From the course: GitHub Advanced Security Cert Prep by Microsoft Press

Unlock this course with a free trial

Join today to access over 24,700 courses taught by industry experts.

Determine if and why a code scanning alert needs to be dismissed

Determine if and why a code scanning alert needs to be dismissed - GitHub Tutorial

From the course: GitHub Advanced Security Cert Prep by Microsoft Press

Determine if and why a code scanning alert needs to be dismissed

- [Instructor] Yes, we want to be careful dismissing alerts because alerts, whether they come up through dependabot, secret scanning, code scanning, will close themselves. That is GitHub will close them once you've resolved the underlying problem, so to dismiss alert is to override GitHub, so we need to justify when we make that choice and validate or confirm basically, that you understand the vulnerability and so on and so forth. This auditing also maintains end-to-end traceability because the rest of your governance team will see, hopefully with very little delay, that an alert was dismissed and can take action if necessary. This is also a best practice reminder to regularly revisit dismissed alerts, just part of your hygiene, and ensure that you don't have anything that slipped through the cracks basically. Next case study, Graphite Industries, they evaluate a code scanning alert in their manufacturing software, and in one case, I guess they justify dismissing the alert after…

Contents