-- [Configure and Use Dependency Management]
You have enabled security updates for a repository. When does GitHub mark a Dependabot alert as resolved for that repository?
A Dependabot alert is marked as resolved only after the related pull request is merged into the repository. This indicates that the vulnerable dependency has been officially replaced with a secure version in the active codebase.
Simply generating a PR or passing checks does not change the alert status; merging is the key step.
Lashandra
5 days agoKristian
10 days agoDenise
15 days agoBrittni
20 days agoStefan
25 days agoSharika
1 month agoCorrina
1 month agoElmer
1 month agoEura
3 months ago