Notifications
Clear all
Topic starter
19/07/2026 1:59 pm
We're starting to use AI coding assistants (like GitHub Copilot) in our team. Our CI pipeline has SAST scans for pull requests, which is great.
But I'm worried about code generated directly in the IDE by these agents. It might not go through a PR and could bypass our security gates. How are teams ensuring this agent code is held to the same standard? Is it just about making sure all code, however it's written, eventually gets scanned in the pipeline, or are there better practices?
Still learning.