diff --git a/assets/images/help/models/github-models-commit-changes.png b/assets/images/help/models/github-models-commit-changes.png deleted file mode 100644 index 72dec7e8b4ea..000000000000 Binary files a/assets/images/help/models/github-models-commit-changes.png and /dev/null differ diff --git a/assets/images/help/models/github-models-compare-toggle.png b/assets/images/help/models/github-models-compare-toggle.png deleted file mode 100644 index f8d28fcd956b..000000000000 Binary files a/assets/images/help/models/github-models-compare-toggle.png and /dev/null differ diff --git a/assets/images/help/models/github-models-datasets.png b/assets/images/help/models/github-models-datasets.png deleted file mode 100644 index bfc1e531a99e..000000000000 Binary files a/assets/images/help/models/github-models-datasets.png and /dev/null differ diff --git a/assets/images/help/models/github-models-system-prompt.png b/assets/images/help/models/github-models-system-prompt.png deleted file mode 100644 index bfd3ed25c275..000000000000 Binary files a/assets/images/help/models/github-models-system-prompt.png and /dev/null differ diff --git a/assets/images/help/models/model-playground-code-tab.png b/assets/images/help/models/model-playground-code-tab.png deleted file mode 100644 index ad09f8cebb97..000000000000 Binary files a/assets/images/help/models/model-playground-code-tab.png and /dev/null differ diff --git a/assets/images/help/models/model-playground-prompt-editor.png b/assets/images/help/models/model-playground-prompt-editor.png deleted file mode 100644 index 91dc1973d4b3..000000000000 Binary files a/assets/images/help/models/model-playground-prompt-editor.png and /dev/null differ diff --git a/data/reusables/enterprise/repo-policy-rules-manage-bypass-request.md b/content/admin/managing-accounts-and-repositories/managing-repositories-in-your-enterprise/bypass-push-rules-requests.md similarity index 71% rename from data/reusables/enterprise/repo-policy-rules-manage-bypass-request.md rename to content/admin/managing-accounts-and-repositories/managing-repositories-in-your-enterprise/bypass-push-rules-requests.md index 6911eb65fcef..e8269ba25c59 100644 --- a/data/reusables/enterprise/repo-policy-rules-manage-bypass-request.md +++ b/content/admin/managing-accounts-and-repositories/managing-repositories-in-your-enterprise/bypass-push-rules-requests.md @@ -1,10 +1,21 @@ -## Managing requests to bypass push rules +--- +title: Managing requests to bypass push rules +intro: View and manage requests for bypass privileges to push commits containing restricted content to a repository. +allowTitleToDifferFromFilename: true +permissions: Enterprise owners +versions: + feature: repo-policy-rules +shortTitle: Manage requests to bypass push rules +contentType: how-tos +category: + - Manage accounts and repositories +--- > [!NOTE] Repository policy delegated bypass is in {% data variables.release-phases.public_preview %} and subject to change. You can view and manage all requests for bypass privileges on the “Bypass Requests" page, located under the **Policy** settings. -You can filter requests by approver (member of the bypass list), requester (contributor making the request), timeframe, and status. The following statuses are assigned to a request: +Filter requests by approver (member of the bypass list), requester (contributor making the request), timeframe, and status. The following statuses are assigned to a request: |Status|Description| |---------|-----------| diff --git a/content/admin/managing-accounts-and-repositories/managing-repositories-in-your-enterprise/governing-how-people-use-repositories-in-your-enterprise.md b/content/admin/managing-accounts-and-repositories/managing-repositories-in-your-enterprise/governing-how-people-use-repositories-in-your-enterprise.md index 7d242ec14483..7a032ed68348 100644 --- a/content/admin/managing-accounts-and-repositories/managing-repositories-in-your-enterprise/governing-how-people-use-repositories-in-your-enterprise.md +++ b/content/admin/managing-accounts-and-repositories/managing-repositories-in-your-enterprise/governing-how-people-use-repositories-in-your-enterprise.md @@ -8,14 +8,14 @@ shortTitle: Govern repository usage contentType: how-tos category: - Manage accounts and repositories +redirect_from: + - /enterprise-onboarding/govern-people-and-repositories/create-repository-policies --- {% data reusables.enterprise.repo-policy-rules-preview %} {% data reusables.enterprise.repo-policy-rules-intro %} ->[!TIP] If you're an **organization owner**, you can create a repository policy for a specific organization. See [AUTOTITLE](/organizations/managing-organization-settings/governing-how-people-use-repositories-in-your-organization). - ## Examples {% data reusables.enterprise.repo-policy-rules-examples %} @@ -24,7 +24,9 @@ category: First, you'll target organizations in your enterprise. You can select all organizations, choose from a list, or create a dynamic rule using `fnmatch` syntax. If you use {% data variables.product.prodname_emus %}, you can also choose to target all repositories owned by users in your enterprise. -Then, you'll target repositories in the selected organizations. {% data reusables.enterprise.repo-policy-rules-with-custom-properties %} +Then, you'll target repositories in the selected organizations. We recommend using repository policies alongside **custom repository properties**. By adding custom properties to repositories, you can flexibly target those repositories in a policy. + +For example, you can add a property to mark repositories that contain production data or other sensitive information, then prevent anyone from making those repositories public. ## Interaction with other policies @@ -73,11 +75,3 @@ Choose which repositories (current or future) to target in the selected organiza ### Delegating bypass of policies {% data reusables.enterprise.repo-policy-rules-delegated-bypass %} - -#### Managing bypass requests - -{% data reusables.enterprise.repo-policy-rules-manage-bypass-request %} - -## Further reading - -To set additional policies for repository management, see [AUTOTITLE](/admin/enforcing-policies/enforcing-policies-for-your-enterprise/enforcing-repository-management-policies-in-your-enterprise). diff --git a/content/admin/managing-accounts-and-repositories/managing-repositories-in-your-enterprise/index.md b/content/admin/managing-accounts-and-repositories/managing-repositories-in-your-enterprise/index.md index 399ed882475d..3070b85282ae 100644 --- a/content/admin/managing-accounts-and-repositories/managing-repositories-in-your-enterprise/index.md +++ b/content/admin/managing-accounts-and-repositories/managing-repositories-in-your-enterprise/index.md @@ -10,6 +10,7 @@ versions: ghes: '*' children: - /governing-how-people-use-repositories-in-your-enterprise + - /bypass-push-rules-requests - /viewing-user-owned-repositories-in-your-enterprise - /accessing-user-owned-repositories-in-your-enterprise - /managing-custom-properties-for-repositories-in-your-enterprise diff --git a/content/billing/concepts/product-billing/github-code-quality.md b/content/billing/concepts/product-billing/github-code-quality.md index 07183cbe1fc0..f2d154ff9ef6 100644 --- a/content/billing/concepts/product-billing/github-code-quality.md +++ b/content/billing/concepts/product-billing/github-code-quality.md @@ -37,7 +37,6 @@ For more information about how {% data variables.product.prodname_ai_credits_sho * Your license usage is calculated based on the number of unique, active committers to repositories with {% data variables.product.prodname_code_quality_short %} enabled. * Each **active committer** uses **one {% data variables.product.prodname_code_quality_short %} license**. * A committer is considered active if one of their commits has been pushed to the repository within the last 90 days, regardless of when it was originally authored. -* A committer is considered active if one of their commits has been pushed to the repository within the last 90 days, regardless of when it was originally authored. To understand your license usage, and which licenses you can free up, it helps to distinguish between active and unique committers. You can see the number of licenses you're using on the **Licensing** page for your organization or enterprise, shown as **"Consumed licenses"**: * **Active committers** are committers who contributed to at least one repository and have a {% data variables.product.prodname_team %} or {% data variables.product.prodname_enterprise %} license with your organization or enterprise. This includes members, enterprise-managed users, external collaborators, and people with a pending invitation to join your organization or enterprise. diff --git a/content/code-security/concepts/code-quality/automatic-code-coverage-setup.md b/content/code-security/concepts/code-quality/automatic-code-coverage-setup.md new file mode 100644 index 000000000000..45a25196f1ae --- /dev/null +++ b/content/code-security/concepts/code-quality/automatic-code-coverage-setup.md @@ -0,0 +1,48 @@ +--- +title: Automatic code coverage setup +shortTitle: Automatic code coverage +intro: 'An AI-powered agent can analyze your repository and generate a working code coverage workflow, so you can start tracking test coverage without manually authoring CI configuration.' +versions: + feature: code-quality +product: '{% data reusables.gated-features.code-quality-availability %}' +contentType: concepts +category: + - Improve code quality +--- + +When you use automatic setup for code coverage, an AI-powered agent analyzes your repository, identifies your test framework, and opens a pull request with a coverage workflow ready for review. + +**There is no additional cost for using this feature.** + +## How the agent works + +The agent works in three phases: + +1. **Discovery:** The agent reads your CI configuration, documentation, and build files to understand your project structure and identify your test framework. +1. **Execution:** The agent installs dependencies, builds the project, and runs your tests with coverage enabled. If coverage tooling is not already configured, the agent adds it to your project configuration (for example, `vitest.config.ts` or `jest.config.js`). +1. **Workflow integration:** If the agent produces a valid coverage report, it checks whether your repository already has a {% data variables.product.prodname_actions %} workflow that runs tests on pull requests. If so, the agent augments that workflow with a coverage upload step. If not, it creates a new workflow file and opens a pull request. + +## When the agent stops + +The agent may stop before opening a pull request in the following situations: + +* **No tests found.** The agent couldn't find tests to instrument, so there's nothing to generate coverage for. +* **Can't reproduce the build.** Missing private registries, proprietary SDKs, or system dependencies prevent the agent from verifying the test suite. + +If the agent stops or produces unexpected results, you can review the agent's session log for details. Navigate to the **Tasks** tab in your repository to find the session associated with the workflow generation attempt. +* **Unsupported coverage report conversion.** The agent won't reconstruct Cobertura XML from reports that only expose aggregated counters. For example, JaCoCo XML does not contain enough line and branch structure for a trustworthy Cobertura upload, so JVM projects that only produce JaCoCo XML may need manual setup instead. +## Pull request outcomes + +> [!NOTE] +> The agent opens the pull request immediately with an initial planning commit that contains no code changes. The actual implementation commit typically arrives a few minutes later. If the pull request initially shows 0 changed files, wait a few minutes and refresh the page. + +If the agent successfully opens a pull request, the pull request may be in one of these states: + +* **Mergeable as-is:** The workflow completes successfully in CI and coverage uploads correctly. +* **Ready to iterate:** The workflow runs but requires adjustments (for example, missing secrets, self-hosted runner configuration, or path differences between local verification and CI). +* **Useful as a reference:** Maintainers may prefer to configure coverage themselves, using the agent's pull request as a starting point for the build and test commands it discovered. + +## Further reading + +* [AUTOTITLE](/code-security/how-tos/maintain-quality-code/set-up-code-coverage#automatic-setup) +* [AUTOTITLE](/code-security/concepts/code-quality/code-quality) diff --git a/content/code-security/concepts/code-quality/index.md b/content/code-security/concepts/code-quality/index.md index e3760a936fc2..97784f22ecd9 100644 --- a/content/code-security/concepts/code-quality/index.md +++ b/content/code-security/concepts/code-quality/index.md @@ -8,4 +8,5 @@ contentType: concepts children: - /code-quality - /enablement-at-scale + - /automatic-code-coverage-setup --- diff --git a/content/code-security/how-tos/maintain-quality-code/enable-code-quality.md b/content/code-security/how-tos/maintain-quality-code/enable-code-quality.md index c9da93a59dd6..f4522451a298 100644 --- a/content/code-security/how-tos/maintain-quality-code/enable-code-quality.md +++ b/content/code-security/how-tos/maintain-quality-code/enable-code-quality.md @@ -59,5 +59,5 @@ If you're rolling out the feature across many teams, we recommend you pilot on a ## Next steps -* **Add code coverage:** Upload reported code coverage from your test suite to see coverage results directly on pull requests. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/set-up-code-coverage). +* **Add code coverage:** Upload reported code coverage from your test suite to see coverage results directly on pull requests. {% data reusables.code-quality.workflow-generation %} * **For your organization:** Understand the code health of your repositories at a glance. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/explore-code-quality). diff --git a/content/code-security/how-tos/maintain-quality-code/set-up-code-coverage.md b/content/code-security/how-tos/maintain-quality-code/set-up-code-coverage.md index b764100cbf88..1f593e4c9e26 100644 --- a/content/code-security/how-tos/maintain-quality-code/set-up-code-coverage.md +++ b/content/code-security/how-tos/maintain-quality-code/set-up-code-coverage.md @@ -14,15 +14,55 @@ category: - Improve code quality --- +You can set up code coverage for your repository in two ways: + +* **Automatic setup:** Use the AI-powered agent to generate a workflow automatically. Choose this option if: + * You want to get started quickly without writing YAML configuration. + * Your project uses common test frameworks and build patterns. + * You're comfortable iterating on an AI-generated workflow. +* **Manual setup:** Configure your CI workflow yourself. Choose this option if: + * You need precise control over the coverage process. + * You have complex CI requirements (such as private registries or custom build steps). + * You want to understand exactly how coverage is configured. + +## Automatic setup + +You can use the automatic setup option to generate a working code coverage workflow without manually authoring CI configuration. An agent analyzes your repository, identifies your test framework, and opens a pull request with a coverage workflow ready for review. + +> [!NOTE] +> Automatic setup uses AI to generate the workflow file. There is no additional cost for using this feature. + +### Prerequisites for automatic setup + +* {% data variables.product.prodname_code_quality_short %} is enabled for your repository. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/enable-code-quality). +* Your repository has an existing test suite. + +### Generating a coverage workflow automatically + +{% data reusables.repositories.navigate-to-repo %} +{% data reusables.repositories.sidebar-settings %} +1. In the sidebar, under "Security", click **{% data variables.code-quality.code_quality_ui_settings %}** to display the "{% data variables.code-quality.code_quality_ui %}" page. +1. In the "Code coverage analysis" section, click the **Setup** dropdown box. +1. In the list, select **Generate workflow with AI**. Wait for the agent to analyze your repository. The agent opens a draft pull request and posts a checklist of the steps it is working through. +1. To review the pull request, click **Review pull request**. + Review the pull request once the agent completes its work. The pull request description summarizes the changes, including any project configuration updates, workflow file changes, and coverage output settings. +1. If the workflow runs successfully in CI and coverage uploads correctly, merge the pull request. + + If the workflow needs adjustments, see [AUTOTITLE](/code-security/concepts/code-quality/automatic-code-coverage-setup) for guidance on the different outcomes and how to iterate. + +For more information about how the agent works and what to expect, see [AUTOTITLE](/code-security/concepts/code-quality/automatic-code-coverage-setup). + +## Manual setup + Built-in code coverage lets you track how thoroughly your tests exercise your code, without adding a third-party service to your toolchain or budget. In the following procedures, you will generate a Cobertura XML coverage report from your test suite, upload it to {% data variables.product.github %}, and view the coverage results on your pull requests. -## Prerequisites +### Prerequisites for manual setup * {% data variables.product.prodname_code_quality_short %} is enabled for your repository. * Your repository has a test suite that runs in {% data variables.product.prodname_actions %}. * Your test framework can produce a coverage report in **Cobertura XML** format. -## Step 1: Generate a Cobertura XML coverage report +### Step 1: Generate a Cobertura XML coverage report Configure your test framework to output a coverage report in the Cobertura XML format. Code coverage works with any programming language that can produce this format. @@ -40,7 +80,7 @@ Configure your test framework to output a coverage report in the Cobertura XML f > [!TIP] > If your framework isn't listed above, check its documentation for Cobertura output support. Many tools either support it directly or can convert to Cobertura XML from other formats. -## Step 2: Upload the coverage report +### Step 2: Upload the coverage report After your tests generate a Cobertura XML report, upload it to {% data variables.product.github %} so coverage results appear on pull requests. @@ -117,7 +157,7 @@ jobs: label: code-coverage/pytest ``` -## Step 3: View coverage results on pull requests +### Step 3: View coverage results on pull requests 1. Open a pull request (or push to an existing one) that triggers the workflow you configured. 1. After the workflow completes, look for a comment from `{% data variables.code-quality.pr_commenter %}` on the pull request. The comment includes: diff --git a/content/code-security/responsible-use/security-and-quality-ai-features.md b/content/code-security/responsible-use/security-and-quality-ai-features.md index b317a14f492a..269dc6a16335 100644 --- a/content/code-security/responsible-use/security-and-quality-ai-features.md +++ b/content/code-security/responsible-use/security-and-quality-ai-features.md @@ -40,7 +40,7 @@ GitHub's security and quality platform includes several AI-powered capabilities * **Copilot Autofix for code scanning**: Automatically generates fix suggestions for CodeQL alerts on pull requests and the default branch. * **Generic secret detection**: Uses a model to identify unstructured secrets in source code that deterministic pattern matching cannot find. * **Custom pattern regex generator**: Uses AI to generate regular expressions for custom secret scanning patterns from natural language descriptions. -* **GitHub Code Quality**: Surfaces code quality issues and offers LLM-powered fix suggestions on pull requests and the default branch. +* **GitHub Code Quality**: Surfaces code quality issues and offers LLM-powered fix suggestions on pull requests and the default branch. Also provides AI-powered automatic generation of code coverage workflows. Copilot Autofix is an expansion of code scanning that provides users with targeted recommendations to help them fix code scanning alerts, avoiding the introduction of new security vulnerabilities. Potential fixes are generated automatically by large