| title | Managing Dependabot malware alerts | ||
|---|---|---|---|
| intro | Find and triage malicious dependencies in your project with {% data variables.product.prodname_dependabot_malware_alerts %}. | ||
| shortTitle | Manage malware alerts | ||
| permissions | {% data reusables.gated-features.dependabot-malware-alerts %} | ||
| versions |
|
||
| contentType | how-tos | ||
| category |
|
{% data reusables.repositories.navigate-to-repo %} {% data reusables.repositories.sidebar-security %} {% data reusables.dependabot.view-malware-alerts %} {% data reusables.dependabot.filter-alerts-step %}
{% data reusables.profile.access_org %}
- Click the name of the organization you want to view. {% data reusables.organizations.security-overview %} {% data reusables.dependabot.view-malware-alerts %} {% data reusables.dependabot.filter-alerts-step %}
{% data reusables.enterprise-accounts.access-enterprise %}
- At the top of the page, click the {% data variables.product.prodname_security_and_quality_tab %} tab. {% data reusables.dependabot.view-malware-alerts %} {% data reusables.dependabot.filter-alerts-step %}
- Navigate to the {% data variables.product.prodname_dependabot_malware_alerts %} view for your repository, organization, or enterprise.
- Click the name of the {% data variables.product.prodname_dependabot_malware_alert_short %} you want to dismiss.
- In the top-right corner, click Dismiss alert {% octicon "triangle-down" aria-hidden="true" aria-label="triangle-down" %}, then select a reason for dismissing the alert.
- Optionally, write a dismissal comment. The dismissal comment will be added to the alert timeline and can be used as justification during auditing and reporting.
- Click Dismiss alert.
-
Navigate to the {% data variables.product.prodname_dependabot_malware_alerts %} view for your repository, organization, or enterprise.
-
To view closed alerts, click {% octicon "shield-check" aria-hidden="true" aria-label="shield-check" %} NUMBER Closed.
-
Click the alert that you would like to view or update.
-
In the top-right corner, click Reopen.
To help reduce false positives for internal packages and low-risk alerts, you can configure {% data variables.dependabot.auto_triage_rules %} to automatically dismiss alerts that meet certain criteria. See AUTOTITLE.
