GitHub Dependabot Gets Customizable Auto-triage Rules to Reduce False Positives

After launching Dependabot’s auto-dismiss policies a few months ago to reduce the number of false positive alerts, GitHub is now adding custom rules support for developers to define the criteria to auto-dismiss and reopen alerts. While solutions like Dependabot promise to help improve security by automatically identifying vulnerabilities in a project’s dependencies, all comes at a price.

Source: InfoQ

 


Date:

Categorie(s):