you must use {% data variables.copilot.copilot_cloud_agent %}.
-
-#### Opening a pull request
-
-1. Click the file name to view details of the quality problems detected.
-1. Review the problems and suggested fixes.
-1. Expand the **Assign to {% data variables.product.prodname_copilot_short %}** drop-down and then click {% octicon "git-pull-request" aria-hidden="true" aria-label="Pull request" %} **Open pull request** to change the default option to "Open pull request". Your preference is remembered.
-
- 
-
-1. Click **Open pull request** to open a dialog of commit options.
-1. Click **Commit change** to create a pull request with the fixes.
-
-## 4. Provide pull request reviewers with context
-
-Providing context on why you are proposing changes to code is the best way to encourage team members to review your pull request. If you used {% data variables.copilot.copilot_cloud_agent %}, the pull request summary already includes full details of the problems fixed by the pull request.
-
-If you opened the pull request directly from the {% data variables.product.prodname_code_quality %} view, the pull request summary links to the "{% data variables.code-quality.recent_suggestions %}" view. You may want to copy some of the explanations from the {% data variables.code-quality.recent_suggestions %} view into the pull request summary.
-
-
-
-## 5. See your changes make an impact on {% data variables.code-quality.recent_suggestions %}
-
-When you return to the "{% data variables.code-quality.recent_suggestions %}" view after merging your pull request, the findings you fixed are no longer listed.
-
-## Next steps
-
-* Learn more about how {% data variables.copilot.copilot_cloud_agent %} can help expedite development tasks. See [AUTOTITLE](/copilot/tutorials/cloud-agent/get-the-best-results).
-* Provide feedback on {% data variables.product.prodname_code_quality %} in the [community discussion](https://github.com/orgs/community/discussions/177488).
diff --git a/content/code-security/tutorials/improve-code-quality/improve-your-codebase.md b/content/code-security/tutorials/improve-code-quality/improve-your-codebase.md
deleted file mode 100644
index 6237e9adf71e..000000000000
--- a/content/code-security/tutorials/improve-code-quality/improve-your-codebase.md
+++ /dev/null
@@ -1,112 +0,0 @@
----
-title: Improving the quality of your repository's code
-shortTitle: Improve your codebase
-intro: Assess and remediate code quality issues detected on your default branch so you can improve the quality of your codebase. As you progress, you'll see your repository's code quality rating rise as a result.
-versions:
- feature: code-quality
-product: '{% data reusables.gated-features.code-quality-availability %}'
-permissions: '{% data reusables.permissions.code-quality-see-repo-findings %}'
-contentType: tutorials
-redirect_from:
- - /code-security/code-quality/tutorials/improve-your-codebase
-category:
- - Improve code quality
----
-
-{% data reusables.code-quality.code-quality-preview-note %}
-
-## Introduction
-
-This tutorial guides you through using {% data variables.product.prodname_code_quality %} to review, prioritize, and remediate code health issues across your repository — helping you systematically reduce technical debt, improve reliability and maintainability, and communicate your impact to stakeholders.
-
-### Prerequisites
-
-* {% data variables.product.prodname_code_quality_short %} is enabled for your repository. See [AUTOTITLE](/code-security/code-quality/how-tos/enable-code-quality).
-* If you're enabling {% data variables.product.prodname_code_quality %} for the first time, ensure you've waited a few minutes after enablement for a full {% data variables.product.prodname_codeql %} scan of the default branch to complete.
-
-## 1. Assess your repository's overall code health
-
-1. Navigate to the **{% data variables.product.prodname_security_and_quality_tab %}** tab of your repository, then under "{% data variables.code-quality.code_quality_ui_views %}", click **{% data variables.code-quality.all_findings %}**.
-1. The overview on the "{% data variables.code-quality.all_findings %}" dashboard gives you an immediate assessment of the state of your default branch today:
-
- * **Maintainability rating** reflects the presence and severity of findings for dead code, duplication, complexity, missing documentation, and failure to follow best practices.
- * **Reliability rating** reflects the presence and severity of findings for correctness, performance, error handling, concurrency, and accessibility of your code.
-
- 
-
-## 2. Identify and prioritize the most impactful findings
-
-On the "{% data variables.code-quality.all_findings %}" view, you'll see the list of results from {% data variables.product.prodname_code_quality_short %}'s last scan of the default branch of the repository. These findings are:
-
-* Grouped by **rule**, so you can see which types of problem most affect your codebase.
-* Assigned a **severity** level ("Error", "Warning", "Note").
-
-### Focus on high severity findings
-
-Use the dashboard **filters** to focus on the highest-severity results first ("Errors"), and review which rules generate the most issues.
-
-
-
-To improve your repository's maintainability or reliability rating, you must resolve (fix or dismiss) all findings with the highest severity level for that metric.
-
-For example, to improve your repository's "Reliability" metric from **Poor** to **Fair**, you would need to address and resolve all **error-level findings** that impact reliability. If you have one or more error-level findings, your rating cannot be higher than "Poor". See [AUTOTITLE](/code-security/code-quality/reference/metrics-and-ratings).
-
-## 3. Investigate a group of findings and understand context
-
-Once you've identified a rule with multiple results that you want to address, you can investigate further to understand the underlying problems.
-
-1. Click the rule name to be taken to a detailed view of all findings for that rule.
-
- 
-
-1. Click **Show more**, then review the explanation of the rule, what the recommended fix is, supporting code examples and references.
-
- 
-
-## 4. Choose remediation options
-
-Evaluate all the highlighted findings for validity, impact, and risk. To improve your quality rating, you need to resolve each finding by either choosing to fix or dismiss it.
-
-### Generate an autofix
-
-If the finding looks valid and relevant for your codebase, you can generate a suggested fix.
-
-1. To the right of an individual finding, click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} Generate fix**.
-1. Review carefully the diff of the proposed change, and if you agree with it, click **Open pull request**.
-1. In the "Commit autofix to branch" dialog box, select "Open a pull request", then click **Commit change**.
-
- > [!TIP]
- > It's not currently possible to generate autofixes for a group of findings in bulk.
- >
- > If you want to address multiple findings with a single pull request, repeat steps 1 and 2 above, then in the "Commit autofix to branch" dialog box, use the branch name you already created for the first autofix, then select "Open pull request" and **Commit change**.
- >
- > The fix will be added to the existing draft pull request for your branch.
-
-1. When you're ready, change the pull request status from "Draft" to "Ready for review", and carefully review the proposed changes. Wait for any CI checks and automated tests to complete and pass before merging the pull request.
-
-### Dismiss a finding
-
-{% data reusables.code-quality.dismiss-irrelevant-findings %}
-
-1. To dismiss a finding, click **{% octicon "shield-slash" aria-label="Dismiss" %}**.
-1. The finding will disappear from the list of open findings. You can still review and reopen dismissed findings from under the "Dismissed" tab at the top of the page.
-
-## 5. Measure improvement and communicate impact
-
-After remediation work is complete, return to the "{% data variables.code-quality.all_findings %}" dashboard to review the updated reliability and maintainability metrics.
-
-When communicating your impact to stakeholders, highlight:
- * Any **reduction** in the number of findings for "Reliability" or "Maintainability".
- * Any **change in rating** for the Reliability or Maintainability ratings.
- * The requirement(s) that has been met to achieve the change in rating. For example, the remediation of all "Warning"-level findings caused the rating to change from "Fair" to "Good".
-
-Use the improvements in quality ratings and reduction in number of findings to demonstrate progress.
-
-## 6. Enforce code quality standards for pull requests
-
-If you haven't already, set up quality thresholds for pull requests, to block any changes to the codebase that will reduce the health of your codebase. See [AUTOTITLE](/code-security/code-quality/how-tos/set-pr-thresholds).
-
-## Next steps
-
-* Reduce technical debt further by fixing findings in recently changed files. See [AUTOTITLE](/code-security/code-quality/tutorials/improve-recent-merges).
-* Provide feedback on {% data variables.product.prodname_code_quality %} in the [community discussion](https://github.com/orgs/community/discussions/177488).
diff --git a/content/code-security/tutorials/improve-code-quality/index.md b/content/code-security/tutorials/improve-code-quality/index.md
index 580cb5bca993..61c002b0e71a 100644
--- a/content/code-security/tutorials/improve-code-quality/index.md
+++ b/content/code-security/tutorials/improve-code-quality/index.md
@@ -6,10 +6,9 @@ versions:
feature: code-quality
contentType: tutorials
children:
- - /quickstart
- - /fix-findings-in-prs
- - /improve-your-codebase
- - /improve-recent-merges
+ - /catch-issues-before-merge
+ - /raise-your-quality-rating
redirect_from:
- /code-security/code-quality/tutorials
---
+
diff --git a/content/code-security/tutorials/improve-code-quality/quickstart.md b/content/code-security/tutorials/improve-code-quality/quickstart.md
deleted file mode 100644
index a16c4e9381e6..000000000000
--- a/content/code-security/tutorials/improve-code-quality/quickstart.md
+++ /dev/null
@@ -1,92 +0,0 @@
----
-title: Quickstart for GitHub Code Quality
-intro: Review code quality findings, generate a {% data variables.copilot.copilot_autofix_short %}, and merge a pull request to improve reliability and maintainability with {% data variables.product.prodname_code_quality %}.
-allowTitleToDifferFromFilename: true
-versions:
- feature: code-quality
-shortTitle: Quickstart
-product: '{% data reusables.gated-features.code-quality-availability %}'
-permissions: '{% data reusables.permissions.code-quality-see-repo-findings %}'
-contentType: tutorials
-redirect_from:
- - /code-security/code-quality/get-started/quickstart
- - /code-security/code-quality/get-started
-category:
- - Improve code quality
----
-
-## Introduction
-
-{% data variables.product.prodname_code_quality %} ({% data variables.release-phases.public_preview %}) helps keep your code reliable and maintainable by surfacing code quality findings in pull requests and on your default branch.
-
-In this tutorial, you’ll learn how to identify and fix a code quality finding on your default branch, helping to improve your repository’s code health.
-
-### Prerequisites
-
-* {% data variables.product.prodname_code_quality %} must be enabled for your repository and you must have code in a supported language. See [AUTOTITLE](/code-security/code-quality/how-tos/enable-code-quality).
-* If you're enabling {% data variables.product.prodname_code_quality %} for the first time, ensure you've waited a few minutes after enablement for a full {% data variables.product.prodname_codeql %} scan of the default branch to complete.
