Skip to main content

About Dependabot auto-triage rules

Who can use this feature?

presets are available for all repository types.

Custom auto-triage rules are available for the following repository types:

Dependabot auto-triage rules allow you to instruct Dependabot to automatically triage Dependabot alerts. You can use auto-triage rules to automatically dismiss or snooze certain alerts, or specify the alerts you want Dependabot to open pull requests for. Rules are applied before alert notifications are sent, so enabling rules that auto-dismiss low-risk alerts will prevent notification noise from future matching alerts.

There are two types of Dependabot auto-triage rules:

  • presets
  • Custom auto-triage rules

Note

presets for Dependabot alerts are rules that are available for all repositories.

presets are rules curated by . The Dismiss low impact issues for development-scoped dependencies is a preset rule. This rule auto-dismisses certain types of vulnerabilities that are found in npm dependencies used in development. The rule has been curated to reduce false positives and reduce alert fatigue. You cannot modify presets. For more information about presets, see Using preset rules to prioritize Dependabot alerts.

The rule is enabled by default for public repositories and can be opted into for private repositories. You can enable the rule for a private repository via the Settings tab for the repository. For more information, see Enabling the Dismiss low impact issues for development-scoped dependencies rule for your private repository.

Note

Custom auto-triage rules for Dependabot alerts are available for organization-owned repositories with Code Security enabled.

With custom auto-triage rules, you can create your own rules to automatically dismiss or reopen alerts based on targeted metadata, such as severity, package name, CWE, and more. You can also specify which alerts you want Dependabot to open pull requests for. For more information, see Customizing auto-triage rules to prioritize Dependabot alerts.

You can create custom rules from the Settings tab of the repository, provided the repository belongs to an organization that has a license for Code Security or Advanced Security. For more information, see Adding custom auto-triage rules to your repository.

Whilst you may find it useful to use auto-triage rules to auto-dismiss alerts, you can still reopen auto-dismissed alerts and filter to see which alerts have been auto-dismissed. For more information, see Managing alerts that have been automatically dismissed by a Dependabot auto-triage rule.

Additionally, auto-dismissed alerts are still available for reporting and reviewing, and can be auto-reopened if the alert metadata changes, for example:

  • If you change the scope of a dependency from development to production.
  • If modifies certain metadata for the related advisory.

Auto-dismissed alerts are defined by the resolution:auto-dismiss close reason. Automatic dismissal activity is included in alert webhooks, REST and GraphQL APIs, and the audit log. For more information, see REST API endpoints for Dependabot alerts, and the "repository_vulnerability_alert" section in Reviewing the audit log for your organization.