Improvement

December 19, 20251 Minute Read

You can now require reviews before closing Dependabot alerts with delegated alert dismissal

Delegated alert dismissal allows you to require a review process before Dependabot alerts are closed. This feature is available to GitHub Code Security customers and can be used in both the UI and API.

This helps you better manage security risk, as well as meet audit and compliance requirements. Delegated alert dismissal brings the same governance controls available for code scanning and Secret Scanning to Dependabot alerts.

This feature helps organizations:

  • Increase accountability across development teams when addressing vulnerability alerts.
  • Prevent insecure activity such as accidental or unauthorized dismissals.
  • Manage alerts at scale by making alert activity easier to govern and audit.

Delegated alert dismissal for Dependabot is available for code security customers now on github.com and in GitHub Enterprise Server 3.21.

To learn more about Dependabot alert dismissal requests, see our documentation about code security.

Subscribe to our developer newsletter

Discover tips, technical guides, and best practices in our biweekly newsletter just for devs.

By submitting, I agree to let GitHub and its affiliates use my information for personalized communications, targeted advertising, and campaign effectiveness. See the GitHub Privacy Statement for more details.

You can now require reviews before closing Dependabot alerts with delegated alert dismissal - GitHub Changelog