-
-## Review scan results for your default branch
-
-In your repository, go to the **{% data variables.product.prodname_security_and_quality_tab %}** tab, click **{% data variables.code-quality.code_quality_ui_views %}** in the left sidebar, then click **{% data variables.code-quality.all_findings %}** to open the repository dashboard.
-
-Here you'll see:
-
-* Ratings for the **Reliability** and **Maintainability** of your codebase, which help you understand your code health at a glance.
-* A **results list** of all the quality issues detected by a {% data variables.product.prodname_codeql %}-powered analysis on your default branch, which are grouped by rule and language.
-
- 
-
-## Identify a high-impact finding
-
-Use the **dashboard filters** to identify a high severity level finding ("Error" or "Warning").
-
-Resolving these will have the biggest impact on your repository's ratings.
-
- 
-
-### Inspect the details of the finding
-
-Click the rule name itself to see a detailed view of the files and lines of code affected by that rule.
-
-
-
-Once you're in the detailed view, click **Show more** to gather context and understand the results.
-
-
-
-## Generate a {% data variables.copilot.copilot_autofix_short %}
-
-To the right of a highlighted finding, click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} Generate fix**.
-
-
-
-Review the suggested fix, then click **Open pull request**.
-
-### Merge the fix
-
-Carefully review the draft pull request. If you're satisfied with the proposed changes, and all checks and tests are passing, go ahead and merge the pull request.
-
-## Observe the metrics change
-
-Return to the {% data variables.product.prodname_code_quality_short %} dashboard (**{% data variables.product.prodname_security_and_quality_tab %}** tab, then **{% data variables.code-quality.code_quality_ui_views %}**, then **{% data variables.code-quality.all_findings %}**).
-
-Wait a few minutes for the next scan to complete — {% data variables.product.prodname_code_quality_short %} scans automatically re-run after every push to the default branch.
-
-Observe the change in metrics at the top of the dashboard:
-
-* The **number of findings** for "Reliability" or "Maintainability" should have decreased.
-* Your **ratings** for "Reliability" or "Maintainability" may have improved, if your fix addressed a number of high-impact findings.
-
- To understand more about how the ratings are calculated, see [AUTOTITLE](/code-security/code-quality/reference/metrics-and-ratings).
-
-## Conclusion
-
-You've successfully used {% data variables.product.prodname_code_quality_short %} and {% data variables.copilot.copilot_autofix_short %} to improve your repository's code health!
-
-Healthy code is easier to understand, maintain, and extend, and remediating code quality issues makes your codebase more reliable, compliant, and accelerates future development.
-
-## Next steps
-
-* Learn how {% data variables.product.prodname_code_quality %} works on pull requests to prevent code quality issues from reaching your default branch. See [AUTOTITLE](/code-security/code-quality/tutorials/fix-findings-in-prs).
-* Provide feedback on {% data variables.product.prodname_code_quality %} in the [community discussion](https://github.com/orgs/community/discussions/177488).
diff --git a/content/code-security/tutorials/improve-code-quality/raise-your-quality-rating.md b/content/code-security/tutorials/improve-code-quality/raise-your-quality-rating.md
new file mode 100644
index 000000000000..e3cb297bf8f9
--- /dev/null
+++ b/content/code-security/tutorials/improve-code-quality/raise-your-quality-rating.md
@@ -0,0 +1,100 @@
+---
+title: Raising your repository's code quality score
+shortTitle: Raise your quality score
+allowTitleToDifferFromFilename: true
+intro: Prioritize and resolve the findings that pose the most risk, raise your repository's code quality score, and prevent new debt from accumulating.
+versions:
+ feature: code-quality
+product: '{% data reusables.gated-features.code-quality-availability %}'
+permissions: '{% data reusables.permissions.code-quality-see-repo-findings %}'
+contentType: tutorials
+redirect_from:
+ - /code-security/code-quality/tutorials/improve-your-codebase
+ - /code-security/tutorials/improve-code-quality/improve-your-codebase
+category:
+ - Improve code quality
+---
+
+## Introduction
+
+In this tutorial, you'll work through a backlog of {% data variables.product.prodname_code_quality_short %} findings on your default branch, prioritize by risk, resolve the highest-impact findings, and communicate the result to stakeholders. You'll learn:
+
+* How to read the dashboard and understand what your scores mean.
+* How to prioritize remediation and decide whether to apply an autofix, delegate to {% data variables.copilot.copilot_cloud_agent %}, or dismiss a finding.
+* How to communicate the impact of remediation work.
+* What additional measures you can take to prevent the backlog from growing again.
+
+This is a guided walkthrough, so it favors understanding over speed. For the basic steps of generating an autofix or dismissing a finding, see the companion how-to: [AUTOTITLE](/code-security/how-tos/maintain-quality-code/fix-backlog-findings).
+
+### Before you start
+
+* {% data variables.product.prodname_code_quality_short %} is enabled on a repository you own or maintain. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/enable-code-quality).
+* If you enabled {% data variables.product.prodname_code_quality_short %} recently, wait a few minutes for the initial {% data variables.product.prodname_codeql %} scan of your default branch to complete.
+
+Throughout this tutorial, we'll use a running example: a repository whose dashboard currently shows scores of "**Reliability: Poor**" and "**Maintainability: Fair**" for code quality.
+
+## Step 1: Assess your current score
+
+{% data reusables.code-quality.dashboard-navigation-repo %}
+{% data reusables.code-quality.dashboard-all-findings %}
+
+Here you'll see scores for **Reliability** and **Maintainability**.
+
+
+
+These scores are calculated from the findings on your default branch:
+
+{% data reusables.code-quality.metrics-definitions-table %}
+
+Each score is determined by the *highest* severity of finding still present for that metric. To raise a score, you have to clear every finding at the current highest severity level.
+
+In our example, **Reliability** is "Poor" because there are still **Error**-level findings affecting reliability. Warnings and Notes are worth addressing, but until the Errors are cleared they can't move the score.
+
+## Step 2: Read the list by rule and focus on the highest-impact findings
+
+In the {% data variables.code-quality.all_findings %} view, findings are grouped by **rule**. This is useful to understand because a single rule with many findings may reflect one repeated coding habit. Once you understand one occurrence, it may be easier to understand the proposed autofixes for all of them, which makes remediation faster and easier to review in bulk.
+
+In addition, look for rules that would complete a severity tier for one of your scores—if clearing a rule removes the last remaining "Error" affecting Reliability, your score moves up immediately.
+
+In our example, one rule—"Overwritten property"—accounts for 40 of the 128 findings, and all 40 are Error-level. Clearing it would remove every Error-level finding affecting Reliability, which would move our score up to the next bracket.
+
+## Step 3: Resolve the findings
+
+Once you've picked a rule, decide how to handle each finding:
+
+| Assessment | Recommended action | Notes |
+| --- | --- | --- |
+| The finding is legitimate. | Click **Generate fix** and open a pull request | Clicking **Generate fix** consumes {% data variables.product.prodname_ai_credits_short %}. You can add multiple autofixes to the same branch to group remediation work in one pull request. |
+| The finding doesn't apply. For example, it's in legacy code, an intentional pattern, or a false positive | Click **Dismiss**. | The finding is considered resolved and removed from the list of open findings. |
+
+In our example, we generate autofixes for the 40 "Overwritten property" findings and open a pull request. Because they share a single pattern, the fixes are nearly identical. We merge the pull request once CI checks pass.
+
+## Step 4: Communicate impact
+
+After you've merged your remediation, return to the "{% data variables.code-quality.all_findings %}" view and capture:
+
+* **The score that changed.** For example, *Reliability: Poor → Fair*.
+* **The requirement that unlocked it.** For example, *all Error-level findings affecting reliability now resolved*.
+* **The reduction in open findings.** For example, *from 128 open to 88*.
+
+In our example, clearing the "Overwritten property" rule moves Reliability from **Poor** to **Fair**—the first score improvement the team can point to.
+
+## How this connects to the rest of your code health
+
+Every finding you resolved today can reappear tomorrow if new pull requests introduce the same kinds of issue. To stop the backlog regenerating:
+
+* **Set a merge threshold on your default branch** to block pull requests that introduce new code quality findings. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/set-pr-thresholds).
+* **Fix findings in the pull request when they appear**. See [AUTOTITLE](/code-security/tutorials/improve-code-quality/catch-issues-before-merge).
+
+## Troubleshooting
+
+* **Scores didn't move after merging fixes.** At least one finding at the current highest severity level for that metric is still open.
+* **The scan hasn't re-run.** {% data variables.product.prodname_code_quality_short %} scans run automatically after every push to the default branch. Wait a few minutes for the workflow to complete.
+
+## Conclusion
+
+In this tutorial, you assessed your repository's quality scores, prioritized backlog work by severity and rule, resolved findings using autofixes, and communicated the outcome as a score movement.
+
+## Next steps
+
+* Reduce technical debt further by fixing findings in recently changed files. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/fix-findings-in-recent-merges).
diff --git a/content/copilot/concepts/agents/code-review.md b/content/copilot/concepts/agents/code-review.md
index f37a0f9c5e09..141c3bd0fbfc 100644
--- a/content/copilot/concepts/agents/code-review.md
+++ b/content/copilot/concepts/agents/code-review.md
@@ -230,9 +230,18 @@ For full instructions, see [AUTOTITLE](/copilot/how-tos/copilot-on-github/set-up
> [!NOTE]
> Unless {% data variables.product.prodname_copilot_short %} has been configured to review each push to a pull request, it will only review a pull request once. If you make changes to the pull request after it has been automatically reviewed and you want {% data variables.product.prodname_copilot_short %} to re-review it, you can request this manually. Click the {% octicon "sync" aria-label="Re-request review" %} button next to {% data variables.product.prodname_copilot_short %}'s name in the **Reviewers** menu.
-## Getting detailed code quality feedback for your whole repository
+## Getting detailed code quality feedback across your repository
-{% data variables.copilot.copilot_code-review %} reviews your code in pull requests and provides feedback. If you want actionable feedback on the reliability and maintainability of your whole repository, enable {% data variables.product.prodname_code_quality %}. See [AUTOTITLE](/code-security/concepts/about-code-quality).
+{% data variables.copilot.copilot_code-review %} reviews the changes in a pull request and suggests fixes. To add systematic feedback on the reliability and maintainability of your code, on pull requests and across your default branch, enable {% data variables.product.prodname_code_quality %}.
