GitHub Code Scanning Adds a Mitigated Dismissal Reason for Alerts

GitHub added Mitigated as a dismissal reason for code scanning alerts on August 20, 2026. It applies when a vulnerability remains in the code but external controls such as a WAF or network policy reduce its risk, distinguishing those cases from alerts marked Won't fix.

On August 20, 2026, GitHub added Mitigated as a reason for dismissing a code scanning alert1. It covers the case where the vulnerability remains in the code but controls outside the code — a web application firewall, a network policy — reduce its risk1.

GitHub says the new reason helps distinguish mitigated vulnerabilities from alerts marked “Won’t fix,” align dismissals with formal exception and risk-acceptance processes, and reduce the need to track those decisions outside GitHub1. The changelog entry does not state which plans or deployments it covers. The company also made a Trends tab for organization-wide code quality generally available the day before, but that concerns Code Quality and is a separate surface from this change.

Sources

  1. Code scanning adds a mitigated alert dismissal reason - GitHub changelog (August 20, 2026)

We publish the latest AI news every day.

Subscribe via RSS Get new posts the moment they go live.

Search other keywords →