Enabling or disabling built-in code quality and security validation tools
By default, Copilot coding agent checks code it generates for security issues and gets a second opinion on its code with Copilot code review. It attempts to resolve issues identified prior to completing the pull request. This improves code quality and reduces the likelihood of the code generated by Copilot coding agent introducing problems such as hardcoded secrets, insecure dependencies, and other vulnerabilities.
Optionally, you can choose to disable these tools to help Copilot work faster or avoid conflicts with other code quality or security products you're using.
You must be a repository administrator to configure these settings.
-
On GitHub, navigate to the main page of the repository.
-
Under your repository name, click Settings. If you cannot see the "Settings" tab, select the dropdown menu, then click Settings.

-
In the "Code & automation" section of the sidebar, click Copilot then Coding agent.
-
In the "Validation tools" section, toggle the tool, or tools, you want to enable or disable.
Allowing GitHub Actions workflows to run automatically when Copilot pushes
By default, GitHub Actions workflows will not run automatically when Copilot pushes changes to a pull request.
GitHub Actions workflows can be privileged and have access to sensitive secrets. Inspect the proposed changes in the pull request and ensure that you are comfortable running your workflows on the pull request branch. You should be especially alert to any proposed changes in the .github/workflows/ directory that affect workflow files.
To allow GitHub Actions workflows to run, click the Approve and run workflows button in the pull request's merge box.

Optionally, you can configure Copilot coding agent to allow GitHub Actions workflows to run without human intervention.
Warnung
Allowing GitHub Actions workflows to run without approval may allow unreviewed code written by Copilot to gain write access to your repository or access your GitHub Actions secrets.
You must be a repository administrator to configure these settings.
-
On GitHub, navigate to the main page of the repository.
-
Under your repository name, click Settings. If you cannot see the "Settings" tab, select the dropdown menu, then click Settings.

-
In the "Code & automation" section of the sidebar, click Copilot then coding agent.
-
In the "Actions workflow approval" section, disable the Require approval for workflow runs setting.