+
+{% data variables.product.prodname_code_quality %} complements {% data variables.copilot.copilot_code-review_short %} by adding:
+
+* **Hybrid detection** that combines rules-based {% data variables.product.prodname_codeql %} analysis with AI-powered analysis, on pull requests and on your default branch.
+* **Test-coverage metrics** on pull requests, so you can see whether a change maintains or reduces coverage.
+* **One-click, {% data variables.product.prodname_copilot_short %}-powered fixes**, including delegating remediation to {% data variables.copilot.copilot_cloud_agent %}.
+* **Optional merge gating** with rulesets, so pull requests with unresolved rules-based findings (or that miss a coverage threshold) can be blocked from merging.
+
+For more information, see [AUTOTITLE](/code-security/concepts/code-quality/code-quality).
## Further reading
diff --git a/content/copilot/how-tos/administer-copilot/manage-for-organization/enable-custom-models.md b/content/copilot/how-tos/administer-copilot/manage-for-organization/enable-custom-models.md
index b31b4e389318..8bb421f81f78 100644
--- a/content/copilot/how-tos/administer-copilot/manage-for-organization/enable-custom-models.md
+++ b/content/copilot/how-tos/administer-copilot/manage-for-organization/enable-custom-models.md
@@ -33,7 +33,7 @@ After you've added your key and selected one or more models, you and your organi
{% data reusables.profile.access_org %}
{% data reusables.profile.org_settings %}
-1. In the sidebar, under "Code, planning, and automation", click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**.
1. Under "Copilot", click **Models**.
{% data reusables.copilot.byok-add %}
diff --git a/content/copilot/how-tos/administer-copilot/manage-for-organization/manage-default-models.md b/content/copilot/how-tos/administer-copilot/manage-for-organization/manage-default-models.md
index 600a2bf940ee..5ba93ded7fc7 100644
--- a/content/copilot/how-tos/administer-copilot/manage-for-organization/manage-default-models.md
+++ b/content/copilot/how-tos/administer-copilot/manage-for-organization/manage-default-models.md
@@ -30,7 +30,7 @@ If the enterprise owner has set a model to **Optional**, you can enable or disab
{% data reusables.profile.access_org %}
{% data reusables.profile.org_settings %}
-1. In the sidebar, under "Code, planning, and automation", click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**.
1. Click **Models**.
1. Next to a model in the list, click the dropdown menu and select an option:
* **Enabled**: The model is available to members of your organization.
diff --git a/content/copilot/how-tos/administer-copilot/manage-for-organization/manage-policies.md b/content/copilot/how-tos/administer-copilot/manage-for-organization/manage-policies.md
index 08052bb6b9d9..f1527fb882ec 100644
--- a/content/copilot/how-tos/administer-copilot/manage-for-organization/manage-policies.md
+++ b/content/copilot/how-tos/administer-copilot/manage-for-organization/manage-policies.md
@@ -34,7 +34,7 @@ category:
{% data reusables.profile.access_org %}
{% data reusables.profile.org_settings %}
-1. In the sidebar, under "Code, planning, and automation", click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**.
* Click **Policies** to edit the policies that control privacy and availability of features.
* Click **Models** to edit the policies that control availability of models beyond the basic models provided with {% data variables.product.prodname_copilot_short %}, which may incur additional costs.
1. For each policy you want to configure, click the dropdown menu and select an enforcement option.
diff --git a/content/copilot/how-tos/administer-copilot/manage-mcp-usage/configure-mcp-server-access.md b/content/copilot/how-tos/administer-copilot/manage-mcp-usage/configure-mcp-server-access.md
index bea70a1f6715..dc17e5cf82d8 100644
--- a/content/copilot/how-tos/administer-copilot/manage-mcp-usage/configure-mcp-server-access.md
+++ b/content/copilot/how-tos/administer-copilot/manage-mcp-usage/configure-mcp-server-access.md
@@ -43,7 +43,7 @@ To ensure uniform access, you can set and maintain your MCP registry URL and all
{% data reusables.profile.access_org %}
{% data reusables.profile.org_settings %}
-1. In the sidebar, under "Code, planning, and automation", click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**, then click **Policies**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**, then click **Policies**.
1. In the "Features" section, ensure **MCP servers in {% data variables.product.prodname_copilot_short %}** is set to **Enabled**.
1. In the **MCP Registry URL (optional)** field, enter the URL of your registry, then click **Save**.
diff --git a/content/copilot/how-tos/cloud-and-local-sandboxes/enabling-or-disabling-cloud-sandboxes-for-your-organization.md b/content/copilot/how-tos/cloud-and-local-sandboxes/enabling-or-disabling-cloud-sandboxes-for-your-organization.md
index fdb436865aeb..ab6b380b2096 100644
--- a/content/copilot/how-tos/cloud-and-local-sandboxes/enabling-or-disabling-cloud-sandboxes-for-your-organization.md
+++ b/content/copilot/how-tos/cloud-and-local-sandboxes/enabling-or-disabling-cloud-sandboxes-for-your-organization.md
@@ -27,7 +27,7 @@ For more information about cloud sandboxes, see [AUTOTITLE](/copilot/concepts/ab
{% data reusables.profile.access_org %}
{% data reusables.profile.org_settings %}
-1. In the sidebar, under "Code, planning, and automation," click **Sandboxes**.
+1. {% data reusables.user-settings.code-planning-automation %} click **Sandboxes**.
1. Under "Sandbox access," select your preferred setting:
* **Disabled**: Sandboxes are not available for organization members.
* **Enabled for all members**: All organization members can use {% data variables.copilot.sandbox_short %}.
diff --git a/content/copilot/how-tos/configure-content-exclusion/exclude-content-from-copilot.md b/content/copilot/how-tos/configure-content-exclusion/exclude-content-from-copilot.md
index e714b2802033..ea9f6ae0d4aa 100644
--- a/content/copilot/how-tos/configure-content-exclusion/exclude-content-from-copilot.md
+++ b/content/copilot/how-tos/configure-content-exclusion/exclude-content-from-copilot.md
@@ -36,7 +36,7 @@ You can use your repository settings to specify content in your repository that
{% data reusables.repositories.navigate-to-repo %}
{% data reusables.repositories.sidebar-settings %}
-1. In the "Code & automation" section of the sidebar, click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}** then click **Content exclusion**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}** then click **Content exclusion**.
If your repository inherits any exclusions from its parent organization, or from organizations in the same enterprise, you'll see one or more gray boxes at the top of the page, containing details of these exclusions. You cannot edit these settings.
diff --git a/content/copilot/how-tos/configure-content-exclusion/review-changes.md b/content/copilot/how-tos/configure-content-exclusion/review-changes.md
index b891212a887b..8c974f673974 100644
--- a/content/copilot/how-tos/configure-content-exclusion/review-changes.md
+++ b/content/copilot/how-tos/configure-content-exclusion/review-changes.md
@@ -15,7 +15,7 @@ redirect_from:
- /copilot/how-tos/content-exclusion/reviewing-changes-to-content-exclusions-for-github-copilot
- /copilot/how-tos/content-exclusion/review-changes
contentType: how-tos
-category:
+category:
- Configure Copilot
---
@@ -26,7 +26,7 @@ Organization and repository settings include the ability to exclude content from
{% data reusables.repositories.navigate-to-repo %}
{% data reusables.repositories.sidebar-settings %}
-1. In the "Code & automation" section of the sidebar, click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**.
{% data reusables.copilot.view-last-change-content-exclusions %}
1. Click the time of the last change.
diff --git a/content/copilot/how-tos/copilot-cli/use-copilot-cli/voice-input.md b/content/copilot/how-tos/copilot-cli/use-copilot-cli/voice-input.md
index 73b82676e6e9..4008af1663e3 100644
--- a/content/copilot/how-tos/copilot-cli/use-copilot-cli/voice-input.md
+++ b/content/copilot/how-tos/copilot-cli/use-copilot-cli/voice-input.md
@@ -16,7 +16,7 @@ Voice input lets you dictate prompts to {% data variables.copilot.copilot_cli_sh
## Prerequisite
-You need a working microphone connected to your machine. Voice input uses your system's default microphone.
+You need a working microphone connected to your machine. By default, voice input uses your system's default microphone.
## Limitation
@@ -62,6 +62,30 @@ Rather than holding down the space bar, you can toggle voice recording on and of
1. Speak your prompt.
1. Press any key to stop recording and insert the transcription.
+### Cleaning up voice-entered prompts
+
+Optionally, to clean up a prompt you have entered by speaking, you can use the `/refine` slash command. This command:
+
+* Removes filler words, false starts or repetitions.
+* Applies any self-corrections you've made.
+* Fixes grammatical mistakes.
+* Groups related points for clarity.
+
+To clean up the current prompt:
+
+1. Before submitting the prompt, press Ctrl+X quickly followed by /.
+1. Type `/refine`, then press Enter.
+
+## Switching microphones
+
+If you have more than one microphone available on your system, you can switch input devices.
+
+1. Enter the `/voice devices` slash command.
+
+ A list of available input devices is shown.
+
+1. Use the arrow keys on your keyboard to select the microphone you want to use, then press Enter.
+
## Switching voice models
You can dictate prompts in English or Spanish, but the appropriate voice model must be downloaded and activated for the language you want to use.
diff --git a/content/copilot/how-tos/copilot-on-github/customize-copilot/add-custom-instructions/add-repository-instructions.md b/content/copilot/how-tos/copilot-on-github/customize-copilot/add-custom-instructions/add-repository-instructions.md
index 189bf8d6b274..7ea3a079698f 100644
--- a/content/copilot/how-tos/copilot-on-github/customize-copilot/add-custom-instructions/add-repository-instructions.md
+++ b/content/copilot/how-tos/copilot-on-github/customize-copilot/add-custom-instructions/add-repository-instructions.md
@@ -176,7 +176,7 @@ Custom instructions are enabled for {% data variables.copilot.copilot_code-revie
{% data reusables.repositories.navigate-to-repo %}
{% data reusables.repositories.sidebar-settings %}
-1. In the "Code & automation" section of the sidebar, click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**, then **Code review**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**, then **Code review**.
