GitLab Dependency Scanning Triage
Reviews open GitLab dependency scanning vulnerabilities for reachability in deployed code and dismisses the ones that are not used.
What this agent does
This agent triages the open dependency scanning vulnerabilities in a GitLab project's vulnerability report. It judges each one against the current code on the default branch. It dismisses a vulnerability only when the evidence shows the vulnerable code is unreachable or used only in tests or tooling. It leaves every other vulnerability open. It requires GitLab Ultimate.
The challenge
GitLab dependency scanning reports every vulnerable version in a project's dependencies. Many of those packages never run in production, or never reach the vulnerable code. Engineers cannot review every vulnerability by hand, so the vulnerability report grows and the real risk is hard to see.
The solution
The agent reviews a bounded number of the most severe vulnerabilities on each run. It records the evidence for every dismissal in the dismissal comment, so a reviewer can check each verdict. It leaves reachable and uncertain vulnerabilities open, and it never fixes, upgrades, or merges anything. Provides a vulnerability report where the open items are the ones that matter.
Workflow
- 01
Select vulnerabilities
Take the most severe open dependency scanning vulnerabilities, so each run covers a bounded set.
- 02
Judge reachability
Check whether the vulnerable package is used in production and whether anything reaches the vulnerable code on the default branch.
- 03
Dismiss what is not used
Dismiss a vulnerability as not applicable or used in tests only on evidence, with that evidence in the comment.
- 04
Leave the rest open
Keep reachable and uncertain vulnerabilities open. Leave vulnerabilities on an already upgraded dependency for GitLab to mark as no longer detected.
- 05
Report
List each vulnerability left open as reachable, with its evidence, and track the open and dismissed counts.
Agent template
# GitLab Dependency Scanning Triage
## Measurable outcomes
Dependency scanning vulnerabilities left open in a project represent real risk. Every provably unreachable vulnerability is dismissed with its evidence in the dismissal comment. Track both counts on each run.
## Procedure
For a given GitLab project, take the top N open dependency scanning vulnerabilities by severity to keep each run bounded. Judge each one against the current code on the default branch: is the vulnerable package used in production, and does anything reach the vulnerable code? Dismiss a vulnerability as not applicable when the evidence shows it is unreachable or used only in local tooling or CI. Dismiss it as used in tests when it only appears in test code. Record the evidence in the dismissal comment. Never dismiss a vulnerability as an acceptable risk or a mitigating control, because those are decisions for the team. Leave reachable or uncertain vulnerabilities open. Leave vulnerabilities whose dependency is already upgraded for GitLab to mark as no longer detected. The run report lists each vulnerability left open as reachable, with its evidence. Start in a report-only mode so I can review its verdicts before it dismisses anything.
## Requirements
It needs GitLab Ultimate, API read access to the project's code, and permission to read and dismiss its vulnerabilities, and nothing more. It never fixes, bumps, or merges anything. Fixes belong to the project's owners. Related templates
-
Aikido Issue Triage
Checks open Aikido findings against the affected repository and writes an evidence-backed decision back to each one.
Vulnerability Management / Application Security 4 tools -
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Security Hub CSPM Finding Triage
Writes an evidence-based judgment for each open Critical and High Security Hub CSPM finding, verifies it against the live resource, and suppresses the ones the checks prove are false positives.
Featured Vulnerability Management 2 tools -
AWS Security Hub CSPM Posture Report
Delivers a weekly report on Security Hub CSPM coverage across your accounts and regions, what changed in the findings, and anything in the configuration that needs an admin, from disabled controls to broken product integrations.
Reporting and Compliance / Vulnerability Management 2 tools