Improvement

June 3, 20251 Minute Read

Custom roles can now review secret scanning alert dismissal requests

Delegated alert dismissal allows you to require a review process before dismissing a secret scanning alert. Previously, only organization owners and security managers had permission to review these requests. Now you can assign the “Review and manage secret scanning alert dismissal requests” permission to custom roles at the organization level. This makes it easier to delegate alert review responsibilities to the right people in your organization.

Individuals assigned custom roles will only see requests for repositories where they have access to secret scanning alerts.

Support for programmatic actors using this permission will be available in the coming weeks.

To learn more about secret scanning alert dismissal requests, see our documentation.

Subscribe to our developer newsletter

Discover tips, technical guides, and best practices in our biweekly newsletter just for devs.

By submitting, I agree to let GitHub and its affiliates use my information for personalized communications, targeted advertising, and campaign effectiveness. See the GitHub Privacy Statement for more details.

Custom roles can now review secret scanning alert dismissal requests - GitHub Changelog