Skip to main content
{ Vulnerability Management } Featured agent

GitHub Dependabot Alert Triage

Reviews open Dependabot alerts for reachability in deployed code and dismisses the unreachable ones.

What this agent does

This agent triages the open Dependabot alerts on a GitHub repository. It judges each alert against the current code on the default branch. It dismisses an alert as not used only when the evidence shows the vulnerable code is unreachable or used outside production. It leaves every other alert open.

The challenge

Dependabot raises an alert for every vulnerable version in a dependency manifest. Many of those packages never run in production, or never reach the vulnerable code. Engineers cannot review every alert by hand, so the open list grows and the real risk is hard to see.

The solution

The agent reviews a bounded number of the most severe alerts on each run. It records the evidence for every dismissal in the dismissal comment, so a reviewer can check each verdict. It leaves reachable and uncertain alerts open, and it never fixes, upgrades, or merges anything.

Workflow

  1. 01

    Select alerts

    Take the top alerts by severity, so each run covers a bounded set.

  2. 02

    Judge reachability

    Check whether the vulnerable package is used in production and whether anything reaches the vulnerable code on the default branch.

  3. 03

    Dismiss unreachable alerts

    Dismiss an alert as not used only on evidence of unreachability or non-production use, with that evidence in the comment.

  4. 04

    Leave the rest open

    Keep reachable and uncertain alerts open. Leave alerts on an already upgraded dependency for Dependabot to close.

  5. 05

    Report

    List each alert left open as reachable, with its evidence, and track the open and dismissed counts.

Agent template

# GitHub Dependabot Alert Triage

## Measurable outcomes

Dependabot alerts left open on a repository represent real risk. Every provably unreachable alert is dismissed as not used, with its evidence in the dismissal comment. Track both values on each run.

## Procedure

For a given repository, take the top N alerts by highest severity to keep each run bounded. Judge each alert against the current code on the default branch: is the vulnerable package used in production, and does anything reach the vulnerable code? Dismiss an alert as not used only when the evidence shows it is unreachable or in a non-production use (local tooling, CI only, test only, etc), and record that evidence in the dismissal comment. Leave reachable or uncertain alerts open. Leave alerts whose dependency is already upgraded for Dependabot to close. GitHub does not support comments on an open alert. The run report lists each alert left open as reachable, with its evidence. Start in a report-only mode so I can review its verdicts before it comments on or dismisses any alerts.

## Requirements

It needs GitHub API read access to the repository's code and read and write access to its Dependabot alerts, and nothing more. It never fixes, bumps, or merges anything. Fixes belong to the repository's owners.