Skip to main content
{ Vulnerability Management }

GitHub Dependabot Alert Triage Recheck

Rechecks and reopens Dependabot alerts that were dismissed as not used if a later code change makes them reachable.

What this agent does

This agent keeps the list of Dependabot alerts dismissed as not used on a GitHub repository accurate as the code changes. When the default branch changes, it finds the dismissals a change could affect. It rechecks each one against the current code and reopens an alert only when the vulnerable code is now reachable.

The challenge

A Dependabot alert dismissed as not used records that the vulnerable code was unreachable at the commit where someone dismissed it. GitHub never checks that dismissal again. A later code change can add a call, route user input to an existing call, or remove a mitigation. GitHub does not reopen the alert, so the team no longer sees that risk among the open alerts.

The solution

The agent compares each change on the default branch against the evidence behind each dismissal. It rechecks only the dismissals the change could affect, and it rechecks when in doubt. If they are found to be reachable due to the changes, it reopens those alerts.

Workflow

  1. 01

    Detect change

    Compare the default branch with the commit of the last run, and stop when it has not moved or only documentation changed.

  2. 02

    Select dismissals

    Read each alert dismissed as not used and its evidence, and flag the ones the change could affect.

  3. 03

    Recheck reachability

    Check whether the recorded reason for each flagged dismissal still holds in the current code on the default branch.

  4. 04

    Reopen reachable alerts

    Reopen an alert when its vulnerable code is now reachable or when the dismissal can no longer be confirmed.

  5. 05

    Report

    List each reopened alert with the change that made it reachable, and track the reopened and rechecked counts.

Agent template

# GitHub Dependabot Alert Triage Recheck

## Measurable outcomes

Every not used dismissal on a repository still holds at the current commit on the default branch. Every alert whose vulnerable code became reachable is reopened, with the reason in the run report. Track the reopened alerts and rechecked dismissals on each run.

## Procedure

For a given repository, compare the default branch with the commit the last run reconciled. Stop when the branch has not moved or when only documentation and images changed. On the first run, record the current commit and recheck nothing, so a dismissal is never judged again at the commit it was made on. Read each not used dismissal and the evidence in its dismissal comment. For each dismissal, decide whether the change could undermine that evidence: a new call into the vulnerable code, user input that reaches an existing call, a removed mitigation, a changed configuration, or code that now ships. Recheck every dismissal when the change is too large to compare. Recheck the flagged dismissals against the current code, starting from the recorded evidence. Reopen an alert when its vulnerable code is now reachable, or when the dismissal can no longer be confirmed. Reopening a false alarm costs less than leaving a live alert dismissed. GitHub does not support a comment when an alert is reopened. The run report lists each reopened alert with the change that made it reachable and its evidence. Start in a report-only mode so I can review its decisions before it reopens any alerts.

## Requirements

It needs GitHub API read access to the repository's code and read and write access to its Dependabot alerts, and nothing more. It only reopens alerts. It never dismisses alerts, and it never fixes, bumps, or merges anything. Dismissal belongs to the triage agent and the repository's owners.