Code scanning adds mitigated alert dismissal reason
Code scanning alerts can now be dismissed with a "Mitigated" reason when vulnerabilities are controlled by external measures like web application firewalls or network policies. This allows developers to document when risks are managed outside the application itself.
You can now dismiss a code scanning alert with the reason Mitigated when a vulnerability remains in the code but external controls, such as a web application firewall or network policy, mitigate its risk.
The new dismissal reason helps you distinguish mitigated vulnerabilities from alerts marked Won’t fix, align dismissals with formal exception and risk-acceptance processes, and reduce the need to track these decisions outside GitHub.
For more information, see resolving code scanning alerts.
The post Code scanning adds a mitigated alert dismissal reason appeared first on The GitHub Blog.
Source: original entry ↗