GitHub Security & compliance Releases

Known-vulnerable dependency (Dependabot)

Part of the Supply-chain alerts check · fix arrives as a guide

What it is

GitHub has an open Dependabot alert: a dependency in your tree has a published vulnerability.

Why it matters

The advisory is public, which means the vulnerability and often a proof of concept are known to everyone. A patched version already exists, and the window between publication and your upgrade is when exploitation is easiest.

How to fix it

Update to the patched version the alert names. Where no patch exists, check whether your code reaches the vulnerable path and mitigate around it or replace the dependency.

Run them all on your app

Connect your repo and your live services with read-only scopes. The first scan is free, and nothing changes without your approval.