Skip to main content
{ Vulnerability Management }

GitLab Dependency Scanning Triage

Reviews open GitLab dependency scanning vulnerabilities for reachability in deployed code and dismisses the ones that are not used.

What this agent does

This agent triages the open dependency scanning vulnerabilities in a GitLab project's vulnerability report. It judges each one against the current code on the default branch. It dismisses a vulnerability only when the evidence shows the vulnerable code is unreachable or used only in tests or tooling. It leaves every other vulnerability open. It requires GitLab Ultimate.

The challenge

GitLab dependency scanning reports every vulnerable version in a project's dependencies. Many of those packages never run in production, or never reach the vulnerable code. Engineers cannot review every vulnerability by hand, so the vulnerability report grows and the real risk is hard to see.

The solution

The agent reviews a bounded number of the most severe vulnerabilities on each run. It records the evidence for every dismissal in the dismissal comment, so a reviewer can check each verdict. It leaves reachable and uncertain vulnerabilities open, and it never fixes, upgrades, or merges anything. Provides a vulnerability report where the open items are the ones that matter.

Workflow

  1. 01

    Select vulnerabilities

    Take the most severe open dependency scanning vulnerabilities, so each run covers a bounded set.

  2. 02

    Judge reachability

    Check whether the vulnerable package is used in production and whether anything reaches the vulnerable code on the default branch.

  3. 03

    Dismiss what is not used

    Dismiss a vulnerability as not applicable or used in tests only on evidence, with that evidence in the comment.

  4. 04

    Leave the rest open

    Keep reachable and uncertain vulnerabilities open. Leave vulnerabilities on an already upgraded dependency for GitLab to mark as no longer detected.

  5. 05

    Report

    List each vulnerability left open as reachable, with its evidence, and track the open and dismissed counts.

Agent template

# GitLab Dependency Scanning Triage

## Measurable outcomes

Dependency scanning vulnerabilities left open in a project represent real risk. Every provably unreachable vulnerability is dismissed with its evidence in the dismissal comment. Track both counts on each run.

## Procedure

For a given GitLab project, take the top N open dependency scanning vulnerabilities by severity to keep each run bounded. Judge each one against the current code on the default branch: is the vulnerable package used in production, and does anything reach the vulnerable code? Dismiss a vulnerability as not applicable when the evidence shows it is unreachable or used only in local tooling or CI. Dismiss it as used in tests when it only appears in test code. Record the evidence in the dismissal comment. Never dismiss a vulnerability as an acceptable risk or a mitigating control, because those are decisions for the team. Leave reachable or uncertain vulnerabilities open. Leave vulnerabilities whose dependency is already upgraded for GitLab to mark as no longer detected. The run report lists each vulnerability left open as reachable, with its evidence. Start in a report-only mode so I can review its verdicts before it dismisses anything.

## Requirements

It needs GitLab Ultimate, API read access to the project's code, and permission to read and dismiss its vulnerabilities, and nothing more. It never fixes, bumps, or merges anything. Fixes belong to the project's owners.