Code scanning adds a mitigated alert dismissal reason
You can now dismiss a code scanning alert with the reason Mitigated when a vulnerability remains in the code but external controls, such as a web application firewall or network… The post Code scanning adds a mitigated alert dismissal reason appeared first on The GitHub Blog.
What happened
Starting August 20, 2026, GitHub has added a 'Mitigated' dismissal reason for code scanning alerts, permitting developers to acknowledge vulnerabilities that are being managed externally.
Why it matters
This update helps developers better track the status of vulnerabilities, enabling them to implement a more nuanced approach to risk management. It also clarifies the condition of vulnerabilities within the code, which can improve team communication and workflow decision-making.