language models (LLMs) using data from the codebase and from code scanning analysis. Copilot Autofix is available for CodeQL analysis and does not require a GitHub Copilot subscription. @@ -50,7 +50,7 @@ Secret scanning's generic secret detection is an AI-powered expansion of secret Secret scanning's custom pattern regular expression generator makes it possible to define custom secret scanning patterns without knowledge of regular expressions. Users input a natural language description of what they want to detect, along with optional example strings, and the generator produces up to three candidate regular expressions. These patterns can then be validated via the dry-run mechanism before being deployed as custom patterns. The regular expression generator does not require a GitHub Copilot subscription. -GitHub Code Quality helps users improve code reliability, maintainability, and overall project health by surfacing actionable feedback and offering automatic fixes for findings in pull requests and on the default branch. When Code Quality is enabled, two types of analysis run: CodeQL quality queries identify problems with the maintainability, reliability, or style of code, and LLM-powered analysis provides additional insights beyond what deterministic engines can find. When a quality issue is detected, Copilot Autofix suggests a relevant fix. On pull requests, results are displayed as comments left by the `github-code-quality` bot. On the default branch, LLM-powered findings are displayed in the **AI findings** dashboard under the **{% octicon "shield" aria-hidden="true" aria-label="shield" %} {% ifversion security-and-quality-tab %}Security and quality{% else %}Security{% endif %}** tab. +GitHub Code Quality helps users improve code reliability, maintainability, and overall project health by surfacing actionable feedback and offering automatic fixes for findings in pull requests and on the default branch. When Code Quality is enabled, two types of analysis run: CodeQL quality queries identify problems with the maintainability, reliability, or style of code, and LLM-powered analysis provides additional insights beyond what deterministic engines can find. When a quality issue is detected, Copilot Autofix suggests a relevant fix. On pull requests, results are displayed as comments left by the `github-code-quality` bot. On the default branch, LLM-powered findings are displayed in the **AI findings** dashboard under the **{% octicon "shield" aria-hidden="true" aria-label="shield" %} {% ifversion security-and-quality-tab %}Security and quality{% else %}Security{% endif %}** tab. Additionally, Code Quality can automatically generate a code coverage CI workflow for your repository using an AI-powered agent, reducing the manual effort required to set up coverage tracking. The primary supported language for GitHub Code Security AI features is English. diff --git a/content/copilot/reference/agent-session-filters.md b/content/copilot/reference/enterprise-administrators/agent-session-filters.md similarity index 94% rename from content/copilot/reference/agent-session-filters.md rename to content/copilot/reference/enterprise-administrators/agent-session-filters.md index 7b74e5d6ff2f..9d7be580c0db 100644 --- a/content/copilot/reference/agent-session-filters.md +++ b/content/copilot/reference/enterprise-administrators/agent-session-filters.md @@ -5,6 +5,8 @@ intro: 'Search agentic activity in your enterprise with filters for agent sessio permissions: Enterprise owners versions: feature: copilot +redirect_from: + - /copilot/reference/agent-session-filters contentType: reference category: - Track Copilot usage diff --git a/content/copilot/reference/agentic-audit-log-events.md b/content/copilot/reference/enterprise-administrators/agentic-audit-log-events.md similarity index 97% rename from content/copilot/reference/agentic-audit-log-events.md rename to content/copilot/reference/enterprise-administrators/agentic-audit-log-events.md index db15accd4b9b..390526d619da 100644 --- a/content/copilot/reference/agentic-audit-log-events.md +++ b/content/copilot/reference/enterprise-administrators/agentic-audit-log-events.md @@ -5,6 +5,8 @@ intro: 'Understand the structure of audit log events for agents in your enterpri permissions: Enterprise owners versions: feature: copilot +redirect_from: + - /copilot/reference/agentic-audit-log-events contentType: reference category: - Learn about Copilot diff --git a/content/copilot/reference/enterprise-managed-settings-reference.md b/content/copilot/reference/enterprise-administrators/enterprise-managed-settings.md similarity index 97% rename from content/copilot/reference/enterprise-managed-settings-reference.md rename to content/copilot/reference/enterprise-administrators/enterprise-managed-settings.md index 733124df00ad..d5b6c816cdcd 100644 --- a/content/copilot/reference/enterprise-managed-settings-reference.md +++ b/content/copilot/reference/enterprise-administrators/enterprise-managed-settings.md @@ -1,10 +1,11 @@ --- -title: Enterprise managed settings reference -shortTitle: Managed settings reference -intro: 'Reference for the enterprise managed settings schema used by {% data variables.product.prodname_copilot_short %} clients.' +title: Enterprise managed settings +intro: 'Understand the enterprise managed settings schema used by {% data variables.product.prodname_copilot_short %} clients.' versions: feature: copilot contentType: reference +redirect_from: + - /copilot/reference/enterprise-managed-settings-reference category: - Configure Copilot --- diff --git a/content/copilot/reference/enterprise-administrators/index.md b/content/copilot/reference/enterprise-administrators/index.md new file mode 100644 index 000000000000..978cbe1d56f8 --- /dev/null +++ b/content/copilot/reference/enterprise-administrators/index.md @@ -0,0 +1,14 @@ +--- +title: Enterprise administrators +intro: Find information to apply to your work as an enterprise administrator for {% data variables.product.prodname_copilot %}. +versions: + feature: copilot +children: + - /agent-session-filters + - /agentic-audit-log-events + - /enterprise-managed-settings + - /mcp-allowlist-enforcement + - /policy-conflicts +contentType: reference +--- + diff --git a/content/copilot/reference/mcp-allowlist-enforcement.md b/content/copilot/reference/enterprise-administrators/mcp-allowlist-enforcement.md similarity index 96% rename from content/copilot/reference/mcp-allowlist-enforcement.md rename to content/copilot/reference/enterprise-administrators/mcp-allowlist-enforcement.md index 7c0c30a16b8d..5fe05658fe84 100644 --- a/content/copilot/reference/mcp-allowlist-enforcement.md +++ b/content/copilot/reference/enterprise-administrators/mcp-allowlist-enforcement.md @@ -4,6 +4,8 @@ intro: 'Understand the logic and limitations of MCP allowlist