GitHub Code Quality became generally available on 20 July 2026. It runs CodeQL quality queries plus AI-assisted detection on pull requests, suggests fixes with Copilot Autofix, and adds organization dashboards and merge gates. If your code lives on GitHub, it is the obvious default to evaluate.
Skylos is an open-source CLI (Apache-2.0) for dead code, security, secrets and quality checks, plus a "done" check for agent-written changes. It runs locally and in any CI, with an optional Cloud service.
They overlap less than the names suggest. This page covers where each is the better fit and how to use both.
GitHub facts checked on 9 Oct 2026. Pricing and features change; follow the links for the current terms.
The short version
| GitHub Code Quality | Skylos | |
|---|---|---|
| What it is | GitHub-hosted quality checks: CodeQL queries plus AI-assisted detection, shown in pull requests and org dashboards | Open-source CLI; optional Skylos Cloud for history, PR checks and team workflow |
| Where it runs | On GitHub, for GitHub Team and Enterprise Cloud. Not on GitHub Enterprise Server at launch | Your machine, any CI runner, the Docker image or the GitHub Action |
| Price | $10 per active committer per month (bots not charged), plus usage-based billing for AI detection and Copilot Autofix, plus Actions compute. Public repos: $0 per committer plus AI usage | CLI free (Apache-2.0). Skylos Cloud: Free plan (1 project) and Workspace plan, turned on for good by any one-time credit pack; no seats or subscriptions |
| Setup | Turn it on in GitHub settings, per repository or across the organization | pip install skylos, then skylos cicd init --no-upload for a PR workflow |
| Python dead code | Unused import, unused local variable, unused global variable, unreachable code, commented-out code. No published query for unused functions, classes or methods | Unused functions, classes, methods, imports and variables across modules, followed transitively, with framework entry points modeled |
| AI | AI-assisted detection and Copilot Autofix (usage-billed; no Copilot subscription needed) | A normal scan calls no model. Optional LLM review of dead-code findings with your own model key (skylos agent verify) |
| Merge gates | Rulesets, including coverage thresholds (Cobertura XML), with an evaluate mode | Exit codes and --gate thresholds in any CI; required checks from the generated workflow |
| Org view | Org-level dashboards with maintainability and reliability scores | None in the CLI. Skylos Cloud keeps scan history and PR checks |
| Agent-written changes | Copilot coding agent runs security and quality analysis on code it creates | skylos done checks for deleted, skipped or weakened tests and code that special-cases tests; agent hooks for Claude Code, Codex and Cursor |
| Languages | Java, JavaScript, TypeScript, Python, Ruby, C#, Go | Python (deepest), TypeScript/JavaScript and Java: dead code, security and quality. PHP, Rust, Dart: dead code and security. Go: dead code and security need the separate skylos-go engine (in the Docker image and GitHub Action, not the PyPI package). C# partial. Kotlin: dead code only. C++: unused file-local functions only. Shell: security only |
Sources for the GitHub column: the GA changelog, the feature page and the Python query list. The Copilot coding agent row is from GitHub's 28 Oct 2025 changelog.
Where GitHub Code Quality is the better choice
- Nothing to install or maintain. You enable it in settings, including across an organization. Skylos needs a workflow file and a pinned version you update.
- Organization dashboards. GitHub shows maintainability and reliability scores across repositories. The Skylos CLI has no org view.
- Fixes, not just findings. Copilot Autofix suggests a fix for you to review. A Skylos scan reports;
skylos cleancan remove unused imports and functions, but there is no general autofix in the CLI. - Coverage gates. Rulesets can block a merge on coverage thresholds from Cobertura reports. Skylos has no coverage-percentage gate.
- AI detection beyond fixed rules. GitHub pairs deterministic CodeQL queries with AI-assisted detection for issues rules miss.
- Breadth of quality queries. The Python list alone has about a hundred CodeQL queries for reliability and maintainability.
If your team is on GitHub Team or Enterprise Cloud, wants one switch for every repository and is happy with per-committer pricing, start there.
Where Skylos differs
It runs anywhere a CLI runs
Skylos is a Python package and a Docker image. It runs on a laptop before a push, on self-hosted runners, on GitHub Enterprise Server runners, in GitLab CI or anywhere else. GitHub Code Quality isn't available on GitHub Enterprise Server at launch.
The CLI has no per-committer fee
The CLI is free and open source. A team that only needs pull-request checks can run it in CI without a Skylos account:
skylos cicd init --no-upload
This writes a GitHub Actions workflow with a changed-line scan job, PR annotations and comments, and, when it finds a pytest project, a job that runs skylos done. It needs no Skylos account or API key; --no-upload leaves out the Skylos Cloud upload job.
Python dead code across modules
GitHub's published Python queries for Code Quality cover unused imports, unused local and global variables, unreachable code and commented-out code. On 9 Oct 2026 the list had no query for a function, class or method that nothing in the project calls. That is the core Skylos dead-code check:
$ skylos . --format concise
app/main.py:14 SKY-U001 unused function: unused_report
app/report.py:5 SKY-U001 unused function: Report.render_pdf
app/report.py:9 SKY-U004 unused class: OldExporter
app/old_helpers.py:1 SKY-E002 Empty Python file (no code, or docstring-only)
Skylos follows dead code transitively and treats Flask and FastAPI routes, Django views, pytest fixtures and other framework entry points as used. skylos clean . --dry-run previews removing unused imports and functions. See Does Ruff detect dead code? for why per-file checks can't answer this question.
A check for agent-written changes
skylos done --base main re-runs your tests and compares them with the base branch. By default it blocks on failing tests, deleted or skipped tests, loosened test settings, edits to Skylos's own settings, added secrets and code that special-cases the tests. We found no equivalent check in GitHub Code Quality's documentation. Details and limits are on Your AI agent says the tests pass.
Deterministic by default
A normal Skylos scan does not upload source or call a model, so its findings don't depend on a model's output. Dependency CVE checks query OSV and some import checks query package registries; the optional LLM features use a model you choose.
Billing notes
Two points from GitHub's own pages and forum, stated as they appear:
- Billing for GitHub Code Quality "begins automatically at general availability (July 20, 2026)" (changelog).
- Two GitHub Community threads ask about charges after Code Quality was turned off: #208611 (23 Sep 2026) and #209596 (6 Oct 2026). The accepted answer in #209596 explains the charge as a prorated licence for the current billing period.
If you trial it, note when the billing period ends.
Using both
They answer different questions, so running both on the same pull request is reasonable:
- GitHub Code Quality for reliability and maintainability queries, Copilot Autofix and the org dashboard.
- Skylos for project-wide Python dead code, security and secrets checks you can run locally, and the done check on agent-written changes.
If you want one gate, decide which tool's result is the required status check and let the other comment.
Related
- Best Python SAST tools in 2026
- Bandit vs CodeQL vs Semgrep for Python
- SonarQube vs Skylos for Python
- Python security scanning in GitHub Actions
- Skylos CI/CD docs
Try Skylos
pip install skylos
skylos . -a
-a turns on the security, secrets, quality, AI-defect and dependency checks; the dependency check queries OSV over the network.