On August 20, 2026, GitHub added Mitigated as a reason for dismissing a code scanning alert1. It covers the case where the vulnerability remains in the code but controls outside the code — a web application firewall, a network policy — reduce its risk1.
GitHub says the new reason helps distinguish mitigated vulnerabilities from alerts marked “Won’t fix,” align dismissals with formal exception and risk-acceptance processes, and reduce the need to track those decisions outside GitHub1. The changelog entry does not state which plans or deployments it covers. The company also made a Trends tab for organization-wide code quality generally available the day before, but that concerns Code Quality and is a separate surface from this change.
Sources
- Code scanning adds a mitigated alert dismissal reason - GitHub changelog (August 20, 2026)