1. Toggle the “Use custom instructions when reviewing pull requests” option on or off.
> [!NOTE]
diff --git a/content/copilot/how-tos/copilot-on-github/customize-copilot/configure-mcp-servers.md b/content/copilot/how-tos/copilot-on-github/customize-copilot/configure-mcp-servers.md
index 739e74466845..dcd9bb37857b 100644
--- a/content/copilot/how-tos/copilot-on-github/customize-copilot/configure-mcp-servers.md
+++ b/content/copilot/how-tos/copilot-on-github/customize-copilot/configure-mcp-servers.md
@@ -49,7 +49,7 @@ Repository administrators can configure MCP servers by following these steps:
{% data reusables.repositories.navigate-to-repo %}
{% data reusables.repositories.sidebar-settings %}
-1. In the "Code & automation" section of the sidebar, click **{% data variables.product.prodname_copilot_short %}** then **MCP servers**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% data variables.product.prodname_copilot_short %}** then **MCP servers**.
1. On the "Model Context Protocol (MCP)" page, add your configuration in the "MCP configuration" section.
The following sections in this article explain how to write the JSON configuration that you need to enter here.
@@ -354,7 +354,7 @@ If you want to allow {% data variables.product.prodname_copilot_short %} to acce
1. Create a {% data variables.product.pat_generic %} with the appropriate permissions. We recommend using a {% data variables.product.pat_v2 %}, where you can limit the token's access to read-only permissions on specific repositories. For more information on {% data variables.product.pat_generic_plural %}, see [AUTOTITLE](/authentication/keeping-your-account-and-data-secure/managing-your-personal-access-tokens).
{% data reusables.repositories.navigate-to-repo %}
{% data reusables.repositories.sidebar-settings %}
-1. In the "Code & automation" section of the sidebar, click **{% data variables.product.prodname_copilot_short %}** then **MCP servers**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% data variables.product.prodname_copilot_short %}** then **MCP servers**.
1. Add your configuration in the "MCP configuration" section. For example, you can add the following:
```javascript copy
@@ -396,7 +396,7 @@ If you disable this setting, {% data variables.copilot.copilot_code-review_short
{% data reusables.repositories.navigate-to-repo %}
{% data reusables.repositories.sidebar-settings %}
-1. In the "Code & automation" section of the sidebar, click **{% data variables.product.prodname_copilot_short %}** then **Code review**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% data variables.product.prodname_copilot_short %}** then **Code review**.
1. Click the **Allow Copilot to use MCP tools when reviewing pull requests** toggle to disable the setting.
## Next steps
diff --git a/content/copilot/how-tos/copilot-on-github/customize-copilot/customize-the-firewall.md b/content/copilot/how-tos/copilot-on-github/customize-copilot/customize-the-firewall.md
index 24894409648e..fb85b596b6e3 100644
--- a/content/copilot/how-tos/copilot-on-github/customize-copilot/customize-the-firewall.md
+++ b/content/copilot/how-tos/copilot-on-github/customize-copilot/customize-the-firewall.md
@@ -100,7 +100,7 @@ To access the firewall settings:
{% data reusables.repositories.navigate-to-repo %}
{% data reusables.repositories.sidebar-settings %}
-1. In the "Code & automation" section of the sidebar, click **{% data variables.product.prodname_copilot_short %}** then **Internet access**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% data variables.product.prodname_copilot_short %}** then **Internet access**.
### Enabling or disabling the firewall
diff --git a/content/copilot/how-tos/copilot-on-github/set-up-copilot/configure-automatic-review.md b/content/copilot/how-tos/copilot-on-github/set-up-copilot/configure-automatic-review.md
index 0b5122ed9b4b..368a570f5cb9 100644
--- a/content/copilot/how-tos/copilot-on-github/set-up-copilot/configure-automatic-review.md
+++ b/content/copilot/how-tos/copilot-on-github/set-up-copilot/configure-automatic-review.md
@@ -13,7 +13,7 @@ redirect_from:
- /copilot/how-tos/agents/request-a-code-review/configure-automatic-review
- /copilot/how-tos/use-copilot-agents/request-a-code-review/configure-automatic-review
contentType: how-tos
-category:
+category:
- Configure Copilot
---
@@ -70,10 +70,9 @@ You can set the default review effort level that {% data variables.copilot.copil
{% data reusables.repositories.navigate-to-repo %}
{% data reusables.repositories.sidebar-settings %}
-1. In the "Code & automation" section of the sidebar, click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**, then **Code review**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**, then **Code review**.
1. Next to "Review effort level," select the effort level for automatic reviews in this repository.
* **Low**: Standard review (default).
* **Medium**: Deeper analysis of complex logic, security-sensitive code, and cross-service changes.
Medium reviews use more {% data variables.product.prodname_actions %} minutes and {% data variables.product.prodname_ai_credits_short %}. If you use Medium effort, consider configuring larger or self-hosted runners for better performance. See [AUTOTITLE](/copilot/how-tos/copilot-on-github/set-up-copilot/configure-runners).
-
diff --git a/content/copilot/how-tos/copilot-on-github/set-up-copilot/configure-runners.md b/content/copilot/how-tos/copilot-on-github/set-up-copilot/configure-runners.md
index 6539f6d68524..ed3af46734fb 100644
--- a/content/copilot/how-tos/copilot-on-github/set-up-copilot/configure-runners.md
+++ b/content/copilot/how-tos/copilot-on-github/set-up-copilot/configure-runners.md
@@ -83,7 +83,7 @@ This is useful if your organization requires all code reviews and {% data variab
{% data reusables.profile.access_org %}
{% data reusables.profile.org_settings %}
-1. In the sidebar, under "Code, planning, and automation," click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**, and then click **Runner type**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**, and then click **Runner type**.
1. Next to "Runner type configuration," click {% octicon "pencil" aria-label="Edit" %}.
1. In the "Edit runner type" dialog, select the runner type to use by default across your organization, then click **Save runner selection**.
* **Standard {% data variables.product.prodname_dotcom %} runner**: {% data variables.copilot.copilot_code-review_short %} and {% data variables.copilot.copilot_cloud_agent %} will use the standard {% data variables.product.prodname_dotcom %}-hosted runner.
diff --git a/content/copilot/how-tos/use-copilot-agents/cloud-agent/configuring-agent-settings.md b/content/copilot/how-tos/use-copilot-agents/cloud-agent/configuring-agent-settings.md
index cac3a5780193..90c1a80ca680 100644
--- a/content/copilot/how-tos/use-copilot-agents/cloud-agent/configuring-agent-settings.md
+++ b/content/copilot/how-tos/use-copilot-agents/cloud-agent/configuring-agent-settings.md
@@ -6,7 +6,7 @@ intro: 'Learn how to configure settings for {% data variables.copilot.copilot_cl
versions:
feature: copilot
contentType: how-tos
-category:
+category:
- Configure Copilot
redirect_from:
- /copilot/how-tos/use-copilot-agents/coding-agent/configuring-agent-settings
@@ -22,7 +22,7 @@ You must be a repository administrator to configure these settings.
{% data reusables.repositories.navigate-to-repo %}
{% data reusables.repositories.sidebar-settings %}
-1. In the "Code & automation" section of the sidebar, click **{% data variables.product.prodname_copilot_short %}** then **{% data variables.copilot.copilot_cloud_agent_short_cap_c %}**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% data variables.product.prodname_copilot_short %}** then **{% data variables.copilot.copilot_cloud_agent_short_cap_c %}**.
1. In the "Validation tools" section, toggle the tool, or tools, you want to enable or disable.
## Allowing {% data variables.product.prodname_actions %} workflows to run automatically when {% data variables.product.prodname_copilot_short %} pushes
@@ -35,5 +35,5 @@ You must be a repository administrator to configure these settings.
{% data reusables.repositories.navigate-to-repo %}
{% data reusables.repositories.sidebar-settings %}
-1. In the "Code & automation" section of the sidebar, click **{% data variables.product.prodname_copilot_short %}** then **{% data variables.copilot.copilot_cloud_agent_short %}**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% data variables.product.prodname_copilot_short %}** then **{% data variables.copilot.copilot_cloud_agent_short %}**.
1. In the "Actions workflow approval" section, disable the **Require approval for workflow runs** setting.
diff --git a/content/copilot/how-tos/use-copilot-agents/copilot-memory/manage-as-administrator.md b/content/copilot/how-tos/use-copilot-agents/copilot-memory/manage-as-administrator.md
index e1ea636cf85c..a98bc0d1d00e 100644
--- a/content/copilot/how-tos/use-copilot-agents/copilot-memory/manage-as-administrator.md
+++ b/content/copilot/how-tos/use-copilot-agents/copilot-memory/manage-as-administrator.md
@@ -37,7 +37,7 @@ If the organization belongs to an enterprise, the ability for organization owner
{% data reusables.profile.access_org %}
{% data reusables.profile.org_settings %}
-1. In the sidebar, under "Code, planning, and automation", click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**, then click **Policies**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**, then click **Policies**.
1. Under "Features", scroll down to the setting for **{% data variables.copilot.copilot_memory %}**.
1. Click the dropdown button and select **Enabled**.
@@ -59,7 +59,7 @@ You can export user-level preferences in JSONL format. You can do this for every
{% data reusables.organizations.navigate-to-org %}
{% data reusables.organizations.org_settings %}
-1. In the sidebar, under "Code, planning, and automation", click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**, then click **Access**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**, then click **Access**.
1. From here, you can export preferences for everyone or for an individual user.
* For an individual user: Next to the user's name, click **{% octicon "kebab-horizontal" aria-label="Open seat options" %}**, then click **Export Copilot memories**.
@@ -73,7 +73,7 @@ You can delete user-level preferences in bulk or for individual users.
{% data reusables.organizations.navigate-to-org %}
{% data reusables.organizations.org_settings %}
-1. In the sidebar, under "Code, planning, and automation", click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**, then click **Access**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**, then click **Access**.
1. From here, you can delete preferences for everyone or for an individual user.
* For an individual user: Next to the user's name, click **{% octicon "kebab-horizontal" aria-label="Open seat options" %}**, then click **Delete Copilot memories**.
@@ -111,4 +111,4 @@ Events appear in your organization or enterprise's audit log when an administrat
## Further reading
-* [AUTOTITLE](/copilot/how-tos/use-copilot-agents/copilot-memory/manage-for-yourself)
\ No newline at end of file
+* [AUTOTITLE](/copilot/how-tos/use-copilot-agents/copilot-memory/manage-for-yourself)
diff --git a/content/copilot/tutorials/optimize-code-reviews.md b/content/copilot/tutorials/optimize-code-reviews.md
index f64f9e6f1ac2..cf5f425485d4 100644
--- a/content/copilot/tutorials/optimize-code-reviews.md
+++ b/content/copilot/tutorials/optimize-code-reviews.md
@@ -141,7 +141,6 @@ The response from {% data variables.product.prodname_copilot_short %} follows gu
Automatic review comments like these support you in building your own understanding when you're coding or can help you focus and narrow feedback given to others when reviewing.
