GitHub agentic autofix now turns fix patterns into repository memory that other Copilot features can reuse. Review the learned rule as a shared security control, not only the patch that produced it.
One accepted patch now has a larger blast radius
On September 25, GitHub changed the unit of review. Agentic autofix now reads existing memories and stores a fix pattern as memory after it creates a fix. That pattern can help later autofix runs and teach Copilot code review and the cloud agent about repository-specific secure development practices.
The broader Copilot Memory documentation names four consumers: agentic autofix, code review, cloud agent and CLI. A rule learned in one surface can influence another. That is useful context reuse, but it also means patch acceptance and memory acceptance are different decisions.
A reviewer can correctly accept a local SQL injection fix without deciding that the observed pattern should guide future reviews across the repository. The patch answers, "Does this change remediate this alert?" The memory answers, "Should this rule be reused when another feature interprets related code?"

Both agentic autofix and Copilot Memory remain public previews. Treat enablement as a cross-feature release, not a small autofix preference.
GitHub validates citations; you still own the security rule
GitHub already applies an important stale-memory control. Repository facts include citations to supporting code, and Copilot checks those citations against the current branch before it uses a fact. Only validated facts are used. Facts can even originate in a closed pull request that never merged, but current code must still substantiate them.
That validation answers whether the cited code still exists and supports the fact. It does not replace the tests and ownership around a security rule. GitHub's responsible-use documentation for security and quality features says autofix suggestions may have syntax, location or semantic errors; may fail to remediate the vulnerability; may introduce another vulnerability; may be partial; or may propose unsupported or fabricated dependencies.
The same documentation requires explicit developer review before a suggestion is accepted. Keep that control. A memory citation can be current while the learned pattern is too broad, changes a dependency, or lacks a regression test for the original failure mode.
For merge decisions, keep deterministic analysis and repository protections authoritative. The Copilot security review and CodeQL boundary still applies: generated guidance can accelerate review, but an advisory memory is not a merge-blocking security result.
Keep an external adoption ledger
Do not invent a GitHub integration that the product does not expose. GitHub documents a repository settings view where administrators can review and delete facts. It does not document a custom policy API for attaching your own approval fields to an internal memory record.
The practical control is a small external adoption ledger for every security pattern your organization decides to rely on. Key it by repository plus a digest of the visible memory text, then retain:
- the originating code scanning alert ID and CodeQL query ID;
- the cited file and location;
- the accepted fix commit;
- the human security reviewer;
- the regression test that represents the original failure mode;
- the current commit on which that test passed;
- whether the rule is path-scoped or repository-wide;
- any dependency introduced or upgraded;
- the review decision and deletion date when the fact becomes misleading.
This ledger does not recreate Copilot Memory. It records the organization's decision to trust a learned security rule. The distinction matters because GitHub's input to autofix includes CodeQL SARIF, current branch snippets, roughly the first 10 lines of involved files and query help. Your release evidence can include the wider behavior and deployment constraints that those inputs do not establish.
The lifecycle belongs under the same doctrine as governed agent memory: provenance, retrieval eligibility, expiry and deletion are separate controls.
Route each pattern to one of four outcomes
A usable review does not need a score. It needs four explicit routes:
- Delete: the citation is no longer valid, or a fact from an unmerged change is not supported by current code.
- Quarantine: the fact lacks an origin alert, accepted commit, reviewer or current regression evidence.
- Review: the pattern changes a dependency or makes a repository-wide claim without security-owner approval.
- Eligible: the origin, citation, accepted fix, reviewer and current regression all reconcile.

The reference classifier below is dependency-free. It evaluates an external adoption record, not GitHub's private memory schema.
export function decideMemoryUse(record) {
const required = [
"repository", "memoryDigest", "originAlertId", "queryId", "citationRef"
];
const missing = required.filter((key) => !record[key]);
if (missing.length) {
return { route: "quarantine", reason: `missing:${missing.join(",")}` };
}
if (!record.citationValidOnCurrentBranch) {
return { route: "delete", reason: "citation-no-longer-valid" };
}
if (record.origin === "closed-unmerged-pr" && !record.currentBranchStillSupportsFact) {
return { route: "delete", reason: "unmerged-origin-not-supported" };
}
if (!record.acceptedFixCommit || !record.humanReviewer) {
return { route: "quarantine", reason: "accepted-fix-evidence-missing" };
}
if (!record.regressionTestRef || !record.regressionPassesCurrentCommit) {
return { route: "quarantine", reason: "current-regression-evidence-missing" };
}
if (record.changesDependency && !record.dependencyVerified) {
return { route: "review", reason: "dependency-change-needs-review" };
}
if (record.claimScope === "repository-wide" && !record.securityOwnerApproved) {
return { route: "review", reason: "broad-rule-needs-security-owner" };
}
return { route: "eligible", reason: "current-evidence-and-owner-present" };
}The retained reference artifact passes 16 local cases. It covers missing provenance, stale citations, closed unmerged origins, absent accepted-fix evidence, current regression failure, unverified dependencies, broad unowned claims and the complete eligible path. Those are control-flow tests, not a GitHub performance benchmark.
Do not use the 28-day timer as a release gate
An unused fact or preference is automatically deleted after 28 days, but successful validation and use may reset that timer. Retention therefore measures use, not correctness. A bad rule that keeps matching code can stay warm. A good rule that does not recur can disappear.
Use your current regression test and owner decision as the release evidence. Treat GitHub's timer as provider retention behavior. If the cited code or expected behavior changes, re-run the representative security case and route the record again.
Repository owners can review and manually delete repository-level facts. Rehearse that deletion before the pilot, then record who owns the review and what event triggers it. The shortest trigger list is:
- a citation no longer validates;
- the regression test fails on the current commit;
- a memory becomes broader than its accepted fix;
- a dependency or framework version changes the remediation;
- a reviewer finds the fact misleading or inappropriate.
Roll out the preview as a four-consumer change
Enterprise and organization administrators manage Copilot Memory as a policy. Managed subscriptions keep Memory off by default until an administrator enables it. After enablement it is on for users by default, and users may opt out. The setting is per user rather than per repository, so a pilot owner must inspect where those users invoke supported Copilot features.
Use this release sequence:
- Name the security owner and the repositories allowed in the pilot.
- Inventory agentic autofix, code review, cloud agent and CLI as separate consumers.
- Review the current repository facts before enabling reliance on them.
- Retain an external adoption record for security patterns that affect decisions.
- Test stale citations, closed unmerged origins, missing regression evidence and an unverified dependency.
- Require human review for every proposed fix.
- Rehearse fact deletion and the repository-level disable path.
- Expand only after the four routes produce the expected terminal states.
GitHub provides two direct stop controls for agentic autofix: disable Copilot Autofix, which also blocks agentic autofix, or opt the repository out of cloud agent. Use them when the pilot cannot preserve review or when a shared memory produces a misleading rule.
The narrowest acceptable rollout is not "memory enabled." It is one owned repository, four known consumers, a reviewed fact inventory, representative negative cases, a deletion rehearsal and explicit human acceptance of every patch.
Frequently asked questions
Does GitHub Copilot Memory expire?
An unused fact or preference is automatically deleted after 28 days. GitHub says the timer may reset when Copilot successfully validates and uses the entry, so retention is not a correctness signal.
Can Copilot Memory use facts from an unmerged pull request?
Yes. GitHub says facts can be captured from pull requests closed without merging, but they affect behavior only if current code still substantiates them.
Can an administrator delete repository memories?
Yes. Repository administrators can review stored repository-level facts in repository settings and delete facts they consider inappropriate, misleading or incorrect.








