

Most codebases have a favorite mistake. It might be a query built from string concatenation, or a missing check on user input. A developer fixes it in one file. A few weeks later, the scanner finds the same flaw in another file, and the fix starts from scratch.
GitHub wants to stop paying for that lesson twice. On September 25, the company said agentic autofix now uses Copilot Memory for customers who have turned Memory on. Before the agent works on a security alert, it checks stored memories for context that might help. After it creates a fix, it saves the fix pattern as a memory for later use.
Those patterns don’t stay inside autofix. According to GitHub’s changelog, they help the agent resolve other security alerts, and they inform other Copilot features, including code review and the Copilot cloud agent, about secure development practices specific to the repository.
Both agentic autofix and Copilot Memory are still in public preview.
How the Pieces Fit
Agentic autofix entered public preview on July 10. Instead of a one-shot suggestion, a developer assigns a code scanning alert to Copilot. The agent explores relevant files, proposes a fix, and reruns CodeQL to confirm the alert is gone. If it isn’t, the agent tries again. Then it opens a draft pull request that explains the fix. GitHub says this usually takes two to four minutes.
The feature requires a GitHub Code Security or Advanced Security license, plus a Copilot license with the cloud agent enabled. It also uses the organization’s AI credits and GitHub Actions minutes.
Copilot Memory is the other half. It stores two kinds of information: facts about a repository, such as coding conventions, architecture decisions, and build commands, and a user’s personal preferences. Repository facts stay in the repository where they were learned.
The design detail that matters most here is validation. GitHub’s documentation says repository facts are stored “with citations pointing to the code that supports them.” Before Copilot uses a fact, it checks those citations against the current branch. Only validated facts get used. And any fact that goes unused for 28 days is deleted automatically.
For individual plans, Memory is on by default. For plans managed by an organization or enterprise, an administrator has to enable the policy first. So in most enterprise shops, this update does nothing until someone makes that call.
From Fixing to Preventing
The interesting part isn’t that autofix gets a little smarter. It’s that a fix now teaches the rest of the toolchain.
In most organizations, security knowledge dies in the pull request. A developer fixes an alert, and the next developer who makes the same mistake never sees the fix.
With memory in the loop, a fix pattern can reach code review. If Copilot code review knows how this repository handles a certain class of vulnerability, it has a better chance of flagging the same mistake in a new pull request before it merges. That moves the work earlier, from cleaning up alerts to catching them in review.
Mitch Ashley, vice president and practice lead for CIO & technology buyers and software lifecycle engineering at The Futurum Group, sees a bigger point in how GitHub built it. “GitHub’s move matters because of what it says about agent trust. A system earns trust by showing its work, not by producing more of it,” he says. “Tying a fix pattern to citations that expire once the code changes is a real step toward self-evidencing agent memory, a piece most agentic tooling still lacks.”
Questions to Ask First
This is a preview, and teams should treat it that way. A few things are worth checking before you rely on it.
First, what gets remembered, and when? The changelog says autofix saves the fix pattern when it creates a fix. It doesn’t say whether that happens before or after a human approves the pull request. Ashley thinks that detail carries a lot of weight. “Whether autofix banks a pattern before or after a human approves the fix will decide how much this helps. Bank it too early, and a weak pattern can spread faster than review catches it.”
Second, who turns it on? In an enterprise, the Memory policy is an admin decision. Security and platform teams should make it together.
Third, what does it cost? Every agentic autofix run uses AI credits and Actions minutes. If memory helps the agent clear more alerts, usage may rise.
Fourth, how long do lessons last? The 28-day expiry keeps stale facts from piling up. It also means a pattern tied to a rare class of bug may fade before that bug shows up again.
The Bigger Picture
AI coding agents have mostly worked like contractors who show up with no notes from the last job. Memory changes that. It gives an agent a record of how a specific team writes and secures its code.
That’s useful. It’s also a new thing to govern. Teams will need to know what’s in an agent’s memory and where it came from.
For DevOps teams, the practical step is simple. If you’re already testing agentic autofix, turn on Memory in a few repositories with a steady flow of security alerts. Then watch whether the same findings stop coming back. And watch your own team, too. “Watch whether teams that enable Memory also tighten scrutiny of agent-written fixes instead of just clearing more alerts,” Ashley says.