-
## 3. Flag security vulnerabilities and fix them
Next, imagine you've been tasked to improve how passwords are stored in your order processing system. You submit a pull request with code you thought sufficiently hashed user passwords to protect them.
@@ -202,17 +201,26 @@ def check_password(password: str, known_hash):
> [!NOTE]
> * Always verify and validate any changes {% data variables.product.prodname_copilot_short %} suggests before accepting them.
-> * In this example, {% data variables.copilot.copilot_code-review_short %} may also highlight the need to generate unique salts.
+> * In this example, {% data variables.copilot.copilot_code-review_short %} may also highlight the need to generate unique salts.
+
+As you can see, identifying vulnerabilities automatically, along with suggestions for fixing them, helps you make security a priority. {% data variables.copilot.copilot_autofix_short %} enables you to focus on understanding secure coding and on fixes that work best for your code base and project.
+
+## 4. Add reliability, maintainability, and coverage checks
+
+So far, {% data variables.copilot.copilot_code-review_short %} has provided per-pull request feedback on style and design, and {% data variables.copilot.copilot_autofix_short %} for {% data variables.product.prodname_code_scanning %} has flagged and fixed security vulnerabilities. To focus on the long-term health of your code, {% data variables.product.prodname_code_quality %} adds reliability, maintainability, and code coverage checks. It combines deterministic, rules-based {% data variables.product.prodname_codeql %} analysis for well-defined anti-patterns with {% data variables.product.prodname_copilot_short %}-powered analysis for issues that fall outside existing rules, so the two approaches complement each other on every change.
+
+When {% data variables.product.prodname_code_quality_short %} is enabled, it posts reliability and maintainability findings as inline comments on the pull request, each with a one-click, {% data variables.product.prodname_copilot_short %}-powered autofix you can apply directly. It also reports coverage metrics that show whether the change maintains or reduces reported code coverage from your test suite compared to the default branch. If you want to enforce these standards, rulesets can require rules-based findings to be resolved and coverage thresholds to be met before merge.
-As you can see, identifying vulnerabilities automatically, along with suggestions for fixing them, helps you make security a priority. {% data variables.copilot.copilot_autofix_short %} enables you to focus on understanding secure coding and on fixes that work best for your code base and project.
+For more information, see [AUTOTITLE](/code-security/concepts/about-code-quality).
## Optimized reviews with {% data variables.product.prodname_copilot_short %}
Automatic review comments help you optimize your reviews and secure your code more efficiently regardless of your level of experience.
* Custom instructions helped refine the responses from {% data variables.copilot.copilot_code-review_short %} so they were specific to our project and user needs and we also saw how we can tailor how much explanation {% data variables.product.prodname_copilot_short %} provides in feedback.
-* {% data variables.copilot.copilot_code-review_short %} helped us quickly improve our error logging and understand why it mattered.
-* {% data variables.copilot.copilot_autofix_short %} for {% data variables.product.prodname_code_scanning %} helped us prevent using an insufficient password hashing approach and protect user data.
+* {% data variables.copilot.copilot_code-review_short %} helped us quickly improve our error logging and understand why it mattered.
+* {% data variables.copilot.copilot_autofix_short %} for {% data variables.product.prodname_code_scanning %} helped us prevent using an insufficient password hashing approach and protect user data.
+* {% data variables.product.prodname_code_quality %} flagged reliability and maintainability issues and reported code coverage on the pull request, and rulesets let us require those findings to be resolved and coverage thresholds to be met before merge.
## Next steps
@@ -221,6 +229,7 @@ To make your reviews more efficient and effective using {% data variables.produc
1. Create custom instructions specific to your project and repository. Write your own, or take inspiration from our library of examples. See [AUTOTITLE](/copilot/tutorials/customization-library/custom-instructions).
1. To enable automatic {% data variables.copilot.copilot_code-review_short %} for your repository, see [AUTOTITLE](/copilot/how-tos/copilot-on-github/set-up-copilot/configure-automatic-review).
1. To configure {% data variables.copilot.copilot_autofix_short %} for your repo you'll need to enable {% data variables.product.prodname_code_scanning %}. Once {% data variables.product.prodname_code_scanning %} with {% data variables.product.prodname_codeql %} analysis is enabled, {% data variables.copilot.copilot_autofix_short %} is enabled by default. For the easiest setup, see [AUTOTITLE](/code-security/how-tos/find-and-fix-code-vulnerabilities/configure-code-scanning/configure-code-scanning).
+1. To add reliability, maintainability, and coverage checks to your pull requests, enable {% data variables.product.prodname_code_quality %} for your repository. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/enable-code-quality).
## Further reading
diff --git a/content/copilot/tutorials/review-ai-generated-code.md b/content/copilot/tutorials/review-ai-generated-code.md
index 7d45f7c0c289..2718f4c2e9ed 100644
--- a/content/copilot/tutorials/review-ai-generated-code.md
+++ b/content/copilot/tutorials/review-ai-generated-code.md
@@ -22,6 +22,7 @@ Always run automated tests and static analysis tools first.
* Make sure the code compiles and all tests pass. Check for any new warnings or errors.
* Use tools like [{% data variables.product.prodname_codeql %}](https://codeql.github.com/) and [{% data variables.product.prodname_dependabot %}](/code-security/concepts/supply-chain-security/dependabot-version-updates) to catch vulnerabilities and dependency issues.
+* Use {% data variables.product.prodname_code_quality %} to catch reliability and maintainability issues and see code coverage. [AUTOTITLE](/code-security/concepts/about-code-quality).
* See [AUTOTITLE](/copilot/tutorials/copilot-cookbook/testing-code/generate-unit-tests) and [AUTOTITLE](/copilot/tutorials/copilot-cookbook/testing-code/create-end-to-end-tests) for examples of verifying code with {% data variables.product.prodname_copilot_short %}.
### Example prompts
@@ -48,7 +49,7 @@ Check that the AI-generated code fits the purpose and architecture of your proje
## 3. Assess code quality
-Human standards still matter.
+In addition to automated tools like {% data variables.product.prodname_code_quality %}, human standards still matter.
* Look for readability, maintainability, and clear naming.
* Avoid accepting code that is hard to follow or would take longer to refactor than to rewrite.
@@ -104,7 +105,7 @@ Pairing and team input helps catch subtle issues.
Let tools handle the repetitive work.
-* Set up CI checks for style, linting, and security.
+* Set up CI checks for style, linting, security, code quality and code coverage.
* Use {% data variables.product.prodname_dependabot %} for dependency updates and alerts.
* Apply {% data variables.product.prodname_codeql %} or similar scanners for static analysis.
* [AUTOTITLE](/copilot/how-tos/get-code-suggestions/find-matching-code) shows how {% data variables.product.prodname_copilot_short %} can help track down code patterns and automate search tasks.
diff --git a/content/copilot/tutorials/roll-out-at-scale/govern-at-scale/maintain-codebase-standards.md b/content/copilot/tutorials/roll-out-at-scale/govern-at-scale/maintain-codebase-standards.md
index be1faa7550af..19bef4034d35 100644
--- a/content/copilot/tutorials/roll-out-at-scale/govern-at-scale/maintain-codebase-standards.md
+++ b/content/copilot/tutorials/roll-out-at-scale/govern-at-scale/maintain-codebase-standards.md
@@ -86,4 +86,4 @@ To prepare for these scenarios, you should plan for how you will address problem
## 7. Check code quality
-If you're confident in your governance model but still concerned that {% data variables.product.prodname_copilot_short %} will reduce the quality of your codebase over time, you can measure this over the course of a rollout. If enabled, {% data variables.product.prodname_code_quality %} provides metrics on the code health of your repositories. See [AUTOTITLE](/code-security/concepts/about-code-quality).
+If you're confident in your governance model but still concerned that {% data variables.product.prodname_copilot_short %} will reduce the quality of your codebase over time, you can measure this over the course of a rollout. If enabled, {% data variables.product.prodname_code_quality %} provides metrics on the code health of your repositories. See [AUTOTITLE](/code-security/concepts/code-quality/code-quality).
diff --git a/content/issues/planning-and-tracking-with-projects/managing-your-project/managing-project-templates-in-your-organization.md b/content/issues/planning-and-tracking-with-projects/managing-your-project/managing-project-templates-in-your-organization.md
index fe9dfc483cfd..ebd4f1a76a91 100644
--- a/content/issues/planning-and-tracking-with-projects/managing-your-project/managing-project-templates-in-your-organization.md
+++ b/content/issues/planning-and-tracking-with-projects/managing-your-project/managing-project-templates-in-your-organization.md
@@ -66,7 +66,7 @@ You can add up to six templates to your organization's recommended templates.
{% data reusables.profile.access_org %}
{% data reusables.profile.org_settings %}
-1. In the "Code, planning, and automation" section of the sidebar, click **{% octicon "table" aria-hidden="true" aria-label="table" %} Projects**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "table" aria-hidden="true" aria-label="table" %} Projects**.
1. Under "Recommended templates", click **Customize recommended templates**.
1. In the list of templates owned by your organization, select up to six templates that you want to recommend to your members.
diff --git a/content/organizations/managing-organization-settings/allowing-project-visibility-changes-in-your-organization.md b/content/organizations/managing-organization-settings/allowing-project-visibility-changes-in-your-organization.md
index 669ad98ff7d2..795a3c2fcd97 100644
--- a/content/organizations/managing-organization-settings/allowing-project-visibility-changes-in-your-organization.md
+++ b/content/organizations/managing-organization-settings/allowing-project-visibility-changes-in-your-organization.md
@@ -26,7 +26,7 @@ This option may not be available to you if an enterprise owner restricts visibil
{% data reusables.profile.access_org %}
{% data reusables.profile.org_settings %}
-1. In the "Code, planning, and automation" section of the sidebar, click **{% octicon "table" aria-hidden="true" aria-label="table" %} Projects**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "table" aria-hidden="true" aria-label="table" %} Projects**.
1. To allow members to adjust project visibility, select **Allow members to change project visibilities for this organization**.
