GitHub
Security & compliance
Releases
Known-vulnerable dependency (Dependabot)
Part of the Supply-chain alerts check · fix arrives as a guide
What it is
GitHub has an open Dependabot alert: a dependency in your tree has a published vulnerability.
Why it matters
The advisory is public, which means the vulnerability and often a proof of concept are known to everyone. A patched version already exists, and the window between publication and your upgrade is when exploitation is easiest.
How to fix it
Update to the patched version the alert names. Where no patch exists, check whether your code reaches the vulnerable path and mitigate around it or replace the dependency.
Run them all on your app
Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.