Code-to-cloud risk visibility with Microsoft Defender for Cloud is now generally available – GitHub Changelog

Code-to-cloud risk visibility with Microsoft Defender for Cloud is now generally available – GitHub Changelog

By Allison
Publication Date: 2026-05-05 14:24:00

This integration is now generally available. Since entering public preview, we’ve heard valuable feedback from customers, and we’ve shipped follow-up improvements that bring artifact and runtime context closer to the GitHub Advanced Security alert experience.

This integration connects code, build artifacts, and runtime context so you can track, prioritize, and remediate the security risks most relevant to your environment.

Defender for Cloud correlates what’s running in your cloud environments back to the source code that produced it. Defender maps container images deployed in your environments to the GitHub repositories that built them, using signals like GitHub artifact attestations alongside its own runtime intelligence.

Once Defender for Cloud links an artifact to its source, you can evaluate security findings in the context of where and how the code runs.

Defender for Cloud also brings workload details into GitHub through the Deployment Record API, populating the…