1. Click **Save**.
diff --git a/content/organizations/managing-organization-settings/managing-commit-comments-for-your-organization.md b/content/organizations/managing-organization-settings/managing-commit-comments-for-your-organization.md
index 48b01588e241..c41cabb54637 100644
--- a/content/organizations/managing-organization-settings/managing-commit-comments-for-your-organization.md
+++ b/content/organizations/managing-organization-settings/managing-commit-comments-for-your-organization.md
@@ -29,7 +29,7 @@ When you disable commit comments for your organization:
{% data reusables.profile.access_org %}
{% data reusables.profile.org_settings %}
-1. In the "Code, planning, and automation" section of the sidebar, select **{% octicon "repo" aria-hidden="true" aria-label="repo" %} Repository**, then click **General**.
+1. {% data reusables.user-settings.code-planning-automation %} select **{% octicon "repo" aria-hidden="true" aria-label="repo" %} Repository**, then click **General**.
1. Under "Commits", select or deselect **Allow comments on individual commits**.
diff --git a/content/organizations/managing-organization-settings/managing-rulesets-for-repositories-in-your-organization.md b/content/organizations/managing-organization-settings/managing-rulesets-for-repositories-in-your-organization.md
index 73d592775b7d..b49a595ce08c 100644
--- a/content/organizations/managing-organization-settings/managing-rulesets-for-repositories-in-your-organization.md
+++ b/content/organizations/managing-organization-settings/managing-rulesets-for-repositories-in-your-organization.md
@@ -88,7 +88,7 @@ You can view insights for rulesets to see how rulesets are affecting the reposit
{% data reusables.profile.access_org %}
{% data reusables.profile.org_settings %}
-1. In the left sidebar, in the "Code, planning, and automation" section, click **{% octicon "repo" aria-hidden="true" aria-label="repo" %} Repository**, then click **Rule insights**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "repo" aria-hidden="true" aria-label="repo" %} Repository**, then click **Rule insights**.

diff --git a/content/packages/learn-github-packages/configuring-a-packages-access-control-and-visibility.md b/content/packages/learn-github-packages/configuring-a-packages-access-control-and-visibility.md
index 90beacd26273..effef21506b3 100644
--- a/content/packages/learn-github-packages/configuring-a-packages-access-control-and-visibility.md
+++ b/content/packages/learn-github-packages/configuring-a-packages-access-control-and-visibility.md
@@ -100,7 +100,7 @@ If you disable automatic inheritance of access permissions, new packages scoped
{% data reusables.profile.access_org %}
{% data reusables.profile.org_settings %}
-1. In the sidebar, in the "Code, planning, and automation" section, click **{% octicon "package" aria-hidden="true" aria-label="package" %} Packages**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "package" aria-hidden="true" aria-label="package" %} Packages**.
1. Under "Default Package Settings", deselect **Inherit access from source repository**.
1. Click **Save**.
@@ -117,9 +117,9 @@ If you publish a package that is linked to a repository, {% data variables.produ
{% endif %}
{% ifversion org-automatic-registry-access %}
-
+
Granting a repository access here also allows {% data variables.product.prodname_dependabot %} to pull from this package automatically, without requiring {% data variables.product.pat_generic_plural %} or `dependabot.yml` registry configuration. See [AUTOTITLE](/code-security/concepts/supply-chain-security/automatic-dependabot-access-to-github-registries).
-
+
{% endif %}
> [!NOTE]
diff --git a/content/pages/configuring-a-custom-domain-for-your-github-pages-site/verifying-your-custom-domain-for-github-pages.md b/content/pages/configuring-a-custom-domain-for-your-github-pages-site/verifying-your-custom-domain-for-github-pages.md
index a6b116d44f6f..66c7713e6b6e 100644
--- a/content/pages/configuring-a-custom-domain-for-your-github-pages-site/verifying-your-custom-domain-for-github-pages.md
+++ b/content/pages/configuring-a-custom-domain-for-your-github-pages-site/verifying-your-custom-domain-for-github-pages.md
@@ -32,7 +32,7 @@ You may be verifying a domain you own, which is currently in use by another user
> If you don’t see the options described below, make sure you’re in your **Profile settings**, not your repository settings. Domain verification happens at the profile level.
{% data reusables.user-settings.access_settings %}
-1. In the "Code, planning, and automation" section of the sidebar, click **{% octicon "browser" aria-hidden="true" aria-label="browser" %} Pages**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "browser" aria-hidden="true" aria-label="browser" %} Pages**.
{% data reusables.pages.settings-verify-domain-setup %}
1. Wait for your DNS configuration to change, this may be immediate or take up to 24 hours. You can confirm the change to your DNS configuration by running the `dig` command on the command line. In the command below, replace `USERNAME` with your username and `example.com` with the domain you're verifying. If your DNS configuration has updated, you should see your new TXT record in the output.
@@ -51,7 +51,7 @@ Organization owners can verify custom domains for their organization.
{% data reusables.profile.access_org %}
{% data reusables.profile.org_settings %}
-1. In the "Code, planning, and automation" section of the sidebar, click **{% octicon "browser" aria-hidden="true" aria-label="browser" %} Pages**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "browser" aria-hidden="true" aria-label="browser" %} Pages**.
{% data reusables.pages.settings-verify-domain-setup %}
1. Wait for your DNS configuration to change. This may be immediate or take up to 24 hours. You can confirm the change to your DNS configuration by running the `dig` command on the command line. In the command below, replace `ORGANIZATION` with the name of your organization and `example.com` with the domain you're verifying. If your DNS configuration has updated, you should see your new TXT record in the output.
diff --git a/content/repositories/configuring-branches-and-merges-in-your-repository/managing-rulesets/available-rules-for-rulesets.md b/content/repositories/configuring-branches-and-merges-in-your-repository/managing-rulesets/available-rules-for-rulesets.md
index 74d9b1009ce9..39aebe5ab9fe 100644
--- a/content/repositories/configuring-branches-and-merges-in-your-repository/managing-rulesets/available-rules-for-rulesets.md
+++ b/content/repositories/configuring-branches-and-merges-in-your-repository/managing-rulesets/available-rules-for-rulesets.md
@@ -212,7 +212,7 @@ If your repositories are configured with {% data variables.product.prodname_code
* Analysis fails for any reason, for example: you have exhausted your budget for actions minutes.
* {% data variables.product.prodname_code_quality_short %} found a result of a severity of the level defined in the ruleset, or a higher severity.
-For more information, see [AUTOTITLE](/code-security/concepts/about-code-quality) and [AUTOTITLE](/code-security/how-tos/maintain-quality-code/set-pr-thresholds).
+For more information, see [AUTOTITLE](/code-security/concepts/code-quality/code-quality) and [AUTOTITLE](/code-security/how-tos/maintain-quality-code/set-pr-thresholds).
## Restrict code coverage
diff --git a/content/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-github-actions-settings-for-a-repository.md b/content/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-github-actions-settings-for-a-repository.md
index ed7d80972440..6ab5d995e479 100644
--- a/content/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-github-actions-settings-for-a-repository.md
+++ b/content/repositories/managing-your-repositorys-settings-and-features/enabling-features-for-your-repository/managing-github-actions-settings-for-a-repository.md
@@ -32,6 +32,14 @@ You can disable {% data variables.product.prodname_actions %} for a repository,
{% data reusables.repositories.settings-permissions-org-policy-note %}
+{% ifversion fpt or ghec %}
+
+> [!NOTE]
+> If you see **{% data variables.product.prodname_actions %} is currently disabled for this repository** or **{% data variables.product.prodname_actions %} is currently disabled for your account**, the repository or account may be in a separate {% data variables.product.github %}-controlled disabled state, and changing these settings won't restore access.
+> Contact {% data variables.contact.github_support %} for review.
+
+{% endif %}
+
{% data reusables.repositories.navigate-to-repo %}
{% data reusables.repositories.sidebar-settings %}
{% data reusables.repositories.settings-sidebar-actions-general %}
diff --git a/content/repositories/managing-your-repositorys-settings-and-features/repository-access-and-collaboration/removing-yourself-from-a-collaborators-repository.md b/content/repositories/managing-your-repositorys-settings-and-features/repository-access-and-collaboration/removing-yourself-from-a-collaborators-repository.md
index d3dd70b226fb..c09e5219bb0b 100644
--- a/content/repositories/managing-your-repositorys-settings-and-features/repository-access-and-collaboration/removing-yourself-from-a-collaborators-repository.md
+++ b/content/repositories/managing-your-repositorys-settings-and-features/repository-access-and-collaboration/removing-yourself-from-a-collaborators-repository.md
@@ -22,7 +22,7 @@ category:
- Manage access and repository policies
---
{% data reusables.user-settings.access_settings %}
-1. In the "Code, planning, and automation" section of the sidebar, click **{% octicon "repo" aria-hidden="true" aria-label="repo" %} Repositories**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "repo" aria-hidden="true" aria-label="repo" %} Repositories**.
1. Next to the repository you want to leave, click **Leave**.
1. Read the warning carefully, then click **I understand, leave this repository.**
diff --git a/content/rest/deployments/statuses.md b/content/rest/deployments/statuses.md
index 1af5f577e82d..a2e022a66158 100644
--- a/content/rest/deployments/statuses.md
+++ b/content/rest/deployments/statuses.md
@@ -12,6 +12,16 @@ category:
- Automate CI/CD workflows
---
+## About deployment statuses
+Deployment statuses allow external services to mark deployments with an `error`, `failure`, `inactive`, `in_progress`, `queued`, `pending`, or `success` state. Systems listening to [`deployment_status` events](/webhooks/webhook-events-and-payloads#deployment_status) can consume and respond to these statuses. A deployment status can also include an optional `description` and `log_url`.
+
+A deployment can accumulate multiple statuses over time as it progresses, for example from `pending` to `in_progress` to `success`. {% data variables.product.github %} tracks the most recent status for each deployment and uses it to display the deployment's current state.
+
+### Data retention
+
+{% data variables.product.github %} retains records of previous deployment statuses for **90 days**. Previous statuses older than 90 days are automatically deleted and are no longer returned by the REST API or GraphQL API.
