A RetroSearch Logo

Home - News ( United States | United Kingdom | Italy | Germany ) - Football scores

Search Query:

Showing content from https://docs.github.com/en/code-security/security-overview/viewing-metrics-for-dependabot-alerts below:

Viewing metrics for Dependabot alerts

You can use security overview to see how many Dependabot alerts are in repositories across your organization, to prioritize the most critical alerts to fix, and to identify repositories where you may need to take action.

Who can use this feature?

Access requires:

Organizations owned by a GitHub Team account with GitHub Code Security, or owned by a GitHub Enterprise account with GitHub Code Security

About metrics for Dependabot

The metrics overview for Dependabot provides valuable insights for both developers and application security (AppSec) managers. The data in the Dependabot dashboard page contains a vulnerability prioritization funnel that helps with efficiently prioritizing, remediating, and tracking vulnerabilities across multiple repositories. This ensures that the most critical risks are addressed first and that security improvements can be measured over time.

For more information about how AppSec managers can best use these metrics to optimize alert fixing, see Prioritizing Dependabot alerts using metrics.

You can see Dependabot metrics if you have:

The available metrics combine severity, exploitability, and patch availability, and help in the following ways:

These metrics help managers measure the effectiveness of their vulnerability management and ensure compliance with organizational or regulatory timelines.

Viewing metrics for Dependabot for an organization
  1. On GitHub, navigate to the main page of the organization.

  2. Under your organization name, click Security.

  3. In the sidebar, under "Metrics", click Dependabot dashboard.

  4. Optionally, use the filters at your disposal, or build your own filters. See Dependabot dashboard view filters.

  5. Optionally, click on a number on the x-axis of the chart to filter the alert list by the relevant criteria (for example has:patch severity:critical,high epss_percentage:>=0.01).

  6. Optionally, click on an individual repository to see the associated Dependabot alerts.

Configuring funnel categories

The default funnel order is has:patch, severity:critical,high, epss_percentage>=0.01. By tailoring the funnel’s order, you and your teams can focus on the vulnerabilities that matter most to your organization, environments, or regulatory obligations, making remediation efforts more effective and aligned with your specific needs.

  1. On GitHub, navigate to the main page of the organization.

  2. Under your organization name, click Security.

  3. In the sidebar, under "Metrics", click Dependabot dashboard.

  4. On the top right of the "Alert prioritization" graph, click .

  5. In the "Configure funnel order" dialog, move the criteria as desired.

  6. Once you're done, click Move to save your changes.

Tip

You can reset the funnel order back to the default settings by clicking Reset to default to the right of the graph.


RetroSearch is an open source project built by @garambo | Open a GitHub Issue

Search and Browse the WWW like it's 1997 | Search results from DuckDuckGo

HTML: 3.2 | Encoding: UTF-8 | Version: 0.7.4