Skip to content

Intelligent severity scoring #12642

Mar 10, 2022 · 1 comments · 1 reply
Discussion options

You must be logged in to vote

Hi @sandstrom, that's good feedback. We're working on making alerts more relevant. We just released a new beta where alerts now can surface vulnerable code paths for Python, and are working on extending that to other ecosystems. We're also building out the ability to flag development dependencies and transitive dependency paths. Once we're able to differentiate those alerts, we'll be able to make Dependabot Alerts a lot smarter, or even potentially configurable.

Let me know if you'd like to provide more feedback over a 1 hour user research session (gift card provided for your time)!

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@sandstrom
Comment options

Answer selected by erinhav
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Dependabot Code Security Build security into your GitHub workflow with features to keep your codebase secure Product Feedback
2 participants