GitHub Dependabot Alert Triage
Reviews open Dependabot alerts for reachability in deployed code and dismisses the unreachable ones.
What this agent does
This agent triages the open Dependabot alerts on a GitHub repository. It judges each alert against the current code on the default branch. It dismisses an alert as not used only when the evidence shows the vulnerable code is unreachable or used outside production. It leaves every other alert open.
The challenge
Dependabot raises an alert for every vulnerable version in a dependency manifest. Many of those packages never run in production, or never reach the vulnerable code. Engineers cannot review every alert by hand, so the open list grows and the real risk is hard to see.
The solution
The agent reviews a bounded number of the most severe alerts on each run. It records the evidence for every dismissal in the dismissal comment, so a reviewer can check each verdict. It leaves reachable and uncertain alerts open, and it never fixes, upgrades, or merges anything.
Workflow
- 01
Select alerts
Take the top alerts by severity, so each run covers a bounded set.
- 02
Judge reachability
Check whether the vulnerable package is used in production and whether anything reaches the vulnerable code on the default branch.
- 03
Dismiss unreachable alerts
Dismiss an alert as not used only on evidence of unreachability or non-production use, with that evidence in the comment.
- 04
Leave the rest open
Keep reachable and uncertain alerts open. Leave alerts on an already upgraded dependency for Dependabot to close.
- 05
Report
List each alert left open as reachable, with its evidence, and track the open and dismissed counts.
Agent template
# GitHub Dependabot Alert Triage
## Measurable outcomes
Dependabot alerts left open on a repository represent real risk. Every provably unreachable alert is dismissed as not used, with its evidence in the dismissal comment. Track both values on each run.
## Procedure
For a given repository, take the top N alerts by highest severity to keep each run bounded. Judge each alert against the current code on the default branch: is the vulnerable package used in production, and does anything reach the vulnerable code? Dismiss an alert as not used only when the evidence shows it is unreachable or in a non-production use (local tooling, CI only, test only, etc), and record that evidence in the dismissal comment. Leave reachable or uncertain alerts open. Leave alerts whose dependency is already upgraded for Dependabot to close. GitHub does not support comments on an open alert. The run report lists each alert left open as reachable, with its evidence. Start in a report-only mode so I can review its verdicts before it comments on or dismisses any alerts.
## Requirements
It needs GitHub API read access to the repository's code and read and write access to its Dependabot alerts, and nothing more. It never fixes, bumps, or merges anything. Fixes belong to the repository's owners. Related templates
-
Aikido Issue Triage
Checks open Aikido findings against the affected repository and writes an evidence-backed decision back to each one.
Vulnerability Management / Application Security 4 tools -
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Security Hub CSPM Finding Triage
Writes an evidence-based judgment for each open Critical and High Security Hub CSPM finding, verifies it against the live resource, and suppresses the ones the checks prove are false positives.
Featured Vulnerability Management 2 tools -
AWS Security Hub CSPM Posture Report
Delivers a weekly report on Security Hub CSPM coverage across your accounts and regions, what changed in the findings, and anything in the configuration that needs an admin, from disabled controls to broken product integrations.
Reporting and Compliance / Vulnerability Management 2 tools