GitHub's changelog notes a new dismissal reason for code scanning alerts: Mitigated. This applies when a vulnerability remains in the code but external controls, such as a web application firewall or network controls, are in place.
CONTEXT FROM THE GITHUB BLOG
The update is described in a GitHub Blog changelog entry published on 2026-08-20. TechStaged has also covered CodeQL 2.26.3 expands JavaScript, TypeScript, and Vue modeling and tightens GitHub Actions queries.
WHO IS AFFECTED
Developers and security teams using GitHub's code scanning feature.
NOTES ON EXTERNAL CONTROLS
The post references external controls as examples for mitigated dismissal, including a web application firewall or network controls.
- External controls such as a web application firewall (WAF) or network controls
WHAT HAPPENS NEXT
The GitHub Blog post serves as the primary source for this update.
RELATED COVERAGE
- CodeQL 2.26.3 expands JavaScript, TypeScript, and Vue modeling and tightens GitHub Actions queries
- GitHub introduces a dedicated Actions path for Code Quality, separating CodeQL workflows
- GitHub expands credential control with token-type deauthorization and revocation during security incidents
- GitHub adds Trends tab to organization Code Quality dashboard to track code health over time
- Software articles
SOURCES
- Archive: 2026 - GitHub Changelog: Code scanning adds a mitigated alert dismissal reason Published · Primary source