enforcement.' versions: feature: copilot contentType: reference +redirect_from: + - /copilot/reference/mcp-allowlist-enforcement category: - Learn about Copilot --- diff --git a/content/copilot/reference/policy-conflicts.md b/content/copilot/reference/enterprise-administrators/policy-conflicts.md similarity index 91% rename from content/copilot/reference/policy-conflicts.md rename to content/copilot/reference/enterprise-administrators/policy-conflicts.md index 78044efb89d1..76de262eac28 100644 --- a/content/copilot/reference/policy-conflicts.md +++ b/content/copilot/reference/enterprise-administrators/policy-conflicts.md @@ -2,13 +2,14 @@ title: Feature availability when GitHub Copilot policies conflict in organizations shortTitle: Policy conflicts allowTitleToDifferFromFilename: true -intro: 'Learn how delegating {% data variables.product.prodname_copilot_short %} policy decisions to organizations affects users granted a license by organizations with different policies.' +intro: 'Delegating {% data variables.product.prodname_copilot_short %} policy decisions to organizations affects users granted a license by organizations with different policies.' versions: feature: copilot category: - Learn about Copilot redirect_from: - /copilot/reference/feature-availability-enterprise + - /copilot/reference/policy-conflicts contentType: reference --- @@ -35,7 +36,7 @@ Feature, model, and privacy settings for users are set according to the **least | Policy | Availability matches | More information | | :---- | :---- | :---- | | {% data variables.product.prodname_copilot_short %} Metrics API | Most restrictive organization | {% ifversion ghec %}[AUTOTITLE](/rest/copilot/copilot-usage-metrics){% else %}Not applicable{% endif %} | -| Semantic indexing for non-GitHub repositories | Most restrictive organization (only available when all organizations explicitly set **Enabled**; **Unconfigured** behaves as disabled) | [AUTOTITLE](/copilot/concepts/context/repository-indexing) | +| Semantic indexing for non-{% data variables.product.github %} repositories | Most restrictive organization (only available when all organizations explicitly set **Enabled**; **Unconfigured** behaves as disabled) | [AUTOTITLE](/copilot/concepts/context/repository-indexing) | | Suggestions matching public code (privacy policy) | Most restrictive organization | [AUTOTITLE](/copilot/concepts/completions/code-suggestions) | | Allow members without a {% data variables.product.prodname_copilot_short %} license to use {% data variables.copilot.copilot_code-review_short %} in {% data variables.product.prodname_dotcom_the_website %} | Most restrictive organization | [AUTOTITLE](/copilot/responsible-use/agents) | | {% data variables.product.prodname_copilot_short %} can search the web | Least restrictive organization | [AUTOTITLE](/copilot/responsible-use/chat) | diff --git a/content/copilot/reference/index.md b/content/copilot/reference/index.md index aed53af68bd3..0fb945a38498 100644 --- a/content/copilot/reference/index.md +++ b/content/copilot/reference/index.md @@ -15,16 +15,12 @@ children: - /custom-agents-configuration - /custom-instructions-support - /hooks-reference - - /policy-conflicts - /supported-surfaces-for-policies - - /enterprise-managed-settings-reference - /copilot-allowlist-reference - - /mcp-allowlist-enforcement - /metrics-data - /copilot-billing - - /agentic-audit-log-events - - /agent-session-filters - /review-excluded-files - /copilot-usage-metrics + - /enterprise-administrators contentType: reference --- diff --git a/content/enterprise-onboarding/govern-people-and-repositories/create-repository-policies.md b/content/enterprise-onboarding/govern-people-and-repositories/create-repository-policies.md deleted file mode 100644 index c70ea238e76a..000000000000 --- a/content/enterprise-onboarding/govern-people-and-repositories/create-repository-policies.md +++ /dev/null @@ -1,64 +0,0 @@ ---- -title: Defining policies for repositories in your enterprise -shortTitle: Create repository policies -intro: Enforce repository policies across your enterprise using custom properties and targeting rules. -versions: - ghec: '*' -contentType: how-tos -docsTeamMetrics: - - enterprise-onboarding ---- - -{% data reusables.enterprise.repo-policy-rules-preview %} - -{% data reusables.enterprise.repo-policy-rules-intro %} - -## Examples - -{% data reusables.enterprise.repo-policy-rules-examples %} - -## Creating a repository policy - -{% data reusables.enterprise-accounts.access-enterprise %} -{% data reusables.enterprise-accounts.policies-tab %} -1. Under "Policies", click **Repository**. -1. Click **New policy**. -1. Configure your new policy, then click **Create**. For help, consult the following subsections. - -### Policy name - -Use something descriptive to communicate the purpose of the policy. Organization owners can view the policy, so good names help add clarity. For example: `Prevent public repos on production`. - -### Enforcement status - -{% data reusables.enterprise.repo-policy-rules-enforcement %} - -### Allow list - -{% data reusables.enterprise.repo-policy-rules-allow-list %} - -### Targets - -Choose which organizations and repositories the policy applies to. - -#### Target organizations - -Select all organizations, choose a selection of existing organizations, or set a dynamic list by name. If you use {% data variables.product.prodname_emus %}, you can also choose to target all repositories owned by users in your enterprise. - -If you set a dynamic list, you'll add one or more naming patterns using `fnmatch` syntax. For example, the string `*open-source` would match any organization with a name that ends with `open-source`. For syntax details, see [AUTOTITLE](/repositories/configuring-branches-and-merges-in-your-repository/managing-rulesets/creating-rulesets-for-a-repository#using-fnmatch-syntax). - -#### Target repositories - -Choose which repositories (current or future) to target in the selected organizations. You can select all repositories or set a dynamic list by custom property. - -### Policies - -{% data reusables.enterprise.repo-policy-rules-policies-section %} - -### Delegating bypass of policies - -{% data reusables.enterprise.repo-policy-rules-delegated-bypass %} - -## Next steps - -Create rulesets to consistently govern important branches in your enterprise's repositories. See [AUTOTITLE](/enterprise-onboarding/govern-people-and-repositories/protect-branches). diff --git a/content/enterprise-onboarding/govern-people-and-repositories/index.md b/content/enterprise-onboarding/govern-people-and-repositories/index.md index 51da6a28942e..46c1b17aa102 100644 --- a/content/enterprise-onboarding/govern-people-and-repositories/index.md +++ b/content/enterprise-onboarding/govern-people-and-repositories/index.md @@ -5,10 +5,8 @@ intro: Implement