GitHub Dependabot Alert Triage Recheck
Rechecks and reopens Dependabot alerts that were dismissed as not used if a later code change makes them reachable.
What this agent does
This agent keeps the list of Dependabot alerts dismissed as not used on a GitHub repository accurate as the code changes. When the default branch changes, it finds the dismissals a change could affect. It rechecks each one against the current code and reopens an alert only when the vulnerable code is now reachable.
The challenge
A Dependabot alert dismissed as not used records that the vulnerable code was unreachable at the commit where someone dismissed it. GitHub never checks that dismissal again. A later code change can add a call, route user input to an existing call, or remove a mitigation. GitHub does not reopen the alert, so the team no longer sees that risk among the open alerts.
The solution
The agent compares each change on the default branch against the evidence behind each dismissal. It rechecks only the dismissals the change could affect, and it rechecks when in doubt. If they are found to be reachable due to the changes, it reopens those alerts.
Workflow
- 01
Detect change
Compare the default branch with the commit of the last run, and stop when it has not moved or only documentation changed.
- 02
Select dismissals
Read each alert dismissed as not used and its evidence, and flag the ones the change could affect.
- 03
Recheck reachability
Check whether the recorded reason for each flagged dismissal still holds in the current code on the default branch.
- 04
Reopen reachable alerts
Reopen an alert when its vulnerable code is now reachable or when the dismissal can no longer be confirmed.
- 05
Report
List each reopened alert with the change that made it reachable, and track the reopened and rechecked counts.
Agent template
# GitHub Dependabot Alert Triage Recheck
## Measurable outcomes
Every not used dismissal on a repository still holds at the current commit on the default branch. Every alert whose vulnerable code became reachable is reopened, with the reason in the run report. Track the reopened alerts and rechecked dismissals on each run.
## Procedure
For a given repository, compare the default branch with the commit the last run reconciled. Stop when the branch has not moved or when only documentation and images changed. On the first run, record the current commit and recheck nothing, so a dismissal is never judged again at the commit it was made on. Read each not used dismissal and the evidence in its dismissal comment. For each dismissal, decide whether the change could undermine that evidence: a new call into the vulnerable code, user input that reaches an existing call, a removed mitigation, a changed configuration, or code that now ships. Recheck every dismissal when the change is too large to compare. Recheck the flagged dismissals against the current code, starting from the recorded evidence. Reopen an alert when its vulnerable code is now reachable, or when the dismissal can no longer be confirmed. Reopening a false alarm costs less than leaving a live alert dismissed. GitHub does not support a comment when an alert is reopened. The run report lists each reopened alert with the change that made it reachable and its evidence. Start in a report-only mode so I can review its decisions before it reopens any alerts.
## Requirements
It needs GitHub API read access to the repository's code and read and write access to its Dependabot alerts, and nothing more. It only reopens alerts. It never dismisses alerts, and it never fixes, bumps, or merges anything. Dismissal belongs to the triage agent and the repository's owners. Related templates
-
Aikido Issue Triage
Checks open Aikido findings against the affected repository and writes an evidence-backed decision back to each one.
Vulnerability Management / Application Security 4 tools -
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Security Hub CSPM Finding Triage
Writes an evidence-based judgment for each open Critical and High Security Hub CSPM finding, verifies it against the live resource, and suppresses the ones the checks prove are false positives.
Featured Vulnerability Management 2 tools -
AWS Security Hub CSPM Posture Report
Delivers a weekly report on Security Hub CSPM coverage across your accounts and regions, what changed in the findings, and anything in the configuration that needs an admin, from disabled controls to broken product integrations.
Reporting and Compliance / Vulnerability Management 2 tools