Skip to main content
{ Vulnerability Management }

GitLab Dependency Scanning Triage Recheck

Rechecks and reverts GitLab dependency vulnerabilities that were dismissed as not applicable or used in tests when a code change makes them reachable.

What this agent does

This agent keeps the dismissed dependency scanning vulnerabilities in a GitLab project accurate as the code changes. When the default branch changes, it finds the dismissals a change could affect. It rechecks each one against the current code and reverts a vulnerability to detected only when the vulnerable code is now reachable. It requires GitLab Ultimate.

The challenge

A vulnerability dismissed as not applicable or used in tests was unreachable at the commit where it was dismissed. GitLab never checks that decision again. A later change can add a call, route user input to an existing call, or remove a mitigation. GitLab does not reopen the vulnerability, so the team no longer sees that risk in the vulnerability report.

The solution

The agent compares each change on the default branch against the evidence behind each dismissal. It rechecks only the dismissals the change could affect, and it rechecks when in doubt. If a dismissed vulnerability is now reachable, it reverts it to detected with a comment that explains why. Provides a vulnerability report where every dismissal still holds.

Workflow

  1. 01

    Detect change

    Compare the default branch with the commit of the last run, and stop when it has not moved or only documentation changed.

  2. 02

    Select dismissals

    Read each vulnerability dismissed as not applicable or used in tests, and flag the ones the change could affect.

  3. 03

    Recheck reachability

    Check whether the recorded reason for each flagged dismissal still holds in the current code.

  4. 04

    Revert reachable vulnerabilities

    Revert a vulnerability to detected when its vulnerable code is now reachable or the dismissal can no longer be confirmed.

  5. 05

    Report

    List each reverted vulnerability with the change that made it reachable, and track the reverted and rechecked counts.

Agent template

# GitLab Dependency Scanning Triage Recheck

## Measurable outcomes

Every dependency vulnerability dismissed as not applicable or used in tests still holds at the current commit on the default branch. Every one that became reachable is reverted to detected, with the reason in a comment. Track the reverted vulnerabilities and rechecked dismissals on each run.

## Procedure

For a given GitLab project, compare the default branch with the commit the last run reconciled. Stop when the branch has not moved or when only documentation and images changed. On the first run, record the current commit and recheck nothing, so a dismissal is never judged again at the commit it was made on. Read each vulnerability dismissed as not applicable or used in tests, and the evidence in its comment. For each one, decide whether the change could undermine that evidence: a new call into the vulnerable code, user input that reaches an existing call, a removed mitigation, a changed configuration, or code that now ships. Recheck every dismissal when the change is too large to compare. Revert a vulnerability to detected when its vulnerable code is now reachable, or when the dismissal can no longer be confirmed, and add a comment with the change that made it reachable. Reverting a false alarm costs less than leaving a live vulnerability dismissed. Leave dismissals a person made as an acceptable risk or a mitigating control alone. The run report lists each reverted vulnerability with the change that made it reachable and its evidence. Start in a report-only mode so I can review its decisions before it reverts anything.

## Requirements

It needs GitLab Ultimate, API read access to the project's code, and permission to read vulnerabilities and revert them to detected, and nothing more. It never dismisses vulnerabilities, and it never fixes, bumps, or merges anything.