policies, custom properties, and rulesets to govern users and r versions: ghec: '*' children: - - /create-repository-policies - /protect-branches contentType: concepts docsTeamMetrics: - enterprise-onboarding --- - diff --git a/content/enterprise-onboarding/index.md b/content/enterprise-onboarding/index.md index 49e3bd8c0943..87de13e22370 100644 --- a/content/enterprise-onboarding/index.md +++ b/content/enterprise-onboarding/index.md @@ -31,7 +31,7 @@ journeyTracks: guides: - href: '/admin/concepts/security-and-compliance/enterprise-policies' - href: '/admin/managing-accounts-and-repositories/managing-repositories-in-your-enterprise/managing-custom-properties-for-repositories-in-your-enterprise' - - href: '/enterprise-onboarding/govern-people-and-repositories/create-repository-policies' + - href: '/admin/managing-accounts-and-repositories/managing-repositories-in-your-enterprise/governing-how-people-use-repositories-in-your-enterprise' - href: '/enterprise-onboarding/govern-people-and-repositories/protect-branches' - href: '/admin/concepts/security-and-compliance/audit-log-for-an-enterprise' - id: 'github_apps' diff --git a/content/migrations/troubleshooting/troubleshooting-your-migration-with-github-enterprise-importer.md b/content/migrations/troubleshooting/troubleshooting-your-migration-with-github-enterprise-importer.md index e3c519534a13..e74b669826ff 100644 --- a/content/migrations/troubleshooting/troubleshooting-your-migration-with-github-enterprise-importer.md +++ b/content/migrations/troubleshooting/troubleshooting-your-migration-with-github-enterprise-importer.md @@ -131,7 +131,7 @@ You can temporarily disable your rulesets during your migration, or you can use ### `Your push would publish a private email address` error -If you receive a `Git source migration failed` error with `GH007: Your push would publish a private email address`, the Git source you're trying to migrate includes commits authored by an email address that you have blocked from being pushed to {% data variables.product.prodname_dotcom %}. For more information, see [AUTOTITLE]({% ifversion not fpt or ghec %}/enterprise-cloud@latest{% endif %}/account-and-profile/setting-up-and-managing-your-personal-account-on-github/managing-email-preferences/blocking-command-line-pushes-that-expose-your-personal-email-address){% ifversion fpt or ghec %}.{% else %} in the {% data variables.product.prodname_ghe_cloud %} documentation.{% endif %} +If you receive a `Git source migration failed` error with `GH007: Your push would publish a private email address`, the Git source you're trying to migrate includes commits authored by an email address that you have blocked from being pushed to {% data variables.product.prodname_dotcom %}. For more information, see [AUTOTITLE]({% ifversion not fpt or ghec %}/enterprise-cloud@latest{% endif %}/account-and-profile/how-tos/email-preferences/blocking-command-line-pushes-that-expose-your-personal-email-address){% ifversion fpt or ghec %}.{% else %} in the {% data variables.product.prodname_ghe_cloud %} documentation.{% endif %} To resolve this error, you can either rewrite the Git history to remove the email address, or you can disable the "Block command line pushes that expose my email" setting. diff --git a/content/migrations/using-github-enterprise-importer/migrating-between-github-products/overview-of-a-migration-between-github-products.md b/content/migrations/using-github-enterprise-importer/migrating-between-github-products/overview-of-a-migration-between-github-products.md index 45cc585ddc41..02af64ec4e82 100644 --- a/content/migrations/using-github-enterprise-importer/migrating-between-github-products/overview-of-a-migration-between-github-products.md +++ b/content/migrations/using-github-enterprise-importer/migrating-between-github-products/overview-of-a-migration-between-github-products.md @@ -174,9 +174,9 @@ If you were using {% data variables.actions.hosted_runner %}s, self-hosted runne * To use runners at the organization or enterprise level, update your workflows. For more information, see [AUTOTITLE](/actions/how-tos/manage-runners/self-hosted-runners/use-in-a-workflow). 1. If you use {% data variables.actions.hosted_runner %}s, reconfigure your runners. - * Configure runner groups to control access to your runners. For more information, see [AUTOTITLE]({% ifversion ghes %}/enterprise-cloud@latest{% endif %}/actions/using-github-hosted-runners/controlling-access-to-larger-runners). - * Set up your {% data variables.actions.hosted_runner %}s. For more information, see [AUTOTITLE]({% ifversion ghes %}/enterprise-cloud@latest{% endif %}/actions/using-github-hosted-runners/managing-larger-runners). - * Update your workflows to point to your runners. For more information, see [AUTOTITLE]({% ifversion ghes %}/enterprise-cloud@latest{% endif %}/actions/using-github-hosted-runners/running-jobs-on-larger-runners). + * Configure runner groups to control access to your runners. For more information, see [AUTOTITLE]({% ifversion ghes %}/enterprise-cloud@latest{% endif %}/actions/how-tos/manage-runners/larger-runners/control-access). + * Set up your {% data variables.actions.hosted_runner %}s. For more information, see [AUTOTITLE]({% ifversion ghes %}/enterprise-cloud@latest{% endif %}/actions/how-tos/manage-runners/larger-runners/manage-larger-runners). + * Update your workflows to point to your runners. For more information, see [AUTOTITLE]({% ifversion ghes %}/enterprise-cloud@latest{% endif %}/actions/how-tos/manage-runners/larger-runners/use-larger-runners). 1. Re-add any encrypted secrets. * To use the browser, see [AUTOTITLE](/actions/how-tos/write-workflows/choose-what-workflows-do/use-secrets#creating-secrets-for-a-repository). diff --git a/data/features/actions-schedule-timezone.yml b/data/features/actions-schedule-timezone.yml new file mode 100644 index 000000000000..4d8c2bb17430 --- /dev/null +++ b/data/features/actions-schedule-timezone.yml @@ -0,0 +1,6 @@ +# Scheduled workflows support timezones + +versions: + fpt: '*' + ghec: '*' + ghes: '>=3.22' diff --git a/data/features/github-models.yml b/data/features/github-models.yml deleted file mode 100644 index 2b33dccc8098..000000000000 --- a/data/features/github-models.yml +++ /dev/null @@ -1,4 +0,0 @@ -# GitHub Models (AI models on GitHub Models) -versions: - fpt: '*' - ghec: '*' diff --git a/data/features/org-automatic-registry-access.yml b/data/features/org-automatic-registry-access.yml deleted file mode 100644 index d87ae8623c54..000000000000 --- a/data/features/org-automatic-registry-access.yml +++ /dev/null @@ -1,6 +0,0 @@ -# Reference: #22447 -# Automatic Dependabot access to GitHub-hosted registries [GA] -versions: - fpt: '*' - ghec: '*' - ghes: '>=3.22' diff --git a/data/release-notes/enterprise-server/3-21/0.yml b/data/release-notes/enterprise-server/3-21/0.yml