+
+This retention policy applies to all deployment status endpoints, including [List deployment statuses](#list-deployment-statuses) and [Get a deployment status](#get-a-deployment-status). The current status of a deployment is not affected, because it is stored on the deployment itself and remains available regardless of the deployment's age.
diff --git a/content/webhooks/webhook-events-and-payloads.md b/content/webhooks/webhook-events-and-payloads.md
index 7d24ab24d484..d7cae5154078 100644
--- a/content/webhooks/webhook-events-and-payloads.md
+++ b/content/webhooks/webhook-events-and-payloads.md
@@ -27,6 +27,12 @@ Each webhook event on this page includes a description of the webhook properties
Each event is only available to specific types of webhooks. For example, an organization webhook can subscribe to the `team` event, but a repository webhook cannot. The description of each webhook event lists the availability for that event. For more information, see [AUTOTITLE](/webhooks/types-of-webhooks).
+### The `sender` property
+
+Most webhook payloads include a `sender` property identifying the user who triggered the event. Sometimes {% data variables.product.github %} can't resolve a specific user, for example when an event comes from an internal process rather than a person, or when the triggering action has no associated user. For some events, such as `check_run` and `check_suite`, this includes actions with no Git push or authenticated API actor.
+
+In these cases, `sender` is populated with the [`ghost` user](https://github.com/ghost), a placeholder account whose `login` is `ghost` and whose `id` isn't tied to a real, current user. Don't assume `sender` always identifies the person who caused an event, and account for the `ghost` user in any security or business logic that relies on it.
+
### Payload cap
{% data reusables.webhooks.payload_cap %}
diff --git a/data/reusables/actions/github-token-scope-descriptions.md b/data/reusables/actions/github-token-scope-descriptions.md
index 8be5e87337bd..5767e9b8c88d 100644
--- a/data/reusables/actions/github-token-scope-descriptions.md
+++ b/data/reusables/actions/github-token-scope-descriptions.md
@@ -13,7 +13,7 @@ Available permissions and details of what each allows an action to do:
| {% endif %} |
| `checks` | Work with check runs and check suites. For example, `checks: write` permits an action to create a check run. For more information, see [AUTOTITLE](/rest/authentication/permissions-required-for-github-apps?apiVersion=2022-11-28#repository-permissions-for-checks). |
| {% ifversion code-quality %} |
-| `code-quality` | Work with code quality. For example, `code-quality: write` permits an action to upload code coverage reports. For more information, see [AUTOTITLE](/code-security/concepts/about-code-quality). |
+| `code-quality` | Work with code quality. For example, `code-quality: write` permits an action to upload code coverage reports. For more information, see [AUTOTITLE](/code-security/concepts/code-quality/code-quality). |
| {% endif %} |
| `contents` | Work with the contents of the repository. For example, `contents: read` permits an action to list the commits, and `contents: write` allows the action to create a release. For more information, see [AUTOTITLE](/rest/authentication/permissions-required-for-github-apps?apiVersion=2022-11-28#repository-permissions-for-contents). |
| `deployments` | Work with deployments. For example, `deployments: write` permits an action to create a new deployment. For more information, see [AUTOTITLE](/rest/authentication/permissions-required-for-github-apps?apiVersion=2022-11-28#repository-permissions-for-deployments). |
diff --git a/data/reusables/code-quality/apply-suggestion.md b/data/reusables/code-quality/apply-suggestion.md
new file mode 100644
index 000000000000..012faf4c06af
--- /dev/null
+++ b/data/reusables/code-quality/apply-suggestion.md
@@ -0,0 +1 @@
+1. If you agree with the suggestion and you want to apply the fix, click **Commit suggestion**, or **Add suggestion to batch**.
diff --git a/data/reusables/code-quality/code-quality-org-targeting-preview-note.md b/data/reusables/code-quality/code-quality-org-targeting-preview-note.md
deleted file mode 100644
index f715443d3414..000000000000
--- a/data/reusables/code-quality/code-quality-org-targeting-preview-note.md
+++ /dev/null
@@ -1,2 +0,0 @@
-> [!NOTE]
-> Organization-level repository targeting for {% data variables.product.prodname_code_quality %} is in {% data variables.release-phases.public_preview %} and subject to change.
\ No newline at end of file
diff --git a/data/reusables/code-quality/fix-findings-with-cloud-agent.md b/data/reusables/code-quality/fix-findings-with-cloud-agent.md
index 7295d534a22e..6bb0da4ed2fd 100644
--- a/data/reusables/code-quality/fix-findings-with-cloud-agent.md
+++ b/data/reusables/code-quality/fix-findings-with-cloud-agent.md
@@ -1,4 +1,4 @@
-Alternatively, if you have a {% data variables.product.prodname_copilot_short %} license, you can delegate the remediation work to {% data variables.copilot.copilot_cloud_agent %}. Comment on the pull request mentioning `@{% data variables.product.prodname_copilot_short %}` and request that {% data variables.product.prodname_copilot_short %} fix the detected issues.
+If you have a {% data variables.product.prodname_copilot_short %} license, you can delegate the remediation work to {% data variables.copilot.copilot_cloud_agent %}. Comment on the pull request mentioning `@{% data variables.product.prodname_copilot_short %}` and request that {% data variables.product.prodname_copilot_short %} fix the detected issues.

@@ -10,4 +10,4 @@ You can track {% data variables.copilot.copilot_cloud_agent %}'s work:
* Using the [agents page](https://github.com/copilot/agents?ref_product=copilot&ref_type=engagement&ref_style=text) or session logs, see [AUTOTITLE](/copilot/how-tos/copilot-on-github/use-copilot-agents/manage-and-track-agents).
You need a {% data variables.product.prodname_copilot_short %} license to invoke {% data variables.copilot.copilot_cloud_agent %}.
-
Sign up for {% data variables.product.prodname_copilot_short %} {% octicon "link-external" height:16 aria-label="link-external" %}
+
Sign up for {% data variables.product.prodname_copilot_short %} {% octicon "link-external" height:16 aria-label="link-external" %}
diff --git a/data/reusables/code-quality/generate-autofix-from-dashboard.md b/data/reusables/code-quality/generate-autofix-from-dashboard.md
new file mode 100644
index 000000000000..3dbbc61c5618
--- /dev/null
+++ b/data/reusables/code-quality/generate-autofix-from-dashboard.md
@@ -0,0 +1,3 @@
+1. To the right of an individual finding, click **Generate fix**.
+1. Review the diff of the proposed change. If you agree with it, click **Open pull request**.
+1. In the "Commit autofix to branch" dialog, select "Open a pull request", then click **Commit change**.
diff --git a/data/reusables/code-quality/metrics-definitions-table.md b/data/reusables/code-quality/metrics-definitions-table.md
new file mode 100644
index 000000000000..82eef1562891
--- /dev/null
+++ b/data/reusables/code-quality/metrics-definitions-table.md
@@ -0,0 +1,4 @@
+| Metric | Definition | Example findings |
+|----------------|-----------------|----------------------|
+| **Reliability** | Assess whether the code performs its intended function correctly, predictably, and consistently. Reliable code is free from bugs, handles errors safely, and operates as expected under normal and edge-case conditions. | Issues with performance, concurrency, error handling, correctness |
+| **Maintainability** | Assess how easy it is to understand, modify, and extend the code over time. Maintainable code follows best practices, avoids unnecessary complexity, and is organized for ease of future changes and collaboration. | Unused/dead code, readability, complexity, conflicting naming, poor separation of concerns |
diff --git a/data/reusables/code-quality/recent-suggestions-preview-note.md b/data/reusables/code-quality/recent-suggestions-preview-note.md
new file mode 100644
index 000000000000..2fcc3757da37
--- /dev/null
+++ b/data/reusables/code-quality/recent-suggestions-preview-note.md
@@ -0,0 +1,2 @@
+> [!NOTE]
+> The "{% data variables.code-quality.recent_suggestions %}" page for recently changed files is currently in {% data variables.release-phases.public_preview %} and subject to change.
diff --git a/data/reusables/code-quality/review-comment-and-autofix.md b/data/reusables/code-quality/review-comment-and-autofix.md
new file mode 100644
index 000000000000..9cfa3cc5b5ab
--- /dev/null
+++ b/data/reusables/code-quality/review-comment-and-autofix.md
@@ -0,0 +1 @@
+1. Carefully review the comment and the suggested autofix for logic, security, and style.
diff --git a/data/reusables/code-quality/severity-levels-table.md b/data/reusables/code-quality/severity-levels-table.md
new file mode 100644
index 000000000000..c634bf277396
--- /dev/null
+++ b/data/reusables/code-quality/severity-levels-table.md
@@ -0,0 +1,5 @@
+| Severity | Definition |
+|-----------|--------------------|
+| **Error** | Indicates a high-severity issue that is likely to cause bugs, failures, or major maintainability risks. |
+| **Warning** | Indicates a moderate-severity issue that may impact code quality or reliability, but is not immediately critical. |
+| **Note** | Indicates a low-severity issue, minor improvement, or recommendation. These findings are useful for ongoing code health and maintainability. |
diff --git a/data/reusables/codespaces/accessing-prebuild-configuration.md b/data/reusables/codespaces/accessing-prebuild-configuration.md
index 6894ed8c0d1c..7f74faca5ea1 100644
--- a/data/reusables/codespaces/accessing-prebuild-configuration.md
+++ b/data/reusables/codespaces/accessing-prebuild-configuration.md
@@ -1,3 +1,3 @@
{% data reusables.repositories.navigate-to-repo %}
{% data reusables.repositories.sidebar-settings %}
-1. In the "Code & automation" section of the side bar, click **{% octicon "codespaces" aria-hidden="true" aria-label="codespaces" %} {% data variables.product.prodname_codespaces %}**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "codespaces" aria-hidden="true" aria-label="codespaces" %} {% data variables.product.prodname_codespaces %}**.
diff --git a/data/reusables/codespaces/codespaces-org-policies.md b/data/reusables/codespaces/codespaces-org-policies.md
index 807edcf95265..7cab312da8dc 100644
--- a/data/reusables/codespaces/codespaces-org-policies.md
+++ b/data/reusables/codespaces/codespaces-org-policies.md
@@ -1,3 +1,3 @@
-1. In the "Code, planning, and automation" section of the sidebar, select **{% octicon "codespaces" aria-hidden="true" aria-label="codespaces" %} {% data variables.product.prodname_codespaces %}** then click **Policies**.
+1. {% data reusables.user-settings.code-planning-automation %} select **{% octicon "codespaces" aria-hidden="true" aria-label="codespaces" %} {% data variables.product.prodname_codespaces %}** then click **Policies**.
