-- [Configure and Use Dependency Management]
You have enabled security updates for a repository. When does GitHub mark a Dependabot alert as resolved for that repository?
A Dependabot alert is marked as resolved only after the related pull request is merged into the repository. This indicates that the vulnerable dependency has been officially replaced with a secure version in the active codebase.
Simply generating a PR or passing checks does not change the alert status; merging is the key step.
Cristal
10 days agoMatt
13 days agoGene
16 days agoCristal
19 days agoChauncey
22 days agoWilliam
23 days agoMichel
24 days agoMatt
1 months agoDorothy
1 months agoAlaine
2 months agoKathrine
24 days agoShawna
27 days ago