index e088cdeee3f2..a8d5727860b4 100644 --- a/data/release-notes/enterprise-server/3-21/0.yml +++ b/data/release-notes/enterprise-server/3-21/0.yml @@ -152,6 +152,9 @@ sections: - heading: Organizations notes: + # https://github.com/github/releases/issues/6789 + - | + Enterprise owners can apply custom properties to organizations, allowing them to associate organizations with metadata such as regions or compliance requirements and target them in rulesets. For details, see the [changelog](https://github.blog/changelog/2026-01-13-organization-custom-properties-now-generally-available/). [Updated: 2026-08-04] # https://github.com/github/releases/issues/7596 - | Organization owners can require that contributors explicitly select a value for required custom properties when creating a repository, rather than relying on a default value. This ensures repositories meet organizational policy requirements at creation time, improving adoption of rulesets and accuracy of property values. For more information, see [AUTOTITLE](/organizations/managing-organization-settings/managing-custom-properties-for-repositories-in-your-organization). For details, see the [changelog](https://github.blog/changelog/2026-02-17-custom-properties-and-rule-insights-improvements/). @@ -295,6 +298,6 @@ sections: errata: - | - These release notes previously included a note about pull requeset reviewers being able to comment on any line of a changed file, not just lines within the diff. The note was added prematurely and has been removed. We will republish it when the feature is ready. [Updated: 2026-06-23] + These release notes previously included a note about pull request reviewers being able to comment on any line of a changed file, not just lines within the diff. The note was added prematurely and has been removed. We will republish it when the feature is ready. [Updated: 2026-06-23] - | These release notes incorrecly indicated that the `case` function is supported in {% data variables.product.prodname_actions %} expressions. [Updated: 2026-07-30] diff --git a/data/reusables/code-quality/workflow-generation.md b/data/reusables/code-quality/workflow-generation.md new file mode 100644 index 000000000000..5d9ac3d4c574 --- /dev/null +++ b/data/reusables/code-quality/workflow-generation.md @@ -0,0 +1 @@ +You can use the automatic setup option to generate a workflow with an AI-powered agent, or configure your workflow manually. See [AUTOTITLE](/code-security/how-tos/maintain-quality-code/set-up-code-coverage). diff --git a/data/reusables/copilot/code-review/skills-and-mcp-preview-note.md b/data/reusables/copilot/code-review/skills-and-mcp-preview-note.md deleted file mode 100644 index 70ed25ff548b..000000000000 --- a/data/reusables/copilot/code-review/skills-and-mcp-preview-note.md +++ /dev/null @@ -1,2 +0,0 @@ -> [!NOTE] -> Support for agent skills and MCP servers with {% data variables.copilot.copilot_code-review_short %} is in {% data variables.release-phases.public_preview %} and subject to change. \ No newline at end of file diff --git a/data/reusables/enterprise-accounts/models-policies.md b/data/reusables/enterprise-accounts/models-policies.md deleted file mode 100644 index e3e5c1ed3605..000000000000 --- a/data/reusables/enterprise-accounts/models-policies.md +++ /dev/null @@ -1 +0,0 @@ -1. Under {% octicon "law" aria-hidden="true" aria-label="law" %} "Policies", click **{% octicon "ai-model" aria-hidden="true" aria-label="ai-model" %} Models**. diff --git a/data/reusables/enterprise-accounts/to-upgrade-or-get-started.md b/data/reusables/enterprise-accounts/to-upgrade-or-get-started.md deleted file mode 100644 index f6b206a9cef7..000000000000 --- a/data/reusables/enterprise-accounts/to-upgrade-or-get-started.md +++ /dev/null @@ -1 +0,0 @@ -To upgrade to {% data variables.product.prodname_enterprise %} or to get started with an enterprise account, contact {% data variables.contact.contact_enterprise_sales %}. diff --git a/data/reusables/github-models/production-rate-limits-note.md b/data/reusables/github-models/production-rate-limits-note.md deleted file mode 100644 index b2ca6bcfe0de..000000000000 --- a/data/reusables/github-models/production-rate-limits-note.md +++ /dev/null @@ -1 +0,0 @@ -> [!NOTE] Once you opt in to paid usage, you will have access to production grade rate limits and be billed for all usage thereafter. For more information about these rate limits, see [Microsoft Foundry Models quotas and limits](https://learn.microsoft.com/en-us/azure/ai-foundry/model-inference/quotas-limits) in the Azure documentation. diff --git a/data/reusables/models/byok-preview-note.md b/data/reusables/models/byok-preview-note.md deleted file mode 100644 index 3deb76107c7a..000000000000 --- a/data/reusables/models/byok-preview-note.md +++ /dev/null @@ -1,2 +0,0 @@ -> [!NOTE] -> The ability to bring your own keys (BYOK) to use custom models with {% data variables.product.prodname_github_models %} for organizations on {% data variables.product.github %} is in {% data variables.release-phases.public_preview %} and subject to change. diff --git a/data/reusables/models/enable-select-models-in-org.md b/data/reusables/models/enable-select-models-in-org.md deleted file mode 100644 index 34d004440e2f..000000000000 --- a/data/reusables/models/enable-select-models-in-org.md +++ /dev/null @@ -1,16 +0,0 @@ -{% data reusables.profile.access_org %} -{% data reusables.profile.org_settings %} -{% data reusables.organizations.models-development %} -1. Under "Models", in the "Models in your organization" section, click {% octicon "chevron-down" aria-label="the down arrow" %} beside **Disabled** and select **Enabled** from the dropdown. - - > [!NOTE] - > If {% data variables.product.prodname_github_models %} is already enabled for the organization, the dropdown will show **Enabled**, and you can skip the step above. - -1. Under "Models permissions", select one or more options. - * **All publishers** is the default option and indicates that models from all the current and future publishers available on the {% data variables.product.prodname_github_models %} catalog from the {% data variables.product.prodname_marketplace %} can be used in the organization. - * **Only select models** allows you to define a list of models and publishers: - * Available to the organization (**Enabled list**) - * Restricted for use in the organization (**Disabled list**) - - Depending on your requirements, you can specify an enabled list, a disabled list, or both. - Once you've added a publisher to a list, you can fine-tune the list by removing individual models from it. diff --git a/data/reusables/models/enable-select-models-intro.md b/data/reusables/models/enable-select-models-intro.md deleted file mode 100644 index d05a0fad2a34..000000000000 --- a/data/reusables/models/enable-select-models-intro.md +++ /dev/null @@ -1,3 +0,0 @@ -You can choose to enable or disable {% data variables.product.prodname_github_models %} for your organization. You can also choose to only allow the use of selected models or model publishers. For more information, see the instructions below. - -You can also integrate your preferred external LLM models by bringing your own keys (BYOK) to {% data variables.product.prodname_github_models %}. See [AUTOTITLE](/github-models/github-models-at-scale/using-your-own-api-keys-in-github-models) diff --git a/data/reusables/models/enterprise-change-models-settings.md b/data/reusables/models/enterprise-change-models-settings.md deleted file mode 100644 index 78e5dd08987a..000000000000 --- a/data/reusables/models/enterprise-change-models-settings.md +++ /dev/null @@ -1,2 +0,0 @@ -> [!NOTE] -> You can only change your organization's Models settings if your enterprise policies allow access to {% data variables.product.prodname_github_models %}. diff --git a/data/reusables/models/feature-overview.md b/data/reusables/models/feature-overview.md deleted file mode 100644 index d8113a70aca5..000000000000 --- a/data/reusables/models/feature-overview.md +++ /dev/null @@ -1 +0,0 @@ -{% data variables.product.prodname_github_models %} automates, enhances, and streamlines AI-powered software development processes within {% data variables.product.github %}. You can use {% data variables.product.prodname_github_models %} to manage and optimize prompts, compare models, and create robust evaluations. See [AUTOTITLE](/github-models/about-github-models). diff --git a/data/reusables/models/models-preview-note.md b/data/reusables/models/models-preview-note.md deleted file mode 100644 index 39647b58a9ea..000000000000 --- a/data/reusables/models/models-preview-note.md +++ /dev/null @@ -1,2 +0,0 @@ -> [!NOTE] -> {% data variables.product.prodname_github_models %} for organizations and repositories is in {% data variables.release-phases.public_preview %} and subject to change. diff --git a/data/reusables/models/prereq-enable-models-in-enterprise.md b/data/reusables/models/prereq-enable-models-in-enterprise.md deleted file mode 100644 index c039c42fc47c..000000000000 --- a/data/reusables/models/prereq-enable-models-in-enterprise.md +++ /dev/null @@ -1 +0,0 @@ -For {% data variables.product.prodname_github_models %} to be available to your organization, an enterprise owner must first enable the feature for the enterprise. diff --git a/data/reusables/models/steps-to-open-model-playground.md b/data/reusables/models/steps-to-open-model-playground.md deleted file mode 100644 index cda401b53d3a..000000000000 --- a/data/reusables/models/steps-to-open-model-playground.md +++ /dev/null @@ -1,5 +0,0 @@ -1. Go to [github.com/marketplace/models](https://github.com/marketplace/models). -1. Click **Model: Select a Model** at the top left of the page. -1. Choose a model from the dropdown menu. - - Alternatively, in the dropdown menu, click **View all models**, click a model in the Marketplace, then click **{% octicon "command-palette" aria-hidden="true" aria-label="command-palette" %} Playground**. diff --git a/data/reusables/organizations/custom-models.md b/data/reusables/organizations/custom-models.md deleted file mode 100644 index b47ea977ef39..000000000000 --- a/data/reusables/organizations/custom-models.md +++ /dev/null @@ -1 +0,0 @@ -1. {% data reusables.user-settings.code-planning-automation %} click **{% octicon "ai-model" aria-hidden="true" aria-label="ai-model" %} Models** dropdown. Then click **Custom models**. The "Custom Models" page displays the API keys and custom models added to the organization. diff --git a/data/reusables/repositories/actions-scheduled-workflow-example.md b/data/reusables/repositories/actions-scheduled-workflow-example.md index 60d73a5daab9..1be74cf88f74 100644 --- a/data/reusables/repositories/actions-scheduled-workflow-example.md +++ b/data/reusables/repositories/actions-scheduled-workflow-example.md @@ -1,8 +1,12 @@ -Use [POSIX cron syntax](https://pubs.opengroup.org/onlinepubs/9699919799/utilities/crontab.html#tag_20_25_07) to schedule workflows to run at specific times. By default, scheduled workflows run in UTC. You can optionally specify a timezone using an [IANA timezone string](https://en.wikipedia.org/wiki/List_of_tz_database_time_zones) for timezone-aware scheduling. Scheduled workflows run on the latest commit on the default branch. The shortest interval you can run scheduled workflows is once every 5 minutes. +Use [POSIX cron syntax](https://pubs.opengroup.org/onlinepubs/9699919799/utilities/crontab.html#tag_20_25_07) to schedule workflows to run at specific times. {% ifversion actions-schedule-timezone %}By default, scheduled workflows run in UTC. You can optionally specify a timezone using an [IANA timezone string](https://en.wikipedia.org/wiki/List_of_tz_database_time_zones) for timezone-aware scheduling{% else %}Scheduled workflows run in UTC{% endif %}. Scheduled workflows run on the latest commit on the default branch. The shortest interval you can run scheduled workflows is once every 5 minutes. + +{% ifversion actions-schedule-timezone %} > [!NOTE] > For schedules that set `timezone` to a time zone that observes daylight saving time (DST), during DST spring-forward transitions, scheduled workflows in skipped hours advance to the next valid time. For example, a 2:30 AM schedule advances to 3:00 AM. +{% endif %} + {% data reusables.repositories.cron %} You can use these operators in any of the five fields: @@ -14,6 +18,8 @@ You can use these operators in any of the five fields: | - | Range of values | `30 4-6 * * *` runs at minute 30 of the 4th, 5th, and 6th hour. | | / | Step values | `20/15 * * * *` runs every 15 minutes starting from minute 20 through 59 (minutes 20, 35, and 50). | +{% ifversion actions-schedule-timezone %} + This example triggers the workflow to run at 5:30 AM in the America/New_York timezone every Monday through Friday: ```yaml @@ -23,6 +29,8 @@ on: timezone: "America/New_York" ``` +{% endif %} + A single workflow can be triggered by multiple `schedule` events. Access the `schedule` event that triggered the workflow through the `github.event.schedule` context. This example triggers the workflow to run at 5:30 UTC every Monday-Thursday, and 17:30 UTC on Tuesdays and Thursdays, but skips the `Not on Monday or Wednesday` step on Monday and Wednesday. ```yaml diff --git a/data/reusables/repositories/navigate-to-models.md b/data/reusables/repositories/navigate-to-models.md deleted file mode 100644 index fb5f0d93fcfc..000000000000 --- a/data/reusables/repositories/navigate-to-models.md +++ /dev/null @@ -1 +0,0 @@ -At the top of the page for your repository, click **{% octicon "ai-model" aria-hidden="true" aria-label="ai-model" %} Models**.