1. On the "Codespaces policies" page, click **Create Policy**.
1. Enter a name for your new policy.
diff --git a/data/reusables/copilot/access-settings.md b/data/reusables/copilot/access-settings.md
index 75623e8d0091..2b6b6d4f4e7e 100644
--- a/data/reusables/copilot/access-settings.md
+++ b/data/reusables/copilot/access-settings.md
@@ -1 +1 @@
-1. In the "Code, planning, and automation" section of the sidebar, click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**, and then click **Access**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**, and then click **Access**.
diff --git a/data/reusables/copilot/cloud-agent-settings.md b/data/reusables/copilot/cloud-agent-settings.md
index 246489e5e4fc..d61c412e6383 100644
--- a/data/reusables/copilot/cloud-agent-settings.md
+++ b/data/reusables/copilot/cloud-agent-settings.md
@@ -1 +1 @@
-1. In the sidebar, under "Code, planning, and automation", click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**, and then click **{% data variables.copilot.copilot_cloud_agent_short_cap_c %}**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**, and then click **{% data variables.copilot.copilot_cloud_agent_short_cap_c %}**.
diff --git a/data/reusables/copilot/custom-instructions-enabling-for-ccr.md b/data/reusables/copilot/custom-instructions-enabling-for-ccr.md
index a651baa7dd00..ed27adf27038 100644
--- a/data/reusables/copilot/custom-instructions-enabling-for-ccr.md
+++ b/data/reusables/copilot/custom-instructions-enabling-for-ccr.md
@@ -4,5 +4,5 @@ Custom instructions are enabled for {% data variables.copilot.copilot_code-revie
{% data reusables.repositories.navigate-to-repo %}
{% data reusables.repositories.sidebar-settings %}
-1. In the "Code & automation" section of the sidebar, click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**, then **Code review**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "copilot" aria-hidden="true" aria-label="copilot" %} {% data variables.product.prodname_copilot_short %}**, then **Code review**.
1. Toggle the “Use custom instructions when reviewing pull requests” option on or off.
diff --git a/data/reusables/copilot/manage-repo-memories.md b/data/reusables/copilot/manage-repo-memories.md
index 746d5ad94d23..54ea9fd5a7f1 100644
--- a/data/reusables/copilot/manage-repo-memories.md
+++ b/data/reusables/copilot/manage-repo-memories.md
@@ -1,4 +1,4 @@
{% data reusables.repositories.navigate-to-repo %}
{% data reusables.repositories.sidebar-settings %}
-1. In the "Code & automation" section of the sidebar, click {% data variables.product.prodname_copilot_short %}, then click **Memory**.
+1. {% data reusables.user-settings.code-planning-automation %} click {% data variables.product.prodname_copilot_short %}, then click **Memory**.
1. You will see a list of repository-level facts, which you can delete as needed.
diff --git a/data/reusables/issues/access-issue-types-settings.md b/data/reusables/issues/access-issue-types-settings.md
index 01ffc487b727..fcc0cbd04b9d 100644
--- a/data/reusables/issues/access-issue-types-settings.md
+++ b/data/reusables/issues/access-issue-types-settings.md
@@ -1,3 +1,3 @@
{% data reusables.profile.access_org %}
{% data reusables.profile.org_settings %}
-1. In the "Code, planning, and automation" section of the sidebar, select **{% octicon "table" aria-hidden="true" aria-label="table" %} Planning**, then click **Issue types**.
+1. {% data reusables.user-settings.code-planning-automation %} select **{% octicon "table" aria-hidden="true" aria-label="table" %} Planning**, then click **Issue types**.
diff --git a/data/reusables/organizations/access-custom-properties.md b/data/reusables/organizations/access-custom-properties.md
index e67040a41e59..fd4514e5d644 100644
--- a/data/reusables/organizations/access-custom-properties.md
+++ b/data/reusables/organizations/access-custom-properties.md
@@ -1,3 +1,3 @@
-1. In the left sidebar, in the "Code, planning, and automation" section, click **{% octicon "repo" aria-hidden="true" aria-label="repo" %} Repository**, then click **Custom properties**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "repo" aria-hidden="true" aria-label="repo" %} Repository**, then click **Custom properties**.

diff --git a/data/reusables/organizations/access-ruleset-settings.md b/data/reusables/organizations/access-ruleset-settings.md
index e1da69893ac2..2c2988c2f5d6 100644
--- a/data/reusables/organizations/access-ruleset-settings.md
+++ b/data/reusables/organizations/access-ruleset-settings.md
@@ -1,3 +1,3 @@
-1. In the left sidebar, in the "Code, planning, and automation" section, click **{% octicon "repo" aria-hidden="true" aria-label="repo" %} Repository**, then click **Rulesets**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "repo" aria-hidden="true" aria-label="repo" %} Repository**, then click **Rulesets**.

diff --git a/data/reusables/organizations/custom-models.md b/data/reusables/organizations/custom-models.md
index 549e2954e2f5..b47ea977ef39 100644
--- a/data/reusables/organizations/custom-models.md
+++ b/data/reusables/organizations/custom-models.md
@@ -1 +1 @@
-1. In the "Code, planning, and automation" section of the sidebar, click **{% octicon "ai-model" aria-hidden="true" aria-label="ai-model" %} Models** dropdown. Then click **Custom models**. The "Custom Models" page displays the API keys and custom models added to the organization.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "ai-model" aria-hidden="true" aria-label="ai-model" %} Models** dropdown. Then click **Custom models**. The "Custom Models" page displays the API keys and custom models added to the organization.
diff --git a/data/reusables/organizations/models-development.md b/data/reusables/organizations/models-development.md
index 731e98c9db3a..5ffe396b8a91 100644
--- a/data/reusables/organizations/models-development.md
+++ b/data/reusables/organizations/models-development.md
@@ -1 +1 @@
-1. In the "Code, planning, and automation" section of the sidebar, click the **{% octicon "ai-model" aria-hidden="true" aria-label="ai-model" %} Models** dropdown. Then click **Development**.
+1. {% data reusables.user-settings.code-planning-automation %} click the **{% octicon "ai-model" aria-hidden="true" aria-label="ai-model" %} Models** dropdown. Then click **Development**.
diff --git a/data/reusables/organizations/repository-defaults.md b/data/reusables/organizations/repository-defaults.md
index 4b8d22ee774a..6bc1c5a6f064 100644
--- a/data/reusables/organizations/repository-defaults.md
+++ b/data/reusables/organizations/repository-defaults.md
@@ -1 +1 @@
-1. In the "Code, planning, and automation" section of the sidebar, select **{% octicon "repo" aria-hidden="true" aria-label="repo" %} Repository**, then click **Repository defaults**.
+1. {% data reusables.user-settings.code-planning-automation %} select **{% octicon "repo" aria-hidden="true" aria-label="repo" %} Repository**, then click **Repository defaults**.
diff --git a/data/reusables/pull_requests/rebase_and_merge_summary.md b/data/reusables/pull_requests/rebase_and_merge_summary.md
index 32e0b7340b4e..175798b1262a 100644
--- a/data/reusables/pull_requests/rebase_and_merge_summary.md
+++ b/data/reusables/pull_requests/rebase_and_merge_summary.md
@@ -1,6 +1,11 @@
When you select the **Rebase and merge** option on a pull request, all commits from the topic branch (or head branch) are added onto the base branch individually without a merge commit. In that way, the rebase and merge behavior resembles a [fast-forward merge](https://git-scm.com/docs/git-merge#_fast_forward_merge) by maintaining a linear project history. However, rebasing achieves this by re-writing the commit history on the base branch with new commits.
-The rebase and merge behavior on {% data variables.product.github %} deviates slightly from `git rebase`. Rebase and merge on {% data variables.product.prodname_dotcom %} will always update the committer information and create new commit SHAs, whereas `git rebase` outside of {% data variables.product.prodname_dotcom %} does not change the committer information when the rebase happens on top of an ancestor commit. For more information about `git rebase`, see [git-rebase](https://git-scm.com/docs/git-rebase) in the Git documentation.
+The rebase and merge behavior on {% data variables.product.github %} deviates slightly from `git rebase` outside of {% data variables.product.prodname_dotcom %}. Rebase and merge on {% data variables.product.prodname_dotcom %}:
+
+* Always updates the committer information and creates new commit SHAs, whereas `git rebase` does not change the committer information when the rebase happens on top of an ancestor commit.
+* Drops commits that were empty to begin with, such as those created with `git commit --allow-empty`, whereas `git rebase` keeps originally-empty commits by default.
+
+For more information about `git rebase`, see [git-rebase](https://git-scm.com/docs/git-rebase) in the Git documentation.
To rebase and merge pull requests, you must have [write permissions](/organizations/managing-user-access-to-your-organizations-repositories/managing-repository-roles/repository-roles-for-an-organization) in the repository, and the repository must [allow rebase merging](/repositories/configuring-branches-and-merges-in-your-repository/configuring-pull-request-merges/configuring-commit-rebasing-for-pull-requests).
diff --git a/data/reusables/user-settings/code-planning-automation.md b/data/reusables/user-settings/code-planning-automation.md
new file mode 100644
index 000000000000..ca07196c9766
--- /dev/null
+++ b/data/reusables/user-settings/code-planning-automation.md
@@ -0,0 +1 @@
+In the sidebar, under "Code, planning, and automation",
diff --git a/data/reusables/user-settings/codespaces-tab.md b/data/reusables/user-settings/codespaces-tab.md
index 9b5c4da22e81..16a8ce4ad002 100644
--- a/data/reusables/user-settings/codespaces-tab.md
+++ b/data/reusables/user-settings/codespaces-tab.md
@@ -1 +1 @@
-1. In the "Code, planning, and automation" section of the sidebar, click **{% octicon "codespaces" aria-hidden="true" aria-label="codespaces" %} Codespaces**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "codespaces" aria-hidden="true" aria-label="codespaces" %} Codespaces**.
diff --git a/data/reusables/user-settings/saved_replies.md b/data/reusables/user-settings/saved_replies.md
index 38a0b4e2d89a..6035cd6b7510 100644
--- a/data/reusables/user-settings/saved_replies.md
+++ b/data/reusables/user-settings/saved_replies.md
@@ -1 +1 @@
-1. In the "Code, planning, and automation" section of the sidebar, click **{% octicon "reply" aria-hidden="true" aria-label="reply" %} Saved replies**.
+1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "reply" aria-hidden="true" aria-label="reply" %} Saved replies**.