Trending:

GitHub adds mitigated alert dismissal option for code scanning alerts

Illustration of GitHub code scanning with mitigated dismissal concept
TechStaged-owned

Summary

  • GitHub now allows dismissing a code scanning alert with the reason Mitigated when a vulnerability remains in the code but external controls are in place

GitHub's changelog notes a new dismissal reason for code scanning alerts: Mitigated. This applies when a vulnerability remains in the code but external controls, such as a web application firewall or network controls, are in place.

CONTEXT FROM THE GITHUB BLOG

The update is described in a GitHub Blog changelog entry published on 2026-08-20. TechStaged has also covered CodeQL 2.26.3 expands JavaScript, TypeScript, and Vue modeling and tightens GitHub Actions queries.

WHO IS AFFECTED

Developers and security teams using GitHub's code scanning feature.

NOTES ON EXTERNAL CONTROLS

The post references external controls as examples for mitigated dismissal, including a web application firewall or network controls.

  • External controls such as a web application firewall (WAF) or network controls

WHAT HAPPENS NEXT

The GitHub Blog post serves as the primary source for this update.

Reporting by Owen Blackridge; editing by TechStaged editors

Editorial disclosure: This article was prepared with AI assistance from a source-limited research package and passed TechStaged's automated factual, originality, licensing, and publication checks.

Our Standards: The TechStaged Editorial Principles.

Suggested Topics: Software Business Software
f in

Owen Blackridge

Owen Blackridge

Technology Editor

Owen covers platform shifts, AI launches, and the practical impact of emerging technology on small teams.